Klosent Privacy & Platform Transparency Notice
Last updated: September 24, 2026
This notice supplements the versioned Klosent Privacy Policy with more specific operational detail. It does not replace the Privacy Policy, certify legal compliance, or create authorization from a third-party platform. It does not make prohibited processing or messaging lawful. The controller for a particular campaign must still assess the facts, applicable law, and current provider rules before processing begins.
1. Controller identity and roles
The Klosent service operator and controller for the activities identified below is Klosent LLC, doing business as Klosent. Privacy questions and rights requests can be sent to privacy@klosent.com.
Klosent acts as controller for its public website, account administration, billing records, security and abuse prevention, support, and Klosent's own direct sales activity. A customer generally acts as controller for contacts, companies, campaign criteria, outreach content, and conversations it places in a Workspace; Klosent generally acts as processor for that Customer Data under the customer's instructions. Klosent may act as a separate controller for the minimum security, fraud-prevention, billing, and legal records it must keep. The relevant role can differ when a connected provider independently determines how it uses data under its own terms.
2. Categories of personal data and where they come from
- Account and lead data: name, business contact details, company, role, Workspace membership, support requests, and information a person submits to Klosent.
- Business-contact and company data: professional identity, employer, title, location, work contact details, public profile or company links, campaign status, source, and suppression status.
- Customer CRM and communication data: contacts, companies, deals, notes, approved campaign content, conversation records, replies, outcomes, and files a customer chooses to provide.
- Connection and delivery data: connected-account identifiers, account health and authorization lifecycle, sending status, delivery receipts, opt-in or opt-out evidence, and provider error categories.
- Optional Keep me connected data: when the feature is available and the account owner explicitly enrolls, their LinkedIn sign-in, usual sign-in country, and optional authenticator setup key. Saved sign-in details are encrypted and bound to that owner's exact connection. The setup key stays server-side; sign-in details and generated verification codes are submitted to Unipile only to verify or reconnect that account. This option works without the browser extension and has its own consent.
- LinkedIn invitation-monitoring observations and receipts: provider-confirmed invitation time, pending or accepted status, acceptance receipt, final exact provider proof, account-health observation, policy-acceptance state from a Workspace owner or administrator, safety-switch event, and the timing decision associated with the invitation.
- Billing and commercial data: selected plan, accepted scope, invoice and transaction metadata, and legal-acceptance records. Klosent does not store full payment-card details.
- Technical and security data: device and browser data, timestamps, IP-derived technical information, session and access records, diagnostic events, and abuse-prevention signals.
When Klosent did not obtain data directly from the person, sources may include customer-authorized imports and operators, approved business-data providers selected for the Workspace, public professional profiles, company websites, public business registries or directories, referrals, event or business-card exchanges, and information returned by a connected account provider. A person may ask Klosent for the available source and categories of personal data associated with a verified request.
3. Purposes and legal bases where GDPR applies
- Contract and requested pre-contract steps: create and administer an account, deliver the selected Service, process an inquiry or purchase, provide support, maintain requested Konnections, and enforce the documented 45-day LinkedIn invitation-monitoring controls for an enabled Workspace.
- Legal obligations: keep required tax, accounting, commercial, sanctions, and compliance records and respond to valid legal process.
- Consent: send communications or use a channel where consent is required, including WhatsApp initiation, and operate optional choices that applicable law requires a person to authorize. Consent may be withdrawn without affecting earlier lawful processing.
- Documented legitimate interests: secure accounts and the Service, prevent fraud and abuse, answer business inquiries, improve limited product and site operations, and conduct responsible business-to-business sales where a necessity and balancing assessment supports the specific use. The interests pursued are service and account security, reliable operation, support, and relevant professional communication. Safeguards should include limited professional data, audience relevance, clear sender identity, an accessible objection or opt-out, suppression after objection, accuracy review, and avoiding special-category targeting.
- Customer-controlled processing: the customer must establish and document its own legal basis for Customer Data, targeting, enrichment, and outreach. Klosent's processor role does not supply that basis for the customer.
A business-to-business label alone is not a legal basis. A general policy statement is not a completed necessity and balancing assessment for a particular list, jurisdiction, purpose, or campaign.
4. Notice when data was obtained indirectly
When Klosent is the controller and GDPR Article 14 applies, the applicable information must be provided within the required period, at the latest when Klosent first communicates with the person or before Klosent first discloses the data, unless a documented legal exception applies. The first communication should clearly identify the sender and business, explain the professional purpose, state the source category, link to this notice and the Privacy Policy, and offer an effective objection or opt-out route.
Publishing this notice does not replace delivering the required information to the person. When a customer is the controller, that customer is responsible for its own notice and timing and must keep appropriate evidence that the requirements were met.
5. Recipients, providers, and disclosure
The categories of recipients may include hosting, database and authentication services; application delivery and monitoring services; payment administration; email and communication delivery; customer-selected account Konnections; customer support; approved business-data providers; customer-requested AI services; professional advisers; and public authorities when disclosure is legally required. A connected provider may act as processor, subprocessor, or independent controller depending on the service and its terms.
This notice is not a complete provider-by-provider subprocessor register. The exact providers and roles depend on the enabled Workspace features and can change. A customer that needs the current scope-specific provider identities, roles, processing locations, or available data-processing terms should request them from privacy@klosent.com before enabling the service. Klosent does not sell personal data.
6. International transfers
Data may be processed outside the person's country. For Klosent-controller processing subject to GDPR transfer restrictions, the applicable service must have a valid transfer mechanism before the restricted transfer occurs. Depending on the destination and provider, that may be an adequacy decision, standard contractual clauses, or another mechanism permitted by law. The applicable safeguards must be established for the actual provider, destination, and processing; a general statement about transfers is not sufficient.
