Back to homeKAIROSIA

Legal information

Privacy Policy

At KAIROSIA we treat personal data with the same seriousness we bring to our clients' decisions. This policy explains, in plain terms, what data we process, for what purpose and which rights you hold, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).

Last updated: September 7, 2026

1. Data controller

KAIROSIA Consulting Services, S.L.U. (hereinafter, "KAIROSIA"), with registered office at Av. Diagonal 640, Edificio Alta Diagonal, 6th Floor A, 08017 Barcelona (Spain), is the controller of the personal data collected through the website kairosia.ai.

KAIROSIA is not required to appoint a Data Protection Officer under Article 37 GDPR. For any matter concerning this policy or the exercise of your rights, please use the contact address provided at the end of this document.

2. Data we process and how we obtain it

The personal data we may process comes exclusively from you, in the following situations:

  • When you write to us by email or through the contact links on the site: identification data (name and surname), contact details (email address, telephone if provided), professional data (company and position) and the content of your message.
  • When you browse the website: technical data strictly necessary for the operation of the service (IP address, browser type, preferred language) and the information derived from the technical cookies described in our Cookie Policy.
  • When you download the Executive Brief or other documents: no additional personal data is collected beyond the technical data mentioned above.

We do not process special categories of data (health, ideology, trade union membership, etc.) or data relating to children under 14. If you are a minor, please do not provide us with personal data.

3. Purposes of processing

We process your personal data for the following purposes:

  • To handle and manage the information or contact requests you send us, and to maintain any subsequent communication arising from them.
  • To assess and, where applicable, formalise a professional strategic advisory relationship with the organisation you represent.
  • To ensure the proper functioning, security and technical improvement of the website.
  • To comply with the legal obligations applicable to KAIROSIA.

We do not build profiles or make automated decisions that produce legal effects concerning you. We do not use your data for advertising purposes or share it with third parties for commercial purposes.

4. Legal basis for processing

The lawful basis for processing your data is, depending on the case:

  • Your consent (Art. 6(1)(a) GDPR), given when you voluntarily send us a communication or request. You may withdraw it at any time without affecting the lawfulness of prior processing.
  • The performance of pre-contractual measures or of a contract (Art. 6(1)(b) GDPR), where the communication aims to assess or formalise a professional relationship.
  • KAIROSIA's legitimate interest (Art. 6(1)(f) GDPR) in ensuring the security of the website and in maintaining the relationship with those who have contacted us, always balanced against your rights and reasonable expectations.
  • Compliance with legal obligations (Art. 6(1)(c) GDPR), particularly in tax, commercial and information society services matters.

5. Retention period

We keep your data only for as long as necessary for the purpose for which it was collected:

  • Contact and information requests: while your request is being handled and, thereafter, for a maximum of two years from the last communication, unless you request erasure earlier.
  • Professional relationships: for the duration of the relationship and, once ended, for the limitation periods of the applicable legal liabilities (generally between five and six years under commercial and tax regulations).
  • Technical browsing data and security logs: a maximum of twelve months.

Once these periods have elapsed, the data will be securely deleted or anonymised.

6. Recipients and processors

KAIROSIA does not disclose your personal data to third parties except where legally required. To deliver the service we rely on technology providers acting as data processors, under a contract compliant with Article 28 GDPR and acting solely on our instructions:

  • Vercel Inc. (website hosting and infrastructure).
  • Resend, Inc. (email communications delivery).
  • Email and office productivity providers used for the ordinary management of communications.

Data may also be disclosed to public authorities, courts and tribunals where a legal obligation so requires.

7. International transfers

Some of the providers listed are headquartered or operate infrastructure outside the European Economic Area, in particular in the United States of America. In such cases, transfers are carried out with the appropriate safeguards provided for in Chapter V GDPR: the provider's certification under the EU-U.S. Data Privacy Framework or, failing that, the Standard Contractual Clauses approved by the European Commission, together with any supplementary measures that may be necessary.

8. Your rights

As a data subject, you may exercise the following rights at any time and free of charge:

  • Access: to know which of your data we process and for what purpose.
  • Rectification: to correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): to request deletion of your data when it is no longer necessary.
  • Objection: to object to processing based on legitimate interest.
  • Restriction of processing: to request that we suspend processing in the cases provided for by law.
  • Portability: to receive your data in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
  • Withdrawal of consent: at any time, without retroactive effect.

To exercise them, write to the contact address at the end of this policy, enclosing a means of verifying your identity. We will respond within one month at most, extendable by a further two months in cases of particular complexity, of which we would inform you.

If you consider that the processing does not comply with the regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, or through its electronic office at www.aepd.es. We would nonetheless appreciate the opportunity to resolve the matter directly beforehand.

9. Security measures

KAIROSIA applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR: HTTPS encryption of communications, access control to information, minimisation of the data collected, use of providers with recognised security certifications and periodic review of the measures in place. In the event of a security breach likely to result in a high risk to your rights, we would notify you without undue delay, in accordance with Articles 33 and 34 GDPR.

10. Cookies

This website uses only technical cookies necessary for its operation and to remember your preferences (language and acceptance of the cookie notice). Full details are available in our Cookie Policy.

11. Updates to this policy

KAIROSIA may amend this Privacy Policy to adapt it to regulatory or case-law developments or to changes in the way we provide our services. The version in force will always be the one published on this page, indicating the date of its last update. We recommend that you review it periodically.

Data protection contact:

KAIROSIA Consulting Services, S.L.U. · Av. Diagonal 640, Edificio Alta Diagonal, 6º Piso A · 08017 Barcelona

info@kairosia.ai