contents13
The essentials
klair is a French custom-software studio — a société par actions simplifiée (SAS) registered in France. We design custom software for our clients and, at their request, we run it for them. klair is a business-to-business (B2B) service: we contract with companies and professionals, not with consumers. We are the data controller for our website, marketing, sales, billing, account data, and the scoping conversations you have with us; we act as a processor for the code and project content we handle to build and host your software, your organisation remaining the controller of that content. We host in the European Union and rely on a small set of providers, described by category below. We do not sell personal data and we do not use it for behavioural advertising. We collect and keep only what is necessary.
Data controller
The controller is KLAIR AI, a société par actions simplifiée (SAS) with share capital of €1,000.00, registered with the Montpellier trade and companies register under number 107 073 769 (intra-community VAT number FR96107073769), with its registered office at Espace Entreprise Garosud, 48 rue Claude Balbastre, 34070 Montpellier, France. The company's full identification and that of its host are set out in our legal notice. For any question about your personal data or to exercise your rights: privacy@klair.dev. Our supervisory authority is the French data-protection authority (CNIL). When we design or run software for a client, we act as a processor for any personal data contained in that client's code and project content, the client remaining the controller; this processing is governed by a separate data-processing agreement (Article 28 GDPR).
Data processed, purposes and legal bases
We process the following categories of data, for the purposes and on the legal bases indicated:
- Account data — name, work email address, organisation, role, language and time-zone preferences, authentication identifiers (we use magic links and OAuth; we store no passwords). Purpose: opening and administering your access. Legal basis: performance of the contract and pre-contractual steps.
- Scoping content — the text you submit through our intake assistant on klair.dev and the draft prepared in order to produce a proposal. Purpose: qualifying your need and preparing an offer. Legal basis: pre-contractual steps and legitimate interests.
- Project content — proposals, messages, milestone sign-offs and attachments exchanged in the portal; and, when we build your software, the associated source code and content, which we process as a processor. Purpose: delivering the service. Legal basis: performance of the contract.
- Billing data — billing address, VAT or other tax identifier, order references and, where applicable, the bank details needed for a refund. Card numbers never reach our servers: they are collected and stored by our payment provider. Purpose: invoicing and collection. Legal basis: performance of the contract and accounting and tax obligations.
- Communications — the content of emails, support requests and meetings. Purpose: responding and following up. Legal basis: legitimate interests and performance of the contract.
- Technical data and logs — IP address (hashed with a salt for rate-limiting), user-agent, timestamps, request and error logs, session identifiers. Purpose: securing the service, ensuring availability and debugging. Legal basis: legitimate interests.
- Contacts and business communications — infrequent messages to client contacts, with an unsubscribe link in every message. Legal basis: legitimate interests and, where the law requires, your consent.
Some data (for example the contact details of the representatives a client designates) is provided to us by your organisation. Where we rely on legitimate interests, we have balanced those interests against your rights, and you may object. Providing account and billing data is necessary to enter into and perform the contract; without it, we cannot provide the service.
Recipients and processors
We disclose personal data only to the following categories of recipient, each governed by a data-processing agreement compliant with Article 28 GDPR:
- cloud hosting and infrastructure — database, authentication and application hosting (European Union, with possible recourse to providers established outside the European Union);
- payment processing (European Union and outside the European Union);
- transactional email delivery (European Union and, where applicable, outside the European Union);
- AI model gateway and providers (European Union and outside the European Union);
- monitoring, logging and fraud prevention (European Union and, where applicable, outside the European Union);
- audience measurement (mainly European Union).
We also disclose data, where strictly necessary, to our professional advisers (lawyers, accountants, auditors) bound by confidentiality, to competent authorities where the law requires it, and to a potential successor in the event of a corporate transaction. A current, named list of our processors is provided to clients on request; it is also set out in the data-processing agreement (Article 28). We do not sell personal data, we do not rent contact lists, and we carry out no cross-context behavioural advertising.
Transfers outside the European Union
Where a recipient is located outside the European Union, the transfer is framed by a European Commission adequacy decision, by the EU–US Data Privacy Framework where the provider is certified under it, or by the Commission's standard contractual clauses (Decision 2021/914) supplemented by the necessary additional measures; a copy of these safeguards is available on request.
Retention periods
We keep personal data only for as long as is necessary for the purposes pursued:
- account data — for the duration of the relationship, then twelve months;
- project content and accounting records — for the duration of the engagement, then ten years, under accounting and tax obligations (Article L123-22 of the French Commercial Code);
- scoping content — up to twelve months after your last activity or, if it leads to an engagement, for the period applicable to that engagement;
- technical and security logs — ninety days;
- business contacts — until you unsubscribe, the suppression record then being kept to ensure your choice is honoured.
Encrypted backups roll out of the system within thirty-five days. You may request earlier deletion at any time; we comply unless a legal retention obligation applies.
Artificial intelligence
We use artificial-intelligence systems and model providers to prepare scoping and proposal content with you and to assist our development work. klair's authorised staff and these systems and providers may access the content you entrust to us strictly to the extent necessary for the purpose pursued and under an obligation of confidentiality. Your content is not used to train third-party AI models. The outputs of these systems are drafts subject to human review; we take no decision producing legal effects or significantly affecting you on the sole basis of automated processing.
Cookies
We use a small set of strictly-necessary cookies for the operation of the service (session, security, consent state) and, where applicable, consent-exempt audience measurement. The detail — the name, purpose and lifetime of each tracker — is set out in our cookies policy.
Security
We implement appropriate technical and organisational measures: encryption in transit and at rest, magic-link and OAuth authentication (no password stored) and least-privilege access controls. As no system is perfectly secure, we review these measures regularly. In the event of a data breach likely to result in a risk to your rights, we notify the CNIL within seventy-two hours and, where the risk is high, the individuals concerned without undue delay. Security matters and responsible disclosures go to security@klair.dev.
Your rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction and objection, the right to data portability, and the right to withdraw your consent at any time where processing is based on it. You may also set instructions on the fate of your data after your death. Send your request to privacy@klair.dev; we respond within one month, extendable by two months for complex or numerous requests, of which we would inform you. You may at any time lodge a complaint with the CNIL (cnil.fr), without prejudice to a judicial remedy.
Changes
We may update this policy. Any material change is signalled to you by appropriate means before it takes effect; minor changes are published on this page with a new effective date.
Contact
Questions about your personal data and exercise of your rights — privacy@klair.dev. Security and responsible disclosure — security@klair.dev. Legal notices — legal@klair.dev. Supervisory authority — the French data-protection authority (CNIL), cnil.fr.
Governing language
The French version of this policy is authoritative. English and Spanish translations are provided for convenience only; in the event of any discrepancy of interpretation, the French version prevails.