klate
Legal

Information under the EU Data Act

As at: 8 October 2026 · Version 1.3

DeutschEnglish

Convenience translation. This English version is a non-binding convenience translation provided for your convenience only. The legally binding version of this document is the German original, Informationen nach der Datenverordnung. In the event of any discrepancy or dispute, the German version prevails.

This page contains the information that we, as the provider of Klate, make available under Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data ("Datenverordnung", in English the "Data Act"). Clause 23 of the AGB refers to it.

The contractual rules on export, switching and deletion are set out in the AGB, above all in Clause 23 of the AGB, and in Clause 11 of the Leistungsbeschreibung (Annex 1). This page restates them and adds the information that the Data Act additionally requires. The information applies to all plans, to consumers and businesses alike.


Contents

  1. What this page is about
  2. Switching and export: the procedure
  3. What the export contains
  4. Formats and standards
  5. Register of data structures
  6. Known restrictions
  7. Charges
  8. Jurisdiction and location of the infrastructure
  9. Measures against unlawful governmental access
  10. Contact and updates

1. What this page is about

The Data Act is meant to make it easier for customers of data processing services to switch to another provider or to an environment of their own. For that purpose you will find here:

  • in Sections 2, 3, 4 and 6 the procedure for switching and export, the available methods and formats, and the restrictions and technical limitations known to us (Art. 26(a) of the Data Act);
  • in Section 5 the register of the data structures and data formats in which your exportable data is available, with the standards used (Art. 26(b));
  • in Section 7 the charges (Art. 29);
  • in Sections 8 and 9 the jurisdiction to which the IT infrastructure used for Klate is subject, and our measures against unlawful governmental access (Art. 28(1)).

2. Switching and export: the procedure

To switch, you do not have to ask us first or wait for any period to run. You export your content yourself, continue to use it in the new service or in your own environment, and end the contract when you are ready. You decide the order.

2.1 Export in the application

You start the export in the application at app.klate.ai: for your personal workspace in your account settings, for a team workspace in the team's settings, in each case in the section "Workspace-Daten exportieren" (in the English version "Export workspace data"). The application is available in German and in English. If your account is suspended under Clause 21 of the AGB, you find the export on the page on which we show you the suspension.

  • The export is available to you at any time, also during the contract and in the free plan, and it is free of charge (Clause 23 of the AGB).
  • A team workspace can be exported by the team's owner and its administrators, not by editors or viewers. This also applies while the workspace is suspended under Clause 21 of the AGB. If, however, your account is suspended, you can export your personal workspace and a team workspace of which you are the owner, but not a team that you only manage as an administrator.
  • The export is built in the background. As soon as it is ready, the application offers it for download and we notify you by email. Only the person who started it can download it, for at most 7 days from its completion. If a newer export of the same person for the same workspace is finished before then, it generally replaces the older one, which can then no longer be downloaded. When we delete export files, and when a deletion does not take place, for example while a retention order is in place, is set out in the privacy notice, section "Storage period and erasure".
  • A large workspace is delivered in several ZIP files (Section 4). Such an export is built step by step and only continues while you have the export page open or open it again. An export that is not finished 24 hours after it was started is no longer completed and is aborted by the next daily clean-up run at the latest; you do not have to wait for that run to start a new export.

2.2 Other routes

  • In the Pro and Team plans you can also read out your content in structured form with an AI agent of your own via the MCP server (Clause 5 of the Leistungsbeschreibung). The MCP server is not available in the Free plan.
  • If you use Klate for business purposes, we additionally provide you with a structured extract of your content on request at privacy@klate.ai under the data processing agreement (Annex 4).
  • We answer questions on the export format at support@klate.ai (Clause 23 of the AGB).

2.3 Termination and notice periods

The export does not require a termination. For ending the contract, Clause 11 of the AGB provides:

  • You can end the free plan and the contract as a whole at any time, for example by notifying us of the ending in text form (Clauses 11.1 and 11.5 of the AGB).
  • You can terminate a paid plan at any time with effect from the end of the current billing period; a billing period lasts one month. There is no minimum term and no further notice period (Clause 11.2 of the AGB). The workspace then moves to the free plan without any content being deleted, and the export remains available (Clause 11.4 of the AGB). While a paid plan is running, ending the contract as a whole in text form also only takes effect at the end of the current billing period. If you instead delete your account in the settings, the contract ends immediately, and a running plan with it, without a refund for the rest of the paid billing period (Clause 11.5 of the AGB); export your content first (Section 2.5).

