Automation should save time without creating risk. This page explains how we handle data, access, retention, and incident response when building and supporting automations.
For procurement requests (DPA, security questionnaire, data-flow diagram), contact: security@kasperautomation.com
General contact: hello@kasperautomation.com
We support the following delivery models. The responsibilities and data exposure depend on which model you choose.
You run the automation runtime in your own environment (your cloud account or servers). We build and support workflows within that environment.
We host and operate the automation runtime to deliver the service.
The data processed depends on the tools you connect and the workflows you request. Typical categories include:
We do not sell customer data and do not use it for advertising.
Most automations follow this pattern:
A client-specific data-flow diagram is available on request for your exact tool stack and hosting model.
Request it at: hello@kasperautomation.com
We apply least-privilege access as a default approach.
Workflows often require API keys or OAuth tokens. Our approach:
Retention depends on your hosting model and chosen tools. We document the retention rules for your setup, including logs and support data.
Upon termination of services, we will delete or return customer data that we control, subject to legal and contractual requirements.
If you have specific retention requirements (e.g., 30 days), specify them during onboarding.
We maintain a list of subprocessors used for hosting, monitoring, support, and analytics (where applicable).
We will notify customers of material subprocessor changes where contractually required.
If a security incident affects customer data, we follow this process:
To report a vulnerability or security concern: security@kasperautomation.com
If your organisation requires a DPA for GDPR/UK GDPR, we can provide one.
We can complete vendor security questionnaires and provide responses aligned to your hosting model.
Send questionnaires to: security@kasperautomation.com
No. We process customer data only to deliver and support the workflows you request.
Often yes. We can work with scoped accounts, staging environments, or via pairing with your team.
We design workflows to minimise storage. Some tools may keep execution/error logs for reliability; we document what is stored and for how long.
Yes. If you require client-hosted, we will deliver and document that model.
Yes. See /dpa.html.