Privacy Policy

Effective Date: June 1, 2026

1. Why Should You Read This Privacy Policy?

In brief

This Policy explains how we process your personal data. It helps you understand what we do with your information and what your privacy rights are.

Welcome! This Privacy Policy ("Policy") explains how Koenig Solutions S.L., operating under the KiroSleep brand and other home goods brands ("Company", "we", "us", or "our"), processes your Personal Data ("Personal Data" or "Data") when you:

  • visit our sales websites ("Website");
  • purchase our products or services ("Goods" or "Service");
  • otherwise interact with us (support, social media, contests, affiliate programs, etc.).

This Policy describes the data we collect, the purposes for which it is collected, how we use and share it, how long we retain it, your rights, and how we protect your data. We commit to processing your data lawfully, fairly, and transparently, in accordance with:

  • the General Data Protection Regulation (GDPR);
  • the ePrivacy Directive 2002/58/EC;
  • the UK General Data Protection Regulation (UK GDPR);
  • and any other applicable data protection legislation.

This Policy applies worldwide and is based on the principles of the GDPR (General Data Protection Regulation). It reflects high standards of data protection, such as lawfulness, fairness, and transparency. Specific national or regional requirements of the United Kingdom are addressed in the Regional Addenda located at the end of this Policy.

If you do not agree with our practices, please refrain from using the Website, purchasing our Goods or Services, or submitting your Data in any other way. This Policy is effective from June 1, 2026. We may update this Policy from time to time, and all updates become effective upon publication, so we encourage you to check it regularly to stay informed.

2. Who is Responsible for the Protection of Your Personal Data?

In brief

We are: Koenig Solutions S.L., your Data Controller.

Company registration number: B16446106

Registered office address: Carrer de Jules Verne, 19, Sarrià-Sant Gervasi, 08006 Barcelona, Spain

Customer support email address: support@kirosleep.com

We have appointed a Data Protection Officer (DPO) to oversee our data protection obligations. You can contact them at support@kirosleep.com by including the title "Personal Data Protection" in the subject line of your email.

3. For What Purposes and What Data Do We Collect?

In brief

We generally collect only the Data necessary to deliver our Goods or Services and operate our Website. This section explains why we collect it and how we use it.

We collect only the Data that we genuinely need and use it only for clear and lawful reasons (e.g., to process your purchase, provide services, respond to your inquiries, ensure Website functionality, etc.). You can find a complete list of purposes, the Data we collect, how we use it, and more detailed information in the subsections below:

1. Processing and Fulfilling Your Order

When do we process your data?
When you purchase Goods through our Website or sign up for a regular subscription for Goods (if applicable), we process your Personal Data to manage and fulfill your order or subscription. This includes arranging delivery, processing payments, invoicing, sending order or payment confirmations, as well as handling updates, renewals, returns, refunds, or cancellations. Note: Goods and subscriptions to Goods are sold without creating a customer account.
Data categories
Identification & contact data: Full name, delivery address, email address, and phone number.
Payment data: Price, currency, credit card brand (payment system), card type, Bank Identification Number (BIN), and issuing country.
Technical information: IP address, language, device type.
Lawful basis
Article 6(1)(b) GDPR. Performance of a contract: to fulfill and deliver your purchase.
Retention period
Order and payment data are stored for 10 years in accordance with legal, tax, and accounting obligations.
Data recipients
Logistics partners and courier services (including companies registered in the PRC for direct delivery of goods); payment service providers; corporate group companies (EEA); partners/affiliates (some outside the EEA); providers of ERP/CRM systems and cloud accounting.

2. Payment Processing and Compliance with Legal Obligations

When do we process your data?
We process your personal data when managing payments related to your orders, subscriptions, discounts, product returns, or refunds. This processing also includes fulfilling tax obligations, such as invoicing, accounting, and complying with other statutory requirements.
Data categories
Payment information: payment method (card type, last digits of the card), payment token, transaction amount, date and time of the transaction, reasons for refund.
Billing and legal data: name, email address, phone number, billing address, IBAN/bank account number, payment records, invoices, VAT (IVA), and other necessary accounting or legal documentation.
Customs or import/export info: personal identification codes or customs data required by law in certain countries (e.g., for shipments subject to customs clearance).
Lawful basis
Article 6(1)(b) GDPR. Performance of a contract: to receive and manage payments.
Article 6(1)(c) GDPR. Legal obligation: to comply with statutory accounting requirements.
Retention period
We store accounting-related data for 10 years, as required by financial and tax regulations.
Data recipients
Banks and payment gateways (Stripe, PayPal, etc.); tax authorities of Spain (Agencia Tributaria) and the United Kingdom (HMRC); customs brokers and declaration authorities; certified auditors and public regulators as required by law.

