Privacy Policy
How Kleos collects, uses, shares, and protects personal data across the Kleos websites, pre-launch signups, partner accounts, prospect research, AI voice calling, appointment booking, calendar integrations, billing, emails, and the Kleos AI coach.
Who we are
Kleos operates kleos.click, kleosleads.com, and a compliance-first AI sales operations platform for appointment-driven businesses. The platform helps partners research relevant prospects, prepare approved scripts, run gated AI voice outreach where permitted, book appointments, send notifications, review transcripts and outcomes, and use Kleos AI for sales coaching and operational analysis.
For our own websites, accounts, pre-launch signups, billing, support, security, and Kleos acquisition activity, Kleos acts as the controller of the personal data we process. For a partner's prospect, customer, campaign, and appointment data, Kleos normally acts as a processor acting on the partner's documented instructions. The Data Processing Addendum applies to that processor relationship.
Personal data we collect or process
- Website and pre-launch data: name, email address, country, consent choices, signup source, unsubscribe status, launch-invite status, IP-derived country where available, and anti-abuse challenge results.
- Partner account data: partner name, business name, legal name where provided, website, work email, phone, role, region, timezone, authentication identifiers, approval status, onboarding answers, and support messages.
- Team onboarding data: employment profile, assigned venture and commission terms, the reviewed agreement version and document hash, typed signer name, electronic-signature intent, acceptance timestamp, encrypted beneficiary address and payout/tax details, masked account and tax-identifier endings, tax-form classification, administrator verification status, and reveal/review audit evidence.
- Prospect and customer records: names, company names, business contact details, phone numbers, email addresses, websites, addresses, service-area data, customer status, campaign fit, public-source signals, imported CRM/list fields, and provenance showing where the data came from.
- Research and scoring data: research runs, public business-listing results, website signals, fit scores, reasons to call, call-preparation briefs, script recommendations, confidence scores, and review decisions.
- Consent, suppression, and compliance data: consent text, consent source, consent timestamp, consent channel, revocation records, do-not-call and opt-out records, calling-window checks, country rule-pack decisions, AI-disclosure rules, and audit logs.
- Call data: call ID, direction, status, calling number, called number, date, time, duration, provider event data, disposition, outcome, appointment link, call summary, transcript, redaction status, and recording reference only if recording is enabled with the required notice and approval.
- Booking and calendar data: connected-calendar account identifier, encrypted OAuth tokens, chosen calendar ID, free/busy availability blocks, appointment title, appointment time, timezone, location or meeting link, event description, attendees we add to the event, reminders, reschedule/cancel data, and calendar event IDs.
- Messages and notifications: emails, SMS notifications where enabled, booking confirmations, reminders, unsubscribe events, delivery logs, and limited message metadata needed for delivery and compliance.
- Billing and usage data: plan, subscription status, credit usage, call minutes, research credits, invoices, Stripe customer and subscription IDs, and payment status. Payment card details are processed by Stripe and are not stored by Kleos.
- Kleos AI conversations and outputs: chat messages, strategy briefs, script drafts, coach answers, model-memory candidates, learning insights, experiment results, and review decisions.
- Website chat data: the first name you enter, your messages and the assistant's replies, the page you started from, your browser language and user-agent, an approximate country and city, a shortened IP address, an IP hash used for rate limiting, and, only if you book a call, your email address and company name.
- Security and device data: log data, IP address, browser or device information, authentication events, rate-limit events, audit records, and abuse-prevention signals.
How we use personal data
- Provide and operate Kleos, including account access, dashboards, research, scoring, campaign preparation, call readiness, approved voice outreach, appointment booking, reminders, transcripts, summaries, reports, billing, support, and security.
- Run compliance gates before external actions, including consent verification, suppression screening, global no-call checks, country and state rule checks, calling-window checks, caller-ID checks, recording settings, AI-disclosure rules, and campaign approval.
- Create partner-branded call scripts, objection paths, follow-up notes, closer handoff notes, and coaching based on partner instructions, approved playbooks, and reviewed outcomes.
