Sub-processors

As a data processor for our customers, Kloner may engage third parties ("sub-processors") to carry out parts of the processing. This page provides an overview of the categories of sub-processors we use and the purposes they serve. We keep this list up to date and will notify existing customers at least 30 days before adding a new sub-processor, so that the customer has the opportunity to object.

DRAFT — under legal review. Not yet a binding document.

Infrastructure and hosting (Norway)

The Kaduno platform is operated on server infrastructure located in Norway. The sub-processor in this category provides physical hosting, network resources, and managed database services.

All production data processing takes place within Norwegian infrastructure. Backups are handled within the same geographic region unless otherwise agreed.

Email delivery

We use an external provider for transactional email — for example order confirmations, password resets, and notifications generated by the platform on the customer's behalf.

The provider processes email addresses and the content of the relevant messages. Data is transferred only to the extent necessary to deliver the specific email.

AI model providers

K-AI and other embedded AI features use third-party AI models to generate responses, summaries, and recommendations.

For each call, the model ID, token usage, and cost are logged per account and per tenant — this is tenant-isolated and visible in the admin interface. Prompts and context sent to the model are limited to the data required for the specific function.

AI model providers do not act as independent controllers of this data — they process only on Kloner's instructions in the role of sub-processor.

Payment processing

Kaduno supports integration with payment gateways to receive payment from end users. Payment processors (e.g. Worldline/Bambora, depending on the customer's configuration) act as independent controllers of payment data under their own terms of service and payment card industry standards (PCI-DSS).

Kloner does not store full card details. Payment gateways handle tokenisation and settlement directly. The customer is responsible for having a valid agreement with their chosen payment gateway.

Alerting and monitoring

To maintain platform stability and availability, Kloner uses error and performance monitoring services. These may receive log and trace data, including IP addresses and user IDs where necessary for fault diagnosis.

Data sent to monitoring services is limited to what is necessary for technical operations monitoring and is restricted to Kloner's technical operations staff.

Changes to this list

Kloner will notify existing customers by email at least 30 days before adding new sub-processor categories. The date of the most recent update to this list is shown in the document metadata.

If a customer has objections to a new sub-processor, they are asked to contact us within the notice period. We will endeavour to find a resolution; if this is not possible, the customer may terminate the agreement without additional charges in accordance with the procedures in the service agreement.