PRIVACY POLICY OF KLARTO.IO

Effective Starting: May 06, 2026

KlartoTech OÜ values user privacy and considers it an important matter. This privacy policy (“Klarto,” “we,” “us,” or “our”) explains how KlartoTech OÜ (“Klarto,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information whether you use our project management software, website, or mobile applications. Based in Tallinn, Estonia (Registration Code: 17413858; Address: Narva mnt 5, 10117), our operations are undertaken in accordance with the strict governance of European digital law. We have developed a specialized suite of cloud-hosted collaboration tools specifically for enterprise-level organizations and professional teams. In this document, we refer to our entire digital infrastructure, including the platform at app.klarto.io, our iOS and Android applications, and our support infrastructure as the “Services.” Not only will this document help explain how we collect and use your data, but it will also serve as a guide to your rights. This includes how you can take control of your data by objecting to certain forms of processing or by requesting access to your account settings. The usage of Klarto Services implies compliance with all policies described here. If you disagree with any aspect of the notice, we encourage you to stop using our website and related business services. This privacy policy is intended to help you understand:

1. LEGAL DEFINITIONS AND INTERPRETATION
2. THE KLARTO ARCHITECTURE: ROLES OF CONTROLLER AND PROCESSOR 3. CATEGORIES OF PERSONAL DATA COLLECTED
4. LEGAL BASIS FOR DATA PROCESSING
5. AUTHORIZED SUB-PROCESSORS AND THIRD-PARTY INTEGRATIONS
6. DATA RETENTION AND DISPOSAL PROTOCOLS
7. CROSS-BORDER INFORMATION FLOWS AND GOVERNANCE
8. DETAILED PROCESSOR DUTIES (ARTICLE 28)
9. SECURITY AND INCIDENT RESPONSE
10. COOKIE AGREEMENT AND TRACKING METHODS
11. YOUR RIGHTS UNDER EU LAW (GDPR)
12. SUPERVISORY AUTHORITY AND DISPUTE RESOLUTION
13. AGE RESTRICTIONS AND PROTECTION OF MINORS
14. AMENDMENTS AND POLICY UPDATES 15. CONTACT INFORMATION AND DPO INQUIRIES

1. LEGAL DEFINITIONS AND INTERPRETATION

Before we look into the “how” and “why,” we need to be clear about the “what.” In law, definitions are everything. We’ve kept these as simple as possible. 1. “Agreement” refers to the Terms of Service and this Privacy Policy collectively. 2. “The Company” (The “Customer”) refers to the legal entity, usually represented by an Administrator or Authorized User, that purchases a Klarto subscription. 3. “Data Controller” is the person or entity that determines the “why” and “how” of data processing. 4. “Data Processor” is the party that processes any data on behalf of the Data Controller. 5. “Authorized User” means any individual (team member, employee, or contractor) who has been invited into a Company Workspace. 6. “Personal Information” is any type of information that can be used to identify a specific person or their details. 7. “Workspace” is your private, secure space inside Klarto. It’s where all your projects, tasks, and team efforts are kept, protected by encryption. 8. A “Sub-processor” refers to a third-party service provider, like AWS or Stripe, that helps us deliver the Service.

2. THE KLARTO ARCHITECTURE: ROLES OF CONTROLLER AND PROCESSOR

In the field of B2B SaaS (Business-to-Business Software as a Service), there is a very important distinction in legal responsibility. We want you to understand exactly where we stand. 2.1. When Klarto is the “Data Controller.” We act as the Data Controller for the basic information we need to run our business and provide the platform. This includes the name and email of the Administrator or Authorized User who signs up, the billing information used for Stripe payments, and the technical logs (like IP addresses) we need to keep the site secure. We decide how this data is administered to ensure we can fulfill our contract with you. 2.2. When Klarto is the “Data Processor.” Once the Administrator or Authorized User starts creating a workspace and adding their team members for tasks, the roles change. The company becomes the Data Controller for that workspace. They decide which team members to add, what tasks to write, and when to delete them. KlartoTech OÜ acts strictly as the Data Processor for this workspace data. We host it, we back it up, and we keep it secure, but we do not “own” it. We only process it according to the instructions of the company. If you are a team member and have questions about the data inside your workspace, you should talk to your Administrator first, as they are the ones “controlling” that environment.

