Legal information
Privacy policy
Last updated:
This Privacy Policy describes how Boostage, publisher of the Klarity service (hereinafter "Klarity", "we"), collects, uses, retains and protects personal data, in compliance with Regulation (EU) 2016/679 of 27 April 2016 ("GDPR") and French Act No. 78-17 of 6 January 1978 as amended, known as the French Data Protection Act.
Klarity is an online software (SaaS) that assists the practice of coaching, intended for independent Professionals. It enables client and session management, note-taking, the generation of session reports and briefings, as well as an AI-assisted session memory (automatic summaries, briefings, search and chat over the longitudinal memory).
1. Data controller and DPO contact
For the processing described in this policy (the Professional user's data), the data controller is:
- Company name: Boostage
- Legal form: EURL
- Registered office: 200 rue de la Croix Nivert, 75015, Paris, France
- Registration: RCS Paris — 988 833 869 R.C.S. Paris
- Contact email: support@klarity.coach
- Website: https://klarity.coach — Application: https://app.klarity.coach
Data Protection Officer (DPO)
Given the nature of the data processed (longitudinal tracking, processing by artificial intelligence, data that may be sensitive on the Professionals' clients' side), a data protection representative has been appointed. You may contact them for any question relating to your data or to exercise your rights:
- DPO / GDPR representative: Anthony Desbois
- Email: support@klarity.coach
- Postal address: 200 rue de la Croix Nivert, 75015, Paris, France
2. Scope: what this policy covers and does not cover
Klarity processes personal data in two distinct roles within the meaning of the GDPR, which it is essential not to confuse.
2.1 What this policy covers — Klarity as data controller
This policy applies exclusively to the data for which Klarity acts as data controller, that is, the data concerning the Professional user themselves:
- the Professional's account and identity data (registration, authentication, profile, qualification, preferences);
- billing and subscription data (via our payment provider);
- platform usage data (activity, technical logs, usage metrics, quotas);
- communication and marketing data (transactional emails and, subject to consent, marketing);
- customer support data.
2.2 What this policy does NOT cover — Klarity as processor
Klarity is not the data controller for the data that the Professional enters, imports or generates about their own end clients (the Professional's clients). This includes in particular:
- the client records and longitudinal history;
- the Professional's session notes and enrichment notes;
- the transcriptions of sessions captured via visio;
- the reports, briefings and imported documents;
- the follow-up objectives and commitments, and the between-session check-ins (optional follow-up questions emailed to the client, whose encrypted answers feed the RAG memory);
- the RAG memory (vectorization of transcriptions, summaries and notes) and the Chat Memory exchanges.
For this data, it is the Professional who is the data controller: they determine the purposes, collect their clients' consent, and are answerable for their rights. Klarity acts only as a processor, on the Professional's instructions and solely for the needs of providing the service.
➜ This processing is governed by the data processing agreement (DPA) concluded between the Professional and Boostage, in accordance with Article 28 of the GDPR. This DPA details the data categories, security measures, location, sub-processors and support arrangements. The Professional's clients wishing to exercise their rights must contact their Professional, the data controller.
3. Data categories, purposes, legal bases and retention periods
The tables below concern only the processing for which Klarity is the controller (the Professional's data — see section 2.1).
3.1 Identity and account data
Data collected: last name, first name, email address, password (stored in hashed form), language and timezone, the Professional's profile data (public slug, avatar, qualification / "about"), role and organization.
| Purpose | Legal basis | Retention period |
|---|---|---|
| Account creation and management, authentication, service provision | Performance of the contract (Art. 6.1.b) | Duration of the account, then deletion / anonymization (see §7) |
| Account security (email verification, password reset, email change) | Performance of the contract + legitimate interest (security) | Duration of the account |
3.2 Connection and platform usage data
Data collected: connection history, activity and execution logs, usage and quota metrics (number of sessions, import credits, Chat Memory message volume, cost per AI message), application events, IP address, technical identifiers.
| Purpose | Legal basis | Retention period |
|---|---|---|
| Operation, quota and subscription tracking, usage-based billing | Performance of the contract (Art. 6.1.b) | Duration of the account + applicable legal period |
| Security, fraud and abuse prevention, anti-bot | Legitimate interest (Art. 6.1.f) | 12 months for security logs (indicative) |
| Service improvement and proper operation, internal statistics | Legitimate interest (Art. 6.1.f) | Aggregated / anonymized beyond the contractual relationship |
3.3 Billing and subscription data
Data collected: subscribed plan (Starter, Professional, Signature), subscription status, payment history, payment provider's customer identifier, subscription metadata. Payment card data is never collected or stored by Klarity: it is processed directly by our payment provider, PCI-DSS certified.
