Kasar

Privacy Policy

Version: 2026-09-28 · Last updated: September 28, 2026

This English version is provided for convenience only. In the event of any discrepancy, the French version prevails.

This Policy describes how KASAR ("Kasar", "we") processes the personal data for which it is the controller:

  • that of visitors to its website kasar.app (audience measurement, traffic source, chat, meeting booking);
  • that of its prospects;
  • that of Users of the KasarCRM platform, for the management of their account and of the contractual relationship.

It also describes, for the information of Users and of the platforms concerned (Google, Meta), what the Service does with data from the integrations a User connects (sections 8 to 11).

Scope. For the data that our customers store or synchronize in their CRM workspace (contacts, emails, conversations, events, leads, etc.), the Customer is the controller and Kasar acts as processor, under the conditions of the Data Processing Agreement (DPA) (dpa.md) and of the General Terms (cgv.md). Sections 8 to 11 below describe that processing without changing this allocation of roles.

1. Controller and contact#

  • Controller: KASAR, SAS with a share capital of €1,000, 60 rue François Ier, 75008 Paris, registered with the Paris Trade and Companies Register (RCS) under number 999 602 865.
  • Data protection contact: support@kasar.app.

2. Data we collect#

CategoryDataSource
Website visitPages viewed, country derived from the IP address, device and browser type, time spent, scroll depth, elements clicked, page performance metricsAutomatic (section 4.1)
Traffic sourceSource, channel, campaign, referring site, landing page, type of ad click identifier, outreach campaign identifier where applicableAutomatic, with your consent (section 4.2)
Website chatMessages exchanged, email address if you provide it, technical session information (browser, page viewed)You / Crisp (section 4.3)
Meeting bookingName, email address, chosen time slot, information you enter, traffic sourceYou / Cal.com (section 4.4)
Guide readingGuide viewed, reading progress, traffic sourceAutomatic (section 4.5)
User accountLast name, first name, email address, profile picture, job title, account statusYou / your identity provider (e.g. Google)
OrganizationOrganization name, identifier, administrator roleYou
BillingSubscription and payment customer identifiers, plan, subscription status and due datesYou / our payment provider Stripe
Platform login / usageSessions, activity logs, AI usage logs (volumes, costs, without the content), application audience and performance metricsAutomatic
Error reportsOrganization and user identifier, URL and technical details of the errorAutomatic
Support and communicationsExchanges with our support, transactional emailsYou
ProspectsBusiness contact details, commercial exchangesYou / professional sources

We never store your payment card data: it is transmitted directly from your browser to our payment provider (Stripe).

PurposeLegal basis (Article 6 GDPR)
Create and manage your account, provide the ServicePerformance of the contract (Art. 6(1)(b))
Bill the subscription and manage paymentsPerformance of the contract / legal obligation (Art. 6(1)(b) and (c))
Ensure security, prevent fraud and abuseLegitimate interest (Art. 6(1)(f))
Measure the audience and performance of the website and the application, fix errorsLegitimate interest (Art. 6(1)(f))
Know where visitors and requests come from (section 4.2)Consent (Art. 6(1)(a)), collected for the placing of the cookie (section 5)
Answer your chat messages and organize the meetings you bookPre-contractual steps taken at your request (Art. 6(1)(b)) / legitimate interest
Track the reading of guides sent to our prospects (section 4.5)Legitimate interest (Art. 6(1)(f))
Respond to your support requestsPerformance of the contract / legitimate interest
Send you marketing communications about similar productsLegitimate interest, with a right to object / consent where required
Comply with our legal and accounting obligationsLegal obligation (Art. 6(1)(c))

4. The kasar.app website#

The website is hosted by Vercel (running in France). Your requests are logged there (IP address, page requested) for security and abuse prevention; the IP address is also used, transiently, to rate-limit certain routes (Upstash).

4.1 Audience measurement: PostHog, without cookies#

We measure the website's audience with PostHog (PostHog Cloud EU, hosted in the European Union), called from our own domain. The following are recorded: pages viewed, country derived from the IP address, device and browser, time spent, scroll depth, elements clicked and page performance metrics (Web Vitals).

