klate
Legal

Privacy Notice

As at: 8 October 2026 · Version 2.12

DeutschEnglish

Convenience translation. This English version is a non-binding convenience translation provided for your convenience only. The legally binding version of this document is the German original, Datenschutzerklärung. In the event of any discrepancy or dispute, the German version prevails.

This privacy notice informs you, pursuant to Art. 12 to 14 of the General Data Protection Regulation (GDPR), which personal data we process, for which purposes, on which legal basis, to whom we disclose it, how long we store it and which rights you have.


Contents

Part A: General

  1. About this privacy notice
  2. Controller and contact
  3. Who this privacy notice is addressed to
  4. Our role: controller or processor
  5. Legal bases at a glance

Part B: Websites and public offerings

  1. Accessing our websites, and server log files
  2. Cookies and access to your terminal equipment
  3. Measurement of loading performance (Vercel Speed Insights)
  4. Contacting us and legal declarations
  5. Status page and further domains
  6. What we do not use

Part C: The application (signed-in use)

  1. Registration, account and sign-in
  2. Profile details
  3. Workspaces, teams, seats and invitations
  4. Shares, share links and collaboration
  5. Content you create in Klate
  6. Uploaded files and media
  7. Comments, mentions and notifications
  8. Approvals (sign-off procedure)
  9. Logging and audit log
  10. AI features
  11. AI memory
  12. Setup assistant on first start
  13. MCP interface and access by AI agents
  14. Billing, payments and credit
  15. Transactional emails
  16. Feedback from within the application
  17. Operational, error and performance telemetry
  18. Third-party content loaded within the application
  19. Access to your data on our side

Part D: People whose data our customers enter

  1. Who is responsible for your data
  2. How we handle this data

Part E: Cross-cutting topics

  1. Recipients and sub-processors
  2. Transfers to third countries
  3. Storage period and erasure
  4. Data security
  5. Your rights
  6. Right to object
  7. Right to lodge a complaint with a supervisory authority
  8. No automated decision-making in individual cases
  9. Whether you are required to provide your data
  10. Processing for a different purpose
  11. Minors
  12. Changes to this privacy notice

Part A: General

1. About this privacy notice

1.1 Which offerings it applies to

This privacy notice applies to all of the following offerings of Klate Technology UG (haftungsbeschränkt) (hereinafter "Klate", "we" or "us"):

OfferingAddressShort description
Websiteklate.aiOur public website with product and pricing information
Applicationapp.klate.aiThe Klate product, usable after registration
Internal documentationdocs.klate.aiInternal development documentation; not a public offering, accessible only after signing in with the provider (Section 10)
Status pagestatus.klate.aiPublic availability display
MCP interfaceapp.klate.aiProgrammatic access for AI agents (Section 24)
Redirectsklate.io, getklate.comPure redirects to klate.ai

Klate is a tool for conversation design: professionals use it to design the conversational flow of an AI assistant before that assistant is built. Klate itself does not conduct conversations with your end customers; the dialogues created in Klate are drafts and examples, not systems running in live operation.

1.2 How to read this notice

This notice is structured by audience. Please read Part A and Part E (they apply to everyone), and in addition the part that applies to you:

  • You only visit our website? → Part B
  • You have a Klate account or are a member of a team? → Part B and Part C
  • Your data was entered into Klate by one of our customers? → Part D

1.3 Relationship to other documents

This privacy notice is separate from our Impressum (site notice) under § 5 DDG and does not replace it. For the processing of content that our customers enter into Klate, the Auftragsverarbeitungsvertrag (data processing agreement) concluded with the respective customer applies in addition (Section 4). Our current sub-processor list forms part of Section 33.


2. Controller and contact

2.1 Controller

The controller (Verantwortlicher) within the meaning of Art. 4(7) GDPR is:

Klate Technology UG (haftungsbeschränkt) Im Galluspark 4 60326 Frankfurt am Main Germany

Represented by the Geschäftsführer (managing director): Arian Fetahaj

Email: privacy@klate.ai

Entered in the Handelsregister (commercial register) of the Amtsgericht (Local Court) Frankfurt am Main under HRB 145040.

2.2 Contact for data protection matters

For all questions concerning data protection and for exercising your rights under Section 37, you can reach us at:

privacy@klate.ai

or by post at the address given above, marked "Datenschutz"

2.3 Data protection officer

We have not appointed a data protection officer. There is no obligation to appoint one: we do not, as a rule, have at least 20 persons permanently engaged in the automated processing of personal data (§ 38 Abs. 1 Satz 1 BDSG), we do not carry out any processing that is subject to a data protection impact assessment under Art. 35 GDPR, and we process personal data neither commercially (geschäftsmäßig) for the purpose of transfer, nor for the purpose of anonymised transfer or of market or opinion research (§ 38 Abs. 1 Satz 2 BDSG).

Your point of contact for data protection questions is therefore directly the controller at privacy@klate.ai.

2.4 Representative in the Union

A representative under Art. 27 GDPR does not have to be designated, because our seat is in Germany and thus in the Union.


3. Who this privacy notice is addressed to

We process personal data of the following groups of persons:

a) Visitors to our websites. Persons who access klate.ai or status.klate.ai without signing in; likewise persons who access docs.klate.ai, even if, lacking access authorisation, they are merely redirected there to the provider's sign-in page (Section 10).

b) Account holders and team members. Persons who hold a Klate account or who have been added as a member of a workspace.

c) Invited persons and approvers. Persons whose email address has been provided by a Klate user in order to invite them into a workspace (Section 14) or to ask them to approve a draft (Section 19). These persons did not give us their data themselves; for them, the information under Art. 14 GDPR in Sections 14, 15 and 19.4 applies in addition.

d) Persons whose data our customers enter into Klate. Part D applies to this group.

e) Persons who write to us. Prospective customers, applicants and everyone who contacts us by email (Section 9).


4. Our role: controller or processor

The role in which we process data depends on which data is concerned. This distinction matters because it determines whom you should address with your rights.

4.1 We as controller

We are the controller (Verantwortlicher) within the meaning of Art. 4(7) GDPR for all data that we process in order to provide and operate our own service. This is in particular:

  • your account and profile data (Sections 12 and 13),
  • usage, billing and log data (Sections 20, 25 and 28),
  • data of website visitors (Part B),
  • your communication with us (Sections 9 and 27).

For this data, this privacy notice is the authoritative information, and you exercise your rights under Section 37 directly vis-a-vis us.

4.2 We as processor

We are the processor (Auftragsverarbeiter) under Art. 4(8), Art. 28 GDPR for the content that you as a customer enter, upload or cause to be generated in Klate, that is, for your conversation designs, briefs, guideline cards, tool and widget definitions, comments and uploaded files.

You alone decide about this content. We process it only on your instructions and do not pursue any purposes of our own in doing so. In particular, we do not analyse your content in order to build profiles from it, and we do not use it to train AI models (Section 21.6).

Exception. Within narrow limits we also process data arising in connection with your content as controller, and thus for our own purposes: for our audit log (Section 20), for billing and abuse detection in relation to AI requests (Section 21.8) as well as for the security and availability of our service (Sections 6 and 36). What is processed in this respect is transaction and consumption data, not the content of your designs.

The basis of this processing is an Auftragsverarbeitungsvertrag (AVV) (data processing agreement) under Art. 28(3) GDPR. It applies to any business use of Klate and comes into existence upon registration of your account; you do not need to request it separately. The full text including the sub-processor list can be found at https://klate.ai/legal/dpa; we will provide you with a signed counterpart on request at privacy@klate.ai.

4.3 What this means for you as a customer

Klate is designed for drafting conversation flows with invented sample data, that is, with made-up names, order numbers and scenarios. We expressly recommend not entering any real personal data of third parties into designs where this is not necessary for the drafting purpose.

To the extent that you nevertheless enter real personal data, you are the controller for it. You must ensure that there is a legal basis for that processing and that you have informed the data subjects in accordance with Art. 13 and 14 GDPR.


We process personal data only where there is a legal basis for doing so. In this notice we state the specifically applicable basis for each processing operation. The following may apply:

Permission provision (Erlaubnistatbestand) / legal basisWhen we rely on it
Art. 6(1)(a) GDPR, consentOnly where we expressly ask you for your consent: for the technical details accompanying a piece of feedback (Section 27), for the AI memory including the associated automatic analysis of your messages and their transmission to our model provider in the USA (Section 22), and for connecting an AI agent via MCP (Section 24).
Art. 6(1)(b) GDPR, contract and pre-contractual measuresFor everything that is necessary in order to provide the service: account, workspaces, content, AI features, billing, transactional emails.
Art. 6(1)(c) GDPR, legal obligationFor the retention of billing-relevant records under § 147 AO, § 257 HGB and § 14b UStG (Section 25) as well as for the legally mandated termination and withdrawal function including the acknowledgement of receipt under § 312k and § 356a BGB (Section 9.2).
Art. 6(1)(f) GDPR, legitimate interestsFor operational security, abuse prevention, error diagnosis, performance measurement, the audit log and the time your account was last used (Section 12). We state the respective legitimate interest specifically for each individual processing operation.
§ 25 Abs. 2 Nr. 2 TDDDG, permission provision for access to your terminal equipment (not a legal basis under Art. 6 GDPR)For the storage of information on your terminal equipment, or access to it, to the extent that this is strictly necessary for the provision of the service expressly requested by you (Sections 7 and 8). For the subsequent processing of the data so collected, one of the above GDPR legal bases applies in addition in each case.

To the extent that we rely on Art. 6(1)(f) GDPR, we have in each case examined whether your interests or fundamental rights override ours. We will inform you of the outcome of that balancing exercise on request at privacy@klate.ai. We draw your attention separately to your right to object in these cases in Section 38.


Part B: Websites and public offerings

6. Accessing our websites, and server log files

Purpose. When you access klate.ai or app.klate.ai, your browser transmits technically necessary data to our hosting provider so that the page can be delivered. This data arises with every retrieval of a website and cannot be avoided.

Data processed. IP address, date and time of the request, the address and method requested, HTTP status code, volume of data transferred, referrer address, browser and operating system identifier (user agent) as well as the processing data centre location.

Our application's log lines. In addition, our application writes its own log lines into the server log files of our hosting provider. For requests to the application these are a request identifier, the method, path, status code and response time and, once your sign-in has been checked, your internal account ID. For every answer of the AI assistant we also write the identifiers of the conversation and of the answer, the model used and the costs calculated. For errors and for background operations (for example payments, email sending, exports and deletion runs) internal identifiers of the records concerned are added, for example your account ID or the ID of your workspace or of an order, as well as the identifiers our payment service provider assigns to the customer, subscription, invoice and payment, amounts and plan details of a payment operation, error codes and technical error messages. In rare cases, technical error messages may contain fragments of the data being processed.

Recipients. Vercel Inc. as our hosting provider (Section 33). Our application is run in the Frankfurt am Main (fra1) region. Name resolution for our domains takes place via Cloudflare, Inc.; DNS query data arises there in the process. Protection against overload attacks on the application is provided by the network protection functions of our hosting provider. Only when public media is retrieved via media.klate.ai and when an uploaded file is retrieved from the object storage (Section 17) does your browser establish the connection directly with Cloudflare; in that case Cloudflare additionally receives your IP address and your browser identifier.

Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest consists in making our offerings technically available, ensuring their stability and security, investigating errors and malfunctions and warding off attacks.

Storage period. According to our hosting provider, server log files are kept for up to 30 days; after that they can no longer be retrieved by us either. We do not store them separately. We use them solely for error diagnosis, for safeguarding stability and performance, for warding off attacks and for investigating malfunctions, including malfunctions in billing, and we do not create usage profiles from them.

Protection against misuse and limitation of the request load. In order to ward off automated attacks we use the network protection functions of our hosting provider; in addition, we count the requests per source within the application itself and temporarily reject them if limit values are exceeded.

For this counting we store counter values which, for non-signed-in access, contain the IP address, in particular when an approval link is accessed (Section 19) and for non-signed-in requests to the MCP interface (Section 24). These counter values are removed by a nightly clean-up run as soon as they have not been used for 24 hours; since the run takes place once per night, an IP address therefore remains stored for up to about 48 hours after the last request from that address. If requests continue to be made from the same address, storage is extended accordingly. These counter values are not analysed for any other purposes.

Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest is the warding off of attacks, the prevention of misuse and the maintenance of the availability of the service for all users.

Country-based price display on klate.ai. So that you see prices on our website in the currency relevant to you, our hosting provider determines from your IP address, when the page is accessed, the country from which you are accessing it, and communicates to our application only the result "United States" or "not United States". We then display US dollar or euro prices. We do not receive your IP address itself in this process; we store neither the country nor the result, we do not place anything on your terminal equipment and we do not combine this information with other data. The legal basis is Art. 6(1)(f) GDPR with the legitimate interest of displaying to you, from the outset, the prices that apply to you.


7. Cookies and access to your terminal equipment

7.1 Our website does not set any cookies

On our website klate.ai we set no cookies whatsoever and do not access information stored on your terminal equipment. There is therefore also no consent banner on klate.ai; it would be without purpose.

7.2 Cookies in the application

In the application app.klate.ai we set the following cookies. All of them are strictly necessary for the service to work. We set no cookies for advertising, tracking or reach analysis purposes.

CookiePurposePropertiesStorage period
__Secure-neon-auth.session_tokenThe actual sign-in cookie. It keeps you signed in and identifies your session. Without this cookie, signed-in use is technically impossible.HttpOnly, Secure, Path=/; set and managed by our authentication serviceDuration of the session as specified by the authentication service
__Secure-neon-auth.local.session_dataCache of the session details as a signed JSON Web Token, so that the authentication service does not have to be queried on every page view.HttpOnly, Secure, Path=/, signed5 minutes, at most until the session expires
__Host-cd_active_ws (in the development environment: cd_active_ws)Remembers which workspace you last selected, so that you can continue working there after a reload.HttpOnly, SameSite=Lax, Secure, Path=/, without a Domain attribute180 days
__Host-klate-locale (in the development environment: klate-locale)Remembers the language of the interface that you chose, so that the application appears in that language after a reload.HttpOnly, SameSite=Lax, Secure, Path=/, without a Domain attribute180 days

The cookie __Host-cd_active_ws contains no access authorisation. It stores only an identifier of the workspace last selected; on every access we check anew, on the server side, whether you are in fact a member of that workspace. A manipulated value can therefore not give you access to other people's data.

We set the cookie __Host-klate-locale only when you choose the language of the interface yourself (in the application, or through a language link that carries a language code in the address), or when, after you sign in, we restore the choice that you saved in your account (Section 13). We do not set it for visitors who have not chosen a language; the application then follows the language of your browser. It contains only the language code (for example de) and no access authorisation; we ignore an unknown or manipulated value because we check it against the list of offered languages on every request. On klate.ai we still set no cookie for this: there the language is in the address of the page (Section 7.1).

Legal basis. § 25 Abs. 2 Nr. 2 TDDDG for the storage of the information on your terminal equipment and for access to it: these cookies are strictly necessary in order for us to provide the service expressly requested by you. For the subsequent processing of the data so collected: Art. 6(1)(b) GDPR.

