Website & sign-up · Updated 8 September 2026
Privacy policy
Transparency builds trust, especially when AI reads requests and prepares replies. This notice describes how KITech processes personal data on the product website kissa.kitech.ai: when you visit, request trial access or book a demo.
Processing of social media messages in the application is described separately at kissa-ai.kitech.ai/datenschutz. The two texts complement each other and do not replace one another. See also: kitech.ai/datenschutz. This is not legal advice.
1. Controller
KITech (sole proprietorship), Ingo Zimmermann
Salmenweg 14, 4057 Basel, Switzerland
UID/VAT: CHE-494.864.694 MWST
Email: datenschutz@kitech.ai · Phone: +41 61 525 96 22
Where applicable, the GDPR and the Swiss Federal Act on Data Protection (FADP / revDSG) apply. Swiss supervisory authority: FDPIC, Feldeggweg 1, 3003 Bern.
2. Your rights
Access, rectification, erasure, restriction, objection, data portability, withdrawal of consent and complaint to a supervisory authority. Contact datenschutz@kitech.ai.
End users whose Instagram messages ran through KISSA_AI: request data deletion.
3. Visiting the website
When you open the site, technically necessary connection data (e.g. IP address, time, user agent) may appear in server and security logs, for operations, abuse prevention and stability. Retention is typically a few days, longer only as needed for security clarification (indicatively up to 90 days).
3a. Cookies and consent
The product page does not require JavaScript to read content. Forms can be submitted without CAPTCHA. No advertising tracking cookies are set. Technically necessary connection data and session hints may arise for operations and security.
Cookie banner. On first visit you can choose (FADP and, where applicable, GDPR):
- Accept all : necessary cookies and consent to optional categories (analytics/marketing) if introduced later;
- Necessary only : technically required cookies only;
- Reject : reject optional cookies; necessary cookies remain allowed because the site cannot operate without them.
We store your choice locally in the browser (localStorage, key
kissa_cookie_consent_v2), not as a cookie. While no optional cookies are
active, all three options have the same practical effect: no tracking cookies are set.
Legal basis for necessary cookies: legitimate interest in secure operation
(Art. 31 para. 1 FADP, Art. 6(1)(f) GDPR). Optional cookies only with consent.
Withdrawal: clear the stored choice in the browser and reload the page.
4. Forms: trial access and demo
What you enter is sent via a classic HTML form to the application and stored in its PostgreSQL database. The landing page stores nothing locally and has no own database.
| Data | Purpose | Legal basis |
|---|---|---|
| Company, name, email, optional phone | Trial access or demo follow-up | Art. 6(1)(b) GDPR (pre-contract) / (f) |
| Message, preferred time | Demo request content | Art. 6(1)(b) / (f) |
| Acceptance of terms & privacy | Proof of acknowledgement | Pre-contract / documentation |
| Source (campaign), origin/referer | Abuse protection, analytics | Art. 6(1)(f) |
| Honeypot field «webseite» | Block automated submissions | Art. 6(1)(f) |
Trial access is followed by a confirmation email with a password link. Without confirmation, no active account is created. Rate limiting protects against abuse.
4b. Contact details in the application
If someone leaves a phone number or email with a business via social media, the
application stores that detail encrypted. Overviews show only a
shortened form (e.g. a***@firma.ch, +••••••••622).
After retention ends, names and contact details are anonymised. Commercial records
(e.g. a qualified lead) may remain without personal identifiers where needed for billing.
Details and deletion path: application privacy notice at kissa-ai.kitech.ai/datenschutz and Delete data.
5. Retention
- Unconfirmed registrations: per application logic (time-limited confirmation link)
- Active accounts: while the account exists; after suspension until deletion
- Demo requests: until processed, then per internal rules and legal duties
- Commercial records: up to 10 years where required
6. Recipients and third countries
Processing on systems operated by KITech for the application. Email for confirmation. No disclosure to unrelated third parties for advertising.
The application may involve model providers and Meta (Instagram), see application privacy. Transfers to third countries only with appropriate safeguards (e.g. SCCs) where required.
7. Security
Transmission via HTTPS. Access control, tenant separation and logging in the application. Forms check origin/referer and use a honeypot against bots.
8. Changes
We update this notice for material changes. The version published on this page applies.