EN — Privacy notice
1. Controller
KASPIT Security GmbH Fischerstrand 4/1/3, 1220 Vienna, Austria FN 593406g, Commercial Court of Vienna VAT ID: ATU79083849 E-mail: office@kaspit.net
2. Data Protection Officer (DPO)
No Data Protection Officer is currently appointed.
Privacy requests: office@kaspit.net (subject e.g. “Privacy Desk”).
3. Purposes and legal bases
We process personal data in connection with KASPIT Desk (scheduling / operations SaaS) for:
| Purpose | Examples | Legal basis (Art. 6(1) GDPR) |
|---|---|---|
| Contract / account | Registration, login, profiles, roles, tenant/org data, support | (b) contract / pre-contract |
| Operations & security | Server/app logs, abuse/security detection, backups | (f) legitimate interests and/or (b) |
| Billing / accounting | Invoices, payment status, statutory retention | (c) legal obligation and/or (b) |
| Communication | Support tickets, e-mail to office@kaspit.net | (b) / (f) |
| Product improvement (optional) | anonymised / aggregated usage stats | (f) legitimate interests, or (a) consent where required |
B2B note: Desk targets organisations. Customer admins may enter staff data; the customer organisation may be (joint) controller or processor depending on setup.
4. Categories of data
- Identity and contact data
- Access/authentication data (hashed credentials / session tokens — no plaintext passwords)
- Usage and log data (IP, timestamps, browser/device, error logs)
- Content users store in Desk (e.g. roster / ops data — customer-controlled)
- Billing data (if/when charged)
5. Recipients / processors
- Hosting / infrastructure in the EU where practicable
- xAI (Grok) — used only when an organisation admin enables Desk AI. xAI then processes the short signal/shift snippets sent for a suggested summary or draft. Desk AI is assistive: deterministic gates (no-show, geo-near, far/low-sig Intel) decide whether to react; the model never AUTO-maps GDELT/drawer, never auto-escalates from GDELT-only, never invents officer GPS or SIGINT, and never bypasses the P0 Ack/Escalate ladder. GDELT Event pins (when shown) are OSINT · noisy third-party coding that can be wrong or miscoded — never confirmed terror.
- Authorities where legally required
A current processor list and DPA are available on request from office@kaspit.net. Third-country transfers only with an adequacy decision or appropriate safeguards (e.g. SCCs).
6. Retention
- Account data: for the contract term plus statutory retention (often up to 7 years in AT where applicable)
- Logs typically 30–90 days; backups follow the hosting cycle
- After account deletion: erase or anonymise unless retention duties apply
7. Cookies and similar technologies
- Strictly necessary: login, session, security, language — no consent where indispensable.
- Optional (analytics, marketing): not in use. Contact office@kaspit.net if that changes.
8. Your rights
Access, rectification, erasure, restriction, portability, objection (Art. 21), and withdrawal of consent (Art. 7(3)).
Complaint: Austrian Data Protection Authority (DSB), Barichgasse 40–42, 1030 Vienna, https://www.dsb.gv.at/
9. Obligation to provide data
Without certain data (e.g. valid e-mail, organisation account) a Desk account cannot be provided.
10. Automated decision-making
No Art. 22 automated decision-making with legal or similarly significant effects. Desk AI (default OFF) drafts or auto-acks only Intel that a human can Undo within 15 minutes; ops Alarms, SOS, Reports, and P0 Ack/Escalate stay human. T3 act-low and T4 act-high auto-react stay off until disclosed to the client organisation. Work items are marked “Draft by Desk AI” or “Hidden by Desk AI”.
11. Security
Appropriate technical and organisational measures (TOMs): encryption in transit, access control, backups. Details on request from office@kaspit.net.
12. Changes
This notice may be updated. The version published on desk.kaspit.net prevails. Material changes will be communicated via the app or e-mail where practicable.
© 2026 KASPIT Security GmbH · Fischerstrand 4/1/3 · 1220 Wien · office@kaspit.net
Back to sign in