Klosent Privacy Policy
Last updated: September 14, 2026
This Privacy Policy explains how Klosent LLC, doing business as Klosent ("Klosent", "we", "us") collects, uses, shares, and protects personal data when you use Klosent's websites, software, and services (the "Service").
1. Who we are
Klosent provides B2B revenue software and related services. For account, billing, website, and direct sales data, Klosent generally acts as controller. For business contacts and other Customer Data a customer places in a Workspace, the customer generally acts as controller and Klosent acts as processor.
2. Data we collect
- Account data: first and last name, work email, signup phone number, company, role, authentication records, and Workspace membership.
- Lead data: information submitted through sales, Done for You, White-label, contact, or booking forms, including an optional phone number where requested.
- Usage and device data: pages viewed, conversion events, browser and device information, IP-derived technical information, timestamps, and diagnostic logs.
- Customer Data: contacts, companies, deals, campaigns, conversations, outcomes, documents, reports, and notes placed in a Workspace.
- Connection data: provider account identifiers, connection status, sync status, and authorization lifecycle records. Provider credentials and API secrets are handled server-side.
- Invitation-monitoring data: provider-confirmed invitation times, status observations, acceptance receipts, final exact provider proof, account-health observations, policy-acceptance records from a Workspace owner or administrator, safety-switch events, and related operational receipts.
- Billing data: limited package, accepted-scope, Terms-acceptance, invoice, payment-confirmation, and transaction metadata. Stripe or the approved Payoneer process handles payment information under its own terms; Klosent does not store payment-card details.
- Enrichment and research data: business-contact and company information returned by approved data providers or public business sources when a customer requests it.
- Website-assistant data: questions you submit to Klosy, limited recent chat history, generated replies, and technical information used to prevent abuse.
- Real-estate service data, where included in an agreed engagement: property and ownership records, owner or representative contact details, source and verification information, call notes, expressed interest, follow-up requests, and suppression records. Recordings or transcripts are included only where enabled within the agreed scope and permitted by law with any required notice and permission.
3. How we use data
We use personal data to:
- provide, secure, maintain, and improve the Service;
- authenticate users and enforce Workspace, role, Seat, and account permissions;
- record commercial approvals, Checkout or manual payment confirmation, and authorized subscriptions or service engagements;
- connect authorized provider accounts and operate requested product workflows;
- monitor provider-confirmed LinkedIn invitation status to enforce the 45-day no-withdrawal-before deadline, advance accepted invitations, keep pending invitations waiting, and retain evidence of authorization, account health, timing, and safety decisions;
- generate customer-requested AI drafts from bounded Workspace guidance and public professional source content;
- answer website questions through Klosy using the question and limited recent chat history;
- carry out agreed real-estate support work, manage authorized follow-up, and honor objections and suppression requests;
- respond to sales inquiries, support requests, security reports, and data requests;
- send service, acknowledgment, and account communications;
- understand public-site performance through privacy-conscious conversion analytics; and
- comply with law, enforce agreements, and prevent abuse.
4. Legal bases where GDPR applies
Where GDPR applies, the basis depends on the purpose and Klosent's role. Contract and requested pre-contract steps support account administration, agreed services, and requested inquiries. Legal obligations support required accounting and other statutory records. Consent is used where required for a particular communication, recording, or optional processing. Documented legitimate interests may support security, abuse prevention, service operation, and relevant business communication where a necessity and balancing assessment supports the specific use. A business-to-business label or a public source is not, by itself, a legal basis. A customer is responsible for establishing the legal basis for the Customer Data and outreach it controls; Klosent remains responsible for its own controller obligations.
5. Analytics and cookies
Klosent uses necessary browser storage and cookies to operate the Service. Public marketing pages may use Vercel Web Analytics and allow-listed conversion events to understand page performance and actions such as beginning signup, submitting a form, or using the ROI calculator. These events are designed not to include form contents, message content, credentials, or raw ROI inputs. You can use browser controls to restrict optional cookies where available.
6. Klosy website assistant
Klosy is Klosent's AI website assistant, not a human representative. Using the chat is optional. It explains our public services and can point you to pricing, signup, or George's booking page. The website assistant cannot access your private Workspace, send outreach, make a purchase, or confirm a calendar booking for you. Please check important answers with our team and avoid sharing passwords, payment details, confidential customer records, or other sensitive information.
When you submit a question or select a suggested question, Klosent processes your question and limited recent chat history. For private-route AI-generated answers, Klosent sends that text to OpenAI, our AI service provider, to generate a reply. Some product answers and availability fallbacks are provided without an AI request. Opening, moving, or hiding the website mascot does not itself send a question to OpenAI. If you follow a booking or signup link, the information you submit there is handled through that separate service.
Model-improvement sharing is off by default. An optional, initially unchecked choice allows eligible general product questions to use OpenAI's complimentary model-improvement sharing project when available. On that route, Klosent sends only its canonical public catalog and a server-selected predefined question intent, never your original question text, chat history, credentials, or private Workspace data. OpenAI may use those shared public inputs and generated outputs to improve its models. Freeform or ineligible questions, and requests when sharing is unavailable, use the private paid route subject to availability and a daily spending cap; that route is not opted into model-improvement sharing. Standard FAQs use no AI. You can uncheck the choice at any time for future requests. Changing the choice clears this page's chat history and cancels the local pending request, but cannot retract processing already started. The choice is not saved across page reloads.
