Data Processing Terms
These terms form the data-processing part of the agreement between a Klamic business user and Klamic where Klamic processes personal data on that user's behalf.
Last reviewed 17 August 2026
1. Roles
For customer, contact and invoice-recipient personal data entered into Klamic by a user, the user is normally the controller and Klamic is the processor. These terms apply only to processing where that controller-processor relationship exists.
Klamic remains an independent controller for personal data it uses for its own account administration, subscription billing, security, support and legal obligations.
2. Processing details
| Subject matter | Hosting, organising, displaying, generating and exporting invoice and customer information through Klamic. |
|---|---|
| Duration | For the period the controller uses Klamic, plus limited periods reasonably required for deletion, backup restoration, security and legal obligations. |
| Nature and purpose | Providing invoicing functionality requested by the controller, including saved customers, invoices, PDFs, invoice history and statistics. |
| Personal data | Names, business/contact details, postal addresses, email addresses, telephone numbers, invoice references, line descriptions, payment-status information and other data the controller chooses to include in an invoice or customer record. |
| Data subjects | The controller's customers, clients, contacts, invoice recipients and other individuals whose information the controller places in Klamic. |
3. Documented instructions
Klamic will process controller data only on the controller's documented instructions, including instructions expressed through normal use of Klamic's product controls, except where UK law requires other processing. If legally permitted, Klamic will inform the controller before processing required solely by such a legal obligation.
4. Confidentiality
Klamic will ensure that people authorised to process controller data are subject to an appropriate duty of confidentiality and receive access only where needed for their role.
5. Security
Klamic will maintain technical and organisational measures appropriate to the risk of the processing. Current measures include authenticated access, access controls, database permissions, encrypted provider connections, separation of user records through application and database controls, and restricted server-side administrative credentials.
Security measures may evolve as Klamic and its providers improve their systems, provided the overall level of protection is not materially reduced without a reasonable security or legal basis.
6. Sub-processors
The controller gives Klamic general authorisation to use sub-processors needed to provide the service. Current categories include application hosting and database, authentication and storage infrastructure. Providers used for these purposes may include Vercel and Supabase.
Klamic will require sub-processors that process controller data to be bound by data-protection obligations appropriate to the processing. Klamic remains responsible for its processor obligations where the UK GDPR makes it responsible for a sub-processor's performance.
If Klamic materially changes the sub-processors used for controller data, it will make updated information available and, where required, provide a reasonable opportunity for the controller to raise a substantiated data-protection objection.
7. International transfers
Klamic will not intentionally transfer controller data outside the UK except where the transfer is permitted under UK data-protection law. Where a restricted transfer requires safeguards, Klamic will use an applicable transfer mechanism or provider arrangement intended to satisfy those requirements.
8. Data subject requests
Taking account of the nature of the processing, Klamic will provide reasonable assistance through product controls or other proportionate technical and organisational measures to help the controller respond to requests by data subjects exercising their rights.
If Klamic receives a request that clearly concerns controller data, Klamic may direct the requester to the controller unless Klamic is legally required to respond itself.
9. Compliance assistance
Taking account of the nature of processing and information available to Klamic, Klamic will provide reasonable assistance with the controller's obligations relating to processing security, personal-data breaches, data-protection impact assessments and regulatory consultation where those obligations concern Klamic's processing.
10. Personal-data breaches
Klamic will notify the controller without undue delay after becoming aware of a personal-data breach affecting controller data where notification is required from Klamic as processor. Klamic will provide information reasonably available to it that the controller needs to assess and manage the breach.
11. Return and deletion
During an active account, Klamic provides product controls for accessing and exporting information. When the account is permanently deleted, Klamic will delete controller data from active systems, except to the extent retention is required by law or temporarily persists in protected backups or security records under normal deletion cycles.
Where legally required retained data will remain protected and will not be used for unrelated purposes.
12. Information and audits
Klamic will make available information reasonably necessary to demonstrate compliance with these processor obligations. Where that information is not sufficient and Article 28 requires an audit or inspection, Klamic will allow and contribute to a reasonable audit by the controller or an independent auditor appointed by the controller.
Audits must be proportionate, protect other users' confidentiality and Klamic's security, avoid unnecessary disruption, and ordinarily use existing independent reports or remote evidence before intrusive access is requested. This does not restrict a regulator's lawful powers.
13. Controller responsibilities
The controller is responsible for the lawfulness, fairness and accuracy of the personal data it places in Klamic; for providing required privacy information to its data subjects; for responding to data-subject requests as controller; and for giving Klamic only lawful instructions.
14. Priority
If these Data Processing Terms conflict with the general Terms of Service on a matter specifically concerning Klamic's obligations as processor, these Data Processing Terms take priority for that matter.
Operator details
Legal operator name, UK correspondence address and support email are intentionally withheld from this private pre-launch preview and will be added through launch configuration before publication.