Privacy Notice
Last updated: 24 July 2026 | Version: 2026-07-24
1. Identity and scope
This Privacy Notice explains how K LIFE LIMITED, trading as KLAP.life, company number 14434391, registered office at 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ (“KLAP”, “we”, “us”, “our”), collects and uses personal data through KLAP.life, white-label pages and widgets, mobile pages, business dashboards, APIs, ticketing, bookings, subscriptions, payments, CRM, PMS, analytics, email, WhatsApp Business Platform, AEO/GEO and AI-assisted services.
It applies to visitors, account holders, ticket purchasers, members, guests, business customers, promoters, organisers, staff, suppliers and people who receive communications through the Services.
2. Who is the controller?
KLAP is controller for data used for its own purposes, including platform accounts, marketplace operation, security, billing, fraud prevention, support, legal compliance, service analytics and product administration.
Where an Organiser, venue, brand or other Business Customer decides why and how customer data is used for its event, booking, CRM or campaign, that Business Customer is normally the controller and KLAP acts as its processor/service provider. You should also read that Business Customer’s privacy notice. KLAP and the Business Customer may each be independent controllers for different purposes.
3. Personal data we collect
- Identity and account data: name, username, account ID, role, organisation, authentication information and account preferences.
- Contact data: email address, telephone/WhatsApp number, country, city, postal or billing details where required.
- Transaction and service data: bookings, tickets, subscriptions, memberships, orders, attendance or scan status, refunds, disputes, invoices, payment status, payment-provider and mandate identifiers. Payment providers normally process full card or bank details.
- Business and content data: events, venues, products, customer lists, campaigns, templates, uploaded files, images, messages, support requests and instructions.
- WhatsApp and Meta data: WhatsApp Business Account and phone-number identifiers, Meta business identifiers, permissions, access-token metadata, message templates, opt-in evidence, recipient numbers, delivery/read/failure events, conversation and message metadata and, where needed to provide the service, message content and attachments. Secrets are restricted and should be encrypted at rest.
- Technical and usage data: IP address, device, browser, operating system, language, approximate location derived from IP, login and security logs, cookie or similar identifiers, referral URLs, campaign parameters, pages viewed and interactions.
- Consent and preference data: Terms version, privacy notice version, timestamp, source, IP, user agent, marketing choices, withdrawals, suppressions and complaint history.
- Analytics and inferred data: aggregated performance, conversion, attribution and recommendations generated from service activity. We distinguish observed data, external verified data, model estimates and AI recommendations where relevant.
4. How data is collected
We collect data directly from you, from a Business Customer acting for an event or campaign, through checkouts and widgets, from connected Meta/WhatsApp and payment accounts, from service providers, from public or lawfully licensed sources, and automatically through logs, cookies and similar technologies.
5. Purposes and legal bases
- Contract: create accounts, process bookings, tickets, payments and subscriptions, deliver messages requested by a Business Customer, provide support and operate the Services.
- Legal obligation: accounting, tax, payment, consumer, fraud, sanctions, law-enforcement and regulatory requirements.
- Legitimate interests: secure and improve the platform, prevent abuse, measure performance, maintain records, defend claims and communicate with business contacts, provided those interests are not overridden by your rights.
- Consent: optional email or WhatsApp marketing, non-essential cookies, certain advertising/analytics uses and any processing that legally requires consent. Consent may be withdrawn at any time without affecting prior lawful processing.
- Vital interests or public task: only in exceptional circumstances permitted by law, such as an urgent safety request.
6. WhatsApp communications and opt-in
Businesses are required to obtain valid opt-in before sending WhatsApp marketing messages. Opt-in must identify the business, the WhatsApp channel and the categories or purposes of messages. A number supplied for a booking or support request is not automatically a marketing opt-in. Marketing consent is separate from Terms acceptance and is not required to purchase.
You can withdraw WhatsApp marketing consent at any time by replying with a clear opt-out word such as STOP, UNSUBSCRIBE, CANCEL, END, QUIT, BAJA, SALIR, ANNULLA or DISISCRIVI, by blocking the sender in WhatsApp, or by using our unsubscribe page. We keep a suppression record so that marketing does not restart accidentally. Separate service messages may still be used to deliver purchased tickets, QR or access credentials, booking or reservation confirmations, payment and security updates, event changes and support requested by you, where lawful and necessary to provide the service.
WhatsApp and Meta process data under their own terms and privacy notices. Messages sent through the WhatsApp Business Platform are not the same as private consumer-to-consumer chats, and businesses and their service providers may access message content as required to provide the business service.
7. Email marketing
We send optional email marketing only where consent or a valid legal exception applies. Every commercial email must identify the sender and provide a working unsubscribe method. You may opt out through the message link or unsubscribe page. We may retain a minimal suppression record to honour your choice.
8. Cookies, analytics and advertising
Strictly necessary technologies support login, security, cart, checkout and user preferences. Non-essential analytics, advertising, remarketing, Meta Pixel/Conversions API, Google Analytics, LinkedIn or similar technologies are used only where permitted and, where required, after consent through the cookie controls. Browser signals such as Global Privacy Control are honoured where legally required and technically applicable.
