Terms of Service
Klaaro is a service of Catalytics Group, LLC, a Delaware limited liability company ("Klaaro," "we," "us," "our"). This policy explains what personal data we collect, why, and what we do with it. All customer data is stored and processed in the United States.
1. Two kinds of data, two different roles
Klaaro is used by agencies to manage video and content work for their own clients. That creates two distinct relationships, and our obligations differ between them.
Account data. Information about the agencies that subscribe to Klaaro and the people who use it — names, email addresses, billing details, usage records. We decide how this is used, and for this data we are the controller.
Customer Content. Video, audio, images, documents, comments, transcripts, and related material that an agency uploads or generates in Klaaro, including material relating to the agency's own clients and to people who appear in that material. We process this only on the agency's instructions, for the purpose of running the Service. For this data the agency is the controller and we are a processor.
If you are an agency's client, an employee, or someone appearing in a video hosted on Klaaro, and you want to know what data an agency holds about you or ask for it to be deleted, contact the agency directly. We will refer such requests to them and support them in responding.
2. What we collect
2.1 Account and user data
When an account is created or a user is invited, we collect name, email address, and optionally phone number. Authentication is handled through our identity provider; we do not store passwords in plain form.
2.2 Client portal guests
When an agency invites a client contact into a portal, that person creates an account and we collect the same information as in 2.1.
2.3 Share link visitors
Share links can be configured to allow access without a login. When someone opens one, we record:
a display name they type in, which is free text and unverified;
a one-way salted hash of their IP address;
a one-way salted hash of their browser user agent;
the time of access and what they viewed, commented on, or approved.
We record this so the agency has an audit trail of who reviewed and approved their work.
Because the display name is free text, a visitor may enter anything, including another person's name or an email address. We do not verify it, and the agency controlling the share link is responsible for what is entered.
2.4 Customer Content
Everything uploaded to or created in the Service. This can include personal data about the agency's clients and about people appearing in the material — faces, voices, names spoken aloud, and text in documents. We do not control what is uploaded.
2.5 Billing data
Our payment provider collects and processes payment card details. We do not receive or store full payment card numbers. We hold billing contact details, subscription status, and invoice history.
2.6 Technical and usage data
Page routes visited, feature usage, performance timings, and error diagnostics. See Section 6 for what we deliberately do not collect here.
2.7 Communications
Messages you send us by email or through support channels.
3. IP addresses
We do not store your IP address in our systems. For share-link auditing we store a one-way salted hash, which cannot be reversed to recover the original address. Rate limiting holds IP addresses in memory for approximately sixty seconds and never writes them to storage.
Our hosting and infrastructure providers log IP addresses transiently as part of delivering the Service, under their own retention schedules. Our error monitoring is configured not to attach IP addresses to reports.
4. How we use data
Purpose | Data | Basis |
Providing the Service | Account data, Customer Content | Contract |
Authentication and access control | Account data | Contract |
Billing and collections | Billing data | Contract |
Transactional email (invitations, notifications, alerts) | Account data | Contract |
Security, abuse prevention, and audit | Hashed access records, technical data | Legitimate interests |
Diagnosing errors and improving performance | Technical data | Legitimate interests |
Product analytics in aggregate | Technical data | Legitimate interests |
Responding to support requests | Communications, account data | Contract / legitimate interests |
Legal compliance | As required | Legal obligation |
We do not sell personal data. We do not share personal data for cross-context behavioural advertising. We do not use Customer Content to train artificial intelligence or machine learning models, and we do not permit our providers to do so.
5. Automated and AI-assisted processing
This section describes exactly what happens to uploaded media, because it is the question our customers ask most.
5.1 Transcoding — automatic
When video is uploaded, it is automatically converted into playback formats. This runs entirely on infrastructure we operate and is not sent to any AI service. Working copies are removed once the job completes.
5.2 Thumbnails and previews — in your browser
Thumbnails and hover-scrub previews are generated locally in the uploading user's browser. The media does not leave the device for this step.
5.3 Transcription — only when requested
Speech-to-text transcription is optional and per-asset. It runs only when a user chooses to generate a transcript for a specific file.
When requested, the audio track is extracted and sent to OpenAI for transcription. The video file itself is never sent. The extracted audio is removed from our processing infrastructure once the job completes. The resulting transcript is stored with the asset in the agency's account.
5.4 Generated captions, titles, and hashtags — only when requested
When a user asks Klaaro to generate captions, titles, hashtags, or director's notes, the transcript text and related asset metadata are sent to OpenAI. The original media is not sent for this step.
5.5 About OpenAI
OpenAI does not use data submitted through its API to train its models. OpenAI may retain API data for a limited period for abuse monitoring under its own published terms. See Section 7.1 for details.
5.6 Accuracy
Transcripts and generated text are produced by automated systems and may contain errors. They must be reviewed before use. None of this processing produces legal effects or decisions about individuals.
5.7 Consent for people appearing in content
Where a video contains third parties — talent, employees, interviewees, members of the public — the agency uploading it is responsible for having obtained the necessary permissions, including permission for the transcription described above. This obligation is set out in our Terms of Service.
6. Cookies and analytics
We do not use advertising cookies, tracking pixels, or cross-site trackers. We do not use session replay — we do not record your screen, mouse movements, or keystrokes.
We use:
Strictly necessary cookies for authentication and session management. The Service does not function without these.
Cookieless analytics measuring page routes and performance timings, without cookies and without device fingerprinting.
Error monitoring configured to exclude user identity, cookies, query parameters, and request bodies, with automatic redaction of credentials and signed URLs before any report is transmitted.
Because we do not use cookies for analytics, advertising, or profiling, no consent banner is presented.