The website chat keeps the conversation in the current page's memory. Its answer handler does not save a permanent chat transcript in Klosent's application database. Klosent also processes limited technical information, including IP-derived rate-limit identifiers, to prevent abuse. These statements are not a promise that no data is processed or retained by our infrastructure or providers.
Klosent sends AI requests with store: false and marks website assistant responses no-store. These controls do not disable the optional model-improvement sharing described above. Klosent requests that OpenAI not store responses as retrievable API response records. This is not a zero-retention guarantee: OpenAI may retain content for abuse monitoring, safety, or legal requirements under its applicable terms and settings. See OpenAI's API data controls in the references below. Contact privacy@klosent.com for questions about recipients, retention, transfers, or your rights.
7. Enrichment and data caching
When a customer requests enrichment, Klosent may retrieve business-contact details and retain eligible results for a limited period to improve speed and avoid repeated provider requests. Data may be refreshed, suppressed, or removed according to provider rules, customer instructions, retention settings, and verified data-subject requests. Klosent does not promise that enriched information is complete or current.
8. Real-estate services and data sources
Where real-estate calling, contact research, or skip tracing is included in an agreed written scope, records may concern individuals in a personal capacity, not only professional business contacts. Sources depend on the service and may include customer-supplied lists, lawfully accessible property records, authorized data providers, and information supplied by the person during a conversation. Public availability or a returned phone number does not establish permission to contact, record, or sell that person's data.
The customer and Klosent must establish their respective roles, the source authority, permitted purpose, applicable legal basis, calling and recording requirements, suppression process, recipients, and retention before processing begins. Property-owner information must not be reused to build a buyer or lender marketing list without a separately permitted purpose and any required notice or permission. Describing a category here does not mean every service or recording feature is enabled.
Where Klosent obtains personal data indirectly as controller, it must provide any required information within the applicable legal period, including at first communication or first disclosure where required. Publishing this Policy does not replace delivering that information. You may ask about the available source and categories of your data through privacy@klosent.com. When a customer is controller, Klosent coordinates relevant requests with that customer.
9. Who we share data with
Klosent uses service providers for hosting, databases, authentication, application delivery, analytics, email delivery, provider Konnections, payment administration, customer support, approved enrichment, AI assistance, and booking services. OpenAI processes website-assistant questions and recent chat context as described above. Their processing is governed by applicable agreements, Klosent's instructions where the provider acts on our behalf, and the provider's own terms and privacy disclosures. Depending on the service, a provider may process data to deliver and secure its service, prevent abuse, comply with law, and for other purposes it discloses. A provider's independent role does not remove Klosent's obligations for its own selection, disclosure, or processing of personal data. Klosent does not sell personal data.
The exact providers, roles, and processing locations depend on the enabled service. You may request the current scope-specific details and applicable data-processing terms from privacy@klosent.com. This category list is not a complete subprocessor register.
We may disclose data when required by law, during a corporate transaction subject to appropriate safeguards, or when reasonably necessary to protect users, the Service, or legal rights.
10. International transfers
Data may be processed in countries other than your own. Where transfer restrictions apply, the relevant processing requires a valid transfer mechanism, such as an applicable adequacy decision, standard contractual clauses, or another mechanism permitted by law. The safeguards must cover the actual provider, destination, and processing before a restricted transfer occurs. You may request information about the applicable mechanism and copies of available safeguards, subject to necessary security or commercial redactions, from privacy@klosent.com.
11. Retention
Klosent keeps personal data only as long as reasonably needed for the purposes described here, to provide the Service, resolve disputes, enforce agreements, and meet legal obligations. Retention differs by data type and contract. Invitation-monitoring observations and receipts are retained only as needed to enforce the timing, authorization, account-health, and safety controls, investigate a dispute or account restriction, and meet applicable recordkeeping duties. After an account closes, Klosent deletes or anonymizes eligible data within a reasonable period, subject to backups, legal holds, suppression records, and required financial records.
12. Security
Klosent uses administrative, technical, and organizational measures designed to protect personal data, including access controls, server-side authorization, tenant-scoped database policies, session checks, protected provider credentials, and redaction of sensitive operational logs. No online service can guarantee absolute security. More information is available on the Data & Security page.
Where a personal-data incident requires notification under applicable law or an agreement, Klosent must follow those notification obligations. A security disclaimer does not remove those duties.
13. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, port, or object to processing, and to withdraw consent. To make a request, contact privacy@klosent.com. Klosent may need to verify your identity and authority before completing a request.
Withdrawal of consent does not affect earlier lawful processing. Where GDPR applies, you may lodge a complaint with a competent supervisory authority without first contacting Klosent. Klosent may coordinate with the customer when that customer is the controller.
14. Do-not-contact and data-subject requests
If your personal data appears in the Service, including business-contact or property-contact data, and you want to request access, correction, deletion, or suppression, contact privacy@klosent.com. Klosent will review verified requests and coordinate with the relevant customer or provider when appropriate. Limited suppression evidence may be retained where lawful to honor an objection and prevent renewed contact; deletion of an active contact record must not be used to bypass a stop request.
15. Children
The Service is for business users and is not intended for anyone under 18. Klosent does not knowingly collect personal data from children.
16. Changes
We may update this Policy and will post the revised version with a new date. We will provide additional notice where required for material changes.
17. Contact
Privacy questions and data requests: privacy@klosent.com.
Official source references
These primary sources support the boundaries described above. Provider rules can change, so review the current source before enabling a capability.