Account & Billing

Using KleioBase professionally

How professional genealogists can research on behalf of clients in KleioBase, including the Data Processing Agreement and the controls available to you.

Last updated August 5, 2026

If you research on behalf of clients, an archive, or another organisation rather than for yourself, a few things work differently in KleioBase. This guide covers what changes, the agreement that governs it, and the controls you have over a client's data.

Controller and processor

When you upload and research your own family history, that is personal, household use and no special agreement applies - our Privacy Policy covers it.

When you research on behalf of someone else - a client, an employer, or an organisation you work for - you are the controller of the personal data in those records: you decide what gets uploaded and why, and you are responsible for having a lawful basis to process it and for answering to the people it is about. KleioBase is your processor: we handle that data only under your instructions and under the terms of our Data Processing Agreement.

This distinction does not change anything about how you use the product day to day. Uploading, processing, and confirming records works exactly the same. It changes who is answerable for the research and what KleioBase commits to in writing about how it handles the data behind it.

The Data Processing Agreement

The DPA sets out what KleioBase does with a client's personal data, what it will not do with it, and what you can require of it, covering instructions, confidentiality, security, sub-processors, breach notification, deletion, and international transfers.

It is already in force. You do not need to sign anything. The DPA applies automatically to every account within its scope from the moment you use KleioBase to process personal data on someone else's behalf. There is no checkbox to tick and no separate contract to accept - it is incorporated into the Terms of Service you already agreed to.

Read the full agreement at /dpa.

Requesting a countersigned copy

Some organisations' procurement or compliance processes want a signed document on file even though the agreement is already binding. If yours does, you can request a countersigned copy at /forms/dpa-countersign.

A countersigned copy is a convenience for your records. It does not change the terms of the DPA and it is not what brings them into force - the agreement already applies to you whether or not you request one. Most professional users never need to ask for this; only request it if someone specifically requires a signed copy.

Sub-processors

KleioBase uses a small number of other companies to help provide the Service, such as our AI provider and our hosting infrastructure. Some of them process the personal data in the records you upload; others only handle account and billing information that KleioBase controls independently.

The current, authoritative list of sub-processors that touch your records is at /subprocessors. That page marks which providers process Customer Content and which do not, and it is kept up to date as vendors change - it is more current than the snapshot annex in the DPA itself.

If you want advance notice before a new sub-processor starts processing your data, subscribe to change notifications on the sub-processors page. That subscription is how you receive the 30 days' notice the DPA promises before a new sub-processor begins handling client data.

Historical context and living relatives

Under Settings > Account & Preferences (/settings/account) there is a toggle called Infer historical context from relatives.

When it is on, and a person in your tree has no religion, nationality, or caste recorded, KleioBase fills that gap in from their nearest ancestor's or spouse's record to decide which historical events show up on that person's timeline. This is what lets a person with a thin record still get relevant historical context instead of none.

When it is off, KleioBase matches historical events only against what a person actually has recorded about themselves - nothing is inferred from relatives.

If you are researching a client's family and the tree includes living relatives, consider turning this off. Inferring a trait like religion or nationality for a specific living person from a relative's record, even just to pick which historical events appear on their timeline, is a judgment call you may not want KleioBase making on your client's behalf. Turning the toggle off keeps every person's timeline based only on what is directly recorded for them.

Requests from people named in a client's records

Occasionally, someone named in a record you have uploaded on a client's behalf - a living relative, a witness, an informant - may contact KleioBase directly to ask about their personal data.

Because you are the controller of that data, KleioBase does not answer these requests on its own. If we receive one, we do not respond to it substantively. Instead, we forward it to you without undue delay, and where we can identify the requester, we tell them we have done so and that you are the controller responsible for answering. You then handle the request within the time limits your applicable data protection law sets.

Most of what you would need to respond - exporting, correcting, or deleting a specific person's data - you can already do yourself from the knowledge base, without waiting on us. See Your Knowledge Base for editing and deleting individual profiles and records.

Exporting and deleting a client's data when an engagement ends

When you finish working for a client, you can take a full copy of their data with you and then remove it from your account.

  • Export first. Use the full data download or a GEDCOM export from Settings > Import / Export to get a complete copy of the records, profiles, and family tree before you delete anything. See Importing & Exporting Data for the difference between the two.
  • Then delete. From Settings > Account & Preferences, clear the knowledge base if you want to remove the client's data but keep your account, or delete the account outright if the engagement was the only reason you had one. Both actions are processed immediately and irreversibly, with no recovery window, so export first.

This matches the deletion process described in the DPA: exporting and deleting are actions you take yourself, in the product, on your own schedule - you do not need to ask KleioBase to do it for you.

More in Account & Billing

Still stuck? Email [email protected] or ask the Research Companion inside the app.

We use cookies and similar technologies. Essential cookies keep the site working. We only load analytics (PostHog) and marketing (Meta Pixel) with your consent. See our Privacy Policy.