| Purpose | Legal basis | Retention period |
|---|---|---|
| Subscription management, collection, trial management (14 jours, sans carte bancaire) | Performance of the contract (Art. 6.1.b) | Duration of the contract |
| Accounting and tax obligations (invoices) | Legal obligation (Art. 6.1.c) | 10 years (accounting records — Art. L.123-22 of the French Commercial Code) |
| Churn analysis and payment fraud prevention | Legitimate interest (Art. 6.1.f) | Duration of the contract + limitation period |
3.4 Communications and marketing
Data collected: email address, communication preferences, lifecycle events (registration, onboarding, quota alerts, reminders), interactions with our emails.
| Purpose | Legal basis | Retention period |
|---|---|---|
| Transactional emails (security, billing, service notifications) | Performance of the contract (Art. 6.1.b) | Duration of the account |
| Marketing emails / commercial prospecting, automation sequences | Consent (Art. 6.1.a) — withdrawable at any time | Until consent is withdrawn, or 3 years after the last contact |
| Commercial relationship management (via a third-party CRM tool) | Legitimate interest (Art. 6.1.f) — customer relationship follow-up; right to object | 3 years after the last contact |
3.5 Customer support
Data collected: content of support requests, email address, history of exchanges.
Support requests may be handled via a third-party support tool that processes the email address and the message content; the list of sub-processors is provided on simple request to support@klarity.coach.
| Purpose | Legal basis | Retention period |
|---|---|---|
| Handling requests, assistance, quality monitoring | Performance of the contract + legitimate interest (Art. 6.1.b / 6.1.f) | Duration of the account + 3 years after the last exchange |
3.6 Technical data, cookies and trackers
Data collected: strictly necessary cookies and trackers (session, security, CSRF protection, anti-bot protection), and, where applicable, audience measurement trackers.
| Purpose | Legal basis | Retention period |
|---|---|---|
| Operation, security, anti-bot protection | Legitimate interest / exemption (Art. 82 of the French Data Protection Act — necessary trackers) | Session duration or 13 months max |
| Audience measurement and non-essential trackers | Consent (Art. 6.1.a + Art. 82 of the French Data Protection Act) | 13 months max, see Cookie Policy |
4. Legal bases for processing
In accordance with Article 6 of the GDPR, our processing operations rely on the following legal bases:
- Performance of the contract (Art. 6.1.b) — provision of the Klarity service to the Professional: account, authentication, subscription, features, transactional emails.
- Legitimate interest (Art. 6.1.f) — security, fraud and abuse prevention, service improvement, internal statistics, commercial relationship management. This interest is balanced against your rights and freedoms; you have a right to object.
- Legal obligation (Art. 6.1.c) — retention of accounting and tax records.
- Consent (Art. 6.1.a) — commercial prospecting / marketing emails, non-essential trackers. Consent is freely given, specific, informed and withdrawable at any time, without such withdrawal affecting the lawfulness of prior processing.
5. Recipients and sub-processors
Your data is never sold. It is accessible to our authorized internal teams and to processors selected for their compliance guarantees and bound by contractual commitments (Article 28 GDPR). Each provider intervenes only within the limits of the purpose assigned to it.
To provide the service, we use the following categories of recipients and sub-processors, without this list designating any company in particular:
- Infrastructure and database host, located within the European Union;
- Payment provider (subscription and collection management), PCI-DSS certified;
- Artificial intelligence model providers (generation of summaries, briefings, RAG memory, Chat Memory);
- Capture and transcription provider for videoconference sessions;
- Emailing tool (transactional emails and, subject to consent, marketing);
- Customer relationship management (CRM) tool (processes the Professional's data);
- Technical monitoring tool and application error tracking;
- Anti-bot protection service;
- Customer support tool (support messaging widget and contact record) — processes the Professional's data (identity, contact, subscription status);
- IP address geolocation service at registration (used, when the CRM is enabled, for commercial localization and currency selection);
- Internal alerting messaging tool (internal operational / billing notifications, in production) — the Professional's name / email;
- Where applicable, third-party calendar integration service, enabled at your request.