  • No cookie and no local storage is placed by this measurement: PostHog is configured in cookieless mode, with state held in memory for the life of the page. To tell visits apart, PostHog computes server-side a hashed identifier (IP address, browser, salt) that changes every day and cannot recognize you from one day to the next.
  • No session recording (video or replay) is made.
  • Your browser's "Do Not Track" signal is honored: when it is on, no measurement is sent.
  • This data is not linked to your identity, is not sold and is not used for any ad targeting.

Legal basis: legitimate interest. Consent: not required, since no information is read from or stored on your device. You may object by writing to support@kasar.app or by turning on "Do Not Track".

When you arrive on kasar.app from another site, a search engine, an AI assistant, an ad or a link we sent you, we record that source, if you have consented to it, in a kasar_attr cookie, placed on the .kasar.app domain for 180 days. It contains: the source, channel, campaign name and its parameters (utm_term, utm_content), the referring site, the landing page, the type of ad click identifier detected (for example gclid, without its value) and the date of each attributed visit (first and last).

  • When you arrive through a link from one of our outreach campaigns, the utm_content parameter may contain a prospect identifier specific to that campaign: the cookie then allows your visit to be linked to that prospect.
  • The cookie contains neither your name, nor your email address, nor any third-party advertising identifier. It is not read by ad networks and is not used to track you on other sites.
  • It is read by the platform.kasar.app platform at sign-up, by our server when you read a guide (section 4.5), and passed to Cal.com as UTM parameters when you book a meeting (section 4.4).
  • No cookie is placed if your visit carries no source information (internal navigation or direct access), or if you have not given your consent.

Purpose: learn which channels make us known and where requests come from. Legal basis: your consent. As this cookie is not among the trackers exempt from consent, it is placed only with your agreement, which you may withdraw at any time (see section 5). You can also ask us to delete the source attached to your request.

4.3 Live chat (Crisp)#

The website includes the chat module of Crisp (Crisp IM SAS, France). This module is loaded only on your initiative, when you open the chat: no information is read from or stored on your device by Crisp before that action. Once the chat is open, Crisp writes into your browser's local storage a chat session identifier (crisp-client/session/…), so as to keep the conversation from one page to the next, and may place its own technical session cookies. If you write in the chat, your messages, the email address you provide and technical session information (browser, page viewed) are sent to Crisp, which hosts them on our behalf.

Purpose: answer your questions. Legal basis: pre-contractual steps taken at your request / legitimate interest. Consent: not required, as these trackers are strictly necessary for the chat service you expressly requested by opening the chat (see section 5). Duration: set by Crisp for its session; conversations are kept under the conditions applicable to prospects (section 13).

4.4 Meeting booking (Cal.com)#

The "See a demo" buttons open a booking window provided by Cal.com (Cal.com, Inc., United States). The Cal.com module is loaded only on your initiative, when you open the booking window; it then sends Cal.com your IP address and the technical information of the request. Kasar places no cookie on that occasion. When you book, the data you enter (name, email, time slot, answers) and your traffic source (section 4.2) are processed by Cal.com, which may place its own technical cookies in its booking window. The same module is used in the platform to book an onboarding call.

Purpose: organize the meeting you requested. Legal basis: pre-contractual steps taken at your request. Transfer outside the EU: yes (section 12).

4.5 Guide reading#

Our guides, shared by direct link in our campaigns, measure reading progress (opening, scrolling, completion). Each event is sent to PostHog (section 4.1) and to our own server, which reads the traffic source cookie where you have consented to it (section 4.2): when that cookie carries a prospect identifier, the reading is linked to that prospect so that we can adapt our commercial follow-up. These events are kept in our host's logs (Vercel), then in our CRM under the conditions applicable to prospects.

Legal basis: legitimate interest (B2B prospecting), with a right to object at any time at support@kasar.app.

5. Cookies and trackers#

The table below lists the trackers actually placed or read, on the website and on the platform. "Consent" refers to the rules of Article 82 of the French Data Protection Act (implementing the ePrivacy Directive).

