Legal information
Security & privacy
Last updated:
Your clients trust you with their most personal matters. Klarity is built so that this bond of trust stays yours. This page explains, in concrete terms, where your data lives, how it is protected, and what we never do with it.
This is general information. For the contractual commitment, see our Privacy Policy. The Data Processing Agreement (DPA) and the list of sub-processors are provided on simple request to support@klarity.coach.
The essentials, in three points
- Hosted in France (EU). All your data at rest is hosted in the eu-west-3 (Paris, France) region. It does not leave the European Union to be stored.
- Sensitive content is encrypted. The sensitive content of your sessions — notes, transcripts, reports, memory, briefings — is encrypted at the application layer in the database (AES-256-GCM), on top of the database's at-rest encryption. Identity data (names, emails) is protected by the database's at-rest encryption, strict access control and per-organisation isolation. All exchanges are encrypted in transit (TLS/HTTPS).
- Your content never trains an AI model. Summaries, briefings and the RAG memory are generated through APIs whose terms provide that the content sent is not used to train the providers' foundation models.
What Klarity is
Klarity is a web application (https://app.klarity.coach) for the independent coach. It captures and prepares your sessions, builds a longitudinal per-client memory (the "RAG memory"), and assists you before and after each session. Two categories of data coexist, and we handle them differently:
- Your account data (identity, email, billing) — you are responsible for it.
- Your clients' data (records, sessions, transcripts, notes, summaries) — you are the data controller; Klarity acts as a processor on your behalf, governed by the DPA.
Where your data lives
The entire application infrastructure and database are hosted within the European Union, in the eu-west-3 (Paris, France) region. Data at rest — client records, sessions, RAG memory, imported files — stays in the European Union.
Some features rely on providers established outside the EU (AI models, capture/transcription, email). The corresponding transfers are governed by the European Commission's Standard Contractual Clauses (SCCs), supplemented by technical measures (encryption in transit, data minimisation). The provider-by-provider detail is provided on simple request to support@klarity.coach.
Encryption
- Application-layer content encryption: the sensitive content of your sessions (coach internal notes, session notes and enrichments, transcripts, summaries, briefings, RAG memory, Memory Chat messages, objectives, engagements, tasks) is encrypted at the application layer in the database (AES-256-GCM), on top of the database's at-rest encryption.
- Identity data: your clients' identity data (names, emails, phone) is not subject to this application-layer encryption; it is protected by the database's at-rest encryption, strict access control and per-organisation isolation.
- In transit: every exchange between your browser, the application and our providers goes over TLS/HTTPS.
- Secrets: access keys to third-party services are stored in a dedicated secrets manager, never in the code.
- Passwords: account passwords are hashed (bcrypt) and are never stored in cleartext.
Artificial intelligence & your data
This is the heart of Klarity, and therefore the heart of our commitment:
- The AI features (post-session summaries, briefings, RAG memory, Memory Chat) send session content to model providers through their API.
- Under the terms of those APIs, this content is not used to train the providers' foundation models.
- You keep control over enabling these features and over session capture.
- Video capture is subject to the consent of the person being coached, managed directly in the product.
Consent of the people being coached
Klarity handles your clients' consent: a session is only captured with the agreement of the person concerned, and that consent can be withdrawn. As the professional, you remain your clients' point of contact for exercising their rights — which mirrors our role as a processor described in the DPA.
You stay in control
- Export: you can request an export of your data at any time.
- Deletion: you can erase a client record, a session, or your entire account. Deletion removes the associated data, including the corresponding RAG memory.
- Limited retention: we keep your data only as long as necessary for the purposes described in the Privacy Policy; technical and security logs have a short lifetime.
- Never sold: your data and your clients' data are never sold or shared for advertising purposes.
Isolation and access
- Per-account isolation: each coach has a logically isolated space; queries are filtered by organisation identifier, so an account only ever reaches its own data.
- Restricted internal access: only authorised members of our team can access the systems, strictly limited to what operations and support require.
- Audit log: sensitive operations are recorded in an immutable audit log.
- Anti-abuse protection: rate limiting, anti-bot protection and cross-site request forgery (CSRF) protection guard access.
- Monitoring: application errors are monitored so incidents are detected and fixed quickly.
Frequently asked questions
Do my clients know they are being recorded? Yes. Capture is subject to their consent, collected and traceable in the product, and revocable at any time.
Do you, or the AI, "learn" from my sessions? No. Content sent to AI models goes through APIs whose terms exclude training foundation models on that content. Nor do we use your content to train a model of our own.
Can my data leave the European Union? Storage at rest stays in the EU (eu-west-3 (Paris, France)). Some processing (AI, transcription, email) involves providers outside the EU, governed by Standard Contractual Clauses. The list is public.
What happens if I cancel? You can export your data before leaving, then request its deletion. Deleting the account removes the associated data, including the RAG memory.
Who is responsible for my clients' data? You are. Klarity acts as a processor on your behalf, under the DPA (Article 28 GDPR).
Report a vulnerability
Security is ongoing work. If you believe you have found a vulnerability, write to us at support@klarity.coach — we review every report and get back to you.
Related documents
For any data protection question: support@klarity.coach — Boostage, 200 rue de la Croix Nivert, 75015, Paris, France.
