Data processing agreement
This page is written in French. The English and Spanish versions are courtesy translations: if they differ, the French version prevails.
Version 1 — September 21, 2026
What Krealo Media does, and doesn't do, with the personal information that Krealo Chat processes on behalf of a merchant. Everything written here is true today and matches the code; the privacy policy and the Security page say the same thing, in different words.
1. The parties and their roles
The merchant who installs Krealo Chat on their site is responsible for the personal information collected in their conversations: they decide what to ask their customers and why. Krealo Media inc., Montréal (Quebec), is the mandatary (processor): it operates the service on the merchant's behalf and doesn't use this information for anything else.
This agreement is part of the terms of use and applies as soon as a site is created in the console. It lasts as long as the account exists.
2. What is processed
| Information | From whom | Why |
|---|---|---|
| Messages, attachments (images and PDFs, 8 MB max.) | Visitors and agents | It's the conversation itself. |
| Visitor identifier (in the browser) | Visitors | Recognize the same thread when the person comes back. |
| Pages visited, landing page, referrer, language | Visitors | So the agent knows what they're being asked about. |
| Device, browser, IP address, approximate city | Visitors | Language, time zone, abuse limiting. |
| Name, email, phone — if the person types them | Visitors | Pick the conversation back up, find their orders. |
| Cart contents; last five orders for the email given | Visitors, through the Shopify store | Answer about what the person is buying. Never without their email. |
| Name, email, photo from the Google account | Agents and administrators | Sign in to the console. |
Krealo Chat never asks for a password or a card number and has no way of receiving one. No information is used for advertising, sold, or cross-referenced with other sources.
3. Where, and the transfer outside Quebec
The data is hosted at Google Cloud (Firebase, Firestore,
Cloud Storage), region us-central1,
in the United States. This is a transfer outside Quebec
within the meaning of section 17 of Law 25: Krealo Media has carried
out the corresponding privacy impact assessment and makes it
available to the merchant on request. In short: the data is
encrypted in transit and at rest, access is limited to two people at
the agency through named accounts, Google Cloud is bound by its own
contractual processing commitments, and no sensitive information
(health, finances, password) is collected by the service.
4. Sub-processors
| Who | What | When |
|---|---|---|
| Google Cloud / Firebase (United States) | Hosting, database, files, sign-in emails | Always |
| Google — Gemini API | Reply draft, summary, voice transcription | Only when an agent asks for it, or for the after-hours bot if the merchant turns it on |
| Shopify | Catalogue, cart, orders for the email given | Only if the merchant connects their store |
| Meta (Messenger, Instagram) | Messages received and sent on these channels | Only if the merchant connects their page |
| Resend | Transactional emails (invitations, delayed reply) | Not active yet: as soon as it is, this line will get a date |
Adding a sub-processor is done by changing this page and notifying merchants through the what's new page at least 30 days in advance. A merchant who refuses can close their account and export their conversations beforehand.
5. How long
The visitor card (journey, cart, city, device, IP) is automatically anonymized after 30 days without a visit. Conversations are kept as the business's history as long as the account exists. When a person asks for deletion, it's their identity that is erased from the thread — name, email, phone, IP, city — and what remains identifies no one. When the account is closed, nothing is deleted unless the merchant asks; they can request complete erasure, which is carried out within 30 days, or export first.
6. Security
Described in the present tense, with what's missing, on the Security page: encryption, access rules by site and by workspace, one-hour signed links for files, store tokens out of reach of browsers, a daily backup kept for 30 days, an audit log of actions in the console.
7. Helping the merchant with individuals' rights
Access, correction, deletion, withdrawal of consent: the merchant
can respond to these themselves from the console (visitor card,
export, "Forget this person"). What they can't do alone, Krealo
Media does on written request to ken@krealomedia.com within
10 business days. Requests that Shopify forwards
(customers/data_request,
customers/redact, shop/redact) are
processed automatically.
8. Confidentiality incidents
If an incident affects the merchant's information, Krealo Media notifies the merchant without unreasonable delay, no later than 72 hours after becoming aware of it, with what is known at that point: what, who, since when, and what has been done. It keeps the register of incidents required by Law 25 and helps the merchant assess whether the Commission d'accès à l'information and the persons concerned must be notified.
9. Verification
The merchant can ask any question about the processing in writing; Krealo Media answers in writing within 10 business days. The service's code is in a private repository and can be shown on request to verify what this page states.
10. Personnel, governing law and signature
Two people at Krealo Media have access to the data, each with their own account, and only to operate and troubleshoot the service. The agreement is governed by the laws of Quebec. It is accepted by using the service; for a signed version, or one in English, write to ken@krealomedia.com.
Person in charge of the protection of personal information: Keneth Walters, Krealo Media — ken@krealomedia.com.