Data processing agreement
Last updated: 9 October 2026
This data processing agreement (“agreement”) is part of the contract between you (“controller”, “customer”, “your business”) and Klarte.no (“processor”, “Klarte”) under Article 28 of the General Data Protection Regulation (GDPR).
1. Subject matter
Klarte processes personal data on your behalf only to provide the booking platform: storing bookings, sending email confirmations, recording consents you configure, analytics you turn on, and related technical operation.
2. Duration
The agreement applies for as long as you use the Service, and until the data has been deleted in line with the retention settings.
3. Nature and purpose of the processing
Operation, transmission, storage, and display of booking data, sending email, security logging, and consent records as configured in the product. Klarte does not use booker data for its own marketing or advertising.
4. Categories of data subjects
Your customers (“bookers”) and staff you have given access.
5. Types of personal data
Contact details, booking times, notes, consent records, and technical metadata as described in the privacy-notice template for bookers.
6. Instructions and the controller’s duties
You instruct Klarte only through product settings and documented features. You alone are responsible for:
- Lawful processing and transparency toward bookers
- Giving privacy information to bookers (including that your business is the controller)
- Responding to requests from bookers
- Setting retention and marketing practice within the product settings
- Not instructing Klarte to process information in breach of applicable law
7. The processor’s duties
Klarte shall:
- Process information only on your documented instructions
- Ensure confidentiality for personnel with access
- Implement appropriate security measures (Article 32)
- Assist with data-subject requests where technically possible, without taking over your duties as controller
- Delete or return information on termination, subject to retention required by law
- Make available the information needed to demonstrate compliance with Article 28
- Provide in-product tools so you can export, delete, or anonymise a booker’s data when they use the right to erasure (see the data-request guide)
The security measures include HTTPS/TLS for production traffic, access control, hashed passwords, encrypted two-factor secrets, and encrypted database backups (AES-256) that are deleted after 30 days. The public description is on security measures. The measures do not guarantee uninterrupted availability. The Service is provided “as is”, as stated in the terms of use section 8, and indirect loss (including lost revenue and lost customers) is excluded under section 9.
8. The controller’s liability
Klarte is not responsible for you meeting your duties as controller. Fines from a supervisory authority or claims from bookers that arise from your instructions, setup, privacy information, or business practice are your responsibility, except where they are solely caused by Klarte failing to meet its duties as processor under this agreement.
9. Sub-processors
You authorise Klarte to use sub-processors for hosting, email, SMS, payment infrastructure, and related technical services under Article 28. The current public list (name, purpose, location, and transfer basis) is published at /legal/sub_processors. Klarte notifies material changes via the platform or email before or when the change takes effect, in line with Article 28(2).
Email is sent from noreply@klarte.no and that address does not accept replies. Replies that are nevertheless sent there, and email to Klarte’s support and contact addresses, are forwarded by the inbound-email sub-processor on the list. Such messages may contain booking information. That provider is then a sub-processor for that processing.
10. Transfers to third countries
Where information is transferred outside the EEA, Klarte uses appropriate safeguards, such as the EU standard contractual clauses (Article 46), as described for each provider on the sub-processors page.
11. Personal data breaches
Klarte notifies you without undue delay after becoming aware of a personal data breach that affects your booking data on the platform. You are responsible for assessing and meeting the duty to notify bookers and the authorities, as controller. Klarte’s contact for a platform breach is hjelp@klarte.no. Where Klarte must notify the Norwegian Data Protection Authority as controller for SaaS account data, Klarte aims to do so within 72 hours of becoming aware of the breach, when Article 33 applies.
12. Acceptance
By completing platform legal onboarding, or by publishing a public booking form, you accept this agreement on behalf of your organisation.
Complete legal onboarding (sign-in required)