At Karma Studio we process personal data of the people who visit our website, of our clients, and of anyone who uses our app or writes to the businesses that work with us. This page explains what data we collect, what we use it for, on what legal basis, who we share it with, how long we keep it and how you can exercise your rights. It follows Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018.
1Data controller
Owner: Carlos Aleu Fernández (Karma Studio)
Tax ID: 48895477-F
Address: Avenida Ejército Español 1, Bloque 2, 2ºB, 51002, Ceuta
Contact email: info@karma.studio
2Who this policy applies to
It covers every place where Karma Studio processes personal data:
- The public website karma.studio, its forms, the website chat and the WhatsApp button.
- The client panel (app.karma.studio) and the team panel (admin.karma.studio): the platform from which the contracted services are managed.
- The «Karma» mobile app for iPhone and Android, in both modes: customer of a business and business owner.
- Our clients' websites where our connector runs (chat, forms, shop, pixel): there the business is the controller and Karma Studio acts on its behalf, as explained in section 9.
3What data we process
Only what each use requires. By group:
If you visit the website
What you send us by form, chat or WhatsApp (name, email, phone, message), the page you write from, and the technical browsing data described in the cookie policy.
If you are a client
Your account data (name, email, encrypted password, phone), your business data (company name, tax ID, address, domain, business profile), billing and payment data, the third-party accounts you connect, your CRM conversations and contacts, and a log of what is done in your panel.
If you use the «Karma» app
Your email, your name, your phone if you provide it, the messages you send and receive, and a device identifier so we can send you notifications. Nothing else: no location, no contacts, no camera, no advertising identifiers.
If you write to one of our clients
What you send through their website (chat, form, order or booking): identification, contact details and the content of the message. We process it on behalf of that business.
4What we use your data for
We process your data only for the purposes listed below. We do not use it for anything else without telling you first.
- Deliver the services you contracted (SEO, advertising, social media, website and invoicing) and give you access to your panel.
- Manage the contractual relationship: quotes, contracts, invoices, payments and support.
- Answer enquiries you send us by form, email or WhatsApp.
- Send you information about your services and, with your consent, commercial information. You can unsubscribe at any time.
- Run the chat and the CRM: deliver messages between each business and its customers, show the history and notify when a new message arrives.
- Send you notifications on your phone or browser only if you turn them on, and stop as soon as you turn them off.
5Legal basis
Each processing activity relies on one of these bases:
- Performance of a contract: delivering and managing the contracted services.
- Consent: commercial communications, non-essential cookies and connecting your third-party accounts.
- Legitimate interest: security of our systems and improvement of the services.
- Legal obligation: retention of invoices and of tax and accounting records.
6The client panel
The panel (app.karma.studio) is the platform we deliver the services from. When you use it we process:
- Your account and your business: identification, logins, business profile, contracts and subscriptions. The password is stored encrypted and is never displayed.
- Billing: quotes, invoices and payments. Payments are processed by Stripe; we never see or store your full card number. If you have contracted VeriFactu invoicing, your invoice records are sent to the Spanish Tax Agency as required by law.
- Connected accounts: the permissions you grant us over your Google, Meta, LinkedIn or WordPress accounts (detailed in section 14). Tokens are stored encrypted and deleted when you disconnect.
- Your CRM and your chat: your customers' contacts, conversations and leads arriving via WhatsApp, Messenger, Instagram, your website chat, forms or your campaigns. You are the controller of that data; we store and process it on your behalf.
- Activity logs: what has been done in your panel, when and from where, for support and security.
7The «Karma» mobile app
The app is available for iPhone and Android and has two modes: «I'm a customer of a business», to follow your conversations with businesses that use Karma, and «I have my business on Karma», to handle your inbox. What you need to know:
- Data: in customer mode, your email (verified with a one-time code), your name, your phone if you provide it, and the messages. In owner mode, the same data as in your panel. We ask for nothing else.
- Notifications: if you turn them on, the device generates a notification identifier (Expo token) that we store to alert you of new messages. Alerts travel through Expo, Apple (APNs) and Google (Firebase); they only carry the sender's name and an excerpt of the message. You can turn them off in the app's or the system's Settings, and we then delete the identifier.
- Permissions: the app only asks for the notifications permission. It does not access your location, contacts, camera, microphone or photos, does not use advertising identifiers, and contains no ads or third-party trackers.
- On your device: the app keeps your session in the system's secure storage and a local copy of the messages you have already seen, so they open offline. They are deleted when you sign out.
- Deleting your account: in customer mode you can delete your account from Settings › Privacy and data. Your account, your devices and your contact details are erased; the businesses you talked to keep the conversation without your name or email, because the history belongs to them. A business account is cancelled from the panel or by writing to us, subject to the retention periods in section 11.
- The app and the panel are not aimed at children under 14 and we do not knowingly collect data from minors. If you believe a minor has given us their data, write to us and we will delete it.
8Artificial intelligence
Part of the work is done by artificial-intelligence systems we run with external providers (Anthropic, Google and, for the chat assistant, Scaleway): writing content for your website and social media, proposing adjustments to your campaigns, helping answer enquiries and classifying messages. These providers act as processors, do not use your data to train their models, and only receive what is strictly necessary for each task. Decisions that affect your money (publishing, changing a budget, replying on your behalf) are reviewed by a person or approved by you from the panel; the chat assistant only replies for you if you switch it on.