TrackerIssuer / locationPurposeLegal basisDurationConsent
PostHog measurementWebsiteAudience and performance measurementLegitimate interestNothing stored (page memory)Not required (nothing stored)
kasar_attrWebsite, .kasar.app domainSource of visits and requestsConsent180 daysRequired; collected through the banner
crisp-client/session/… (local storage) and Crisp cookiesCrisp, on the website, when the chat is openedChat sessionPre-contractual steps taken at your requestSet by CrispNot required (service requested)
Cal.com window cookiesCal.com, when the booking opensBooking operationPre-contractual stepsSet by Cal.comNot required (service requested)
next-auth.session-tokenPlatformAuthentication sessionPerformance of the contract30 daysNot required (strictly necessary)
kasar-authPlatformSecure database access tokenPerformance of the contract4 hoursNot required
kasar_signed_inPlatform, .kasar.app domainTells the website you are signed in (value 1, no identity)Legitimate interest30 days, deleted at sign-outNot required (user-requested interface customization)
Integration authorization cookies (OAuth state, extension code)PlatformSecurity of connecting an integration or the extensionPerformance of the contract5 to 10 minutesNot required
kasar-tzPlatformDisplay time zonePerformance of the contract1 yearNot required
View preference (kanban) and kasar_meta_vPlatformDisplay preferences and interface cachePerformance of the contract1 year / 24 hoursNot required
kasar-ws-transitionPlatformWorkspace switchingPerformance of the contract30 secondsNot required
kasar-impersonationPlatformSupport access to an account, display of the related bannerLegitimate interest / performance of the contract24 hoursNot required
Vercel Web Analytics and Speed InsightsPlatformApplication audience and performance measurementLegitimate interestNo cookieNot required (nothing stored)

Consent collection. On your first visit, a banner lets you accept or refuse, as easily as one another, the trackers that require consent. Until you accept, none of these trackers is placed, and the website remains fully usable if you refuse. You can withdraw your consent at any time, as easily as you gave it, from the website. The Crisp chat and the Cal.com booking window are loaded only when you open them. No advertising tracker (Meta pixel, Google Ads tag, LinkedIn Insight or other) is loaded on the website or on the platform.

6. Recipients and processors#

Your data is accessible to Kasar's authorized staff and to our processors acting on our behalf:

  • platform (full list in Annex 3 of the DPA): Supabase (database and file storage), Vercel (application hosting, monitoring and error reports, audience and performance measurement), Upstash / Redis (cache, processing queues), DigitalOcean (synchronization and asynchronous processing infrastructure, WhatsApp gateway), Amazon Web Services S3 (recordings), Twilio (native telephony), Dropcontact (business email lookup), Stripe (payment), Resend (transactional emails), Anthropic, Deepgram and OpenAI (AI features, section 7);
  • website: Vercel (hosting), Upstash (abuse prevention), PostHog (audience measurement), Crisp (chat), Cal.com (meeting booking).

We do not sell your data. We only disclose it to third parties in the cases provided for in this Policy or where required by law (judicial or administrative authority).

7. Artificial intelligence providers#

The Service's AI features are provided by Anthropic (text generation, analysis, summarization, the Léo assistant), Deepgram (transcription of meetings, calls and voice memos) and OpenAI (speech synthesis of Léo's answers, fallback transcription). These providers are called directly, through their commercial APIs, without any gateway or aggregator; the relevant content is sent to them for processing (Section 13 of the General Terms).

  • Anthropic: Kasar has signed a zero-retention addendum with Anthropic: the content sent is processed to produce the answer and is then not retained by Anthropic, except where required by law or to combat use contrary to its usage policy. Anthropic does not use it to train its models.
  • OpenAI does not use this content to train its models under its API terms; it may retain it temporarily, notably for 30 days for abuse monitoring.
  • Deepgram may temporarily retain the audio content sent, under its API terms; it does not use it to train or improve its models (Section 13.3 of the General Terms).

Kasar does not use its Users' data or data from integrations to train AI models.

8. Google data (Gmail, Google Calendar, Google Meet)#

When you connect a Google account, the Service requests the following permissions: gmail.modify (reading, sending and organizing your emails), calendar (reading and writing your calendars) and, if you enable transcript retrieval, meetings.space.readonly (Google Meet transcripts). A connected Microsoft (Outlook) account is handled in the same way for emails and calendar.

8.1 Google Calendar: data accessed#

  • the list of your calendars (names, identifiers);
  • the events in your calendars: title, description, dates and times, location, attendees, response status, recurrence, video conference link;
  • the associated metadata: event identifiers, creation and modification dates, time zones.

