Privacy policy
1. Data Controller
The controller of personal data collected through klusto.ai and the Klusto plugin is BMD Creatives, LLC:
- Registered office: 30 N Gould St Ste R, Sheridan, WY 82801, United States.
- Mailing address: 7345 W Sand Lake Rd Ste 210 Office 2145, Orlando, FL 32819, United States.
- Operational structure: distributed team, with main operations outside the United States (including Argentina).
- Contact email for privacy matters: get@klusto.ai
For European Union users: requests related to GDPR rights can be sent to the indicated email and will be processed within a maximum of 30 days.
2. Data we collect
2.1 Data the user provides directly
- Registration and billing data: name, email, country, tax data required for invoicing. Processed through our Merchant of Record (Paddle).
- Account data: license email, hashed password, contracted plan.
- Communication data: content of emails you send to our contact.
2.2 Data generated by the use of the Service
- Technical logs: IP, user agent, timestamps, errors, and plugin events. Used for diagnostics and security.
- Data from your connected WordPress site: the plugin analyzes your site (URLs, titles, categories, published content) to generate relevant content. This data is processed within your own WordPress installation.
- AI prompts and outputs: when you generate content with Klusto, the prompt is sent to Anthropic (processor) and the output is returned to your WordPress.
2.3 Automatically collected data
- Cookies and similar: see Cookie Policy.
3. Purposes and legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Provision of the contracted service | Performance of contract (b) |
| Billing and tax obligations | Legal obligation (c) |
| Transactional communications (activation, renewal, support) | Performance of contract (b) |
| Newsletter and marketing | Consent (a) — revocable at any time |
| Service improvement (aggregate analytics, debugging) | Legitimate interest (f) |
| Compliance with legal obligations and defense of rights | Legal obligation (c) / Legitimate interest (f) |
4. Sub-processors (providers processing data on our behalf)
To provide the service, BMD uses the following sub-processors. All of them comply with equivalent security standards and, where applicable, the standard contractual clauses (SCCs) for international transfers:
- Anthropic, PBC (United States) — AI processing for content generation. Anthropic’s privacy policy.
- Brevo (Sendinblue SAS) (France, EU) — transactional emails and opt-in marketing. Brevo’s privacy policy.
- Hosting.com (United States) — web hosting infrastructure for the klusto.ai site.
- Paddle.com Market Limited (United Kingdom) — Merchant of Record, payment processing and invoicing with international tax compliance. Paddle’s privacy policy.
This list is updated if we add or change providers. Active subscriptions will be notified at least 30 days in advance of substantive changes.
5. International transfers
Personal data may be transferred to:
- United States: BMD Creatives, LLC and sub-processors Anthropic, Hosting.com.
- United Kingdom: Paddle.
- Countries where BMD’s distributed team operates: mainly Argentina, under applicable international transfer safeguards.
All transfers are made under the standard contractual clauses (SCCs) approved by the European Commission, or equivalent mechanisms (UK IDTA, etc.), guaranteeing a level of protection essentially equivalent to GDPR.
6. Data retention
- Active account data: while the subscription is active.
- After cancellation: 6-month retention in case the user wants to reactivate, except upon express request for deletion.
- Billing data: 7 years due to tax obligations.
- Technical logs: 90 days for security diagnostics.
- Marketing data: until you withdraw consent.
7. User rights
You have the right to:
- Access: request a copy of the data we have about you.
- Rectification: correct inaccurate data.
- Erasure (“right to be forgotten”): request deletion of your data, except for legal retention obligations.
- Restriction: limit processing in cases provided by law.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interest.
- Withdrawal of consent: revoke at any time the consent previously granted.
- Complaint to a supervisory authority: in Spain, before the AEPD; in other EU countries, before your national authority.
To exercise these rights, send an email to get@klusto.ai indicating the right you wish to exercise. We will respond within a maximum of 30 days.
8. Security
BMD implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or destruction: encryption in transit (TLS 1.2+), passwords with hashing, access control, regular backups, and event monitoring.
9. Minors
Klusto is not directed at minors under 16. We do not intentionally collect personal data from minors. If we detect that we have collected data from a minor without valid parental consent, we will delete that data.
10. Changes to this policy
This policy may be updated to reflect legal or service changes. Substantial changes will be notified by email to the registered user at least 30 days in advance. The date of the last update appears at the bottom of this page.
11. Contact
- Email: get@klusto.ai
- Mailing address: BMD Creatives, LLC — 7345 W Sand Lake Rd Ste 210 Office 2145, Orlando, FL 32819, USA