Global Privacy Policy
Document Reference: K2B-LEG-PRV-2026-V4 | Effective Date: January 1, 2024 | Last Revision: July 2026
Executive Preamble
This Global Privacy Policy ("Policy") establishes the binding legal framework under which KyrosB2B LLC and its corporate affiliates ("KyrosB2B", "Company", "we", "us", or "our") collect, store, process, transfer, and safeguard Personal Data obtained from business professionals, platform users, subscribers, and campaign participants across our global digital media network reaching 88M+ decision makers.
1. Corporate Scope & Applicability
This Policy applies universally to all digital assets, publishing portals, event platforms, web services, API integrations, and demand generation programs operated by KyrosB2B. By accessing our services, downloading whitepapers, registering for webcasts, or submitting corporate contact information, you acknowledge the data processing practices detailed herein.
This document is structured in strict alignment with international privacy standards, including Regulation (EU) 2016/679 (General Data Protection Regulation - "GDPR"), the UK Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the CAN-SPAM Act of 2003, Canada's Anti-Spam Legislation ("CASL"), Brazil's Lei Geral de Proteção de Dados ("LGPD"), and Japan's Act on the Protection of Personal Information ("APPI").
2. Controller vs. Processor Classifications
Under applicable global data privacy statutes, KyrosB2B acts in dual regulatory capacities depending upon the specific campaign execution architecture:
- Data Controller: KyrosB2B serves as Data Controller when collecting first-party subscriber information across our 20+ digital publishing properties, managing newsletter subscriptions, maintaining platform telemetry, and governing proprietary B2B audience databases.
- Data Processor / Joint Controller: Under custom client demand generation, Cost-Per-Lead (CPL), and content syndication programs, KyrosB2B operates as Data Processor or Joint Controller according to executed Data Processing Agreements (DPAs) with enterprise solution sponsors.
3. Comprehensive Categories of Personal Data Collected
KyrosB2B strictly limits data collection to professional B2B attributes necessary to connect corporate decision-makers with relevant enterprise technologies. We explicitly do not collect Sensitive Personal Data (e.g., health data, biometric identifiers, political affiliations, or financial payment cards):
A. Professional Identity Data
Full legal name, corporate business email address, direct work telephone number, corporate office mailing address, and business mobile contact.
B. Employment & Firmographic Attributes
Current job title, functional role, department, management seniority level (C-Level, VP, Director, Manager), official company name, primary industry vertical, annual corporate revenue tier, employee count range, and technology stack environment.
C. Technical, Telemetry & Behavioral Data
Internet Protocol (IP) address, geolocation data derived from IP, browser user-agent string, operating system version, referrer URL headers, timestamped content download signatures, cryptographic double opt-in confirmation hashes, and pixel engagement interactions.
4. Lawful Bases for Processing (GDPR & UK GDPR)
Pursuant to Article 6 of Regulation (EU) 2016/679, KyrosB2B relies upon the following lawful bases to process personal data:
- Legitimate Interests (Art. 6(1)(f)): Processing is necessary for the legitimate business interests of KyrosB2B and our enterprise clients to deliver targeted B2B content, conduct professional direct marketing, and connect commercial buyers with enterprise vendor solutions, balanced against individual data subject rights as supported by GDPR Recital 47.
- Explicit Consent (Art. 6(1)(a)): Where mandated by jurisdiction (e.g., whitepaper downloads, newsletter signups, or custom webinar registrations), processing is based upon explicit, unbundled double opt-in consent captured at the point of collection.
- Contractual Necessity (Art. 6(1)(b)): Processing necessary to fulfill obligations under client Insertion Orders (IOs) and Master Services Agreements (MSAs).
- Legal Obligation (Art. 6(1)(c)): Processing required to satisfy tax, statutory auditing, regulatory enforcement, or legal discovery obligations.
5. First-Party Data Collection & Zero Tolerance for Scraped Lists
KyrosB2B strictly enforces a 100% first-party data policy. All subscriber records in our 88M+ database are collected directly through our owned media properties, gated content forms, proprietary research surveys, and opt-in publishing portals.
Strict Anti-Scraping Warranty: KyrosB2B explicitly warrants that we never acquire, purchase, license, or process unverified third-party data lists, web-scraped email databases, or illegally harvested contact directories.
