Compliant by design, not by promise.
Compliance
This page lists, control by control, how Kartio treats the references that matter for an AI assistant in a European ecommerce. What you read is already implemented and verifiable; what is missing is stated at the bottom, with no beating around the bush.

EU AI Act
- Transparency under Article 50, in force from 2 August 2026: the assistant declares it is an artificial intelligence in the greeting, keeps a persistent chip in the interface and labels recommended products.
- Outputs marked in machine-readable form with dedicated DOM attributes, including in the voice answer with just-in-time notice. The attributes support traceability: we do not present them as formal certification of the marking under Article 50(2).
- The shopping use case does not fall among the high-risk systems of Annex III. The assessment is reopened if the product enters regulated domains (credit, employment, education, biometrics).
- No emotion recognition, no biometric categorisation: if they were introduced in the future, additional mandatory disclosures would apply.
GDPR
- Real minimisation: no identifier created at page load, session cookie only at the first voluntary interaction, lifetime extended to 30 days only after explicit consent.
- IP address never stored in clear, conversations deleted after ninety days, aggregated statistics. Voice is treated as personal but not biometric data: no speaker identification, voiceprint or cloning.
- Roles clear by contract: the store is the controller, Kartio is the processor; in the white-label channel Kartio is a sub-processor under Article 28(4) with the agency as processor.
- With activation the store receives the data processing agreement and the complete supplier register, with location, subprocessors and retention for each.
ISO/IEC 42001 and 27001
- AI management (42001): model governance, answer evaluation with repeatable benchmarks, quality and cost monitoring per store.
- Information security (27001): per-store isolation enforced by the database with verified per-tenant roles, keys treated as secrets, spending cap per tenant, encrypted backups with rotation.
- The product is designed by a lead auditor of these standards: controls originate from the requirements, not from marketing.
- Said clearly: Kartio is not certified. Formal certification is part of the roadmap; the controls listed here are already in operation and verifiable.
How long data is kept
Operational durations, not commercial estimates. On expiry the data is deleted or made unlinkable to the person; a deletion may remain in encrypted backups until the maximum thirty-day rotation.
The suppliers, no black boxes
Chat and language processing run on European infrastructure, with no US gateways; text voice uses European endpoints. Realtime voice can only be enabled by the platform owner, store by store, and until the non-EU contractual path is closed it remains limited to non-sensitive demonstration data.
Every actual supplier is covered by a processing agreement, with subprocessors, location and retention documented in the register the store receives before signing.
The data processing agreement, clause by clauseThe sub-processors, category by category
What remains with the store
The store remains the data controller: it updates its own privacy notice, maps its consent manager to Kartio's signal and checks that retention periods are consistent with its own purposes. The browser microphone permission is a technical control; it does not replace a legal basis and a privacy notice.
On the roadmap, said openly
Formal product certification, full regionalisation of the realtime voice supplier and a model register with continuous quality monitoring. If you want the full controls documentation, the supplier register or the draft processing agreement, write to info@kartio.ai.