KLEVRManagement

Privacy Policy

Last updated: 29 September 2026

1. Who we are

KLEVR Management (“KLEVR”, “we”, “us”) provides tour, event and crew management on the web and in the KLEVR Management and KLEVR Chat apps. It is run by KLEVR AUDIO LLC, a limited liability company registered in Maryland, USA, 6544 S Clifton Rd, Frederick, MD 21703, USA. Email: hello@klevrmanagement.com.

Where we work. The people who run KLEVR work from Frederick (Maryland, USA), Oslo (Norway) and Buenos Aires (Argentina). Because we operate in Oslo, Norway, we are established in the EEA and the GDPR applies to us directly. Our supervisory authority is Datatilsynet, the Norwegian Data Protection Authority, so we have no separate representative under GDPR Art. 27.

2. Two roles: your team’s data and our own

Your team decides what goes into its workspace: gigs, crew lists, contact details, travel and passport details, dietary needs, files and chat. For that data the team (the band, company or organisation that runs it) is the controller, and we process it on the team’s behalf under our data processing agreement. Questions about what a team keeps about you go first to that team; we help them answer.

We decide about your account, billing, security logs, support and our own emails, and for that data we are the controller. This policy describes both.

Teams can add people who have no KLEVR account, for example crew or guests on a gig. Their data comes from the team, is used only to run the team’s gigs, and they have the same rights as below.

3. What we collect

  • Account: name, email, password (stored hashed by our log-in provider), whether you confirmed you are 16 or older, and two-factor settings if you turn them on.
  • Profile details you or your team add: phone, photo, instrument, technical and rider notes, date of birth, address, sizes, dietary needs and allergies, passport, visa and driving licence details, loyalty programme numbers and travel preferences, for tour logistics.
  • Content: events, setlists, timesheets, inventory, offers and invoices, guest lists, files, photos and chat messages.
  • Payments: plan and payment status. Card details are handled by Stripe or Apple and never reach us.
  • Device and technical data: push tokens if you allow notifications, IP address and browser or device type in security logs, and anonymous page speed metrics.

Sensitive details. Allergies and dietary needs can be health data, and passport and ID numbers need extra care. Fill them in only if your team needs them for a tour. The app shows them to your team’s admins and the people they give access to, never to other teams, and you can remove them at any time.

4. Why we use it, and on what legal basis

PurposeDataLegal basis
Your account and the service you signed up forName, email, password (hashed), profile details, team memberships, content you createContract (GDPR Art. 6(1)(b))
Subscriptions, invoices and bookkeepingTeam name, billing contact, plan, payment status (card details stay with Stripe or Apple)Contract, and legal obligation for accounting records (Art. 6(1)(b) and (c))
Service emails and notifications (invitations, changes, reminders, security)Name, email, push tokens, notification settingsContract (Art. 6(1)(b))
News about KLEVR ManagementName, emailYour consent, or for paying customers our legitimate interest in telling them about similar features. You can unsubscribe at any time.
Security, abuse prevention and fixing faultsLog-in events, IP address, device and browser type, audit trail of changes, error reportsLegitimate interest in keeping the service and your data safe (Art. 6(1)(f))
Performance measurement of the websiteAnonymous page speed metrics (Vercel Speed Insights, no cookies, no identifiers)Legitimate interest in a fast service (Art. 6(1)(f))
Handling reports, legal requests and disputesWhat the report or request contains, and correspondenceLegal obligation and legitimate interest (Art. 6(1)(c) and (f))

We do not sell personal data, share it for advertising, or use it to make automated decisions about you. You don’t have to give us more than your name and email; without those we can’t give you an account.

5. AI document import

If your team has the AI import add-on and you choose to import a run plan, a tour schedule or a flight ticket, that document is sent to Anthropic’s Claude API so it can be read and turned into fields for you to check. Nothing else in KLEVR is sent to an AI service. Anthropic processes it on our behalf, does not use it to train models, and keeps it only briefly under its commercial terms. What the AI reads is always shown to you to review before anything is saved.