The Data Act permits a notice period of at most two months for initiating a switch (Art. 25(2)(d)). The periods under the AGB are shorter; the export itself is subject to no period at all.

2.4 Transitional period

If you wish to switch to another service or to an environment of your own, at your request we keep Klate available in unchanged quality after a termination for a transitional period of up to 30 days after the ending (Clause 23 of the AGB). You tell us of this request in text form, for example by email to support@klate.ai (Clause 24.1 of the AGB), ideally together with the termination.

The Data Act limits the transitional period to a maximum of 30 calendar days (Art. 25(2)(a)). It also provides that the provider may set a longer transitional period of at most seven months where the statutory period is technically unfeasible (Art. 25(4)), and that the customer may extend the transitional period once (Art. 25(5)).

2.5 After the end of the contract

Under Clause 23 of the AGB you have read and export access to your content for at least 30 days after the ending if the contract ends through a termination by us, through a discontinuation pursuant to Clause 14.2 of the AGB, through the ending of the free plan pursuant to Clause 11.1 of the AGB or through your termination in text form; thereafter we delete the account. If you end the contract yourself by deleting your account, no access exists after that; export your content beforehand.

The Data Act requires, after the transitional period, a period of at least 30 calendar days in which you can still retrieve your data (Art. 25(2)(g)), and thereafter the complete erasure of the exportable data (Art. 25(2)(h)). How we delete your content after the access ends is governed by Clause 23 of the AGB; for personal data, Annex 4 and the privacy notice, section "Storage period and erasure", apply in addition.


3. What the export contains

The export contains the content of the workspace, ordered by customer records and projects:

  • the customer records with their settings (name, colours, logo, permitted email domains);
  • the projects with their settings (chat title and tagline, persona, default agent, colours, background);
  • the designs with all conversation paths and turns, including the assignment of guidelines to turns;
  • the briefs with their saved versions;
  • the guidelines;
  • the tools and the tool providers;
  • the subagents;
  • the widgets;
  • the forms;
  • the comments on designs and projects;
  • the version history of the designs and the briefs, and the history of their phases and approvals;
  • the history of the conversations with the assistant that the exporting person started in this workspace, with the images attached to them;
  • the uploaded files of the media library, as they are stored with us (Section 6), with an indication of where they are used;
  • the name of the workspace and the additional brief fields created for it.

Each entry comes with its identifier, its timestamps and, where we store them, the identifiers of the persons who created it or last changed it. Approvals and the history of phases also contain the email address of the person who was asked for approval or who acted. Media that you embedded via an internet address are included as that address; the file itself is not held by us (Clause 11 of the Leistungsbeschreibung).

Digital assets. Klate operates no applications, assistants or runtime environments for you; a design is never executed (Clauses 1.2 and 12 of the Leistungsbeschreibung). Beyond the content and files listed above there are therefore no digital assets that would have to be transferred in a switch.

Not included are:

  • our internal audit and security logs (Clause 23 of the AGB);
  • conversations with the assistant that other members of the workspace started; they are those members' personal data;
  • access and sharing settings: memberships and roles, shares, share links and invitations;
  • billing, credit and usage data;
  • content that is marked as deleted;
  • an uploaded file we have blocked under Clause 21 of the AGB, for as long as the block lasts. An export already created that could contain it is withdrawn with the block; a new export is possible at any time;
  • credentials such as the tokens of approval links, and our internal cost figures for AI requests;
  • your account data (name, email address, settings), the assistant's memory entries and your notifications. You can request access to your personal data and its portability under the privacy notice, section "Your rights".

4. Formats and standards

The export is an archive in ZIP format, with the ZIP64 extensions for large archives. A large workspace is delivered in several ZIP files: each is a complete archive, their paths do not overlap, and if you extract all parts into the same folder you get the whole export. The first part always contains all JSON documents.

