Legal
Privacy Policy
Last updated: March 27, 2026
1. Introduction
This Privacy Policy describes how LB FRAME ("we," "us," or "our"), a simplified joint-stock company (SASU) incorporated in Salon-de-Provence, France, collects, uses, and protects your personal data when you use Klozeo — the API-first lead management platform (the "Service").
This policy is written in compliance with the General Data Protection Regulation (GDPR), the French Data Protection Act (loi Informatique et Libertés), and other applicable data protection laws.
Our dual role under GDPR
Data Controller — we determine how and why your account, billing, and usage data are processed.
Data Processor — for the lead data you upload to Klozeo, you remain the Data Controller. We process that data exclusively on your behalf and according to your instructions.
2. What personal data we collect
2.1 Account data
When you create an account, we collect:
- Email address
- Name (if provided)
- Authentication credentials (stored as secure hashes — never in plain text)
- Profile information
2.2 Lead data (your content)
You control what lead data you store. This data belongs entirely to you. Typical fields include:
- Business names and contact information
- Addresses and geographic location data
- Phone numbers and email addresses
- Website URLs and social media links
- Business categories and custom attributes
- Notes and scoring metadata
2.3 Usage and analytics data
We collect anonymized analytics data to understand how the Service is used and improve it. See Section 6 — Analytics & Tracking for full details on the tools we use and the data they collect.
2.4 API usage data
When you use the Klozeo API, we log request metadata (endpoint, timestamp, HTTP status, rate-limit counters) to enforce plan limits and ensure service stability. This data does not include request payloads.
2.5 Payment data
Payments are processed by Stripe, Inc. We never store credit card numbers or full payment details. We retain only a Stripe customer ID and subscription status. See Stripe's Privacy Policy for details.
3. How we use your personal data
3.1 Your lead data
- We do not sell your data
- We do not share your data with third parties for their marketing or advertising purposes
- We do not use your data to train AI or machine-learning models
- We do not access your lead data except when strictly required to provide technical support at your request
3.2 Account and operational data
We use account and operational data to:
- Provision, operate, and maintain the Service
- Process payments and send billing-related communications
- Send transactional emails (password resets, security alerts, plan changes)
- Respond to support requests
- Monitor service health, detect abuse, and prevent fraud
- Comply with legal and regulatory obligations
4. Your rights
As a user of Klozeo, you have meaningful rights over your personal data. We are committed to honoring them promptly.
4.1 Rights for EU/EEA residents (GDPR)
- Right to access — obtain a copy of the personal data we hold about you
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure — request deletion of your personal data ("right to be forgotten")
- Right to restrict processing — limit how we use your data in specific circumstances
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés)
4.2 Access and export
You can access and export your lead data at any time using the built-in export features (CSV, JSON, XLSX).
4.3 Account deletion
You can delete your account and all associated data via the Service settings, or by contacting us through our contact page.
4.4 California residents (CCPA)
- Right to know what personal information is collected and how it is used
- Right to know whether your personal information is sold or disclosed (we do not sell it)
- Right to opt out of the sale of personal information
- Right to access and delete your personal information
- Right to non-discrimination for exercising your privacy rights
5. Legal basis for processing (GDPR Art. 6)
5.1 Contract performance (Art. 6(1)(b))
- Account creation and management
- Processing your lead data as instructed
- Processing payments and managing subscriptions
- Providing customer support
5.2 Legitimate interests (Art. 6(1)(f))
- Maintaining a secure and functional platform
- Analyzing anonymized usage patterns to improve the Service
- Detecting and preventing fraud or abuse
- Enforcing our Terms of Service
5.3 Legal obligation (Art. 6(1)(c))
- Tax and accounting obligations
- Responding to lawful requests from competent authorities
6. Analytics & tracking
We use two analytics tools to understand how the Service is used and to improve it. Both are configured to respect your privacy.
6.1 Umami Analytics (cookieless)
We use Umami, a privacy-first, open-source analytics platform, to measure aggregate website traffic.
- Does not use cookies or browser storage of any kind
- Does not track users across websites or sessions
- Does not collect personally identifiable information
- IP addresses are anonymized and never stored
- Collects: page views, referrer, device type, browser, anonymized country — all in aggregate
Because Umami operates without cookies and without collecting personal data, it does not require consent under the GDPR or the ePrivacy Directive.
6.2 PostHog (product analytics)
We use PostHog to understand how users interact with the Klozeo dashboard — which features are used, where friction occurs, and how to improve the product experience.
PostHog collects:
- Page views and navigation events within the dashboard
- Feature interactions (clicks, form submissions, API usage patterns)
- Session metadata (browser, OS, viewport — no screen recordings)
- A pseudonymous user identifier stored in a browser cookie
PostHog sets a first-party cookie (ph_*) in your browser to maintain session continuity. This cookie does not track you across third-party websites.
The legal basis for PostHog analytics is legitimate interest (Art. 6(1)(f) GDPR) — understanding product usage is necessary to operate and improve the Service. PostHog data is retained for 12 months.
PostHog is self-hosted on our EU infrastructure. No data is sent to PostHog Cloud servers outside the EU.
9. Data storage and security
9.1 Data location
9.2 Security measures
- Encryption in transit (HTTPS/TLS) for all data exchanges
- Encrypted storage for sensitive fields
- Access controls and API key authentication
- Regular security assessments
No method of internet transmission is 100% secure. We apply industry-standard protections but cannot guarantee absolute security.
9.3 Data retention
- Account and lead data: retained for as long as your account is active
- Lead data: permanently deleted within 30 days of account termination
- Backups: retained for up to 90 days after deletion
- Legal holds: certain data may be retained longer as required by law
10. Children's privacy
Klozeo is a professional tool intended exclusively for users aged 18 and over. We do not knowingly collect personal data from minors. If you believe a minor has created an account, please contact us and we will delete the account immediately.
11. International data transfers
Lead and account data is stored within the EU. Stripe may process payment data in the United States. Such transfers comply with applicable data protection requirements through:
- EU-US Data Privacy Framework (where applicable)
- Standard Contractual Clauses (SCCs)
- Other lawful transfer mechanisms recognised under GDPR
12. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or the tools we use. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Continued use of the Service after a policy update constitutes your acceptance of the revised policy.
13. Contact
For any questions about this Privacy Policy, to exercise your rights, or to contact our data protection team, please use our contact page.
You also have the right to lodge a complaint with the French data protection authority:
CNIL — Commission Nationale de l'Informatique et des Libertés
www.cnil.frLB FRAME
SASU — Salon-de-Provence, France