Parties and Roles
Customer: the organization or person using Klara for its own planning data.
Provider: Jasper Zimmerling, Leubnitzer Straße 28, 01069 Dresden, Germany.
For business customers, Customer acts as controller and Klara acts as processor for workspace content processed on Customer instructions.
For direct consumer accounts, Klara acts as controller for the consumer account and workspace data. This DPA applies to B2B customer processing unless a separate agreement states otherwise.
Subject Matter, Duration, and TOMs
Klara processes personal data to provide planning, task, calendar, goal, encryption, synchronization, optional Google Calendar and AI features, transactional email, feedback, export, and deletion functionality.
Processing continues for the account or subscription term and ends after deletion or return of data, subject to legal obligations and expiry through the documented infrastructure-backup cycle. The current signed infrastructure DPA does not state a fixed backup-retention period.
The Technical and Organizational Measures published by Klara form part of this DPA.
Documented Processing Instructions
Customer instructs Klara to store user content and account data necessary to provide the service.
Customer instructs Klara to sync account and workspace data across authenticated devices.
Customer instructs Klara to support browser-side encryption and decryption workflows for the encrypted fields described in the Privacy Policy and TOMs.
Customer instructs Klara to provide self-service data export and deletion functions.
If Customer or an authorized user activates an optional integration, Customer instructs Klara to exchange the minimum feature data with Google Calendar, OpenAI, Resend, or Discord as described in the Privacy Policy and subprocessor section.
Klara processes personal data only on documented Customer instructions, unless Union or Member State law requires processing. Klara informs Customer of such legal requirement unless prohibited by law.
Categories of Data and Data Subjects
Data subjects include account users, people named in tasks or events, event attendees entered by users, and other individuals whose personal data is entered into Customer workspace content.
Personal data includes email address, identifiers, task/event/project content, calendar day highlight labels, week template content, notes, goals, timestamps, focus preferences, recurrence settings, relationship metadata, technical metadata, Google account and calendar data when connected, AI feature inputs and outputs, transactional email content, and user-submitted feedback or attachments.
Processor Obligations
Klara ensures that persons authorized to process personal data are bound by confidentiality obligations.
Klara implements the TOMs described in the Technical and Organizational Measures document.
Klara assists Customer, taking into account the nature of processing and available information, with data subject requests, security obligations, breach notification duties, data protection impact assessments, and prior consultation obligations.
Breach Notification
Klara notifies Customer without undue delay after becoming aware of a personal-data breach affecting Customer personal data.
The notification includes available information reasonably required for Customer to meet its GDPR breach notification obligations, including the nature of the breach, affected data categories, likely consequences, and measures taken or proposed.
Subprocessors
Levo Studio, operated by Julius Grimm in Germany, processes data for Klara under a signed Article 28 GDPR agreement and provides deployment, Docker Swarm and Dokploy administration, server and PostgreSQL operation, backups, monitoring, maintenance, security support, and technical troubleshooting.
The documented production infrastructure uses four EU/EEA nodes: one Hetzner Online GmbH node in Falkenstein, Germany; one DataLix node in Frankfurt am Main, Germany; and two Wordbase / SkyLink Data Center nodes in the Netherlands. The application runs as a containerized Next.js service with a PostgreSQL database. Vercel and Supabase are not part of the current production runtime.
Optional or feature-specific providers are Google Ireland Limited / Google LLC for Google Calendar synchronization; OpenAI Ireland Ltd. and OpenAI affiliates for requested transcription and goal drafting; Plus Five Five, Inc. (Resend) for transactional account-verification and password-reset email; and Discord Netherlands B.V. / Discord Inc. for configured feedback, mailing-list, operational, and security webhooks.
Klara informs Customer about intended additions or replacements of subprocessors before the change takes effect. Customer can object where required by GDPR or the applicable customer agreement.
Klara imposes data protection obligations on subprocessors that are equivalent in substance to this DPA and remains responsible for subprocessor performance.
International Transfers
Where personal data is transferred outside the EU/EEA, Klara relies on an applicable transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, and supplementary measures where required.
Core hosting and database processing is documented in Germany and the Netherlands. Optional Google, OpenAI, Resend, and Discord processing can occur outside the EU/EEA. The relevant provider DPA, adequacy or Data Privacy Framework coverage, and/or EU Standard Contractual Clauses apply as documented by the provider.
Klara updates its subprocessor and transfer disclosures when a provider, purpose, or material processing location changes.
Return and Deletion
Upon termination, Customer can request return of personal data through the self-service export where available, followed by deletion.
Customer can also choose deletion through the account deletion flow. Deletion removes the application account and associated app data from live systems, subject to the documented infrastructure-backup cycle, provider-specific deletion processes, and legal obligations.
Audit and Information
Klara provides information reasonably necessary to demonstrate compliance with this DPA, including TOMs, subprocessor information, and relevant security summaries.
Customer audits are scoped, pre-notified, and limited to what is necessary to verify compliance without compromising other users, confidential information, or system security.