9When we process data on behalf of a client
If you write to a business through its website (chat, form, order, booking) or its ads, the controller of your data is that business. Karma Studio receives, stores and processes it following its instructions, as a processor (Article 28 GDPR), under the data-processing agreement signed with each client. We do not use it for our own purposes or share it between businesses.
To exercise your rights over that data, contact the business you talked to; if you write to us, we will forward your request and help them handle it.
10Who helps us deliver the service
We share data only with providers that work on our behalf, under contract and only for what is stated:
- Hosting and email: the servers that run the platform, the websites we host and transactional email.
- Stripe: collection of subscriptions and our clients' payments.
- Meta: WhatsApp Business, Messenger and Instagram Direct (messages you send and receive on those channels), Facebook and Instagram (pages, ads and posts we manage for you).
- Google: the Google services you connect (section 14) and Google Ads.
- Anthropic, Google and Scaleway: artificial-intelligence providers (section 8).
- Expo, Apple and Google: delivery of notifications to the mobile app.
- Sentry: logging of technical errors on the platform so we can fix them.
- Spanish Tax Agency: VeriFactu invoicing records, by legal obligation.
Some of these providers are outside the European Economic Area. In those cases the transfer relies on the EU-US Data Privacy Framework where the provider is certified or, failing that, on the standard contractual clauses approved by the European Commission. We do not sell personal data to anyone.
11How long we keep it
We keep your data for as long as the contractual relationship lasts and, afterwards, blocked for the legal periods: six years for commercial and accounting records (Commercial Code) and four years for tax records (General Tax Law). Data processed with your consent is deleted as soon as you withdraw it. Customer-mode app accounts are deleted the moment you delete them; notification identifiers, as soon as you turn alerts off.
12Security
We apply technical and organisational measures to protect your data: encryption in transit (HTTPS), role-based access control, encrypted passwords, regular backups and activity logging. Access tokens for your third-party accounts and the platform's keys are stored encrypted and never displayed in the panel. In the app, the session lives in the operating system's secure storage.
13Your rights
You may exercise the following rights at any time, free of charge and without giving reasons:
Access
Find out what data of yours we process and obtain a copy.
Rectification
Correct inaccurate or incomplete data.
Erasure
Ask us to delete your data when it is no longer necessary.
Objection
Object to processing based on legitimate interest or for marketing purposes.
Portability
Receive your data in a standard format to take it to another provider.
Restriction
Ask us to suspend processing while a claim is resolved.
To exercise them, tell us which right you wish to exercise and we will reply within one month at the latest. If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es). Write to us at info@karma.studio
14Connections to third-party services
Karma Studio works on your behalf inside platforms that belong to you. To do that we ask for specific permissions, always with your explicit authorisation and only the minimum each contracted service needs. Below is every permission, exactly what we do with it, and how to revoke it whenever you want.
Google / YouTube
youtube.upload— upload the vertical videos we produce for you to your channel. We do not read, modify or delete any other video on your channel.youtube.readonly— read your channel name and ID, only to show you which channel we are publishing to.webmasters— read in Search Console which searches people find you with and where you rank, to guide the SEO work.analytics.readonly,analytics.edit— read your website traffic and, if you do not have one yet, create your Google Analytics 4 property and data stream.business.manage— manage your Google Business Profile: post updates, reply to reviews and read its insights.adwords— read and manage your Google Ads campaigns if you have that service contracted.indexing,siteverification— notify Google about new pages on your site and verify that the domain is yours.calendar.app.created,calendar.freebusy— create and read only the events Karma Studio generates. We do not access the rest of your calendar.openid,userinfo.email,userinfo.profile— identify you when linking the account (your name and email). Not used for anything else.
Karma Studio's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. By connecting your YouTube account you also agree to the YouTube Terms of Service.
You can revoke Karma Studio's access to your Google account at any time, without giving reasons and without losing your data, from these Google pages:
Meta (Facebook, Instagram y Threads)
pages_show_list,pages_read_engagement— see the list of pages you manage and read their insights.pages_manage_posts— publish the posts we prepare on the page you choose.instagram_basic,instagram_manage_insights— see your Instagram professional account and read the insights of what has been published.instagram_content_publish— publish the content we prepare on your Instagram.pages_messaging,pages_manage_metadata— receive in your panel inbox the messages people send to the page you connect for the chat, and send the replies written by you, your team or your assistant if you have it switched on. Only while the channel is active, within the 24 hours Meta allows, and never to anyone who has not written to you first. The second permission is used only to subscribe that page to notifications of new messages (and, if you have contracted ads, of the contacts from your forms).instagram_manage_messages— the same for direct messages to the Instagram professional account linked to that page: you receive them in the inbox and reply from there. With this permission we do not read comments, followers or posts.threads_basic,threads_content_publish— see your Threads profile and publish the content we prepare on it.
w_member_social— publish the content we prepare on your LinkedIn.openid,profile,email— identify you when connecting the account.
We never sell or share this data, we do not use it to train artificial-intelligence models, and we do not access anything the service you contracted does not need. If you disconnect a platform from your panel, we delete its access token immediately.