Draft — pending legal review. This document describes Kapllan’s intended data practices and is not yet a finalised legal agreement. Entity details marked […] are to be confirmed before publication.

Kapllan ID · Legal

Privacy Policy

Version 0.1 (draft) · Effective TBD

Kapllan is built on a simple principle: your data should be owned, not borrowed. This policy explains what we collect, why, how we protect it, and the control you have over it. We keep it in plain language and short — if anything is unclear, ask us.

1.Who we are

This Privacy Policy explains how [Kapllan legal entity — org. nr. to confirm](“Kapllan”, “we”, “us”) collects and processes personal data when you create a Kapllan account and use our products, including Llana and other services that sign in with Kapllan ID.

For the personal data described here, Kapllan is the data controller. Where you use Kapllan through an organisation (for example, your employer’s enterprise account), that organisation is the controller of the content you submit, and Kapllan acts as its processor under a separate data processing agreement.

We are based in the Nordics and operate our own computing infrastructure. Our supervisory authority for data protection is [Datatilsynet (Norway) / IMY (Sweden) — confirm per registered entity].

2.Information we collect

We collect only what an account needs to function and stay secure:

Information you provide

  • Account details — your email address and name, provided when you register.
  • Authentication credentials — passkeys (public keys) you enrol. Kapllan is passwordless: we do not ask for, store, or transmit passwords.
  • Linked sign-in providers — if you choose to sign in with Google, GitHub, or another provider, we receive your email and basic profile from that provider to link it to your account. This is optional and can be unlinked at any time.
  • Consents — your acceptance of our terms (with version and timestamp), and your marketing and model-training choices.
  • Content you submit — the prompts, files, and other inputs you provide to a product in order to receive a response.

Information collected automatically

  • Security and audit events — sign-in events, IP address, device/browser information, and timestamps, used to protect your account.
  • Preferences — language, theme, and similar settings.

We do not sell your personal data, and we do not use it for advertising.

3.How and why we use your data

We process personal data for these purposes and legal bases under the GDPR:

PurposeDataLegal basis
Create and operate your account; provide the productEmail, name, credentials, content you submitPerformance of a contract
Keep your account and our services secureSign-in and audit events, IP, device infoLegitimate interests (security)
Record terms acceptanceConsent records (version, timestamp)Legal obligation
Send product and marketing updatesEmail, marketing preferenceConsent (opt-in; withdraw anytime)
Improve our AI modelsContent you submit, if you opt inConsent (off by default — see below)

4.Model training

By default, we do not use your content to train our AI models. Model training is strictly opt-in. You can turn it on or off at any time in your account settings, and your choice is enforced at the data-pipeline level — not only in the interface.

If you use Kapllan through an organisation, training on that organisation’s content is governed by its agreement with us and is off unless the organisation enables it.

5.How we share data

We share personal data only with service providers who process it on our behalf under contract (“subprocessors”), and only as needed to run the service. Our current subprocessors:

ProviderPurposeLocation
Google (Workspace)Transactional and account email deliveryEU region
HetznerEdge hosting / networkEU (Germany / Finland)
Kapllan (own infrastructure)Core processing, model inference, storageNordics (EEA)
Stripe [when billing launches]Payment processingSee Stripe’s terms (US entity; SCCs)

We keep this list current and will update it before adding a new subprocessor that handles personal data. We may also disclose data where legally required, or to protect our rights and users’ safety.

6.Where your data is stored

Core processing and storage happen on our own infrastructure in the Nordics, within the European Economic Area (EEA). This is a deliberate design choice: your data stays in Europe by default.

Where a subprocessor is outside the EEA (for example, a payment processor), any transfer relies on an approved safeguard such as the EU Standard Contractual Clauses, and is limited to the data that provider needs.

7.How long we keep it

We keep account data for as long as your account is active. When you delete your account, we remove or anonymise your personal data, subject to a short grace period (a deletion “tombstone”, typically 30 days) after which the deletion propagates to backups.

Some records are kept longer where the law requires it (for example, records of terms acceptance, or invoicing records once billing is active). Security logs are kept on a rolling short-term basis.

8.Your rights

Under the GDPR you have the right to:

  • Access — get a copy of your data. You can download an export directly from your account settings.
  • Rectification — correct inaccurate data.
  • Erasure — delete your account and data, from settings or on request.
  • Portability — receive your data in a portable format.
  • Object / restrict — object to or limit certain processing.
  • Withdraw consent — for anything based on consent (marketing, model training), at any time, without affecting prior processing.
  • Complain — lodge a complaint with your supervisory authority.

To exercise these rights, use your account settings or contact privacy@kapllan.ai. We respond within the timeframe required by law (generally one month).

9.How we protect your data

Kapllan ID is passwordless: sign-in uses passkeys and one-time email codes, which removes the most common account-takeover routes. We apply encryption in transit, brute-force protection, rate limiting, and audit logging, and we restrict administrative access to your account.

No system is perfectly secure, but security is central to how the platform is built. If a breach affects your data, we will notify you and the relevant authority as required by law.

10.Cookies and local storage

We use strictly necessary cookies and local storage to keep you signed in and to remember your preferences. We do not use advertising or cross-site tracking cookies. Your sign-in session is held in a secure, http-only cookie.

11.Children

Kapllan is not directed to children. You must be at least the age of digital consent in your country (for example, 13 in Norway) to create an account. We do not knowingly collect data from children below that age.

12.Changes to this policy

We may update this policy as our services evolve. We will post the new version here with an updated version number and effective date, and for material changes we will notify you and, where required, ask you to review the changes.


Questions about this document or your data? Contact privacy@kapllan.ai.