Privacy policy.
Protection of personal data in connection with the Kleep size recommendation service.
Reference KLP-PC-2026-v2.0 · 14 April 2026 · Prepared by the Data Protection Officer · Approved by Federico Fortis, President, Kleep SAS
1. Who we are
Kleep SAS (“Kleep”, “we”) is a French simplified joint-stock company with share capital of EUR 3,077, registered with the Paris Trade and Companies Register under number 904 780 335, with its registered office at 23 rue Blondel, 75002 Paris, France.
Kleep publishes an artificial-intelligence-based size recommendation software solution, integrated into the e-commerce websites of its merchant clients (the “Merchants”). This policy describes how Kleep processes the personal data of visitors to and customers of Merchant websites (the “Users”) when they use the Kleep service.
| Contact | Details |
|---|---|
| Data Protection Officer (DPO) | dpo@kleep.ai |
| Data protection contact | Federico Fortis, federico@kleep.ai |
| Chief Information Security Officer (CISO) | Théophile Bousquet, theophile@kleep.ai |
| Postal address | Kleep SAS (FAO the DPO), 23 rue Blondel, 75002 Paris, France |
2. Scope and roles
This policy applies to the Kleep size recommendation service (the “Service”) as deployed on Merchants’ e-commerce websites, in particular through a widget embedded in product pages (the “Widget”).
Under Regulation (EU) 2016/679 (“GDPR”), roles are allocated as follows:
| Processing activity | Controller | Kleep's role |
|---|---|---|
| Size recommendation for Users of the Merchant's website | The Merchant | Processor (Art. 28 GDPR), acting on the Merchant's documented instructions |
| Improvement and development of Kleep's recommendation algorithm (controlled reuse of pseudonymised / aggregated data) | Kleep (controller for this further processing) | Reuse subject to the Merchant's prior written authorisation, as provided in the GDPR annex to the services agreement |
Deployment scope
The Kleep suite includes optional features, such as photo-based body scanning, which may involve additional processing. They are activated only at the Merchant’s express request. Where they are not activated, they fall outside the deployment scope and no photograph is collected: the recommendation is then based solely on the self-declared morphological questionnaire. The agreed scope is specified in the services agreement.
3. Personal data processed
Kleep applies the data minimisation principle (Art. 5(1)(c) GDPR): only data strictly necessary for the size recommendation is collected. The Service collects no directly identifying data (no name, email address, postal address or payment data).
| Category | Data | Source |
|---|---|---|
| Self-declared morphological data | Age, height, weight, answers to the morphological questionnaire (e.g. usual size or shoe size, body shape, fit preferences) | Voluntarily entered by the User in the Widget |
| Pseudonymous technical identifiers | Random visitor identifier (UUID), session identifier, local recommendation token | Generated by the Widget, stored in the browser |
| Usage events | Product page views, interactions with the Widget, add-to-cart actions, order confirmation (variant, price, currency) | Widget / CMS integration |
| Transactional data | Order and return history linked to a Merchant customer identifier | The Merchant's e-commerce system (CMS), via API or secure SFTP |
No special category data (Art. 9 GDPR) and no data relating to criminal convictions or offences (Art. 10 GDPR) is processed. The Service is not specifically directed at minors and does not make it possible to identify them.
4. Purposes and legal bases
| Purpose | Legal basis | Role |
|---|---|---|
| First purpose (size recommendation): analysing the self-declared morphological data and comparing it with the fit profile of the Merchant's products in order to recommend the most suitable size | User's consent (Art. 6(1)(a) GDPR), collected through the Merchant's consent management platform (CMP) before the Kleep script is loaded | Kleep, as the Merchant's processor |
| Second purpose (reuse): improvement and development of Kleep's services and products, specifically its size recommendation algorithm for the Merchant | User's consent, together with the Merchant's prior written authorisation (GDPR annex to the agreement); pseudonymised or aggregated data only | Kleep, as controller for this further processing |
5. Cookies, trackers and local storage
The Kleep script is loaded and executed only after the User’s consent has been collected through the Merchant’s CMP. Without consent, no tracker is placed and no data is collected.
| Identifier | Type | Purpose | Duration |
|---|---|---|---|
kleep_uid / kleep_user_uuid | localStorage | Pseudonymous visitor identifier (UUID) | 12 months |
kleep_session_uuid | sessionStorage | Session identifier | Browsing session |
kleep_mid | localStorage | Measurement / recommendation identifier | 12 months |
kleep_recommendation_type | localStorage | Recommendation category (e.g. apparel, footwear) | 12 months |
kleep_retailer | localStorage | Merchant website domain | 12 months |
kleep_is_test | localStorage | Technical flag (0/1) | 12 months |
Where the Merchant activates the audience measurement option, additional trackers may be placed subject to the same prior consent requirement; they are documented in the integration sheet provided to the Merchant.
