Privacy Policy
1. Controller and Purpose
The data controller is:
KIWacht
info@kiwacht.de
KIWacht enables you to classify support requests from **any system** (email, chat, CRM) using rules or optional AI — while keeping your data under your control.
2. Zero-Data Architecture
KIWacht is designed with **no database and no persistent storage**:
- All processing happens **in your automation environment** (e.g., Google Apps Script)
- KIWacht **never receives your messages directly** — only your script sends data
- When AI is used, text is **discarded immediately after classification**
- We store **no email content, headers, IPs, or metadata**
This ensures **maximum security**, **GDPR alignment**, and **predictable costs**.
3. Optional AI Processing
If you enable AI classification:
- Your script sends text to our API
- We forward it to OpenAI **only for that single request**
- OpenAI processing uses **EU Standard Contractual Clauses (SCCs)**
- **Training is disabled** — your data is not used to improve models
You can disable AI at any time — KIWacht will continue working with your keyword rules.
4. Usage Tracking
We use **Upstash Redis** to count API usage per key (e.g., 42/80 requests). This data is:
- **Anonymized** (no user identity linked)
- **Auto-deleted after 31 days**
- **Never includes message content**
5. Your Rights
You have the right to access, rectify, or delete your data. Since we store **no personal data**, these rights are fulfilled by design.
6. Contact
For privacy inquiries, contact:info@kiwacht.de