  • Structured content: JSON according to RFC 8259, character encoding UTF-8.
  • Timestamps: ISO 8601 in Coordinated Universal Time (UTC), for example 2026-09-24T09:30:00.000Z.
  • Checksums: SHA-256, hexadecimal, for every file under files/ (Section 5.3).
  • Explanation: every archive contains a file README.txt that explains the layout briefly in English.

Uploaded files are included in the file format in which they are stored with us, with their media type and the following file extension. These are the ten file types that can be uploaded under Clause 7.4 of the Leistungsbeschreibung; images attached to conversations with the assistant have one of the four image types.

Media typeFile extension
image/png.png
image/jpeg.jpg
image/gif.gif
image/webp.webp
video/mp4.mp4
video/webm.webm
audio/mpeg.mp3
audio/wav.wav
audio/ogg.ogg
audio/webm.webm

A file that is stored with us with any other media type is included unchanged with the file extension .bin; manifest.json names its media type (Section 5.3).

We know of no open interoperability specification and no harmonised standard for conversation designs. The archive therefore uses a layout of its own with the format identifier klate.workspace-export, format version 1. It rests exclusively on the open standards named above and is described in Section 5.


5. Register of data structures

This register describes every file of the export and the fields of its documents. It is the register under Art. 26(b) of the Data Act to which Clause 23 of the AGB refers.

5.1 Layout of the archive

PathContent
manifest.jsonDirectory of the archive: format identifier and version, scope, number of objects per kind, all documents and all files with size and SHA-256 checksum
README.txtShort explanation of the layout in English
workspace.jsonThe workspace and its additional brief fields
media.jsonThe media library: one entry per uploaded file
customers/<name>--<id>/customer.jsonA customer record with its tool providers and the customer-wide tools, forms, widgets and subagents
customers/<name>--<id>/projects/<name>--<id>/project.jsonA project with brief, guidelines, the project's tools, forms, widgets and subagents and the comments on the project
customers/<name>--<id>/projects/<name>--<id>/designs/<name>--<id>.jsonA design of a project
customers/<name>--<id>/designs/<name>--<id>.jsonA design that is not assigned to a project
customers/<name>--<id>/ai-conversations/<id>.jsonOne of your own conversations with the assistant
files/media/<id>.<ext>An uploaded file
files/ai-attachments/<sha256>.<ext>An image attached to one of your own conversations with the assistant

<name> is a short form derived from the name, made of lower-case letters, digits and hyphens, at most 40 characters long (untitled if nothing is left). <id> is the object's identifier and makes every path unique. <ext> is the file extension according to Section 4, or .bin for any other stored media type.

5.2 General rules

  • Every JSON document except workspace.json contains the field formatVersion.
  • Identifiers are strings. They do not change, and objects refer to one another through them, for example with customerId, projectId, mediaId or guidelineId.
  • Timestamps follow Section 4. A missing value is generally null; in messages[].meta and in the embedded structures of Sections 5.4, 5.5 and 5.7, fields that are not set may also be absent altogether.
  • Fields that we store as JSON text, such as the content of a turn or a brief, the fields of a form or the structure of a widget, are embedded as a JSON value. A stored value that cannot be read as JSON appears there unchanged as a string.
  • This register describes the current structure. Content that was stored before a structure changed may contain individual fields in their earlier form.

5.3 Documents and objects

The column "Object" names the document, or the name under which the object appears in its parent object; [] marks a list of such objects. The value lists of individual fields are in Section 5.6.