7.3 Further storage on your terminal equipment

In the application we additionally store information in the local storage (localStorage) of your browser:

  • Interface settings, your choice between a light and a dark appearance, the AI model last selected or preset, the width, position and state of the side areas, of the toolbar and of the sidebar (which entries are expanded or collapsed), the zoom level of the canvas, your display options and the colours last used as well as, for as long as you restrict the sidebar to a single customer ("Sensibler Modus", in the English version "Sensitive mode", for example for screen sharing), the identifier of that customer.
  • Notice of changes to the project brief, per design the state of the project brief you last saw, so that we can point out to you a change saved since then.
  • Intermediate states of your editing, changes to a design that have not yet been saved are held locally for a short time so that your work is not lost in the event of a connection failure or an accidental closing of the window. Changes to the project brief and to the guideline cards of a project that have not yet been saved remain stored locally until you save or discard them. These intermediate states may therefore contain the same content as the design, the project brief or the guideline cards themselves.
  • Identifier of your account, we store the identifier of the account last signed in so that, on a shared device, all of the local information mentioned above, with the exception of the choice of appearance, is deleted automatically as soon as a different account signs in. The identifier is not transmitted to us and serves this protective purpose alone.
  • Synchronisation of the sign-in state between several browser tabs, our authentication service stores a short message under the key better-auth.message so that all open tabs use the same sign-in status. This message contains merely the statement that the session state has changed, the trigger, a random identifier and a timestamp, neither your session token nor your name or your email address. The entry remains on your device until you delete the site data in your browser.

In addition, we store in the session storage (sessionStorage) of your browser, per customer and project, the identifier of the conversation with the AI assistant that you last had open there (key cd:gi:thread:…), so that you can continue in the same conversation after reloading the page. The entry contains no content of the conversation. Session storage is bound to the individual browser tab; the browser discards it when you close the tab.

This information remains on your device and is not separately transmitted to us; the intermediate states do not replace storage on our servers but safeguard it. The legal basis is § 25 Abs. 2 Nr. 2 TDDDG: the storage is strictly necessary in order to provide you with the service with the resilience you expect. You can delete this data at any time via the settings of your browser.

Bot check on the registration page (Cloudflare Turnstile). On the registration page app.klate.ai/auth/sign-up, and only there, we embed the bot protection Turnstile of Cloudflare, Inc. (Section 12). It is loaded as an embedded frame (iframe) from challenges.cloudflare.com. We ourselves set no cookie for it and store nothing in local storage; the one-time token generated by the check service is transmitted only together with your registration. We have not enabled the "pre-clearance" function, under which Cloudflare would set a cf_clearance cookie. Whether Cloudflare's embedded frame for its part stores information on your terminal equipment in the storage area of its own domain is something we have not yet conclusively verified; we will complete that verification and supplement this notice should that be the case. We consider the check strictly necessary in order to protect the service you have requested, the creation of an account, against automated mass registrations (§ 25 Abs. 2 Nr. 2 TDDDG).

Since we use neither advertising nor tracking technologies and since all of the storage operations mentioned above are strictly necessary, we do not require consent for them under § 25 Abs. 1 TDDDG. Should we use consent-requiring technologies in future, we will obtain your consent beforehand via a consent banner and will update this notice.


8. Measurement of loading performance (Vercel Speed Insights)

Purpose. In the application app.klate.ai, not on the website klate.ai, we measure how quickly pages actually load for you. For this we use "Speed Insights" of our hosting provider Vercel. Without this measurement we would not be able to detect performance problems that occur only with certain devices, networks or pages.

Data processed. What is recorded is the route and address accessed, the measured web vital value and its attribution, the estimated network speed, browser, device type and operating system, the country according to ISO 3166-1 alpha-2 as well as the time of arrival at the server. The measurement runs throughout the entire application, that is, also on the sign-in pages and thus already before you sign in.

What expressly does not happen. Speed Insights sets no cookie and places no data on your terminal equipment. No visitor identifier and no session ID is assigned. According to the provider's information, the measured values are designed in such a way that they cannot be attributed either to an individual visitor or to an IP address and that a page history cannot be reconstructed. No cross-site tracking takes place.

Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest consists in monitoring the loading speed and stability of our application and in remedying performance problems in a targeted manner.

Access to your terminal equipment. For the measurement, our measurement script reads properties of your device, in particular an estimate of your connection speed, device type, browser and operating system. We base this access on § 25 Abs. 2 Nr. 2 TDDDG: it is strictly necessary in order to provide you with the service expressly requested by you in the promised quality, because without this measurement we would not be able to tell whether our application reaches your device and your network without errors and quickly. The measurement sets no cookie and places no data on your terminal equipment; it assigns no visitor identifier and allows no recognition across page views. For the subsequent processing of the data so collected, Art. 6(1)(f) GDPR is the legal basis.

Objection. You may object to this processing under Art. 21(1) GDPR; see Section 38.

Recipients, place of processing and storage period. Vercel Inc. as processor (Section 33). The measured values are processed by Vercel in the United States; the provider does not offer EU data residency for this measurement. On the transfer to a third country, see Section 34.2. The measured values are kept there for 30 days and are then deleted.


9.1 Contacting us by email

Purpose. If you write to us, for example to privacy@klate.ai or support@klate.ai, we process your message in order to answer it.

Data processed. Your email address, your name insofar as given, the content of your message as well as the technical header data of the email.

Recipients. Our mailboxes at @klate.ai are operated via Google Workspace (Google Ireland Limited); the provider processes the message content as a processor (Section 33).

Legal basis. Art. 6(1)(b) GDPR where your enquiry serves the initiation or performance of a contract; otherwise Art. 6(1)(f) GDPR with the legitimate interest of answering enquiries and keeping the correspondence traceable.

Storage period. We delete your enquiry as soon as it has been conclusively dealt with and no retention obligations stand in the way. Business letters within the meaning of commercial and tax law are retained by us for the statutory periods.

Note on job applications. Application documents that you send to us unsolicited or in response to a job posting are processed by us exclusively for the purpose of conducting the application procedure. The legal basis is Art. 6(1)(b) GDPR (performance of pre-contractual measures at your request), supplemented by § 26 Abs. 1 Satz 1 in Verbindung mit Abs. 8 Satz 2 BDSG. We delete them no later than six months after conclusion of the procedure, unless you have agreed to longer retention.

9.2 Termination and withdrawal function

Purpose. At app.klate.ai/kuendigen we provide the termination function under § 312k BGB, and at app.klate.ai/widerruf the withdrawal function under § 356a BGB. Via these pages you can terminate a paid plan or, as a consumer, withdraw from it. Both pages are accessible without signing in and without an account, because that is precisely what the law requires. We process your details in order to receive your declaration, to confirm its receipt (Zugang) to you and to implement it.

Data processed. Your name, your email address, an address given voluntarily, the details of the contract concerned as well as, in the case of a termination, its type, the desired end date and, in the case of an extraordinary termination, the reason stated by you. In addition we record the date and time of receipt, because both provisions expressly require this. We compare your email address once against our customer records in order to be able to attribute the contract. If no account is found, your declaration nevertheless remains effective and stored.

No cookies, no reach measurement. Both pages set no cookies and store nothing on your terminal equipment (Section 7). We use your IP address exclusively in order to limit the number of submissions per minute and thus to ward off abusive mass use; it is not stored together with your declaration.

Limitation of the acknowledgements of receipt. So that the functions cannot be misused to flood other people's mailboxes with confirmation emails, we send at most three acknowledgements of receipt per hour to the same email address and at most 500 per day in total. For this count we do not store your email address but a hash value (SHA-256) of the lower-cased address; like the other counters (Section 6), the count is removed by the nightly clean-up run once it has not been used for 24 hours. If one of these limits has been reached, your declaration is nevertheless received, stored with its date and time and effective, and the confirmation page shows you its content to save and print. Only the confirmation email is then not sent automatically; it is marked to be sent on by hand. If the count cannot be carried out because of a technical fault, we send the confirmation nonetheless. The legal basis for this count is Art. 6(1)(f) GDPR; our legitimate interest is warding off this misuse.

Recipients. We send the acknowledgement of receipt via our dispatch service provider (Section 26); if it cannot be delivered straight away, we automatically try again (Section 26). The declaration itself is stored by us in our database (Section 33). So that your declaration is acted on, we notify the people who process it at our end by email, through the same dispatch service provider, to our mailbox (Section 9.1). This internal message names only the reference number, the type of declaration, the time it was received and whether the acknowledgement of receipt could be sent to you, not your name, your email address or your postal address.

Legal basis. Art. 6(1)(c) GDPR: providing both functions and confirming receipt of your declaration is prescribed for us by law under § 312k Abs. 2 und Abs. 4 BGB and § 356a BGB. For the implementation of your declaration within the contractual relationship, Art. 6(1)(b) GDPR applies in addition.

Storage period. See Section 35.1. Your declaration is a received commercial letter (§ 257 Abs. 1 Nr. 2 HGB, § 147 AO) and at the same time your proof that you have ended the contract. We therefore do not delete it, neither automatically nor upon a request for erasure under Section 37 (Art. 17(3)(b) and (e) GDPR). Your right of access remains unaffected by this: on request we will provide you with the declaration in full.


10. Status page and further domains

Status page. At status.klate.ai we display the availability of our service; the page can be used without signing in. It is operated by Better Stack, s. r. o. (Czech Republic). When it is accessed, server log files with the connection data listed in Section 6 under "Data processed" arise at that provider; our application's log lines do not arise there.

Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest consists in delivering the status page technically, securing its stability and warding off attacks on it; without the processing of the connection data, accessing the page is technically impossible.

Storage period. The server log files arise at the provider and are deleted there in accordance with its specifications. We do not retrieve them, do not analyse them and do not combine them with other data.

Internal documentation domain. At docs.klate.ai our internal development documentation is located; accessing it leads to the sign-in page of Mintlify, Inc., 1 Post St, STE 1800, San Francisco, CA 94104, USA, and the only person authorised to access it is our Geschäftsführer (managing director). Because the domain is publicly resolvable, the connection data of every access nevertheless arises at Mintlify, Inc. in the USA; the legal basis and storage period correspond to the above statements on the status page; on the transfer to a third country, see Section 34.2.

Redirect domains. The domains klate.io and getklate.com are registered with Porkbun LLC (USA) and redirect to klate.ai via its redirect service. If you access one of these domains, connection data including your IP address arises briefly at Porkbun LLC in the USA; see Section 34.


11. What we do not use

The following statements apply to klate.ai and app.klate.ai; for the status page status.klate.ai and the documentation domain docs.klate.ai, Section 10 applies. As at the date of this notice, the following applies:

  • We use no advertising networks, no tracking pixels, no tag manager and no retargeting technologies.
  • We operate no reach analysis for marketing purposes and create no user profiles. In particular we use no Google Analytics, no Google Tag Manager, no Google Ads conversion tracking, no Meta pixel and no LinkedIn Insight Tag. For technical performance measurement we collect the measured values described in Sections 8 and 28; these serve exclusively for operations.
  • We send no newsletter and no advertising emails. All emails that we send are transactional (Section 26).
  • We embed no social media plugins and no external video players.
  • We use no CAPTCHA of a third-party provider, with one exception: on the registration page app.klate.ai/auth/sign-up we use the bot protection Cloudflare Turnstile to protect against automated mass registrations (Sections 7.3, 12 and 29). It is not loaded on klate.ai or on any other page of the application.
  • We use no fonts that are loaded at runtime from an external server. The font "Geist" used by us is downloaded already when the application is built and is delivered by our own server. When our pages are accessed, no connection to Google Fonts is therefore established and no IP address is transmitted to Google.
  • We carry out no session recording ("session replay") and no automatic recording of your screen contents.

Should we use one of these methods in future, we will inform you beforehand at this point and will, to the extent necessary, obtain your consent.


Part C: The application (signed-in use)

12. Registration, account and sign-in

Purpose. In order to use Klate you need an account. We process your sign-in data in order to authenticate you, to attribute your workspaces to you and to protect your account against unauthorised access.

Data processed.

DataOrigin
Name, email address, password, confirmation status of the email address, profile picture where applicableprovided by you at registration
Time of creation and of the last change to the accountautomatically
Time and version ("Stand") of the terms of use you accepted, and whether you accepted them at registration or within the applicationautomatically when the mandatory box in the registration form is ticked, or when you accept within the application
Session data: session identifier, expiry time, IP address and user agent of the sessionautomatically upon sign-in
Time of last use: date and time of the first use of your account on the calendar day on which it was last usedautomatically when you use the application signed in or when an AI agent you connected accesses it on your behalf
One-time passwords for confirming the email address and for resetting the passwordautomatically

Sign-in procedure. Signing in currently takes place exclusively with email address and password. Signing in via third-party providers such as Google or Microsoft is currently not set up.

Passwords. When you sign in, your password travels encrypted to our server, which passes it on to our authentication service; it is stored exclusively as a cryptographic hash. If you change your password, we sign out all other sessions.

Confirmation of the email address. At registration we send you a confirmation code to the address provided. Without confirmation, the account is not activated. Once your account is activated, we send you a one-time confirmation of your registration with the withdrawal notice and the terms of use (Section 26).

Terms of use. At registration you confirm, by means of a mandatory box that is not pre-ticked, that you have read and accept our terms of use. For this purpose we store the time and the version of the terms of use accepted, in order to be able to prove their incorporation (legal basis: Art. 6(1)(f) GDPR, legitimate interest in proving the conclusion of the contract, § 305 Abs. 2 BGB). If we change the terms of use in a way that requires your acceptance (clause 14.3 of the terms of use), or if we do not yet hold an acceptance from you, we ask for your acceptance within the application by way of a notice. If you accept there, we likewise store the time and the version as well as the fact that you accepted through this request; the legal basis and the storage period are the same. The request does not restrict your use. If you close it with "Not now", we store nothing, not on your device either, and ask again the next time the application is loaded. This privacy notice itself is information under Art. 13 GDPR and is not "accepted"; we do not require any consent or tick box for it.

Protection against misuse at registration. When an account is created, we compare the domain part of your email address against a list of known providers of disposable addresses and reject the registration where appropriate. The check takes place at the moment at which our authentication service triggers the creation of the account; in doing so we process the domain part alone, and exclusively in main memory. If a registration is rejected, our server log records exclusively the domain of the rejected address, not the full address; it is kept for up to 30 days under Section 6. No assessment of your person and no disclosure takes place. In addition, our authentication service limits the number of sign-in and registration attempts per source address. The legal basis is Art. 6(1)(f) GDPR with the legitimate interest of preventing automated mass registrations and attacks on accounts.

Bot check (Cloudflare Turnstile). Before a registration is passed on to our authentication service, your browser must pass a check by the Turnstile service of Cloudflare, Inc. (USA), which distinguishes automated registrations from human ones. The check service is loaded on the registration page only (Section 29) and as a rule runs without any action on your part; only where Cloudflare has doubts is a box displayed for you to tick. According to Cloudflare's own information, Cloudflare receives in the process your IP address, technical characteristics of your encrypted connection (TLS fingerprint), your browser identifier (user agent) as well as the identifier of our check widget and the calling domain. The check produces a one-time token valid for five minutes, which your browser sends to us with the registration; our server has it confirmed by Cloudflare and in doing so transmits exclusively the token and our access key, not your IP address and nothing from the registration form. Without a confirmed token we reject the registration without your details reaching the authentication service; if the check service cannot be reached, registration is temporarily not possible. Cloudflare processes the signals for us as a processor (Section 33.1) and, according to its own information, at the same time under its own responsibility in order to improve Turnstile (Section 33.2). The legal basis is Art. 6(1)(f) GDPR with the legitimate interest of preventing automated mass registrations; on the transfer to the USA, see Section 34.2.

