1. Introduction

Klarivox ApS ("Klarivox," "we," "us," "our") provides a software-as-a-service platform that helps businesses understand their customers by connecting customer conversations to revenue data. We respect your privacy and are committed to protecting personal data.

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and the rights you have in relation to that data. It applies whenever Klarivox acts as a data controller — meaning we determine why and how personal data is processed.

2. Scope: When This Policy Applies (and When It Doesn't)

Klarivox plays two different roles under EU data-protection law, and which role applies determines which document governs the processing.

This Privacy Policy applies when we act as a data controller — that is, to personal data we collect for our own purposes, including:

  • Visitors to our websites, including getklarivox.com
  • Prospects and leads we contact for marketing or sales
  • Users who sign up for an account, log in, or otherwise use the Klarivox platform
  • Billing and finance contacts at our customers
  • People who contact us for support, careers, or other enquiries

This Privacy Policy does not apply to personal data that our customers upload into the Klarivox platform about their own customers, prospects, employees, or end users (for example, call recordings, support tickets, CRM records, NPS responses). For that data, Klarivox acts only as a data processor, and the processing is governed by the Data Processing Agreement (DPA) between Klarivox and the relevant customer.

If you believe a Klarivox customer holds personal data about you and you wish to exercise your rights in respect of that data, please contact that customer directly. They are the controller; we can only act on their instructions.

3. Who We Are (Data Controller)

The data controller responsible for personal data processed under this Privacy Policy is:

Klarivox ApS CVR no. 46445104
Registered office: Glamsbjergvej 15, 2770 Kastrup, Denmark
Website: getklarivox.com
Email for privacy enquiries: privacy@getklarivox.com

We have not appointed a Data Protection Officer (DPO) as we are not required to do so under Article 37 of the GDPR. For any privacy-related questions, please contact us at the email address above.

4. Personal Data We Collect

We collect the categories of personal data set out below. Some data you provide directly; some we collect automatically through your use of our website or platform; and some we receive from third parties.

4.1 Data you provide directly

  • Contact information: name, work email, phone number, company name, job title, country
  • Account credentials: username, hashed password (we never store passwords in plain text), SSO identifiers
  • Profile information: profile photo (if you upload one), language preference, notification settings
  • Communications: messages you send us by email, live chat, or in-app support, including any attachments
  • Billing information: billing contact, billing address, VAT number, and limited payment-card metadata (the full card number is processed by our payment provider, not stored by us)
  • Demo and trial requests: any information you choose to provide in a form (use case, team size, current tools)

4.2 Data we collect automatically

  • Device and connection data: IP address, browser type and version, operating system, device type, language, time zone, referring URL
  • Usage data: pages visited, features used, clicks, session duration, in-app actions, error logs, timestamps
  • Authentication and security logs: login times, login attempts, source IP, user-agent, multi-factor authentication events, audit-trail entries
  • Cookies and similar technologies: see Section 10 below

4.3 Data we receive from third parties

  • Sales-prospect enrichment: we may receive publicly available business information about you (job title, employer, work email, LinkedIn URL) from B2B data providers, where you appear to be a relevant potential customer for our product
  • Single Sign-On (SSO) providers: if you log in via Google, Microsoft, or another identity provider, we receive the limited profile data they share with us
  • Integration partners: if you connect your CRM, calendar, or other tools, those services may send us metadata about your account
  • Referrals: information from people who refer you to us

5. Purposes for Which We Use Your Data, and Our Legal Bases

Under Article 6 of the GDPR, we are required to have a lawful basis for each processing activity. The table below summarises why we process personal data and the legal basis we rely on for each purpose.

Purpose Categories of data Legal basis (GDPR Art. 6) Notes
Providing the Klarivox platform to logged-in users Account, profile, usage, security logs Contract — Art. 6(1)(b) Necessary to perform our agreement with the customer that employs you
Processing payments and managing billing Billing contact and billing info Contract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c) Tax and accounting law require us to retain certain billing records
Responding to support and other enquiries Contact data, communications content Contract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f) Where you are not yet a customer, our interest in answering you
Securing the platform and preventing fraud Device, connection, security logs Legitimate interests — Art. 6(1)(f) Necessary to protect customers and the integrity of the service
Product analytics and improvement Usage data, pseudonymised event data Legitimate interests — Art. 6(1)(f) We minimise and pseudonymise where practical
Direct marketing to existing customers about similar products Contact data, account data Legitimate interests — Art. 6(1)(f); ePrivacy soft opt-in You can opt out at any time using the unsubscribe link
Marketing to non-customer prospects (cold outbound) Business contact data, enrichment data Legitimate interests — Art. 6(1)(f) Balancing test performed (see Section 8); easy unsubscribe in every message
Marketing emails based on signup or content download Contact data Consent — Art. 6(1)(a) You can withdraw consent at any time
Compliance with legal obligations Any relevant data Legal obligation — Art. 6(1)(c) E.g. responding to lawful requests from authorities
Establishing, exercising, or defending legal claims Any relevant data Legitimate interests — Art. 6(1)(f) Including dispute resolution and audit records

