KlarBond Privacy Policy
Effective date: 29 June 2026
This Privacy Policy explains how KlarBond collects, uses, shares, retains and protects personal data when people visit our website, request early access, complete a scorecard, communicate with us or use a KlarBond account or workspace.
1. Who we are
KlarBond is operated by:
KlarBond Ltd, registered in England and Wales
Company number: 17300261
ICO registration number: ZC182066
Registered office: 5th Floor, 167–169 Great Portland Street, London, W1W 5PF, United Kingdom
Privacy contact: privacy@klarbond.com
Legal contact: legal@klarbond.com
KlarBond Ltd is the controller for the personal data described in this policy unless we explain that we process it on behalf of a customer.
European Union representative
KlarBond does not currently actively market or onboard the closed beta in the EEA. KlarBond will review whether an EU representative is required before any active EEA launch or other activity that requires one.
2. What this policy covers
This policy covers personal data processed through:
- the KlarBond website;
- early-access request forms;
- scorecard forms and reports;
- cookie and browser-storage choices;
- website analytics and campaign measurement where enabled;
- email, support and business communications;
- product trials, beta workspaces and customer workspaces;
- account registration and authentication;
- connected-source activity; and
- document-related activity inside KlarBond where personal data is included.
3. Our role: controller and processor
For website visitors, early-access applicants, scorecard users, contacts, prospects, account users, support contacts and business contacts, KlarBond usually acts as the controller. This means we decide why and how we use that personal data.
For documents, files and workspace content uploaded or connected by a customer organisation, KlarBond usually acts as a processor. This means we process that content on behalf of the customer organisation and in line with the customer's instructions, our agreement with that customer and applicable data processing terms.
If your organisation uploads personal data about other people into KlarBond, your organisation is responsible for ensuring that it has the right to do so and that the content complies with the Restricted Data Policy.
4. Personal data we collect
Information you provide
This may include:
- name;
- work email address;
- organisation name;
- role or job title;
- department;
- country or region;
- use case;
- early-access answers;
- scorecard answers;
- messages, feedback and support requests;
- account registration details; and
- billing or contract contact information where applicable.
Workspace and product data
If you use a KlarBond workspace, we may process:
- account and workspace profile details;
- organisation settings;
- user roles and permissions;
- uploaded or connected documents and files;
- document metadata;
- document text and extracted content;
- comments, notes, prompts, review instructions and questions submitted by users;
- AI-assisted outputs, summaries, checks, classifications, reports or drafts;
- embeddings, indexes and search-related data;
- connector records and authorised source-change information; and
- usage events needed to operate, secure, maintain and improve the service.
Workspace content may include personal data if you or your organisation choose to include it. During the closed beta, only limited ordinary business personal data should be included where necessary and authorised.
Technical and security data
We may collect:
- IP address or hashed IP address;
- user agent;
- browser and device information;
- source path and referrer;
- timestamps;
- authentication and access logs;
- workspace, permission and audit events;
- log data;
- error reports;
- performance data; and
- security and abuse-prevention signals.
Cookies and similar technologies
We use cookies, local storage, session storage, tags and similar technologies. Necessary technologies support authentication, security, service operation and cookie preferences. Optional technologies, including site-improvement and measurement technologies, are used only where required consent has been given. Our Cookie and Browser Storage Notice gives more detail.