Time of last use. Under Clause 11.1 of the General Terms and Conditions (AGB) we may end the contract on the free plan if no one has signed in to the account for twelve months; we give at least 30 days' notice of this, and if you sign in within those 30 days the contract remains in place. In order to be able to establish and prove whether this condition is met, we store a single point in time for each account: the first use on the calendar day (in Coordinated Universal Time, UTC) on which the account was last used. Every request to the application with a valid sign-in counts as use, including a request that an open page of the application makes on its own, for example to fetch new notifications, as does an access by an AI agent you connected via the MCP interface as described in Section 24. The value is overwritten at most once a day. We do not store a history of your use, and we do not build a usage profile from it. We record it for every account regardless of plan, because an account can change its plan. It is not visible to other members of your workspaces; you receive it with an access request under Section 37. We have not currently set up a procedure that ends contracts under Clause 11.1 of the AGB; we will amend this notice before we set one up. The legal basis is Art. 6(1)(f) GDPR, with the legitimate interest of being able to prove the conditions of this contractual rule and of not keeping unused free accounts indefinitely. We store the point in time until your account is erased.

Suspension of your account. If we suspend your account under Clause 21 of our Terms of Use, we store that and since when it is suspended, the reason as we recorded it, and which member of our team ordered the suspension. For as long as the suspension lasts, we check on every request of your signed-in session whether your account is suspended and then refuse the request. We do not end your session in doing so, so that you can still sign out and reach the cancellation and withdrawal functions (Section 9.2) and our legal texts. You can also switch the AI memory (Section 22) off and view and delete its entries during the suspension, and you can still export your personal workspace and a team workspace of which you are the owner (Section 37); the page on which we show you the suspension offers the controls for this. A workspace that you only manage as an administrator cannot be exported by you during the suspension. All other functions of the application are not available to you during the suspension, including those with which you otherwise view, rectify or delete data yourself, such as your conversations with the AI assistant (Section 21.7) or the content of your workspaces. You can exercise these rights at any time during the suspension via privacy@klate.ai (Section 37); we then carry out your request for you. We revoke all access tokens of your MCP connections (Section 24) with the suspension; your connections are thereby disconnected. We tell you the reason by email; we do not show it in the application. We record the suspension and its lifting, with the reason, in the audit log (Section 20). We delete the suspension record itself when the suspension is lifted (Section 35.1). The legal basis is Art. 6(1)(b) GDPR for enforcing the agreed rules of use and Art. 6(1)(f) GDPR with the legitimate interest of protecting the service, other users and third parties against violations and of establishing or defending legal claims. Section 14 applies to the suspension of a workspace.

Recipients. The authentication service Neon Auth is operated by Databricks, Inc. (USA, parent company of Neon, LLC; "Neon") and runs in the same database as our remaining data in Frankfurt am Main (aws-eu-central-1). The emails containing the confirmation code and the link for resetting the password are sent by us via our dispatch service provider Resend (Section 26); for this purpose the authentication service hands us the code or the link and your email address.

Legal basis. Art. 6(1)(b) GDPR for the account, sign-in and session management; Art. 6(1)(f) GDPR for the storage of the IP address and user agent for the session, with the legitimate interest of detecting unauthorised access.

Storage period. A session becomes ineffective upon expiry of its validity; an expired session no longer permits any access. The associated row containing the session identifier, IP address and browser identifier is deleted by a daily clean-up run 30 days after expiry of the session; it ceases to exist earlier upon erasure of your account or at your request under Section 37. You can end any session yourself by signing out or by changing your password; the latter signs out all other devices. Account and profile data are stored by us until your account is erased (Section 35).


13. Profile details

Purpose. You may voluntarily store further details about yourself, for example your role, your company and a short self-description. These details are shown to other members of your workspace when they click on your name in a mention.

Voluntary nature. These details are entirely voluntary. If you do not provide them, this has no disadvantages for your use of Klate.

Legal basis. Art. 6(1)(b) GDPR, since the details form part of the collaboration features you use.

Storage period. Until you delete the details or your account is erased.

Language setting. You choose the language of the interface (German or English) in the user menu or in the settings of your account under "Sprache" ("Language"). Once you have chosen, we store your choice in your account (a language code or the entry "automatic", together with the time of the last change) so that it also applies after the cookie under Section 7.2 has been deleted and on another device; when you sign in, we read it once and use it to restore the cookie. Other members of your workspace do not see it. We also use it as the language of our emails to you (Section 26). The entry is voluntary; without a choice the application follows the language of your browser. Legal basis: Art. 6(1)(b) GDPR, since you are setting a preference of the service you use. Storage period: until you reset the choice to "Automatic" (only the entry "automatic" then remains) or your account is erased.


14. Workspaces, teams, seats and invitations

Purpose. Klate is a tool for collaboration. Content is held in workspaces; every user has a personal workspace and can be a member of team workspaces.

What other members can see. Within a workspace, the other members see your name, your email address, your profile picture and your role as well as the content you create or change there, including your authorship of comments, versions and sharing decisions. Administrators of a team workspace can additionally view the member list and the seat allocation.

Invitations. If you invite someone, we process that person's email address, the role assigned by you, the status of the invitation and the time of the response. The invited person receives an email from us containing your name, the name of the workspace and a link for acceptance. An invitation grants access only after express acceptance.

If you have been invited. You can decline the invitation; we will then not use your address any further. You receive the information under Art. 14 GDPR by way of this notice, which can be accessed at any time via the reference in the invitation email and at https://klate.ai/legal/datenschutz. In detail, the following applies:

  • Categories of data: your email address, the role assigned to you, the status of the invitation and the time of your acceptance or refusal. Your email address is additionally included in the log entry about the granting of the authorisation (Section 20).
  • Source: your email address was communicated to us by the person who invited you. We did not collect it from publicly accessible sources.
  • Purpose and legal basis: delivery and management of the invitation as well as proof of it, Art. 6(1)(f) GDPR. Our legitimate interest and the legitimate interest of our customer consist in enabling you to join the workspace and in keeping traceable to whom access was granted.
  • Recipients: our email dispatch service provider (Sections 26 and 33); its delivery logs and metadata are stored in the USA (Section 34.2).
  • Storage period: an invitation to a team workspace lapses 14 days after it is created; an invitation to an individual customer, project or design does not lapse of its own accord. If you decline, if the invitation is withdrawn or if it lapses, any access thereby ceases; the entry is deleted by the next daily clean-up run once 30 days have passed since that point in time. If you accept, the resulting permission remains in existence for the duration of your membership; the invitation entry for a team workspace is deleted by the next clean-up run after 30 days have elapsed since redemption. If the account of the inviting person is erased, we delete the invitations to team workspaces issued by that person together with the account. Permissions which that person granted to others for an individual customer, project or design thereby lose only the reference to that person and remain in existence with your email address for as long as the access exists; only after they have been declined, withdrawn or have lapsed does the clean-up run remove them after its own period of 30 days. For the log entry, Section 35 applies. You can request erasure at any time under Section 37.
  • Your rights: Section 37, in particular your right to object under Section 38 and your right to lodge a complaint under Section 39.

Leaving a team. If your membership is ended, your access ceases immediately. Content that you have created in the team workspace remains there; it belongs to the workspace, not to your account. Your name therefore remains visible on content, comments, shares and log entries of that workspace created by you. If you do not wish this, please contact privacy@klate.ai; see also Section 37.

Suspension of a workspace. If we suspend a workspace under Clause 21 of our Terms of Use, we store on the workspace since when it is suspended, the recorded reason and which member of our team ordered the suspension. For as long as the suspension lasts, its content cannot be opened by its members or by persons with whom content from it was shared. In overviews such as the sidebar, the search and the home page, its entries may still appear with their overview details (such as title, short description, colour, logo and the name of the assistant), as may notifications and references to comments, with a short excerpt, that already exist. Share and approval links into the workspace have no effect, and it cannot be reached by AI features or connected agents (Section 24). Anyone who calls up content of the workspace does not learn the reason for the suspension, but at most that the workspace is currently unavailable. You too, as a member, cannot view, rectify or delete the content of the suspended workspace yourself during the suspension, including the conversations with the AI assistant held there (Section 21.7); we do this on your message to privacy@klate.ai (Section 37). The export is the exception: the owner and the administrators of the workspace can export its content during the suspension too (Section 37). Your AI memory (Section 22) and your MCP connections (Section 24) belong to your account and remain unaffected by the suspension of a workspace. Managing the plan by the administration of the workspace, this export and cancellation (Section 9.2) are not covered by the suspension. We record the suspension and its lifting, with the reason, in the workspace's audit log (Section 20); we delete the suspension record when it is lifted (Section 35.1). The legal basis is the same as for the suspension of an account (Section 12).

Legal basis. Art. 6(1)(b) GDPR for the collaboration features; for the processing of the data of invited persons, Art. 6(1)(f) GDPR with the legitimate interest of enabling our customers to collaborate within a team.


Purpose. You can give individual persons access to a customer, a project or a design, as viewer, editor or administrator.

Share links. You can additionally generate an unlisted share link. Important for your assessment of the risk:

  • A share link authorises reading only (role "viewer").
  • The link can be redeemed only by signed-in persons. Whoever opens the link must have a Klate account; upon redemption, the access is permanently bound to that account. A link that has been passed on therefore does not give anonymous access to your content.
  • You can give a link an expiry date and revoke it at any time.

Separation of the workspaces. Every access is checked on the server side against your actual permissions. If the permission is missing, we respond with an error that does not reveal whether the requested content exists at all.

If a share was addressed to your email address. If a user of Klate has provided your email address in order to give you access to a piece of content, the following applies, and this is at the same time the information under Art. 14 GDPR:

  • Categories of data: your email address, the role assigned to you, the status of the share and the time of your acceptance or refusal. Your email address is additionally included in the log entry about the granting of the share (Section 20).
  • Source: your email address was communicated to us by the person who shared the content with you. We did not collect it from publicly accessible sources.
  • Purpose and legal basis: delivery and management of the share as well as proof of it, Art. 6(1)(f) GDPR. Our legitimate interest and the legitimate interest of our customer consist in making the shared content accessible to you and in keeping traceable to whom access was granted.
  • Recipients: our email dispatch service provider (Sections 26 and 33); its delivery logs and metadata are stored in the USA (Section 34.2).
  • Storage period: an open share invitation does not lapse of its own accord. The entry remains in existence until you accept or decline the share or until the sharing person revokes it. If you accept, it remains in existence until the share is revoked. It is removed at the latest upon erasure of the sharing account; for the log entry, Section 35 applies. You can request erasure at any time under Section 37.
  • Your rights: Section 37, in particular your right to object under Section 38 and your right to lodge a complaint under Section 39.

Legal basis. Art. 6(1)(b) GDPR for the sharing features; for the processing of the data of persons whose email address has been provided for a share, Art. 6(1)(f) GDPR in accordance with the preceding paragraph.


16. Content you create in Klate

Purpose. We store the content created by you so that you can work with it.

Content concerned. Customer and project details, designs with their conversation paths and individual turns, briefs, guideline cards, tool and provider definitions, widgets, forms, comments as well as all version states of this content.

Personal reference. This content consists of free-text fields. It may therefore contain personal data, both your own and that of third parties. For content that you enter, we act as processor; Section 4.2 and Part D apply.

Versioning. Klate stores version states of your designs so that you can trace changes and restore earlier versions. A version shows who created it and when. We delete automatically created version states 30 days after their creation, unless your plan provides for longer retention or a retention order is in place for the workspace; version states created manually or on a phase change remain until you delete them.

Legal basis. Art. 6(1)(b) GDPR vis-a-vis you as customer; in relation to data subjects whose data you enter, the legal basis is determined by your own determination as controller.

Storage period. See Section 35. Deleted customers, projects and designs are finally removed from our database 30 days after deletion; within that period we can reverse an accidental deletion at your request. Tools, tool providers, widgets, forms, guideline cards, subagents as well as individually deleted conversation paths, conversation contributions, version states and comments, by contrast, are deleted immediately and finally; restoration by us is not possible there. The content of an individually deleted conversation path or conversation contribution remains contained in earlier version states of the design until those are deleted. With regard to uploaded files and to backup copies, please note Sections 35.1 and 35.3.


17. Uploaded files and media

Purpose. You can upload files, in particular images, and use them in designs and widgets.

Workspace a file belongs to. A file that you upload while editing a customer, project or design is stored in the workspace to which that customer, project or design belongs, even if that is a team workspace of which you are a member or, through a share, the workspace of another person; it appears in that workspace's media library and counts towards its storage. We store a picture for a team workspace in that team, and your profile picture in your personal workspace.

Storage location and protection. Uploaded files are held in private object stores at Cloudflare R2. We have specified Western Europe as the storage location; the provider does not promise us any guaranteed storage location for this. Storage outside the European Economic Area is permissible under the Auftragsverarbeitungsvertrag (data processing agreement) only subject to the safeguards of Section 34. These stores are not publicly accessible: there is no public address and no dedicated domain for them. A file can be retrieved only after we have checked your access authorisation and have thereupon generated a short-lived, signed retrieval link. Without a valid signature, knowledge of the file name is worthless.

Separately from this, we operate a public object store exclusively for our own brand and marketing materials, such as the logo in our emails. No customer content is held there.

Blocking a file. If we block an uploaded file under Clause 21 of the Terms of Use, for example after a notice to abuse@klate.ai, we store on the file since when it has been blocked and the case number of our procedure together with the type of breach; we do not store the name of a notifying person there. For as long as the block lasts, nobody is given a retrieval link for the file any more, no member of the workspace and nobody through a share; a short-lived retrieval link generated before the block remains valid until it expires. The file does not appear in the media library, is not included in any export (Section 37) and cannot be uploaded to that workspace again. An export already created that could contain the file is withdrawn with the block: the application no longer generates a download link for it, a download link generated before loses its validity at the latest ten minutes after it was generated, and a new export is possible at any time. Blocking does not delete the file: it stays in our private object storage so that we can lift the block after a successful statement and the evidence is preserved. For the workspace we put a retention order ("legal hold", Section 35.1) in place, which we lift once the procedure is concluded, unless it has to remain in place because of a legal dispute or an enquiry by an authority. If we lift the block, the file is available again as before. We record the block and its lifting in the workspace's audit log (Section 20); we delete the block record on the file when the block is lifted (Section 35.1). The legal basis is Art. 6(1)(b) GDPR for enforcing the agreed usage rules and Art. 6(1)(f) GDPR with the legitimate interest of no longer making unlawful content accessible, protecting the rights of third parties and establishing, exercising or defending legal claims.

Legal basis. Art. 6(1)(b) GDPR.

Storage period. See Section 35.


18. Comments, mentions and notifications

Purpose. You can comment on content, mention colleagues with "@" and are notified about events relevant to you.

Data processed. Comment text, author, time and reference to the content commented on; for notifications, the recipient identifier, the type and occasion of the notification as well as the read status. During joint editing we show other members that you are currently working on a piece of content (presence display) and briefly lock individual turns against simultaneous editing.

Legal basis. Art. 6(1)(b) GDPR.

Storage period. Comments are retained until the associated content or your account is deleted. Notifications are deleted by us automatically 30 days after they arise, irrespective of whether you have read them and whether the content they refer to still exists. Presence and lock entries are short-lived and lapse automatically.


19. Approvals (sign-off procedure)

This section is relevant for you even if you do not have a Klate account but have been asked to approve a design.

