Privacy Policy
Last updated: May 2026
This Privacy Policy describes how Softaar Technologies UG (haftungsbeschränkt) ("we", "us", "Klugon") collects, uses, and shares personal data when you use the Klugon platform at klugon.com. It applies to all users of our website and services.
1. Data Controller
Softaar Technologies UG (haftungsbeschränkt)
Blasewitzer Str. 41, ABAKUS Business Center
01307 Dresden, Germany
Email: contact@softaar.com
2. Data We Collect
Account data: name, email address, company name, and password hash when you create an account.
Billing data: billing address and payment method details processed by Stripe. We do not store full card numbers.
Usage data: conversation logs, chatbot configurations, knowledge base content, and integration settings you add to your Klugon workspace.
Technical data: IP addresses, browser type, pages visited, and session identifiers collected automatically when you use the platform.
Communications: messages you send us via email or support channels.
3. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR) — to provide, operate, and improve the Klugon service.
- Legitimate interests (Art. 6(1)(f) GDPR) — for security, fraud prevention, and service analytics.
- Legal obligation (Art. 6(1)(c) GDPR) — for tax and accounting records.
- Consent (Art. 6(1)(a) GDPR) — for marketing communications where required.
4. How We Use Your Data
- Providing and operating the Klugon service
- Processing payments and issuing invoices
- Sending transactional and service emails (account confirmations, billing receipts)
- Improving platform features through aggregated, anonymised analytics
- Complying with legal obligations and tax requirements
5. Sub-Processors and Third-Party Services
We work with the following sub-processors to deliver the service:
| Provider | Purpose | Location |
|---|---|---|
| Google Firebase | Authentication, database, and cloud functions | USA (SCCs) |
| OpenAI | AI language model processing | USA (SCCs) |
| Stripe | Payment processing | USA (SCCs) |
| Twilio | Voice and SMS services (optional) | USA (SCCs) |
| Vercel | Application hosting and edge network | USA/EU (SCCs) |
SCCs = Standard Contractual Clauses (EU–US data transfer mechanism).
6. Data Retention
We retain account and usage data for the duration of your active subscription plus 30 days after account deletion, to allow recovery.
Billing records are retained for 10 years as required by German tax law (§ 147 AO).
You may request earlier deletion of your data by contacting us at contact@softaar.com.
7. Your Rights Under GDPR
If you are located in the European Economic Area, you have the following rights:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion ("right to be forgotten")
- Restriction — ask us to pause processing your data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
To exercise any right, email us at contact@softaar.com. We respond within 30 days. You also have the right to lodge a complaint with the relevant supervisory authority (in Germany: the Saxon Data Protection Commissioner, saechsdsb.de).
8. Cookies
We use session cookies necessary for authentication and service functionality. We do not use third-party advertising or tracking cookies. You can disable cookies in your browser settings, but doing so may prevent you from logging in.
9. Security
We implement technical and organisational measures appropriate to the risk, including HTTPS encryption, access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
10. Children
Klugon is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and update the "Last updated" date above. Continued use of the service after changes constitutes acceptance.
12. Contact
Questions about this Privacy Policy can be directed to:
contact@softaar.com
Softaar Technologies UG, Blasewitzer Str. 41, 01307 Dresden, Germany