8.2 Use#

Google Calendar data is used exclusively to:

  • display your events in Kasar's calendar;
  • create and modify, at your request, events in Google Calendar from Kasar;
  • link your events to the contacts and opportunities in your CRM, and prepare or summarize your meetings when you use those features.

Gmail data is used exclusively to synchronize your exchanges with your CRM records, display your inbox in Kasar and send the emails you write or schedule. Google Meet transcripts are only retrieved for meetings in your calendar, to link them to your records and summarize them.

8.3 Storage and retention#

Synchronized Google data is stored in your Organization's isolated area, in our database hosted by Supabase in Ireland (EU). Its synchronization is run by our processing servers, located in the United States as of today (DigitalOcean, section 12). It is kept in your Organization, as your CRM history, for the term of the contract: disconnecting your Google account stops synchronization but does not delete the data already synchronized. It is deleted earlier if you delete it yourself from Kasar or ask us to do so (section 8.7), and at the latest at the end of the contract, under the conditions of Section 17 of the General Terms.

8.4 Sharing#

Google data is not disclosed to any third party, other than our hosting and processing processors (section 6) and, when you use an AI feature on that data (summary, drafting, the Léo assistant), the AI providers in section 7, only to the extent needed for that feature. Within Kasar, it is only accessible to the members of your Organization, according to the permissions set in your workspace.

8.5 What Kasar does not do with your Google data#

  • Kasar does not sell or transfer your Google data to advertising platforms, data brokers or information resellers;
  • Kasar does not use your Google data to serve advertising, targeting or retargeting;
  • Kasar does not use your Google data to determine creditworthiness or for lending purposes;
  • Kasar does not use your Google data to develop, improve or train generalized artificial intelligence or machine learning models;
  • no human at Kasar reads your Google data, except (a) with your explicit consent, for example when you ask support to intervene, (b) for security purposes, such as investigating abuse, (c) to comply with applicable law, or (d) on aggregated and anonymized data for internal operations.

8.6 Compliance with the Google API Services User Data Policy#

Kasar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8.7 Revocation#

You can disconnect your Google account at any time from Kasar's integration settings, or revoke access from https://myaccount.google.com/permissions. Revocation stops synchronization: Kasar no longer accesses your Google account.

The Google data already synchronized (emails, events, transcripts) remains in your Organization as Customer Data (as defined in the General Terms), as part of your CRM history, until the first of the following occurs (Section 10.3 of the General Terms):

  • you delete it from Kasar;
  • you request its deletion at support@kasar.app, which may cover all the data synchronized from a given Google account;
  • the contract ends (Section 17 of the General Terms).

9. Meta Lead Ads (Facebook and Instagram)#

Kasar allows an advertiser to connect a Facebook Page to automatically receive in its CRM the leads from its instant forms (Lead Ads), on Facebook and Instagram. The advertiser is the controller of these leads; Kasar acts on its behalf.

9.1 Data accessed#

  • the answers entered by the person in the advertiser's form: typically name, email address, phone number, company, and any custom question defined by the advertiser;
  • the lead's metadata: lead identifier, submission date, source form, organic or paid nature, identifiers of the ad, ad set and campaign;
  • the list of Pages you manage (name, identifier), so that you can choose which one to connect.

9.2 Use#

Meta data is used exclusively to create or enrich a record in the advertiser's workspace, so that it can contact the people who asked to be contacted, and to link each lead to the campaign that generated it.

9.3 Storage and retention#

Each lead is written to the isolated database area of the Organization concerned, hosted by Supabase in Ireland (EU). Leads are never pooled between advertisers. They are kept in the Organization, as its CRM history, for the term of the contract, including after the Page is disconnected, until they are deleted by the advertiser, the advertiser requests their deletion (section 9.6) or the contract ends.

9.4 Sharing#

Leads from Meta are not disclosed to any third party, other than our processors (section 6). They are only accessible to the members of the Organization that owns the connected Page, according to the permissions set in its workspace.

9.5 What Kasar does not do with Meta data#

  • Kasar does not sell or transfer leads to advertising platforms, data brokers or information resellers;
  • Kasar never pools leads between advertisers;
  • Kasar does not use leads to serve advertising, targeting or retargeting;
  • Kasar does not use leads to determine creditworthiness or for lending purposes;
  • Kasar does not use leads to train AI models;
  • no human at Kasar reads this data, except (a) with the advertiser's explicit consent, (b) for security purposes, or (c) to comply with applicable law.

