KyrosPub
KyrosPub Loading Research Vault...

EU & UK GDPR Compliance Statement

Comprehensive data governance protocols detailing how KyrosPub protects the fundamental privacy rights of European Economic Area (EEA) and United Kingdom (UK) data subjects.

Effective Date: July 24, 2026 Statutory Basis: EU GDPR • UK DPA 2018 Chapter V SCCs Certified • Art. 37 DPO Monitored
European Regulatory Compliance Guarantee

KyrosPub, operated by KyrosB2B.com Inc., guarantees statutory compliance with Regulation (EU) 2016/679 ("EU GDPR") and the UK Data Protection Act 2018 / UK GDPR. We enforce rigorous Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), and transparent lead syndication consent frameworks across all enterprise research operations.

01. Statutory Scope & Territorial Applicability

This Statement applies to all processing of Personal Data conducted by KyrosPub where such processing pertains to data subjects residing within the European Economic Area (EEA), European Union member states, or the United Kingdom (UK), pursuant to Article 3(2) of the GDPR (Territorial Scope - Extra-territorial offer of services).

Whether you access KyrosPub as a corporate reader downloading technical whitepapers or as a brand syndicating research reports, your data rights under European privacy law are fully recognized, protected, and enforceable.

02. Controller vs. Processor Legal Status

Under GDPR Article 4 definitions, KyrosPub’s legal operational roles are bifurcated depending on the specific data workflow:

Data Controller Status (Art. 4(7))

KyrosB2B.com Inc. acts as an independent Data Controller regarding user account registration details, platform navigation logs, cookie preferences, direct newsletter subscriptions, and core infrastructure security telemetry.

Joint / Independent Controller (Art. 26)

When you register to download a sponsored whitepaper, KyrosPub and the designated enterprise Sponsor act as independent Data Controllers regarding lead contact information transferred upon download, governed by reciprocal Data Processing Agreements.

03. Lawful Bases Processing Matrix (Art. 6 GDPR)

KyrosPub processes Personal Data of EEA and UK residents strictly when supported by a statutory Lawful Basis under Article 6(1) of the GDPR:

1. Affirmative Opt-In Consent (Art. 6(1)(a)): Required prior to transferring professional contact details to third-party content Sponsors during gated whitepaper downloads, or when signing up for marketing intelligence digests.
2. Legitimate Interests & LIA (Art. 6(1)(f)): Applied to platform performance optimization, cybersecurity monitoring, B2B industry categorization, and direct corporate outreach. Supported by a documented Legitimate Interests Assessment (LIA) confirming your fundamental privacy rights are not overridden.
3. Contractual Obligation (Art. 6(1)(b)): Necessary to establish user credentials, deliver requested PDF documents, and fulfill service terms.

04. B2B Gated Content & Consent Framework (Art. 7)

In accordance with Article 7 of the GDPR (Conditions for Consent), KyrosPub enforces strict design rules for lead capture interfaces:

Unbundled & Transparent Opt-In Protocol

  • No Pre-Ticked Boxes: All lead capture forms require a deliberate, affirmative action (e.g., checking an un-ticked box or clicking a clear submission trigger).
  • Granular Sponsor Disclosure: Forms explicitly identify the enterprise Sponsor receiving your business contact details prior to data transmission.
  • Instant Revocation: You retain the statutory right to withdraw consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.

05. Data Minimization & Storage Limits (Art. 5)

Adhering to Article 5(1)(c) (Data Minimization) and Article 5(1)(e) (Storage Limitation), KyrosPub collects only professional identity data relevant for enterprise syndication. Inactive profiles and telemetry logs are purged or anonymized under strict retention timetables (maximum 36 months of inactivity).

06. Cross-Border Transfers & SCCs (Chapter V)

Because KyrosB2B.com Inc. operates cloud infrastructure within the United States, personal data transferred from the EEA or UK to the US is safeguarded pursuant to Chapter V of the GDPR:

Standard Contractual Clauses (SCCs) Execution of European Commission SCCs (Commission Implementing Decision (EU) 2021/914) Module 1 (Controller-to-Controller) and Module 2 (Controller-to-Processor).
UK Addendum & TIA Certification Execution of the UK International Data Transfer Addendum alongside completed Transfer Impact Assessments (TIAs) verifying supplemental technical protections.

07. Technical Security Safeguards (Art. 32)

Pursuant to Article 32 GDPR, KyrosPub enforces state-of-the-art Technical and Organizational Measures (TOMs):

  • Pseudonymization and end-to-end TLS 1.3 cryptographic transport protocols.
  • AES-256 database encryption at rest across all production servers.
  • SOC 2 Type II compliant cloud provider hosting infrastructure.
  • Automated intrusion detection, rate-limiting, and RBAC authentication.

08. Data Subject Rights Matrix (Chapter III)

EEA and UK residents possess statutory rights under Articles 15 to 22 of the GDPR, which KyrosPub enforces without cost:

Right of Access (Art. 15) Obtain confirmation and a full export of personal data held by KyrosPub.
Right to Erasure (Art. 17) Request immediate deletion ("Right to be Forgotten") from active databases.
Right to Rectification (Art. 16) Correct inaccurate corporate details or outdated job titles.
Right to Object & Revoke (Art. 21) Object to direct B2B marketing outreach or legitimate interest processing.
Right to Restriction (Art. 18) Request temporary restriction of data processing during verification disputes.
Data Portability (Art. 20) Export your data in a structured, machine-readable JSON/CSV format.

09. DPIA & Automated Decision Safeguards

KyrosPub conducts periodic Data Protection Impact Assessments (DPIAs) under Article 35 GDPR to evaluate risk vectors associated with lead syndication. We do not engage in automated decision-making or profiling that produces legal or similarly significant effects under Article 22 GDPR.

10. Supervisory Authorities & Escalation Rights

If you believe KyrosPub has processed your Personal Data in violation of the GDPR, you have the statutory right under Article 77 GDPR to lodge a formal complaint with a European Data Protection Supervisory Authority (e.g., the Irish Data Protection Commission, CNIL in France, BfDI in Germany) or the UK Information Commissioner’s Office (ICO).

11. EU/UK Legal Representative & DPO Desk

To submit a Data Subject Access Request (DSAR) or contact our Data Protection Officer pursuant to Article 37 GDPR:

KyrosB2B.com Inc. - Data Protection Office (DPO)

Attn: European Data Protection Officer & Privacy Counsel

DPO Direct Email: dpo@kyrosb2b.com

DSAR Gateway: privacy@kyrosb2b.com

EU Representative Desk: KyrosB2B EU Privacy Representative, Grand Canal Dock, Dublin 2, Ireland

UK Representative Desk: KyrosB2B UK Privacy, City of London, EC2A 2BB, UK

Home Research
Publish
Log In