Privacy policy

Last updated: August 2026

This policy explains what data KAI processes, why we process it and what rights you have under the EU General Data Protection Regulation (GDPR).

1. Who we are

KAI (short for Kassa AI) is an AI intelligence layer for cafés, based in Stockholm, Sweden. KAI connects to the systems a café already uses, such as point of sale, inventory, ordering and compliance tools, and presents sales, waste, inventory and compliance information in one place.

KAI is the data controller for the personal data described in this policy. You can reach us at hannibal@kaisolutions.se.

2. What data we collect

Website and pilot applications: your name, café name, email address, phone number and number of locations when you apply for a pilot or contact us.

Operational café data: sales transactions, product and inventory data, waste logs, prep and forecasting data, hygiene and temperature records, and similar operational records retrieved from the systems you connect. This data is primarily business data, not personal data.

Limited employee data: where your systems attach a staff identifier to a transaction or a log entry, that identifier may be processed as part of the operational record.

Technical data: basic log data required to run and secure the service, such as timestamps and error logs.

We do not collect customer payment card details, and we do not read the content of any private communications.

3. How we use your data

Pilot application data is used only to contact you about the pilot and to set up your account. We do not use it for advertising or credit assessment, and we do not sell it.

Operational café data is used only to deliver the product: to show live sales, waste, inventory and compliance information, to generate forecasts and recommendations, to produce reports and documentation for your café, and to answer questions you ask the AI assistant.

We do not train AI models on your data, and we do not use your data to build products for other customers. Aggregated and fully anonymised statistics, which cannot identify you, your café or any individual, may be used to improve the service.

4. Legal basis

We process pilot and contact data on the basis of your consent and our legitimate interest in responding to your enquiry.

We process operational café data on the basis of the agreement between KAI and your café, and, where KAI acts as a processor on behalf of your café, on that café's instructions under a data processing agreement.

5. Connected systems and access

KAI connects to your systems through their official APIs, using credentials or authorisation you provide. We request the narrowest access needed to deliver the features you use, and we do not write changes back into your systems unless you have explicitly enabled a feature that requires it.

You can revoke access to any connected system at any time. When access is revoked, KAI stops retrieving new data from that system.

6. Who we share data with

We do not sell your data and we do not share it with advertisers, data brokers or information resellers.

We share data only with service providers who help us deliver the product: cloud hosting and database providers operating on EU servers, and AI model providers used to generate answers, summaries and recommendations. AI model providers do not train their models on data sent through their APIs by default.

Where a provider processes data outside the EU or EEA, the transfer is covered by the European Commission's Standard Contractual Clauses together with appropriate additional safeguards.

We may disclose data where we are legally required to do so.

7. Security

All traffic is encrypted in transit with TLS. Credentials and access tokens are encrypted at rest.

Data minimisation: we retrieve only the data needed for the features you use.

Access control: each café's data is isolated and not accessible to other cafés. Internal access is limited to what is needed to operate and support the service.

Hosting: data is processed and stored on servers located within the EU.

8. Retention and deletion

Operational data is retained for as long as your café uses KAI, so that historical trends and required documentation remain available.

If your café stops using KAI, all stored data is deleted within 30 days, except where we are required by law to keep certain records.

Pilot application data is kept until you ask us to delete it. You can request deletion at any time by writing to hannibal@kaisolutions.se.

9. Your rights

Under the GDPR you have the right to request access to your personal data, and to request rectification, deletion, restriction of processing, data portability, and to object to processing.

To exercise any of these rights, contact hannibal@kaisolutions.se. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

10. Automated decision making

KAI generates forecasts, recommendations and informational answers based on your connected data. These are decision support only. They are not legally binding decisions and are not made automatically on your behalf. Your café is always responsible for the decisions it takes.

11. Changes and contact

We may update this policy. If we make material changes we will notify you by email.

Questions about this policy: hannibal@kaisolutions.se.