KlarBond
ProductHow it worksSolutionsSecurityResources
Request early access

KlarBond Restricted Data Policy

Effective date: 29 June 2026

This policy explains what information must not be uploaded, connected, entered or otherwise processed through KlarBond during the closed beta unless KlarBond has given separate written approval and agreed appropriate safeguards.

KlarBond is designed for business and organisational document review. It is not designed to receive every type of sensitive, regulated, secret or high-risk information by default.

1. Permitted ordinary business information

Subject to the Terms of Service, Privacy Policy and Customer's own obligations, KlarBond may be used for ordinary business documents such as:

  • policies and procedures;
  • ordinary commercial documents;
  • supplier materials;
  • operational documentation;
  • internal knowledge materials;
  • reports and presentations;
  • non-sensitive governance materials; and
  • business correspondence.

Limited ordinary business personal data may be included where necessary and authorised, such as a person's name, work email address, employer, job title or professional role.

Ordinary business documents may still contain confidential information. Customer is responsible for checking that it has authority to process that information through KlarBond and through the providers listed in the Subprocessor List.

2. Prohibited information during the closed beta

Unless a separate written agreement expressly says otherwise after KlarBond completes legal, privacy and security review, users must not upload, connect or enter the categories below.

2.1 Sensitive personal data

  • health, medical, patient, therapy or disability information;
  • genetic data;
  • biometric data used for identification;
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • sex life or sexual orientation;
  • criminal allegations, proceedings, convictions, cautions or offences;
  • safeguarding records;
  • children's data;
  • vulnerable-person data; or
  • large or systematic datasets about employees, applicants, customers, pupils, patients, beneficiaries, claimants, tenants or service users.

2.2 High-impact personal decisions

Do not use KlarBond as the sole or determinative basis for decisions concerning employment, recruitment, credit, insurance, education, healthcare, legal services, public benefits, safeguarding, immigration or another person's rights, eligibility, access or treatment.

Ordinary non-sensitive policies or documents from these sectors may be reviewed only where they do not contain prohibited information and every Output remains subject to appropriate human review.

2.3 Credentials and security secrets

  • passwords;
  • API keys;
  • private cryptographic keys;
  • access, refresh or session tokens;
  • recovery codes;
  • authentication cookies;
  • database credentials; or
  • information that could enable unauthorised access to a system, account, network or encrypted information.

2.4 Payment and identity information

  • full payment-card data;
  • card verification values, PINs or payment authentication data;
  • online banking credentials;
  • passports, driving licences, national identity cards or similar identity documents;
  • national insurance, social security, tax or government-issued identification numbers;
  • detailed bank-account information or bank statements; or
  • documents used for identity verification, anti-money-laundering or know-your-customer checks.

2.5 Privileged, classified and controlled information

  • legally privileged advice, litigation strategy or protected investigation material;
  • classified government information or official secrets;
  • export-controlled or national-security information;
  • source code, private security architecture, vulnerability details or penetration-test findings that could materially increase security risk;
  • information whose cloud or external-AI processing is prohibited by law, court order, contract, professional duty or internal policy; or
  • information that requires a certification, accreditation, location or control that KlarBond has not expressly confirmed in writing.

2.6 Unlawful or unauthorised information

  • information obtained unlawfully;
  • information the Customer is not authorised to possess or process;
  • illegal content;
  • malicious code or content intended to compromise KlarBond or a connected service; or
  • information submitted in breach of another person's intellectual-property, confidentiality, privacy or contractual rights.

3. Documents belonging to clients or third parties

A Customer may submit a client, supplier, employee or other third-party document only where:

  • the Customer has authority to process it through KlarBond;
  • the relevant client, controller or other party has provided any required instruction or permission;
  • required privacy information has been provided;
  • the processing has an appropriate lawful basis;
  • external cloud and AI processing is permitted; and
  • the document does not contain information prohibited by this policy.

If the Customer acts for its own client, the Customer must ensure that it may appoint KlarBond and the providers listed in the Subprocessor List.

4. Data minimisation

Before submitting a permitted document, users should:

  1. upload only information reasonably necessary for the task;
  2. remove unrelated pages, attachments, comments, tracked changes, hidden text and metadata where possible;
  3. redact unnecessary names, contact details, signatures, account details and identifiers;
  4. use anonymised or pseudonymised content where the purpose can be achieved without direct identification;
  5. limit connected-source permissions to the minimum necessary files and folders;
  6. confirm the destination workspace and access permissions; and
  7. avoid placing restricted information in filenames, prompts, notes or support messages.

Redaction must remove the underlying information, not merely cover it visually.

5. Connected sources

When connecting Google Drive, Microsoft OneDrive or Microsoft SharePoint, the Customer must:

  • use an authorised account;
  • select the minimum required scope;
  • ensure selected files comply with this policy;
  • review changes or synchronisation settings; and
  • revoke access when it is no longer needed.

A source permission does not replace the Customer's obligation to obtain any required client, controller or confidentiality authorisation.

6. AI-assisted features

Some KlarBond features transmit selected document text, prompts, metadata and Outputs to approved commercial AI providers.

Users must not submit information to an AI-assisted feature where their organisation, client, contract, professional duty or applicable law prohibits processing by an external AI or cloud provider.

Access to an AI feature does not mean that every document is approved for that feature.

7. Accidental submission

If prohibited information is submitted by mistake, the Customer must:

  1. stop further processing or sharing;
  2. restrict access to the affected item or workspace where possible;
  3. notify KlarBond promptly at privacy@klarbond.com;
  4. identify the affected workspace, file and approximate upload time without repeating the prohibited information unnecessarily; and
  5. follow reasonable containment, deletion and investigation instructions.

KlarBond may quarantine, restrict or delete affected content and may suspend the relevant account or feature where reasonably necessary.

An accidental submission may also require a personal-data-breach assessment.

8. No automatic detection guarantee

KlarBond may use warnings, file restrictions, scanning or other safeguards, but does not guarantee that it will detect prohibited information before or after submission.

The absence of a warning or technical block does not mean that the information is permitted.

9. Future enterprise exceptions

KlarBond does not currently approve the prohibited categories in this policy for standard closed-beta use.

A future enterprise use case may be considered only through a separate written assessment and agreement. Additional controls may include different provider settings, no external AI processing, shorter retention, specific hosting or regional requirements, additional access controls, security review, or customer-specific contractual terms.

Access to the current beta does not create any expectation that an exception will be approved.

10. Enforcement

A material or repeated breach may result in quarantine or deletion of content, restriction of a feature, suspension or termination under the Terms of Service.

11. Contact

Questions or accidental-upload reports: privacy@klarbond.com

KlarBond Ltd
Company number: 17300261
ICO registration number: ZC182066
Registered office: 5th Floor, 167–169 Great Portland Street, London, W1W 5PF, United Kingdom

KlarBond LtdCompany number 17300261ICO registration number ZC182066Registered office: 5th Floor, 167-169 Great Portland Street, London, W1W 5PF, United KingdomRegistered in England and Wales

© 2026 KlarBond Ltd. All rights reserved.

Legal CentreTerms of ServicePrivacy PolicyCookie NoticeAI Processing NoticeRestricted Data PolicySubprocessor ListCommunications