Privacy policy

What we hold, why, and how to get it back.

klaspr is built on a rule: never show information without saying where it came from. This page applies that rule to the information klaspr holds about you.

Last updated 17 August 2026

1. Who is responsible

The data controller is [legal entity name], [registered address]. For anything on this page, write to [privacy contact email].

klaspr has not appointed a Data Protection Officer. It is not required to: it does not carry out large-scale monitoring of individuals, and it processes no special-category data.

2. What we collect

Only what the service needs to work. There is no analytics script, no advertising tag, and no third-party tracker anywhere on this site — a claim you can verify in the page source.

Account data. Your email address and password. The password is never stored in readable form: authentication is handled by Supabase, which stores a cryptographic hash. We also keep your account identifier and the dates it was created and last updated.

Organisation data. The name of your organisation, your role in it, and its subscription tier.

Your company profile. What you tell us during onboarding about the company you work for: its name, website, sector, country, a description of what it does, its products, and its target audience. These fields are the entire input to a discovery run.

Discovery results. The companies a scan surfaced, the search query that found each one, the date it was read, a relevance score, the written reason behind that score, and whether you kept, ignored or rejected it.

Monitoring records. Copies of public web pages belonging to the companies you track, the structured data extracted from them, and the changes detected between two readings. See section 5.

Technical data. Our hosting provider processes the usual request metadata — IP address, user agent, requested URL, time — for delivery and security. klaspr does not build profiles from it.

3. Why we process it, and on what basis

  • To provide the service — creating your account, running discovery, storing your shortlist. Legal basis: performance of the contract between you and klaspr (GDPR art. 6.1.b).
  • To keep the service secure and working — access control, abuse prevention, debugging, backups. Legal basis: our legitimate interest in operating a service that is not compromised (art. 6.1.f).
  • To gather competitive information about companies from their public pages. Legal basis: the legitimate interest of klaspr and its customers in market intelligence drawn from published business information (art. 6.1.f). Section 5 sets out the limits we apply and how to object.
  • To answer you when you contact us, and to comply with legal obligations such as accounting once billing exists (art. 6.1.b and 6.1.c).

We do not sell personal data, do not share it for advertising, and do not use it to profile you for marketing.

4. How language models are involved

Two steps of a discovery run call a large language model: turning your company profile into search queries, and classifying each candidate the search returned. The text sent consists of your company profile fields, the visible text of public pages that were read, and candidate company names. Your email address, password and account identifier are never included.

No model produces a fact that klaspr presents as a fact. Anything a model concluded is labelled as an interpretation or a hypothesis in the interface, and prices are extracted by deterministic code with no model involved at all. That is a product rule, and this policy states it because it changes what a model can get wrong about you.

Model providers act as our subprocessors and are listed on the subprocessors page. klaspr does not use customer data to train models, and configures providers on API terms that exclude training on submitted content. Free evaluation tiers that reserve the right to use submitted data for model improvement are used for internal testing only, never with customer data.

No decision producing legal effects concerning you is taken automatically (art. 22). A relevance score orders a list; keeping, ignoring or rejecting a company remains your decision.

5. Information about other companies

klaspr reads public pages belonging to companies its customers track — typically a homepage and a pricing page — and stores what it read, when, and what changed. This is business information about legal entities, which for the most part is not personal data.

It can be personal data in one case that matters: a sole trader, a freelancer or a one-person company whose business is identified by their own name. Where that happens, klaspr is the controller of that data, its legal basis is legitimate interest, and the source is the company’s own published website. This section is the notice required by GDPR art. 14.

The limits klaspr applies, in code and not only in policy:

  • Only pages that are publicly reachable. Nothing behind a login, a paywall or a form.
  • Only pages of a business nature: homepage, pricing, product, changelog.
  • No collection of employee names, contact details, CVs or social profiles.
  • Every stored observation carries the URL it came from and the date it was read, so any claim can be traced back and challenged.

If you are identified by such a page and you object to the processing, or the information held is wrong, write to [crawler contact email]. The KlasprBot page explains how to block collection at the source as well.

6. Who else processes your data

klaspr relies on a small number of providers to host, store and process data on its instructions. Each one, what it receives and where it is located, is listed on the subprocessors page. They act as processors under written terms and may not use the data for their own purposes.

Beyond that, data is disclosed only where the law requires it, or to professional advisers bound by confidentiality.

7. Transfers outside the EEA

Several of those providers are established in the United States, so personal data is transferred outside the European Economic Area. Those transfers rely on the European Commission’s Standard Contractual Clauses, and where applicable on the provider’s certification under the EU-US Data Privacy Framework. The subprocessors page states the location of each one.

8. How long we keep it

Account and organisation data: for as long as the account exists. Deleting your account deletes it — the database removes your organisation, your company profile, your tracked companies and your discovery results along with the account itself, rather than marking them hidden.

Observations of third-party public pages: these are shared infrastructure. They are not attached to your account, they contain no information about you, and they are not deleted when an account is closed. They are also append-only by design: a past observation cannot be rewritten, because rewriting it would silently change the evidence behind a conclusion already shown.

klaspr does not yet apply an automatic retention limit to stored page content. A ninety-day purge of raw HTML is planned and is not built. Saying otherwise would describe a roadmap item as a practice.

Backups are kept by our database provider and are overwritten on that provider’s own cycle. Data deleted from the live database persists in a backup until that cycle completes.

9. Security

Isolation between accounts is enforced in the database itself, through PostgreSQL row-level security, rather than only in application code. Every query runs under the identity of the signed-in user, so a bug in a page cannot return another organisation’s rows. Writes to shared tables are restricted to a service role that no browser session holds.

Traffic is encrypted in transit. Passwords are stored hashed by our authentication provider. Third-party access tokens, where the product stores them, are encrypted at rest with a key held outside the database.

No system is beyond compromise. If a breach is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform you where the law requires it.

10. Your rights

Under the GDPR you may request access to your personal data, its correction, its erasure, the restriction of its processing, its portability in a machine-readable format, and you may object to processing based on legitimate interest.

Write to [privacy contact email]. We answer within one month, and will say so if a request needs longer. We may ask for proof of identity where a request concerns data whose disclosure to the wrong person would itself be a breach.

If our answer does not satisfy you, you may lodge a complaint with the CNIL (Commission nationale de l'informatique et des libertés, France) (file a complaint), or with the authority of the EU country where you live or work.

11. Children

klaspr is a tool for businesses and is not directed at anyone under 16. We do not knowingly collect their data. If you believe a child has created an account, tell us and it will be removed.

12. Changes to this policy

This policy changes when the product changes — a new subprocessor, a new category of data, a retention limit that finally exists. The date at the top is updated whenever the text is. Changes that materially affect you will be announced in the application before they take effect, not published quietly and dated afterwards.