Subprocessors
Everyone else who touches the data.
klaspr does not run its own servers, its own database or its own models. This is the complete list of providers that process data on our instructions, what each one receives, and where it sits.
Last updated 17 August 2026
Current subprocessors
- Purpose
- Database, authentication and file storage for the application.
- Data received
- Account email, authentication credentials, organisation and company profile data, discovery results, monitoring records.
- Location
- [hosting region]
- Purpose
- Application hosting, content delivery and scheduled jobs.
- Data received
- HTTP request metadata (IP address, user agent, requested URL) and anything submitted through the application in transit.
- Location
- United States, with edge delivery worldwide
- Purpose
- Web search, used to find candidate competitors.
- Data received
- Search queries generated from your company profile. No account identifier is attached to a query.
- Location
- United States
- Purpose
- Large language model used to turn a company profile into search queries and to classify candidates. Default provider.
- Data received
- Your company profile fields (name, website, industry, country, description, products, target audience), the text of public pages read for a scan, and candidate company names.
- Location
- United States
- Purpose
- Alternative language model provider, selectable by configuration.
- Data received
- Same as the default provider when it is the one configured.
- Location
- United States
- Purpose
- Alternative language model gateway, selectable by configuration.
- Data received
- Same as the default provider when it is the one configured.
- Location
- United States
“Optional” means the provider is an alternative that a deployment can be configured to use instead of the default language model provider. It is listed because it can process the same data, not because it currently does.
What is not on this list
These absences are as informative as the entries, and each one is verifiable from the project’s dependencies:
- No payment processor. Nothing is billed, and no card data is collected, transmitted or stored anywhere.
- No email provider. klaspr sends no email beyond what the authentication service issues for sign-in itself. There are no alerts, no briefs and no marketing mail.
- No analytics or advertising provider. See the cookie policy.
- No font or asset CDN. Typefaces and images are served from klaspr’s own domain.
Transfers outside the EEA
Providers established in the United States are marked as such above. Transfers to them rely on the European Commission’s Standard Contractual Clauses, and where applicable on certification under the EU-US Data Privacy Framework. Each provider’s own terms, linked in the table, set out the guarantees it offers.
Changes to this list
Adding a subprocessor is a change to how your data is handled, so it is announced rather than merely recorded. This page is updated before a new provider starts processing customer data, and the date at the top reflects the change.
To be notified of changes, or to object to a specific provider, write to [privacy contact email].