HomePrivacy
Privacy
Privacy and data protection
Klivr sells to organisations, and the system runs on behaviour data from the people who use it. This page is the short version: what the system reads, who is responsible, and who sees what. The documents a privacy officer actually works through are listed at the foot of the page, and we send them on request, usually within two working days.
Last updated 12 August 2026.
What the system reads
The system records what someone practises, how far they have come in a programme, and the reflections that person chooses to share. Account data is a name, a work email address and a team. Logs are kept for security and availability.
Who is responsible
Klivr holds three positions in law depending on which data is in question, and they carry different obligations.
-
Processor, for your programme
Your organisation is the controller and Klivr acts on your documented instructions. The lawful basis is yours to establish, normally performance of the employment contract or a legitimate interest, with works council (ondernemingsraad) consent recorded where article 27 of the Dutch Works Councils Act (WOR) applies. Our obligations sit in the data processing agreement.
-
Controller, for learning across organisations
Klivr learns from aggregated data with names and organisations removed, on the legitimate interest under article 6(1)(f) in understanding where adoption stalls and what helps. The aggregation happens before the data is used, so no result traces back to a person or to a customer. Your programme data stays yours and never appears in another customer’s view.
-
Controller, for running our own business
Account administration, billing and the security of the service, on performance of the contract with your organisation and on legitimate interest in keeping the system secure and available.
Who sees what
A manager sees the team picture: where the team stands, and which step helps most this week. A reflection carries a name after the person releases it, and only then. When someone wants help, they choose who receives it: their manager, an external coach, both, or a private note to themselves.
Until five people have responded, the system shows a phase signal with a suggested action in place of a score.
Where processing happens
This depends on the component. The coach runs on one language model. We name the region for every component, and the transfer mechanism wherever one processes outside the European Union, in a dated subprocessor list with each name, role and country. The security pack sets out how sign-in works, who can reach what, and what is written to the access log. Ask and we send it.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, objection, and data portability. Write to hi@klivr.nl. For anything inside your programme your employer is the controller, so we pass the request on and support them in answering it. For account data and the aggregated learning we answer you directly. The Dutch data protection authority (Autoriteit Persoonsgegevens) supervises this processing, and you may complain to them at any time.
Klivr has not appointed a data protection officer (functionaris gegevensbescherming): the thresholds in article 37 are not met at our size. Privacy questions reach Rob at hi@klivr.nl.
Cookies on this website
This section is about klivr.nl itself, not about the system inside your programme. We count visitors with Cloudflare Web Analytics. It places nothing on your device and records no personal data, so it runs for everyone and we do not ask.
Analytics cookies only run if you accept them. Google Analytics tells us which pages are read and how people find us. Microsoft Clarity records how a page is used, which means mouse movement, scrolling and clicks. This website carries no forms and no input fields, so there is nothing you type for it to record. Both place cookies on your device and process data in the United States under standard contractual clauses. Decline and neither one loads, nothing is placed on your device, and the site works exactly the same.
Your answer is kept in your own browser rather than in a cookie, and you can change it by clearing this site's data. Cloudflare, Google and Microsoft are named in the dated subprocessor list we send on request, with their role and country.
Documents we send on request
Klivr holds no security certification today. What exists is listed here, and it is what we send.
-
Data processing agreement
We sign one before any personal data is processed, with standard contractual clauses where they apply. Retention periods per category are set in it.
-
Subprocessor list
Dated, with each name, role and country of processing, and the transfer mechanism wherever one sits outside the European Union.
-
Security questionnaire
Our answers on the ISO/IEC 27001:2022 Annex A controls. We answer the ones we can evidence in code and configuration, and we name the ones we leave out.
-
DPIA input
Our input for your data protection impact assessment, with a template to start from.
-
Works council pack
An information pack in Dutch covering consent under article 27 of the Dutch Works Councils Act (ondernemingsraad, WOR).
Write to hi@klivr.nl. We answer privacy officers within two working days. Klivr B.V. (in registration, in oprichting) is established in the Netherlands, and the Chamber of Commerce (Kamer van Koophandel, KvK) number is published here as soon as incorporation completes.