3. CATEGORIES OF PERSONAL DATA COLLECTED

We hate “bloatware” and “bloat-data.” We only collect what is strictly necessary to keep the lights on and the software running. 3.1. Information You Provide to Us 1. Identity Data: This includes your first and last name. We use this, so your team knows who is assigning them a “To-Do” list. 2. Contact Data: Your professional email address. Your “Key” is your access to the platform. It’s used for logging in, resetting passwords, and for other important support interactions. 3. Phone Number: Your contact phone number, used for account verification, security purposes (e.g. two-factor authentication, if applicable), and support communication. 4. Financial & Billing Data: For the account owner (Authorized User), we collect the company name, VAT number, and billing address. We need this information to issue legal invoices under Estonian law. 5. Authentication Data: We keep and secure your password, but never store it in plain text to prevent readability. 3.2. The Tech Stuff: Data We Collect Automatically 1. Data & Security Logs: Our servers keep tracking your IP address and the time you logged in. Why? We need to know where a security breach came from if it happens. This is to keep both you and us safe. 2. Device Metadata: We can identify if you’re using our iOS or Android app or a certain web browser. This helps us fix bugs that might only happen in one version of the software. 3. Marketing & Analytics Tracking: We use Google Analytics. This tool helps us understand how people use our website and allow us to run targeted advertising campaigns to reach the right professional audience. We do not use Facebook Pixel or any other advertising/marketing tracking tools. 3.3. Information We Do NOT Collect We want to be very clear about what we don’t do: 1. AI and Automated Analysis: We currently do not use AI to “read” your tasks or analyze team productivity. No user data is currently used to train AI models. If we implement AI features in the future, we will provide advance disclosure, specifically regarding whether your data will be used for model training. 2. Third-Party Data Brokers: We do not buy data from third-party “brokers.”

4. LEGAL BASIS FOR PROCESSING: THE “WHY.”

Under the GDPR (Article 6), we aren’t allowed to just “process data” because we want to. We must have a valid legal reason. We rely on three specific pillars: 1. Contractual Performance: This is the big one. You pay us 70 EUR (or more for extra members) to provide a project management tool. We process your name, email, and billing info because it’s impossible to provide that service without it. 2. Legal Obligation: We are a registered Estonian company. The Estonian Tax and Customs Board (Maksu- ja Tolliamet) requires us to keep invoices and financial records for 7 years. We have to process and store this data to stay on the right side of the law. 3. Legitimate Interests: We store login logs and IP addresses. We have a “legitimate interest” in preventing hackers from accessing your private workspace. It’s an important step to keep the Klarto software secure and safe.

5. AUTHORIZED SUB-PROCESSORS AND THIRD-PARTY INTEGRATIONS

We don’t build everything from scratch. We use the world’s best infrastructure to make sure Klarto is fast and reliable. Under GDPR Article 28, these companies are our “Sub-processors.” 1. Amazon Web Services (AWS): This is where our servers and infrastructure are hosted, including SMTP configuration used for transactional/system emails. We have specifically chosen to host your data in the EU Region (located in the Paris region). 2. Stripe: This is our payment engine. When the user buys a subscription, Stripe handles the heavy lifting of the transaction. 3. Google Workspace: This is used for internal communication, email services (including support@klarto.io), and document/storage management. We have signed “Data Processing Agreements” (DPAs) with all listed sub-processors to ensure compliance with GDPR requirements and to guarantee appropriate safeguards for personal data.

6. DATA RETENTION AND DISPOSAL PROTOCOLS

We don’t keep data forever. That’s a security risk. 1. Active Account Data: We keep your information as long as your subscription is active and you are using the Service. 2. After Deletion: If an Administrator or Authorized User deletes the Company account via the dashboard, we trigger a “hard delete” of the workspace data. Within a defined technical window of up to 30 days (required for secure backup cycles), that data is permanently deleted. 3. The “Estonian 7-Year Rule”: Even if you delete your account, your invoices and billing history will stay in our archives for 7 years. This is not our choice; it is a requirement of the Estonian Accounting Act. This information is kept in a “cold” archive and strictly reserved for only potential tax audits.

7. CROSS-BORDER INFORMATION FLOWS AND GOVERNANCE

Although the company KlartoTech OÜ strives primarily to store and process personal data inside the European Economic Area (EEA), by utilizing the cloud storage and processing infrastructure of Amazon Web Services (AWS) in Paris, there are specific situations that will require KlartoTech OÜ to process and/or store personal data outside the EEA. When the personal data is used and/or accessed from or transferred to non-European Union and non-EEA jurisdictions, for example, when working with global sub-processors like Stripe and AWS support teams, KlartoTech OÜ complies with the required legal safeguards. Specifically, KlartoTech OÜ uses Standard Contractual Clauses (SCCs) approved by the European Commission for ensuring that the recipient country provides an adequate protection level as stipulated by GDPR for personal data received. Furthermore, KlartoTech OÜ conducts regular evaluations and due diligence procedures aimed at verifying whether third-party partners in other countries have put in place the necessary technical and organizational measures to make sure that personal data is adequately protected from unauthorized access, including by governments from foreign countries.

8. DETAILED PROCESSOR DUTIES (ARTICLE 28)

In its capacity as a Data Processor in respect of Workspace Data, KlartoTech OÜ adheres to the following obligations: Documented Instructions: Personal data shall be processed strictly in accordance with the documented instructions of the Customer, including in relation to transfers to third countries, unless otherwise required by applicable European Union or Estonian law. Confidentiality of Personnel: All employees, agents, and contractors of KlartoTech OÜ who can process personal data must follow strict confidentiality rules, based on their contracts or the law. Security of Processing: KlartoTech OÜ takes appropriate technical and organizational measures to protect personal data. These measures encompass encryption and restricted access, all implemented to reduce the potential risks associated with its data processing operations. Audit and Compliance Support: KlartoTech OÜ will provide the necessary information to show adherence to all relevant legal requirements. Furthermore, we will work during any audits or inspections initiated by the Customer or an authorized auditor in collaboration. You may contact us via support@klarto.io for a signed copy.

