GDPR Compliance
Privacy by Design
Kleevo is designed with privacy, security, and transparency in mind, helping businesses send documents for signing while meeting their GDPR obligations.
GDPR Compliance at a Glance
Kleevo is designed with privacy and data protection at its core. Here's a quick overview of how we help businesses comply with GDPR.
Privacy by Design
Data Processor
Data Processing Agreement (DPA)
Encrypted Communication
Secure Cloud Storage
Limited Document Retention
Document Verification
Complete Audit Trail
No Selling of Personal Data
Data Minimization
Your Data, Your Control
Our Commitment
Our goal is simple:
Provide the easiest document signing experience while protecting the privacy and personal data of every sender and signer.
Privacy by Design
At Kleevo, protecting personal data isn't an afterthought. It is a core part of how we've built the platform.
Every feature is designed with privacy, security, and transparency in mind, helping businesses send documents for signing while meeting their obligations under the General Data Protection Regulation, GDPR.
Our Role Under GDPR
In most cases, Codeberg Solutions AB (operating Kleevo) acts as a Data Processor.
Our customers act as the Data Controller, meaning they determine why and how personal data is processed.
Kleevo processes personal data only to provide the document signing services requested by our customers.
Data Controller
As the customer, you control:
- Which documents are uploaded
- Who receives signing requests
- Which signing method is used
- How long documents should be retained, depending on your plan
Data Processor
Kleevo processes personal data solely to:
- Deliver signing requests
- Verify signatures
- Generate audit trails
- Notify recipients
- Finalize completed documents
- Provide customer support
We never sell your personal data or use uploaded documents for advertising or marketing purposes.
Data Processing Agreement
For customers that require one, Kleevo offers a Data Processing Agreement, DPA.
The DPA describes:
- How personal data is processed
- Security obligations
- Confidentiality
- Subprocessors
- Customer rights
- GDPR responsibilities
You can request a signed DPA by contacting us.
Data Storage
Customer data is stored using secure cloud infrastructure.
Documents remain encrypted during transmission and are securely stored throughout the signing process.
Kleevo is not intended to be a permanent document archive.
Completed documents are retained only for the applicable retention period before being securely deleted.
Customers remain responsible for the long-term storage of finalized documents.
Security Measures
Protecting your information is one of our highest priorities.
Kleevo uses modern security practices including:
- HTTPS/TLS encrypted communication
- Secure cloud storage
- Cryptographic document hashing
- Complete audit trails
- Role-based access controls
- Continuous monitoring
For more information, please visit our Security page.
Data Minimization
We believe software should only collect the information necessary to provide the service.
We only process personal data required to:
- Create signing requests
- Identify recipients
- Verify completed signatures
- Deliver notifications
- Generate audit trails
- Operate and secure the platform
We never collect unnecessary information.
Document Retention
Unlike many document management platforms, Kleevo is not designed for permanent storage.
Once a document has been completed and successfully delivered, it is retained only for the period associated with your subscription before being securely deleted.
This helps reduce unnecessary long-term storage of personal data.
International Data Transfers
Where personal data is transferred outside the European Economic Area, EEA, Kleevo ensures that appropriate safeguards are in place in accordance with applicable data protection laws.
Subprocessors
Kleevo works with carefully selected service providers to operate the platform.
Examples include providers for:
- Cloud infrastructure
- Email delivery
- SMS delivery
- Payment processing
- Identity verification, Swedish BankID
Every subprocessor is carefully evaluated to ensure an appropriate level of security and data protection.
A complete list of subprocessors is available upon request.
Your Rights
If you are the subject of personal data processed through Kleevo, you may have rights under GDPR, including:
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object to processing
Requests should generally be directed to the organization that sent you the document, as they are typically the Data Controller.
If you have questions about Kleevo's own processing of personal data, you're always welcome to contact us.
Privacy by Default
Every new Kleevo account is configured with privacy in mind.
Examples include:
- Secure authentication
- Encrypted communication
- Limited document retention
- Audit logging
- Verification of finalized documents
Privacy shouldn't require additional configuration. It should be built into the platform.
Transparency
We believe businesses should understand how their information is handled.
That's why we openly provide documentation covering:
- Privacy Policy
- Terms of Service
- Security
- GDPR Compliance
- Cookie Policy
- Data Processing Agreement, DPA
Our goal is to be transparent about how Kleevo works and how your data is protected.
Questions?
If you have questions regarding GDPR, data protection, or privacy, we'd be happy to help.
Contact: support@kleevo.se
Our Commitment
GDPR compliance isn't just about legal requirements.
It's about respecting the trust our customers place in us every time they upload a document.
Our goal is simple:
Provide the easiest document signing experience while protecting the privacy of every sender and signer.