The list of sub-processors, kept up to date and specifying the identity, location and applicable guarantees of each provider, is provided on simple request to support@klarity.coach. The named details also appear in the data processing agreement (DPA — see §2.2).
Several of these categories (notably the AI providers and the capture provider) intervene primarily on the Professional's clients' data, for which Klarity acts as a processor: their intervention then falls under the DPA (see §2.2).
Your data may also be disclosed to third parties where required by law (administrative or judicial authorities) or for the establishment, exercise or defense of legal claims.
6. Data transfers outside the European Union
Data at rest (database, file storage, secrets, backups) is hosted within the European Union, in the eu-west-3 (Paris, France) region.
Some sub-processors, in particular the artificial intelligence providers as well as certain capture / transcription, emailing, CRM, monitoring and anti-bot protection tools, are established or operate outside the European Union. The use of these categories of provider may result in a transfer of data outside the EU.
These transfers are governed by appropriate safeguards within the meaning of Articles 44 et seq. of the GDPR, notably:
- the Standard Contractual Clauses (SCCs) adopted by the European Commission;
- where applicable, the provider's certification under the EU–US Data Privacy Framework (DPF);
- additional technical and organizational supplementary measures (encryption in transit, minimization of the data transmitted, access controls).
Specific point of attention regarding AI. When the Professional uses the AI features (automatic summaries, briefings, RAG memory, Chat Memory), session content may be transmitted to the artificial intelligence model providers for processing. This content falls mostly under the Professional's responsibility (see §2.2 and the DPA). These features rely on these providers' professional APIs: for OpenAI, the API terms provide by default that models are not trained on the transmitted data; for Google Gemini, we use the paid tier of the API, whose terms exclude the use of transmitted content to train or improve the models. The Professional retains control over the activation of these features and over session capture (client consent managed via the service).
You can obtain a copy of the safeguards put in place by writing to support@klarity.coach.
7. Retention periods
The detailed periods appear in the tables in section 3. In summary:
- Account and profile data: retained for the entire duration of the contractual relationship, then deleted or anonymized within a reasonable time after account closure (indicative period of 30 to 90 days for backups).
- Billing data and accounting records: 10 years under accounting and tax obligations.
- Marketing and prospecting data: until the withdrawal of consent, or at the latest 3 years after the last contact.
- Technical and security logs: strictly necessary duration, indicatively 12 months.
- Support data: duration of the account + 3 years after the last exchange.
Upon expiry of these periods, the data is deleted or irreversibly anonymized. Data processed as a processor (the Professional's client data) follows the periods and the return / deletion arrangements provided for by the DPA.
8. Data security
Boostage implements appropriate technical and organizational measures to preserve the confidentiality, integrity and availability of the data (Article 32 GDPR):
- Hosting within the European Union (eu-west-3 (Paris, France) region) for data at rest.
- Encryption of sensitive content: sensitive content on the Professional's clients' side (notes, transcriptions, reports, briefings, memory) is encrypted at the application layer in the database (AES-256-GCM), on top of the database's encryption at rest; identity data (names, emails) is protected by encryption at rest, strict access control and partitioning by organization.
- Encryption in transit (TLS/HTTPS) for all exchanges.
- Strict access control: authentication, partitioning by organization (multi-tenant isolation — each Professional only accesses their own data), role and permission management, principle of least privilege.
- Application-level protections: rate limiting, anti-bot protection, CSRF protection, secure secrets management.
- Logging and monitoring of accesses and errors (immutable audit log for sensitive operations, technical monitoring of application errors).
- Regular backups and restoration procedures.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we undertake to notify the CNIL (the French data protection authority) within 72 hours and, where applicable, to inform you, in accordance with Articles 33 and 34 of the GDPR.
9. Your rights
In accordance with the GDPR and the French Data Protection Act, you have, over the data for which Klarity is the data controller, the following rights:
- Right of access — obtain confirmation that your data is being processed and receive a copy of it.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — obtain the deletion of your data under the conditions provided by law.
- Right to object — object to processing based on legitimate interest, or to commercial prospecting.
- Right to portability — receive your data in a structured, commonly used and machine-readable format, or have it transmitted to another controller (an export feature for the main data categories is available in the application).
- Right to restriction of processing.
- Right to withdraw your consent at any time, for the processing that depends on it (marketing, non-essential trackers), without retroactive effect.
- Right to set post-mortem directives relating to the fate of your data after your death (Article 85 of the French Data Protection Act).
