Privacy Policy

Last updated 26 August 2026
Last reviewed: 26 August 2026

DSAR Desk (dsar.klairlabs.com, operated by Klair Technology Solutions Private Limited (Klair Labs), Hyderabad, India) is a tool businesses use to receive and track GDPR, CCPA and DPDP data-subject requests. This policy describes what we actually store — not a generic template — and it covers two different people, because DSAR Desk plays two different roles depending on who you are.

You run a business using DSAR DeskWe are, in effect, a data processor acting on your instructions for the requests you handle — you remain the controller of your own customers' data. This policy explains what we store about your account and how we handle the requests flowing through it on your behalf.
You submitted a request through someone's DSAR Desk linkThe business whose link you used is the controller of your data, not us — direct your GDPR/CCPA/DPDP request to them, using the same link or their usual contact channel. We are a processor storing your submission on their behalf. See "If you submitted a request" below for what that means for you specifically.

1. Information we collect from account holders (businesses)

WhatWhyHow long
Your email address. Created the first time you sign in — there is no password, only a signed emailed link.To identify your account and sign you in. Until you ask us to delete your workspace
Business name, and optionally a logo and accent colour (logo/colour is a Pro feature).Shown on your public intake page so requesters know who they're submitting to — this is a trust requirement, not a cosmetic one.Until you change or remove it
Subscription records — plan, status and renewal dates, from Razorpay. To provide what you've paid for.As required for tax and accounting records
An internal audit trail of actions on your account and requests (e.g. a status change, a note added, a licence issued) — timestamp and actor, not full message content beyond what's described below.Accountability and security; the record of who did what and when.Currently kept indefinitely alongside the account
An anonymous usage beacon when a page loads — page path, an event name, and the referring host. No email addresses or request content are included. To know which parts of the product actually get used.Indefinitely, as aggregate counts

2. Information we collect from requesters (processed on a business's behalf)

When someone submits a data request through your DSAR Desk intake link, we store, on your instructions and for your use in responding:

We do not read, use or share this data for our own purposes — it exists so your business can see and act on it, and so the deadline is calculated automatically. We send the requester one automatic acknowledgement email on submission; we do not otherwise contact them.

If you submitted a request:

Your request lives in the account of the business you sent it to, not in an account of ours. We can't act on it, change it, or tell you its status — that's the business's decision, since they're the controller. If you have concerns about how DSAR Desk itself (as opposed to the business) secures or retains this data, or you believe a business is misusing the tool, email hello@klairtech.com and we'll look into it.

3. What we don't do

4. Cookies and local storage

DSAR Desk uses localStorage, not a persistent tracking cookie, to hold your signed-in session token (dsar_lic) on your own device. There is no advertising or third-party analytics cookie on any DSAR Desk page. A small first-party beacon (see above) reports anonymous page-view counts; it sets no cookie and carries no identifying value.

5. Payments

Subscriptions are processed by Razorpay. Card, UPI and bank details are entered on Razorpay's own checkout and go directly to them — DSAR Desk never receives or stores your card number, CVV, UPI PIN or bank credentials. We receive only a subscription identifier, its status, and the email address you signed up with.

6. Email

We send transactional email only — sign-in links, request acknowledgements, and account notices — through Amazon Simple Email Service. We do not send marketing email, and using the free tier does not put you on a mailing list.

7. Sub-processors

The full, current list of sub-processors — the third-party services that handle account or request data on our behalf, what each does, and where each runs — lives on its own page: Sub-processors. As at 26 August 2026 it is: Amazon Web Services (hosting and database, Mumbai), Amazon SES (transactional email, Mumbai), Razorpay (payments, India), and Amazon CloudFront (content delivery; caches pages, not account or request data). Pages also load fonts from Google Fonts, which means Google receives the visitor's IP address for the font request — the sub-processor page covers that too. We commit to updating that page at least 14 days before adding a new sub-processor.

If your organisation needs a Data Processing Addendum for its own compliance records, we publish one you can read and countersign: Data Processing Addendum.

8. Data retention and deletion

You can delete your own workspace at any time from Settings in the app — this removes your account, every request record, every property and any branding you've set, immediately, with no need to email us. Where we must keep a record of a payment for tax purposes, we keep only that. You can choose a retention window for how long request records are kept (6, 12 or 24 months, or indefinitely) in Settings. A daily automated job purges request records past their window once they're closed (completed or denied) — an open request is never purged early regardless of age, since it's still a live obligation you have to answer. If you want records gone sooner, email hello@klairtech.com and we'll do it manually within the deadline that would apply to a GDPR erasure request — 30 days — even though we are not always the controller.

9. Where data is held

Account, request, and subscription records are stored in AWS's Asia Pacific (Mumbai) region. Pages are served through a global content delivery network for speed; that network caches and serves pages, it does not store the personal data described above.

10. Your rights

If you're an account holder, you can ask what we hold about you and ask us to correct or delete it, the same way described in section 8. If you're a requester, your rights run against the business you submitted your request to, as explained in section 2 — we'll still help if your concern is with DSAR Desk specifically rather than that business.

11. Children

DSAR Desk is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18 as an account holder.

12. Changes

If this policy changes we'll update the date at the top. Material changes to how we handle personal data will be announced on this page.

13. Contact

Klair Labs — hello@klairtech.com. This policy is a description of what DSAR Desk does, not a substitute for legal advice about your own obligations as a business — see our Terms for that distinction spelled out.