6. Who can see your data

Other members of your team see what their role allows (an admin sees crew details; an artist sees the gigs they’re on). People outside the team see only what the team shares with them on purpose, such as a tour share link or a client portal. We share data with these service providers, only as needed to run the service, under contracts that bind them to protect it:

  • Supabase: Database, log-in and file storage (EU (Ireland))
  • Vercel: Hosting of the website and app, page speed metrics (EU (Dublin) and USA)
  • Resend: Sending email (USA)
  • Stripe: Web payments (USA and EU)
  • Apple: In-app purchases, push notifications to iPhones (USA)
  • Google: Push notifications to Android, venue address search (Places) (USA and EU)
  • Browser push services (Apple, Google, Mozilla, Microsoft): Push notifications in the browser (USA and EU)
  • Anthropic: Reads documents you choose to import with AI (see below) (USA)
  • AeroDataBox (via RapidAPI): Flight times from a flight number and date only (EU and USA)
  • Monday.com, PowerOffice, Tripletex: Only if your team connects them: event and invoice data your team sends there (EU and USA)
  • Spotify: Importing a playlist into your song list (no personal data sent) (EU)

We may also disclose data where the law requires it, for example to a court or an authority with a valid order.

7. Transfers outside the EEA

Our database and files are stored in the EU. KLEVR AUDIO LLC is a US company, the people who support the service also work from the USA and Argentina, and some providers above are in the USA. Where data is reached from outside the EEA, it is protected by the EU Standard Contractual Clauses, by the provider’s certification under the EU-US Data Privacy Framework, or for Argentina by the EU’s adequacy decision. You can ask us for a copy of the safeguards.

8. How long we keep it

  • Account and profile: as long as your account exists.
  • Team data: as long as the team uses KLEVR, and deleted within 30 days after the team ends (see the DPA).
  • Security audit trail: 12 months.
  • Accounting records: as long as tax law requires (usually 5 to 10 years).
  • Backups: overwritten on a rolling 7-day cycle.

You can delete your account at any time under My Profile → Delete account in the app, or through the deletion page. Records that belong to a team (for example past gigs or settlements) may stay with that team with your contact details removed.

9. Your rights

You can ask us to:

  • see the data we hold about you, and get a copy of it;
  • receive it in a machine-readable file to take elsewhere (My Profile → Your data → Download my data);
  • correct it, or delete it;
  • restrict how we use it, or object to our use of it;
  • stop news emails at any time (link in every email, or My Profile → Notifications);
  • withdraw a consent you gave, without affecting earlier use.

Email hello@klevrmanagement.com and we answer within one month. If you think we handle your data wrongly, you can complain to a data protection authority, in Norway Datatilsynet, or the authority where you live or work.

California residents: we do not sell or share personal information, and the rights above are open to you too.

10. Cookies and storage on your device

We use only what the service needs: a log-in cookie, your settings, and a copy of recent data so the app opens fast. A link with a discount code stores that code for 90 days so the discount applies. We use no advertising or tracking cookies, and we do not track you across other websites or respond to “Do Not Track” signals, since there is nothing to switch off. Details are on the cookies page.

11. Security

Data is encrypted in transit and at rest, access is limited by role and by team, and two-factor sign-in is available. The security page describes the measures. If a breach puts your data at risk, we tell you and the authorities as the law requires.

12. Children

KLEVR is for professional use and for people aged 16 or older. Everyone confirms their age when they sign up. If we learn that a child under 16 has an account, we delete it.

13. Changes

We update this policy when the service or the law changes. The date at the top shows the latest version, and we tell you by email or in the app about changes that matter.

14. Contact

Questions about this policy or your data: hello@klevrmanagement.com, or by post to KLEVR AUDIO LLC, 6544 S Clifton Rd, Frederick, MD 21703, USA.