Personal Data and Privacy Protection Policy – KAIRN
Date of last update : 01/07/2025
When you use and/or register on the platform accessible at the following URL: kairn.co (the "Platform"), we ("KAIRN", "We", "Our", "Us") may collect and process your personal data.
This Personal Data and Privacy Protection Policy (the "Policy") is intended to inform users of the Platform ("User", "You", "Your", "Yours"), whether registered or not on the Platform, about the means implemented to collect and process Your personal data, in compliance with the applicable French and European legislation, including Law No. 78-17 of January 6, 1978 on Information Technology, Data Files and Civil Liberties, as amended by Law No. 2004-801 of August 6, 2004 and by Law No. 2018-493 of June 20, 2018 ("Data Protection Act"), Regulation (EU) No. 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR"), and Directive 2002/58 of July 12, 2002, as amended by Directive 2009/136/EC ("ePrivacy Directive"), as well as any national implementing legislation or subsequent legislation ("Applicable Regulations").
We attach the utmost importance to respecting Your privacy and protecting Your personal data. By accessing and/or using the Platform, You understand that Your personal data may be collected and processed under the conditions and according to the terms set out below.
If You do not accept this Policy, You must stop using the Platform.
1. Definitions
The terms "personal data" ("Personal Data"), "processing", "data controller", "processor", "recipient(s)", "consent", and "file" have the same meaning as set out in Article 4 of the GDPR.
2. Data Controller
The data controller of the User's Personal Data is the company KAIRN, a company in formation, whose contact details are provided in Article 10.
3. What personal data is collected?
When collecting Personal Data, the User will be informed of whether the Personal Data requested is mandatory or optional during their registration on the Platform.
Failure to provide the mandatory Personal Data will make it impossible to access and use the services of the Platform.
In particular, KAIRN may collect the following categories of Personal Data:
For registered Users
Personal Data processed during account creation on the Application:
- First name;
- Date of birth;
- Phone number.
Personal Data processed during use of the Platform:
- Data freely entered by the User in the chat, which may include sensitive data as defined in Article 9 of the GDPR;
- Goals set by the User;
- Exercises followed by the User;
- Personal journal entries including a title, an emotion, and a description.
4. Why do we collect your personal data?
The Personal Data that You provide to Us, as well as the data collected and/or processed as part of Your use of the Platform, are processed for the following purposes:
| Legal Basis | Purpose |
|---|---|
| Contract between the User and KAIRN (consisting of KAIRN's T&Cs and this Policy) | To provide the Platform and Our Services to You, ensure its proper functioning, and deliver Our Services. |
| Express consent provided by the User during registration and before using the chat on the Platform | To process the data You enter in the Platform's chat, which will then direct You to targeted exercises. |
| KAIRN's legitimate interest in managing its client relationship | To manage the commercial relationship between KAIRN and the Users. |
| KAIRN's legitimate interest in promoting its products and offering You promotions and news | To inform You about KAIRN's offers and news, unless You object. |
| Compliance with a legal obligation | To respond to Your requests to exercise Your rights (access, objection, portability, etc.). |
5. Who are the recipients of your personal data?
KAIRN undertakes to take all necessary precautions and appropriate organizational and technical measures to preserve the security, integrity, and confidentiality of Personal Data, and in particular to prevent it from being distorted, damaged, or accessed by unauthorized third parties.
5.1 Data transferred to authorities and/or public bodies
In accordance with applicable regulations, Personal Data may be transmitted to competent authorities upon request, including public bodies, solely to meet legal obligations, legal auxiliaries, officers of the court, and debt collection agencies.
5.2 Data accessible to third parties
Personal Data may be used by KAIRN, its processors, its affiliates, and/or, where applicable, by its business partners for the purposes described in Article 4 above.
- KAIRN staff, control services (including auditors), and KAIRN's processors will have access to the Personal Data collected in connection with use of the Platform.
- Any third party involved in providing the Services offered on the Platform.
In any case, KAIRN does not sell or engage in any paid transactions relating to the Personal Data collected during the provision of the Services.
5.3 Transfers outside the European Union
The User's Personal Data may be processed outside the European Union, including via remote access. KAIRN undertakes not to carry out any transfer of Personal Data outside the European Union without implementing appropriate safeguards in accordance with the Applicable Regulations.
6. What are your rights regarding your personal data?
In accordance with the Applicable Regulations and subject to a formal request, You have the right to access Your Personal Data, to rectify it, to object to its processing, as well as the right to have it erased, under the conditions provided for by the Applicable Regulations.