ObjectMeaningFields
manifestContent of manifest.json. workspace is the workspace as in workspace.json; exportedByUserId the identifier of the exporting person; snapshotAt the time at which the export was requested (files uploaded later are not included)format, formatVersion, exportId, exportedAt, snapshotAt, workspace, exportedByUserId, scope, counts, documents, files
manifest.scopeScope of the export in words (English): the contractual basis, which conversations are included, what is not included, and the note on multi-part archivescontract, aiConversations, excluded, parts
manifest.countsNumber of objects included per kindcustomers, projects, designs, paths, turns, turnGuidelineLinks, briefs, briefVersions, briefFieldDefinitions, guidelines, tools, toolProviders, subagents, widgets, forms, comments, designVersions, approvals, lifecycleEvents, aiConversations, aiMessages, mediaFiles, aiAttachmentFiles
manifest.files[]Every file under files/: path in the archive, kind (media or ai-attachment), identifier of the source, media type, size in bytes and SHA-256 checksumpath, kind, sourceId, mime, bytes, sha256
workspace.jsonThe workspace and its additional brief fieldsworkspace, briefFieldDefinitions
workspaceThe workspaceid, name, kind
briefFieldDefinitions[]An additional brief field created for the workspaceid, name, description, position, createdAt
customer.jsonA customer record; the lists contain the customer-wide entries that are not assigned to a projectformatVersion, customer, projects, toolProviders, tools, forms, widgets, subagents
customerThe customer record with name, colours, logo (as a file identifier or an internet address), the internal-only marker and the permitted email domainsid, name, brandColor, darkAccentColor, logoMediaId, logoUrl, internalOnly, allowedEmailDomains, createdByUserId, updatedByUserId, createdAt, updatedAt
projects[]Reference to a project of the customer record and the path of its documentid, name, path
project.jsonA projectformatVersion, project, brief, guidelines, tools, forms, widgets, subagents, comments, designs
projectThe project with the settings of the chat, the persona, the default agent and the coloursid, customerId, name, chatTitle, chatTagline, personaName, personaAvatarMediaId, personaAvatarUrl, defaultAgentName, defaultAgentAvatarMediaId, defaultAgentAvatarUrl, accentColorOverride, darkAccentColor, chatBackgroundPattern, createdByUserId, updatedByUserId, createdAt, updatedAt
briefThe project's brief (null if none has been created) with its content (Section 5.5), its versions, the history of its phases and its approvalsid, phase, content, updatedByUserId, createdAt, updatedAt, versions, lifecycleEvents, approvals
brief.versions[]A saved version of the briefid, label, phase, content, createdBy, createdAt
guidelines[]A guideline: when it applies, what to do then, and whyid, when, then, why, position, createdAt, updatedAt
designs[]Reference to a design of the project and the path of its documentid, title, path
toolProviders[]A tool providerid, name, domain, logoMediaId, logoUrl, color, createdAt
tools[]A tool from the library with its description, its parameters (params, JSON), examples and technical detailsid, projectId, name, displayName, description, whenToUse, providerKey, providerId, logoMediaId, logoUrl, kind, endpoint, method, transport, params, returns, exampleArgs, exampleResult, sideEffect, idempotent, confirmation, confirmationPrompt, errorFallback, loadingMessage, timeLimitMs, auth, environment, dataSensitivity, owner, status, tags, notes, createdAt, updatedAt
forms[]A form; fields is the list of its fields (Section 5.5)id, projectId, name, submitLabel, fields, createdByUserId, updatedByUserId, createdAt, updatedAt
widgets[]A widget; root is its structure, variables its example values (Section 5.5)id, projectId, name, status, templateId, variables, root, createdByUserId, updatedByUserId, createdAt, updatedAt
subagents[]A subagentid, projectId, name, avatarMediaId, avatarUrl, colorTag, createdAt
comments[]A comment; a reply refers with parentId to the comment it answersid, parentId, anchorType, anchorId, authorUserId, body, resolvedAt, resolvedBy, createdAt, updatedAt
approvals[]A request for approval of a design or brief and its decisionid, status, requestedBy, approverEmail, approverUserId, note, createdAt, expiresAt, decidedAt, decidedBy
lifecycleEvents[]An entry in the history of the phases of a design or briefid, kind, fromPhase, toPhase, actorType, actorUserId, actorEmail, note, createdAt
designs/<name>--<id>.jsonA designformatVersion, design, paths, comments, lifecycleEvents, approvals, versions, versionContent, versionContentMissing
designThe designid, customerId, projectId, title, description, tags, phase, isPii, createdAt, updatedAt
paths[]A conversation path, the main path first; a branching path names the main-path turn at which it branches off and, where applicable, the one at which it leads back into the main pathid, name, isMain, pathType, branchFromMessageId, rejoinFromMessageId, position, createdAt, updatedAt, turns
turns[]A turn in the order of the path; content is the list of its blocks (Section 5.4)id, position, role, agentId, content, timeLimitMs, intent, intentAvoid, isEscalation, guidelines, createdAt, updatedAt
turns[].guidelines[]A guideline assigned to this turnguidelineId, stance
versions[]A version of the design (Section 5.7)id, parentVersionId, trigger, phase, label, comment, createdBy, createdAt, treeHash, manifest
ai-conversations/<id>.jsonA conversation with the assistantformatVersion, conversation, messages
conversationThe conversationid, customerId, projectId, agentKey, title, status, createdByUserId, createdAt, updatedAt
messages[]A message; for the assistant's replies, parts contains its individual steps as they were displayedid, role, content, parts, meta, attachments, createdAt
messages[].metaDetails of the message (null if there are none): number of images, mentions, error message and request identifierimages, mentions, error, requestId
meta.mentions[]An object mentioned in the messagekind, id, label, customerId, projectId
messages[].attachments[]An attached image with its path in the archivemediaType, file
media.jsonThe media libraryformatVersion, media
media[]An uploaded file with its path in the archiveid, file, mime, bytes, sha256, createdAt, libraryEntries
libraryEntries[]Where the file was added to the media library, and by whomcustomerId, projectId, designId, uploadedByUserId, createdAt

