1. About This Policy
This Privacy Policy explains how FITIONLED Oy, the company that owns and operates Clafk, collects, uses, and protects personal data when you use our Service.
We comply with the EU General Data Protection Regulation (GDPR) and applicable Finnish data protection laws.
By using Clafk, you acknowledge and accept the practices described in this Policy.
2. Who We Are
FITIONLED Oy is a company registered in Finland under Business ID 3462861-3.
For the purposes of GDPR:
- We act as the Data Controller for account-related personal data such as names, email addresses, and billing information.
- For customer mailbox content and other Customer Data processed through the Service on behalf of business customers, we act as the Data Processor.
For privacy-related matters, you can contact us at:
Email: security@clafk.com
3. Data We Collect
We may collect the following categories of personal data:
- Contact information, such as your name, email address, company name, and role.
- Account information, including login credentials and preferences.
- Billing information, such as billing address and payment details processed by our payment providers.
- User Content, including emails, documents, and information connected or uploaded to Clafk.
- Mailbox connection credentials, including the access and refresh tokens issued by Google or Microsoft when you connect a mailbox. These are stored server-side and are not accessible from your browser.
- Derived writing-style information, such as greeting, closing, formality and phrasing patterns inferred from recent sent messages to personalise draft writing.
- Usage information about how you interact with the Service.
- Technical information such as IP address, browser type, device information, and operating system details.
4. How We Collect Data
We collect personal data:
- Directly from you when you create an account, contact us, or use the Service.
- Automatically through cookies, logs, and similar technologies when you interact with Clafk or our website.
- From third-party providers, such as Google or Microsoft, when you connect external services to Clafk.
5. Why We Use Your Data
We process personal data only where permitted by applicable law. We use data to:
- Provide, operate, and maintain the Service.
- Process payments and manage subscriptions.
- Communicate with you regarding support, updates, and account-related matters.
- Improve and develop Clafk and its features.
- Meet legal and regulatory obligations.
- Detect, prevent, and investigate fraud, abuse, and security issues.
Our legal bases for processing include:
- Performance of a contract.
- Legitimate business interests.
- Compliance with legal obligations.
- Consent, where required by law.
6. Email and LLM Processing
Clafk automatically processes connected mailbox data to classify messages and prepare draft replies. Processing starts only after you connect a mailbox through Google or Microsoft, and you can disconnect it at any time.
Normal operation does not involve human review of customer mailbox content. Processing is performed automatically by Clafk’s systems.
Clafk processes message content only as necessary to provide the Service. Complete inbound email bodies are not permanently stored and are not sent to LLM providers. Limited excerpts are processed for classification and draft generation, and stored while your account is active. Email attachments are not retrieved or stored.
Clafk uses Large Language Model (LLM) providers as technical subprocessors for classification and draft generation. Only the information needed for the request is sent, such as sender details, the subject line, and limited excerpts of message text. When you add knowledge-base content, portions of that content may also be processed by an AI provider to create embeddings used for retrieval.
- Clafk does not use customer data to train its own models.
- Clafk uses LLM providers to perform the classification and draft-generation requests required by the Service.
- Requests are made by Clafk’s servers. Your data is not sent to LLM providers from your browser.
- How LLM providers handle and retain data submitted through their interfaces is set out in their own terms.
7. Sharing Your Data
We share personal data only with parties that help us operate and provide the Service, including:
- Service providers that help us run Clafk, covering hosting and infrastructure, database services, mailbox integrations, transactional email delivery, monitoring, payments, LLM processing, and customer relationship tools used to respond to enquiries.
- Public authorities where disclosure is legally required.
- Successors or acquiring entities in the event of a merger, acquisition, restructuring, or sale of our business.
Our service providers are required to process personal data in accordance with applicable data protection requirements and their contractual obligations.
We do not sell your personal data.
8. International Data Transfers
Some service providers used by Clafk may process data outside the European Economic Area (EEA), including in the United States.
Where international transfers occur, we use safeguards approved under GDPR, such as Standard Contractual Clauses (SCCs), to protect personal data.
9. Data Retention
We retain personal data only for as long as necessary to:
- Provide and maintain the Service.
- Comply with legal, tax, accounting, and regulatory obligations.
- Resolve disputes and enforce agreements.
Complete inbound email bodies are not permanently stored. Generated drafts and the limited message details needed to run the Service are stored while your account is active.
When personal data is no longer required, we delete it. We do not apply fixed retention periods to customer content. Customer data is retained while your account is active and removed through our deletion process when you delete your account, subject to applicable legal requirements and provider backup processes.
You may request deletion of your personal data at any time, subject to applicable legal requirements.
10. Security
We implement appropriate technical and organisational safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.
Our measures include encrypted connections, TLS-protected communication between Clafk and the services it integrates with, server-side processing of mailbox data, and access controls that separate each customer’s data.
Clafk does not manually review customer emails as part of normal service operation. Limited access may occur only when necessary for operational support or security purposes, and is restricted to authorised personnel.
While we work to maintain strong security practices, no system can be guaranteed to be completely secure. You are responsible for maintaining the confidentiality of your account credentials.
If we become aware of a data breach affecting your personal data, we will notify you and relevant authorities where required by law.
11. Your Rights
If you are located in the EU or EEA, you may have the following rights under GDPR:
- Access your personal data.
- Correct inaccurate or incomplete data.
- Request deletion of your data.
- Restrict or object to certain processing activities.
- Receive your data in a portable format.
- Withdraw consent where processing is based on consent.
- File a complaint with a supervisory authority.
To exercise your rights, contact security@clafk.com.
We aim to respond to requests within 30 days where required under applicable law.
You may also contact the Office of the Data Protection Ombudsman regarding data protection concerns.
12. Cookies
Clafk uses necessary cookies for authentication, security, and core website functionality. With your consent, we may also use analytics cookies, including Google Analytics 4, to understand how visitors use the website and improve the service.
You can accept, reject, or change your cookie choices through the Cookiebot consent banner. Analytics cookies are not loaded unless you consent to Statistics cookies.
You can also control cookies through your browser settings. Disabling necessary cookies may affect certain functionality of the Service.
13. Children’s Privacy
Clafk is intended for business and professional use and is not designed for individuals under the age of 18.
We do not knowingly collect personal data from children.
14. Changes to This Policy
We may update this Privacy Policy from time to time.
The “Last Updated” date indicates the latest version. Continued use of the Service after updates become effective constitutes acceptance of the revised Policy.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us: