GDPR Compliance Guide
This guide describes the practical controls Kairos uses to support responsible handling of personal data under the General Data Protection Regulation.
Scope and roles
GDPR responsibilities depend on the activity. A client may act as controller for its product, while Kairos may act as processor when handling data on documented client instructions.
The applicable role, purposes, data categories, and instructions should be confirmed for each engagement before processing begins.
We keep processing limited to defined purposes and avoid collecting information that is not needed for the service.
Records, notices, and contracts should describe the processing clearly enough for people and organizations to understand it.
This guide supports, but does not replace, a project-specific data protection assessment.
Core GDPR principles
Kairos aligns its process with lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.
- Define a lawful purpose before collecting data
- Use only data necessary for that purpose
- Keep data accurate and retention periods visible
- Protect confidentiality and access
- Document decisions and review controls
Security measures should be proportionate to the nature, scope, context, and risk of the processing.
Data subject rights
We support processes for access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where those rights apply.
Requests should be routed to the responsible controller and handled within applicable legal deadlines.
Processors assist controllers with reasonable information and technical measures, but the controller remains responsible for deciding the purpose and legal basis.
Incident response
We maintain a process for identifying, containing, investigating, and documenting suspected personal-data incidents.
Where a client is the controller, Kairos will notify the client without undue delay in line with the agreed contract and incident procedure.
Access is reviewed on a need-to-know basis, and credentials should be removed when a person no longer needs them.
International transfers
If personal data is transferred outside the EEA, the parties should identify an appropriate legal mechanism and document the relevant safeguards.
Vendor review should consider location, subprocessors, security controls, and whether the transfer is necessary for the service.
- Lawful purpose and transparent notice
- Data minimization and defined retention
- Appropriate security and access controls
- Documented processor instructions
- Rights-request and incident procedures
- Review, evidence, and accountability
Governance
We review privacy practices as services and risks change, keep appropriate records, and use contractual terms to clarify responsibilities with clients and providers.
Practical next step
Before processing personal data, confirm the roles, purpose, categories, retention, access, vendors, transfer locations, and incident contacts for the specific project.
This guide is general information, not legal advice or a guarantee of compliance for every processing activity.
Conclusion
A qualified privacy professional should review the project context, records, contracts, and controls before relying on this guide.
We build and improve digital products for real operating workflows.
Tell us where the product is now and where it needs to go. We’ll help define the clearest next step. See all FAQs
