Data Privacy Policy
Last updated: September 8, 2026
1. Who Is Responsible
The controller responsible for the processing of your personal data under the General Data Protection Regulation (GDPR) when you use Klarity or visit klarity.so is:
Black Bridge GmbH
Elisabeth-Langgässer-Straße 1
64521 Groß-Gerau, Germany
info@blackbridge.so
Further company details are in our imprint. "We", "us" and "our" in this policy refer to Black Bridge GmbH.
2. Data We Collect
When you use Klarity, we collect the following information:
- Account information: Your name and email address provided at sign-up, plus your profile picture if you sign in with Google or your organisation's identity provider.
- Billing information: A customer identifier and subscription status from our payment processor. We do not collect or store your card number, PayPal account, Apple Pay token, or other payment-method details ourselves.
- Usage data: Information about how you interact with the application, including tasks created, pages visited, and features used.
- Technical data: IP address, browser type, device information, and session data necessary for the service to function.
3. How We Use Your Data
We use your data to:
- Provide and maintain the Klarity service, including task management, scheduling, and collaboration features.
- Authenticate your identity and secure your account.
- Improve the application based on aggregated, anonymized usage patterns.
- Communicate important service updates or changes.
We do not sell your personal data to third parties.
4. Data Storage and Security
Your data is stored on secure servers within the European Union. We implement industry-standard security measures, including encryption in transit (TLS), to protect your information.
Access to your data is restricted to authorized personnel who need it to operate and maintain the service.
5. Third-Party Services and Processors
Klarity integrates with the following third-party services. Where a service processes personal data on our behalf, it does so as our processor under a data processing agreement (Art. 28 GDPR).
- Google OAuth: Used for authentication. We receive your name, email, and profile picture from Google when you sign in.
- Google Calendar / Microsoft 365 / CalDAV / ICS feeds: If you connect a calendar, we access your calendar data to provide scheduling features. This data is only used within Klarity and not shared further.
- Crisp (live chat support): We use Crisp (Crisp IM SARL) to provide in-app chat support. When you are signed in, your name and email address are shared with Crisp so we can identify you in support conversations, along with the messages you send us. Crisp's handling of your data is governed by their own privacy policy.
- Polar (payment processor): Subscription billing is handled by Polar (Polarsource, Inc.). When you start a paid plan, you enter payment details (credit/debit card, PayPal, Apple Pay, or other methods Polar supports) directly with Polar — we never see or store them. We only receive a customer identifier, subscription status, and billing period from Polar. Polar's handling of your data is governed by their own privacy policy.
- Cloudflare Turnstile (bot protection): Our sign-up form uses Turnstile by Cloudflare, Inc. to tell people from automated scripts. To do so, the Turnstile script processes your IP address, browser characteristics and the result of the check; it sets no advertising cookies and we receive only a pass/fail token. Cloudflare's handling of your data is governed by their own privacy policy.
- Postmark (transactional email): We send account emails — email address verification, password resets, workspace invitations and notifications you have enabled — through Postmark, a service of ActiveCampaign, LLC (Chicago, USA). Postmark receives your email address, your name where it appears in the message, and the message content, and keeps delivery logs for a limited period. Transfers to the USA are covered by the EU–US Data Privacy Framework and the EU Standard Contractual Clauses. Postmark's handling of your data is governed by their own privacy policy.
- Sentry (error monitoring): When something goes wrong in the application or our API, a technical error report is sent to Sentry (Functional Software, Inc.), using its European Union data region (data is stored in Germany). A report contains the error message and stack trace, the page or API route involved, browser and device type, and request metadata, which may include your IP address. Reports are kept for 90 days. We do not send your name, email address or the content of your workspace to Sentry. Sentry's handling of your data is governed by their own privacy policy.
Except for the services listed here, we do not embed third-party scripts, advertising trackers or conversion pixels on our website or in the application. Advertising is measured only through our self-hosted analytics described in the next section.
6. Analytics
We measure how our website and application are used with a self-hosted instance of OpenPanel, an open-source analytics platform. It runs entirely on our own servers within the European Union — analytics data is never shared with, or accessible to, any third party.
- Cookieless by default: Unless you opt in below, analytics uses no cookies or fingerprinting. On our public website it collects aggregate technical data only: pages visited, referrer, campaign parameters, browser and device type, and coarse location derived from your IP address (the address itself is not stored).
- Pseudonymous product usage: When you are signed in, usage events (for example, which features you use) are linked to a pseudonymous internal user identifier. Your name and email address are never sent to the analytics system.
- Legal basis: We process this data on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in understanding and improving Klarity.
- Optional attribution identifier (consent): If you accept the banner on our website, we store a random identifier and the campaign parameters of your first visit in your browser's local storage and a first-party cookie. This lets us recognize your browser across visits — and connect your journey across our website and app — so we can understand which advertisement led to a signup. The legal basis is your consent (Art. 6(1)(a) GDPR); you can decline without any effect on the website, and withdraw at any time via "Cookie settings" in the footer or by clearing your browser data. Without consent, only the cookieless analytics described above run.
- Campaign attribution without consent: If you decline, nothing is stored in your browser for this purpose. The campaign parameters and referrer of the visit you arrived with are passed along in the link when you go from our website to the app, and if you sign up during that same visit they are recorded on your account (which campaign led to the signup — not who you are). This does not recognize your browser on later visits. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in measuring our own marketing.
- On account deletion: The identifier linking analytics events to you is destroyed together with your account, after which the remaining data can no longer be associated with any person.
7. Your Rights
Under the GDPR and applicable data protection laws, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate personal data.
- Erasure: Request deletion of your personal data ("right to be forgotten").
- Portability: Request a machine-readable copy of your data.
- Objection: Object to processing of your personal data for specific purposes.
- Withdrawal of consent: Withdraw your consent at any time where processing is based on consent.
8. Data Retention
We retain your personal data for as long as your account is active. If you delete your account, your data will be permanently removed within 30 days, except where we are legally required to retain certain records.
9. Contact
If you have questions about this privacy policy or wish to exercise your data rights, please contact us at:
Black Bridge GmbH
Elisabeth-Langgässer-Straße 1
64521 Groß-Gerau, Germany
info@blackbridge.so
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your residence or place of work. The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (datenschutz.hessen.de).