Privacy Policy
Last updated: 29 September 2026
1. Who we are
KLEVR Management (“KLEVR”, “we”, “us”) provides tour, event and crew management on the web and in the KLEVR Management and KLEVR Chat apps. It is run by KLEVR AUDIO LLC, a limited liability company registered in Maryland, USA, 6544 S Clifton Rd, Frederick, MD 21703, USA. Email: hello@klevrmanagement.com.
Where we work. The people who run KLEVR work from Frederick (Maryland, USA), Oslo (Norway) and Buenos Aires (Argentina). Because we operate in Oslo, Norway, we are established in the EEA and the GDPR applies to us directly. Our supervisory authority is Datatilsynet, the Norwegian Data Protection Authority, so we have no separate representative under GDPR Art. 27.
2. Two roles: your team’s data and our own
Your team decides what goes into its workspace: gigs, crew lists, contact details, travel and passport details, dietary needs, files and chat. For that data the team (the band, company or organisation that runs it) is the controller, and we process it on the team’s behalf under our data processing agreement. Questions about what a team keeps about you go first to that team; we help them answer.
We decide about your account, billing, security logs, support and our own emails, and for that data we are the controller. This policy describes both.
Teams can add people who have no KLEVR account, for example crew or guests on a gig. Their data comes from the team, is used only to run the team’s gigs, and they have the same rights as below.
3. What we collect
- Account: name, email, password (stored hashed by our log-in provider), whether you confirmed you are 16 or older, and two-factor settings if you turn them on.
- Profile details you or your team add: phone, photo, instrument, technical and rider notes, date of birth, address, sizes, dietary needs and allergies, passport, visa and driving licence details, loyalty programme numbers and travel preferences, for tour logistics.
- Content: events, setlists, timesheets, inventory, offers and invoices, guest lists, files, photos and chat messages.
- Payments: plan and payment status. Card details are handled by Stripe or Apple and never reach us.
- Device and technical data: push tokens if you allow notifications, IP address and browser or device type in security logs, and anonymous page speed metrics.
Sensitive details. Allergies and dietary needs can be health data, and passport and ID numbers need extra care. Fill them in only if your team needs them for a tour. The app shows them to your team’s admins and the people they give access to, never to other teams, and you can remove them at any time.
4. Why we use it, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Your account and the service you signed up for | Name, email, password (hashed), profile details, team memberships, content you create | Contract (GDPR Art. 6(1)(b)) |
| Subscriptions, invoices and bookkeeping | Team name, billing contact, plan, payment status (card details stay with Stripe or Apple) | Contract, and legal obligation for accounting records (Art. 6(1)(b) and (c)) |
| Service emails and notifications (invitations, changes, reminders, security) | Name, email, push tokens, notification settings | Contract (Art. 6(1)(b)) |
| News about KLEVR Management | Name, email | Your consent, or for paying customers our legitimate interest in telling them about similar features. You can unsubscribe at any time. |
| Security, abuse prevention and fixing faults | Log-in events, IP address, device and browser type, audit trail of changes, error reports | Legitimate interest in keeping the service and your data safe (Art. 6(1)(f)) |
| Performance measurement of the website | Anonymous page speed metrics (Vercel Speed Insights, no cookies, no identifiers) | Legitimate interest in a fast service (Art. 6(1)(f)) |
| Handling reports, legal requests and disputes | What the report or request contains, and correspondence | Legal obligation and legitimate interest (Art. 6(1)(c) and (f)) |
We do not sell personal data, share it for advertising, or use it to make automated decisions about you. You don’t have to give us more than your name and email; without those we can’t give you an account.
5. AI document import
If your team has the AI import add-on and you choose to import a run plan, a tour schedule or a flight ticket, that document is sent to Anthropic’s Claude API so it can be read and turned into fields for you to check. Nothing else in KLEVR is sent to an AI service. Anthropic processes it on our behalf, does not use it to train models, and keeps it only briefly under its commercial terms. What the AI reads is always shown to you to review before anything is saved.
6. Who can see your data
Other members of your team see what their role allows (an admin sees crew details; an artist sees the gigs they’re on). People outside the team see only what the team shares with them on purpose, such as a tour share link or a client portal. We share data with these service providers, only as needed to run the service, under contracts that bind them to protect it:
- Supabase: Database, log-in and file storage (EU (Ireland))
- Vercel: Hosting of the website and app, page speed metrics (EU (Dublin) and USA)
- Resend: Sending email (USA)
- Stripe: Web payments (USA and EU)
- Apple: In-app purchases, push notifications to iPhones (USA)
- Google: Push notifications to Android, venue address search (Places) (USA and EU)
- Browser push services (Apple, Google, Mozilla, Microsoft): Push notifications in the browser (USA and EU)
- Anthropic: Reads documents you choose to import with AI (see below) (USA)
- AeroDataBox (via RapidAPI): Flight times from a flight number and date only (EU and USA)
- Monday.com, PowerOffice, Tripletex: Only if your team connects them: event and invoice data your team sends there (EU and USA)
- Spotify: Importing a playlist into your song list (no personal data sent) (EU)
We may also disclose data where the law requires it, for example to a court or an authority with a valid order.
7. Transfers outside the EEA
8. How long we keep it
- Account and profile: as long as your account exists.
- Team data: as long as the team uses KLEVR, and deleted within 30 days after the team ends (see the DPA).
- Security audit trail: 12 months.
- Accounting records: as long as tax law requires (usually 5 to 10 years).
- Backups: overwritten on a rolling 7-day cycle.
You can delete your account at any time under My Profile → Delete account in the app, or through the deletion page. Records that belong to a team (for example past gigs or settlements) may stay with that team with your contact details removed.
9. Your rights
You can ask us to:
- see the data we hold about you, and get a copy of it;
- receive it in a machine-readable file to take elsewhere (My Profile → Your data → Download my data);
- correct it, or delete it;
- restrict how we use it, or object to our use of it;
- stop news emails at any time (link in every email, or My Profile → Notifications);
- withdraw a consent you gave, without affecting earlier use.
Email hello@klevrmanagement.com and we answer within one month. If you think we handle your data wrongly, you can complain to a data protection authority, in Norway Datatilsynet, or the authority where you live or work.
California residents: we do not sell or share personal information, and the rights above are open to you too.