PRIVACY / DATA LIFECYCLE + RIGHTS

Privacy Policy

This Privacy Policy explains how KAIA identifies its role, limits collection, defines purpose and lawful basis, governs service providers and international transfers, secures and retains information, and enables privacy rights across the public website and other Services that reference this Policy.

Effective
28 NOV 2025
Version
2025.11
Owner
KAIA TECHNOLOGIES, INC.
Sections
13
DOCUMENT STATUSPUBLIC · CURRENT

This document is current only for the version and effective date published on this site.

01 / 13

1. Purpose, scope, and layered notices

This Policy applies when Kaia Technologies, Inc. and its affiliates ("KAIA," "we," "us") process personal data through a website, application, platform, API, support channel, recruitment process, or other Service that links to this Policy. A product, employment, applicant, supplier, government-program, or customer-specific notice or agreement may provide additional or controlling information for its scope.

This public website currently provides corporate information, internal inquiry forms, interactive presentation controls, and optional mapping and analytics integrations. It is not an approved channel for classified, export-controlled, privileged, or operationally sensitive information.

02 / 13

2. Controller, representatives, and definitions

The primary controller for information described by this public Policy is Kaia Technologies, Inc., 215 N Payne St, Alexandria, Virginia 22314, United States.

Personal data means information relating to an identified or reasonably identifiable person. Processing includes collection, recording, organization, storage, use, disclosure, transfer, restriction, deletion, and other operations. Controller and processor roles depend on the purpose, instruction, contract, and applicable law.

  • Questions about controller status should identify the relevant Service and relationship.
  • No UK or EU representative is represented as appointed unless a current notice expressly identifies one.
  • This Policy does not convert customer-controlled operational data into website data.
03 / 13

3. Information collected

KAIA collects information that you provide directly, limited technical and security information generated through use, and information lawfully received from authorized partners or public sources when necessary for a defined purpose. The categories actually collected depend on the Service and enabled integrations.

  • Inquiry data: name, work email, organization, role, country or region, subject, message, language, consent, and a reference identifier.
  • Professional or applicant data: résumé, work history, education, qualifications, work authorization, references, and accommodation information when voluntarily provided through an authorized process.
  • Account and transaction data: credentials, entitlements, contract, billing, and support records where an account or paid Service exists.
  • Technical and security data: network identifier, request time, browser or device characteristics, logs, authentication events, error reports, and abuse-prevention signals.
  • Usage and preference data: page interaction, language, accessibility preference, a device-local visual-experience value, and—only after optional analytics consent—an experiment identifier, assigned variant, entry surface, and non-content interaction event. Form values and typed message content are excluded from experiment telemetry.
  • Location context: coarse region inferred from a network request, or precise location only when a Service expressly requests it and the user or administrator authorizes it. This public site does not request device geolocation.
  • User Content: information submitted to an authorized Service, governed by the applicable agreement and purpose.
04 / 13

4. Purposes and lawful bases

KAIA processes personal data only for defined purposes and on a lawful basis available in the relevant jurisdiction. The same data may support more than one compatible purpose, but each purpose must remain documented and proportionate.

  • Contract or pre-contract steps: provide a Service, create and administer an account, respond to a requested briefing, deliver support, and manage transactions.
  • Legitimate interests: secure and improve Services, prevent abuse, maintain business records, understand service performance, manage relationships, and protect rights—subject to balancing against individual rights.
  • Legal obligation and public interest: respond to lawful process, meet tax, sanctions, export, employment, security, or regulatory requirements, and preserve legally required records.
  • Consent: optional analytics, certain marketing communications, precise location, or another activity where consent is the appropriate basis. Consent may be withdrawn prospectively.
  • Vital interests or other lawful bases may apply only where the facts and applicable law support them.
05 / 13

5. Disclosure and service providers

KAIA does not sell personal data in the ordinary meaning of selling data for money. Information may be disclosed to affiliates, infrastructure and security providers, professional advisers, payment or communications providers, recruitment partners, and other processors that need the information for an authorized purpose and are subject to appropriate obligations.

KAIA may disclose information with consent; to comply with law, enforce agreements, investigate misuse, protect rights or safety, or respond to lawful government requests; and in connection with a merger, financing, reorganization, or asset transaction subject to appropriate confidentiality and notice. Public authorities do not receive unrestricted access merely because KAIA serves government customers.

