Trust

Trust Centre

Last updated: 2026-08-01

Every row on this page is generated from versioned files in the source repository that defines them, not written by hand. Where we have not yet verified something against our production systems, this page says so instead of stating it.

Data residency

Where each category of data actually lives. A region is stated here only once it has been verified against the deployed environment; the rest say so plainly.

DataRegionStatus
Database recordsAll platform records: workspaces, proposals, documents metadata, members, audit trailsGermany West Central (Frankfurt)Verified
Uploaded and generated filesDocuments members upload, and files the platform generatesAutomatic placement (not region-pinned)Verified
Document content sent for parsingThe full text of every uploaded tender document, sent to the parserUnited StatesVerified
Generative model inference (drafting, extraction, summarisation)Prompts and completions for the document and extraction paths. The conversational agent is listed separately below because it resolves differently.Europe (Stockholm), eu-north-1Verified
Text embeddingsVector embeddings computed over document chunks and queriesEurope (Stockholm), eu-north-1Verified
Meeting audio and transcriptsUploaded meeting recordings and their machine transcriptsEurope (Stockholm), eu-north-1Verified
Conversational agent inferencePrompts and completions for the in-app chat agent, which reads the workspace content a member is authorised to see.Being verified (#1909 - awaiting a deployed-environment read of the agent model actually in use)Being verified

1 of 7 categories are still being verified against our production logs. We would rather show you an unfinished table than a claim we cannot yet evidence.

Sub-processors

Every third party that receives data from the platform. Providers that are wired but switched off in production are listed with that stated, rather than omitted - each is one configuration change away from being on.

ProcessorPurposeRegionIn productionTransfer safeguard
Amazon Web Services - Amazon BedrockTouches customer contentGenerative model inference (drafting, extraction, summarisation, the chat agent) and text embeddingsEurope (Stockholm), eu-north-1YesNot applicable
Amazon Web Services - Amazon Transcribe and S3Touches customer contentSpeech-to-text for meeting recordings, and the S3 bucket staging the audio for itEurope (Stockholm), eu-north-1YesNot applicable
CloudflareTouches customer contentObject storage for uploaded documents and generated files, and content deliveryAutomatic placementYesEU Standard Contractual Clauses
Google - sign-in and document connectorsTouches customer contentFederated sign-in, and member-initiated document-source connectionsUnited StatesYesEU-U.S. Data Privacy Framework
LlamaIndex - LlamaParseTouches customer contentParsing uploaded documents into text. This is the default parser, and it receives the entire document.United StatesYesEU Standard Contractual Clauses
Microsoft - sign-in and SharePoint connectorTouches customer contentFederated sign-in, and member-initiated SharePoint document connectionsUnited StatesYesEU-U.S. Data Privacy Framework
Microsoft AzureTouches customer contentUnderlying infrastructure on which the Neon database runsGermany West Central (Frankfurt)YesNot applicable
NeonTouches customer contentManaged PostgreSQL holding all platform recordsGermany West Central (Frankfurt)YesNot applicable
TavilyTouches customer contentWeb-search enrichment for research and the chat agent. Receives the search query, which may be derived from customer content.United StatesYesEU Standard Contractual Clauses
Bolagsverket (Swedish Companies Registration Office)Touches customer contentCold-start org profiling: an organisationsnummer the customer enters about their own organisation is sent to the free 'vardefulla datamangder' open-data API, which returns the public register record (name, SNI activity codes, registered address, activity description).Not in useNoNo transfer outside the EEA. Bolagsverket is a Swedish public authority acting as controller for the register; the API is published free under the EU open-data directive and no agreement is required to read it.
DocuSignTouches customer contentMember-initiated e-signature connectorNot in useNoEU-U.S. Data Privacy Framework would apply if enabled
Google - Gemini APITouches customer contentAlternative document-parsing path (PARSER_TYPE=gemini), and the optional notice-translation pathNot in useNoEU Standard Contractual Clauses would apply if enabled
Microsoft Azure OpenAI ServiceTouches customer contentAlternative generative providerNot in useNoEU Standard Contractual Clauses would apply if enabled
OpenAITouches customer contentAlternative generative and embedding providerNot in useNoEU Standard Contractual Clauses would apply if enabled
Google (Gmail SMTP relay)Fallback transport for transactional email when Resend is not configured or fails. Carries the message body, so it sees email content.United StatesYesEU-U.S. Data Privacy Framework
PexelsStock imagery lookup for generated document headers. Receives a search term, not customer documents.United StatesYesEU Standard Contractual Clauses
ResendTransactional email: invitations, saved-search alerts, and customer-initiated outreachUnited StatesYesEU-U.S. Data Privacy Framework / EU Standard Contractual Clauses
StripeSubscription billing and payment processing. Card data is processed by Stripe and never reaches Klarum systems.United StatesYesEU-U.S. Data Privacy Framework
VercelHosting for the web frontendBeing verified (#1909)YesEU Standard Contractual Clauses
HubSpotMember-initiated CRM connector. Distinct from Klarum's own internal CRM use, which is not a platform sub-processor.Not in useNoEU-U.S. Data Privacy Framework would apply if enabled
SalesforceMember-initiated CRM connectorNot in useNoEU-U.S. Data Privacy Framework would apply if enabled
SlackMember-initiated workspace connectorNot in useNoEU-U.S. Data Privacy Framework would apply if enabled