7. Who we share data with
We share personal data with service providers ("subprocessors") who help us run the Service. Each is bound by contract to protect it, use it only for the services we have engaged them for, and not for their own purposes. The full list is in Section 7.1 below.
We may also disclose data:
when legally required, in response to valid legal process, or to protect rights, safety, or property;
in connection with a merger, acquisition, financing, or sale of assets, with notice to affected customers and subject to equivalent protection;
to professional advisors under confidentiality obligations.
We do not sell personal data to anyone.
7.1 Subprocessor list {#subprocessors}
All customer data is stored and processed in the United States.
We notify customers at least thirty (30) days before adding a new subprocessor that will process Customer Content. To receive these notices, email contact@klaaro.co and ask to be added to the list. Customers may object to a new subprocessor on reasonable data protection grounds; if we cannot offer a reasonable alternative, the customer may terminate the affected part of the Service.
Infrastructure
Provider | Purpose | Location | Customer Content |
Supabase | Database and authentication | United States | Yes — account data, comments, transcripts, metadata |
Backblaze | Object storage for uploaded files | United States | Yes — all uploaded media |
Vercel | Application hosting | United States | Yes — data in transit |
Amazon Web Services | Job queueing, video transcoding, transcription processing | United States | Yes — video and audio during processing |
Product features
Provider | Purpose | Location | Customer Content |
OpenAI | Speech-to-text transcription (on request); generation of captions, titles, and hashtags (on request) | United States | Yes — extracted audio and transcript text, only when a user requests it |
Permit.io | Role and permission management | United States | No — user, role, and organisation identifiers only |
Resend | Transactional email delivery | United States | No — names, email addresses, notification content |
Pathfix | Slack notification delivery, where a customer enables it | United States | No — notification content and channel names |
Billing
Provider | Purpose | Location | Customer Content |
Stripe | Payment processing and subscription billing | United States | No — billing data only |
Operations
Provider | Purpose | Location | Customer Content |
Vercel Analytics | Cookieless product and performance analytics | United States | No — page routes and timings only |
Sentry | Error monitoring | United States | No — diagnostics, with identity, cookies, query parameters, and request bodies excluded and credentials redacted |
8. Our personnel
Our team includes employees and individual contractors who work under our direction and on our systems. Some of them may access personal data, including from locations outside the United States, where necessary to build, operate, secure, and support the Service.
All personnel are bound by written confidentiality and data protection obligations, work under access controls limited to what their role requires, and access customer data only where necessary. Personal data is not copied to personal devices or systems outside our control. Our personnel work under our direction on our systems and are not subprocessors.
9. International transfers
All customer data is stored and processed in the United States. If you access Klaaro from outside the United States, your data will be transferred to and processed in the United States, where data protection laws differ from those in your jurisdiction.
Where our customers are subject to laws requiring a transfer mechanism, our Data Processing Addendum includes Standard Contractual Clauses.
10. Retention and deletion
What | How long |
Files sent to trash | 30 days, then permanently deleted |
Deleted file versions in object storage | Purged within 30 days |
Database backups | Rolling 7 days |
Trial accounts that are not converted | Permanently deleted 14 days after trial expiry |
Share-link access records | Retained for the life of the account (see below) |
Billing records | As required by tax and accounting law, typically 7 years |
Account and Customer Content after cancellation | Retained until deletion is requested (see below) |
10.1 After cancellation
When a subscription is cancelled, we currently retain the account and its Customer Content until deletion is requested. We do not automatically purge cancelled accounts. To have an account and all its content permanently deleted, email contact@klaaro.co from the account's registered address. We will action the request and confirm when it is complete.
We are working toward automatic deletion after a defined period following cancellation. This policy will be updated when that changes.
10.2 Backups
When data is deleted from active systems, residual copies may remain in database backups for up to seven (7) days, and in object storage for up to thirty (30) days, after which they are permanently removed. Deleted data is not restored to active systems.
10.3 Share-link access records
Records of share-link access, including the entered display name and hashed IP and user agent, are retained for the life of the account and not automatically deleted. They exist to preserve the review and approval audit trail that agencies rely on. Deleting these records would erase the attribution of who approved what.
10.4 Older files
Object storage lifecycle rules were introduced on [DATE]. Deleted files predating that change may persist longer. Contact contact@klaaro.co if you need confirmation about specific historical content.
11. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including:
encryption in transit (TLS) and at rest;
role-based access control with least-privilege provisioning;
authentication managed by a dedicated identity provider;
direct browser-to-storage upload using short-lived signed URLs, so files do not transit our application servers;
automatic redaction of credentials and signed URLs in error monitoring;
rate limiting on public endpoints;
separation of environments and access logging.
No system is perfectly secure. We cannot guarantee absolute security, and the Service is not designed for protected health information, payment card data, government identifiers, or other data subject to specialised regulatory regimes, which must not be uploaded.
If we become aware of a breach affecting personal data, we will notify affected customers without undue delay and cooperate with them in meeting their own notification obligations.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the use of your personal data, to object to certain processing, and to withdraw consent.
If you are an agency using Klaaro, exercise these rights by emailing contact@klaaro.co from your registered address, or through your account settings.
If you are a client, employee, or other individual whose data an agency has put into Klaaro, contact that agency. They control the data and we act on their instructions. If you contact us, we will forward your request to them.
We will not discriminate against you for exercising your rights. We respond within the timeframes required by applicable law — generally 30 days under GDPR and 45 days under US state privacy laws.
13. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If we learn we have, we will delete it.
14. Changes
We may update this policy. For material changes we will give at least thirty (30) days' notice by email or in-product before they take effect. The date at the top shows when it was last revised.
15. Contact
Privacy questions and requests: contact@klaaro.co General enquiries: hello@klaaro.co
Catalytics Group, LLC 1000 Brickell Avenue Suite #715 PMB 734 Miami, FL 33131