  • Data minimization and purpose limitation apply to disclosures.
  • Processor access should be role-based and instruction-bound.
  • A change of controller or material purpose should be communicated where required.
06 / 13

6. International transfers

Information may be processed in the United States and other countries where KAIA or an authorized provider operates. Laws in those locations may differ from those in the person’s home jurisdiction.

07 / 13

7. Privacy rights and request verification

Depending on jurisdiction and relationship, individuals may have rights to know or access personal data; correct inaccuracies; delete data; restrict or object to processing; receive portable data; withdraw consent; opt out of certain sale, sharing, targeted advertising, or profiling; limit use of sensitive data; and receive non-discriminatory treatment for exercising rights. EEA, UK, Swiss, U.S. state, and Türkiye rights differ in scope and exceptions.

Submit a Privacy inquiry through the internal Contact page. KAIA may verify identity and authority, clarify scope, protect third-party information, and deny or limit a request where law permits. Authorized agents must provide legally sufficient authority. Individuals may appeal or complain to a competent regulator where applicable.

  • Requests should identify the Service and relationship.
  • Do not send identity documents until requested through an authorized channel.
  • Deletion and access rights may be limited by security, legal-hold, contract, privilege, or recordkeeping duties.
  • Withdrawing consent does not invalidate processing completed before withdrawal.
08 / 13

8. Security and incident response

KAIA applies technical and organizational safeguards proportionate to information sensitivity, use, threat, and system context. Measures may include encryption in transit and at rest, least-privilege access, authentication, segmentation, secure development, logging, monitoring, vulnerability management, backup, recovery, supplier controls, training, and confidentiality duties.

No security measure eliminates all risk. KAIA’s incident process should identify, contain, preserve evidence, assess affected data and people, remediate causes, and provide notice where required. Do not submit active malware, exploit code, classified incident evidence, or sensitive logs through the public form.

09 / 13

9. Retention, deletion, and legal holds

KAIA retains information only as long as reasonably necessary for the purpose collected and for applicable security, contractual, dispute, tax, accounting, regulatory, and legal obligations. Criteria include relationship status, data sensitivity, record type, limitation periods, threat context, deletion feasibility, and whether data can be de-identified.

At the end of the applicable period, information should be deleted, securely destroyed, or de-identified, subject to backups and lawful holds. A deletion request does not override a documented legal or security obligation, but access to retained data should remain restricted.

10 / 13

10. Cookies, local storage, Mapbox, and optional analytics

The site may use strictly necessary storage for security, language, accessibility, inquiry state, and a device-local visual-experience assignment. The first-party resilient geometry engine runs locally. When the Mapbox basemap is available, Mapbox GL may cause the browser to transmit network and device information to Mapbox; all public map scenes are explanatory and do not use customer operational data.

After optional analytics consent, a first-party experiment register may receive a pseudonymous unit hash and minimized A/B exposure or conversion events; it does not store the raw unit identifier, IP address, field values, or message content. Google Analytics and Segment remain inactive until valid identifiers are supplied and the same consent boundary is satisfied. No experiment winner, uplift, or causal conclusion is represented until sample size, event quality, statistical method, and review criteria are defined and satisfied.

  • Necessary functions are separated from optional analytics.
  • Rejecting optional analytics must not block core website access.
  • Browser controls may also delete or block local storage and cookies.
  • Third-party providers process data under their own terms and KAIA’s applicable agreements.
11 / 13

11. Children

The Services are not directed to children under eighteen, and the public site does not knowingly solicit their personal data. If KAIA learns that personal data was collected from a child without legally sufficient authorization, it will take appropriate steps to delete or otherwise lawfully handle the data.

12 / 13

12. Changes and policy governance

KAIA may update this Policy to reflect changes in law, technology, providers, Services, or processing. The published effective date and version identify the controlling public edition. Material changes should receive proportionate notice; renewed consent will be requested where required.

Privacy governance should include ownership, records of processing, data-protection and transfer assessments where appropriate, processor review, incident readiness, rights-request tracking, retention controls, and periodic verification that public statements match implemented behavior.

13 / 13

13. Contact

Privacy questions, rights requests, appeals, and complaints should be submitted through the internal Contact page using the Privacy category. Mailing notices may be addressed to: Legal Department (Privacy), Kaia Technologies, Inc., 215 N Payne St, Alexandria, Virginia 22314, United States.

The public form must not include unnecessary sensitive data, government identifiers, medical records, classified information, export-controlled technical data, privileged communications, or credentials. KAIA may direct the requester to a more appropriate authenticated or regulated channel.

QUESTION / NOTICE

Create a traceable record about this policy.

Open the internal contact form