9.6 Disconnection and deletion#

The advertiser can disconnect a Page at any time from the integration settings: Kasar then removes the lead notification subscription for that Page, and no new lead is received. Access can also be revoked from the Facebook account settings. In accordance with Section 10.3 of the General Terms, leads already received from that Page remain in the Organization as Customer Data, until they are deleted by the advertiser from Kasar, the advertiser requests their deletion or the contract ends. Any deletion request, including from a person whose data has been received, can be sent to support@kasar.app; the procedure is described at https://kasar.app/data-deletion.

10. WhatsApp#

Kasar allows you to link a WhatsApp account to find your business conversations in the CRM. Linking is done by scanning a QR code: Kasar becomes a device linked to your account, like WhatsApp Web. This connector is not based on any partnership with Meta (Section 10.6 of the General Terms).

10.1 Data accessed#

Once the account is linked, Kasar accesses:

  • the list of your conversations, individual and group, with the date of their last message;
  • the content of messages exchanged, including attachments, images and voice messages;
  • your contacts' identifiers: phone number, WhatsApp technical identifier, profile name they chose and, when WhatsApp provides it, the name you gave them in your address book;
  • their profile picture and the membership of the groups you belong to.

10.2 The conversation index#

To display a complete and up-to-date conversation list, Kasar keeps a technical index of the linked account's conversations: for each one, the contact's identifier, the date of the last message and a truncated excerpt of it, encrypted at rest.

This index lists every conversation passing through the account, including with people who are not records in your CRM. For the duration of the link, it is therefore a record of who talks to whom. Being in this index is not being recorded in the CRM: only the conversations you add explicitly, or that your synchronization rules admit, result in interactions being recorded on a record.

10.3 Processing locations#

The WhatsApp session and message routing are handled by our gateway, hosted in the United States as of today (DigitalOcean, section 12). The index and recorded interactions are stored in your Organization's isolated area, hosted by Supabase in Ireland (EU), and are never pooled between Organizations. Profile pictures are not stored: they are relayed on demand from WhatsApp.

10.4 Disconnection and deletion#

When you disconnect the account from Kasar, synchronization stops, and the WhatsApp session and the conversation index (section 10.2) are deleted immediately.

Messages already recorded in the CRM, that is, the interactions linked to your records, remain in your Organization as Customer Data, as part of your CRM history. In accordance with Section 10.3 of the General Terms, they remain there until you delete them from Kasar, you request their deletion at support@kasar.app, or the contract ends.

10.5 What Kasar does not do with your WhatsApp data#

  • Kasar sends no message on your behalf without an action on your part (manual sending, or a sequence or automation you configured);
  • Kasar does not sell or transfer your conversations or contacts to third parties;
  • Kasar never pools this data between Organizations;
  • Kasar does not use the content of your conversations to train AI models;
  • no human at Kasar reads your messages, except (a) with your explicit consent, (b) for security purposes, or (c) to comply with applicable law.

10.6 Your contacts#

Use of WhatsApp remains governed by Meta's terms. Your contacts are not informed that your account is linked to Kasar: as the controller of your workspace, it is up to you to inform them where your context requires it.

11. Kasar Chrome extension#

The Kasar Chrome extension ("Kasar CRM" on the Chrome Web Store) is optional. You install it on your own initiative and link it to your Kasar account; as long as you are not signed in to Kasar, it transmits no data to the Service. The data it transmits is data of your CRM workspace, for which your Organization is the controller (see "Scope" at the beginning of this Policy and Section 10.7 of the General Terms).

11.1 Sites and functions#

The extension only operates on the following sites, and only for the functions indicated.

SiteWhat the extension readsWhenWhat is transmitted to the Service
LinkedInAddress and name of the profile, company or correspondent displayed; profiles in search results; data of the profile or company you importCheck: when the page is displayed. Import: on your clickCheck: the profile or company address, the name and, where applicable, the email address displayed, to show whether they are already in your CRM. Import: the profile or company data
GmailName and email address of the sender and recipients of the open thread, their company domain, thread subjectCheck: when a thread is opened. Add: on your clickCheck: names, email addresses and domains of the correspondents, to show whether they are in your CRM. Add: the contact or company chosen. Neither the subject nor the content of emails is transmitted
WhatsApp WebName, phone number and picture of the correspondent in the open conversationCheck: when the Kasar panel is open. Add: on your clickCheck: number and name. Add: the contact. Message content is not read
Google CalendarNothingNeverNothing: the extension only adds a shortcut to the Kasar panel
Google Meet, Microsoft Teams, ZoomDuring a recording you have started: see section 11.3On your "Start" clickSee section 11.3
Kasar platform (platform.kasar.app)Status of your Kasar sessionAt sign-in and sign-outNothing more: the platform informs the extension that you are signed in and may ask it, upon your action, to link your LinkedIn account (section 11.2)

