Klyro Privacy Policy
As of: July 28, 2026
This Privacy Policy explains how ZXNET SOLUTIONS SAS ("Klyro", "we", "our" or "us") collects, uses, stores and protects personal data when providing the Klyro platform and related services (the "Service").
This Privacy Policy applies to visitors of our website, Customers, Authorized Users, End Users who interact with Klyro Capture Sessions, and other individuals whose personal data we process in connection with the Service.
By accessing or using the Service, you acknowledge that your personal data may be processed as described in this Privacy Policy.
1. Who We Are
The Service is provided by:
ZXNET SOLUTIONS SAS
- Registered office: 26 rue Bosquet, 75007 Paris - France
- Share capital: €1,000
- Registered with the Paris Trade and Companies Register under number 944 068 253
- VAT: FR32944068253
- Email: contact@withklyro.com
2. Scope
Klyro provides a platform allowing organizations to request, collect, verify and manage photographic evidence and related metadata.
Depending on the circumstances, Klyro may process personal data:
- as a Data Controller, for information relating to our Customers, website visitors, billing, support and account management;
- as a Data Processor, when processing Customer Data on behalf of our Customers.
Where Klyro acts solely as a processor, the relevant Customer remains responsible for determining the purposes and legal basis for processing personal data.
3. Information We Collect
The categories of information we may collect include:
Account Information
- name
- email address
- telephone number
- job title
- organization name
- login credentials
- account preferences
Organization Information
- company name
- registered address
- VAT number
- billing information
- subscription information
Capture Session Information
Depending on how our Customers configure the Service, Capture Sessions may include:
- photographs
- videos
- timestamps
- device information
- approximate location information
- browser information
- IP address
- session identifiers
- reference numbers
- Customer-provided metadata
- comments or notes
The exact information collected is determined by the Customer using the Service.
Technical Information
We automatically collect technical information including:
- IP address
- browser type
- operating system
- device characteristics
- language preferences
- pages visited
- access times
- diagnostic logs
- API usage
- error reports
Billing Information
Payments are processed by third-party payment providers.
Klyro does not store complete payment card numbers.
We may receive information such as:
- payment status
- transaction identifiers
- invoice references
- subscription status
- billing history
4. How We Use Personal Data
We use personal data to:
- provide the Service;
- authenticate users;
- create and manage accounts;
- process payments;
- generate invoices;
- operate Capture Sessions;
- detect fraud and abuse;
- maintain platform security;
- improve reliability and performance;
- provide customer support;
- communicate service updates;
- comply with legal obligations;
- enforce our Terms of Service.
We do not sell personal data.
5. Legal Bases for Processing
Where the GDPR applies, we process personal data on one or more of the following legal bases:
- performance of a contract;
- compliance with legal obligations;
- legitimate interests;
- consent, where required by law.
When Klyro acts as a processor, the legal basis for processing is determined by the relevant Customer acting as controller.
6. Customer Responsibilities
Customers are responsible for ensuring that they have an appropriate legal basis to collect and submit personal data through the Service.
Customers are responsible for providing any notices and obtaining any consents required under applicable law, including with respect to End Users participating in Capture Sessions.
Klyro processes Customer Data only in accordance with the Customer's documented instructions unless otherwise required by law.
7. How We Share Personal Data
We may disclose personal data only where necessary to provide the Service or where required by applicable law.
Recipients may include:
- cloud hosting providers;
- infrastructure and storage providers;
- payment processors;
- email delivery providers;
- customer support providers;
- analytics and monitoring providers;
- professional advisers, auditors and insurers;
- public authorities where legally required.
We do not sell personal data to third parties.
We do not share Customer Data with advertisers.
8. Subprocessors
To operate the Service, Klyro relies on carefully selected third-party service providers.
Depending on the features used, these providers may include services for:
- cloud infrastructure;
- database hosting;
- object storage;
- payment processing;
- invoicing;
- email delivery;
- monitoring and logging;
- customer support.
Subprocessors are granted access only where necessary to perform services on our behalf and are contractually required to protect personal data.
An up-to-date list of subprocessors may be made available upon request or published on our website.
9. International Data Transfers
Personal data may be processed in countries other than the country where it was originally collected.
Where personal data is transferred outside the European Economic Area, United Kingdom or Switzerland, Klyro implements appropriate safeguards as required by applicable law, including where appropriate:
- Standard Contractual Clauses approved by the European Commission;
- adequacy decisions;
- or other legally recognized transfer mechanisms.
10. Data Retention
We retain personal data only for as long as necessary to:
- provide the Service;
- comply with legal obligations;
- resolve disputes;
- enforce agreements;
- maintain security;
- prevent fraud.
Retention periods vary depending on the type of data.
Examples include:
- account information while an account remains active;
- billing records for applicable statutory retention periods;
- security logs for a limited period;
- Customer Data in accordance with the Customer's instructions and applicable contractual commitments.
Upon termination of the Service, Customer Data may be deleted after a reasonable retention period unless continued retention is required by law or requested by the Customer.
11. Security
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration or destruction.
Such measures may include:
- encryption in transit;
- encryption at rest where appropriate;
- role-based access controls;
- authentication mechanisms;
- infrastructure monitoring;
- audit logging;
- backup procedures;
- vulnerability management;
- incident response procedures.
No method of electronic transmission or storage is completely secure, and therefore we cannot guarantee absolute security.
12. Artificial Intelligence
Klyro may use automated technologies to assist in analyzing metadata, detecting inconsistencies, improving fraud detection or providing Service functionality.
Unless explicitly agreed otherwise in writing:
- Customer Data is not used to train public artificial intelligence models;
- uploaded photographs, videos and Customer Data are not used to train generative AI models;
- Customer Data remains under the Customer's control subject to applicable agreements.
Where AI-assisted features are provided, they are intended to support human decision-making and do not constitute legal, insurance or professional determinations.
13. Cookies and Similar Technologies
Klyro uses cookies and similar technologies necessary for:
- authentication;
- security;
- session management;
- user preferences;
- performance monitoring;
- analytics.
Where required by applicable law, we request consent before placing non-essential cookies.
Additional information may be provided in a separate Cookie Policy.
14. Your Rights
Depending on your jurisdiction, you may have rights including:
- access to your personal data;
- correction of inaccurate data;
- deletion of personal data;
- restriction of processing;
- objection to processing;
- data portability;
- withdrawal of consent where processing is based on consent;
- lodging a complaint with the competent supervisory authority.
If Klyro processes your personal data solely on behalf of one of our Customers, you should generally direct your request to that Customer, who acts as the data controller.
Where appropriate, we will assist our Customers in responding to such requests.
15. Children's Privacy
The Service is intended for business use.
It is not directed toward children, and we do not knowingly collect personal data directly from children.
If we become aware that personal data has been collected in violation of applicable law, we will take reasonable steps to delete it.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
Material changes will be communicated through appropriate means, including the Service or our website where appropriate.
The "As of" date at the top of this Privacy Policy indicates the latest revision.
17. Contact
Questions regarding this Privacy Policy or our processing of personal data may be sent to:
Klyro (ZXNET SOLUTIONS SAS)
Email: contact@withklyro.com
If you believe your personal data has been processed in violation of applicable law, you may also contact the competent data protection authority in your jurisdiction.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.