Privacy Policy.
A short, plain-language explanation of every piece of personal data this site touches, why, and what your rights are. In summary: analytics only if you opt in, no cross-site tracking, and no marketing pixels.
Who is collecting your data
Klariad (“Klariad”, “we”, “us”) is the data controller for all personal data processed through klariad.eu and the related client platform at app.growbeyond.ai. Klariad is a trading name of Klariad EU OÜ (registry code 17589008), Tornimäe tn 5, 10145 Tallinn, Estonia. We serve clients in Denmark, the wider EU, and globally. For any question about your data, contact us at mail@klariad.eu.
What data this site processes
There are two categories.
1. Things you actively give us
Your name, email, and message when you submit the contact form. Stored in our database so that we can reply to you. Never shared, never added to a mailing list — this site runs no newsletter and no sales follow-up.
Your conversations with our intake assistant — voice, chat, the guided session, the phone line, and the composer on the front page. They are processed to answer you in the moment, and we review them internally so the assistant’s knowledge covers what people actually ask. Raw conversation records are deleted within 90 days, and contact details are stripped before review. A brief you choose to file is handled like a contact-form lead, above.
2. Things stored on your device
By default, only Cloudflare’s strictly-necessary cookies (bot-protection on the contact form — see the Cookie Policy). Analytics cookies are set only if you opt in via the consent banner (see section 3). Once you answer the banner — accept or decline — your choice itself is kept in a small on-device record so we do not ask twice; it is not a cookie and never leaves your browser.
3. Things measured — only if you allow it
If you accept the consent banner, Google Analytics 4 records anonymised, aggregate usage (which pages are viewed, rough region, device type) so that we can see what is useful. Decline and nothing is measured — the Analytics script never loads. No cross-site tracking, no advertising profiles, no selling of data. Change your choice at any time via “Cookie settings” in the footer.
Why we are allowed to process this data
Under the GDPR, every piece of processing requires a legal basis. Ours are:
- Consent (Art. 6(1)(a)) — for Google Analytics. It runs only after you opt in via the banner, and you can withdraw at any time via “Cookie settings” in the footer.
- Legitimate interest (Art. 6(1)(f)) — for the contact form (you submitted it; we need to reply) and for security/bot-prevention (Cloudflare Turnstile). You can object via email.
- Contractual necessity (Art. 6(1)(b)) — for any data exchanged once we are working together on an engagement.
How long we keep things
- Contact-form leads — for the active conversation, then archived for up to 24 months for context if you re-engage. Deleted on request.
- Intake-assistant conversations — raw records up to 90 days, then deleted automatically. A filed brief follows the contact-form retention above.
- Cloudflare bot-protection — short-lived, set and expired by Cloudflare (30 minutes to 30 days).
- Google Analytics — only if you opt in: aggregate usage retained up to 14 months; the _ga cookies last up to 2 years (cleared sooner if you withdraw consent).
Who we share data with
A short and complete list:
- Cloudflare — DNS, CDN, and Turnstile bot-protection. They process IPs and basic request metadata as a sub-processor. Cloudflare’s privacy policy.
- Google (Analytics) — only if you accept analytics. Google processes anonymised usage data as a sub-processor; data may be handled in the US under Standard Contractual Clauses and Google’s EU-US Data Privacy Framework certification. Nothing is shared with Google until you opt in.
- AI processing (xAI and Anthropic) — only when you talk to the intake assistant. The assistant’s replies are generated by xAI (the voice, chat, session and phone doors) and Anthropic (the front-page composer); your conversation text is sent to them to produce the reply, under their API terms. xAI’s privacy policy · Anthropic’s privacy policy.
- The hosting provider — our own EU VPS hosts both the marketing site and the platform (files + database); DNS and bot-protection run through Cloudflare. one.com provides email for the klariad.eu mailboxes. They host infrastructure, nothing more.
We do not sell data, share it with advertisers, run retargeting pixels, embed third-party trackers, or send your data to anyone for any purpose unrelated to delivering the service.
International data transfers
Some sub-processors (Cloudflare, and Google Analytics if you opt in) operate globally. Where data leaves the EEA, it is covered by Standard Contractual Clauses (SCCs)or an adequacy framework (Google’s EU-US Data Privacy Framework) — the GDPR-approved transfer mechanisms. We keep our own primary database (contact-form leads) on a VPS in the EU.
Your rights
Under the GDPR you may request any of the following at any time. We will act within 30 days:
- Access — a copy of every piece of data we hold about you.
- Rectification — fix anything wrong.
- Erasure — delete everything (the “right to be forgotten”).
- Portability — get your data in a machine-readable format.
- Objection — stop processing based on legitimate interest.
- Lodge a complaint — with the Danish Data Protection Authority (Datatilsynet) or your local supervisory authority.
To exercise any of these, email mail@klariad.eu. We reply within one working day.
Children
This site is not directed at anyone under 16, and we do not knowingly collect data from children. If you believe a child has submitted personal data, contact us and we will delete it immediately.
Changes to this policy
If we change anything material, we will update this page and the “updated” date at the top. Analytics is opt-in: it stays off until you accept the consent banner, and you can withdraw at any time via “Cookie settings” in the footer — opt-in, never assumed.
Questions
Email mail@klariad.eu. We read every message.
— Klariad