6. Third-Party Disclosures & Client Sponsor Protocols
When a business professional registers for or downloads content sponsored by a specific enterprise solution provider (e.g., a co-branded whitepaper or sponsored research report), KyrosB2B discloses at the point of download that contact details will be shared with the designated sponsor.
Recipient sponsors operate as independent data controllers and are contractually bound under KyrosB2B Sponsor Terms to utilize provided business contacts solely for commercial B2B outreach relevant to the downloaded topic, and to honor all opt-out and suppression requests promptly.
7. International Data Transfers & Standard Contractual Clauses (SCCs)
KyrosB2B operates a global infrastructure spanning North America, the European Economic Area (EEA), the United Kingdom, and Asia-Pacific. Data transfers from the EEA or UK to third countries lacking an European Commission adequacy decision are safeguarded under:
- 2021 European Commission Standard Contractual Clauses (SCCs - Module 1 Controller-to-Controller and Module 2 Controller-to-Processor).
- UK International Data Transfer Addendum (IDTA) to the EU Commission SCCs.
- Supplementary Technical Security Safeguards (end-to-end encryption in transit and at rest).
8. Data Retention & Lifecycle Governance
KyrosB2B retains personal data only for as long as necessary to fulfill the purposes for which it was collected, satisfy commercial reporting obligations, or enforce legal rights:
9. Technical & Organizational Security Measures (TOMs)
KyrosB2B implements enterprise-grade cybersecurity controls aligned with ISO/IEC 27001 standards and SOC 2 Type II principles:
- Encryption Standards: All data in transit is encrypted using TLS 1.3 protocols. All data at rest is encrypted using AES-256 bit encryption algorithms.
- Access Controls: Strict Role-Based Access Control (RBAC) enforced via multi-factor authentication (MFA) and zero-trust perimeter network segmentation.
- Incidence Response & 72-Hour Breach Notification: In the event of a confirmed security incident impacting personal data, KyrosB2B will notify competent Supervisory Authorities within 72 hours under GDPR Article 33 guidelines.
10. Data Subject Rights Under GDPR & UK GDPR
European Union and United Kingdom business professionals possess statutory data subject rights under Articles 15-22 of the GDPR:
Submit DSAR requests directly through our Automated DSAR & Preference Center or email dpo@kyrosb2b.com.
11. California Consumer Rights (CCPA / CPRA) & GPC Signals
Under the California Consumer Privacy Act (CCPA) as amended by the CPRA (Cal. Civ. Code § 1798.100 et seq.), California residents possess specific statutory consumer rights:
- Right to Know categories and specific pieces of personal information collected.
- Right to Opt-Out of the "Sale" or "Sharing" of Personal Information.
- Right to Non-Discrimination for exercising consumer privacy rights.
- Global Privacy Control (GPC): Our web platform detects and automatically honors opt-out preference signals transmitted via Global Privacy Control browser headers.
12. Cookies, Pixels & Telemetry Technologies
KyrosB2B utilizes first-party cookies, tracking pixels, and web beacons to enable site navigation, measure campaign conversion rates, and deliver personalized B2B media. You can manage or disable non-essential cookies at any time via our Interactive Cookie Preferences Portal.
13. Absolute Prohibition on Children's Privacy
KyrosB2B offers services strictly intended for enterprise business professionals. We do not knowingly collect, solicit, or market to individuals under the age of eighteen (18). If we learn that personal data of a minor has been collected, it will be deleted immediately.
14. Data Protection Officer (DPO) & Regulatory Contact Directory
For inquiries, formal legal notices, DSAR enforcement, or Data Protection Impact Assessments (DPIA), please contact our Data Protection Office:
KyrosB2B Data Protection Office
Attn: Chief Privacy Officer & Data Protection Officer
Email: privacy@kyrosb2b.com | Legal Counsel: legal@kyrosb2b.com
Headquarters: 100 Enterprise Parkway, Suite 500, Tech City, USA
EU/UK Data Subjects also maintain the legal right to lodge a complaint with their local Supervisory Authority (e.g., the Information Commissioner's Office - ICO in the UK, or the CNIL in France).