Privacy requests — who does what
Last updated: 18 July 2026
This page explains how privacy requests from a booker (access, erasure, rectification, withdrawal of marketing consent, complaints) are handled when you use Klarte.no. It is a practical summary, not legal advice.
1. Two kinds of requests
| If the request is about… | Who is responsible | Who to contact first |
|---|---|---|
| Appointments and booker data at your business | Your business (controller) | The business email as shown on the booking page / in the privacy notice |
| Your Klarte account (sign-in, billing, the platform) | Klarte (controller) | hjelp@klarte.no |
2. Deadlines
- 30 days — the usual reply period for data-subject requests (GDPR Article 12)
- 72 hours — Klarte may have to notify the supervisory authority after a personal data breach (Article 33) when the conditions are met
- Without undue delay — Klarte notifies affected businesses when booking data on the platform is involved (see the data processing agreement section 11)
3. Bookers — self-service first
Confirmations and reminders contain a privacy link. A booker can usually:
- Download their information (JSON export)
- Request erasure / anonymisation (pending bookings may be cancelled)
- Withdraw marketing consent
The actions are logged automatically. No one on your staff needs to do anything, unless the booker also emails you.
4. Businesses — when a booker emails you
- Confirm that you received the request quickly (good practice within a few business days)
- Ask them to use the privacy link if they have not already
- If they cannot: Dashboard → Settings → Legal → Help a customer → search by email → export JSON → reply
- Mark manual access requests as completed under Help a customer when that applies
- Reply within 30 days
Full guide: data-request guide.
5. When a booker contacts Klarte directly
Klarte is the processor for your booking data. We will:
- Explain that your business is the controller
- Forward the request to the business email stored in the system
- Provide technical help if the privacy portal or the tools fail
We do not reply as controller for data about people who book with you.
6. Complaints
- GDPR complaints about how you use booker data — you reply as controller. The booker may complain to their supervisory authority (for example Datatilsynet in Norway)
- Complaints about Klarte (your SaaS account) — contact hjelp@klarte.no
7. Personal data breaches
If you suspect a breach that affects data on the platform, contact hjelp@klarte.no immediately. Klarte assesses whether the platform is affected and notifies affected businesses without undue delay. You remain responsible for assessing notice to bookers, as controller.
8. Contact
9. Related
- Data-request guide
- Controller responsibilities
- Data processing agreement
- Sub-processors
- Terms of use (subscription and Stripe)