Sub-processors
Last updated: 2026-08-27
Klar is a product of AEYEON Technologies Private Limited ("AEYEON"). To operate Klar we engage a small number of third-party service providers ("sub-processors") that may process customer data on our behalf. This page lists them.
It also lists, in the two sections after that, every third party your data can reach because you asked it to — the sources you connect and the places you have Klar deliver to. Those aren't sub-processors in the strict sense; you choose them, and you can disconnect them. We list them anyway, because what matters to you is where your data goes, not which legal category it goes there under.
We aim to keep this list current. Workspace administrators are notified at least 14 days in advance of any new sub-processor or material change, giving you the opportunity to review or object on reasonable grounds before the change takes effect.
Platform sub-processors
Engaged by AEYEON to run Klar itself. These apply to every customer.
| Sub-processor | Purpose | Data location | Legal entity |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud compute (ECS), managed database (RDS Postgres), caching (ElastiCache), secrets management (KMS), and infrastructure | ap-south-1 (Mumbai), with limited us-east-1 for supporting services | Amazon Web Services, Inc. |
| Amazon SES | Transactional email delivery (account, security, digest and alert emails) | ap-south-1 / us | Amazon Web Services, Inc. |
| Cloudflare | DNS, CDN, DDoS protection, and R2 object storage (uploaded files, generated exports) | Global edge network | Cloudflare, Inc. |
| Anthropic | AI inference (Claude API) for insights, chat and auto-dashboards. Anthropic does not train models on API data; requests/responses are retained for up to 30 days for safety review, then deleted. | United States | Anthropic, PBC |
| Paddle | Merchant of Record — billing, subscription management and tax handling for customers outside India | UK / global | Paddle.com Market Ltd. |
| Razorpay | Processing your payments to AEYEON for your Klar subscription (India) | India | Razorpay Software Private Limited |
Customer-initiated connectors
These are sources a customer connects themselves. AEYEON reads from them only after the customer explicitly authorises the connection, only for the accounts or files they select, and always read-only — Klar requests no permission to create, edit or delete anything in a customer's account with these providers. A connection can be removed at any time from Data Sources, which stops all future reads.
| Provider | Connector | Data location | Legal entity |
|---|---|---|---|
| Google APIs | Google Analytics 4, Google Sheets | Customer's Google region | Google LLC |
| Microsoft Graph | OneDrive / SharePoint workbooks | Customer's Microsoft 365 region | Microsoft Corporation |
| Stripe | Payments, subscriptions and customer records | United States / customer's Stripe region | Stripe, Inc. |
| Shopify | Orders, products and customer records | Customer's Shopify region | Shopify Inc. |
| Meta | Meta Ads campaign and spend reporting | United States / customer's Meta region | Meta Platforms, Inc. |
| Klaviyo | Email and SMS campaign metrics | United States | Klaviyo, Inc. |
| Amazon Selling Partner API | Seller orders and settlement reporting | Customer's marketplace region | Amazon.com Services LLC |
| Razorpay | Reading payments and settlements from your own Razorpay merchant account (India) | India | Razorpay Software Private Limited |
| RentCast | Property listings and market statistics, under the customer's own RentCast API key and licence | United States | Fortnoff Financial LLC |
Delivery destinations
Where a customer asks Klar to send scheduled digests or alerts, the content of those messages — which includes the metrics being reported — reaches the platform they chose. The customer supplies the webhook or bot credential themselves, and can remove it at any time. Email delivery goes through Amazon SES, listed above.
| Destination | Purpose | Data location | Legal entity |
|---|---|---|---|
| Slack | Scheduled digests and alerts to a customer-supplied incoming webhook | United States / customer's Slack region | Slack Technologies, LLC (a Salesforce company) |
| Telegram | Scheduled digests and alerts via a customer-supplied bot token | Global | Telegram Messenger Inc. |
Notes
- Connected sources are copied, not just queried. For the connectors above, each scheduled refresh copies the rows you selected into Klar's own storage (AWS and Cloudflare R2, listed above), and your charts run on that copy. Deleting the dataset in Klar deletes the copy. Direct database and warehouse connections are the exception — see below.
- Your own databases and warehouses are not sub-processors. When you connect PostgreSQL, MySQL, Snowflake, BigQuery or Amazon Redshift, Klar queries your infrastructure directly at the moment a chart is rendered. That data is yours, held by you, and AEYEON engages no third party to process it.
- Public market data is one-way. Zillow Research, HUD and US Census bulk files are downloaded by AEYEON from public sources. No customer data is sent to them, so they are not sub-processors.
- OneDrive / SharePoint scopes. A first connect requests
User.ReadandFiles.Read— sign-in, and the signed-in user's own OneDrive.Sites.Read.All, for SharePoint document libraries, is requested separately and only if the customer goes looking for a site. No write permission is requested at any point. - All customer data is encrypted in transit (TLS 1.2+) and at rest. Credentials are stored in AWS Secrets Manager using KMS-wrapped envelope encryption — never in application databases.
- Customer data is never used to train any AI/ML model, ours or a provider's.
Questions about sub-processors: security@aeye-on.com