Your data is yours, and leaving is always possible
HR data is the most sensitive data a small company holds — salaries, identity documents, bank details. Here is exactly how Klok handles it, in plain terms, including the things we deliberately do not do.
The commitments that matter
Export Everything, Anytime
Every register, every payslip, every employee record exports to CSV whenever you want — including after you cancel. No exit fee, no export charge, no waiting on a support ticket.
Your Company Is Isolated
Each company’s data is separated at the database layer and that separation is covered by automated tests on every release, not by a policy document.
Role-based Access
Who can see salary, documents and personal details is controlled by role, and sensitive views are recorded — so “who saw this” is a report rather than a guess.
An Audit Trail That Cannot Be Rewritten
Approvals and changes are recorded as they happen and cannot be edited afterwards. A register that can be quietly altered is not evidence of anything.
AI That Never Writes Alone
AI drafts records from your documents; a human confirms before anything is saved. That rule is enforced in code and covered by tests — it is not a setting somebody can switch off by accident.
Where It Runs
Klok runs on managed infrastructure with encrypted transport, restricted administrative access and regular backups. Ask us for current specifics before you sign — we will answer precisely.
Leaving is always possible
The fair test of a data policy is not what happens while you are a customer. It is what happens when you decide to leave.
Everything is exportable, at any time, without asking anyone: employee records, attendance, leave ledgers, payroll registers, documents. There is no export request to raise and no retention hold on your own data. A vendor whose commercial defence is that your data is difficult to extract has told you what it thinks of the relationship.
Isolation, roles and the trail
Each company's data is isolated. Within it, access is role-based and scoped by entity, so a plant manager sees their plant. The most sensitive fields — identity numbers, bank details — are encrypted at rest.
Every write is recorded, and so is every export of personal data. The trail cannot be edited from the application.
AI never writes alone
This is a security property, not only a product one. Because no model output reaches a record without a human confirming it, there is no path by which a misread document silently alters a salary, a balance or an identity field. The blast radius of a bad reading is one draft that somebody declines.
What protects the data
Isolation
Your company's data is separated from every other tenant's.
Role and scope
Access by role, bounded by entity and workplace. Sensitive fields encrypted at rest.
The trail
Every write and every personal-data export recorded, and not editable from the application.
Exit
Full export whenever you want it, without a request, in formats you can actually use.
What people ask before trusting us with this
Where is our data actually stored?
On infrastructure in India, in a database where every row of yours is bound to your company and every query is scoped to it — a boundary enforced in the software and covered by automated tests, not a convention support staff are asked to respect. If a procurement or diligence process needs the specific hosting arrangement in writing, ask and we will provide it as a document rather than a marketing line.
What happens to our data if we stop paying?
Nothing dramatic, deliberately. A missed invoice triggers notice and a grace period, not a lock-out — we do not delete a company's payroll history because an invoice is late, and we do not hold data hostage in a renewal negotiation. If you decide to leave, the export rights below apply in full during the wind-down, and the decision to go never depends on our co-operation.
Can your staff see our salary data?
Support access is limited to what the specific issue genuinely requires, and any access by our staff to a tenant is written to the same append-only audit trail that records your own team's actions — so "who looked at our salaries" is a question your administrator can answer from inside the product, not a question you have to take on trust. If your diligence needs this in writing, ask.
Does the AI send our documents to third parties?
Yes, and we would rather describe it precisely than deny it vaguely: when the AI reads a document, its content is processed by Anthropic (Claude) or Google (Gemini) under business terms that do not permit training on your data. Nothing is sent except for the reading you asked for, the output returns as a draft a person must confirm, and if data residency is a hard requirement for you, raise it before you buy — that is a real constraint.
Can the audit trail be edited or deleted?
Not from the application, by anyone — there is no screen, role or setting that alters or removes an entry, including for administrators and including for us in the ordinary course. That is the property that makes it evidence rather than comfort: a trail a sufficiently senior person can rewrite is worse than none, because it convinces without proving. Exports of the trail are themselves recorded.
Do you hold ISO 27001 or SOC 2? Do you support SSO or SCIM?
No certifications today, and no SSO or SCIM yet — and we would rather put that in plain text on this page than have you discover it in procurement. What exists is what this page describes: application-level encryption of bank and identity fields, tenant isolation under test, an append-only trail, and consent-gated location. For a few thousand identities the SSO gap may be a blocker; if it is, tell us before you buy and we will tell you honestly where it sits on the roadmap.
What exactly can we export, and when?
Everything, at any time, without raising a request: employees, attendance, leave, payroll history, documents and the audit trail, in usable formats. This is the commitment the rest of the page hangs on — a system you cannot leave is one you cannot trust with payroll, so the exit door is load-bearing, not a courtesy.
What happens to our data after we leave?
You take your export during the wind-down window, and after it closes we delete the account's data, except what the law requires anyone to retain. Deleted data then ages out of the encrypted backup cycle as those backups expire on their fixed schedule — deletion is a process with an end date, not a checkbox, and we would rather say that than pretend backups vanish instantly.
Try it on your own payroll
Fourteen days, no card, and every record exports back out if you decide against it.