- Send service emails, booking confirmations, account emails, invoices, pre-launch confirmation emails, launch invitations, and marketing updates where the recipient has consented or where another lawful basis applies.
- Prevent abuse, fraud, spam, unauthorized access, scraping, and attempts to bypass consent, suppression, calendar, billing, or compliance controls.
- Administer team agreements and manual contractor payouts, including recording electronic acceptance, reviewing official tax-form and beneficiary evidence, blocking payout approval until the current terms and profile are verified, and retaining the accounting and audit evidence required for disputes or legal obligations.
- Improve Kleos through reviewed learning loops. Call outcomes, transcripts, script performance, and research quality may generate recommendations or training candidates, but production behavior does not silently change. Training candidates are scoped, redacted where appropriate, reviewed, and approved for the exact use before use.
- Comply with legal, regulatory, tax, accounting, security, and dispute-resolution obligations.
Google Calendar, Gmail delivery, and Google API Limited Use
Kleos offers an optional Google Calendar integration so a partner or closer can connect their own Google account and let Kleos check availability and write booked appointments. Kleos requests Google Calendar OAuth access only when an authorized user starts the Google connection flow.
The Google Calendar OAuth scopes are calendar.readonly and calendar.events. Kleos uses calendar.readonly to list the connected account's calendars and query free/busy availability windows for scheduling. Kleos uses calendar.events to create Kleos-booked appointment events in the selected calendar. Kleos does not use Google Calendar data to read event content for prospecting, advertising, sales targeting, or unrelated analytics.
A Zavelora closer may separately connect Gmail invoice delivery. That flow adds gmail.send only so an approved invoice can be sent from the assigned closer's exact Google account with the private PDF attached. It does not request Gmail inbox or message read access. Kleos stores the sender and recipient addresses, frozen CC/BCC lists, delivery attempt status, Gmail message and thread identifiers, errors, timestamps, and invoice evidence needed for CRM, audit, accounting, and duplicate-send prevention.
Kleos stores the connected Google account identifier, the selected calendar ID, encrypted OAuth access and refresh tokens, free/busy blocks returned for scheduling checks, and the Google event ID for appointments Kleos creates. Access tokens and refresh tokens are encrypted at rest and are used only to provide the calendar and send-only invoice features the connected user enabled.
Kleos's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Kleos does not sell Google user data, use Google user data for targeted advertising, retargeting, interest-based advertising, credit-worthiness, lending, data-broker activity, information-reseller activity, or training generalized AI or machine-learning models. Humans do not review Google Calendar data unless the user authorizes support access for a specific issue, access is necessary for security or abuse investigation, or access is required by law.
A user may revoke Google access from their Google Account permissions page or by disconnecting the integration in Kleos when that control is available. After revocation, Kleos stops using the tokens and may retain minimal records such as appointment IDs, invoice delivery evidence, audit logs, and suppression/compliance records where needed to operate the service or meet legal obligations.
Website support chat
Kleos runs an AI chat assistant on its public websites. It is an AI, not a person, and it says so if you ask. It can answer questions about Kleos and book a strategy call with a human.
When you use the chat, Kleos processes the first name you enter to start the conversation, the messages you send and the replies you receive, the page you started from, your browser's language and user-agent string, an approximate country and city derived from your IP address, a shortened form of your IP address, and a one-way hash of your IP address used for rate limiting and abuse prevention. Kleos does not store your full IP address against the conversation. If you choose to book a call, the chat also collects your email address and company name at that point, and not before.
If you send a link to a website, Kleos fetches that single public page from its own servers so the assistant can answer questions about it. Kleos reads only the one page you send, does not sign in to anything, and does not crawl the rest of the site. Public email addresses found on that page are stripped before the content reaches the assistant.
Conversations are stored so support staff can follow up, review quality, and handle abuse, and are retained in line with the Retention and deletion section below. The assistant is provided using an AI model provider acting as a subprocessor under the categories described in the Data Processing Addendum. You can end a conversation at any time, and you can make a privacy request using the contacts at the end of this policy.
