Kartio
Back to home

The data processing agreement

Legal

Last updated: August 2026

Before activation, every store receives and signs the data processing agreement (DPA). This page sets out its content in readable form: the roles, the safeguards and the timeframes that the contractual text makes binding.

The roles, in four lines

01The store

Data controller

02The agency, when it resells the service

Data processor

03Kartio

Processor or sub-processor (Art. 28(4) GDPR)

04Kartio's suppliers

Further sub-processors, listed in the register delivered at signing

Kartio never contacts the store's visitors or customers: instructions and operational communications go through the commercial channel.

Only on documented instructions

We process personal data only to deliver the service and only on documented instructions: the agreement, the configuration set in the panels and accepted written requests. If an instruction appears to conflict with the GDPR, we flag it before executing it instead of executing it in silence.

Exclusion from training

We do not train models of our own on customer content. From the artificial intelligence suppliers we require configurations that exclude the use of data for training or general improvement: the status of this exclusion, supplier by supplier, is documented in the register delivered before signature. Quality analyses remain limited to the individual store: a cross-cutting use would require a new documented instruction and aggregated or anonymous data.

Sub-processors with advance notice

The list of sub-processors is part of the register delivered before signing. Every addition or replacement is communicated with at least thirty days' notice; you may object on documented grounds within fifteen days and, if no alternative can be found, withdraw from the affected service without penalty. Every sub-processor is bound by contract to obligations no less onerous than ours.

The suppliers, category by category

Data subject rights

We assist the commercial channel in acting on requests for access, rectification, erasure, restriction, portability and objection: data is segregated per store and technically searchable. If a data subject writes directly to us, we do not reply on the merits: we forward the request without undue delay.

Personal data breaches

Every breach we become aware of is notified without undue delay and in any case within 48 hours, with the nature, categories and approximate number of data subjects, the likely consequences and the measures taken. Notification to the supervisory authority and to data subjects remains the controller's responsibility.

Measured retention

Retention periods are product settings, not commercial estimates: messages and transcripts 90 days, follow-up contacts 365 days, order attribution 730 days, encrypted backups 30 days. Scheduled deletion runs every day and the full table is public.

The retention table, data item by data item

Deletion and return at the end of the relationship

On termination, upon documented instruction, personal data is returned in a usable format or deleted from primary systems within thirty days; copies in encrypted backups expire with rotation, within a maximum of thirty days. Execution is confirmed in writing on request.

Transfers outside the European Union

We do not present the service as entirely European as a matter of principle: the actual location of every processing operation is documented in the register. A transfer to third countries takes place only with a safeguard under Articles 44-49 GDPR, normally the standard contractual clauses, and after a transfer impact assessment. Realtime voice follows a dedicated activation sheet: without a proven region, supplier retention and documented authorisation it is not enabled on real customer data.

Transparency about artificial intelligence

The assistant declares itself as artificial intelligence in the greeting, stays marked in the interface and in machine-readable form, under Article 50 of the AI Act. No biometric identification, no emotion recognition, no voice cloning. Kartio is not a certified product and does not claim to be.

The detail of the controls

Audits

We make available the technical and organisational documentation needed to demonstrate compliance with Article 28 GDPR. One audit per year is possible with thirty days' notice, with arrangements proportionate to the risk and without prejudice to the other stores.

What does not enter the service

Special categories of data (Art. 9 GDPR) and judicial data (Art. 10) are neither requested nor solicited: if a visitor communicates them spontaneously they follow the applicable retention and can be deleted on instruction. The service is not designed to address minors.

The full contractual text, with the supplier register and the activation sheets, is delivered before signing. To receive it, write to info@kartio.ai.