19.1 Purpose

Users can send a design or a brief for approval to a named person, typically to a contact person on the customer side. In our Terms of Use and their annexes this procedure is called "Abnahme" (approval) and the link sent for it "Abnahmelink" (approval link); both terms mean the same as "approval" in this section.

19.2 Data processed

The email address of the approving person, an optional free-text note from the requesting person, a randomly generated key for the approval link (token), the expiry time, the time of the decision and the identifier or email address of the person who decided.

19.3 How access works

The approving person receives an email containing the title of the design, the name of the requesting person, the note text and the approval link, which contains this token.

In every case, the link acts as an access key for reading: whoever possesses it can view the draft in question even without signing in, and in read-only mode, together with the associated customer record, the project, the project brief, the rule cards and the linked tool, provider, widget, form and sub-agent definitions. This is the only place at which content can be viewed without an account; the share links under Section 15 are to be distinguished from this and can be used only after signing in.

For the approval decision, the following applies in addition:

  • If the approving person has a Klate account, the decision is bound to that account and can be taken only after signing in. A link that has been passed on therefore allows a third party to read, but not to approve in that person's name.
  • If that person has no account, they grant or refuse the approval directly via the link.

The token lapses automatically after 14 days. The approval decision is limited in volume, and we deliberately respond to invalid tokens in such a way that no conclusions about the existence of a design can be drawn from it. The read access via the link, by contrast, is not separately limited in volume. Therefore do not pass on an approval link.

19.4 Information under Art. 14 GDPR for approving persons

If you have received an approval request without being a customer of ours yourself, the following applies:

  • Categories of data: your email address as well as your approval decision and the time of it.
  • Source: your email address was communicated to us by the person who asked you for the approval. We did not collect it from publicly accessible sources.
  • Purpose and legal basis: carrying out the approval procedure initiated by our customer, Art. 6(1)(f) GDPR. Our legitimate interest and the legitimate interest of our customer consist in enabling a demonstrable approval of drafts.
  • Recipients: our email dispatch service provider (Sections 26 and 33). Delivery logs and metadata of the dispatch are stored by that provider in the USA; on this, see Section 34.
  • Storage period: the token of the approval link lapses after 14 days. Your email address remains stored in the record of the approval decision for as long as the associated draft exists, because that record is precisely the purpose of the procedure. If the draft is deleted, the record is finally deleted 30 days later together with the draft. If the account of the requesting person is dissolved, the personal reference of the record is removed; the transaction itself remains in existence without a personal reference. You may object to the processing under Section 38 and request erasure under Section 37.
  • Further storage: your email address is additionally included in the unalterable log entry about the approval request (Sections 19.5 and 20).
  • Your rights: the rights under Section 37 apply, in particular your right to object under Section 38.
  • Right to lodge a complaint: you may lodge a complaint with a data protection supervisory authority at any time (Section 39).

19.5 Permanent record

For every approval request and decision we maintain an unalterable log entry which contains the acting person with an identifier or email address and the note text. This record is the purpose of the procedure: an approval is worth something only if it remains traceable who granted it and when. On the storage period, see Section 35.


20. Logging and audit log

Purpose. We maintain an audit log of operations relevant to security and to proof: changes to permissions, invitations and their acceptance, shares, role changes, billing events, suspensions of accounts, workspaces and individual uploaded files and their lifting (Sections 12, 14 and 17), your acceptance of the terms of use (Section 12), the sending of a notification about a change to them, of a contract confirmation and of a confirmation of your registration (Sections 25 and 26), the postponement of a start of the service (Section 25) as well as accesses by automated agents via the MCP interface (Section 24).

Data processed. The acting person with an identifier and in some cases an email address, the type of action, the object concerned, the time and a brief additional data record about the operation.

Legal basis. Art. 6(1)(f) GDPR. Our legitimate interests are the traceability of security-relevant changes, the investigation of cases of misuse and the fulfilment of our accountability obligation under Art. 5(2) GDPR. Records that are subject to retention obligations under commercial or tax law are not kept by us in the audit log but in the billing records (Sections 25 and 35.1); for these, Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 257 HGB applies.

Storage period. Audit log entries are not alterable; that is their purpose. They are, however, not retained indefinitely: the daily clean-up run deletes every entry 90 days after it arises. For workspaces for which a retention order ("legal hold") is in place, we suspend the deletion for the duration of the order (Section 35.1). If your account is erased while entries still exist, we remove your attribution as the acting person; the operation itself is retained as a record until the 90 days have expired (Section 35). Individual entries may in addition contain an email address, because the logged operation concerned precisely that address, for example an invitation or an approval request. We remove such details at the request of the person concerned, to the extent that no retention obligation stands in the way. Entries about the suspension of an account name the suspended person and the reason for the suspension; if their account is erased, we remove their identifier and the reason from these entries, and likewise the reason from the entries about the suspension of their personal workspace and of the team workspaces deleted with their account. Entries about the blocking of a file (Section 17) name the acting member of our team and the case number of our procedure, but no notifying person; they remain as evidence, also after an account is erased, until their period expires.


21. AI features

This section describes the processing with the greatest volume of content data and the most extensive transfer to the United States. Further transfers to third countries are listed in full in Section 34.2. Please read this section in full.

21.1 Which features are concerned

Klate offers AI-supported features. These are Klate's own features, not third-party products booked separately by you. They are executed only in connection with a conversation started by you, never in the background and never without your involvement:

  • the AI assistant "Ask Klate", which you trigger yourself and which supports you in drafting and, on your instruction, creates and changes content in your workspace,
  • the automatic titling of a newly started chat, which runs automatically alongside your first message so that the conversation remains findable in the list,
  • the AI-supported creation of a first design in the setup assistant (Section 23), which you trigger yourself,
  • the automatic examination of your message and of the response for details worth remembering, which runs automatically alongside for as long as you have the AI memory switched on (Section 22).

21.2 Which data is transmitted

When you trigger an AI feature, we transmit to the model provider:

  • your input (prompt) as well as the previous course of the respective conversation,
  • the instructions to the model (system prompt) including details of which page you are on and which workspace, customer, project or design is currently open,
  • the content that is necessary for processing the request, in particular the brief, guideline cards, conversation paths and turns of the design in question as well as linked tool and widget definitions,
  • content that you expressly include in the request via an "@" mention,
  • the definitions and results of the tools that the assistant calls in the course of processing,
  • stored memory entries, provided that you have switched on the AI memory,
  • images attached by you to the conversation,
  • your name as part of the instructions to the model,
  • the name of the language of your interface (for example "German") in one sentence of the instructions to the model, so that the assistant replies in that language; not the language code, not your saved language setting and not the cookie,
  • your email address as well as the names and email addresses of the other contributors to the customer, project or design currently being worked on, but only if the assistant actually calls the tool provided for this in the course of processing, for example in order to suggest to you the appropriate person for a mention.

What we do not transmit: your password, your payment data as well as the content of designs, project briefs and files from workspaces that are not open for the request.

Since this content is free text, it may contain personal data if you have entered such data. Please note our recommendation in Section 4.3 in this respect.

21.3 To whom transmission takes place

The requests run via the AI gateway of Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA) to the model provider used in each case. The model providers are currently exclusively:

ProviderLegal entityPlace of processingWhat it is used for
OpenAIOpenAI, L.L.C., USA; the contracting party for data from the EEA is OpenAI Ireland LimitedUSAThe default assistant model; where applicable, further models selectable in the input bar; creation of the first design in the setup assistant
AnthropicAnthropic PBC, USA; our contracting party is Anthropic Ireland, LimitedUSAWhere applicable, a model selectable in the input bar; fallback model if the selected model fails; the low-cost model for the automatic titling and the memory analysis

Without a choice of your own, your request runs on the OpenAI model preset by us. If we offer several models for selection in the input bar, you can choose a different one there; only models of the two providers named above are available for selection. Titling, memory analysis and the fallback model are specified by us and cannot be influenced by you. Models of further providers, in particular models operated in China, have been removed from the application entirely; they cannot be addressed even by a manipulated request. Which model executes a request is therefore determined exclusively by the selection described above.

Which operator actually runs a model. We specify the model identifier to the AI gateway. The gateway selects the executing operator itself for every request, according to throughput, availability and response time, but only within two requirements that our application passes with every request: the request may be executed exclusively by the model providers OpenAI and Anthropic themselves, and only by an operator for which, according to Vercel Inc., it has been agreed that your inputs are not used for training AI models. If no operator is available that meets both requirements, the request fails instead of switching to a different operator. The content transmitted in each case is that described in Section 21.2; the safeguards under Section 21.4 and Section 34.2 apply.

Until 6 September 2026 our application did not pass these requirements to the AI gateway with every request. During that period the gateway could also execute the same model in regular operation at an operator commissioned by Vercel Inc. instead of at the model provider itself, in particular at Microsoft Corporation (Azure OpenAI Service) for the OpenAI models as well as at Amazon Web Services, Inc. (Amazon Bedrock) and Google LLC (Google Vertex AI) for the Anthropic models, in each case in the USA. Those operators were commissioned by Vercel Inc. as its sub-processors, not by us; our safeguard for those transfers was the data processing agreement with Vercel Inc., which incorporates the Standard Contractual Clauses (Implementing Decision (EU) 2021/914).

21.4 Transfer to the USA

The processing by the model providers takes place in the United States: we use the programming interfaces of OpenAI and Anthropic, which are operated from there. We do not technically specify a routing region to the AI gateway, so that processing at another location of the respective provider cannot be ruled out; the safeguards described below apply, in accordance with the respective governing contractual chain, irrespective of the place of processing. This is a transfer to a third country which we do not base on an adequacy decision.

Who our contracting party is. To the extent that we commission the model providers directly, our contracting parties are established in the Union, for OpenAI it is OpenAI Ireland Limited, for Anthropic it is Anthropic Ireland, Limited; the path taken by your data to them is then not itself a third-country transfer. To the extent that the request is executed via the access credentials of Vercel Inc., our contracting party is Vercel Inc.; the model providers are then its sub-processors.

In both cases the processing takes place in the USA, because the model providers use affiliated companies in the United States for the operation of the models. In legal terms this is an onward transfer by the respective provider. The safeguards under Art. 46 GDPR for this onward transfer are ensured by the model providers by way of the data processing agreements underlying their engagement, depending on the access used, either our own contracts with the providers or the contracts of Vercel Inc. as the operator of our AI gateway. What is used in each case are the Standard Contractual Clauses of the European Commission (Implementing Decision (EU) 2021/914). We do not base the processing on an adequacy decision (EU-US Data Privacy Framework), even if a provider should be certified under that framework.

On request at privacy@klate.ai we will tell you which safeguards the respective provider uses for your processing and where you can inspect them.

The AI gateway is operated by Vercel Inc. in the USA. We base this transfer on the data processing agreement concluded with Vercel Inc., which incorporates the Standard Contractual Clauses under Art. 46(2)(c) GDPR; Vercel Inc. is moreover certified under the EU-US Data Privacy Framework.

Notwithstanding these safeguards, we expressly point out to you: in the United States there are powers of access for security authorities against which data subjects from the Union may possibly not be able to obtain legal protection equivalent to that under Union law.

21.5 What happens to your inputs at the providers

We deliberately state here the contractually assured position and no more:

  • No training. We use the AI features vis-a-vis the providers only on the condition that your inputs and the outputs generated may not be used for the training or improvement of AI models. For use via the programming interfaces of OpenAI and Anthropic, this assurance applies contractually, irrespective of whether the request is executed via our own access credentials or via those of the operator of our AI gateway. In addition, our application requires the AI gateway with every request to route it only to an operator for which this exclusion has been agreed according to Vercel Inc. (Section 21.3).
  • The AI gateway stores no content. According to the information provided by Vercel Inc., prompts and outputs are not retained in the gateway but are deleted immediately after completion of the request. What is logged there is metadata: time, status, model, executing operator and its region, token count, costs, duration as well as the access via which the request was authenticated. The details of the operator selection are, according to the provider's information, kept for 30 days; the log entry itself remains in existence beyond that for the duration of the retention period configured at the provider.
  • Short-term storage at the model providers. Both model providers reserve the right to retain inputs and outputs for up to 30 days for the detection of misuse and to delete them thereafter. If a provider establishes a breach of its terms of use, it may, according to its own information, retain the inputs and outputs for up to two years and the associated safety assessments for up to seven years. We have not agreed with the providers on a processing entirely free of storage ("zero data retention").
  • Caching to speed things up and reduce costs. So that long conversations do not have to be processed in full again with every request, we use the caching function of the providers. The recurring part of your request, namely instructions, previous course of the conversation and tool results, is thereby retained at the provider for the short lifetime of that cache.

21.6 We do not train models

We do not develop, train or fine-tune any AI models of our own. In Klate there is no training function, no data set export and no feeding back of your content into model training. Your content is used exclusively as input for the request triggered by you in each case.

21.7 What we store on our side

Your conversations with the assistant, namely your messages, the responses and the tool calls used in the process, are stored by us in your workspace in Frankfurt am Main so that you can view the history and continue working with it. Images attached to a conversation are stored by us in the private object store (Section 17). A conversation is finally deleted by a daily clean-up run 30 days after its last use (last message or last change to the conversation). Attached images are thereafter no longer retrievable through the application, because no signed retrieval link is generated any more; the stored file itself is removed by a separate deletion run for the object storage that is not yet active (Section 35.1). In addition, for every request we log the time, the model used, the AI feature called, the number of tokens processed and the costs incurred as well as the attribution to your account, your workspace and the respective conversation. We use these details in order to bill your credit correctly, to detect misuse and to assess the economic viability of the individual AI features.

You can delete any conversation that you yourself started at any time via the bin icon in the history list of the assistant. The deletion takes effect immediately and finally; restoration is not possible. For as long as we have suspended your account (Section 12) or the workspace to which the conversation belongs (Section 14), this is not possible in the application; we then delete the conversation on your message to privacy@klate.ai. Conversations that another person started in a shared project can be viewed by you, but not deleted. If you wish such a conversation to be deleted, a message to privacy@klate.ai is sufficient.

Art. 6(1)(b) GDPR, since the AI features form part of the service used by you and are executed only in connection with a conversation started by you (Section 21.1). For the analysis of the consumption data for the purposes of misuse detection and operational security, additionally Art. 6(1)(f) GDPR with the legitimate interest in a stable, cost-controlled and misuse-free operation.

21.9 No automated decision, limits of the outputs

The AI features generate proposals which you can accept, change or discard. A decision based solely on automated processing in an individual case within the meaning of Art. 22(1) GDPR does not take place; see also Section 40.

Outputs generated by AI may be incorrect or incomplete. Check them before you use them. Responsibility for content that you pass on or publish on that basis lies with you.

21.10 Transparency about the use of AI

For our AI-supported features we use third-party models; we do not develop, train or fine-tune any models of our own. The AI-supported features are marked in the interface, so that it is apparent to you that you are interacting with an AI system (Art. 50(1) of Regulation (EU) 2024/1689). Klate does not generate any content that would have to be marked as a deceptively realistic imitation of real persons or events. The conversations designed in Klate are drafts and are not conducted by Klate with your end customers.


22. AI memory

What it is. On request, the assistant remembers individual details about you and your way of working, for example preferred spellings or recurring general conditions, so that you do not have to repeat them in every conversation.

Switched off by default. The AI memory is deactivated as delivered. It becomes effective only if you expressly switch it on in the settings.