5.4 Content of a turn

The field content of a turn is a list of blocks. Every block has an identifier id and a kind type. A block that refers to a file, a form, a widget or a tool carries its identifier; a file can instead be embedded via an internet address (url).

Block kindMeaningFields
textTextid, type, text
imageImageid, type, mediaId, url, caption
videoVideoid, type, mediaId, url, caption
audioAudioid, type, mediaId, url, caption
codeSource code with the language namedid, type, lang, code
tool_callCall of a tool with arguments and result (each as JSON text); toolId refers to the tool in the library, the other fields are technical detailsid, type, toolId, name, args, result, logoMediaId, logoUrl, timeLimitMs, kind, description, endpoint, method, transport, sideEffect, auth, environment, owner, idempotent, confirmation, dataSensitivity, errorFallback, notes
sourceSource reference with title and addressid, type, title, url
formReference to a formid, type, formId
widgetReference to a widgetid, type, widgetId
ask_questionQuestion with answer optionsid, type, question, options
fileFile handed over in the conversation, with the permitted file kindsid, type, fileName, allowedTypes, mediaId, url

5.5 Further embedded structures

ObjectMeaningFields
brief.contentContent of a brief and of each of its versions: goal, what the assistant does and does not do, audience, channels, escalation, voice and the values of the additional brief fields (by their identifier)goal, scopeDoes, scopeDoesnt, audience, channels, channelOther, escalationNote, voice, customFields
brief.content.voiceThe assistant's voice: description, traits, tone per situation, typical and untypical phrasings, example pairs, greeting and handling of errorsdescription, traits, tones, markers, pairs, greeting, repair
forms[].fields[]A form fieldid, type, name, label, required, placeholder, options, multi

The structure of a widget (root) is a tree of components in the ChatKit widget format: each component is a JSON object with its kind in type, its properties and, where applicable, further components. variables contains the example values the widget displays.

5.6 Value lists

FieldValues
workspace.kindpersonal, team
phase (designs and briefs)draft, in_review, pending_approval, approved
paths[].pathTypehappy, edge, sad, adversarial
turns[].roleuser, ai
turns[].guidelines[].stancedemonstrates, violates
messages[].roleuser, assistant
conversation.statusactive, archived
kind (tools and tool_call)rest, mcp, graphql, webhook, function, builtin, db, rpa, subagent, connector
transport (tools and tool_call)stdio, http, sse
sideEffect (tools and tool_call)read, write, destructive
auth (tools and tool_call)none, api_key, oauth, service_account, internal
environment (tools and tool_call)sandbox, staging, prod
dataSensitivity (tools and tool_call)public, internal, confidential, pii, regulated
tools[].statusdraft, ready, deprecated
widgets[].statusdraft, active
forms[].fields[].typetext, date, select, checkbox
versions[].triggermanual, phase_change, auto, restore
approvals[].statuspending, approved, cancelled
lifecycleEvents[].actorTypeuser, approver, system
comments[].anchorTypemessage, brief_section, guideline

5.7 Version history

The versions of a design are included in the form in which we store them: each turn content appears only once in the design document, even if it occurs in many versions. versionContent maps each hash to such a content; versionContentMissing names the hash values whose content is no longer present in our database.