Side panel and search. When you open the Kasar panel, it displays the record matching the active tab: on a site other than those above, the domain of the site displayed is transmitted to the Service to find the matching company in your CRM, and its icon is loaded from Google's icon service (google.com/s2/favicons), which receives that domain. The search shortcut (Ctrl+Shift+K, or Cmd+Shift+K on Mac) opens a search bar in the active tab and only transmits the terms you type.

Data transmitted for a mere check is used only to display the status of the record; it neither creates nor modifies any record. Only your add, update, import or recording actions record data in your CRM.

11.2 Linking your LinkedIn account#

When you click Connect (or Re-sync) to link your LinkedIn account to the messaging connector (Section 10.6 of the General Terms), the extension transmits to the Service:

  • the session cookies of linkedin.com, including your account's authentication cookie;
  • the identity of your LinkedIn account (identifier, name, picture, profile address);
  • technical characteristics of your browser: user agent, language, technical headers sent by your browser to LinkedIn;
  • an approximate location (country, region, city, internet service provider), derived from your IP address.

These items are used only to synchronize your LinkedIn conversations with your CRM, on your behalf, from a connection point close to yours and with the characteristics of your browser. They are kept for as long as the connector is active, the cookies being encrypted, and deleted when it is disconnected. To detect a change of session, the extension keeps locally a fingerprint of your LinkedIn cookie, never the cookie itself. If you enable the message synchronization option, importing a contact triggers the synchronization of their conversation by the Service.

11.3 Meeting recording#

Recording only starts when you click "Start" in the extension window, on the meeting tab. It stops when you stop it, at the end of the meeting or when the tab is closed. During recording, the extension captures:

  • the audio and video of the meeting tab;
  • your voice;
  • the audio of each participant, to attribute speech;
  • the list of participants (name and, when displayed, email address), the active speaker and, if you have turned them on, the meeting's captions.

Nothing is captured before you start recording. The meeting's text chat is not captured. This data is transmitted, over an encrypted connection, to our recording service (meeting-bot.kasar.app), which produces the recording, the transcript and the summary and links them to your CRM records. Recordings are stored with Amazon Web Services S3 (section 6) and kept as Customer Data (section 13). It is your responsibility to inform the participants before starting the recording and, where applicable, to obtain their consent (Section 13.13 of the General Terms).

11.4 Permissions requested#

PermissionUse
Access to the sites listed in section 11.1, to platform.kasar.app and to meeting-bot.kasar.appDisplay the Kasar buttons and panel on those sites; communicate with the Service
storageKeep locally your preferences, your Kasar session token and the status of a recording in progress (section 11.6)
tabs and activeTabKnow which site is displayed to offer the appropriate function; open search and the panel on the active tab, at your request
cookiesRead your platform.kasar.app session cookie to authenticate you; read the linkedin.com cookies when linking your LinkedIn account (section 11.2)
webRequestOn linkedin.com only: read the cookies and technical headers sent by your browser, to link your LinkedIn account (section 11.2). No request is blocked or modified
scriptingRedisplay the extension's functions on tabs already open after an update; open search on the active tab
tabCapture, offscreenCapture the audio and video of the meeting tab during a recording you start (section 11.3)
sidePanelDisplay the Kasar side panel
notificationsAlert you to a recording error

11.5 Third parties#

The extension's data is transmitted only to the Service (platform.kasar.app) and to our recording service (meeting-bot.kasar.app), and processed by our processors (section 6), with two technical exceptions:

  • in Gmail, the extension uses the InboxSDK library (Streak), which sends its publisher error reports and technical usage events, identified by a fingerprint of your email address, without the content of your emails;
  • Google's icon service receives the domain of the companies displayed (section 11.1).