How an entry comes about. For as long as the memory is switched on, a small, low-cost model automatically examines, at the end of each conversation round, whether your message and the assistant's response contain a detail worth remembering permanently. For this examination we transmit your message and the response, each truncated to 1,500 characters, as well as the entries already stored by you to the model provider Anthropic in the USA; Sections 21.3 to 21.5 apply accordingly.

Nothing is stored as a result of this examination. An entry comes about exclusively in two ways: you expressly instruct the assistant to remember something, or it proposes the entry it has found to you and you expressly confirm it. Without your confirmation, no entry is created.

If you switch the memory off, this examination is omitted entirely.

Separation. An entry that you have stored in connection with a particular customer is not loaded into conversations relating to a different customer. The number of entries is limited.

Your control. You can view all entries at any time, delete them individually, delete them in full and switch the memory off again. This also applies for as long as we have suspended your account (Section 12): you then find these controls on the page on which we show you the suspension. If you merely switch the memory off, entries already stored are retained, unused. If they are to disappear, delete them in addition, either individually or via the "Alle Einträge löschen" button (in the English version "Delete all entries"). The entries remain visible while the memory is switched off; you do not have to switch it back on to view or delete them.

Legal basis. Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time with effect for the future by switching the feature off; the lawfulness of the processing carried out up to the withdrawal remains unaffected by this.

Storage period. Until you delete the entry or your account.


23. Setup assistant on first start

Purpose. When you first sign in, we ask you a few questions about your work, for example about the industry, the use case and the target group, and automatically generate a first design from them so that you are not faced with an empty workspace.

Data processed. Your answers in the interview, the name of the language of your interface (for example "German"; Section 21.2) as well as the content generated from them.

Transmission. Your answers are transmitted, for the generation of the design, to one of the model providers named in Section 21.3 in the USA. Section 21.4 and 21.5 apply accordingly.

Voluntary nature. You do not have to complete the interview; you can skip it and start immediately with an empty workspace.

Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest consists in making it easier for you to get started with our tool with a first draft tailored to the details you provide. You may object to this processing under Art. 21(1) GDPR; see Section 38.


24. MCP interface and access by AI agents

What it is. Klate provides an interface based on the Model Context Protocol (MCP). With it you can connect an AI agent of your choice, for example Claude, with your Klate account, so that the agent can read and, if you allow it, also write in Klate in your name.

The connection requires your express consent. Before the connection, we show you a consent page on which you can see which application is requesting access and which permission level it requests, and on which you select which workspaces the access is to extend to. The page describes the requested level in words. With "read" (klate.read), the agent can read your designs and the related content in the selected workspaces, including the names and email addresses of the people who have access, but cannot create, change or delete anything; with "read and write" (klate.write), it can additionally create, change and delete content there, manage comments, approvals and access, and thereby trigger invitations and approval requests by email. If the application requests no level, "read and write" applies. We enforce the level you consent to technically; it remains in place for the connection even when the agent renews its token. Without your confirmation, no access is granted. If you make no selection there, the connection applies to all of your workspaces that are enabled for AI features. You can change the scope at any time in the settings under "Verbindungen" (in the English version "Connections"), without re-establishing the connection; you can withdraw your consent at any time, and we will then disconnect the connection without undue delay (unverzüglich). For as long as we have suspended your account (Section 12), the settings cannot be reached; your connections are, however, then already disconnected, because we revoke all access tokens with the suspension (see below).

Data processed. Details of the connected application, the workspaces released by you, the permission level granted as well as access tokens, which we store exclusively as a cryptographic hash value. An access by the agent counts as use of your account and updates the time of last use (Section 12) as soon as we have recognised the access token as valid and established that at least one of the workspaces you released is available, even if we then refuse it because your account has made too many requests. An access does not count if we refuse it before this check is complete (for example because of too many requests from the same IP address or because of a technical fault), or if the check shows that the access token is missing, invalid, revoked or expired or that none of the released workspaces is available (any longer).

Storage period. An access token is valid for one hour, a refresh token for 30 days; a revoked or expired token no longer grants any access. The stored hash value is deleted by a daily clean-up run 30 days after expiry or revocation of the token. The authorisation code issued when the connection is established is valid for 60 seconds and is deleted immediately upon its redemption; a code that is not redeemed is removed 30 days after its expiry. If a refresh token is presented a second time after it has been renewed, we block all tokens of that connection as a precaution; you then re-establish the connection. The registration of an application to which neither you nor any other user has granted access within 30 days of the registration is deleted by the daily clean-up run; we store the time of the first grant of access with the registration. A registration to which access has once been granted remains in existence even if the connection has been disconnected or all tokens have expired, so that the application can reconnect without a new registration; it contains no details about your person. The attribution of the workspaces released by you is stored by us until your account is erased. If we suspend your account (Section 12), we revoke all tokens of your connections and issue no new ones for the duration of the suspension; after the suspension is lifted, you re-establish the connection. A suspended workspace (Section 14) cannot be reached by connected agents.

What the agent can reach. A connected agent is subject to the same access checks as you yourself: it can access only what you are permitted to access, only in the workspaces released by you, and only within the permission level granted.

Note for members of a team workspace. If a member connects an agent with a team workspace, that agent can read the content of that workspace which the member is also permitted to access themselves, including the names and email addresses of other members. The legal basis for this is Art. 6(1)(f) GDPR with the legitimate interest of our customer in using the tools chosen by it within its workspace. Every action of an agent that makes a change is recorded in the audit log (Section 20).

Important note on responsibility. The agent connected by you is a service of a third party which you select and commission. Content that the agent retrieves from Klate is thereby transferred to the operator of that agent and processed there in accordance with that operator's data protection provisions. We are not responsible for this further processing, and the provider of the agent is not a sub-processor of ours. Please check, before connecting, which provider you are granting access to.

Legal basis. Art. 6(1)(a) GDPR for the granting of the access, Art. 6(1)(b) GDPR for the subsequent execution of the requests as well as Art. 6(1)(f) GDPR for the logging of the agent accesses, with the legitimate interest in the traceability of automated accesses.


25. Billing, payments and credit

Purpose. As soon as paid plans, seats and credit for AI use are available, we process the data necessary for billing. As at the date of this notice, paid plans are not yet enabled; the statements below describe the processing from the point at which they are enabled.

Data processed. Identifier of the payment account at the payment service provider, plan and number of seats, status of the subscription, invoices and payment transactions including the VAT charged on them, whether you ordered as a consumer or as a business, and the verification status of a VAT identification number (VAT ID) you provided — not the number itself — as well as the balance and the movements of your credit including the underlying AI use.

Order record. As soon as you start a paid order - a new plan, a change to a higher plan, additional seats or AI Boost - we create an order record: which account ordered what for which workspace, the identifier of the corresponding transaction at the payment service provider, the status of the order and the time at which the ordered service was enabled. The record is created as soon as you open the payment page or submit the change. If the order is not completed - for example because you leave the payment page or the payment fails before we have sent you the contract confirmation - we delete the record automatically 30 days after it was created. A reduction or a termination does not create an order record. The order record contains no payment data.

The order record also contains what you state in the order step: whether you requested that we begin the service before the withdrawal period expires, with the identifier of the declaration text shown, the language in which it was shown to you and the time of your choice; whether you agreed to the separate agreement on the characteristic of the AI features, with the identifier of the text and the time; whether your workspace was recorded as a consumer or as a business at that time; and, if you did not request an immediate start, the calculated date on which the service begins. A change to a running subscription without an immediate start is stored as a scheduled order and carried out on that date. We create the order record with these details when you click, before anything is transmitted to the payment service provider, and record the same details in the audit log (Section 20) at the same time; if either of these two entries cannot be written, we do not accept the order. We do not store an IP address for the order record. These details serve as proof of the declarations the law provides for a start of the service before the withdrawal period expires and for agreeing a characteristic of the AI features (§ 356(5), § 357a(2) and § 327h BGB).

Contract confirmation. For every paid order we send you a contract confirmation by email (Section 26). As a rule we attempt to send it before we enable the ordered service; if it cannot be delivered straight away, we retry automatically (Section 26), and an enablement that is due with the order still takes place. The order record therefore also contains the time at which we handed the contract confirmation over to our email dispatch service provider - from it we calculate the withdrawal period and, if you did not request an immediate start, the start of the service -, a check value (SHA-256) of the content sent and the version date, version and check value of the contract documents attached. We do not store the content of the email itself. As long as the contract confirmation has not been handed over, this time remains empty; we then do not carry out a scheduled change to a running subscription without an immediate start. If the contract confirmation is handed over on a later day than assumed when you ordered, we postpone the start of an order that is still waiting for its start accordingly - later, never earlier -, record the postponement in the audit log (Section 20) and state the new date in the contract confirmation; for a new subscription we transmit this new date to Stripe as the start of the first billing. We obtain the prices stated in the contract confirmation from Stripe (the amounts of the order and a preview of the monthly invoice); in doing so we transmit to Stripe only the identifiers of your payment account, your subscription and the order's payment page or invoice and the quantity ordered, which Stripe already holds.

Payment service provider. We handle payments via Stripe Payments Europe, Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland. When a payment account is created, we transmit to it your email address, the name of your workspace as well as the internal identifiers of the workspace and the account. When you start an order, or change the seats, AI Boost or the paid plan of a running subscription, we additionally transmit the internal identifier of the account that triggered the order or change, the internal identifier of the order, as well as the chosen plan, the number of seats and the number of AI Boost units; if you did not request an immediate start for a new subscription, also the calculated date on which the service begins, from which Stripe first bills the subscription. In that case we also transmit to Stripe the note that Stripe's payment page shows under the button: that you did not request an immediate start, with that date, in the language of your order step. From these details, and from when an order or change is billed, Stripe can therefore tell whether you requested an immediate start. We do not transmit to Stripe your agreement to the characteristic of the AI features, the identifiers of the texts shown or the times of your declarations. For the handling of the payment transaction, fraud prevention and the fulfilment of its own regulatory and anti-money-laundering obligations, Stripe is an independent controller; in that respect Stripe's privacy notice applies. Your complete payment data, in particular card numbers, does not reach our systems at any time; it is entered directly at Stripe and processed there. The same applies to your billing address, your name and, if you order as a business, the name of your business and your VAT ID: you enter these details on Stripe's order page; Stripe stores them with your payment account, calculates the VAT from them and checks a VAT ID you provided against the databases of the competent authorities after the order. You can later view and change your payment methods, invoices, billing email address, name, billing address and VAT ID in Stripe's customer portal, which you open from your account. Stripe transmits to us the details of orders, of paid and failed invoices, of subscription changes, of refunds and of payment disputes; these can also contain the address, name, email address and VAT ID entered. Of these we store only whether you ordered as a business and which verification status Stripe reports for your VAT ID, and otherwise the details necessary for attribution and bookkeeping. On the transfer to a third country, see Section 34.

Legal basis. Art. 6(1)(b) GDPR for the performance of the contract; Art. 6(1)(c) GDPR for retention under commercial and tax law; for retaining what you state in the order step Art. 6(1)(f) GDPR - our legitimate interest is being able to prove, in a dispute, which declarations you made when ordering.

Storage period. Billing-relevant records are retained by us in accordance with the statutory retention obligations under § 147 AO, § 257 HGB and § 14b UStG. Whether you ordered as a consumer or as a business, and the verification status of your VAT ID, are stored with the workspace for as long as it exists (Section 35). Consumption and credit movements which we maintain only for billing control are anonymised by us once the purpose ceases to apply, instead of being deleted, so that the accounting remains coherent (Section 35). We do not automatically delete the order record of a completed order; that of an order not completed is deleted after 30 days (Section 35.1). An order whose contract confirmation we have handed over also counts as completed, even if its payment fails later.


26. Transactional emails

Purpose. We send you emails that are necessary for the use of the service. These are: the one-time welcome message after you complete your registration (with a link into the application and the address for questions), invitations into a workspace or a team, invitations to an individual customer, project or design, requests for the approval of a draft or of a project brief, the confirmation of receipt of a piece of feedback and the notification that a piece of feedback has been implemented, the welcome message after taking out a paid plan, the receipt for additionally purchased credit, the notification about a failed payment with the request to pay the open amount within a period (payment request under Clause 10.5 of the terms of use), the notification about the blocking and re-enabling of the AI features after a chargeback or a refund as well as a staged sequence of reminders around the expiry of a plan. In addition there are the acknowledgement of receipt of a termination and the acknowledgement of receipt of a withdrawal from the functions under Section 9.2, the notification that an export of your workspace that you started is ready (Section 37; it contains the name of the workspace, the date until which the download is possible and a link to your settings, not the export file itself), the confirmation that you deleted your account in the settings (Section 35.2; it contains the date of the deletion and an overview of what was deleted and what we retain, and goes to the address the account had until the deletion), the notification about a change to the terms of use and their annexes, which we send to the stored email address at least 30 days before the change takes effect (clause 14.3 of the terms of use), as well as the emails that the sign-in itself requires, namely the confirmation code and the link for resetting the password (Section 12). We also send the contract confirmation for every paid order (§ 312f(2) BGB; Section 25) and, once a new account is activated, a one-time confirmation of your registration (Section 12). Both contain the withdrawal notice and the model withdrawal form in full and have the terms of use with the annexes applicable to you attached as files. The billing-related emails presuppose a paid plan (Section 25). We notify you about mentions and comments exclusively within the application, not by email.

No newsletter, no advertising. We do not send any advertising emails.

Language of the emails. We write an email in the language that the recipient has chosen in their account (Section 13). If they have not chosen one, or have no account, we write in the language that the person who triggered the email had set in the application, otherwise in the language of that person's browser, otherwise in English. The legally required messages (the order confirmation, the confirmation of your registration, the receipts for a termination and a withdrawal, the payment request and the notice of a change to the terms of use) do not follow this choice but the language rule of the respective declaration (Sections 9.2, 12 and 25).

Data processed. Recipient address, name, subject and the content necessary for the respective occasion, in particular titles of and references to the content concerned. The contract confirmation additionally contains your name and email address, the name of the workspace, what you ordered and when, the start of the service, the prices and the billing period as well as what you stated in the order step (Section 25); it goes to the account that placed the order. The confirmation of your registration contains your email address and the time of activation. For this confirmation we store with your account when your account was activated and when the email was handed over to the dispatch service provider, a check value (SHA-256) of the content sent and the version date, version and check value of the documents attached, so that it is sent only once and can be proven; we do not store the content of the email. The payment request contains the name of the workspace, the number of the invoice, the open amount, the last day of the payment period and a link to our payment service provider's payment page for that invoice (Section 25); it goes to the person who owns the workspace. With the workspace we store when we handed it over to the dispatch service provider and when the period ends, so that the paid plan does not end before the period has expired, and we record the dispatch in the audit log (workspace, invoice identifier and period, no email address). We do not send design content by email. We record the sending of a notification about a change to the terms of use in the audit log (your user identifier, the version, the date the change takes effect and the service provider's message identifier, no email address), so that nobody receives the notification twice and its dispatch can be proven; Section 20 and its storage period apply to this entry.

No open or click tracking. We do not measure whether and when you open an email, and we do not provide links with counting pixels or redirects for measuring success.

Recipients. The dispatch service provider Resend (Plus Five Five, Inc.). Dispatch takes place from an EU region (Ireland). Please note: according to the provider's information, account data, delivery logs and metadata of the emails are stored in the United States, irrespective of the dispatch region selected. In that respect there is a transfer to a third country; see Section 34.

