Privacy Policy
Last updated: 11 July 2026
This policy explains how Klievo (“we”, “us”) — a business based in Australia operating the Klievo event-CRM platform (the “Service”) — collects, uses, stores and discloses personal information. It is written to meet the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, and the EU/UK General Data Protection Regulation (“GDPR”) for users in those regions. Contact us any time at support@klievo.com.
1. The two kinds of data we handle
a. Account data — we are the controller
When a studio signs up we collect the information needed to run their workspace: name, email address, authentication details (or your Google/Apple/Microsoft sign-in identity), business profile details, billing information (handled by Stripe — we never store full card numbers), and support correspondence.
b. Customer Data — we are the processor
Studios use Klievo to manage their own business records, which include personal information about their clients, leads and crew: names, email addresses, phone numbers, event details, messages, questionnaire responses, contracts and signatures, invoices and payment records. For this data the studio is the controller (or “APP entity”) and Klievo processes it only on the studio's instructions to provide the Service. If you are a client of a studio that uses Klievo and you want your information corrected or deleted, contact that studio first — we will assist them in fulfilling your request.
2. What we collect automatically
- Operational logs — IP address, browser type, requests and errors, used for security, rate limiting and debugging.
- Error telemetry (Sentry) — stack traces and request context when something breaks, so we can fix it.
- Product analytics (PostHog, EU-hosted) — feature usage events, collected only after you accept the analytics consent banner. If you decline, no analytics are collected. You can change your choice at any time.
- Email interaction — if a studio enables it, emails it sends through Klievo may include an open-tracking pixel.
3. How we use personal information
- to provide, secure and support the Service (contract performance);
- to bill for subscriptions (contract performance / legal obligation);
- to send service and security notices (legitimate interests);
- to improve the product using consent-gated analytics (consent);
- to comply with law, and to establish or defend legal claims.
We do not sell personal information, and we do not use Customer Data to train AI models.
4. Cookies and the consent banner
Klievo uses strictly-necessary cookies to keep you signed in, remember your active workspace, and protect against cross-site request forgery. These are required for the Service to work and cannot be switched off. Optional analytics run only after you accept the in-product consent banner; declining (or ignoring) the banner keeps analytics off. We do not use third-party advertising cookies.
5. Who we share data with (subprocessors)
We share personal information only with the service providers below, each bound by their own data-protection commitments, and only to the extent needed to run the feature involved:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | Cloud infrastructure (region pinned per project) |
| Vercel | Application hosting and content delivery | Global edge network |
| Stripe | Payment processing (your subscription to Klievo, and payments your clients make to you when you connect your own Stripe account) | Global |
| Email sending/reading and calendar sync — only when you connect a Google account | Global | |
| Microsoft | Email sending/reading and calendar sync — only when you connect a Microsoft account | Global |
| Meta Platforms | WhatsApp, Instagram and Facebook messaging — only when you connect those channels | Global |
| Twilio | SMS messaging — only when you connect SMS | Global |
| Sentry | Error telemetry so we can find and fix crashes | Cloud (errors only, no session recording) |
| PostHog (EU) | Product analytics — only after you accept the analytics consent banner | European Union |
| Cloudflare (Workers AI) | AI-assisted drafting features (for example suggested replies) | Global edge network |
Connected-account providers (Google, Microsoft, Meta, Twilio, Stripe, and accounting integrations) only receive or provide data for workspaces that explicitly connect those accounts. We may also disclose information where required by law or to protect the rights, safety or property of Klievo, our users or the public.
Klievo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. International transfers
Our providers operate global infrastructure, so personal information may be processed outside your country (including outside Australia, the EU and the UK). Where the GDPR applies, we rely on adequacy decisions or standard contractual clauses put in place by our providers. Product analytics is deliberately EU-hosted.
7. Security
All traffic is encrypted in transit (TLS) and data is encrypted at rest by our infrastructure providers. Access to production data is restricted, tenant data is isolated per workspace at the database layer (row-level security), secrets are stored encrypted, and we apply security headers, rate limiting and audit logging across the platform. No system is perfectly secure — if we become aware of a data breach that is likely to result in serious harm, we will notify affected users and the relevant regulator (including under the Australian Notifiable Data Breaches scheme and GDPR articles 33–34).
8. Retention and deletion
- Account and Customer Data are retained while your workspace is active.
- When a workspace is deleted — at your request via support@klievo.com — its records are permanently removed from the production database, with residual copies expiring from encrypted backups on a rolling schedule (typically within 30 days).
- Billing records are kept as long as tax and accounting law requires.
9. Your rights
Depending on where you live (including under the Privacy Act and the GDPR), you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal information, and to withdraw consent (for example, analytics consent) at any time. Studios can export their core records (clients, jobs, invoices) directly from the Service. To exercise any other right — including full account deletion — email support@klievo.com; we respond within 30 days. If you are unsatisfied with our response you can complain to your local regulator (in Australia, the OAIC at oaic.gov.au; in the EU/UK, your data-protection authority).
10. Children
The Service is for businesses and is not directed at children under 16. We do not knowingly collect personal information from children as account holders.
11. Changes to this policy
We may update this policy from time to time. For material changes we will give notice by email or in-product notice before the change takes effect. The “Last updated” date at the top reflects the current version.
12. Contact
Privacy questions, requests and complaints: support@klievo.com.