22 processors listed. A longer list is the honest outcome of enumerating everything rather than only the flattering entries.

Data use and model training

Customer content is never used to train or fine-tune foundation models, whether by Klarum or by a model provider acting on Klarum's behalf.

Absolute. It is not configurable and there is no switch that turns it off.

Your organisation's control

Beyond serving your own organisation, Klarum does not use your content or your interaction signals for anything unless your organisation opts in.

The default is the restrictive value. An organisation that never touches this setting is never included in cross-organisation model improvement. That makes the setting a stated guarantee with an audit trail rather than a toggle between two live behaviours, which is the honest description of it.

What that setting gates

  • Cross-organisation ranking-model training - pipeline/scripts/train_ltr_artifacts.py reads labelled rows from match_signal_log across every organisation and fits one shared logistic-regression weights artifact plus an isotonic calibrator. Those artifacts are then applied to every organisation's match scoring when LEARNED_WEIGHTS_ENABLED / LEARNED_CALIBRATION_ENABLED are on.

What it deliberately does not gate

  • Serving your own organisation - Matching, ranking, retrieval, drafting and the per-organisation personal recommender all operate on your data to serve you. That is the product, and the setting does not affect it.
  • Foundation-model training - Already prohibited absolutely by the commitment above. There is nothing for a switch to control.
  • Aggregate operational metrics - Counts, latencies and error rates carry no customer content and are used to run the service.

Per provider

  • aws-bedrockThe provider does not retain prompt content and does not train on inputs or outputs.
  • llamaindexUnder review. LlamaParse receives the entire document, and its terms are not the same as Bedrock's. Until the terms are read and recorded here, no no-training statement is made for this path.
  • google-geminiNot applicable in production; the path is off. If enabled as a parser, the Gemini API terms must be read and recorded here first, because the paid and free tiers differ on training use.
  • tavilyReceives search queries, which may be derived from customer content. Its retention and training position has not been recorded.

What we retain

Klarum does retain the working record of AI-assisted work inside the customer's own tenant, because the product would not function otherwise.

Retention

There is no automated retention enforcement anywhere in the platform. Nothing is deleted unless a person deletes it.

DataPosition
Customer data in workspacesRetained for the life of the subscription and deleted on termination. Deletion is performed by our team on termination or on request; there is no automated purge.
Soft-deleted recordsDeleted records are removed from the product immediately. They are not yet purged from storage on a schedule.
Expired sessions (refresh tokens)Sessions expire and stop working on expiry. Expired session records are not yet swept from storage.
Password-reset tokensSingle-use and short-lived. Consumed on use; expired unused rows are not yet swept.
Public procurement noticesRetained indefinitely. This is public data published by contracting authorities, and it is not customer data.
Billing recordsRetained for 7 years from the end of the financial year, as Swedish accounting law requires.

Security measures we operate

Our security notice states the controls we operate, each with whether it is in place, partial, or planned. It withdraws, in writing, any control an earlier revision overstated. Our privacy policy covers lawful bases, your rights, and international transfers.

Requesting a data processing agreement

Email security@klarum.com for a data processing agreement, our current record of processing activities, or the detailed security package.

How this page is kept true

The tables above are generated at build time from versioned files in our source repository. A continuous-integration check fails our build when the code gains a third-party client, or changes a region, that those files do not describe - so this page cannot quietly fall out of date with the software it describes.

Source: Klarum-Software/pivi/docs/trust at 9695fad22bf0