How to exercise your rights
To exercise these rights, write to the GDPR representative at support@klarity.coach or by post to 200 rue de la Croix Nivert, 75015, Paris, France. We may ask you for proof of identity in the event of reasonable doubt. We respond within one month of receiving the request (extendable by two months in the event of complexity).
Important reminder. If your request concerns data relating to a Professional's clients (records, notes, transcriptions, memory), Klarity is only a processor and cannot respond to it directly: the request must be addressed to the Professional concerned, the data controller. We will assist them in accordance with the DPA.
Complaint to the CNIL
If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the French Data Protection Authority (Commission nationale de l'informatique et des libertés, CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.
10. Cookies and trackers
The website and the application may place cookies and trackers for the purposes of operation, security (session, CSRF protection, anti-bot protection), and, where applicable, audience measurement. Trackers that are not strictly necessary are only placed after obtaining your consent, in accordance with Article 82 of the French Data Protection Act.
The details of the cookies used, their purposes, their durations and how to manage your preferences appear in the Cookie Policy.
11. Third-party calendar integrations (Google and Microsoft) — Limited Use of data
Klarity offers, subject to activation by the Professional, synchronization with their external calendar in order to display their busy slots, avoid double bookings, and reflect their Klarity sessions in their calendar. These integrations are optional and are only enabled at the Professional's explicit request, after authorization through the provider's official mechanism (OAuth).
The calendar data synchronized concerns the Professional user themselves: for this data, Klarity acts as data controller (see §2.1), on the legal basis of performance of the contract (Art. 6.1.b — provision of the calendar feature).
11.1 Google Calendar (Google user data)
When the Professional connects their Google account, Klarity accesses, through the Google APIs, the following scopes, and only those:
https://www.googleapis.com/auth/calendar.readonly— reading the events of the primary calendar, to display busy slots and detect conflicts with sessions;https://www.googleapis.com/auth/calendar.events— creating, updating and deleting only the events corresponding to Klarity sessions (outbound mirror), and reading / writing the associated videoconference link.
Data concerned: event title, start and end dates and times, the event's technical identifier, and where applicable the videoconference link. This data is stored on our hosting infrastructure located within the European Union (see §8), in the form of busy blocks.
Strictly limited use (Limited Use). The Google user data obtained through these APIs is used solely to provide and improve the user-facing calendar features described above for the Professional. In particular:
- it is never sold, nor used for advertising or targeting purposes;
- it is not transmitted to the artificial intelligence model providers, nor used to train or improve AI or machine-learning models;
- it is not disclosed, shared or transferred to any third party, with the sole exception of our infrastructure and database host (located within the European Union), which stores it on our behalf as a processor — and except where required by law or for the establishment, exercise or defense of legal claims;
- it is not read by any human, except with the Professional's explicit consent, for security purposes (for example investigating an abuse), to comply with a legal obligation, or where it has been irreversibly aggregated and anonymized for internal operations.
Klarity's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
11.2 Microsoft Outlook / Microsoft 365 (Microsoft Graph)
When this integration is enabled, Klarity accesses, through Microsoft Graph and after the Professional's OAuth authorization, their Outlook / Microsoft 365 calendar under the following scopes, and only those:
Calendars.Read— reading events, to display busy slots and detect conflicts;Calendars.ReadWrite— creating, updating and deleting only the events corresponding to Klarity sessions.
The data concerned and the strictly limited use are identical to those described in §11.1 for Google: the same categories (title, times, identifier, videoconference link), the same storage within the European Union, and the same prohibitions — no sale, no advertising purpose, no training of AI models, no disclosure to any third party other than our host, no human reading outside the exceptions above. The use and transfer of this data complies with the Microsoft APIs Terms of Use and Microsoft's requirements regarding the use of user data, which is used only to provide or improve the feature requested by the Professional.
11.3 Revocation and deletion
The Professional can disconnect a calendar integration at any time from the application's settings, or revoke access directly from their Google or Microsoft account. Upon disconnection, the access tokens are revoked and deleted, the Klarity events reflected in the Professional's calendar are removed, and the imported external events are erased from our systems. This data otherwise follows the general retention periods described in §7.
12. Changes to this policy
This Privacy Policy may be updated to reflect changes in the service, our sub-processors or regulations. Any substantial change will be communicated to you by email after it takes effect. The applicable version is the one published at https://klarity.coach on the date you consult it.
