1. Basic summary
This section summarises the main points of our Privacy Policy. You will find the complete and detailed information below.
Data controller: Carles Fuster Guerrero
Privacy email address: privacidad@kaiperkit.com
Main purposes: managing enquiries, user accounts, workspaces, use of the platform, communications, support, billing and security.
Legal basis: consent, performance of a contract, legitimate interests and compliance with legal obligations, depending on the case.
Recipients: technology, hosting, email, analytics, payment and support providers, and public authorities where there is a legal obligation to disclose the data.
Rights: access, rectification, erasure, objection, restriction, portability and withdrawal of consent.
2. Data controller
The controller responsible for processing personal data through kaiperkit.com and, where applicable, app.kaiperkit.com, is:
Owner / Data controller: Carles Fuster Guerrero
Tax identification number (NIF/CIF): 208 579 18T
Address: Antonia Cerdà, nº 3, Alzira, Valencia
General email address: contacto@kaiperkit.com
Privacy email address: privacidad@kaiperkit.com
Website: https://kaiperkit.com
Hereinafter, the data controller may be referred to as KaiperKit, the platform, we, us or the controller.
If KaiperKit appoints a Data Protection Officer in the future, their contact details will be added to this policy.
3. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed by KaiperKit in connection with:
- Browsing the commercial website kaiperkit.com.
- Requests for information, contact, demonstrations or commercial proposals.
- Registration and access to app.kaiperkit.com.
- The creation and management of user accounts.
- The creation, management and administration of workspaces.
- Use of KaiperKit features by researchers, administrators, invited members, collaborators or institutional staff.
- The purchase of plans, services, licences, workspaces or institutional agreements.
- The handling of enquiries, technical incidents and support requests.
- Commercial, informational or product communications.
This policy does not apply to third-party websites, platforms or services that may be linked from KaiperKit. Those third parties will have their own privacy policies.
4. Personal data we may process
Depending on your relationship with KaiperKit, we may process different categories of personal data.
4.1. Identification and contact information
- First name and surname.
- Email address.
- Telephone number, when provided voluntarily.
- The institution, company, university, hospital, R&D centre or research group to which you belong.
- Your position, professional role or function within the organisation.
4.2. Account and access data
- Username or internal identifier.
- Email address associated with the account.
- Securely hashed password.
- Registration date.
- Account status.
- Platform roles, such as owner, administrator, editor, collaborator or viewer.
- Scientific or professional roles, such as principal investigator, researcher, PhD candidate, co-supervisor, coordinator, technician, research fellow, collaborator, student or other defined role.
4.3. Workspace and organisation data
- Workspace name.
- Associated organisation or institution.
- Users belonging to the workspace.
- Member permissions, invitations, roles and statuses.
- Basic activity history required for the security, auditing and operation of the platform.
4.4. Platform usage data
- Date and time of access.
- IP address.
- Browser and device type.
- Pages or sections visited.
- Actions performed within the platform.
- Technical logs needed to detect errors, incidents, unauthorised access or misuse.
4.5. Commercial and billing data
- Contact details of the person requesting or responsible for the purchase.
- Details of the contracting institution, company or organisation.
- The purchased plan and number of workspaces, users, seats or licences.
- Billing information required to issue quotations and invoices or manage payments.
- History of commercial communications or requests.
4.6. Content entered into the platform
Users may enter information into KaiperKit relating to projects, research lines, papers, tasks, notes, documents, deadlines, resources or team members.
KaiperKit does not ask users to enter special categories of personal data, such as health data, political opinions, religious beliefs, trade union membership, sexual orientation, biometric data or other particularly sensitive information. If an institution, research group or user chooses to enter this type of information into the platform, they are responsible for ensuring that they have an appropriate legal basis for doing so.
5. Purposes of processing
KaiperKit may process personal data for the following purposes:
5.1. Managing information and contact requests
We process the information you provide to respond to enquiries, demonstration requests, commercial requests, questions about the platform or communications sent through forms, email or other contact channels.
5.2. Creating and managing user accounts
We process the data required to enable registration, sign-in, authentication, password recovery, profile configuration and secure access to the platform.
5.3. Providing the KaiperKit service
We process data to create, maintain and administer workspaces, projects, research lines, tasks, documents, notes, calendars, teams, permissions, roles, invitations and other features available through the platform.