5. How we use personal data
| Purpose | Data used | Lawful basis |
|---|---|---|
| Receive and review early-access requests | Name, work email, organisation, role, country, use case and form answers | Legitimate interests; steps before contract where relevant |
| Provide scorecard results and follow-up | Contact details, organisation details and scorecard answers | Legitimate interests; consent where required; steps before contract where relevant |
| Operate KlarBond accounts and workspaces | Account details, workspace data, user activity, documents and outputs | Contract, legitimate interests, and customer instructions where we act as processor |
| Analyse uploaded or connected documents and produce outputs | Customer Content, document text, prompts, metadata, embeddings and outputs | Contract and legitimate interests; where acting as processor, customer instructions |
| Provide support and respond to messages | Contact details, communication content and support history | Legitimate interests and contract |
| Secure the service and prevent abuse | Technical logs, hashed IP, user agent, access events, security events and abuse signals | Legitimate interests and legal obligation where applicable |
| Maintain, test and improve reliability and product quality | Usage information, feedback, error data, telemetry and non-content operational data | Legitimate interests; consent where required for optional technologies |
| Measure website interest and campaigns | Cookie choices, campaign source, visitor data and analytics events | Consent where required |
| Send relevant product or business communications | Work contact details, communication preferences and relationship history | Legitimate interests or consent depending on the context |
| Comply with legal, tax, accounting, regulatory and dispute obligations | Account, billing, contract, legal and communication records | Legal obligation and legitimate interests |
We do not sell personal data.
6. AI-assisted processing
KlarBond may use selected commercial AI providers to support document analysis, summaries, contradiction checks, structured outputs, drafting support, embeddings and related product features.
When AI providers are used, they may process prompts, selected document text, metadata, embeddings inputs and generated outputs where needed to provide the requested feature.
KlarBond does not use consumer AI accounts to process customer workspace content. KlarBond does not use customer workspace content to train general-purpose AI models unless expressly agreed with the customer. KlarBond also disables optional provider model-improvement or data-sharing settings for Customer Content where those settings are available to KlarBond.
Commercial AI providers may retain limited request or response information for service delivery, security, abuse prevention, legal compliance, support or other purposes described in their commercial terms. Retention varies by provider, product, endpoint, model and configuration. KlarBond may use reduced-retention or zero-data-retention options where available, appropriate and commercially agreed, but those options are not promised unless stated in a separate written agreement or published provider configuration for the relevant feature.
AI-assisted outputs should be reviewed by a human before they are relied on.
More detail is provided in the AI Processing Notice and Subprocessor List.
7. Restricted data
During the closed beta, KlarBond is not intended for:
- health or medical data;
- other special-category personal data;
- criminal-offence data;
- children's or vulnerable-person data;
- safeguarding records;
- legally privileged material;
- passports or identity documents;
- detailed bank, payment-card or authentication data;
- passwords, private keys, access tokens or other secrets;
- classified or export-controlled information; or
- information that your organisation is not authorised to process through external cloud or AI providers.
The Restricted Data Policy gives more detail. KlarBond does not guarantee that it can detect restricted information before it is processed.
8. Cookies and website measurement
Some cookies or similar technologies are necessary for the website or application to work, to authenticate users, to remember cookie choices or to provide a setting selected by the user.
Optional cookies, analytics tags, campaign measurement tools and similar technologies are only used where required consent has been given.
The current public-site optional measurement setup uses Google Tag Manager container `GTM-WWJTR75Q` to run Google Analytics 4 destination `G-CBRKC8Q16K`, including `page_view` and `generate_lead` events, and Meta Pixel `1014729200934579` for campaign funnel measurement. These tags are controlled through the cookie-consent mechanism.
You can change your cookie choices through the Cookie Settings control on our website or application.
9. Who we share personal data with
We may share personal data with:
- hosting and infrastructure providers;
- database, storage, backup and security providers;
- authentication and email providers;
- analytics, telemetry and campaign measurement providers where enabled;
- AI, automation and processing providers used to deliver KlarBond features;
- connected-source providers authorised by a customer, such as Google or Microsoft;
- professional advisers, such as lawyers, accountants and insurers;
- authorities, regulators, courts or law enforcement where required by law; and
- potential buyers, investors or successors if KlarBond is involved in a merger, acquisition, investment, restructuring or sale.
Where providers process personal data for us, we use appropriate contracts and data-protection arrangements.
Current core infrastructure is hosted through Amazon Web Services in the AWS Europe (London) Region. The public Subprocessor List identifies the provider categories and customer-directed connected sources.