11.6 Local storage and uninstallation#

The extension keeps in your browser your interface preferences, a short-lived Kasar session token, the status of a recording in progress and, if you have linked LinkedIn, your LinkedIn account identifier and the fingerprint described in section 11.2. No password is stored there. Signing out of Kasar erases the token and the LinkedIn data; uninstalling erases everything, without affecting data already recorded in your Organization (Section 10.3 of the General Terms).

11.7 Code and limited use#

The extension runs no remote code: all its code is included in the package published on the Chrome Web Store. Its requests to the Service are encrypted (HTTPS or WSS).

The use of information received by the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. In particular, Kasar uses this information only to provide the functions described above, does not sell it, does not use it for advertising or to determine creditworthiness, and only transfers it to the recipients in section 11.5, for those functions only. No human at Kasar reads it, except with your explicit consent, for security purposes or to comply with applicable law.

12. Transfers outside the European Union#

The main hosting of platform data (database, file storage) is located in Ireland (EU) and the application runs in France. Some processing takes place in the United States, notably by:

  • DigitalOcean: synchronization infrastructure (emails, LinkedIn and WhatsApp messages, imports, automations) and WhatsApp gateway, in New York; its migration to the EU is planned;
  • Twilio: call routing for native telephony;
  • Deepgram, OpenAI and, depending on its server routing, Anthropic;
  • Resend, Stripe (in part), Upstash depending on the applicable region;
  • Cal.com, for meetings booked from the website or the platform.

PostHog (website audience measurement) and Crisp (chat) process data in the European Union. Where a provider processes data outside the EEA, the transfer is governed by the European Commission's standard contractual clauses (Decision (EU) 2021/914) or by the safeguards provided in that provider's DPA, together with supplementary measures where appropriate. Details are in Annex 3 of the DPA; you can obtain a copy of the applicable safeguards by writing to support@kasar.app.

13. Retention periods#

DataPeriod
Account and organization dataFor the term of the contract, then deletion at the end of the recovery period provided for in the General Terms (subject to legal obligations)
Data from integrations (Google, Microsoft, Meta, LinkedIn, WhatsApp…)For the term of the contract, including after the integration is disconnected, which only stops synchronization; earlier deletion by you from Kasar or on request at support@kasar.app (Section 10.3 of the General Terms). The WhatsApp session and index are deleted on disconnection
Billing and accounting data10 years (legal accounting obligation)
Record history displayed in the CRM (changes, activities and interactions)Customer Data: for the term of the contract, unless deleted by you
Technical and security logs: login logs, error logs, AI usage logs12 months from when they are recorded
Error reports / telemetryPeriod set by our monitoring provider (Vercel), limited to what is needed to fix errors
Website audience measurement (PostHog)Retention period of our PostHog project, limited to what is needed for measurement
Prospects (including chat, bookings, guide reading)3 years from the last contact
kasar_attr traffic source cookie180 days
Other cookies and trackersSee section 5; 13 months maximum

14. Your rights#

Under the GDPR, you have the rights of access, rectification, erasure, restriction, portability and objection (notably to prospecting and to audience measurement), as well as the right to withdraw your consent at any time and to set instructions regarding the fate of your data after your death.

To exercise these rights: support@kasar.app. We respond within one (1) month, which may be extended by two (2) months given the complexity or number of requests (Article 12(3) GDPR). Where your data is in the CRM workspace of one of our customers, we forward your request to that customer, as controller, and assist it in responding. You may lodge a complaint with the CNIL (www.cnil.fr).

15. Security#

We implement appropriate technical and organizational measures to protect your data: encryption in transit, encryption at rest of the hosting and, for certain content (messages, WhatsApp index excerpts, integration access tokens), application-level encryption; access control; isolation of each Organization's data; logging. Content is decrypted when it has to be processed, notably by AI providers. See also Annex 2 of the DPA.

16. Automated decision-making#

We do not take any decision producing legal effects or significantly affecting you based solely on automated processing within the meaning of Article 22 GDPR.

17. Protection of minors#

The Service is intended for professionals and is not intended for minors. We do not knowingly collect data relating to minors.

18. Changes#

We may amend this Policy. Any substantial change will be brought to your attention by appropriate means. The version and date of last update appear at the top of the document. In the event of any discrepancy between the French version and a translation, the French version prevails.