9. SECURITY AND INCIDENT RESPONSE

9.1 Technical Protections 1. Encryption in Transit: Every time you click a button in Klarto, the data is encrypted using SSL/TLS. It’s like sending information in a sealed box, that’s safe and secure. 2. Encryption at Rest: On our AWS servers, your data is “encrypted at rest.” If someone were to physically steal a hard drive from an AWS data center (which is nearly impossible), they still wouldn’t be able to read your project names. 3. Team Isolation: Our software is designed so that Workspace A can never see the data of Workspace B. We use strict “multi-tenancy” logic to ensure your private workspace stays private. 9.2 Breach Notification Protocols We have an established system of internal procedures for handling and investigating any possible security breaches. Should a breach of your personal data occur, we will act accordingly depending on the seriousness of the threat to our users: Regulatory Reporting: KlartoTech OÜ pledges to report all breaches that are likely to lead to a risk to the rights and freedoms of individuals to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) within 72 hours after becoming aware of a security breach. User Notification: In case a breach is found to be a threat of “high risk” to your rights and freedoms, we will inform you about this issue immediately. You will receive an explanation of what happened and how the breach may affect you, as well as recommendations to reduce possible risks. Internal Documentation: We keep records of any incidents that occurred in relation to data security issues and their subsequent investigation.

10. COOKIE AGREEMENT AND TRACKING METHODS

Klarto uses a limited set of cookies, including both Essential and Non-Essential cookies: 1. Essential Cookies: These are necessary for the operation of the platform. They allow you to stay logged in, maintain session security, and prevent attacks such as Cross-Site Request Forgery (CSRF). 2. Analytics Cookies: We use Google Analytics to understand how users interact with our website and improve performance. These cookies are not strictly necessary and are only activated after obtaining your consent. Consent Mechanism: Upon visiting our website, users will be presented with a cookie consent banner that allows them to accept or reject non-essential cookies (such as analytics). If you choose to disable cookies entirely in your browser, certain parts of the Klarto Services may not function properly.

11. YOUR RIGHTS UNDER EU LAW (GDPR)

In accordance with GDPR, people can also request the restriction of processing data for some reasons, for example, if the accuracy of personal data is contested by a user or data is required for legal claims. During such a period, data won’t be actively processed, but only stored by Klarto. Right to data portability means that a person will get their data in machine-readable format when processing is based on consent or contract and carried out automatically. People also have the right to object to the processing of their data based on legitimate interests, and Klarto stops the processing in this case. To submit the request, one may use the Klarto dashboard or send an email to support@klarto.io.

12. SUPERVISORY AUTHORITY AND DISPUTE RESOLUTION

Klarto recommends that users contact the company directly regarding any issues related to the processing of their personal data. At the same time, users possess the right to complain about violations of their rights with regard to personal data protection by the supervisory authority. Given that KlartoTech OÜ operates within Estonia, the main data protection supervisory body is Andmekaitse Inspektsioon (the Estonian Data Protection Inspectorate). The users can turn to it with their requests, complaints, and questions regarding data protection laws. Supervisory Authority Contact Information: Andmekaitse Inspektsioon Email: info@aki.ee Website: aki.ee Country: Estonia In addition, users from other European Union member states should reach out to the appropriate authorities as required by GDPR. Klarto agrees to work with all supervisory authorities.

13. AGE RESTRICTIONS AND PROTECTION OF MINORS

Klarto is a software for professionals, Employees, and their teams. It is not intended for children. While the legal age of consent for online services in Estonia is 13, Klarto requires all users to be at least 16 years of age. We do not knowingly collect information from children. If we find out a 12-year-old has made a project management account (perhaps they are a very organized child!), we will delete that account immediately.

14. AMENDMENTS AND POLICY UPDATES

The digital world changes quickly. We may need to change this privacy policy over time to align with new laws or to reflect new features. We will revise the “Effective Date” at the top of this page when the changes are implemented. We will email the account owners to let them know, and if the change is significant (like introducing a new sub-processor or sharing data), then you have to agree to the new terms if you keep using Klarto after these changes.

15. CONTACT INFORMATION AND DPO INQUIRIES

If you have a question that isn’t answered here, or if you want to exercise your “Right to be Forgotten,” please get in touch. The Data Protection Officer (DPO) for Klarto is the owner themselves, ensuring that privacy is handled at the highest level of leadership. KlartoTech OÜ DPO: Mads Landdorf Rasmussen Support Email: support@klarto.io Registered Address: Estonia, Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 5, 10117