Renewed delivery of the acknowledgements of receipt and contract confirmations and of the payment request. If one of the two acknowledgements of receipt under Section 9.2, a contract confirmation, the confirmation of your registration or a payment request cannot be delivered straight away, we automatically try to deliver it again, as a rule once a day and at most eight times in total. For this we do not store your email address or the content of the email a second time, but only a reference to your stored declaration, your order, your account or the invoice and the workspace concerned, the number of attempts, a technical error code and the times; the email is generated afresh from these stored details on each attempt, and the address is read from the declaration or from your account at the time of sending. For the contract confirmation, the confirmation of your registration and the payment request we create this entry before the first attempt, so that each is sent only once. A payment request that is no longer owed at a renewed attempt, because you have paid in the meantime, is no longer sent. Storage period: Section 35.1. An acknowledgement of receipt that we hold back because a sending limit has been reached (Section 9.2) is not retried automatically; it is sent by hand.

Legal basis. Art. 6(1)(b) GDPR; this also applies to the payment request and to storing when it was sent and when its period ends. For the two acknowledgements of receipt under Section 9.2 it is Art. 6(1)(c) GDPR, because § 312k Abs. 4 BGB and § 356a BGB oblige us to provide that confirmation; you therefore also receive these two emails if you have no account with us. For the contract confirmation and the confirmation of your registration it is Art. 6(1)(b) GDPR and, insofar as § 312f(2) BGB obliges us to confirm the contract, Art. 6(1)(c) GDPR; we base the retention of the hand-over time, the check value and the document versions on Art. 6(1)(f) GDPR - our legitimate interest is being able to prove when and with which content we informed you about your right of withdrawal.


27. Feedback from within the application

Purpose. Within the application you can send us feedback, a bug report or an idea directly.

Data processed. Your free text, the type of feedback, the page you were on and your email address so that we can reply. In addition, the identifier of your account and the identifier of your active workspace are always stored. For every piece of feedback you automatically receive an acknowledgement of receipt by email.

Technical details only with your consent. A check box that is not ticked by default allows you to transmit technical details in addition: browser, operating system, window size, application version and language setting as well as a rough location indication consisting of country and region (for example "DE-HE"). Without your consent we store neither the technical details nor the location indication.

Your IP address is not stored. We derive the location indication from header data of our hosting provider; we discard the raw IP address and do not place it in our database at any time.

Separate storage. Feedback is stored by us in a separate database schema which is separated from the product data.

Legal basis. Art. 6(1)(f) GDPR for the handling of your feedback. Our legitimate interest consists in tracing and remedying reported errors, in replying to your report, in informing you if we have implemented your suggestion and in evaluating the collected feedback as the basis of our product development; for the technical details and the location indication, Art. 6(1)(a) GDPR (consent), revocable at any time at privacy@klate.ai. On the storage period and the decoupling from your person, see Section 35.1.


28. Operational, error and performance telemetry

Error logging. If an unexpected server error occurs, we transmit the technical error context to Sentry (Functional Software, Inc., USA) for diagnosis. What is transmitted is the error message, the call chain (stack trace), a request identifier as well as the route concerned. From the route we remove user and workspace identifiers before transmission; it may however contain the identifier of the content concerned. We have configured the collection tool in such a way that no IP address, no cookies, no headers, no content of your request and no details about your account are transmitted; the log traces that otherwise run alongside ("breadcrumbs") are also switched off. In rare cases the error message of a third-party program library may contain a fragment of processed content; we therefore limit every error message to 250 characters and remove email addresses already before transmission.

Storage location. The error events are stored in a Sentry project of the EU region (storage location Frankfurt am Main). Account, organisation and project metadata, access tokens, the provider's own audit logs as well as the content of any support enquiries are processed by Functional Software, Inc. in the USA, irrespective of the region selected; on this, see Section 34.

Storage period. Error events are deleted by the provider upon expiry of the period applicable to our plan; for the "Developer" plan used by us it is, according to the provider's information, 30 days. The provider's backup copies expire, according to its information, 90 days after their creation.

Measurement of interface performance. Within the application we measure how long individual views take to open, in order to detect performance degradations. What is stored is: the measured duration, the view concerned, the path accessed in generalised form (that is, without identifiers, for example /designs/[id]), a rough size class of the content, a rough device class, a rough country indication, the identifier of the workspace last selected as well as your user identifier.

These measured values are attributed to your person and are therefore personal data; we deliberately do not describe them as anonymous. The raw IP address is discarded, and the browser identifier is not stored. We analyse the measured values exclusively on a technical basis and do not form usage profiles from them. We delete this data automatically after 90 days, and earlier upon the erasure of your account (Section 35.2).

Availability monitoring. An external service checks at short intervals whether our application is reachable, and monitors whether our scheduled maintenance tasks are running. No personal data is processed in the process; all that is queried is a status address without any personal reference.

Legal basis. Art. 6(1)(f) GDPR. Our legitimate interests are the detection and remedying of malfunctions, the maintenance of availability and the safeguarding of the security of our service.


29. Third-party content loaded within the application

We consider it appropriate to disclose these inconspicuous connections as well, because your IP address is transferred to third parties in the process.

Icons of tool providers and sample images. We display the icons of tool providers as a monogram or as an image uploaded by you, and we deliver the sample images of our templates and of the designs generated by the setup assistant (Section 23) ourselves; your browser does not contact any third-party service for this. One exception: individual widgets that were created in the past from one of our widget templates still contain the address of a sample image of the service Lorem Picsum (picsum.photos). If such a widget is displayed, your browser loads the image directly from there; the provider thereby receives your IP address, your browser identifier and the image address requested and processes this data under its own responsibility in the United States. The image does not show a real person.

Image addresses inserted by you or by the AI. If you store the address of an image from an external server in a design or widget or as a logo or profile picture, your browser loads that image from there when displaying it. The server in question thereby receives your IP address. We have no influence on the selection of these addresses.

Bot check on the registration page. On app.klate.ai/auth/sign-up your browser loads the script and the embedded frame of the bot protection Cloudflare Turnstile from challenges.cloudflare.com (Cloudflare, Inc., USA). Cloudflare thereby receives your IP address, your browser identifier, technical characteristics of your connection and the identifier of our check widget; details and legal basis in Section 12. Unlike the image retrievals described above, you cannot prevent this retrieval without forgoing registration; it is not triggered on any other page.

Legal basis. Art. 6(1)(f) GDPR with the legitimate interest in displaying the images stored in the content as they are stored there. You can prevent this processing by restricting the loading of external images in your browser; the interface then remains usable. An objection under Section 38 is also possible.


30. Access to your data on our side

Access to customer content. We access content that you create in Klate as a processor and only on your instruction, in particular in order to deal with a support enquiry made by you or to remedy a malfunction reported by you. The basis in this respect is the Auftragsverarbeitungsvertrag (data processing agreement) (Art. 28(3)(a) GDPR), not a legal basis of our own.

Access for our own purposes. Independently of this, we access data within narrow limits as an independent controller: in order to safeguard the security and availability of our service, to ward off misuse and to fulfil legal obligations. This includes a cross-workspace read access to the audit log (Section 20); that access is itself logged. The legal basis in this respect is Art. 6(1)(f) GDPR with the legitimate interest in a secure and misuse-free operation, or Art. 6(1)(c) GDPR to the extent that a legal provision obliges us to do so.

Who can access data on our side. Klate is currently operated by the Geschäftsführer (managing director) alone; he is the only person with administrative access. Should we engage further persons in future, they will receive access only to the extent that it is necessary for their task, and will be bound to confidentiality beforehand.


Part D: People whose data our customers enter

31. Who is responsible for your data

This part is addressed to you if your personal data has been entered into Klate by one of our customers, for example because you appear in a designed conversation flow, in a brief or in an uploaded file.

The controller for this data is not Klate but our customer who entered the data. We process it exclusively on that customer's behalf as a processor under Art. 28 GDPR.

Please contact that customer first. Only that customer can inform you why and on what basis your data is being processed. If you do not know who it is, write to us at privacy@klate.ai; we will forward your request insofar as we are able to do so.


32. How we handle this data

  • We process this data only on the instruction of our customer and do not pursue any purposes of our own in doing so.
  • We do not analyse it, form no profiles from it and do not use it for the training of AI models (Section 21.6).
  • The same security measures (Section 36), the same separation of the workspaces (Section 15) and the same recipients (Section 33) apply as for all other content.
  • If our customer triggers an AI feature on content in which your data is contained, that content is transmitted, in accordance with Section 21, to the providers named there in the USA.
  • If we receive a request for access, rectification or erasure that concerns this data, we forward it to our customer and support that customer in answering it, as provided for by Art. 28(3)(e) GDPR.

To the extent that we are ourselves the controller for this data. Within narrow limits we also process data from customer content under our own responsibility, for our audit log, for billing and misuse detection in relation to AI requests as well as for safeguarding operations (Sections 20, 21.8 and 30). The legal basis in this respect is Art. 6(1)(f) GDPR with the legitimate interests named there. Since we did not collect your data from you and cannot send you a separate message without recording additional data about you, we provide you with the information under Art. 14(5)(b) GDPR in the form of this publicly accessible privacy notice. You can assert your rights under Section 37, including the right to object under Section 38, vis-a-vis us at privacy@klate.ai.


Part E: Cross-cutting topics

33. Recipients and sub-processors

We disclose personal data only to the extent that this is necessary for the provision of our service or where there is a statutory obligation. We do not sell personal data and do not disclose it for advertising purposes.

33.1 Processors

The following service providers process personal data exclusively on our instruction, unless otherwise noted in the table. Data processing agreements under Art. 28(3) GDPR come into existence, depending on the provider, by way of a separate agreement or by way of the incorporation of a contractual addendum into the provider's terms of use. Where such a contract has not yet come into existence, we state this following the table.

Service providerPurposeData processedPlace of processing
Vercel Inc. (USA)Hosting, execution of the application, scheduled tasks, network protectionAll application data while a request is being processed; server log filesExecution of the application: Frankfurt am Main (fra1); storage location of the server log files not currently confirmed (Section 34.1); network protection global
Vercel Inc. (USA)Measurement of loading performance (Speed Insights)Measured values under Section 8USA
Vercel Inc. (USA)AI gateway: forwarding of the AI requestsContent of the AI request under Section 21.2USA
Databricks, Inc. (USA; parent company of Neon, LLC, "Neon")Database (leading system) and authentication serviceAll permanently stored data, including accounts and sessionsFrankfurt am Main (aws-eu-central-1)
Cloudflare, Inc. (USA)Object storage for uploaded files; name resolution; delivery of public media; bot check at registration ("Turnstile", Section 12)Uploaded files; connection data; for the bot check the IP address, TLS fingerprint, browser identifier and widget identifier of the registration page as well as the one-time check tokenObject storage Western Europe; network global; bot check: not fixed to a region by the provider, see Section 34.2
Plus Five Five, Inc. ("Resend", USA)Dispatch of transactional emailsRecipient address, name, content of the respective messageDispatch EU (Ireland); account data, logs and metadata USA
Stripe Payments Europe, Ltd. (Ireland)Payment processing, VAT calculation, invoices, subscriptions and customer portal from the point at which paid plans are enabled (Section 25); for fraud prevention and for its own regulatory and anti-money-laundering obligations at the same time an independent controller (Section 25)Email address and name of the account holder, name of the workspace, internal identifiers, billing address, for business customers the name of the business and the VAT ID, payment and invoicing dataEU (Ireland), with transfer to Stripe, Inc. or Stripe, LLC (USA)
OpenAI (contracting party for the EEA: OpenAI Ireland Limited)AI inference; depending on the access used, commissioned directly by us or via Vercel Inc. as the operator of our AI gatewayContent of the AI request under Section 21.2USA
Anthropic Ireland, Limited (Ireland), with processing at Anthropic PBC (USA)AI inference; depending on the access used, commissioned directly by us or via Vercel Inc. as the operator of our AI gatewayContent of the AI request under Section 21.2USA
Functional Software, Inc. ("Sentry", USA)Server-side error diagnosisError message, stack trace, request identifier and route; no IP address, no cookies, no request contentError events EU region (Frankfurt am Main); account, organisation and administrative data as well as support enquiries USA
Better Stack, s. r. o. (Czech Republic)Availability monitoring, status pageNo personal data of the users of the application; server log files of the visitors to the status pageEU, or in accordance with the provider's specifications
Mintlify, Inc. (USA)Operation of the internal documentation domain docs.klate.ai (Section 10)Connection data of every access to this domain (as listed in Section 6 under "Data processed") as well as the email address, sign-in and session data of the only person authorised to access it; no account, design or customer contentUSA
Google Ireland Limited (Ireland)Email mailboxes at @klate.aiContent and header data of your emails to usEU, with the possibility of access by Google LLC (USA)

Contracts. Data processing agreements under Art. 28(3) GDPR exist with the service providers listed above. In the case of Functional Software, Inc. ("Sentry") we accepted the provider's contractual addendum (Data Processing Addendum, version 5.1.0) on 5 September 2026; in the case of Mintlify, Inc., the provider's contractual addendum forms part of the contract under its terms of use for customers acting as businesses.

33.2 Independent controllers

The following recipients process the data arising at them under their own responsibility. There is no data processing agreement in this respect, and we have no influence on their further processing. The data protection provisions of the respective provider apply.

RecipientOccasionData processedRegistered office
Lorem Picsum (USA)Sample image in individual widgets created in the past from a widget template (Section 29)IP address, browser identifier, image address requestedUSA, retrieval by your browser, no data processing agreement
Operators of other servers whose image addresses you or the AI store in a piece of content (Section 29)Display of the stored imageIP address, browser identifieraccording to your selection
Operator of an AI agent connected by you (Section 24)Access granted by you via the MCP interfaceThe content retrieved by the agentaccording to your selection
Porkbun LLCRedirection of the domains klate.io and getklate.com (Section 10)Connection data including IP addressUSA
Cloudflare, Inc.Improvement of its bot protection Turnstile using the signals arising from the check on the registration page (Section 12), under its own responsibility according to the provider; the check itself is performed by Cloudflare for us as a processor (Section 33.1)IP address, TLS fingerprint, browser identifier, widget identifierUSA

Your own integrations are not sub-processors of ours. If you connect an AI agent via the MCP interface (Section 24), this is a service selected by you for which you are yourself responsible.

33.3 Further recipients

Beyond this, we disclose personal data to tax advisers, legal advisers and auditors to the extent required by law, as well as to authorities and courts to the extent that we are legally obliged to do so.

Changes. We reserve the right to engage further sub-processors or to change them. Customers with whom a data processing agreement exists are informed by us in advance in accordance with that agreement; we keep this list up to date.


34. Transfers to third countries

34.1 Principle

Our permanent data holding is deliberately located in the European Union: the database including all accounts is located in Frankfurt am Main, the application app.klate.ai is run in the Frankfurt am Main region, email dispatch takes place from Ireland, the error events of the error diagnosis are stored in an EU project (Frankfurt am Main). For the object storage of the uploaded files we have specified Western Europe as the preferred storage location; according to the provider's information this is an optimisation specification and not the promise of a guaranteed storage location.

What is not processed in the Union is the AI requests (Section 21), the measured values of the loading performance (Section 8), the account data and delivery logs of the email dispatch (Section 26), the account and administrative data of the error diagnosis (Section 28), the connection data of the documentation domain (Section 10), the signals of the bot check at registration (Section 12), whose place of processing the provider does not fix to a region, as well as the retrievals by your browser described in Section 29; on this, see Section 34.2. We cannot currently confirm where our hosting provider stores the server log files (Section 6).

