[…] are to be confirmed before publication.Kapllan ID · Legal
Privacy Policy
Version 0.1 (draft) · Effective TBD
Kapllan is built on a simple principle: your data should be owned, not borrowed. This policy explains what we collect, why, how we protect it, and the control you have over it. We keep it in plain language and short — if anything is unclear, ask us.
1.Who we are
This Privacy Policy explains how [Kapllan legal entity — org. nr. to confirm](“Kapllan”, “we”, “us”) collects and processes personal data when you create a Kapllan account and use our products, including Llana and other services that sign in with Kapllan ID.
For the personal data described here, Kapllan is the data controller. Where you use Kapllan through an organisation (for example, your employer’s enterprise account), that organisation is the controller of the content you submit, and Kapllan acts as its processor under a separate data processing agreement.
We are based in the Nordics and operate our own computing infrastructure. Our supervisory authority for data protection is [Datatilsynet (Norway) / IMY (Sweden) — confirm per registered entity].
2.Information we collect
We collect only what an account needs to function and stay secure:
Information you provide
- Account details — your email address and name, provided when you register.
- Authentication credentials — passkeys (public keys) you enrol. Kapllan is passwordless: we do not ask for, store, or transmit passwords.
- Linked sign-in providers — if you choose to sign in with Google, GitHub, or another provider, we receive your email and basic profile from that provider to link it to your account. This is optional and can be unlinked at any time.
- Consents — your acceptance of our terms (with version and timestamp), and your marketing and model-training choices.
- Content you submit — the prompts, files, and other inputs you provide to a product in order to receive a response.
Information collected automatically
- Security and audit events — sign-in events, IP address, device/browser information, and timestamps, used to protect your account.
- Preferences — language, theme, and similar settings.
We do not sell your personal data, and we do not use it for advertising.
3.How and why we use your data
We process personal data for these purposes and legal bases under the GDPR:
| Purpose | Data | Legal basis |
|---|---|---|
| Create and operate your account; provide the product | Email, name, credentials, content you submit | Performance of a contract |
| Keep your account and our services secure | Sign-in and audit events, IP, device info | Legitimate interests (security) |
| Record terms acceptance | Consent records (version, timestamp) | Legal obligation |
| Send product and marketing updates | Email, marketing preference | Consent (opt-in; withdraw anytime) |
| Improve our AI models | Content you submit, if you opt in | Consent (off by default — see below) |
4.Model training
By default, we do not use your content to train our AI models. Model training is strictly opt-in. You can turn it on or off at any time in your account settings, and your choice is enforced at the data-pipeline level — not only in the interface.
If you use Kapllan through an organisation, training on that organisation’s content is governed by its agreement with us and is off unless the organisation enables it.
6.Where your data is stored
Core processing and storage happen on our own infrastructure in the Nordics, within the European Economic Area (EEA). This is a deliberate design choice: your data stays in Europe by default.
Where a subprocessor is outside the EEA (for example, a payment processor), any transfer relies on an approved safeguard such as the EU Standard Contractual Clauses, and is limited to the data that provider needs.
7.How long we keep it
We keep account data for as long as your account is active. When you delete your account, we remove or anonymise your personal data, subject to a short grace period (a deletion “tombstone”, typically 30 days) after which the deletion propagates to backups.
Some records are kept longer where the law requires it (for example, records of terms acceptance, or invoicing records once billing is active). Security logs are kept on a rolling short-term basis.
8.Your rights
Under the GDPR you have the right to:
- Access — get a copy of your data. You can download an export directly from your account settings.
- Rectification — correct inaccurate data.
- Erasure — delete your account and data, from settings or on request.
- Portability — receive your data in a portable format.
- Object / restrict — object to or limit certain processing.
- Withdraw consent — for anything based on consent (marketing, model training), at any time, without affecting prior processing.
- Complain — lodge a complaint with your supervisory authority.
To exercise these rights, use your account settings or contact privacy@kapllan.ai. We respond within the timeframe required by law (generally one month).
9.How we protect your data
Kapllan ID is passwordless: sign-in uses passkeys and one-time email codes, which removes the most common account-takeover routes. We apply encryption in transit, brute-force protection, rate limiting, and audit logging, and we restrict administrative access to your account.
No system is perfectly secure, but security is central to how the platform is built. If a breach affects your data, we will notify you and the relevant authority as required by law.
11.Children
Kapllan is not directed to children. You must be at least the age of digital consent in your country (for example, 13 in Norway) to create an account. We do not knowingly collect data from children below that age.
12.Changes to this policy
We may update this policy as our services evolve. We will post the new version here with an updated version number and effective date, and for material changes we will notify you and, where required, ask you to review the changes.
Questions about this document or your data? Contact privacy@kapllan.ai.