How we handle your data
How Klantr handles your data — in plain language, with no fine print that means something else.
What this is about
Klantr is built by one person, for independent professionals with recurring clients in the Netherlands and Flanders. This page explains, calmly and honestly, which data we keep, why, and what say you have over it. It is an explanation in plain language, not a final legal document: the formal privacy statement and the company's Chamber of Commerce (KVK) number follow at launch.
Which data we keep
For you as a user we store your name, your business name and your email address. Login uses a magic link, so we store no passwords. For each client you add, we keep: the company name, a contact person's first name, a business email address, the retainer amount (€/month), the hours per month, the short line you type, the update that results from it, a 'last contact' timestamp, and whether this month's update has been sent. Nothing more — we ask only for what the work needs.
Why we keep it (and on what legal basis)
We process this data to deliver the service you take from us: writing your monthly updates and watching over your retainer clients. The legal basis for that is the performance of the contract between you and Klantr (GDPR Article 6(1)(b)). We do not use your data for anything else, and we do not sell it to anyone.
Who helps us (sub-processors)
Klantr does not run entirely on its own; a few carefully chosen parties process data on our behalf. Supabase provides the database (Postgres) and the login. Anthropic generates the text of the updates via an API. Resend sends the outbound email. Paddle will later be our payment partner (merchant of record) — it is not yet connected, because billing starts later. With each of them a data-processing agreement is, or will be, in place.
The AI — and your control
The short line you type goes to Anthropic, which turns it into a client-ready update in your tone. Under Anthropic's commercial API terms, your input and the generated text are not used to train their models. The output is descriptive ('this was done, X hours remain') and never advice. You read every update and can edit every word before it goes out — you decide what your client ultimately sees.
The churn clock: just a timestamp
Klantr warns you when a retainer client has gone quiet, along with the amount at stake. That works on one thing: a 'last contact' timestamp. Klantr stores only that moment in time — never the subject, body or attachments of any email. Every time you send an update through Klantr, that timestamp is refreshed for that client. Klantr does not connect to your mailbox and does not receive or read any email; automatically counting messages you bcc to Klantr is on the roadmap.
Where your data lives (international transfers)
Where our providers offer it, we run on EU-region infrastructure. We cannot promise this as an absolute, unconditional guarantee: some services, such as the AI processing via Anthropic, may technically take place outside the EU. Where that is the case, we rely on the data-processing agreement and that party's standard safeguards. We would rather keep this modest and honest than promise more than we can deliver.
Retention, export and deletion
We keep your data for as long as you have an account. You can export it at any time (CSV or JSON) and take it with you. If you want to stop, you can delete your account whenever you like; your data is then erased within 30 days, unless a legal retention duty requires us to keep something a little longer. You are not locked in, and your data stays yours.
Your rights under the GDPR
You have the right to access your data, to have it corrected, to have it erased, to take it with you (data portability), and to object to the processing. Just send us a message and we will handle it. We respond within 30 days — the statutory one-month period — and usually sooner.
How we secure your data
A few things that are genuinely in place: everything runs over HTTPS, and at our database provider data is encrypted in transit and at rest. Row-level security ensures each account sees only its own rows — your clients are visible to no one else. We deliberately minimise what we store, and login uses a magic link instead of passwords. We do not claim certifications (such as ISO 27001 or SOC 2); we would rather tell you honestly what we do than wave badges around.
Cookies and analytics
We like to keep this simple. Klantr uses only the essential cookies needed to keep you logged in. We do not place advertising trackers or ad pixels, and we do not follow you across other websites. No hidden onlookers — only what is needed to make the app work.
Children
Klantr is a business tool for independent professionals and entrepreneurs. The service is not aimed at children and we do not knowingly collect data from children. It is meant for people using it for their work.
Changes to this statement
As Klantr grows, this explanation may change — for example when the billing part via Paddle goes live. If something material changes, we will update this page and make sure you can see it in a reasonable way. We will try to keep the tone the same: calm, honest and in plain language.
An honest closing note
This is an honest explanation in plain language, written by the maker himself, and not a watertight legal statement. The formal privacy statement and the company's Chamber of Commerce (KVK) number follow at launch. Until then, if you have a question about your data, just ask — you will get an actual person on the other side.
Contact
Questions about your data? Email support@klantr.nl. Company details and registration number: will be filled in at launch.