Privacy policy
Kairoseth processes the minimum account, organization, security-assessment and operational data needed to provide and protect the service.
Who is responsible
The Kairoseth service operator is the controller for platform account and service-administration data. The operator's registered legal name, tax identifier and postal address will be published here before commercial launch. Privacy requests may be sent to privacy@kairoseth.com.
Data and purposes
We process account identity and email, organization membership and permissions, authorized assessment targets, assessment results and reports, security/audit events, and service communications. We use them to create and secure accounts, provide requested services, enforce authorization and limits, support customers, prevent abuse, and meet legal obligations.
Legal bases
Depending on the processing, the legal basis is performance of the service contract or pre-contractual steps, compliance with legal obligations, legitimate interests in securing and operating the service, or consent where consent is specifically requested.
Recipients and processors
Data may be handled by infrastructure, database, email and other service providers acting as processors where needed to operate Kairoseth. We do not sell personal data. International transfers, if any, must use an applicable GDPR transfer mechanism and safeguards.
Retention
Account and organization data are retained while the account or service relationship is active and then only as long as necessary for legal, security and dispute purposes. Security Inspector history is bounded by product retention controls and authorized deletion. Backup copies may persist for a limited recovery period before expiry.
Your rights
Where applicable, you may request access, rectification, erasure, restriction, objection or portability, and withdraw consent without affecting prior lawful processing. You may also lodge a complaint with the competent supervisory authority, including the Spanish Data Protection Agency (AEPD).
Security
Kairoseth uses access controls, audit records, bounded operational limits and other technical and organizational measures intended to protect service data. No Internet service can guarantee absolute security.
Operational policy v1. Corporate identification details must be completed before commercial launch and the final texts should receive legal review.