Users may delete these items at any time by clearing their browser’s site data: the local recommendation is then immediately reset.
6. Retention periods
| Data | Period | Deletion arrangements |
|---|---|---|
| Local recommendation token and pseudonymous identifiers (browser) | 12 months | Automatic expiry; immediate deletion possible by the User (clearing the cache) |
| Morphological data and usage events (Kleep servers) | 12 months from collection | Automated deletion (AWS lifecycle rules), in accordance with Kleep's Archiving and Deletion Policy |
| Order / return data used to improve the model | Term of the agreement with the Merchant, limited to what is necessary | Secure deletion within 30 days following the end of the agreement |
| Pseudonymised / aggregated data used for model improvement | Term of the agreement | Deletion or irreversible anonymisation |
7. Recipients and sub-processors
Data is accessible only to authorised Kleep teams (least privilege principle, multi-factor authentication) and to our sub-processors listed below. It is never sold or passed on to third parties for commercial purposes, and is never cross-matched between brands.
| Sub-processor | Service | Location |
|---|---|---|
| Amazon Web Services EMEA SARL (AWS) | Cloud hosting and infrastructure | Region eu-west-1, Dublin, Ireland (EU) |
| PostHog EU Cloud (optional) | Audience measurement and Widget usage analytics, activated only at the Merchant's request and after the User's consent | European Union (Frankfurt, Germany) |
Any new sub-processor is notified to the Merchant in advance, who has a contractual period within which to object.
8. Transfers outside the European Union
All data is hosted and processed exclusively within the European Union. Kleep carries out no transfers of data outside the EU/EEA. Should such a transfer ever be contemplated, it would first be submitted for the Merchant’s written authorisation and framed by an adequacy decision or the European Commission’s standard contractual clauses (Art. 44 et seq. GDPR).
9. Data security
- Encryption in transit (HTTPS, TLS 1.2 / 1.3) and at rest (AES-256, keys managed in AWS KMS with automatic rotation);
- Least-privilege access control (AWS IAM) with mandatory multi-factor authentication;
- Logical isolation of data and models per merchant client;
- Continuous logging and monitoring (AWS CloudTrail, CloudWatch, GuardDuty), web application firewall (AWS WAF) and anti-DDoS protection (AWS Shield);
- Encrypted backups and a formalised personal data breach management procedure.
Detailed measures are set out in Kleep’s Information Security Policy, available on request.
10. Your rights
Under Articles 15 to 22 GDPR and the French Data Protection Act, you have the following rights: access, rectification, erasure, restriction, portability, objection, withdrawal of consent at any time, post-mortem directions regarding your data, and the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects.
No automated decision-making
The Service produces no automated decision within the meaning of Article 22 GDPR: the size recommendation is merely a suggestion, and the purchase decision always remains with the User.
How to exercise your rights
- Immediate self-service: local data (token, identifiers) can be deleted at any time by clearing your browser’s site data;
- With Kleep: by email to dpo@kleep.ai (response within one month, in accordance with Art. 12(3) GDPR);
- With the Merchant: for processing for which it is the controller, using the contact details given in its own privacy policy; Kleep forwards to the Merchant without delay any request falling within its responsibility.
Most of the data processed by Kleep does not make it possible to directly identify an individual. In accordance with Article 11 GDPR, Kleep may ask you for reasonable additional information (e.g. the technical identifier displayed in the Widget) in order to locate your data; if identification remains impossible, Kleep will inform you accordingly.
You also have the right to lodge a complaint with the CNIL (the French data protection authority, www.cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07) or with the supervisory authority of your country of residence.
11. Transparency regarding artificial intelligence
The size recommendation is generated by an artificial intelligence system (supervised learning). In accordance with Regulation (EU) 2024/1689 (the “AI Act”), Users are clearly informed of this within the Widget journey. The system uses no generative AI, performs no biometric identification and is qualified as a limited-risk system (see Kleep’s AI Act qualification note).
12. Updates to this policy
This policy is reviewed at least once a year and whenever there is a significant change to the Service or to applicable regulations. The version in force is dated and provided to Merchants; any substantial change is notified in advance.
Version history
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | 12/03/2024 | Kleep DPO | Document created |
| 1.1 | 20/01/2025 | Kleep DPO | Clarifications on trackers and CMP configuration |
| 2.0 | 14/04/2026 | Kleep DPO | Full review: apparel and footwear scope, roles, retention periods |