34.2 Where data nevertheless leaves the EU

ProcessingRecipientThird countrySafeguard
AI inference (Sections 21, 23)To the extent that we commission directly: OpenAI Ireland Limited and Anthropic Ireland, Limited (both EU); to the extent that execution takes place via the access credentials of the AI gateway: Vercel Inc. with the model providers as its sub-processors. The processing takes place in each case at the affiliated US companies of the model providers, whose programming interfaces are operated from the USAUSA (onward transfer by the provider)The transfer to our contracting parties established in the Union is not itself a third-country transfer. The safeguards under Art. 46 GDPR for the onward transfer to the US companies are ensured by the model providers by way of the data processing agreements underlying their engagement, depending on the access used, either our own contracts or those of Vercel Inc.; what is used in this respect are the Standard Contractual Clauses (Implementing Decision (EU) 2021/914). We do not base the processing on an adequacy decision (EU-US Data Privacy Framework). Further details in Section 21.4.
Forwarding of the AI requestsVercel Inc.USAStandard Contractual Clauses under the data processing agreement; Vercel Inc. is additionally certified under the EU-US Data Privacy Framework
Measurement of loading performance (Section 8)Vercel Inc.USAStandard Contractual Clauses under the data processing agreement
Account data, delivery logs and metadata of the email dispatch (Section 26)Plus Five Five, Inc. ("Resend")USAStandard Contractual Clauses; the provider is moreover certified under the EU-US Data Privacy Framework
Account, organisation and administrative data as well as support enquiries of the error diagnosis (Section 28)Functional Software, Inc. ("Sentry")USAWe accepted the provider's contractual addendum on data processing (Data Processing Addendum, version 5.1.0) on 5 September 2026 (Section 33.1); it contains the Standard Contractual Clauses (Implementing Decision (EU) 2021/914), modules 2 and 3. No adequacy decision: a certification of Functional Software, Inc. under the EU-US Data Privacy Framework has not been evidenced to us. The error events themselves are stored in the EU region (Frankfurt am Main).
Retrieval of a sample image in individual widgets created in the past (Section 29)Lorem PicsumUSAThe retrieval is carried out by your browser. We are not involved in this transfer as the commissioning party and cannot base it on safeguards under Chapter V GDPR. You can prevent it by restricting the loading of external images in your browser.
Payment processing from the point at which paid plans are enabled (Section 25)Our contracting party is Stripe Payments Europe, Ltd. (Ireland); the onward transfer is made to Stripe, Inc. or Stripe, LLCUSA (onward transfer by the provider)Stripe, LLC is certified under the EU-US Data Privacy Framework; in addition, the Standard Contractual Clauses under the data processing agreement apply.
Internal documentation domain (Section 10)Mintlify, Inc.USAMintlify, Inc. is not certified under the EU-US Data Privacy Framework. The provider incorporates into its terms of use for customers acting as businesses a contractual addendum on data processing with Standard Contractual Clauses; this forms part of our contract. What is affected is exclusively the connection data of the accesses to this domain as well as the sign-in and session data of the only person authorised to access it, no account, design or customer content.
Availability monitoring and status page (Section 28)Better StackUSA, to the extent that the processing does not take place in the EUStandard Contractual Clauses. What is affected is not any personal data of the users of the application, but only server log files of the visitors to the status page.
Redirection of the domains klate.io and getklate.com (Section 10)Porkbun LLCUSAThe access is made by your browser vis-a-vis an independent controller; connection data arises briefly.
Bot check at registration (Section 12)Cloudflare, Inc.USA (the provider does not fix the place of processing to a region; we assume possible processing in the USA)For the check on our behalf: Standard Contractual Clauses (Implementing Decision (EU) 2021/914) under the data processing agreement with Cloudflare, Inc. To the extent that Cloudflare processes the signals under its own responsibility to improve Turnstile, we are not involved in that transfer as the commissioning party and cannot base it on safeguards under Chapter V GDPR. The retrieval is carried out by your browser and only on the registration page.
Support and administrative accesses by our service providersamong others Vercel, Neon, CloudflareUSAStandard Contractual Clauses under the respective data processing agreements; in some cases additionally certification under the EU-US Data Privacy Framework

34.3 Note on the residual risk

For transfers to the United States that we base on Standard Contractual Clauses, we point out to you that, from the point of view of the European Union, the United States does not offer a generally adequate level of data protection and that US security authorities can, under certain conditions, access data without data subjects from the Union always having an effective legal remedy available.

34.4 Copy of the safeguards

On request at privacy@klate.ai we will tell you which safeguards the individual transfer is based on and will make the Standard Contractual Clauses available to you insofar as we are ourselves a party to them; otherwise we will name for you the place where they can be found at the respective provider.


35. Storage period and erasure

We store personal data only for as long as is necessary for the purposes stated or for as long as we are legally obliged to do so.

35.1 Overview

DataStorage period
Account, profile and sign-in dataUntil the account is erased
Language setting of your account (Section 13): language code or "automatic", time of the last changeUntil the account is erased
Proof of the confirmation of your registration (Section 26): time of activation and of the hand-over to the dispatch service provider, check value of the content, versions of the attached documentsUntil the account is erased
Time of last use (Section 12)Until the account is erased. It is a single value per account, overwritten on the first use on a later calendar day; no history is created.
Block record for an uploaded file (Section 17): time, case numberFor as long as the block lasts; when it is lifted, the record is deleted, at the latest together with the file. The file itself stays stored during the block (see the rows on uploaded files), and a retention order is in place for the workspace for the duration of the procedure (see the row on the audit log). The entries about the block and its lifting in the audit log expire after its period of 90 days; they keep the case number also after your account is erased.
Suspension record for an account or workspace (Sections 12 and 14): time, reason, ordering personFor as long as the suspension lasts; when it is lifted, the record is deleted. The entries about the suspension and its lifting in the audit log expire after its period of 90 days (see the row on the audit log). If your account is erased, an existing suspension record for your account, for your personal workspace and for the team workspaces deleted along with it ceases to exist, and the log entries about your suspension or about the suspension of those workspaces lose your identifier and the reason.
Session data including the IP address and user agent of the sessionThe session becomes ineffective upon expiry. The row containing the session identifier, IP address and user agent is deleted by a daily clean-up run 30 days after expiry of the session; it ceases to exist earlier upon erasure of your account or at your request under Section 37.
MCP access tokens and authorisation codes (Section 24)The hash value of an access token is deleted by a daily clean-up run 30 days after expiry or revocation. An authorisation code is deleted immediately upon its redemption, a code that is not redeemed 30 days after its expiry. The registration of an application to which no user has granted access within 30 days of the registration is deleted by the same clean-up run; a registration to which access has once been granted remains in existence without any details about your person.
Customers, projects and designs, each with all conversation paths, conversation contributions, project briefs and version states they containUntil you delete them; for automatically created version states see Section 16. If you delete a customer, a project or a design, we keep it together with everything it contains for 30 days and then delete it finally, unless a retention order ("legal hold", see the row on the audit log) is in place for the workspace; for the duration of such an order it remains marked as deleted and is finally deleted by the next clean-up run after the order is lifted. Within the period of 30 days you can have an accidental deletion reversed at privacy@klate.ai. For individually deleted conversation paths, conversation contributions and version states, the following row applies.
Tools, tool providers, widgets, forms, guideline cards, subagents as well as individually deleted conversation paths, conversation contributions, version states and commentsAre deleted immediately and finally upon deletion; restoration by us is not possible. The content of an individually deleted conversation path or conversation contribution remains contained in earlier version states of the design until those are deleted.
Uploaded files: directory entryRemains in existence for as long as the workspace exists. The entry belongs to the media library of the workspace, not to an individual design: deleting a design does not currently remove it, and a deletion function for individual entries does not exist in the application. Upon erasure of the workspace it is finally deleted; we delete individual entries at your request under Section 37. Envisaged clean-up, currently switched off: the application contains a daily run that identifies files which no design, avatar, logo and no widget of the workspace uses any more - not even in a restorable deleted state or a version snapshot - and would delete their directory entry 30 days after that finding; an uploaded file that was never used accordingly 30 days after upload. That run operates exclusively in dry-run mode: it identifies and logs, but marks and deletes nothing. For as long as that is so, it removes no entry and no file. We will amend this notice before we activate it.
Uploaded files: the stored file itselfIs not removed automatically. After deletion of the directory entry, the file can no longer be retrieved via the application, because no signed retrieval link is generated any more. We remove the file itself manually in the course of the erasure of your account or at your request under Section 37; an active automatic deletion run for the object storage does not currently exist (Section 35.2). The daily run described in the row above would remove the file from the object storage in the same operation, immediately before it deletes the directory entry - but it is switched off (dry-run) and removes nothing at present.
List of the files of a deleted account still to be removed (Section 35.2)When an account is deleted, we record the storage locations of the uploaded files that the manual work step under Section 35.2 still has to remove from the object storage. An entry contains only the storage location (which includes the identifier of the workspace), no name and no email address, and is deleted as soon as the file has been removed.
Export files from the export function (Section 37) and the associated job entry (who started the export for which workspace, and when)The export file is kept in our private object storage and can be downloaded for 7 days after it was completed, and only by the person who started the export. Thereafter the next daily clean-up run deletes first the file and then the job entry. If a newer export by the same person for the same workspace is completed before then, we delete the older one as a rule at that point, and at the latest with the next daily clean-up run. If an export may contain a file that we block later, the application no longer generates a download link for it from the time of the block (a link generated before loses its validity at the latest ten minutes after it was generated), and an export still in progress is aborted (Section 17). An export that is still not completed 24 hours after it was started is aborted at the latest by the next daily clean-up run; an aborted or failed export is deleted, with all parts already written, at the latest by the first daily clean-up run that takes place more than 7 days after it was started. None of these deletions takes place for as long as a retention order is in place for the workspace.
Conversations with the AI assistant including the attached images30 days after the last use (last message or last change to the conversation), thereafter final deletion by a daily clean-up run, unless a retention order is in place for the workspace. Attached images are thereafter no longer retrievable through the application, because no signed retrieval link is generated any more; the stored file itself is removed by a separate deletion run for the object storage that is not yet active (see the row on the stored file itself). A conversation that you yourself started can be deleted by you yourself at any time beforehand, during a suspension of your account or of the workspace on a message to privacy@klate.ai (Section 21.7).
Your answers from the setup interview on first start (your own free-text details from which the first draft is generated)30 days after the first draft has been generated or the process has been aborted, thereafter removal of the answers by a daily clean-up run, unless a retention order is in place for the workspace. The process record itself, namely the time, the status and the identifiers and names of the generated draft, remains in existence without the answers until your account is erased.
Memory entriesUntil you delete the individual entry, delete all entries or your account is erased. Merely switching off the memory ends the use of the entries but does not delete them; for that, use the "Alle Einträge löschen" button (in the English version "Delete all entries") in the settings (during a suspension of your account, on the page on which we show you the suspension).
Notifications30 days from the time they arise, thereafter automatic deletion by a daily clean-up run, read as well as unread, and also where the associated content still exists
CommentsUntil the associated content or the account is deleted
InvitationsDeletion by the next daily clean-up run once 30 days have passed since lapse, rejection, withdrawal or redemption. For invitations to a team workspace and for permissions, deletion is suspended for as long as a retention order is in place for the workspace. An accepted permission remains in existence for as long as the access exists.
Approval requests ("Abnahmeanfragen") and the tokens of the approval linksThe token is removed from the record upon the decision on the request, and at the latest, unless a retention order is in place for the workspace, by the next daily clean-up run after 14 days have elapsed since its creation; an expired token can no longer be used even before its removal, a removed token not at all. The record of the decision, namely the email address of the approving person, the decision and the time, remains in existence for as long as the associated draft exists; if the draft is deleted, the record is finally deleted 30 days later together with the draft. If the account of the requesting person is dissolved, the personal reference of the record is removed and the transaction remains in existence in anonymised form.
Audit log (Section 20)90 days from the time the entry arises, thereafter automatic deletion by the daily clean-up run. This applies equally to all entries, including the entries on accesses by automated agents (Section 24) and on the clean-up runs themselves. Exception: workspaces for which a retention order ("legal hold") is in place, for example because of a legal dispute, an enquiry by an authority, a security investigation or the review of a blocked file (Section 17); their entries are not deleted for the duration of the order and lapse with the next clean-up run after it is lifted. If your account is erased within the 90 days, we remove your attribution as the acting person beforehand (Section 35.2). Records that are subject to retention obligations under commercial or tax law are not part of the audit log but are held in the billing records and credit movements of the following rows; they remain unaffected by this period.
History entries on approvals and phase changesFor as long as the associated draft or the associated project brief exists; if that content is deleted, they are finally deleted 30 days later together with it. Upon erasure of the account, the personal reference is removed and the transaction remains in existence in anonymised form.
AI consumption and credit movementsThe movements themselves (amounts, times, model, workspace) until expiry of the retention periods under commercial and tax law (§ 147 AO, § 257 HGB). Your attribution as the acting person is removed by the daily clean-up run 24 months after the entry arises, unless a retention order is in place for the workspace; upon erasure of the account it is removed earlier.
Billing records, invoices, accounting vouchersIn accordance with the statutory periods (§ 147 AO, § 257 HGB, § 14b UStG)
Whether you ordered as a consumer or as a business, and the verification status of your VAT ID (Section 25)For as long as the workspace exists; updated with subscription orders and with paid subscription invoices. When your account is deleted we remove them for your personal workspace and for the team workspaces deleted along with it (Section 35.2). Stripe stores the billing address and the VAT ID themselves (Section 25).
Termination and withdrawal declarations from the self-service functions (Section 9.2)We retain the declaration with its content, your name, your email address, an address given voluntarily as well as the date and time of its receipt (Zugang). An automatic deletion period does not exist. The declaration is a received commercial letter (§ 257 Abs. 1 Nr. 2 HGB, § 147 AO) and at the same time your proof that you have ended the contract; we therefore do not delete or anonymise it even if you request erasure under Section 37 (Art. 17(3)(b) and (e) GDPR). Your right of access remains unaffected: on request we will provide you with the declaration in full.
Time of dispatch and period of a payment request (Section 26)Until the payment arrives or the paid plan ends; we then delete both details. When your account is deleted, we remove them for your personal workspace and for the team workspaces deleted with it (Section 35.2). The audit log entry about the dispatch expires after that log's period (see the row on the audit log).
Queue for the (renewed) delivery of the acknowledgements of receipt and contract confirmations and of the payment requests (Section 26)The entry contains neither your email address nor the content of the email, but a reference to your declaration, your order, your account or the invoice and the workspace, the number of delivery attempts, a technical error code and the times. It is deleted by a daily clean-up run 90 days after the email was delivered or we stopped the delivery attempts; in the course of an erasure under Section 37 we delete it earlier.
Order records (Section 25)Completed order: We retain the order record for as long as we need it to fulfil retention obligations under commercial and tax law (§ 147 AO, § 257 HGB) or claims arising from the order can still be asserted (§§ 195, 199 BGB); an automatic deletion period does not currently exist for it. This also applies to what you stated in the order step, as recorded in it. If you request erasure under Section 37, we remove the attribution to your account; the order itself remains as a billing transaction together with these details (Art. 17(3)(b) and (e) GDPR). A scheduled order that has not yet been carried out is cancelled in that case if it is for your personal workspace or for a team workspace whose only member you are and which we therefore delete as well (Section 35.2); an order you placed for any other team remains in place for the team, only without the attribution to your account. The order record also includes the time, check value and document versions of the contract confirmation (Section 25); an order whose contract confirmation we have handed over counts as completed here. Order not completed (for example an abandoned payment page or a failed payment, in each case without a contract confirmation handed over): a daily clean-up run deletes the order record 30 days after it was created, unless a retention order is in place for the workspace. If you request erasure under Section 37 before then, we delete it at once if the order was started more than 48 hours ago; a more recent one is decoupled from your account as for a completed order, because the order can then still be completed. Your right of access remains unaffected.
Measured values of the interface performance (Section 28)90 days, thereafter automatic deletion; upon erasure of your account already earlier (Section 35.2)
Measured values of the loading performance (Speed Insights, Section 8)30 days at the processor, thereafter automatic deletion
Error events of the server-side error diagnosis (Section 28)Deletion by the processor upon expiry of the period applicable to our plan; for the "Developer" plan used by us it is, according to the provider's information, 30 days. The provider's backup copies expire, according to its information, 90 days after their creation.
Feedback from within the application (Section 27)The content of the feedback (free text, type, page and, where applicable, the technical details and the rough location indication transmitted with your consent) remains stored indefinitely as our own product research. Your attribution as the reporting person (account identifier and email address) is removed by us upon erasure of your account or at your request at any time; a screenshot sent with the feedback is deleted in the process. If you wish the text itself to be deleted, let us know at privacy@klate.ai.
Server log files (Section 6)Up to 30 days at our hosting provider, according to its information; thereafter no longer retrievable by us either. We do not store them separately.
Email correspondenceUntil the matter has been dealt with; in the case of business letters, in accordance with the statutory periods

35.2 Erasure of your account

You can delete your account yourself in the settings at any time ("Konto löschen", in the English version "Delete account", on the account page); to confirm, you enter the email address of your account. You can equally request the complete erasure of your account at privacy@klate.ai. While your account (Section 12) or a workspace you belong to (Section 14) is suspended, deletion in the settings is not possible; you then request it at privacy@klate.ai. Before a deletion in the settings we show you which team workspaces and plans are affected and point you to the export function (Section 37).