5.4. Managing institutions, R&D centres and organisations
For institutional customers, we process data to manage the commercial relationship, create institutional accounts, assign purchased workspaces, configure administrators, control user limits, manage licences, prepare quotations, issue invoices and support the internal adoption of KaiperKit.
5.5. Managing payments, billing and administrative obligations
We process the data required to prepare quotations, manage purchases, issue invoices, verify payments, administer subscriptions, manage renewals and increases in user numbers, and comply with tax, accounting and legal obligations.
5.6. Providing technical support and user assistance
We process data to resolve questions, incidents, errors, access problems, configuration requests, feature enquiries and other requests relating to the use of the platform.
5.7. Improving the platform and analysing its use
We may process technical and usage data to understand how KaiperKit is used, detect errors, improve the user experience, optimise features, prioritise development and measure the overall performance of the service.
5.8. Ensuring security
We process technical information, access logs and activity records to protect the platform, prevent unauthorised access, detect unusual behaviour, prevent fraud, investigate incidents and maintain system integrity.
5.9. Sending service-related communications
We may send communications necessary for the operation of the service, such as account notices, significant changes, incident notifications, security alerts, invitations, confirmations, renewals or operational information about KaiperKit.
5.10. Sending commercial communications
Where an appropriate legal basis exists, we may send commercial communications about KaiperKit, new features, content, resources, events, product improvements or proposals related to the platform.
6. Legal basis for processing
The legal basis that allows us to process your data will depend on the specific purpose of the processing.
Consent: where you voluntarily contact us, request a demonstration, agree to receive communications or configure particular preferences.
Performance of a contract: where processing is necessary to create an account, provide the service, manage workspaces, provide support or administer a subscription.
Legitimate interests: to improve the platform, prevent misuse, ensure security, respond to professional enquiries or maintain commercial relationships with customers and users.
Legal obligation: to comply with tax, accounting, administrative or regulatory obligations, or requests from competent authorities.
Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before its withdrawal.
7. Data processing within institutions, R&D centres and organisations
KaiperKit is designed for use by individual users as well as research groups, institutions, research centres, universities, hospitals, foundations, R&D companies, laboratories and other organisations.
In these cases, an organisation may purchase KaiperKit and appoint administrators or owners to create workspaces, invite members, assign roles, configure permissions and manage use of the platform within its own environment.
If your account was created by or invited to join an institution, centre or research group, that organisation may be able to:
- See that you belong to a particular workspace.
- Assign you a role within the workspace.
- Modify your access permissions.
- Remove you from or suspend your access to the workspace.
- Review certain activity connected with the operational and secure use of the workspace.
- Manage licences, seats, billing or limits associated with the organisation.
The organisation is responsible for informing its users, employees, researchers, collaborators, students or invited members about its use of KaiperKit where applicable.
8. KaiperKit as a data processor
In certain circumstances, particularly where an institution, university, hospital, R&D centre, company, foundation or research group uses KaiperKit to manage information about its own users, teams or projects, KaiperKit may act as a data processor.
This means that the customer organisation may be the controller responsible for certain data entered into or managed through the platform, while KaiperKit processes that data on behalf of the organisation and in accordance with its instructions.
In these cases, the relationship between KaiperKit and the organisation must be governed by a contract, service agreement, data processing addendum or similar document establishing, among other matters:
- The subject matter and duration of the processing.
- The nature and purpose of the processing.
- The types of personal data processed.
- The categories of affected data subjects.
- The obligations and rights of the controller organisation.
- The instructions that KaiperKit must follow.
- The applicable technical and organisational measures.
- The conditions governing the use of subprocessors.
- The arrangements for returning or deleting the data when the service ends.
The relationship between the controller and processor must be formalised through a contract or another legal act binding the processor to the controller.
KaiperKit will not use data processed on behalf of an organisation for its own purposes where those purposes are incompatible with the provision of the service, unless there is a valid legal basis or express authorisation to do so.
9. Recipients and service providers
To provide the service properly, KaiperKit may rely on external providers that process personal data in accordance with our instructions and only for the necessary purposes.
These providers may include:
- Hosting, server, cloud infrastructure and storage providers.
- Transactional email and communications providers.
- Website analytics and usage measurement providers.
- Payment, billing and subscription management providers.
- Technical support, monitoring, security and fraud prevention providers.
