Kartio
Back to home

Compliant by design, not by promise.

Compliance

This page lists, control by control, how Kartio treats the references that matter for an AI assistant in a European ecommerce. What you read is already implemented and verifiable; what is missing is stated at the bottom, with no beating around the bush.

EU AI Act, GDPR and ISO/IEC 42001 and 27001 treated as product requirements: implemented controls, measured retention and a roadmap we state openly.

EU AI Act

Reg. (EU) 2024/1689
  • Transparency under Article 50, in force from 2 August 2026: the assistant declares it is an artificial intelligence in the greeting, keeps a persistent chip in the interface and labels recommended products.
  • Outputs marked in machine-readable form with dedicated DOM attributes, including in the voice answer with just-in-time notice. The attributes support traceability: we do not present them as formal certification of the marking under Article 50(2).
  • The shopping use case does not fall among the high-risk systems of Annex III. The assessment is reopened if the product enters regulated domains (credit, employment, education, biometrics).
  • No emotion recognition, no biometric categorisation: if they were introduced in the future, additional mandatory disclosures would apply.

GDPR

Reg. (EU) 2016/679
  • Real minimisation: no identifier created at page load, session cookie only at the first voluntary interaction, lifetime extended to 30 days only after explicit consent.
  • IP address never stored in clear, conversations deleted after ninety days, aggregated statistics. Voice is treated as personal but not biometric data: no speaker identification, voiceprint or cloning.
  • Roles clear by contract: the store is the controller, Kartio is the processor; in the white-label channel Kartio is a sub-processor under Article 28(4) with the agency as processor.
  • With activation the store receives the data processing agreement and the complete supplier register, with location, subprocessors and retention for each.

ISO/IEC 42001 and 27001

Voluntary standards
  • AI management (42001): model governance, answer evaluation with repeatable benchmarks, quality and cost monitoring per store.
  • Information security (27001): per-store isolation enforced by the database with verified per-tenant roles, keys treated as secrets, spending cap per tenant, encrypted backups with rotation.
  • The product is designed by a lead auditor of these standards: controls originate from the requirements, not from marketing.
  • Said clearly: Kartio is not certified. Formal certification is part of the roadmap; the controls listed here are already in operation and verifiable.

How long data is kept

Operational durations, not commercial estimates. On expiry the data is deleted or made unlinkable to the person; a deletion may remain in encrypted backups until the maximum thirty-day rotation.

Messages and transcripts
90 days
content redacted
Session, hashed IP, user-agent, summary
90 days
identifiers removed or unlinked
Idempotent chat replay
24 hours
deleted
Follow-up leads
365 days
deleted
Order attribution
730 days
deleted; session anonymous already at 90 days
Encrypted PostgreSQL backup
30 days
automatic rotation
History visible in the widget
browser session
sessionStorage only
Push-to-talk voice clip
never archived
browser memory, maximum 12 seconds

The suppliers, no black boxes

Chat and language processing run on European infrastructure, with no US gateways; text voice uses European endpoints. Realtime voice can only be enabled by the platform owner, store by store, and until the non-EU contractual path is closed it remains limited to non-sensitive demonstration data.

Every actual supplier is covered by a processing agreement, with subprocessors, location and retention documented in the register the store receives before signing.

The data processing agreement, clause by clauseThe sub-processors, category by category

What remains with the store

The store remains the data controller: it updates its own privacy notice, maps its consent manager to Kartio's signal and checks that retention periods are consistent with its own purposes. The browser microphone permission is a technical control; it does not replace a legal basis and a privacy notice.

On the roadmap, said openly

Formal product certification, full regionalisation of the realtime voice supplier and a model register with continuous quality monitoring. If you want the full controls documentation, the supplier register or the draft processing agreement, write to info@kartio.ai.