Privacy policy
Effective 30 September 2026. This policy explains what Dimitar Karaskakovski, trading as Karas ("Karas", "we"), does with personal data when you use our website and when our assistant runs on a customer's website.
Who is responsible for what
Two different relationships, and the distinction decides who you contact.
When you visit a Karas customer's website and use the assistant, that business decides what documentation the assistant uses and what happens to the conversation. They are the controller; we act on their instructions as their processor. Requests about your data should go to that business, and we will support them in answering you.
When you deal with us directly — our own website, an enquiry, a contract — we are the controller.
What we process when someone uses the assistant
The question and the conversation. What a visitor types, the answers given, and the preceding turns of the same conversation, which is what lets a follow-up question make sense.
Ratings and comments. A thumbs-up or thumbs-down, and any comment left with it.
Handoff details. If a visitor asks to speak to a person: the name and email address they give, the page they were on, and the conversation transcript, which is passed to that business's helpdesk.
Technical data. An IP address, used to apply per-visitor rate limits and to keep the service available; a session identifier; and a trace identifier for each request, used to diagnose problems.
Redaction. Payment card numbers, card security codes, passwords and API tokens are detected and removed from conversation text — including the question, answer and comment stored with a rating — before it is stored or passed on. Email addresses and telephone numbers are not removed, because they are how a business replies to its customer.
What we do not do
We do not use conversations to train models, ours or anyone else's. We do not sell personal data, we do not share it for advertising, and we do not build profiles across websites. The assistant has no access to a business's orders, customer records or payment systems.
What we process about our own customers
Business contact details, account and configuration settings, billing information, and correspondence. Lawful basis: performance of the contract, and our legitimate interest in running and securing the service.
Where data is processed
Our own systems — the application, the database, the search process and the cache — run on servers we operate in Vienna.
Two providers process question text on our behalf outside the EEA, in the United States, as described in Subprocessors and where data goes: one generates the wording of each answer, and one converts text into the numeric form used for searching. These transfers rely on the European Commission's standard contractual clauses.
A handoff also sends a transcript to the helpdesk the business has chosen, which is that business's own provider and processes data under their agreement with it.
How long we keep it
Live conversation state: one hour after the last message, then deleted automatically.
Ratings, with the question and answer they relate to: 12 months from the rating, then deleted automatically.
Handoff records: 30 days from the request. The ticket itself lives in the business's helpdesk under their own retention policy.
Server logs: bounded by volume rather than by a fixed period — each service keeps only its most recent output, older lines are discarded as new ones arrive, and application logs are cleared on every release. We keep no long-term log archive. The host's own system log, which records administrative access, is deleted after 30 days.
Customer account and billing records: for the life of the contract and then as long as tax and accounting law requires.
See Data retention and deletion for how to request deletion.
Your rights
If you are in the UK or the EEA you have the right to access your data, correct it, have it deleted, restrict or object to its processing, and receive it in a portable form. You can also complain to your national data protection authority.
Where a business is the controller, ask them first — they hold the relationship and we are required to act on their instruction. If you are not sure who to ask, write to us at dimitar@usekaras.com and we will tell you.
Cookies
Our own website uses only what is necessary to serve the site. The assistant does not set cookies on a customer's domain; it keeps a session identifier and minor interface preferences in the visitor's own browser storage, which never reaches us and is removed when the visitor clears their site data.
Children
The service is sold to businesses and is not directed at children. We do not knowingly process the data of anyone under 16.
Security
Described in full in the Security overview, including what we do not yet have.
Changes
We will update this page and change the effective date. For changes that materially affect our own customers, we will tell them directly.
Contact
The controller is Dimitar Karaskakovski, trading as Karas.
Privacy enquiries, data requests and vulnerability reports: dimitar@usekaras.com. We answer data requests within one month, as the regulation requires, and sooner in practice.
A postal address is available on request and is included in the data processing agreement we sign with customers.