- Internal administration, diagnostics and customer service tools.
We may also disclose data to public authorities, courts, tribunals, law enforcement agencies or other competent bodies where there is a legal obligation or valid request requiring us to do so.
KaiperKit requires its providers to offer appropriate guarantees regarding data protection, security and confidentiality, particularly where they act as processors or subprocessors.
10. International data transfers
Some technology providers used by KaiperKit may be located outside the European Economic Area or may process data from countries that do not provide a level of protection equivalent to that available in Europe.
Where international data transfers take place, KaiperKit will seek to ensure that appropriate safeguards are in place, such as adequacy decisions, Standard Contractual Clauses approved by the European Commission or other mechanisms recognised by data protection legislation.
This information may be updated depending on the providers used by KaiperKit at any given time.
11. Data retention periods
We will retain personal data for as long as necessary to fulfil the purposes for which it was collected and, subsequently, for the periods required by applicable legislation or needed to address potential liabilities.
As a general guide:
- Contact and demonstration requests: for the time necessary to respond and carry out reasonable commercial follow-up.
- User accounts: while the account remains active or is needed to provide the service.
- Workspace data: while the workspace remains active or for the period agreed with the customer organisation.
- Billing data: for the periods required under tax, accounting and commercial legislation.
- Technical and security logs: for the time needed to ensure security, resolve incidents or investigate misuse.
- Commercial communications: until the user withdraws their consent or objects to receiving them.
When the data is no longer required, it may be deleted, anonymised or restricted for the period during which legal liabilities may arise.
12. User rights
Users may exercise the rights recognised under data protection legislation. These include the rights of access, rectification, erasure, portability, restriction and objection, as well as the right to withdraw consent and lodge a complaint with the relevant supervisory authority.
In particular, you may exercise the following rights:
- Access: find out whether KaiperKit processes your personal data and obtain information about that processing.
- Rectification: request the correction of inaccurate or incomplete data.
- Erasure: request the deletion of your data where appropriate.
- Objection: object to certain processing based on legitimate interests or for commercial communications.
- Restriction: request the temporary restriction of the processing of your data in certain circumstances.
- Portability: receive your data in a structured format and transmit it to another controller where applicable.
- Withdrawal of consent: withdraw consent given for processing based on that legal ground.
To exercise your rights, you may contact:
Email address: privacidad@kaiperkit.com
Recommended subject: Exercise of data protection rights
To protect your privacy, we may ask for additional information to verify your identity before responding to your request.
If you believe that we have not processed your data correctly, you may lodge a complaint with the Spanish Data Protection Agency.
13. Data security
KaiperKit applies reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction.
These measures may include:
- Password encryption.
- Account and role-based access controls.
- Logical separation of workspaces.
- Secure HTTPS connections.
- Backups and recovery measures.
- Technical logs for detecting incidents.
- Restrictions on internal access to personal data.
- Reviews of relevant technology providers.
Although KaiperKit adopts reasonable security measures, no Internet-connected system can guarantee absolute security. Users must therefore also protect their credentials, use secure passwords and report any suspected misuse of their account.
14. Children and minors
KaiperKit is primarily intended for professionals, researchers, academic teams, R&D centres, institutions, companies and organisations.
As a general rule, KaiperKit is not intended for children or minors and does not knowingly seek to collect their personal data.
If an educational, research or similar institution uses KaiperKit in a context involving students who are minors, that institution must ensure that it has the necessary legal basis and authorisations.
16. Automated decision-making and profiling
KaiperKit does not make decisions producing legal or similarly significant effects on users based solely on the automated processing of their personal data.
If advanced analytics, artificial intelligence, automated recommendations or evaluation systems that may significantly affect users are introduced in the future, KaiperKit will update this policy and provide appropriate information.
17. Changes to this Privacy Policy
KaiperKit may amend this Privacy Policy to reflect legal, technical, organisational, commercial or functional changes.
When significant changes are made, we will update the last-modified date and, where necessary, notify users through reasonable means.
We recommend reviewing this policy periodically to remain informed about how we process personal data.
18. Privacy contact details
For any questions relating to this Privacy Policy or the processing of your personal data, you can contact KaiperKit using the following details:
Privacy email address: privacidad@kaiperkit.com
General email address: hola@kaiperkit.com
Website: https://kaiperkit.com