Legal
Privacy Notice
Klimra provides software services to travel agencies and travel management companies. This notice explains how we handle personal data when you visit our website, communicate with us, or use Klimra through an organization that is our customer.
Last updated20 August 2026
1. Who we are
Klimra AB is a company registered in Sweden.
- Company registration number: 559490-0986
- VAT number: SE559490098601
- Address: Norrtullsgatan 2, 113 29 Stockholm, Sweden
- Email: contact@klimra.com
- Website: klimra.com
Klimra AB is the controller for the personal data we use for our own business purposes, such as managing our website, customer relationships, accounts, security, and support.
When we process information in a customer's connected systems solely to provide the Klimra service, the customer normally determines the purposes of the processing and is the controller. Klimra acts as the customer's processor under the customer agreement and data processing agreement.
2. Personal data we process
Depending on how you interact with Klimra, we may process:
- Business and contact information, such as your name, work email address, employer, role, and information you provide when requesting a demo, contacting us, or receiving support.
- Account and security information, such as organization and account identifiers, sign-in and authorization records, access rights, security events, device and browser information, IP address, and service activity.
- Customer Content, when an organization enables connected service features. This may include business communications, participants, message and mailbox metadata, attachments, drafts, workflow information, and related context made available through connected services such as Microsoft 365.
- Commercial and administrative information, such as customer contacts, agreement and billing details, and records needed to administer the business relationship.
We receive this information from you, from the organization through which you use Klimra, from services that organization chooses to connect, and from your use of Klimra.
Providing business contact information is generally optional, but we may be unable to respond to an enquiry without it. The account and authorization information requested during onboarding is needed to provide secure access to the service.
3. How we use personal data
We process personal data for the following purposes:
- Respond to enquiries, arrange demonstrations, and manage customer relationships.
- Our legitimate interests in communicating with prospective and current business customers and providing support.
- Create and administer accounts and provide the service.
- Performance of a contract where the individual is a party; otherwise our legitimate interests in delivering and administering the service for the customer organization.
- Authenticate users, manage permissions, protect the service, and investigate security or operational issues.
- Our legitimate interests in operating a reliable and secure business service.
- Meet accounting, regulatory, legal, and dispute-resolution requirements.
- Compliance with legal obligations and our legitimate interests in establishing, exercising, or defending legal claims.
- Send relevant business communications.
- Our legitimate interests in communicating about our services, or consent where consent is required.
When Klimra processes Customer Content as a processor, the customer is responsible for identifying the applicable legal basis and providing required information to the people whose data is included. Klimra processes that content only on the customer's documented instructions and as necessary to provide, secure, and support the agreed service.
4. Connected services and AI-assisted features
The customer chooses which systems, users, and business workspaces are connected to Klimra. We use information from those connections only to provide the features the customer has enabled.
Some Klimra features use automated processing, including artificial intelligence, to help organize work, summarize information, or prepare suggested content. These features support the customer's authorized users; they are not used by Klimra to make decisions about individuals that produce legal or similarly significant effects. Customer Content is not sold or used for advertising.
Klimra personnel access Customer Content only where necessary to provide authorized support, protect the service, meet legal obligations, or otherwise act on the customer's documented instructions. Access is subject to confidentiality and access controls.
5. Who we share personal data with
We may share personal data with:
- the customer organization and its authorized administrators and users;
- service providers supporting hosting, infrastructure, authentication, security, communications, scheduling, and customer support;
- connected-service providers, such as Microsoft, when the customer chooses to use the relevant integration;
- professional advisers, auditors, insurers, authorities, or courts where reasonably necessary; and
- a buyer or successor in connection with a merger, financing, reorganization, or sale, subject to appropriate confidentiality and data-protection safeguards.
Our service providers may process personal data only for the agreed purposes and under appropriate contractual protections. Information about subprocessors used for Customer Content is provided to customers in accordance with the data processing agreement.
If you choose to use an external booking or other third-party link, that provider may also process information under its own privacy notice. Klimra receives the information you choose to submit to us through that service.
6. International transfers
Where personal data is transferred outside the European Economic Area, we use a lawful transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses, and apply supplementary safeguards where required.
7. Retention and deletion
We keep personal data only for as long as it is needed for the relevant purpose:
- Customer Content is retained according to the customer's instructions, configured retention, and the customer agreement. When the service ends, it is returned or deleted as agreed, subject to limited backup cycles and legal requirements.
- Account, security, and operational records are kept for limited periods based on the need to provide the service, protect accounts, investigate incidents, and maintain appropriate audit evidence.
- Enquiry, support, and customer relationship records are kept while the matter or business relationship is active and for a reasonable follow-up period.
- Agreement, billing, and legal records are kept for the periods required by applicable accounting, tax, limitation, and other laws.
When information is no longer required, we delete or anonymize it. Data in encrypted backups is removed through the applicable backup-expiry process and is not returned to ordinary service use.
8. Security
We use appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure. These measures include access controls, encryption, environment separation, logging, and procedures for managing vulnerabilities and incidents. No method of processing is entirely risk-free, and we review our safeguards as the service evolves.
9. Your rights
Depending on the circumstances, you may have the right to request access, correction, deletion, restriction, or portability of your personal data, and to object to certain processing. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing. You may opt out of direct marketing at any time by using the unsubscribe method provided or by contacting us.
To exercise your rights in relation to data for which Klimra is the controller, contact contact@klimra.com. We may need to verify your identity before completing a request.
For Customer Content processed on behalf of a Klimra customer, please contact the organization through which you use Klimra or with which you communicated. We will assist the customer in responding where required.
You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se or with the data-protection authority where you live or work.
10. Cookies
We use cookies and similar technologies where necessary for sign-in, security, language preferences, and operation of the service. If we introduce non-essential analytics or marketing technologies that require consent, we will provide relevant information and request consent before using them.
11. Changes to this notice
We may update this notice when our services, providers, or legal obligations change. We will post the current version on our website and update the date above. If a change materially affects how we handle personal data, we will provide additional notice where appropriate.
12. Contact
Questions about this notice or Klimra's handling of personal data can be sent to:
Klimra ABNorrtullsgatan 2113 29 Stockholm, Swedencontact@klimra.com