Protecting your personal data matters to us. This policy informs you in accordance with the GDPR about the nature, scope and purpose of the processing of personal data on this website.
When you access the website, technically necessary data (e.g. IP address, time, page requested) is processed by the hosting provider (Cloudflare) to ensure delivery and security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest).
If you use the Quick-Check or enquiry form, we process the data you provide (e.g. email address, company, enquiry content) solely to handle your request and deliver your result. The legal basis is Art. 6(1)(b) and (f) GDPR. Data is not shared with third parties without your consent.
For the company dashboard and the training we process sign-in data (email address), the names of the participants, their progress and their test result. The legal basis is Art. 6(1)(b) GDPR: without this information neither an account nor a certificate can be issued. Where the participants are employees of a corporate customer, we process this data on that employer’s behalf — see the section on processing on behalf of our customers.
Every certificate carries a verification ID. Anyone who knows that ID can look up the name of the certified person, the company and the expiry date at klarcomply.com/verify. That is precisely what a certificate is for and part of the agreed service (Art. 6(1)(b) GDPR). Without the ID there is no lookup, and there is no list of all certificates. Issued certificates stay verifiable until they expire, including after the contract ends.
Requesting the compliance kit means giving us an email address and the details in the request form. We use them to send the download link and, afterwards, up to four follow-up emails on the subject. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future — one click on the unsubscribe link in each of those emails, or an informal message to us; the lawfulness of processing before the withdrawal is unaffected. We measure neither opens nor clicks in these emails.
We set no cookies for advertising or audience measurement. In your browser’s local storage we keep the language you chose and, once you are signed in, your session and your course progress. This is strictly necessary for the functions you asked for and therefore requires no consent (the ePrivacy rules implementing Art. 5(3) of Directive 2002/58/EC). You can delete this data at any time through your browser settings.
We use the following services: Cloudflare Inc. (hosting and CDN; USA, delivered from EU locations, EU standard contractual clauses), Supabase Inc. (database, sign-in and server functions; USA, data stored exclusively in the EU — AWS eu-central-1, Frankfurt — EU standard contractual clauses) and Google Ireland Ltd. (Google Workspace; sending and receiving our email via kontakt@klarcomply.com). These three process data as processors under Art. 28 GDPR. Payments are handled by Stripe Payments Europe Ltd. (Ireland) as an independent controller; card details never reach us. For reach measurement we use Cloudflare Web Analytics (Cloudflare Inc.): a cookie-less count without cross-site tracking and without profiling — it shows us which pages are visited and how often. If you reach us via a referral or partner link, your browser remembers the origin for 90 days (cookie kc_ref or kc_partner); it contains only the referral code, no personal data, and serves solely to attribute the referral. Beyond that, no tracking or advertising cookies are set.
Where a corporate customer stores data about its staff or its own customers in the dashboard, we are not the controller for that data but a processor under Art. 28 GDPR. The basis is the data processing agreement concluded with the subscription; it is available at klarcomply.com/avv. Data subjects should address their rights to their employer as the controller — we support the employer in answering them.
We keep personal data only as long as the purpose requires or the law demands. Specifically: enquiries and quick-check results until your matter is settled and no further questions are to be expected; account and training data for the term of the contract; certificate data until the certificate expires, so that it stays verifiable; data based on consent until that consent is withdrawn; invoices and accounting records for the statutory commercial and tax retention periods; notices of termination for as long as we must be able to evidence their receipt. After that we delete or anonymise the data.
You have the right to access, rectification, erasure, restriction of processing, data portability and objection. You also have the right to lodge a complaint with the competent supervisory authority (in Malta: Information and Data Protection Commissioner, idpc.org.mt).
Where we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then stop processing that data unless we can demonstrate compelling legitimate grounds that override your interests.