Sub-processors
Last updated: 2026-10-09 (register version 2026-10-09)
Klarte.no (“Klarte”) uses the providers below to run the platform. For booker data, Klarte is the processor under Article 28 of the GDPR for the business (the controller). For business-account and billing data, Klarte is the controller, as stated in the platform privacy notice.
Material changes to the list are notified via the platform and/or by email to businesses, in line with the data processing agreement.
1. Current sub-processors
| Provider | Purpose | Categories of information | Location | Transfer basis |
|---|---|---|---|---|
| Hetzner Online GmbH (hetzner.com) Sub-processor (platform infrastructure) | VPS hosting for the Klarte application, database storage, backups, and production infrastructure | All personal data processed on the platform in production (tenant accounts, booking/booker data, technical and security logs stored on the server) | European Union — Germany / Finland datacenters (as configured for the production VPS) | EEA processing under Hetzner terms and data processing agreement; no routine transfer outside EEA for core hosting |
| Bird / MessageBird B.V. (bird.com) Sub-processor (email and SMS delivery) | Transactional email from noreply@klarte.no and SMS delivery (account verification, booking confirmations, appointment reminders, privacy/manage links). The sending address does not accept replies | Recipient email addresses and mobile numbers, names where included, message subject and body (including booking details and links). Under Bird’s DPA of 21 November 2024, email content is kept for 72 hours and SMS content and traffic data for six months. Bird’s privacy statement also lists email address, subject, IP address and other email traffic data for up to six months after sending | EU data region eu1: messages, recipient data and event logs stay in that region and are not copied to us1. MessageBird B.V. is established in the Netherlands. Sign-in and account administration use Bird’s global platform host. A transfer outside the EEA happens only if a Bird entity or sub-processor outside the EEA is used, as described in Bird’s DPA | Bird Data Processing Agreement, last updated 21 November 2024, accepted electronically when the Bird account is used (GDPR Art. 28(9)). EU Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914, Module Two or Three, apply only if personal data is transferred to a Bird entity outside the EEA or Switzerland |
| ImprovMX (improvmx.com) Sub-processor (inbound email forwarding) | Forwarding inbound email to Klarte addresses (hjelp@klarte.no, kontakt@klarte.no, and any reply sent to noreply@klarte.no) to Klarte’s mailbox | Sender address, subject, message content, and attachments while the message is in transit; short-lived delivery logs. Message content is deleted after delivery | Inbound mail is held transiently in the EU (AWS Paris, France) and deleted after delivery. Onward delivery may use infrastructure in France and the United States, as described by ImprovMX | ImprovMX data processing agreement; EU Standard Contractual Clauses (Art. 46) where delivery uses infrastructure outside the EEA |
| Stripe, Inc. / Stripe Payments Europe, Limited (stripe.com) Independent payment processor / sub-processor for SaaS billing | SaaS subscription billing for Klarte plans, prepaid SMS reminder credit purchases, and card processing for optional booker appointment payments on the tenant’s Stripe connected account (tenant is merchant of record; Klarte is not the seller) | Business account billing identity, payment method metadata, invoices, subscription status; for connected booker charges: charge/refund records and payment metadata needed to run Checkout on the tenant’s Stripe account | EU (Stripe Payments Europe) and/or United States as described in Stripe’s DPA and regional terms | Stripe Data Processing Agreement and published SCCs / adequacy mechanisms |
| Google LLC (Google Sign-In / accounts.google.com) Identity provider / authentication service (optional Google Sign-In) | Optional business-account sign-up and sign-in via Google OAuth (OpenID Connect). Used only when you choose “Sign up with Google” or “Sign in with Google”; email/password accounts do not use this provider for authentication | Google account subject ID, verified email address, email verification status, and given/family name if provided by Google. Technical request metadata during the OAuth redirect. Not used for booker appointment data | United States / global Google infrastructure as described in Google’s privacy documentation | Google Cloud / Google API data processing terms and EU Standard Contractual Clauses (Art. 46) where a transfer outside the EEA occurs; Google Account authentication is also governed by Google’s own terms and privacy policy |
| Tailwind Labs (cdn.tailwindcss.com) CDN / technical service provider | CSS framework delivery on pages that load the Tailwind CDN (necessary for UI). Prefer compiled first-party CSS when available. | Technical data (typically IP address and request metadata) | United States / global CDN | Art. 46 SCC where required; disclosed in Cookie Policy; roadmap to self-host compiled CSS |
| Cloudflare, Inc. (cdnjs.cloudflare.com) CDN / technical service provider | Delivery of icon fonts (Tabler Icons) used on some Klarte pages | Technical data (typically IP address and request metadata) | Global Cloudflare edge (may include non-EEA) | Cloudflare DPA / SCCs where required; prefer self-hosting assets |
2. Transfers to third countries
Where a provider processes personal data outside the EEA/United Kingdom, Klarte relies on appropriate safeguards under Article 46 (usually the EU standard contractual clauses) and the provider’s data-processing terms, unless an adequacy decision applies.
3. Stripe
The Klarte SaaS subscription is billed through Stripe as stated in the terms of use section 6.
Optional card payment for appointments (prepay / pay after) is charged on the business’s connected Stripe account. The business is the seller and the payee. Klarte is not the seller and does not hold funds from bookers. A refund to the booker is started by the business (for example from Calendar) and carried out by Stripe. See the terms of use, section 6a.
4. Optional Google sign-in
If you choose Sign up with Google or Sign in with Google at registration or sign-in, Klarte sends you to Google to authenticate. Google then returns a limited profile to Klarte (a stable Google user ID, a verified email, and a name if provided) so we can create or link the business account. This is optional — you can always use email and password instead. Google sign-in is not used for booker data, and Klarte does not load Google Fonts or Google advertising code as part of this flow.
When you use Google sign-in, Google processes your Google account under Google’s own terms and privacy rules. Klarte’s use of the identity details returned for your Klarte account is described in the platform privacy notice.
5. Questions
hjelp@klarte.no — ask for the current register version and any planned changes.