Trust & data protection
Last updated: 2026-08-19
How Kartafla handles your data, where it is stored, and who else touches it. If you are evaluating Kartafla and need something that is not here — a data processing agreement, or a completed security questionnaire — email support@kartafla.com and we will send it.
At a glance
- Operated by
- Machariel OÜ, registry code 17573220, Sepapaja tn 6, Tallinn 15551, Estonia
- Data controller
- Machariel OÜ
- Data residency
- Your data is stored in the European Union (Germany) and has never been stored elsewhere
- Sub-processors
- Published in full on /privacy, with what each one receives and why
- Data processing agreement
- Available on request
- Security questionnaire
- Completed on request, once per year per customer
Compliance
Kartafla is built to the GDPR as an EU-established controller. We maintain records of processing under Art. 30, a documented personal data breach procedure under Art. 33, and published retention periods that are enforced automatically rather than by hand.
How long we keep things
These are the periods the system enforces, not targets.
- Account data
- For as long as the account exists. Delete it yourself from Settings at any time; cancelling a plan does not delete anything
- Free-scan IP addresses
- 30 days, then redacted
- Free-scan email addresses
- 180 days, then removed
- Server access logs
- 30 days
- Per-call AI usage records
- 90 days, then only monthly totals
- Unsubscribe records
- Kept indefinitely, on purpose — it is how we remember not to email you
Your rights
Access, deletion, export and correction. Email support@kartafla.com from the address on your account and we respond within 30 days.
Deleting your account from Settings removes your projects, keywords, scan results and email enrolments, including the marketing list. The one thing we keep is your unsubscribe record, because deleting that would let a future signup on the same address be emailed again.
Reporting a vulnerability
Email support@kartafla.com with steps to reproduce. We acknowledge within three working days. We do not run a paid bounty, and we will not pursue anyone who reports a genuine issue in good faith without accessing or altering other people’s data. Please give us a reasonable window to fix an issue before disclosing it publicly.