Privacy policy — KISSA_AI
Version 23 August 2026 for kissa.kitech.ai and processing in the kissa-ai.kitech.ai application.
This text describes intended processing. It is not legal advice. Have it reviewed by counsel before go-live (GDPR and Swiss revDSG).
Legal framework
- GDPR (EU 2016/679)
- Swiss revised FADP (revDSG)
- EU AI Act (2024/1689), Art. 50 transparency
1. Controller
Ingo Zimmermann / KITech, Salmenweg 14, 4057 Basel, Switzerland. UID CHE-494.864.694. datenschutz@kitech.ai. No data protection officer appointed.
2. Roles
Businesses connecting their social accounts decide purposes and means; KITech provides the technology as processor. A DPA under Art. 28 GDPR is part of the product.
3. Data categories
Message content, Instagram identifiers, timestamps, voluntary contact details, qualification fields, and automated interest scores — sourced from Instagram APIs and the conversation.
4. Purposes & legal bases
Replying to enquiries (Art. 6(1)(b)/(f)), scoring interest (f), accounting (c)/(f), storing contact data for follow-up (a).
5. Profiling
Enquiries are scored automatically for prioritisation. This is not an Art. 22 decision with legal effect — humans decide whether an offer is made.
6. Machine replies
Replies are prepared by AI. Depending on settings they are approved by a human or sent autonomously. Disclosure at conversation start is enforced. Complaints, legal, press and requests for a human are never automated.
7. Recipients
Meta Platforms Ireland Ltd.; LLM providers (Google Gemini and optionally Anthropic, OpenAI, OpenRouter); DigitalOcean. Transfers to the US may rely on SCCs.
8. Third countries
US transfers may occur. Authority access risk exists.
9. Retention
Raw events 90 days; conversations per customer policy; deletion proof permanent (no content); commercial records 10 years.
10. Rights
Access, rectification, erasure, restriction, objection, portability, withdraw consent, lodge a complaint (EDÖB in Switzerland; any EU supervisory authority). See delete data.
11. Security
TLS only; tokens encrypted at rest; DB-level tenant isolation; immutable audit log; role-based access.
12. Changes
Version dated 23 August 2026. Material changes will update this page.