EU & UK GDPR
Compliance Statement
Comprehensive data governance protocols detailing how KyrosPub protects the fundamental privacy rights of European Economic Area (EEA) and United Kingdom (UK) data subjects.
KyrosPub, operated by KyrosB2B.com Inc., guarantees statutory compliance with Regulation (EU) 2016/679 ("EU GDPR") and the UK Data Protection Act 2018 / UK GDPR. We enforce rigorous Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), and transparent lead syndication consent frameworks across all enterprise research operations.
01. Statutory Scope & Territorial Applicability
This Statement applies to all processing of Personal Data conducted by KyrosPub where such processing pertains to data subjects residing within the European Economic Area (EEA), European Union member states, or the United Kingdom (UK), pursuant to Article 3(2) of the GDPR (Territorial Scope - Extra-territorial offer of services).
Whether you access KyrosPub as a corporate reader downloading technical whitepapers or as a brand syndicating research reports, your data rights under European privacy law are fully recognized, protected, and enforceable.
02. Controller vs. Processor Legal Status
Under GDPR Article 4 definitions, KyrosPub’s legal operational roles are bifurcated depending on the specific data workflow:
Data Controller Status (Art. 4(7))
KyrosB2B.com Inc. acts as an independent Data Controller regarding user account registration details, platform navigation logs, cookie preferences, direct newsletter subscriptions, and core infrastructure security telemetry.
Joint / Independent Controller (Art. 26)
When you register to download a sponsored whitepaper, KyrosPub and the designated enterprise Sponsor act as independent Data Controllers regarding lead contact information transferred upon download, governed by reciprocal Data Processing Agreements.
03. Lawful Bases Processing Matrix (Art. 6 GDPR)
KyrosPub processes Personal Data of EEA and UK residents strictly when supported by a statutory Lawful Basis under Article 6(1) of the GDPR:
04. B2B Gated Content & Consent Framework (Art. 7)
In accordance with Article 7 of the GDPR (Conditions for Consent), KyrosPub enforces strict design rules for lead capture interfaces:
Unbundled & Transparent Opt-In Protocol
- No Pre-Ticked Boxes: All lead capture forms require a deliberate, affirmative action (e.g., checking an un-ticked box or clicking a clear submission trigger).
- Granular Sponsor Disclosure: Forms explicitly identify the enterprise Sponsor receiving your business contact details prior to data transmission.
- Instant Revocation: You retain the statutory right to withdraw consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.
05. Data Minimization & Storage Limits (Art. 5)
Adhering to Article 5(1)(c) (Data Minimization) and Article 5(1)(e) (Storage Limitation), KyrosPub collects only professional identity data relevant for enterprise syndication. Inactive profiles and telemetry logs are purged or anonymized under strict retention timetables (maximum 36 months of inactivity).
06. Cross-Border Transfers & SCCs (Chapter V)
Because KyrosB2B.com Inc. operates cloud infrastructure within the United States, personal data transferred from the EEA or UK to the US is safeguarded pursuant to Chapter V of the GDPR:
07. Technical Security Safeguards (Art. 32)
Pursuant to Article 32 GDPR, KyrosPub enforces state-of-the-art Technical and Organizational Measures (TOMs):
- Pseudonymization and end-to-end TLS 1.3 cryptographic transport protocols.
- AES-256 database encryption at rest across all production servers.
- SOC 2 Type II compliant cloud provider hosting infrastructure.
- Automated intrusion detection, rate-limiting, and RBAC authentication.
08. Data Subject Rights Matrix (Chapter III)
EEA and UK residents possess statutory rights under Articles 15 to 22 of the GDPR, which KyrosPub enforces without cost:
09. DPIA & Automated Decision Safeguards
KyrosPub conducts periodic Data Protection Impact Assessments (DPIAs) under Article 35 GDPR to evaluate risk vectors associated with lead syndication. We do not engage in automated decision-making or profiling that produces legal or similarly significant effects under Article 22 GDPR.
10. Supervisory Authorities & Escalation Rights
If you believe KyrosPub has processed your Personal Data in violation of the GDPR, you have the statutory right under Article 77 GDPR to lodge a formal complaint with a European Data Protection Supervisory Authority (e.g., the Irish Data Protection Commission, CNIL in France, BfDI in Germany) or the UK Information Commissioner’s Office (ICO).
11. EU/UK Legal Representative & DPO Desk
To submit a Data Subject Access Request (DSAR) or contact our Data Protection Officer pursuant to Article 37 GDPR:
KyrosB2B.com Inc. - Data Protection Office (DPO)
Attn: European Data Protection Officer & Privacy Counsel
DPO Direct Email: dpo@kyrosb2b.com
DSAR Gateway: privacy@kyrosb2b.com
EU Representative Desk: KyrosB2B EU Privacy Representative, Grand Canal Dock, Dublin 2, Ireland
UK Representative Desk: KyrosB2B UK Privacy, City of London, EC2A 2BB, UK