3. Providing Customer Support Services

When do we process your data?
We use Artificial Intelligence (AI) tools (fully or semi-automated) to assist our customer support team. These tools are used to suggest draft responses, handle or answer calls before transferring them to a human agent, transcribe and summarize conversations, and provide automated answers to frequently asked or pre-programmed questions. Note! All AI-generated outputs are reviewed and approved by a human if the decisions made could affect your rights. We do not rely solely on automated decision-making that produces legal effects or similarly significantly affects you. We do not use your data to train AI models unless it is fully anonymized.
Data categories
Support communication: Email / online chat (Livechat) data: first name, last name, mobile phone number, email address, residential address. Purchase data and verification info. Entire written correspondence history.
Lawful basis
Article 6(1)(b) GDPR. Performance of a contract: provision of customer support services.
Article 6(1)(f) GDPR. Legitimate interest: providing answers, advising, securing, and processing inquiries when someone initiates initial contact.
Retention period
Call recordings: 6 months from creation. Written communication: 3 years after closing the inquiry (or longer if required to comply with applicable law).
Data recipients
Corporate group companies (EEA); providers of accounting systems / credential processors (EEA); auditors (EEA); providers of customer support (Helpdesk) systems and CRM platforms (including AI automation tools).

4. Providing Transactional Communications

When do we process your data?
When exercising our rights and obligations under the Terms of Service ("ToS"), we have the right to contact you at any time (e.g., to send transactional notifications). We may send you important notices and information via email, SMS, or phone call. Note! These important messages are not considered marketing, and you cannot opt out of receiving them.
Data categories
Contact details: first name, last name, mobile phone number, email address, residential address.
Call details: date, time, duration, and call recordings.
Technical data: copies of electronic messages/SMS, delivery status, open (read) status, links clicked.
Lawful basis
Article 6(1)(b) GDPR — Performance of a contract: administration of the Terms of Service and sending important notifications.
Retention period
Call recordings and electronic communication history records are stored for 6 months, unless a longer period is required by law.
Data recipients
Communication service providers: email / SMS / telephony platforms (EEA and outside the EEA); corporate group companies (EEA).

5. For Marketing Activities

When do we process your data?
To inform you about our products, services, promotional offers, or to request your feedback. This includes sending general or personalized content via email, SMS, or phone calls across managed brands. Personalized marketing may be tailored using past purchase history and behavior. Soft opt-in applies if you are an existing customer for similar products, provided you have a clear way to opt out, including explicitly on the "Thank You" page. You can opt out at any time completely free of charge via the unsubscribe link, sending "STOP" via SMS, or contacting support.
Data categories
Full name, email address, phone number, country. Registration logs of consent/opt-outs. Marketing interaction data (open rates, clicks, delivery timestamps). Purchase history and engagement data. Technical delivery details (IP address, device type).
Lawful basis
Article 6(1)(a) GDPR — Consent: processing through chosen channel.
Article 6(1)(f) GDPR — Legitimate interest: soft opt-in for existing customer relationships.
Retention period
3 years from the date consent is provided (unless unsubscribed earlier). Call recordings: 6 months.
Data recipients
Social media platforms (outside EEA); marketing service providers (outside EEA); corporate group companies (EEA).

6. For Interacting with You on Social Media

When do we process your data?
When you engage with our public profiles, participate in promotions, tag us in photos, or message us on platforms like Facebook, Instagram, LinkedIn, and TikTok. These platform providers act as independent data controllers and have full data access; please check their respective privacy policies to exercise platform-specific rights.
Data categories
First name, last name, profile picture. Likes, follows, comments, shares. Message history, attachments, game participation details, and photos you send or tag us in.
Lawful basis
Article 6(1)(f) GDPR — Legitimate interest (for interactions and responses) and Article 6(1)(a) GDPR — Consent (voluntary event participation).
Retention period
Retention periods are established by the respective social network. We do not manually delete this interactive data unless consent is withdrawn or platform parameters force removal.
Data recipients
Social media platforms acting as independent or Joint Controllers (outside EEA); corporate group companies (EEA); affiliates.

