This English version is provided for convenience only. In the event of any discrepancy, the French version prevails.
This page is published at https://kasar.app/portabilite. The General Terms refer to it (Art. 10.1, 14.6 and 17.10), as does their Appendix 1. It meets two separate obligations under Regulation (EU) 2023/2854 (Data Act): the online register of data structures and formats (Art. 26(b), kept up to date under Art. 30(4)) and transparency on jurisdictions and international governmental access (Art. 28, which requires publication on the website and a reference to it in contracts).
1. Switching provider: the procedure#
| Step | What happens | Timeframe |
|---|---|---|
| Request | In writing to support@kasar.app. Tell us what you want: switch to another provider (with its contact details), switch to your own infrastructure, or erasure. | At any time |
| Notice | Your contract continues; we prepare your exit. | 2 months maximum, shorter if you ask |
| Transition period | The service remains fully provided. We assist your teams and your destination provider, flag any known risks to you, and keep security in place during transfers. | 30 days, extendable once at your request |
| Retrieval | Access kept for export purposes only (see "Exporting your data" below). | 30 days minimum after the transition period |
| Deletion | Your exportable data are deleted under the conditions of Article 12 of the DPA, with backup copies erased as they rotate out; written confirmation on request. | at the end of the retrieval period |
Charges: none. No exit, extraction or switching charges. No penalty linked to the switch itself. Sums paid for the current period remain payable; for the Enterprise Plan, sums due in respect of the commitment term remain governed by the Enterprise Specific Terms (Article 9.6 of the General Terms): they pay for the subscribed term, never for the switch.
Exporting your data.
- Self-service, for all categories (records of all objects with their relationships, notes, tasks, lists, pipelines, files attached to records, data model, organization, configuration, integration settings, consumption, and the AI outputs stored in records): from the interface (CSV, XLSX), via the API or via the MCP server (CSV, JSON), with files in their original format. Exports are limited to 10,000 rows per object per operation, and the API is subject to rate limits; larger volumes are obtained, on a self-service basis, through successive operations or via the API.
- In all circumstances: export remains available on a self-service basis, free of charge and without going through us, including where access to the service is restricted or suspended (Article 17.11 of the General Terms).
Credits. Unused top-up credits are forfeited when the account is closed and are not refundable, except in the cases provided for in Article 7.5 of the General Terms: remember to use them before you leave.
Technical impossibility. If the 30-day transition period proves technically unfeasible, we notify you within 14 working days of your request, stating our reasons, and propose an alternative period not exceeding 7 months.
Cessation of business. If we permanently cease operating the service, we notify you at least 90 days in advance and export remains available throughout that notice period (Article 17.14 of the General Terms). For the Enterprise Plan only, a continuity licence also allows you to deploy the service on your own infrastructure, from a deployment package and a complete export that we deliver to you (Article 12 of the Enterprise Specific Terms).
2. Register of data structures and formats#
This register meets Article 26(b) of the Data Act. It is updated whenever the exported data model changes.
| Data set | Structure | How to obtain | Available formats | Standard / specification |
|---|---|---|---|---|
| Records (contacts, companies, opportunities, products, custom objects) | One row per record; columns = fields of the Organization's data model, relationships included | Self-service | CSV (UTF-8, RFC 4180), XLSX, JSON | RFC 4180, RFC 8259 |
| Data model | Objects, fields, types, enumeration options, relationships | Self-service | CSV or JSON | RFC 4180, RFC 8259 |
| Notes and tasks | One row per item, with linking identifiers | Self-service | CSV, XLSX, JSON | RFC 4180, RFC 8259 |
| Pipelines | Pipelines and stages, with the position of records | Self-service | CSV or JSON | RFC 4180, RFC 8259 |
| Files attached to records | Files in their original format, with linking identifiers | Self-service | Original format | Not applicable |
| AI Outputs retained in records | Scores, enrichments stored in the fields of a record | Self-service, with the record | Included in the record export | Not applicable |
| Organization and permissions | Users, roles, permissions, teams | Self-service | CSV or JSON | RFC 4180, RFC 8259 |
| Working configuration | Lists, views, filters, dashboards, message templates, sequences | Self-service | CSV or JSON | RFC 4180, RFC 8259 |
| Integration settings | Connected integrations, linked accounts, synchronization rules, excluding authentication secrets | Self-service | CSV or JSON | RFC 4180, RFC 8259 |
| Consumption | Credit consumption history, including telephony | Self-service | CSV or JSON | RFC 4180, RFC 8259 |
| Timestamps | All exports | Not applicable | ISO 8601 / RFC 3339 | ISO 8601 |
| Identifiers | All exports | Not applicable | Internal record identifiers | Not applicable |
Open interfaces. The REST API (https://platform.kasar.app/api-docs) and the MCP server are documented and accessible free of charge, on the same terms for all customers and for the destination providers they designate, to enable the development of the software needed for portability and interoperability (Art. 30(2)). General documentation: https://docs.kasar.app.
