Legal
Privacy policy
Last updated: September 2026
1. Who we are
Kliport ("we", "us", "our") provides a client portal platform where you manage projects, tasks, files, invoices, intake forms, and payments in a single branded workspace.
For account and billing data we are the controller. For the client data you and your team enter into your workspace (your clients, projects, forms, files, and invoices), you are the controller and we act as a processor under your instructions.
2. Information we collect
Account information you provide directly: your name, email address, password (stored only as a secure hash), workspace name, and profile details such as an avatar.
Workspace content you create: projects, tasks, client records, invoice line items, forms and their submissions, chat messages, service catalogs, and files you upload. Files are stored encrypted by Cloudflare R2 and served only through short-lived signed URLs.
Payment credentials and client payments: workspaces may connect their own Stripe or PayPal keys, which we encrypt at rest (AES-256-GCM). Payment card data is handled directly by your chosen payment provider — we never see or store full card details, and money settles directly to your account, never through us. For bank transfer payments we retain the account details and a reference you or your client submit.
Billing information: your subscription, plan tier, and payment status, processed through our billing provider (Dodo).
Technical data required to operate the service: session cookies for authentication, IP address, and browser user-agent captured for security logging.
3. How we use information
To provide the service: authenticate users, show workspaces to authorized members and clients, deliver transactional email (verification, invitations, password resets, paid-form receipts), store and share files securely, and process billing for your subscription.
To assist you in collecting from your clients via Stripe, PayPal, or bank transfer, on the workspaces configured by you.
To keep the service safe: prevent abuse, detect fraudulent or unauthorized access, and maintain audit logs of workspace activity you can review in-app.
We do not sell your personal data, and we do not use workspace content for advertising.
4. Legal bases under the GDPR
Providing the service under our contract with you — Article 6(1)(b) GDPR: account creation, authentication, file storage, and workspace features.
Legal obligations — Article 6(1)(c): we may retain invoicing and accounting records for tax purposes and respond to lawful requests from authorities.
Legitimate interests — Article 6(1)(f): securing the platform, preventing abuse, and improving our services. We balance these interests against your privacy rights.
Consent — Article 6(1)(a): where we place non-essential cookies or send marketing communications, we ask for your consent first, which you can withdraw at any time.
For client data collected through your intake forms, you are the controller and are responsible for establishing your own legal basis with your clients.
5. Data sharing
We share data only with processors necessary to run the service: our database hosting provider (Neon), file storage (Cloudflare R2), email delivery (Resend), hosting infrastructure, and our billing provider (Dodo). Each processes data solely on our instructions and is bound by a data processing agreement.
When a workspace connects Stripe or PayPal, we transmit only the data needed to create the payment (amount, currency, line items, and the payer’s email) to that workspace’s own provider account — you control which providers are connected.
Client users you invite can see only the data scoped to them — their own projects, files, tasks, forms, and invoices. Workspace data is strictly isolated by design.
6. International data transfers
Some of our processors (for example Cloudflare, Neon, and Stripe infrastructure) may transfer data outside the European Economic Area, including to the United States.
Where such transfers occur, we rely on the EU-U.S. Data Privacy Framework, the new EU-U.S. adequacy decision, or the European Commission’s Standard Contractual Clauses, and processors are required to maintain equivalent protections for your data.
7. Data retention & deletion
You can delete workspace records at any time from within the app. Deleting a workspace removes its associated data, including files removed from storage.
Authentication and billing data stays active as long as your account is active. We retain minimal accounting records where required by tax law (typically up to 10 years) and audit logs for security for a reasonable period.
If you want your account fully erased, contact us and we will delete it within 30 days, except where retention is legally required. When you delete your account we also trigger deletion of the personal data we process on your behalf, to the extent it cannot be recovered.
8. Security
Passwords are hashed, sessions are cookie-based and HTTP-only, uploaded files are served only through short-lived signed URLs after authorization checks, and payment credentials are encrypted at rest with AES-256-GCM. Transport encryption (TLS) is applied everywhere.
9. Your rights
If you are in the EU, EEA, UK, or Switzerland, the GDPR gives you rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21) to your personal data.
You may also object to or withdraw consent for non-essential cookies at any time via our cookie settings.
Because you act as controller of your clients’ data, we will assist you in responding to your clients’ GDPR requests — including through data export, erasure, and a data processing agreement on request. Contact us through the contact page to exercise your rights.
You have the right to lodge a complaint with your local data protection (supervisory) authority.
10. Cookies
We use only strictly necessary cookies to run the service: an HTTP-only session cookie to keep you signed in, and a small preference cookie (for example, the sidebar state). These do not require consent.
For analytics we use Umami, a privacy-friendly tool that does not set advertising or profiling cookies: IP addresses are hashed and data is aggregate. The analytics script loads only after you accept — you can accept, decline, or change your choice at any time from the cookie banner or the "Cookie settings" link in the footer.
See our Cookie policy for the full list of cookies, their purposes, lifespans, and how to manage them in your browser.
11. Changes to this policy
If we make material changes we will notify you by email or in-app notice before they take effect.
Questions about this policy or a data request? Reach us via the contact page.