What we delete immediately. With the deletion we immediately and definitively remove your identity, sign-in and session data, your profile and memory data including the time of last use, the record of your acceptance of the terms of use (Section 12), the record of the confirmation of your registration (Section 26), your conversations with the AI assistant, your notifications and comments, your permissions, memberships and connections, the invitations into team workspaces you issued, the measured values of the interface performance attributed to your user identifier (Section 28) as well as the content of your personal workspace and of the team workspaces of which you are the only member. A restoration is not possible thereafter. On the device on which you delete your account in the settings you are signed out immediately. On other devices the sign-in can persist for up to five minutes because of the cache under Section 7.2. Your deleted content and memberships are no longer available there, and from the deletion onwards we refuse changes, file uploads, exports and payment transactions there.

Files. The files stored in the object storage of your personal workspace and of the team workspaces deleted along with it, the files of the exports you started, and the screenshots of your feedback (Section 27) are removed by us in a separate, manual work step; until then we record their storage locations in a list (Section 35.1). From the deletion onwards they can no longer be retrieved via the application. The daily clean-up run described in Section 35.1 exists in the application but operates in dry-run mode and does not currently replace that manual step.

Images in workspaces that remain. Images that you attached to your conversations with the AI assistant in a workspace that remains after the deletion (for example in another person's team workspace) likewise can no longer be retrieved via the application from the deletion onwards. Their files are not on that list: they are removed by the separate deletion run for the object storage (Section 35.1, row on the conversations with the AI assistant), which is not yet active, or at your request under Section 37. Neither applies where the same image is also contained there in a conversation of another person: it remains retrievable through that conversation, and the file remains. For an image that was first stored in the workspace less than one hour before the conversation was deleted (with your account or before it), the file may remain allocated to the workspace's storage; that deletion run then does not pick it up, and we remove it at your request under Section 37.

Running plans. If a paid plan is running for your personal workspace or for a team workspace deleted along with it, we end the subscription with our payment service provider (Section 25) immediately upon the deletion. If you last agreed to our terms of use in a version dated before 24 September 2026, a termination takes effect under that version only at the end of the current billing period; for as long as such a subscription is running, the deletion in the settings is therefore possible only after it has ended, and the application points this out to you before the deletion. We do not delete the payment account with the payment service provider, holding among other things your email address, your account identifier, the name of the workspace and the invoices, because we must retain invoices for the statutory periods (Section 25).

Confirmation. After a deletion in the settings we send you a confirmation to the address your account had until then (Section 26).

If deletion in the settings is not possible. In individual cases the application refers you to privacy@klate.ai instead of deleting; we then handle your request under Section 37. Until then, nothing is deleted.

Feedback from within the application (Section 27) is not deleted by us but decoupled from your person: your account identifier and email address are removed, a screenshot sent with the feedback is deleted, and the text of the feedback remains in existence as product research (Section 35.1).

What we anonymise instead. Entries which we are not permitted to delete for reasons of record keeping or for legal reasons, in particular approval and history entries, billing and credit movements as well as the order records of completed orders (Section 25), are decoupled from your person by us: the personal reference is removed, the transaction itself remains in existence. We keep the entry of your workspace itself, to which these billing records are attached, for the same reason, but without its name or image. Its identifier is derived from your former account identifier. If you had a payment account with our payment service provider, the entry and the billing records attached to it remain connected to that account through this identifier; that account still contains your account identifier and your email address (see "Running plans"). In this way we fulfil at the same time the erasure obligation under Art. 17 GDPR and the retention obligations under commercial and tax law. Likewise, we decouple from your person the entries of the audit log that still exist at the time of the erasure of the account; in addition, they are deleted after the period of 90 days in Section 35.1.

What we retain in person-related form unchanged. A third group is neither deleted nor anonymised: termination and withdrawal declarations under Section 9.2. With these, it is precisely the personal reference that constitutes the proof that you ended the contract, so that anonymisation would destroy the purpose of the retention. Art. 17(3)(b) and (e) GDPR exempt them from the erasure obligation. Further details in Section 35.1.

One exception with a short period. The counter values under Section 6 are not separately removed upon erasure of the account; they lapse at the latest around 48 hours after the last request from the same source; in the case of continuing requests from the same source, this period is extended accordingly.

Content in other customers' workspaces. Content that you have created or uploaded in a team workspace of another customer or, through a share, in the workspace of another person (Section 17) belongs to that workspace and is not removed upon erasure of your account; your authorship is, however, decoupled, and your membership or share ends. If you are the owner of a team workspace that has further members, ownership must be transferred beforehand or the other members must be removed; until then, deletion in the settings is not possible, and in the case of an erasure request to privacy@klate.ai we will agree the procedure with you. A team workspace of which you are the only member is deleted together with your personal workspace.

Retention order. If a retention order ("legal hold", Section 35.1) is in place for a workspace, the daily clean-up runs whose rows in Section 35.1 name this exception are suspended for that workspace until the order is lifted; the periods stated there then continue to run with the next clean-up run. Whatever is deleted together with a customer, a project or a design (for example comments, history entries and approval records) remains for as long as that content does. The other rows, for example notifications, apply during such an order as well.

35.3 Backup copies

Deleted data may still be contained in backup copies of our database for a limited transitional period. These backup copies serve exclusively for restoration after an outage, are not analysed for other purposes and expire automatically upon expiry of their retention period.


36. Data security

We take technical and organisational measures in accordance with Art. 32 GDPR. The principal ones are:

  • Encrypted transmission. All connections to our offerings take place exclusively via TLS. For the application app.klate.ai and the website klate.ai we additionally instruct browsers, via the Strict-Transport-Security header, to access them only in encrypted form.
  • Separated workspaces. Every request is checked on the server side against the actual permission of the account. If the permission is missing, the response does not reveal whether the requested content exists.
  • Private file stores. Uploaded files are held in stores that are not publicly accessible and can be retrieved exclusively via short-lived, signed links following a permission check.
  • Password protection. Passwords are stored exclusively as a cryptographic hash value. Access tokens of the MCP interface are stored by us as a SHA-256 hash value.
  • Limitation of the request load. Both in the network and in the application we limit the number of requests per source in order to ward off attacks and misuse.
  • Protection against malicious code in the browser. In the application app.klate.ai and on the website klate.ai we use a Content Security Policy as well as further security headers, among others X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.
  • Separation of particularly sensitive data. Feedback is held in a separate database schema, separated from the product data.
  • Traceability. Security-relevant operations are logged (Section 20).
  • Secrets management. Access credentials for service providers are held exclusively in the secrets management of our platform and never in the source code.
  • Monitoring. Availability and errors are monitored on an ongoing basis, so that malfunctions are detected promptly.
  • Limited group of persons. Administrative access is currently held exclusively by the Geschäftsführer (managing director). Further persons working for us are bound to confidentiality before any access and receive only the rights necessary for their task.

Personal data breaches. If we become aware of a breach of the protection of personal data, we assess it without undue delay (unverzüglich). To the extent that we are the controller, we report it where necessary within 72 hours to the competent supervisory authority under Art. 33(1) GDPR and, where there is a high risk to your rights and freedoms, notify the data subjects under Art. 34 GDPR. To the extent that we are the processor, we inform the customer concerned without undue delay and support that customer with its obligations under Art. 33 and 34 GDPR.

Please note that, despite all measures, the transmission of data over the internet is never absolutely secure.


37. Your rights

You have the following rights vis-a-vis us. Exercising them is free of charge for you.

  • Access (Art. 15 GDPR). You can request information as to whether and which personal data we process about you, and receive a copy of that data.
  • Rectification (Art. 16 GDPR). You can request the rectification of inaccurate data and the completion of incomplete data.
  • Erasure (Art. 17 GDPR). You can request the erasure of your data, to the extent that no retention obligation or other ground for exclusion stands in the way. You can also delete your account yourself in the settings. When this is exceptionally not possible, for example during a suspension, and how we implement an erasure is described in Section 35.2.
  • Restriction of processing (Art. 18 GDPR). You can request that we restrict the processing of your data.
  • Data portability (Art. 20 GDPR). You can receive the data that you have provided to us in a structured, commonly used and machine-readable format, or request its transmission to another controller, to the extent that this is technically feasible. The owner and the administrators of a workspace can in addition export its content themselves at any time in the settings, on every plan and free of charge, also during a suspension of the workspace (Section 14). If your account is suspended, you export on the page on which we show you the suspension, and then only your personal workspace and a team workspace of which you are the owner (Section 12). The export is made as JSON files together with the uploaded files (without a file we have blocked under Clause 21 of the Terms of Use, for as long as the block lasts; Section 17), in one or, for a large workspace, several ZIP files (details in the Terms of Use, section "Data Export and Deletion after the End of the Contract"). The uploaded files are included as they are stored with us. Images that the application already reduces in size and re-encodes on upload (as a rule in the WebP format) are therefore included only in that version; we do not store the original image. The export contains your own conversations with the AI assistant, not those of other members of the workspace. How long the export file is kept is stated in Section 35.1.
  • Objection (Art. 21 GDPR). See the separate Section 38.
  • Withdrawal of a consent (Art. 7(3) GDPR). If you have given us a consent, you can withdraw it at any time with effect for the future. The lawfulness of the processing carried out on the basis of the consent up to the withdrawal is not affected by this. Specifically, you withdraw: the consent to the AI memory by switching the feature off in the settings, during a suspension of your account on the page on which we show you the suspension (Section 22); so that the entries already stored are deleted at the same time, additionally select the "Alle Einträge löschen" button (in the English version "Delete all entries") there, or write to us at privacy@klate.ai; the consent to the technical details accompanying a piece of feedback by message to privacy@klate.ai (Section 27); and the consent to an MCP connection by revoking it in the settings (Section 24); during a suspension of your account your connections are already disconnected (Section 12).
  • Complaint to a supervisory authority (Art. 77 GDPR). See Section 39.

How to exercise your rights. Write to privacy@klate.ai or by post to the address named in Section 2.1. We will answer your request without undue delay, at the latest within one month of receipt. If your request is complex, we may extend this period by up to two further months; we will then inform you within one month about the extension and the reasons for it.

Identity verification. In order to prevent unauthorised persons from obtaining information about your data, we may, in the case of justified doubts, request additional information to confirm your identity. In doing so we do not request more than is necessary to establish your identity.

If your data was entered by one of our customers, please contact that customer first; see Part D.


38. Right to object

Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR.

If you object, we will no longer process your personal data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling to the extent that it is related to such direct marketing. If you object to processing for direct marketing purposes, we will no longer process your personal data for those purposes. As at the date of this notice, we do not carry out any direct marketing (Section 11).

Address your objection, in no particular form, to: privacy@klate.ai

Which processing operations we base on Art. 6(1)(f) GDPR is stated with the respective processing operation; they are Sections 6, 8, 9, 10, 12, 14, 15, 19, 20, 21, 23, 24, 27, 28, 29, 30 and 32.


39. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement.

The supervisory authority competent for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit Postal address: Postfach 31 63, 65021 Wiesbaden Street address: Wilhelmstraße 7, 65185 Wiesbaden Telephone: +49 611 1408-0 Email: poststelle@datenschutz.hessen.de Internet: https://datenschutz.hessen.de


40. No automated decision-making in individual cases

A decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, does not take place (Art. 22(1) GDPR).

By way of clarification:

  • The AI features (Section 21) generate proposals which you accept, change or discard. They do not decide anything about you.
  • The check of the email domain at registration (Section 12) is a simple comparison against a fixed list of providers of disposable addresses. No assessment of your person takes place.
  • The plan and credit logic (Section 25) follows fixed rules and the responses of the payment service provider. It does not assess you.

We operate no scoring, no creditworthiness, fraud or trustworthiness assessment and no profiling for advertising purposes.


41. Whether you are required to provide your data

There is no statutory obligation to provide us with personal data. For the conclusion and performance of the usage contract, however, individual details are necessary; without them we cannot conclude or perform the contract:

  • Necessary for an account: name, email address and password as well as the confirmation of the email address. Without these details we cannot set up an account and cannot provide the service.
  • Necessary for paid plans: the details necessary for payment processing and invoicing. Without them, paid use is not possible.
  • Voluntary: all further details, in particular the profile details (Section 13), the answers in the setup assistant (Section 23), the use of the AI memory (Section 22) and the technical details accompanying a piece of feedback (Section 27). If you do not provide these details, no disadvantages arise for you; individual convenience features are then not available.

42. Processing for a different purpose

If we intend to process your personal data for a purpose other than that for which we collected it, we will inform you before that further processing about the new purpose and will make available to you all further information relevant under Art. 13(2) GDPR (Art. 13(3) GDPR).


43. Minors

Klate is a tool for professional use and is not addressed to children and young people under 16 years of age. We do not knowingly collect personal data from persons under 16 years of age. Should we become aware that an account has been created by a minor contrary to this requirement, we will delete it.


44. Changes to this privacy notice

We adapt this privacy notice if our service, our processing operations or the legal situation change. The version published on this page is always the governing one; the date given above indicates the respective status (Stand).

In the case of material changes that affect your rights, we will additionally inform signed-in users by email or by a clear notice within the application before the change takes effect.

As at: 8 October 2026 · Version 2.12