Further operational details, categories and controls should be shown in the cookie banner or cookie settings. Blocking necessary cookies may prevent essential features from working.
9. Sharing and recipients
We may disclose relevant data to: the Organiser, venue, brand or Business Customer responsible for your booking or campaign; authorised staff and scan operators; payment providers such as Stripe, PayPal, SumUp and GoCardless; Meta/WhatsApp; hosting, database, communications, email, analytics, security, support and professional-service providers; tax, regulatory, judicial and law-enforcement authorities where legally required; and a buyer, investor or successor in a genuine corporate transaction subject to appropriate safeguards.
We do not sell personal data for money. Some advertising or analytics disclosures may be treated as “sharing” under certain US state laws. Where those laws apply, required notice, consent, opt-out and Global Privacy Control mechanisms will be provided.
10. Business Customer data and processor terms
When KLAP acts as processor/service provider, it processes personal data only on documented instructions, applies confidentiality and security controls, assists with rights and breaches as required, controls subprocessors, and deletes or returns data at the end of the service subject to lawful retention. A separate data-processing agreement may apply to business accounts and should be executed where required.
11. International transfers
Data may be processed in the United Kingdom, European Economic Area, United States, Mexico or other countries where KLAP, a Business Customer or an approved provider operates. Where required, transfers are protected through an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, binding contractual protections and supplementary security measures. You may request information about applicable safeguards.
12. Security
We use organisational and technical measures proportionate to risk, including access controls, least privilege, encryption or hashing where appropriate, logging, backups, segregation of business data, secure development practices, incident handling and restricted access to Meta/WhatsApp credentials. No system is completely secure. Business Customers must protect their own accounts, devices, tokens, exports and authorised users.
13. Retention
We retain personal data only for as long as needed for the purpose collected, the active account or business relationship, applicable tax/accounting and limitation periods, fraud and security protection, dispute resolution and legal obligations. The period depends on the data category, contractual requirements, sensitivity, risk and whether deletion is technically possible in active systems and backups. Consent and suppression evidence may be retained after withdrawal to prove compliance and prevent further marketing. Data is then deleted, anonymised or securely isolated.
14. Your rights in the EU and United Kingdom
Subject to conditions and exceptions, you may request access, correction, erasure, restriction, portability, objection and information about processing; withdraw consent; object at any time to direct marketing; and complain to a supervisory authority. In the UK, you may complain to the Information Commissioner’s Office. In the EU/EEA, you may complain to the authority in your country. Exercising a right is normally free, although we may verify identity and may refuse manifestly unfounded or excessive requests as permitted by law.
15. United States privacy rights
Where an applicable US state privacy law covers KLAP, residents may have rights to know/access, delete, correct, obtain a portable copy, opt out of sale or sharing, opt out of certain targeted advertising or profiling, limit certain sensitive-data uses and receive non-discriminatory treatment. California residents may use the same contact and request methods below. We verify requests using information reasonably matched to our records. An authorised agent may act where legally permitted and properly verified.
We do not knowingly sell or share personal information of consumers under 16 without the required authorisation. Marketing texts and calls are sent only with the level of consent required by the Telephone Consumer Protection Act and applicable state law. Commercial email is managed in accordance with the CAN-SPAM Act.
16. Mexico privacy rights
Where Mexico’s Federal Law on Protection of Personal Data Held by Private Parties applies, this notice serves as an integral privacy notice. You may exercise ARCO rights: access, rectification, cancellation and opposition; revoke consent; and limit use or disclosure. Requests should identify the person, describe the data and right requested, and include information reasonably necessary to verify identity. Transfers are made only for the purposes and under the conditions described in this notice and applicable law.
17. Children
The Services are not directed to children who cannot lawfully consent to the relevant processing. We do not knowingly collect personal data from children below the applicable minimum age without valid parental or guardian authorisation. Event age restrictions remain the Organiser’s responsibility. Contact us if you believe a child’s data has been collected unlawfully.
18. AI-assisted processing and profiling
KLAP may use AI-assisted tools to draft content, translate, classify support requests, generate recommendations, detect anomalies or provide predictive analytics. Business-critical or legal decisions should not rely solely on unverified AI output. We do not make solely automated decisions producing legal or similarly significant effects on individuals unless lawfully permitted, appropriately disclosed and accompanied by required safeguards.
19. Data deletion and Meta Platform Data
You may request account or data deletion through the data deletion page or by emailing abuse@klap.life. Requests concerning data received through Meta products are handled through the same process and through the Meta data-deletion callback configured for the KLAP app. Deletion is subject to identity verification and lawful retention exceptions.
20. Changes
We may update this Notice for legal, technical or service changes. The current version and effective date will be published here. Material changes will be notified where required, and fresh consent will be requested where the law requires it.
21. Contact and complaints
Privacy contact: abuse@klap.life
K LIFE LIMITED (company number 14434391)
71–75 Shelton Street, Covent Garden
London, WC2H 9JQ
United Kingdom
When contacting us, describe the request, the relevant account/business and the email address or telephone number concerned. Do not send identity documents unless requested through a secure process.


Login