Your right to erasure of Your Personal Data applies subject to KAIRN's need to retain certain Personal Data, particularly in relation to its legal obligations.
In the event of exercising the right to object, KAIRN will cease processing the Personal Data unless there are legitimate and compelling reasons for the processing, or to ensure the establishment, exercise, or defense of its legal rights, in accordance with the Applicable Regulations.
You may also, subject to the conditions set out in the Applicable Regulations, request a restriction on the processing of Your Personal Data.
Where the processing of Your Personal Data is based on Your consent, You have the right to withdraw Your consent at any time.
You also have the right to the portability of certain Personal Data, enabling You to request an electronic copy in a readable and usable form of Your Personal Data processed by KAIRN (a) in an automated manner and (b) (i) on the basis of Your consent or (ii) within the framework of Your contractual relationship with Us for the subscription to Our offers. This excludes Personal Data that KAIRN may process manually or generate for its own purposes as well as information regarding amounts paid or payable and any information KAIRN may have generated in pursuit of its legitimate interests.
You may provide KAIRN with instructions concerning the fate of Your Personal Data after Your death.
If applicable, KAIRN will inform You of the reasons why Your requests cannot be fulfilled in whole or in part.
To exercise the rights mentioned in this Article, You may contact KAIRN by sending Your request to the contact details provided in Article 10 below.
7. How long do we keep your personal data?
KAIRN undertakes not to retain Your Personal Data beyond the period strictly necessary for the purposes for which it was collected, in accordance with the Applicable Regulations.
KAIRN undertakes to anonymize or delete Your Personal Data once the defined purpose and/or retention period has expired.
However, Personal Data may be archived beyond the specified retention periods for the purposes of research, establishment, and prosecution of criminal offenses, solely to make such Personal Data available to the judicial authority if necessary, or for other retention obligations, including accounting or tax purposes.
The maximum retention periods defined in the table below apply, unless You request the erasure or cessation of processing of Your Personal Data before the expiration of these periods, in accordance with Article 6 above, and subject to any obligations requiring longer retention.
| Category | Retention Period |
|---|---|
| Information relating to Users provided during account creation | Generally: 3 years from the end of the commercial relationship with KAIRN |
| Personal Data processed for marketing and promotional purposes (offers, news) | 3 years from the end of the relationship with the User or from the last interaction initiated by the User |
| Technical navigation and interaction data on KAIRN's website | Cookie retention duration varies by type (see KAIRN's cookie policy for details); maximum retention is 13 months. |
| Personal Data relating to management of rights requests and inquiries | 3 years from the last interaction initiated by the User |
| Information relating to KAIRN's legal obligations | This duration varies depending on the legal obligation concerned. |
8. Protection of minors' personal data
The Platform is generally not intended for minors under 18 years of age. Accordingly, We do not knowingly collect or store Personal Data about children under 18 without obtaining verifiable parental consent, with the understanding that holders of parental authority may request to receive information about their child and request its deletion.
When an adult User enters Personal Data relating to a minor under 18 years of age, they undertake to have obtained verifiable consent from the holders of parental authority and to provide, upon request, any documentation evidencing such consent.
9. Security
In light of technological developments, implementation costs, the nature of the Personal Data to be protected, and the risks to the rights and freedoms of individuals, KAIRN implements appropriate technical and organizational measures to ensure the confidentiality of Personal Data collected and processed and to provide a level of security appropriate to the risk, in accordance with this Policy.
All necessary precautions, in line with industry standards and considering the nature of the Personal Data and the risks associated with processing, will be taken to preserve the security of the Personal Data and, in particular, to prevent it from being distorted, damaged, or accessed by unauthorized third parties.
10. Contact
For any request concerning the processing of Your Personal Data, You may send Your request or complaint directly to KAIRN by contacting it at its registered office via email at: contact@kairn.co.
KAIRN will endeavor to find a satisfactory solution to ensure compliance with the Applicable Regulations.
In the absence of a response from KAIRN or if the dispute persists, You may file a complaint with the CNIL or the supervisory authority of the EU Member State in which You habitually reside.
11. Updates
We may update or modify this Policy from time to time to reflect legal, technical, or business developments. We will notify You and, where required by law, obtain Your consent for any material changes to this Policy. The date of the most recent version of this Policy will appear below.
Date of last update: 01/07/2025