Last updated: July 2026
Klaro ('Klaro', 'we', 'us') operates klaro.services and builds three products: Consentra (cookie & consent management), Sentinel (compliance readiness monitoring for SOC 2, HIPAA, CMMC, ISO 27001, and CIS), and KlaroShield — both a hosted PII/token redaction proxy, and @klaroshield/sdk, an MIT-licensed, self-hosted npm package developers install locally. This policy applies to klaro.services, our dashboards, our embeddable widgets (Consentra's consent banner, KlaroShield's proxy), and the anonymous telemetry described in Section 2a that @klaroshield/sdk sends by default. Contact: privacy@klaro.services
(a) Account data — name, email, company name, billing details. (b) Product data you send us to provide the service: • Consentra: the domains you register, your banner configuration, and the consent decisions your site visitors record (their category choices and a timestamp — Consentra is designed to store the minimum needed to prove consent, not to build a profile of your visitors). • Sentinel: the assets, integrations, and questionnaire answers you provide for a compliance scan, and any findings/artifacts the scan produces. • KlaroShield: request/response payloads pass through our proxy in-memory to be redacted before forwarding — we do not persist the raw, unredacted content. (c) Usage data — features used, login times, actions taken in your dashboard. (d) Payment data — processed by Razorpay. We store only transaction references and invoice amounts, never full card or bank details. (e) Technical data — IP address, browser, device type, session identifiers.
@klaroshield/sdk, our open-source (MIT) local-first middleware package, sends anonymous product telemetry by default — enabled out of the box, disabled with one command (npx klaro telemetry disable) or the KLARO_TELEMETRY=0 environment variable, with the SDK fully functional either way. What is sent: a randomly-generated installation ID and project ID (UUIDs, never derived from your hardware or any identifying value), the SDK and Node.js version, your OS platform, which middleware functions you have configured (e.g. "retries", "pii" — not their options or what they matched), and which CLI command you ran. What is never sent, under any circumstance: prompts, responses, model output, API keys, secrets, PII, the contents of any local file (including .klaro/logs.jsonl), or your source code. The SDK has no code path that reads request/response bodies for telemetry purposes at all. Full detail: klaro.services/klaroshield/privacy.
• To provide and operate Consentra, Sentinel, and KlaroShield • To process payments and issue invoices • To send transactional communications (account, billing, security alerts) • To improve the platform based on aggregate usage patterns • To comply with applicable legal obligations • To prevent fraud, abuse, and unauthorised access We do NOT sell your data. We do NOT use your visitors' consent records or your KlaroShield proxy traffic for advertising. We do NOT share your data with third parties except as described in Section 5.
If you use Consentra on your website, your site's visitors interact with our banner and their consent decisions are recorded on your behalf. We act as a data processor for that consent-decision data — you (our customer) are the data controller for your own site's visitors under GDPR/CCPA/DPDP and the other frameworks Consentra supports. We process this data only as needed to operate the banner and produce your consent ledger/reports; we do not use it for our own marketing or combine it across customers to build cross-site visitor profiles.
We share data only with: - Razorpay — payment processing - Supabase / our own Postgres infrastructure — database hosting - Vercel — application hosting - Email delivery providers — transactional and account communications All processors are bound by data processing agreements. We do not share data with government authorities except when legally compelled with a valid court order or statutory requirement.
Depending on where you or your site visitors are located, you may have rights under GDPR, CCPA/CPRA, India's DPDP Act, and other privacy laws Consentra supports, including: - Access: Request a copy of your data - Correction: Update incorrect data - Deletion: Request deletion (subject to legal retention requirements) - Export: Download your data in standard formats - Withdraw consent: For marketing communications, and for Consentra end-visitors, via the banner itself at any time Exercise rights: privacy@klaro.services. Response within 30 days.
Active accounts: Data retained while the account is active. After cancellation: Account data retained in read-only mode for 90 days for self-service export, then archived. Consentra consent records: Retained as your ledger of proof-of-consent for as long as your account is active, or as required to demonstrate historical compliance. KlaroShield proxy traffic: Not persisted in unredacted form; only aggregate usage counters are retained for billing/metering. @klaroshield/sdk telemetry: Anonymous events (installation ID, project ID, and the fields in Section 2a) are retained indefinitely for aggregate product analytics, since they are not linked to any account or identity and there is nothing to "delete" that identifies you. Disabling telemetry (Section 2a) stops all future collection immediately.
We implement industry-standard security including TLS encryption in transit, encryption at rest, tenant-scoped access controls (every customer can only access their own domains/scans/data), and session management. Despite our best efforts, no system is 100% secure. Report security issues to security@klaro.services.
klaro.services itself uses only essential cookies (session management, authentication) plus first-party product analytics. We do not use advertising cookies. Klaro dogfoods its own Consentra product on this site — see the consent banner for the categories in use.
Klaro's products are not directed at anyone under 18. We do not knowingly collect data from minors. If you believe a minor has signed up, contact privacy@klaro.services immediately.
Klaro operates globally and infrastructure may be located outside your country. Where required, transfers are covered by appropriate safeguards such as standard contractual clauses.
We will notify users of material changes to this policy by email and in-app notification at least 30 days before they take effect.
Privacy: privacy@klaro.services Security: security@klaro.services General: vc@klaro.services