Privacy Policy
DSAR Desk (dsar.klairlabs.com, operated by Klair Technology Solutions Private Limited (Klair Labs), Hyderabad, India) is a tool businesses use to receive and track GDPR, CCPA and DPDP data-subject requests. This policy describes what we actually store — not a generic template — and it covers two different people, because DSAR Desk plays two different roles depending on who you are.
1. Information we collect from account holders (businesses)
| What | Why | How long |
|---|---|---|
| Your email address. Created the first time you sign in — there is no password, only a signed emailed link. | To identify your account and sign you in. | Until you ask us to delete your workspace |
| Business name, and optionally a logo and accent colour (logo/colour is a Pro feature). | Shown on your public intake page so requesters know who they're submitting to — this is a trust requirement, not a cosmetic one. | Until you change or remove it |
| Subscription records — plan, status and renewal dates, from Razorpay. | To provide what you've paid for. | As required for tax and accounting records |
| An internal audit trail of actions on your account and requests (e.g. a status change, a note added, a licence issued) — timestamp and actor, not full message content beyond what's described below. | Accountability and security; the record of who did what and when. | Currently kept indefinitely alongside the account |
| An anonymous usage beacon when a page loads — page path, an event name, and the referring host. No email addresses or request content are included. | To know which parts of the product actually get used. | Indefinitely, as aggregate counts |
2. Information we collect from requesters (processed on a business's behalf)
When someone submits a data request through your DSAR Desk intake link, we store, on your instructions and for your use in responding:
- The requester's email address
- What they're asking for (access, deletion, correction or opt-out) and which law they selected
- Any free-text details they typed in describing their request
- Internal notes you or your team add while working the request (not shared with the requester)
- Timestamps for submission, status changes, and any extension applied
We do not read, use or share this data for our own purposes — it exists so your business can see and act on it, and so the deadline is calculated automatically. We send the requester one automatic acknowledgement email on submission; we do not otherwise contact them.
Your request lives in the account of the business you sent it to, not in an account of ours. We can't act on it, change it, or tell you its status — that's the business's decision, since they're the controller. If you have concerns about how DSAR Desk itself (as opposed to the business) secures or retains this data, or you believe a business is misusing the tool, email hello@klairtech.com and we'll look into it.
3. What we don't do
- We carry no advertising on DSAR Desk, so there is no ad-tracking, no AdSense, and no data shared with ad networks.
- We do not sell personal information, and we do not add anyone to a marketing list because they used the free tier or submitted a request.
- We do not read the contents of a request to train models, market to requesters, or for any purpose beyond delivering the product.
4. Cookies and local storage
DSAR Desk uses localStorage, not a persistent tracking cookie, to hold your
signed-in session token (dsar_lic) on your own device. There is no advertising or
third-party analytics cookie on any DSAR Desk page. A small first-party beacon (see above)
reports anonymous page-view counts; it sets no cookie and carries no identifying value.
5. Payments
Subscriptions are processed by Razorpay. Card, UPI and bank details are entered on Razorpay's own checkout and go directly to them — DSAR Desk never receives or stores your card number, CVV, UPI PIN or bank credentials. We receive only a subscription identifier, its status, and the email address you signed up with.
6. Email
We send transactional email only — sign-in links, request acknowledgements, and account notices — through Amazon Simple Email Service. We do not send marketing email, and using the free tier does not put you on a mailing list.
7. Sub-processors
The full, current list of sub-processors — the third-party services that handle account or request data on our behalf, what each does, and where each runs — lives on its own page: Sub-processors. As at 26 August 2026 it is: Amazon Web Services (hosting and database, Mumbai), Amazon SES (transactional email, Mumbai), Razorpay (payments, India), and Amazon CloudFront (content delivery; caches pages, not account or request data). Pages also load fonts from Google Fonts, which means Google receives the visitor's IP address for the font request — the sub-processor page covers that too. We commit to updating that page at least 14 days before adding a new sub-processor.
If your organisation needs a Data Processing Addendum for its own compliance records, we publish one you can read and countersign: Data Processing Addendum.
8. Data retention and deletion
You can delete your own workspace at any time from Settings in the app — this removes your account, every request record, every property and any branding you've set, immediately, with no need to email us. Where we must keep a record of a payment for tax purposes, we keep only that. You can choose a retention window for how long request records are kept (6, 12 or 24 months, or indefinitely) in Settings. A daily automated job purges request records past their window once they're closed (completed or denied) — an open request is never purged early regardless of age, since it's still a live obligation you have to answer. If you want records gone sooner, email hello@klairtech.com and we'll do it manually within the deadline that would apply to a GDPR erasure request — 30 days — even though we are not always the controller.
9. Where data is held
Account, request, and subscription records are stored in AWS's Asia Pacific (Mumbai) region. Pages are served through a global content delivery network for speed; that network caches and serves pages, it does not store the personal data described above.
10. Your rights
If you're an account holder, you can ask what we hold about you and ask us to correct or delete it, the same way described in section 8. If you're a requester, your rights run against the business you submitted your request to, as explained in section 2 — we'll still help if your concern is with DSAR Desk specifically rather than that business.
11. Children
DSAR Desk is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18 as an account holder.
12. Changes
If this policy changes we'll update the date at the top. Material changes to how we handle personal data will be announced on this page.
13. Contact
Klair Labs — hello@klairtech.com. This policy is a description of what DSAR Desk does, not a substitute for legal advice about your own obligations as a business — see our Terms for that distinction spelled out.