ObjectMeaningFields
versions[].manifestThe structure of the version; v is the version of this structure (currently 1)v, design, paths
manifest.designTitle and description of the design in this versiontitle, description
manifest.paths[]A path of the version with the list of its turns; pathType is absent in versions stored before path types existedid, name, isMain, pathType, branchFromMessageId, rejoinFromMessageId, position, messages
manifest.paths[].messages[]A turn of the version: its identifier, its place in the path and the key of its contentid, position, hash
versionContent[hash]The content of a turn; content is the list of its blocks (Section 5.4), and isEscalation is present only if the turn is an escalationrole, agentId, content, timeLimitMs, intent, intentAvoid, isEscalation

You reconstruct a version by looking up, for every turn in its manifest, the content under versionContent[hash].


6. Known restrictions

  • Images in reduced form. The uploaded files are included as they are stored with us. Images that the application already reduced and re-encoded while uploading them (usually in WebP format) are therefore included only in that form; we do not store the original image.
  • Own conversations only. The export contains only the conversations with the assistant that the exporting person started.
  • Team workspaces. Only the team's owner and its administrators can export; during a suspension of one's own account only the owner (Section 2.1).
  • Embedded media. Media embedded via an internet address are included only as that address.
  • Point in time. What counts is the time at which the export was requested; files uploaded after that are not included.
  • Large workspaces. A large export is delivered in several ZIP files and only continues while the export page is open or opened again; an export that is not finished 24 hours after it was started is no longer completed (Section 2.1). If a workspace is too large for an export, the export stops with a notice; please contact support@klate.ai in that case.
  • Download. Only the person who started the finished export can download it, and for at most 7 days (Section 2.1).
  • Transfer to another provider. There is no function with which Klate transfers your data directly to another provider; you download the export and pass it on. You receive support with the switch under Clause 23 of the AGB at support@klate.ai.
  • No import. We provide no tool with which other products read in the export, and we do not owe an import into another product (Clause 11 of the Leistungsbeschreibung). How far another service can take over the content depends on that service.
  • MCP server. The route via the MCP server is only available in the Pro and Team plans.

7. Charges

Export, switching and ending the contract cost nothing. We charge no fee for the switch or the ending (Clause 23 of the AGB). The Data Act prohibits switching charges entirely from 12 January 2027 and until then permits only reduced charges that do not exceed the costs directly linked to the switch (Art. 29(1) to (3)); we charge none today either.

  • Recurring charges: the prices of the plans and add-ons according to the Preisliste (Annex 2). No further costs arise besides the total price, and there are no minimum terms (Clause 1.1 of the Preisliste).
  • Early termination: there are no penalties or fees for early termination. If you terminate a paid plan, we do not refund the fee already paid for the current billing period (Clause 9.1 of the Preisliste). If we end the contract or discontinue the service, we refund fees paid in advance pro rata (Clause 9.2 of the Preisliste).

8. Jurisdiction and location of the infrastructure

Klate is operated by Klate Technology UG (haftungsbeschränkt), with its registered seat in Frankfurt am Main; German law applies to us. We do not operate data centres of our own. The IT infrastructure on which Klate runs is provided by the following providers:

