Trust & data protection

Last updated: 2026-08-19

How Kartafla handles your data, where it is stored, and who else touches it. If you are evaluating Kartafla and need something that is not here — a data processing agreement, or a completed security questionnaire — email support@kartafla.com and we will send it.

At a glance

Operated by
Machariel OÜ, registry code 17573220, Sepapaja tn 6, Tallinn 15551, Estonia
Data controller
Machariel OÜ
Data residency
Your data is stored in the European Union (Germany) and has never been stored elsewhere
Sub-processors
Published in full on /privacy, with what each one receives and why
Data processing agreement
Available on request
Security questionnaire
Completed on request, once per year per customer

Compliance

Kartafla is built to the GDPR as an EU-established controller. We maintain records of processing under Art. 30, a documented personal data breach procedure under Art. 33, and published retention periods that are enforced automatically rather than by hand.

How long we keep things

These are the periods the system enforces, not targets.

Account data
For as long as the account exists. Delete it yourself from Settings at any time; cancelling a plan does not delete anything
Free-scan IP addresses
30 days, then redacted
Free-scan email addresses
180 days, then removed
Server access logs
30 days
Per-call AI usage records
90 days, then only monthly totals
Unsubscribe records
Kept indefinitely, on purpose — it is how we remember not to email you

Your rights

Access, deletion, export and correction. Email support@kartafla.com from the address on your account and we respond within 30 days.

Deleting your account from Settings removes your projects, keywords, scan results and email enrolments, including the marketing list. The one thing we keep is your unsubscribe record, because deleting that would let a future signup on the same address be emailed again.

Reporting a vulnerability

Email support@kartafla.com with steps to reproduce. We acknowledge within three working days. We do not run a paid bounty, and we will not pursue anyone who reports a genuine issue in good faith without accessing or altering other people’s data. Please give us a reasonable window to fix an issue before disclosing it publicly.