10. International transfers
Some service providers may process personal data outside the United Kingdom or the country where you are located. For example, ancillary support, security, telemetry or provider-subprocessor activity may occur outside the UK even where primary hosting is in London.
Where required, we use appropriate safeguards for international transfers, such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, EU Standard Contractual Clauses or other lawful transfer mechanisms.
You can contact us for more information about the safeguards used.
11. How long we keep personal data
We keep personal data only for as long as needed for the purposes described in this policy, unless a longer period is required by law or reasonably needed for security, legal or dispute purposes.
Our typical retention approach is:
| Data type | Typical retention |
|---|---|
| Early-access requests | Up to 24 months after the last meaningful interaction |
| Scorecard submissions | Up to 24 months, unless deleted earlier on request or needed for ongoing communication |
| Website technical and security logs | Usually up to 12 months, unless needed for security, fraud prevention, investigation or legal reasons |
| Cookie preference records | Up to 180 days, unless renewed or changed earlier |
| First-party visitor identifier, where consented | Up to 180 days |
| Support and business communications | Up to 36 months after the last meaningful interaction |
| Customer workspace content | For the duration of the customer relationship, then deleted or returned according to the customer agreement |
| Deleted Customer Content in active systems | Usually removed from active systems within 30 days |
| Protected backups containing deleted Customer Content | Usually removed or overwritten within 90 days |
| Legal, accounting, contract and tax records | Usually up to 6 years or longer if required by law or a dispute |
| Marketing suppression records | As long as needed to respect opt-outs |
| Privacy requests, complaints and incident records | As long as reasonably needed to handle the matter and evidence compliance, normally up to 6 years where legal claims may be relevant |
Deletion can be subject to technical limitations, backup cycles, legal holds, security investigations, dispute records and provider retention described in the relevant provider terms.
Where we no longer need personal data, we delete it, anonymise it or securely retain it only where legally necessary or reasonably required.
12. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures may include access controls, encryption in transit and at rest, logging, monitoring, secure infrastructure, role-based permissions, least-privilege controls, backups and internal security processes.
No system is completely secure. If you believe your account, workspace or data may have been compromised, contact us promptly at privacy@klarbond.com or legal@klarbond.com.
13. Your rights
Depending on where you are located and the data protection laws that apply, you may have rights to:
- access your personal data;
- correct inaccurate personal data;
- request deletion;
- restrict processing;
- object to processing;
- request data portability;
- withdraw consent where processing is based on consent; and
- complain to a data protection authority.
To exercise your rights, contact privacy@klarbond.com.
If your request relates to personal data contained in a customer workspace, we may refer the request to the relevant customer organisation where they are the controller.
14. Data protection complaints
You can make a data protection complaint by contacting privacy@klarbond.com or by writing to the registered office above.
We will acknowledge a data protection complaint within 30 days, investigate it, keep you informed as appropriate and communicate the outcome without undue delay.
If you are in the UK, you can complain to the Information Commissioner's Office.
15. Marketing communications
We may send relevant product or business communications to business contacts where permitted by law.
You can opt out of marketing communications at any time by using the unsubscribe option in the message or by contacting us.
We will still send non-marketing messages where needed, such as service, security, legal or account-related communications.
16. Children
KlarBond is not intended for children. We do not knowingly collect personal data from children.
17. Links to other websites
Our website may link to third-party websites, services or content. We are not responsible for the privacy practices of those third parties.
18. Language
This Privacy Policy is provided in English. If we provide a translation, it is for convenience only. If there is any inconsistency between a translation and the English version, the English version will prevail unless applicable law requires otherwise.
19. Changes to this policy
We may update this Privacy Policy from time to time.
If we make material changes, we will take reasonable steps to notify users or customers. The updated version will be posted on our website with a new effective date.
20. Contact
KlarBond Ltd
Company number: 17300261
ICO registration number: ZC182066
Registered office: 5th Floor, 167–169 Great Portland Street, London, W1W 5PF, United Kingdom
Privacy: privacy@klarbond.com
Legal: legal@klarbond.com