7. For the Protection of Our Rights and Legitimate Interests

When do we process your data?
If we become a party or interested party in legal proceedings, or when fraud, theft, illegal resale, or digital misuse of our brands is suspected. Unlawful actions are systematically reported to pre-trial investigation authorities like the police or prosecutor's office.
Data categories
Litigation materials, accounting items, statements of claim/defense, court judgments, and where strictly necessary, information regarding criminal offenses or specific categories (such as health data if highly relevant to a precedent).
Lawful basis
Article 6(1)(f) GDPR — Legitimate interest: establishment, exercise, or defense of legal claims.
Retention period
Throughout active legal proceedings and for 10 years from the date a court judgment becomes fully executed.
Data recipients
Lawyers, notaries, bailiffs, consultants (EEA/non-EEA); courts; consumer protection units; corporate group companies.

8. For Monitoring Website Performance and Marketing Effectiveness

When do we process your data?
When you browse our pages, we process certain analytical and technical metrics via tools like Google Analytics based strictly on your opt-in choices inside our cookie consent banner. Refer to our Cookie Policy for more details.
Data categories
IP address, device identifiers, browser parameters, language configs, referral URLs, page interaction details, timestamps, and session behavior.
Lawful basis
Article 6(1)(a) GDPR — Consent: actively provided through our cookie banner.
Retention period
Determined by cookie types. Review our detailed Cookie Policy for exact technical lifespans.
Data recipients
Google Ireland Limited. For explicit detail regarding Google Analytics tracking mechanics, see their official documentation at the linked portal.

9. Organizing Contests and Giveaways

Categories
Full name, email, phone number, social media tags, contest entries, multimedia attachments.
Basis & Retention
Art 6(1)(a) GDPR (Consent). Stored for 1 year after the winner announcement unless specific campaign terms state otherwise.

10. For Creating and Using Promotional Materials (UGC)

Categories
Testimonials, profile handles, images, voice recordings, influencer/affiliate contract records.
Basis & Retention
Art 6(1)(a) GDPR (Consent) or Art 6(1)(b) GDPR (Performance of Contract). Active UGC stored up to 2 years; core campaign materials archived up to 10 years for compliance.

11. For Managing Affiliate Services

Categories
First/last name, contact info, banking data, referral codes, tracking data, and campaign performance logs.
Basis & Retention
Art 6(1)(b) GDPR (Contract) and Art 6(1)(f) GDPR (Fraud Prevention). Account logs kept for 5 years post-termination; accounting/payout items stored for 10 years.

12. For Managing Reviews

Categories
First/last name, email, textual review payload, star rating, associated images/media.
Basis & Retention
Art 6(1)(a) GDPR (Consent). Published and managed for a maximum rolling window of 3 years or until deletion request.

13. For Maintaining Service Operability and Website Security

Categories
IP address, technical server application logs, OS configs, diagnostic footprints, and security alerts.
Basis & Retention
Art 6(1)(f) GDPR (Legitimate Interest in server security). Technical log vectors stored for 12 months unless incident analysis triggers legal holding.

Core Global Framework Disclosures

  • Legal Framework: Processing relies strictly on contract, consent, legal obligation, or legitimate interest.
  • Sensitive Data: We never intentionally harvest biometric, religious, or health sectors. Any voluntary health notes submitted to support desks are handled purely via explicit user consent.
  • Automated Tools and AI: Systems like ChatGPT/Gemini handle automated workflows (chatbots/summaries) but do not compile legal or significant automated decision profiles under Art. 22 GDPR.
  • Sale of Data: We never sell consumer personal data assets to anyone for monetary compensation.
  • Data of Minors: The platform is not built for minors. Accidental data blocks from children are destroyed immediately upon detection.

4. What Sources Do We Obtain Your Data From?

In brief

We receive your Data directly from you, during your use of our Website, or from trusted third parties and public sources. This helps us deliver Services and stay in touch with you.

We may collect Data from the following sources:

  • Directly from you: Form entries, support queries, checkout inputs, or contest entries.
  • Automatically through technology: Tracking tags, cookies, and digital device signatures when browsing our environment.
  • Third parties & service providers: Data pipelines via hosting networks, verification platforms, or legal partners.
  • Affiliate partners: Information derived from referral loops or tracking codes.
  • Internal corporate group channels: Shared for localized administrative needs.
  • Publicly available spaces: Government databases, official company registries, or business profiles (e.g., LinkedIn) for B2B contexts.

5. Do We Share Your Data with Third Parties?

In brief

Yes, but only when necessary, and with robust safeguards, always ensuring the protection of your privacy.