Where we rely on legitimate interests, we have carried out a balancing test to ensure that our interests are not overridden by your interests, rights, or freedoms. You can request a summary of the balancing test for any specific processing activity by emailing privacy@getklarivox.com.

6. Who We Share Personal Data With

We do not sell personal data. We share personal data only as set out below.

6.1 Sub-processors

We use a number of trusted service providers ("sub-processors") to help us deliver our service. These include cloud hosting, communications, analytics, billing, customer support, and AI service providers. Each sub-processor is bound by a written contract requiring them to process personal data only on our instructions and to apply appropriate security measures.

The complete, current list is published at getklarivox.com/subprocessors (or available on request from privacy@getklarivox.com). That page is authoritative: if a provider is not named there, we are not using it. The categories we may engage providers in are:

  • Cloud infrastructure (e.g., UpCloud)
  • AI and large language model providers (e.g., Mistral AI)
  • Analytics (e.g., PostHog, Google Analytics 4)
  • Email and communications (e.g., transactional email and live-chat providers)
  • Payments and billing (Stripe or similar)
  • CRM, marketing automation, and customer support tools we use internally
  • Sales-prospect enrichment vendors

6.2 Other recipients

  • Professional advisers (lawyers, accountants, auditors) bound by confidentiality
  • Authorities, courts, and regulators, where required by law or to protect our legal rights
  • Parties involved in a corporate transaction (merger, acquisition, financing, or sale of assets), subject to appropriate confidentiality and data-protection safeguards

7. International Data Transfers

Some of our service providers are established outside the European Economic Area (EEA), or may permit authorised personnel outside the EEA to access personal data. We make such transfers only in accordance with Chapter V of the GDPR. Where the European Commission has adopted an adequacy decision, including for U.S. recipients actively certified under the EU–U.S. Data Privacy Framework, we may rely on that decision under Article 45. Otherwise, we rely on appropriate safeguards under Article 46, including:

  • The European Commission's Standard Contractual Clauses (2021/914)
  • Supplementary technical and organisational measures (such as encryption in transit and at rest, access controls, and pseudonymisation) informed by a Transfer Impact Assessment

You can request a copy of the relevant safeguards by contacting privacy@getklarivox.com.

8. Marketing, Sales Outreach, and Your Choices

We send marketing communications in the following circumstances:

To existing customers: we may send you information about Klarivox products and features similar to those you already use, on the basis of legitimate interests and the "soft opt-in" under the ePrivacy regime. Every message contains an unsubscribe link.

To people who have opted in: if you have signed up for our newsletter, downloaded content, or otherwise asked to hear from us, we will send marketing emails on the basis of consent. You can withdraw consent at any time.

Cold outbound sales: where you are a business contact who appears to be a relevant decision-maker for our product, we may contact you by email on the basis of legitimate interests. We limit ourselves to business addresses, restrict the volume and frequency of contact, honour unsubscribe requests immediately, and stop contacting you on first request. You can opt out at any time by replying to any email or contacting privacy@getklarivox.com.

You can object to direct marketing at any time, free of charge, and we will stop. Where required by law, we also use a suppression list to ensure we do not contact you again.

9. How Long We Keep Personal Data

We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.

