Kasar

Portability, interoperability and transparency

Version: 2026-09-28 · Last updated: September 28, 2026

This English version is provided for convenience only. In the event of any discrepancy, the French version prevails.

This page is published at https://kasar.app/portabilite. The General Terms refer to it (Art. 10.1, 14.6 and 17.10), as does their Appendix 1. It meets two separate obligations under Regulation (EU) 2023/2854 (Data Act): the online register of data structures and formats (Art. 26(b), kept up to date under Art. 30(4)) and transparency on jurisdictions and international governmental access (Art. 28, which requires publication on the website and a reference to it in contracts).

1. Switching provider: the procedure#

StepWhat happensTimeframe
RequestIn writing to support@kasar.app. Tell us what you want: switch to another provider (with its contact details), switch to your own infrastructure, or erasure.At any time
NoticeYour contract continues; we prepare your exit.2 months maximum, shorter if you ask
Transition periodThe service remains fully provided. We assist your teams and your destination provider, flag any known risks to you, and keep security in place during transfers.30 days, extendable once at your request
RetrievalAccess kept for export purposes only (see "Exporting your data" below).30 days minimum after the transition period
DeletionYour exportable data are deleted under the conditions of Article 12 of the DPA, with backup copies erased as they rotate out; written confirmation on request.at the end of the retrieval period

Charges: none. No exit, extraction or switching charges. No penalty linked to the switch itself. Sums paid for the current period remain payable; for the Enterprise Plan, sums due in respect of the commitment term remain governed by the Enterprise Specific Terms (Article 9.6 of the General Terms): they pay for the subscribed term, never for the switch.

Exporting your data.

  • Self-service, for all categories (records of all objects with their relationships, notes, tasks, lists, pipelines, files attached to records, data model, organization, configuration, integration settings, consumption, and the AI outputs stored in records): from the interface (CSV, XLSX), via the API or via the MCP server (CSV, JSON), with files in their original format. Exports are limited to 10,000 rows per object per operation, and the API is subject to rate limits; larger volumes are obtained, on a self-service basis, through successive operations or via the API.
  • In all circumstances: export remains available on a self-service basis, free of charge and without going through us, including where access to the service is restricted or suspended (Article 17.11 of the General Terms).

Credits. Unused top-up credits are forfeited when the account is closed and are not refundable, except in the cases provided for in Article 7.5 of the General Terms: remember to use them before you leave.

Technical impossibility. If the 30-day transition period proves technically unfeasible, we notify you within 14 working days of your request, stating our reasons, and propose an alternative period not exceeding 7 months.

Cessation of business. If we permanently cease operating the service, we notify you at least 90 days in advance and export remains available throughout that notice period (Article 17.14 of the General Terms). For the Enterprise Plan only, a continuity licence also allows you to deploy the service on your own infrastructure, from a deployment package and a complete export that we deliver to you (Article 12 of the Enterprise Specific Terms).

2. Register of data structures and formats#

This register meets Article 26(b) of the Data Act. It is updated whenever the exported data model changes.

Data setStructureHow to obtainAvailable formatsStandard / specification
Records (contacts, companies, opportunities, products, custom objects)One row per record; columns = fields of the Organization's data model, relationships includedSelf-serviceCSV (UTF-8, RFC 4180), XLSX, JSONRFC 4180, RFC 8259
Data modelObjects, fields, types, enumeration options, relationshipsSelf-serviceCSV or JSONRFC 4180, RFC 8259
Notes and tasksOne row per item, with linking identifiersSelf-serviceCSV, XLSX, JSONRFC 4180, RFC 8259
PipelinesPipelines and stages, with the position of recordsSelf-serviceCSV or JSONRFC 4180, RFC 8259
Files attached to recordsFiles in their original format, with linking identifiersSelf-serviceOriginal formatNot applicable
AI Outputs retained in recordsScores, enrichments stored in the fields of a recordSelf-service, with the recordIncluded in the record exportNot applicable
Organization and permissionsUsers, roles, permissions, teamsSelf-serviceCSV or JSONRFC 4180, RFC 8259
Working configurationLists, views, filters, dashboards, message templates, sequencesSelf-serviceCSV or JSONRFC 4180, RFC 8259
Integration settingsConnected integrations, linked accounts, synchronization rules, excluding authentication secretsSelf-serviceCSV or JSONRFC 4180, RFC 8259
ConsumptionCredit consumption history, including telephonySelf-serviceCSV or JSONRFC 4180, RFC 8259
TimestampsAll exportsNot applicableISO 8601 / RFC 3339ISO 8601
IdentifiersAll exportsNot applicableInternal record identifiersNot applicable

Open interfaces. The REST API (https://platform.kasar.app/api-docs) and the MCP server are documented and accessible free of charge, on the same terms for all customers and for the destination providers they designate, to enable the development of the software needed for portability and interoperability (Art. 30(2)). General documentation: https://docs.kasar.app.

