§ Data protection
Privacy Policy
Information under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) on the processing of personal data in connection with this website.
Version 1.0 · In force from 18 September 2026
01 Who is responsible
The controller for the processing described here is:
- Controller
- K-AI IDENT SOLUTIONS LTD
- Address
- Kolpou Korallion 74-25, 8575 Pegeia, Paphos, Cyprus
- Registration number
- HE 494296
- Telephone
- +357 26 042961
The company has not appointed a data protection officer, as the conditions of Article 37 GDPR are not met. Enquiries about data protection are handled at the addresses above.
02 What this policy covers
This policy covers personal data processed when you visit this website or contact the company through it.
It does not cover data processed inside client projects. Where the company processes documents and data on behalf of a client — for example when operating the document verification system described on this website — the client is the controller and the company acts as a processor under a separate data processing agreement concluded pursuant to Article 28 GDPR. In that situation, the client's own privacy notice applies to the data subjects concerned.
03 Processing operations
3.1 Server log files
When a page is requested, the web server automatically records technical data transmitted by your browser: IP address, date and time of the request, the page or file requested, the HTTP status code, the volume of data transferred, the referring page and the browser and operating system identification string.
Purpose: delivering the website, maintaining stability, and detecting and investigating attacks and misuse. Legal basis: Article 6(1)(f) GDPR. The legitimate interest is operating a functioning and secure website. Retention: log entries are deleted after 14 days unless a specific entry is needed as evidence of an incident, in which case it is retained until the incident is closed.
3.2 Contact form
The contact form asks for your name, email address and message, and optionally your company name. When you send it, your own email program opens with the message prepared; the website itself does not store or transmit the data. The message reaches the company by email and is processed to answer your enquiry.
Purpose: handling your enquiry and any steps that follow from it. Legal basis: Article 6(1)(b) GDPR where the enquiry concerns a contract or steps taken prior to entering into one; otherwise Article 6(1)(f) GDPR, the legitimate interest being business communication with the person who contacted us. The confirmation checkbox on the form records that you were shown this policy before sending; it is not a separate consent and withdrawing it is therefore not necessary in order to stop the processing — an objection under Article 21 GDPR is enough. Retention: enquiries are deleted once they are settled and no statutory retention period applies; business correspondence that documents a contractual relationship is retained for the period required by Cypriot commercial and tax law, currently six years.
3.3 Contact by email or telephone
If you contact the company directly, the data you provide — in the case of email, your address, the message and any attachments — is processed to answer you. Purpose, legal basis and retention are the same as for the contact form.
3.4 Web fonts
The typefaces used on this website are delivered from the company's own server. No connection to a third-party font provider is established, and no data about your visit is transmitted to one.
3.5 Cookies, analytics and tracking
This website sets no cookies, uses no browser storage, and contains no analytics, advertising or tracking services. Details are in the Cookie Policy.
04 Recipients
Personal data is disclosed only where this is necessary for the purposes described above. Recipients may be:
| Recipient | Role | Basis |
|---|---|---|
| NetShop Internet Services Ltd, Republic of Cyprus | Operation of the web server and storage of log files | Processor under Article 28 GDPR |
| Namecheap, Inc. (Private Email), United States | Receipt and storage of enquiries | Processor under Article 28 GDPR |
| Professional advisers, auditors and authorities | Where a legal obligation or the defence of legal claims requires it | Article 6(1)(c) or 6(1)(f) GDPR |
Personal data is not sold, rented or used for advertising, and is not passed to third parties for their own purposes.
05 Transfers to third countries
The website is hosted within the European Economic Area, in the Republic of Cyprus. Emails sent to the company, including messages prepared with the contact form, are stored by its email service provider, Namecheap, Inc., in the United States, on the basis of the safeguards provided for in Chapter V GDPR, such as the standard contractual clauses of the European Commission (Article 46(2)(c) GDPR); details can be requested at the contact address in section 01. Should any other transfer to a third country become necessary, it will be carried out only on the basis of an adequacy decision of the European Commission, standard contractual clauses under Article 46(2)(c) GDPR, or another safeguard permitted by Chapter V GDPR, and this policy will be updated accordingly.
06 Storage periods
Personal data is retained only for as long as it is needed for the purpose for which it was collected, or for as long as a statutory retention obligation requires. The specific periods are stated in section 03. When a period expires, the data is deleted or irreversibly anonymised.
07 Your rights
Under the GDPR you have the right to:
- obtain confirmation whether your data is processed and to receive a copy of it (Article 15);
- have inaccurate data corrected and incomplete data completed (Article 16);
- have your data erased where one of the grounds in Article 17 applies;
- obtain restriction of processing in the cases listed in Article 18;
- receive the data you provided in a structured, commonly used, machine-readable format and have it transmitted to another controller (Article 20);
- object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR (Article 21). Following an objection, the processing stops unless compelling legitimate grounds that override your interests can be demonstrated, or the processing serves the establishment, exercise or defence of legal claims;
- withdraw any consent you have given, with effect for the future and without affecting the lawfulness of processing carried out before withdrawal (Article 7(3)).
To exercise these rights, write to the contact address in section 01. No fee is charged, and the company answers within one month of receipt; where a request is complex, that period may be extended by a further two months and you will be informed of the extension and its reasons.
You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence or place of work. The competent authority for this company is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy).
08 Is providing data mandatory
You are not legally or contractually required to provide personal data through this website. The fields marked as required in the contact form are needed only to reply to you; without them the enquiry cannot be answered. Server log data arises automatically from the technical process of delivering the website and cannot be avoided while the site is being used.
09 Automated decision-making
No automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place in connection with this website.
The system developed by the company applies automated checks to documents and data within client projects. There, negative validation results and detected discrepancies serve as decision support and trigger a mandatory human review before any operational consequence for a third party, in line with Article 22 GDPR. The details for each deployment are governed by the data processing agreement with the client concerned.
10 Security
The connection to this website is encrypted in transit using TLS. Beyond that, the company applies technical and organisational measures appropriate to the risk under Article 32 GDPR, including access control on a need-to-know basis, encryption of data at rest where appropriate, logging of administrative access, and data minimisation in the design of its systems. Measures are reviewed as technology develops.
11 Children
This website is addressed to businesses and is not directed at children. The company does not knowingly collect personal data from persons under the age of 16 through this website.
12 Changes to this policy
This policy is amended when the processing described in it changes or when a change in law requires it. The version and effective date at the top of the page identify the current text. Material changes are announced on this page before they take effect.