Krealo Chat Sign in

Data processing agreement

This page is written in French. The English and Spanish versions are courtesy translations: if they differ, the French version prevails.

Version 1 — September 21, 2026

What Krealo Media does, and doesn't do, with the personal information that Krealo Chat processes on behalf of a merchant. Everything written here is true today and matches the code; the privacy policy and the Security page say the same thing, in different words.

1. The parties and their roles

The merchant who installs Krealo Chat on their site is responsible for the personal information collected in their conversations: they decide what to ask their customers and why. Krealo Media inc., Montréal (Quebec), is the mandatary (processor): it operates the service on the merchant's behalf and doesn't use this information for anything else.

This agreement is part of the terms of use and applies as soon as a site is created in the console. It lasts as long as the account exists.

2. What is processed

Information From whom Why
Messages, attachments (images and PDFs, 8 MB max.) Visitors and agents It's the conversation itself.
Visitor identifier (in the browser) Visitors Recognize the same thread when the person comes back.
Pages visited, landing page, referrer, language Visitors So the agent knows what they're being asked about.
Device, browser, IP address, approximate city Visitors Language, time zone, abuse limiting.
Name, email, phone — if the person types them Visitors Pick the conversation back up, find their orders.
Cart contents; last five orders for the email given Visitors, through the Shopify store Answer about what the person is buying. Never without their email.
Name, email, photo from the Google account Agents and administrators Sign in to the console.

Krealo Chat never asks for a password or a card number and has no way of receiving one. No information is used for advertising, sold, or cross-referenced with other sources.

3. Where, and the transfer outside Quebec

The data is hosted at Google Cloud (Firebase, Firestore, Cloud Storage), region us-central1, in the United States. This is a transfer outside Quebec within the meaning of section 17 of Law 25: Krealo Media has carried out the corresponding privacy impact assessment and makes it available to the merchant on request. In short: the data is encrypted in transit and at rest, access is limited to two people at the agency through named accounts, Google Cloud is bound by its own contractual processing commitments, and no sensitive information (health, finances, password) is collected by the service.

4. Sub-processors

Who What When
Google Cloud / Firebase (United States) Hosting, database, files, sign-in emails Always
Google — Gemini API Reply draft, summary, voice transcription Only when an agent asks for it, or for the after-hours bot if the merchant turns it on
Shopify Catalogue, cart, orders for the email given Only if the merchant connects their store
Meta (Messenger, Instagram) Messages received and sent on these channels Only if the merchant connects their page
Resend Transactional emails (invitations, delayed reply) Not active yet: as soon as it is, this line will get a date

Adding a sub-processor is done by changing this page and notifying merchants through the what's new page at least 30 days in advance. A merchant who refuses can close their account and export their conversations beforehand.

5. How long

The visitor card (journey, cart, city, device, IP) is automatically anonymized after 30 days without a visit. Conversations are kept as the business's history as long as the account exists. When a person asks for deletion, it's their identity that is erased from the thread — name, email, phone, IP, city — and what remains identifies no one. When the account is closed, nothing is deleted unless the merchant asks; they can request complete erasure, which is carried out within 30 days, or export first.

6. Security

Described in the present tense, with what's missing, on the Security page: encryption, access rules by site and by workspace, one-hour signed links for files, store tokens out of reach of browsers, a daily backup kept for 30 days, an audit log of actions in the console.

7. Helping the merchant with individuals' rights

Access, correction, deletion, withdrawal of consent: the merchant can respond to these themselves from the console (visitor card, export, "Forget this person"). What they can't do alone, Krealo Media does on written request to ken@krealomedia.com within 10 business days. Requests that Shopify forwards (customers/data_request, customers/redact, shop/redact) are processed automatically.

8. Confidentiality incidents

If an incident affects the merchant's information, Krealo Media notifies the merchant without unreasonable delay, no later than 72 hours after becoming aware of it, with what is known at that point: what, who, since when, and what has been done. It keeps the register of incidents required by Law 25 and helps the merchant assess whether the Commission d'accès à l'information and the persons concerned must be notified.

9. Verification

The merchant can ask any question about the processing in writing; Krealo Media answers in writing within 10 business days. The service's code is in a private repository and can be shown on request to verify what this page states.

10. Personnel, governing law and signature

Two people at Krealo Media have access to the data, each with their own account, and only to operate and troubleshoot the service. The agreement is governed by the laws of Quebec. It is accepted by using the service; for a signed version, or one in English, write to ken@krealomedia.com.

Person in charge of the protection of personal information: Keneth Walters, Krealo Media — ken@krealomedia.com.