GDPR Compliance

Privacy by Design

Kleevo is designed with privacy, security, and transparency in mind, helping businesses send documents for signing while meeting their GDPR obligations.

GDPR Compliance at a Glance

Kleevo is designed with privacy and data protection at its core. Here's a quick overview of how we help businesses comply with GDPR.

Privacy by Design

Privacy and security are built into every part of the platform from the very beginning.

Data Processor

For customer documents, Codeberg Solutions AB (operating Kleevo) generally acts as a Data Processor, while our customers remain the Data Controller.

Data Processing Agreement (DPA)

A Data Processing Agreement is available for customers who require one.

Encrypted Communication

All communication with Kleevo is protected using HTTPS/TLS encryption.

Secure Cloud Storage

Documents are securely stored using modern cloud infrastructure with encrypted storage and strict access controls.

Limited Document Retention

Kleevo is not a permanent document archive. Documents are retained only as long as necessary before being securely deleted according to your retention settings or subscription plan.

Document Verification

Every finalized document includes verification information and a cryptographic hash, making it possible to verify its authenticity.

Complete Audit Trail

Every signing process generates a detailed audit trail documenting key events from upload to finalization.

No Selling of Personal Data

We never sell customer or signer personal data to third parties.

Data Minimization

We only process the personal data necessary to provide our document signing services.

Your Data, Your Control

You remain in control of your documents and determine who receives signing requests, how they are signed, and how long they should be retained.

Our Commitment

Our goal is simple:

Provide the easiest document signing experience while protecting the privacy and personal data of every sender and signer.

Privacy by Design

At Kleevo, protecting personal data isn't an afterthought. It is a core part of how we've built the platform.

Every feature is designed with privacy, security, and transparency in mind, helping businesses send documents for signing while meeting their obligations under the General Data Protection Regulation, GDPR.

Our Role Under GDPR

In most cases, Codeberg Solutions AB (operating Kleevo) acts as a Data Processor.

Our customers act as the Data Controller, meaning they determine why and how personal data is processed.

Kleevo processes personal data only to provide the document signing services requested by our customers.

Data Controller

As the customer, you control:

  • Which documents are uploaded
  • Who receives signing requests
  • Which signing method is used
  • How long documents should be retained, depending on your plan

Data Processor

Kleevo processes personal data solely to:

  • Deliver signing requests
  • Verify signatures
  • Generate audit trails
  • Notify recipients
  • Finalize completed documents
  • Provide customer support

We never sell your personal data or use uploaded documents for advertising or marketing purposes.

Data Processing Agreement

For customers that require one, Kleevo offers a Data Processing Agreement, DPA.

The DPA describes:

  • How personal data is processed
  • Security obligations
  • Confidentiality
  • Subprocessors
  • Customer rights
  • GDPR responsibilities

You can request a signed DPA by contacting us.

Data Storage

Customer data is stored using secure cloud infrastructure.

Documents remain encrypted during transmission and are securely stored throughout the signing process.

Kleevo is not intended to be a permanent document archive.

Completed documents are retained only for the applicable retention period before being securely deleted.

Customers remain responsible for the long-term storage of finalized documents.

Security Measures

Protecting your information is one of our highest priorities.

Kleevo uses modern security practices including:

  • HTTPS/TLS encrypted communication
  • Secure cloud storage
  • Cryptographic document hashing
  • Complete audit trails
  • Role-based access controls
  • Continuous monitoring

For more information, please visit our Security page.

Data Minimization

We believe software should only collect the information necessary to provide the service.

We only process personal data required to:

  • Create signing requests
  • Identify recipients
  • Verify completed signatures
  • Deliver notifications
  • Generate audit trails
  • Operate and secure the platform

We never collect unnecessary information.

Document Retention

Unlike many document management platforms, Kleevo is not designed for permanent storage.

Once a document has been completed and successfully delivered, it is retained only for the period associated with your subscription before being securely deleted.

This helps reduce unnecessary long-term storage of personal data.

International Data Transfers

Where personal data is transferred outside the European Economic Area, EEA, Kleevo ensures that appropriate safeguards are in place in accordance with applicable data protection laws.

Subprocessors

Kleevo works with carefully selected service providers to operate the platform.

Examples include providers for:

  • Cloud infrastructure
  • Email delivery
  • SMS delivery
  • Payment processing
  • Identity verification, Swedish BankID

Every subprocessor is carefully evaluated to ensure an appropriate level of security and data protection.

A complete list of subprocessors is available upon request.

Your Rights

If you are the subject of personal data processed through Kleevo, you may have rights under GDPR, including:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

Requests should generally be directed to the organization that sent you the document, as they are typically the Data Controller.

If you have questions about Kleevo's own processing of personal data, you're always welcome to contact us.

Privacy by Default

Every new Kleevo account is configured with privacy in mind.

Examples include:

  • Secure authentication
  • Encrypted communication
  • Limited document retention
  • Audit logging
  • Verification of finalized documents

Privacy shouldn't require additional configuration. It should be built into the platform.

Transparency

We believe businesses should understand how their information is handled.

That's why we openly provide documentation covering:

  • Privacy Policy
  • Terms of Service
  • Security
  • GDPR Compliance
  • Cookie Policy
  • Data Processing Agreement, DPA

Our goal is to be transparent about how Kleevo works and how your data is protected.

Questions?

If you have questions regarding GDPR, data protection, or privacy, we'd be happy to help.

Contact: support@kleevo.se

Our Commitment

GDPR compliance isn't just about legal requirements.

It's about respecting the trust our customers place in us every time they upload a document.

Our goal is simple:

Provide the easiest document signing experience while protecting the privacy of every sender and signer.