Known technical limitations, stated under Article 26(a):

  • integration authentication secrets (OAuth tokens, API keys) cannot be exported, for security reasons: connections must be re-established with the destination provider;
  • self-service exports are limited to 10,000 rows per object per operation, and the API is subject to rate limits; beyond that, exports go through successive operations, still on a self-service basis (Section 1);
  • interactions synchronized from connected services (emails, messages, calls, meetings, calendar), their recordings, transcripts and analyses are not part of the exportable data: they remain available in your source services (Appendix 1 of the General Terms). For the Enterprise Plan only, these data may be exported on request sent to support@kasar.app;
  • as the common interoperability standards referred to in Article 30(3) have not yet been published in the Union's central repository for this category of service, exports are provided in structured, commonly used and machine-readable formats, in accordance with Article 30(5). Compatibility with these standards will be ensured within twelve (12) months of their publication.

3. Infrastructure jurisdictions (Art. 28(1)(a))#

The primary hosting of customer data (database, file storage) is located in Ireland (European Union), and the application runs in France. Some processing is, however, carried out in the United States: synchronization and asynchronous processing (emails, LinkedIn and WhatsApp messages, imports, automations) and the meeting recording bot, on a DigitalOcean cluster located in New York; call routing for native telephony (Twilio); and certain AI features. Migration of the DigitalOcean cluster to a European Union region is planned. In addition, several providers are companies governed by U.S. law or have a parent company that is, regardless of the hosting region.

ProviderRoleProcessing regionJurisdiction of the contracting entity
SupabasePostgreSQL database, file storageIreland (AWS eu-west-1)United States (parent company)
VercelApplication execution, monitoringFrance (cdg1)United States (parent company)
DigitalOcean, LLCSynchronization and asynchronous processing, WhatsApp gateway, meeting recording botUnited States (New York, nyc1); migration to the EU plannedUnited States
UpstashCache, processing queues, presenceRegion stated in Upstash's termsUnited States (parent company)
AWS S3Meeting and call recordingsIreland (eu-west-1)United States (parent company)
Anthropic Ireland, LtdAI models (assistant, analysis, summarization, web search)Contracting party in Ireland; inference possible in the United States, Europe, Asia or AustraliaIreland (EU); parent company in the United States
Deepgram, Inc.Audio transcriptionUnited StatesUnited States
OpenAISpeech synthesis; fallback transcriptionUnited StatesContracting party and safeguards according to the OpenAI DPA; parent company in the United States
DropcontactBusiness email address searchFranceFrance
TwilioNative telephonyUnited States (call routing); Ireland (storage of recordings)United States (parent company)
StripePaymentsEU / United StatesIreland / United States
ResendTransactional emailsUnited StatesUnited States

The complete and up-to-date list of sub-processors, with the applicable transfer safeguards, is set out in Appendix 3 to the DPA.

4. Measures against international governmental access (Art. 28(1)(b))#

  • Location. Primary hosting (database, file storage) is deployed in a European region. Processing carried out outside the Union is listed in Section 3 and in Appendix 3 to the DPA.
  • Encryption. Encryption in transit (TLS) between users and the service and with sub-processors, and AES-256-GCM encryption at rest of communication content and of access secrets for third-party services. Content needed for synchronization and AI features is decrypted in order to be processed.
  • Segregation. A dedicated database schema per organization, logical isolation for each transaction, role-based access and logging.
  • Contractual commitments. For each transfer outside the EU, the Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) or the safeguards provided for in the provider's DPA, supplemented, where relevant, by the supplementary measures recommended by the EDPB (Recommendations 01/2020). Our AI model providers do not use the transmitted content to train their models (Article 13.3 of the General Terms); they may retain it temporarily, according to their terms (Article 13.4 of the General Terms).
  • Handling of requests. Any request from a third-country authority is examined in light of Article 32 of the Data Act: Kasar does not transfer any non-personal data held in the Union on the basis of a foreign decision that is not based on an international agreement in force, unless the cumulative conditions of Article 32(3) are met, and, in case of doubt, defers to the opinion of the competent national authority for international legal cooperation.
  • Minimization. Where a request must be complied with, only the minimum amount of data permitted is disclosed.
  • Customer information. The customer is informed of the existence of the request before it is complied with, except for law enforcement purposes and only for as long as necessary to preserve the effectiveness of the investigation.