The chat stores a small amount of data in your browser so a conversation survives while you move between pages. That storage is described in the Cookie Notice.
Lawful bases, consent, and outreach control
Kleos processes personal data under the lawful bases that fit the context, including performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is required. For partner prospect and customer data, the partner determines the lawful basis and instructs Kleos through the service.
Outbound AI voice is allowed only when the contact, campaign, region, and call type pass the applicable Kleos gates. Research and enrichment never create calling permission by themselves. Consent wording, source, timestamp, channel, and revocation history are recorded where consent is used. If a person opts out, objects, or asks not to be contacted, Kleos records the suppression so future outreach can be blocked.
Sharing and subprocessors
Kleos does not sell personal data. Kleos shares personal data only as needed to provide, secure, support, and improve the service, or as required by law. Categories of recipients include infrastructure and database providers, authentication providers, AI and voice providers, telephony providers, calendar providers, email providers, payment processors, analytics and security providers where enabled, professional advisors, and authorities where required.
When Kleos acts as a processor for a partner, subprocessors are used under the Data Processing Addendum. The subprocessor categories are described in the DPA, and the current list of named providers is available to partners on request.
International transfers
Kleos may process data in countries other than the country where a user or contact is located. Where required, Kleos uses appropriate transfer safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, data minimization, access controls, and subprocessor diligence.
Retention and deletion
Kleos keeps personal data only for as long as needed to provide the service, follow partner instructions, maintain security, comply with law, resolve disputes, enforce agreements, and preserve required outreach records. Retention differs by data type. Account, billing, support, security, audit, campaign, call, consent, and telemarketing records may be retained for the period required by applicable law or operational need. Under the current Telemarketing Sales Rule recordkeeping rule, many US telemarketing records must be kept for five years.
Team agreement acceptances, beneficiary verification evidence, payout references, and related audit records may be retained for contract, tax, accounting, fraud-prevention, and dispute purposes after a team relationship ends. Full beneficiary payout and tax values are application-encrypted; ordinary operational reads expose only masked metadata, and sensitive administrator reveal is separately authenticated and audited.
Transcripts, summaries, audit events, and other PII-bearing records can be subject to configurable retention windows. Suppression and opt-out records are retained as needed so Kleos can continue honoring do-not-contact requests. When a deletion request is valid, Kleos deletes or redacts eligible personal data and may keep minimal records necessary for suppression, legal, accounting, security, or dispute purposes.
For verified Zavelora requests, the administrator tool deletes or anonymizes eligible intake, research, CRM, contact, call, meeting, preview, and production evidence without contacting an external provider automatically. It preserves hashed request evidence and minimum suppression records, applies financial-record retention only under an enabled and reviewed controller policy, and keeps the request open until any documented provider-side deletion or exception is resolved.
Your rights
Depending on your location and relationship with Kleos, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent where processing is based on consent. You may also object to direct marketing at any time. If you are a prospect or customer of a Kleos partner, the partner is usually the controller for that data and should receive your request first; Kleos will assist the partner as processor. To make a request directly to Kleos, email privacy@kleos.click or dpo@kleos.click.
Security
Kleos uses tenant isolation, row-level security, least-privilege access, encrypted transport, application encryption for sensitive calendar tokens and team beneficiary details at rest, service-role separation, audit logging, AAL2 checks for sensitive beneficiary reveal and review, admin approval gates, public rate limits, anti-abuse checks, and safe-by-default controls for external actions. No security program can guarantee absolute protection, but Kleos designs the product so risky actions require explicit configuration and review.
Children
Kleos is built for businesses and is not directed to children. Users must be at least 18 years old or the age of majority in their location, whichever is higher. Kleos does not knowingly collect personal data from children.
Changes
Kleos may update this Privacy Policy when our services, integrations, or data practices change. If a change materially affects how Google user data or other personal data is used, Kleos will update this page and provide notice or obtain consent where required before using the data in the new way.
Contact
Privacy requests: privacy@kleos.click. Data protection contact: dpo@kleos.click. Security reports: security@kleos.click. General legal contact: legal@kleos.click.