TaskProviderLocation
Running the application, including the MCP server and the export function, and network protectionVercel Inc. (USA)Application: Frankfurt am Main, Germany; network protection: global
Database with all content except the uploaded files, accounts and sign-inDatabricks, Inc. (USA), parent company of Neon, LLCFrankfurt am Main, Germany
Uploaded files and export files; name resolutionCloudflare, Inc. (USA)Files: Western Europe as the specified preferred storage location, according to the provider no commitment to a guaranteed storage location; name resolution: global
Sending emailsPlus Five Five, Inc. ("Resend", USA)Sending from Ireland; account data, delivery logs and metadata in the USA
Error diagnosticsFunctional Software, Inc. ("Sentry", USA)Error events in the EU region (Frankfurt am Main); account, organisation and administrative data in the USA
AI featuresVercel Inc. (AI gateway, USA) and the model providers OpenAI and Anthropic; where we commission them directly, our contracting parties are OpenAI Ireland Limited and Anthropic Ireland, Limited (Ireland)USA; as we do not specify a routing region to the AI gateway, processing at another location of the respective provider cannot be ruled out
Payment processingStripe Payments Europe, Ltd. (Ireland)EU (Ireland), with onward transfer to Stripe, Inc. or Stripe, LLC (USA)

The database holding your content and the application itself therefore run in Frankfurt am Main, that is in the European Union, where Union law and German law apply. For the uploaded files and the export files, Western Europe is specified as the storage location but not committed to by the provider.

The providers of this infrastructure are, however, companies with their seat in the United States. The only exceptions are our contracting parties for payment processing and, where we commission the model providers directly, for the AI features: they are established in the Union and transfer data onward to companies in the United States. The law of the United States can, under certain conditions, oblige a company with its seat there to hand over data in its possession or under its control, even if the data is stored in the Union. The storage location in the Union therefore does not by itself protect against such access.

If you use the AI features, the content required for them is processed in the United States; processing at another location of the respective provider cannot be ruled out (privacy notice, section "AI features"). If you do not use the AI features, this transfer does not take place; all other features remain unaffected. If you connect an AI agent of your own via the MCP server, its operator receives the content retrieved; which jurisdiction applies to that is determined by your choice.

The privacy notice lists all recipients with their processing locations in the sections "Recipients and sub-processors" and "Transfers to third countries"; for customers who use Klate for business purposes, so does the list of sub-processors in the data processing agreement.


9. Measures against unlawful governmental access

The Data Act requires a general description of the technical, organisational and contractual measures by which a provider seeks to prevent international governmental access to, or transfer of, non-personal data held in the Union where such access would conflict with Union law or the law of a Member State (Art. 28(1)(b)). Our measures apply equally to all content, whether it is personal or not.

Technical measures.

  • The database holding your content is located in Frankfurt am Main; for uploaded files and export files, Western Europe is specified as the storage location (Section 8).
  • All connections to Klate and between Klate and its providers are encrypted with TLS.
  • The providers with which your content is stored encrypt it at rest with AES-256, according to their own documentation. We use no additional encryption or keys of our own; this encryption therefore does not protect against a handover by the provider itself.
  • Uploaded files and export files are held in storage that is not publicly accessible and can only be retrieved via short-lived, signed links after an authorisation check.
  • Every request is checked against the account's actual authorisation; the workspaces are isolated from one another.

Organisational measures.

  • At present only the managing director has administrative access to customer content.
  • Security-relevant events are recorded in an audit log.

Contractual measures.

  • Under Clause 18 of the AGB your content is always confidential. If we have to disclose it on the basis of a statutory obligation or an order of an authority or a court, we inform you beforehand to the extent this is permitted.
  • Data processing agreements are in place with our providers; to the extent data is transferred to third countries, we generally rely on the standard contractual clauses of the European Commission (privacy notice, section "Transfers to third countries"). These agreements concern personal data. Whether the providers' terms contain comparable commitments for non-personal data we have not separately established; we therefore do not list such commitments as a measure.

Limits. None of these measures can rule out that a provider with its seat in the United States is obliged under the law there to hand over data it stores in the Union (Section 8). The same applies to content that is processed in the United States when the AI features are used.


10. Contact and updates

The provider of Klate is Klate Technology UG (haftungsbeschränkt), Im Galluspark 4, 60326 Frankfurt am Main, Germany. Further details are in the imprint.

  • Questions on switching, the export and the export format: support@klate.ai
  • Questions on data protection: privacy@klate.ai

If the export format, the infrastructure or any of the rules restated here changes, we update this page and the date at the top.


As at: 8 October 2026 · Version 1.3