Privacy Policy

Last updated: May 20, 2026

1. Who we are

Klair is a trade name of Nextstep Expert Consulting Limited, a company incorporated under the laws of the United Arab Emirates, registered with the RAK International Corporate Centre under number ICC20250869, with registered office at Office 416, Burlington Tower, Business Bay, Dubai, United Arab Emirates.

Contact: [email protected]

GDPR Representative in the European Union (Article 27 GDPR):
Emmanuel Beauvais


2. Scope

This Privacy Policy applies to all services accessible via klair.work and the Klair API (hereinafter "the Services"), as well as any interaction with our AI-based tools.

Klair targets users located in the European Union. Accordingly, Nextstep Expert Consulting Limited commits to complying with the General Data Protection Regulation (GDPR — Regulation EU 2016/679) pursuant to Article 3(2).


3. Core principles

Klair is built on the principle of user sovereignty: your data belongs to you. Klair does not host any AI model and does not hold any API key on your behalf. You connect your own AI account (Claude, ChatGPT, Gemini, Cursor...) via the MCP protocol.

Your data is never used to train AI models.

EU hosting — Frankfurt: all personal data is hosted exclusively in the European Union, on DigitalOcean Managed PostgreSQL infrastructure in the FRA1 region (Frankfurt, Germany). DigitalOcean FRA1 is ISO 27001 and SOC 2 certified, and operates under German jurisdiction.

Authentication-gated access: access to business data (contacts, history, files...) is strictly conditional on an authenticated session via JWT. AI tools you connect only access data covered by your token. Klair has no access to your data in clear text outside an authenticated session.

Active monitoring: Klair continuously monitors platform availability and health (Better Uptime + Sentry). In case of an incident, transparent communication is published as soon as possible.

The Privacy & Data page in your Klair account allows you at any time to view, edit, download and delete your data. It is only accessible from this interface — never via your AI.


4. Data collected and purposes

Data typePurposeRetention periodDeletion
Profile & settingsAccount access, personalisationUntil deletedOn request
CRM contactsAI context for your conversationsUntil deletedOn request
AI action logsActivity history, skill billing12 months rollingOn request
Privacy settingsPer-field visibility preferencesUntil deletedOn request
Connector tokensAI tool authenticationUntil revokedImmediate
Marketplace signalsConsented profile publicationsUntil depublishedImmediate
Sharing historyAccess audit trail24 monthsOn request
Billing dataInvoicing and tax compliance7 years (legal requirement)Not possible
Activation consents (SkillConsent)Legal proof of skill activation5 years (legal requirement)Not possible

5. Legal bases for processing (GDPR)

ProcessingLegal basis
Service contract performanceArt. 6(1)(b) GDPR
Invoicing and tax obligationsArt. 6(1)(c) GDPR
Service personalisation and improvementArt. 6(1)(f) GDPR (legitimate interest)
Marketplace signalsArt. 6(1)(a) GDPR (explicit consent)
Anonymised analytics (opt-in)Art. 6(1)(a) GDPR (explicit consent)

6. Contact channels and visibility

Each contact channel (work email, personal email, phone, WhatsApp, Telegram, LinkedIn...) has three visibility levels that you control independently from your Privacy & Data page:

  • Public — visible without login
  • Connections — visible only to users you've exchanged with (proven CrmActivity)
  • Only me — never shared

Access to a contact detail is individual: having access to your work email does not grant access to your personal email.


7. Marketplace — anonymous publication

If you enable anonymous publication on the Klair Marketplace, your identity (name, email, LinkedIn) is hidden — only your skills, location and experience level are visible.

Identity reveal can only occur after payment or your manual agreement. You are notified before each publication if you enable this option.


8. AI & analytics controls

  • Activity logs: AI action history for debugging and audit — enabled by default, can be disabled.
  • Signal processing: allow Klair to process LinkedIn engagement signals for approach scoring — enabled by default, can be disabled.
  • Anonymised analytics: anonymous contribution to Klair improvement — disabled by default, opt-in.

9. Subprocessors and data transfers

Klair uses the following subprocessors:

SubprocessorRoleLocation
DigitalOcean (FRA1)Database hostingEU (Frankfurt)
CloudflareDNS, SSL, protectionEU/USA — SCC
StripePayments and billingUSA — SCC + Privacy Shield
BrevoTransactional emailsEU (France)
UnipileMulti-channel connectorsEU
Upstash RedisCache and task queuesEU
SentryError monitoringUSA — SCC

For transfers outside the EU (Cloudflare, Stripe, Sentry), Standard Contractual Clauses (SCC) approved by the European Commission are in place.


10. Your GDPR rights

Under the GDPR, you have the following rights:

  • Right of access — obtain a copy of your data
  • Right to rectification — correct inaccurate data
  • Right to erasure — delete your account and data
  • Right to data portability — export your data in a readable format
  • Right to object — object to certain processing
  • Right to restriction — temporarily restrict processing
  • Right to withdraw consent — at any time for consent-based processing

Exercising your rights: from your Privacy & Data page (export within 48h, deletion within 30 days) or by email to [email protected].

In case of an unresolved complaint, you may contact the supervisory authority of your country of residence (CNIL in France, BfDI in Germany, ICO in the UK...).


11. Security

Klair implements appropriate technical and organisational measures: encryption in transit (TLS) and at rest (AES-256 for sensitive tokens), multi-tenant isolation, access logging, continuous monitoring (Sentry + Better Uptime).


12. Cookies

Klair uses only strictly necessary cookies for service operation (authentication, security). No advertising or third-party tracking cookies are deployed.


13. Changes

Any substantial change to this policy will be notified by email with 30 days' prior notice.


14. Contact

Nextstep Expert Consulting Limited — Klair

Office 416, Burlington Tower, Business Bay, Dubai, UAE

[email protected]