KISSA_AI
Home Documentation Troubleshooting Pricing Sign in DEEN
Privacy · Delete data · Terms · Legal

Privacy policy — KISSA_AI

Version 23 August 2026 for kissa.kitech.ai and processing in the kissa-ai.kitech.ai application.

This text describes intended processing. It is not legal advice. Have it reviewed by counsel before go-live (GDPR and Swiss revDSG).

Legal framework

  • GDPR (EU 2016/679)
  • Swiss revised FADP (revDSG)
  • EU AI Act (2024/1689), Art. 50 transparency

1. Controller

Ingo Zimmermann / KITech, Salmenweg 14, 4057 Basel, Switzerland. UID CHE-494.864.694. datenschutz@kitech.ai. No data protection officer appointed.

2. Roles

Businesses connecting their social accounts decide purposes and means; KITech provides the technology as processor. A DPA under Art. 28 GDPR is part of the product.

3. Data categories

Message content, Instagram identifiers, timestamps, voluntary contact details, qualification fields, and automated interest scores — sourced from Instagram APIs and the conversation.

4. Purposes & legal bases

Replying to enquiries (Art. 6(1)(b)/(f)), scoring interest (f), accounting (c)/(f), storing contact data for follow-up (a).

5. Profiling

Enquiries are scored automatically for prioritisation. This is not an Art. 22 decision with legal effect — humans decide whether an offer is made.

6. Machine replies

Replies are prepared by AI. Depending on settings they are approved by a human or sent autonomously. Disclosure at conversation start is enforced. Complaints, legal, press and requests for a human are never automated.

7. Recipients

Meta Platforms Ireland Ltd.; LLM providers (Google Gemini and optionally Anthropic, OpenAI, OpenRouter); DigitalOcean. Transfers to the US may rely on SCCs.

8. Third countries

US transfers may occur. Authority access risk exists.

9. Retention

Raw events 90 days; conversations per customer policy; deletion proof permanent (no content); commercial records 10 years.

10. Rights

Access, rectification, erasure, restriction, objection, portability, withdraw consent, lodge a complaint (EDÖB in Switzerland; any EU supervisory authority). See delete data.

11. Security

TLS only; tokens encrypted at rest; DB-level tenant isolation; immutable audit log; role-based access.

12. Changes

Version dated 23 August 2026. Material changes will update this page.

© 2026 KITech — KISSA_AI
Documentation Pricing Privacy Delete data Terms Legal notice Contact Sign in