A person or customer may request information about the applicable mechanism and a copy of available safeguards, subject to necessary commercial or security redactions. If Klosent cannot identify the mechanism and supporting documentation for an optional provider service, that service should not be used for restricted data.
7. Retention criteria
Klosent uses the purpose, account and contract status, customer instructions, data accuracy, provider requirements, legal limitation periods, tax and accounting duties, disputes, security investigations, verified rights requests, and technical backup lifecycle as criteria used to decide retention. In particular:
- active account and Customer Data is kept while needed to provide the Service and until deletion, closure, or a controlling contract requires a different outcome;
- prospect, enrichment, and campaign data should not be kept after the approved purpose ends, an applicable objection or deletion request is verified, the data is known to be unreliable, or the controlling customer instructs deletion, subject to a lawful exception;
- consent, opt-out, and suppression evidence may be retained as needed to prove permission, honor the request, and prevent renewed contact;
- billing, acceptance, audit, fraud, and security records may be retained for legal duties, claims, and integrity investigations;
- provider-confirmed LinkedIn invitation observations and receipts may be retained while needed to enforce the 45-day timing rule, demonstrate the policy, authorization, account-health, and safety decision, investigate an account restriction or dispute, and meet applicable recordkeeping duties; and
- protected backups may persist until they are overwritten under the applicable backup lifecycle, unless a legal hold applies.
Keep me connected consent lasts 90 days per enrollment. Expired or withdrawn consent cannot authorize another use. The owner can turn the option off and delete the saved sign-in details from active storage in Konnections, including after losing paid access. An already submitted sign-in may still complete. Audit records retain identifiers, consent and use events, and outcomes, never passwords, setup keys or verification codes; backups follow the lifecycle described above. LinkedIn may still require an owner-supplied code, app approval, CAPTCHA or other verification.
Klosent does not publish one fixed period for every category because the governing criteria and customer contracts differ. A customer may request the scope-specific retention schedule before providing regulated data.
8. Rights and complaints
Depending on the law and Klosent's role, a person may have rights to access, correct, delete, restrict, port, or object to processing, to withdraw consent, and to obtain available information about sources, recipients, transfers, and retention. Requests can be sent to privacy@klosent.com. Klosent may verify identity and authority and may coordinate with the relevant customer when that customer is the controller.
Where GDPR applies, a person also has the right to lodge a complaint with a competent supervisory authority, including an authority in the country where the person lives or works or where the alleged infringement occurred. Contacting Klosent first is welcome but is not a requirement for lodging a complaint.
9. Profiling, AI assistance, and automated decisions
Klosent may use customer-set criteria, rules, enrichment results, and AI assistance to rank or categorize business contacts, suggest fit, prioritize work, draft content, or flag operational risk. Typical inputs are professional role, company, geography, customer criteria, campaign history, and available business-source context. The expected effect is a suggested category, queue priority, draft, or outreach workflow, not a legal entitlement.
Klosent does not intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects for a person. Customers must not use Klosent scoring, enrichment, or AI output as the sole basis for employment, credit, housing, insurance, healthcare, or another similarly significant decision. If Klosent introduces such processing, the applicable notice, legal basis, logic description, human-review safeguards, and contest route must be established before use.
10. Commercial communications and platform boundaries
Commercial email sent through Klosent must identify the real sender, use accurate routing and subject information, identify advertising where applicable, include the sender's valid physical postal address, provide a clear way to stop future commercial email, and honor opt-out requests within the time required by law. The United States CAN-SPAM rules apply to business-to-business commercial email as well as consumer email, and a sender cannot transfer away its compliance responsibility merely by using Klosent or another service provider.
Klosent is an independent service and is not affiliated with, endorsed by, sponsored by, or certified by LinkedIn. Klosent is not authorized by LinkedIn. References to LinkedIn describe customer-selected interoperability only. LinkedIn's published rules prohibit bots and other unauthorized automated methods for access, messaging, connection activity, and engagement. Klosent does not claim direct written authorization from LinkedIn. A customer must not enable or use LinkedIn automation unless the customer's use is permitted by current LinkedIn rules or covered by direct written authorization; connecting an account or using an intermediary does not by itself create that permission. LinkedIn may restrict or remove an account.
For provider-confirmed LinkedIn invitation monitoring, Klosent's stated control is never to withdraw a pending invitation before 45 days from the provider-confirmed invitation time. A provider-confirmed acceptance advances the invitation; a pending invitation waits. At or after day 45, a withdrawal requires final exact provider proof, healthy account status, and current policy acceptance by the Workspace owner or administrator. A disconnect, network failure, stale observation, or other delivery delay may delay a decision but never accelerate it. A safety kill switch stops the activity. These controls do not certify compliance, create LinkedIn authorization, or make prohibited processing or messaging lawful.
Klosent is also independent and is not affiliated with or endorsed by WhatsApp or Meta. WhatsApp's published Business Messaging Policy says a business may contact a person only after the person provided their mobile number and the business received opt-in permission for subsequent messages or calls. The business must honor every opt-out or stop request, use approved templates where required, respect the applicable customer-service window, and maintain a clear human escalation path where automation is used.
Platform terms and technical rules can change, and the platform may restrict or remove an account. Klosent may withhold a capability when the required permission, consent, account eligibility, or documented provider permission is absent. Disclosure of these boundaries is not a warranty that a particular campaign is lawful or platform-authorized.
11. Contact and scope-specific documents
Privacy questions, rights requests, source requests, and requests for a current scope-specific provider, transfer, or retention description can be sent to privacy@klosent.com. Customers should obtain applicable data-processing terms and legal review before enabling a provider service that involves regulated, sensitive, or cross-border data.
Official source references
These primary sources support the boundaries described above. Provider rules can change, so review the current source before enabling a capability.