Data category Default retention period Reason Notes
Account and profile dataDuration of contract + 90 daysService delivery; brief grace period for reactivation
Usage logs and analytics events12 monthsProduct improvement, security investigations
Authentication and audit logs24 monthsSecurity incident investigation
Billing and tax records5 years from end of financial yearDanish Bookkeeping Act (Bogføringsloven)Mandatory under Danish law
Support communications36 months from last contactService continuity and dispute resolution
Marketing leads (unconverted)24 months from last engagementSales follow-up
Cold outbound suppression listIndefinitelyTo ensure we never re-contact people who opted outNecessary to honour opt-outs
Website analytics (aggregated)26 monthsStandard for product analytics
BackupsUp to 90 days after deletionOperational backups roll off on a fixed schedule

After the retention period expires, we either delete the personal data or anonymise it so that it can no longer be associated with you. Where deletion is not technically feasible (for example, in encrypted backups), we securely isolate the data until deletion is possible.

10. Cookies and Similar Technologies

Our websites use cookies and similar technologies (such as pixels and local storage) to make the site work, to remember your preferences, to measure usage, and (where you consent) to support marketing. We categorise these as follows:

  • Strictly necessary cookies — required for the site or service to function (e.g., authentication). Always on; cannot be disabled.
  • Functional cookies — remember your preferences (e.g., language).
  • Analytics cookies — help us understand how the site is used.
  • Marketing cookies — used to deliver relevant marketing and measure campaigns.

Non-essential cookies are only set with your consent. You can manage your cookie preferences at any time using the cookie banner or the "Cookie settings" link in the website footer. Withdrawing consent will not affect the lawfulness of any processing carried out before withdrawal.

A complete list of the cookies we use, with descriptions, durations, and providers, is available in our cookie-settings panel.

11. Your Rights Under the GDPR

Subject to certain conditions and exceptions under applicable law, you have the following rights in relation to your personal data:

Right of access

Request a copy of the personal data we hold about you.

Right to rectification

Have inaccurate or incomplete data corrected.

Right to erasure

Request deletion of your personal data where the conditions in Article 17 are met.

Right to restriction

Ask us to stop using your data while a dispute is resolved.

Right to data portability

Receive a copy of the data you provided to us in a structured, machine-readable format.

Right to object

Object to processing based on legitimate interests, including direct marketing. For marketing, your objection is absolute.

Right to withdraw consent

Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.

Right re: automated decisions

We do not make automated decisions with legal or similarly significant effects on you (see Section 12).

To exercise any of these rights, email privacy@getklarivox.com. We respond within 30 days, and in any event within the timeframe required by Article 12 of the GDPR. We may need to verify your identity before acting on your request.

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark — dt@datatilsynet.dk — or with the supervisory authority in the EU/EEA country where you live or work.

12. Artificial Intelligence and Automated Processing

The Klarivox platform uses artificial intelligence — including large language models provided by third parties such as Mistral AI, to extract themes, sentiment, and patterns from data that our customers upload. This processing happens primarily on customer-uploaded data and is governed by the DPA between Klarivox and our customers.

Personal data of customers, prospects, users, or website visitors that we collect for our own purposes (covered by this Privacy Policy) is not used to train or fine-tune any third-party AI model. Klarivox uses AI sub-processors only under written agreements that prohibit the sub-processor from using submitted content to train their own models.

We do not make automated decisions that produce legal or similarly significant effects on you within the meaning of Article 22 of the GDPR. Internal severity scoring and ranking within the platform are decision-support tools that inform human users; they do not by themselves produce decisions about individuals.

13. Security

We apply technical and organisational security measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encryption of data in transit and at rest, access controls and least-privilege principles, separation of development and production environments, monitoring and alerting, automated security testing in our build pipeline, and incident-response procedures.

Independent penetration testing, annual security training, quarterly access reviews, and tested business-continuity plans are targeted for 2027. Our Trust & Security page states the status of each control.

No security measure is perfect. If we ever become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals in accordance with Articles 33 and 34 of the GDPR.

For a full overview of our security posture, see our Trust & Security page.

14. Children

Klarivox is a business-to-business product not directed at children. We do not knowingly collect personal data from anyone under 16 years of age. If you believe that a child has provided us with personal data, please contact privacy@getklarivox.com and we will take appropriate steps to delete it.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page shows when the policy was last revised. For material changes, we will provide additional notice, such as an email to account holders or a prominent notice on our website, and where required by law we will obtain your renewed consent.

16. How to Contact Us

For any questions or requests relating to this Privacy Policy or your personal data, please contact:

Klarivox ApS

CVR no. 46445104

Glamsbjergvej 15, 2770 Kastrup, Denmark

Email: privacy@getklarivox.com

We aim to respond within 30 days, and in any event within the timeframes required by applicable law.