KlarBond
ProductHow it worksSolutionsSecurityResources
Request early access

KlarBond Subprocessor List

Effective date: 29 June 2026

KlarBond uses selected third-party providers to host, secure, operate and support the Service.

A provider is a subprocessor where it processes personal data contained in Customer Content on KlarBond's behalf.

1. Core Customer Content subprocessors

ProviderService and purposeCustomer Content or personal dataMain processing locationSafeguard and status
Amazon Web Services EMEA SARL (AWS)Application hosting and compute; database; uploaded-document and object storage; authentication; transactional email; queue and cache; logs, error monitoring and operational telemetry; backup and recovery according to the deployed configurationAccount and authentication information; workspace information; uploaded files; extracted content; embeddings and indexes; findings and Outputs; permissions; email delivery data; workflow data; audit, security, performance and error informationAWS Europe (London) Region, United KingdomAWS contractual data-processing terms apply. KlarBond uses the London Region for the listed core services and applies the relevant transfer safeguards to any ancillary processing outside the UK.

KlarBond's core closed-beta application hosting, database, document storage, authentication, transactional email, queue/cache and logging or monitoring are hosted through AWS in the Europe (London) Region.

AI-provider status

No specific commercial AI provider is named in this public closed-beta list while KlarBond is pre-onboarding. Before KlarBond onboards a customer to an AI-assisted feature that sends Customer Content to an external AI provider, KlarBond will identify the relevant provider or provider category in the Subprocessor List, customer agreement or other applicable customer-facing notice.

Any confirmed AI provider will be treated as a material subprocessor where it processes Customer Content on KlarBond's behalf. KlarBond will disclose the provider identity, product or API, training position, retention position, processing location and transfer safeguard at the appropriate onboarding stage. Provider retention may include limited service, security, abuse-prevention, support or legal-compliance retention under the provider's commercial terms. Reduced-retention or zero-data-retention settings may be used where available and agreed, but are not assumed by default.

2. Customer-directed connected sources

Customers may choose to connect the following third-party sources. The provider's legal role depends on the integration and the Customer's own agreement with that provider.

ProviderConnectionInformation involvedCustomer responsibility
GoogleGoogle DriveConnected account and authorisation information, selected file and folder identifiers, metadata, document content and source-change informationCustomer must authorise the account, select an appropriate scope and ensure the documents may be processed through KlarBond
MicrosoftMicrosoft OneDriveConnected account and authorisation information, selected file and folder identifiers, metadata, document content and source-change informationCustomer must authorise the account, select an appropriate scope and ensure the documents may be processed through KlarBond
MicrosoftMicrosoft SharePointConnected tenant or site authorisation information, selected file and folder identifiers, metadata, document content and source-change informationCustomer must authorise the connection, select an appropriate site or library scope and ensure the documents may be processed through KlarBond

KlarBond may read authorised files, monitor authorised source changes and manage connection tokens as necessary to provide these connectors. KlarBond does not modify third-party records through these connectors unless a separate written agreement expressly permits it.

3. Website and application telemetry providers

These providers process data for KlarBond's own website, application reliability, security or measurement activities. They do not receive Customer Content merely because their technology is present on the public website.

ProviderPurposeInformationConsent position
Google Tag Manager — container `GTM-WWJTR75Q`Manages approved public-website tagsBrowser, device, page, referral, event and permitted identifier information according to each enabled tagOptional tags remain disabled until the required consent. Current configured Google tags are listed below.
Google Analytics 4 / Google tag — destination `G-CBRKC8Q16K`Optional public-site measurement and lead-event measurement through GTMPage and event information, browser/device information, referrer/source information, and analytics identifiers such as `_ga` and `_ga_CBRKC8Q16K` where analytics storage is allowedEvents currently identified: `page_view` triggered by `klarbond_page_view`, and `generate_lead` triggered by `generate_lead`. No Google Ads, LinkedIn or Hotjar tag was identified in the reviewed configuration.
Meta Pixel — pixel `1014729200934579`Optional public-site campaign funnel measurementPage and event information, browser/device information, referrer/source information, and Meta Pixel identifiers where marketing consent is allowedEvents currently identified: `PageView`, `ScoreCardInitView`, `ScorecardStart`, `ScorecardEnd`, `ScorecardRequested`, `ScorecardReportView`, and `RequestAccess`. The static no-JavaScript image pixel is not used.

No LinkedIn or Hotjar tag was identified in the reviewed configuration.

4. AI provider onboarding disclosure standard

Before a commercial AI provider processes Customer Content for an onboarded customer, KlarBond should document:

  • the provider and applicable legal entity;
  • whether KlarBond accesses the provider directly or through a cloud intermediary;
  • the commercial product or API;
  • approved endpoints, models and storage features;
  • whether provider training and optional data sharing are disabled;
  • provider-side retention and deletion behaviour;
  • whether any reduced-retention or zero-data-retention configuration applies;
  • processing and support locations;
  • the applicable data processing agreement;
  • international transfer safeguards; and
  • any material provider subprocessors.

KlarBond does not use consumer AI accounts for Customer Content and does not use Customer Content to train a general-purpose AI model unless the Customer separately and expressly agrees in writing.

5. Changes

KlarBond will provide at least 30 days' advance notice of an intended new or replacement material subprocessor where reasonably practicable.

Notice may be provided by email to an account administrator, through the Service or through a published subscription mechanism.

A Customer may object during the notice period on reasonable and documented data-protection grounds. KlarBond and the Customer will work in good faith to resolve a valid objection under the applicable customer agreement or Data Processing Addendum.

Urgent changes required for security, law or service continuity may occur on shorter notice. KlarBond will provide notice as soon as reasonably practicable.

6. Removed subprocessors

ProviderServiceDate processing ended
None currently listed

7. Contact

Questions or objections concerning subprocessors: privacy@klarbond.com

KlarBond Ltd
Company number: 17300261
ICO registration number: ZC182066
Registered office: 5th Floor, 167–169 Great Portland Street, London, W1W 5PF, United Kingdom

KlarBond LtdCompany number 17300261ICO registration number ZC182066Registered office: 5th Floor, 167-169 Great Portland Street, London, W1W 5PF, United KingdomRegistered in England and Wales

© 2026 KlarBond Ltd. All rights reserved.

Legal CentreTerms of ServicePrivacy PolicyCookie NoticeAI Processing NoticeRestricted Data PolicySubprocessor ListCommunications