Known technical limitations, stated under Article 26(a):
- integration authentication secrets (OAuth tokens, API keys) cannot be exported, for security reasons: connections must be re-established with the destination provider;
- self-service exports are limited to 10,000 rows per object per operation, and the API is subject to rate limits; beyond that, exports go through successive operations, still on a self-service basis (Section 1);
- interactions synchronized from connected services (emails, messages, calls, meetings, calendar), their recordings, transcripts and analyses are not part of the exportable data: they remain available in your source services (Appendix 1 of the General Terms). For the Enterprise Plan only, these data may be exported on request sent to support@kasar.app;
- as the common interoperability standards referred to in Article 30(3) have not yet been published in the Union's central repository for this category of service, exports are provided in structured, commonly used and machine-readable formats, in accordance with Article 30(5). Compatibility with these standards will be ensured within twelve (12) months of their publication.
3. Infrastructure jurisdictions (Art. 28(1)(a))#
The primary hosting of customer data (database, file storage) is located in Ireland (European Union), and the application runs in France. Some processing is, however, carried out in the United States: synchronization and asynchronous processing (emails, LinkedIn and WhatsApp messages, imports, automations) and the meeting recording bot, on a DigitalOcean cluster located in New York; call routing for native telephony (Twilio); and certain AI features. Migration of the DigitalOcean cluster to a European Union region is planned. In addition, several providers are companies governed by U.S. law or have a parent company that is, regardless of the hosting region.
| Provider | Role | Processing region | Jurisdiction of the contracting entity |
|---|---|---|---|
| Supabase | PostgreSQL database, file storage | Ireland (AWS eu-west-1) | United States (parent company) |
| Vercel | Application execution, monitoring | France (cdg1) | United States (parent company) |
| DigitalOcean, LLC | Synchronization and asynchronous processing, WhatsApp gateway, meeting recording bot | United States (New York, nyc1); migration to the EU planned | United States |
| Upstash | Cache, processing queues, presence | Region stated in Upstash's terms | United States (parent company) |
| AWS S3 | Meeting and call recordings | Ireland (eu-west-1) | United States (parent company) |
| Anthropic Ireland, Ltd | AI models (assistant, analysis, summarization, web search) | Contracting party in Ireland; inference possible in the United States, Europe, Asia or Australia | Ireland (EU); parent company in the United States |
| Deepgram, Inc. | Audio transcription | United States | United States |
| OpenAI | Speech synthesis; fallback transcription | United States | Contracting party and safeguards according to the OpenAI DPA; parent company in the United States |
| Dropcontact | Business email address search | France | France |
| Twilio | Native telephony | United States (call routing); Ireland (storage of recordings) | United States (parent company) |
| Stripe | Payments | EU / United States | Ireland / United States |
| Resend | Transactional emails | United States | United States |
The complete and up-to-date list of sub-processors, with the applicable transfer safeguards, is set out in Appendix 3 to the DPA.
4. Measures against international governmental access (Art. 28(1)(b))#
- Location. Primary hosting (database, file storage) is deployed in a European region. Processing carried out outside the Union is listed in Section 3 and in Appendix 3 to the DPA.
- Encryption. Encryption in transit (TLS) between users and the service and with sub-processors, and AES-256-GCM encryption at rest of communication content and of access secrets for third-party services. Content needed for synchronization and AI features is decrypted in order to be processed.
- Segregation. A dedicated database schema per organization, logical isolation for each transaction, role-based access and logging.
- Contractual commitments. For each transfer outside the EU, the Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) or the safeguards provided for in the provider's DPA, supplemented, where relevant, by the supplementary measures recommended by the EDPB (Recommendations 01/2020). Our AI model providers do not use the transmitted content to train their models (Article 13.3 of the General Terms); they may retain it temporarily, according to their terms (Article 13.4 of the General Terms).
- Handling of requests. Any request from a third-country authority is examined in light of Article 32 of the Data Act: Kasar does not transfer any non-personal data held in the Union on the basis of a foreign decision that is not based on an international agreement in force, unless the cumulative conditions of Article 32(3) are met, and, in case of doubt, defers to the opinion of the competent national authority for international legal cooperation.
- Minimization. Where a request must be complied with, only the minimum amount of data permitted is disclosed.
- Customer information. The customer is informed of the existence of the request before it is complied with, except for law enforcement purposes and only for as long as necessary to preserve the effectiveness of the investigation.