Parties processing data on our behalf act as official Data Processors bound securely under robust Data Processing Agreements (DPAs). They follow strict direction, maintain absolute security configs, and cannot utilize vectors for third-party use cases. We share data blocks across:

  • Service providers (Processors): IT networks, hosting servers, payment terminals, analytics, auditing, and logistics.
  • Corporate group units: Handled for central management operations.
  • Public institutions / Independent Controllers: Courts, tax structures, enforcement groups, or corporate auditors during asset mergers.
  • Any external third party: Only when authorized via explicit user consent.

6. How Long Do We Retain Your Data?

In brief

We retain your data only for as long as necessary for legal, contractual, or service-related purposes; we then securely delete or anonymize it.

Specific retention parameters are contextualized item-by-item inside Section 3 of this document. Upon passing retention bounds, vectors are systematically scrubbed via irreversible digital purging or complete anonymization pipelines.

7. How Do We Guarantee the Security of Your Data?

In brief

We use robust technical and organizational measures to ensure the security of your Data and constantly work to prevent unauthorized access.

Our standard infrastructure covers advanced cryptographic encryption layers, highly restricted operational data access, systematic internal training models, rolling data recovery backups, and external technical security audits. Note: no digital matrix over the open web is 100% bulletproof. Please keep local credentials complex and secure.

8. Do We Transfer Your Data Internationally?

In brief

Yes, sometimes, but only when necessary and always with reliable legal safeguards.

While primary processing sits directly within the European Economic Area (EEA), operational logistics demand global pipelines.

Special Case: Logistics Pipeline for Orthopedic Pillows

To properly arrange direct logistics and manufacturing delivery routes, key shipping metrics (name, physical address, phone number) are routed directly to logistical systems registered inside the People's Republic of China (PRC). Our Chinese partners operate bound under rigid processing clauses that align with standard GDPR benchmarks.

International validation mechanisms utilized include:

  • Adequacy Decisions: Explicit data framework matching recognized by the European Commission or UK Government.
  • Standard Contractual Clauses (SCCs): Employed systematically for zones lacking adequacy rules (e.g., the PRC).
  • UK Safeguards: Incorporating the International Data Transfer Agreement (IDTA) or UK Addendum layers.
  • Transfer Impact Assessments (TIA): Mandatory pre-deployment assessment under Schrems II guidelines.
  • Additional layers: Full end-to-end encryption protocols in transit and operational access blocks.

9. Do We Use Automated Decision-Making or Profiling?

In brief

Yes, but we do not make important decisions about you based solely on AI. All important decisions are made by real people.

Automated algorithms or customer support matrices may generate draft suggestions, but they completely lack authority to invoke binding legal impacts under Art. 22 GDPR. Humans govern all crucial paths, and you retain rights to trigger human review pipelines at any time.

10. What Are Your Rights?

In brief

You have rights over your personal data (access, rectification, erasure, objection, etc.).

GDPR Article Your Privacy Right Functional Scope
Articles 12–14 Right to be informed Clear transparency on collection and usage vectors.
Article 15 Right of access Requesting a complete local copy of your data file.
Article 16 Right to rectification Correcting broken, incomplete, or outdated data fields.
Article 17 Right to erasure The "Right to be forgotten" (exempt where tax/accounting law holds data).
Article 18 Restriction of processing Halting active processing paths under specific technical disputes.
Article 20 Data portability Receiving your data parameters in a structured machine-readable array.
Article 21 Right to object Absolute power to instantly halt direct marketing profiles.
Article 7(3) Withdraw consent Revoking previously provided permissions completely free of charge.

Filing a Complaint: If you run into issues, email us at support@kirosleep.com first, and we will do our best to resolve it. You maintain absolute legal rights to file operational claims with the Spanish Data Protection Agency (Agencia Española de Protección de Datos — AEPD) via www.aepd.es, or your local regional supervisory hub.

11. How Else to Exercise Your Rights or Contact Us?

Direct all inquiries to support@kirosleep.com.

Our global SLA window handles intake without undue delay and within one calendar month (extendable by an extra month for highly complex technical data cases).

12. Regional Addenda — United Kingdom (UK)

For users residing in the United Kingdom or impacted by processing vectors inside Great Britain, all pathways map directly onto the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

UK Data Subject Rights Structure:

  • Information & Access (Arts 13-15 UK GDPR): Transparent intake maps and clear local data copies.
  • Rectification & Erasure (Arts 16-17 UK GDPR): Rapid updates and full account purging options (barring HMRC legal limits).
  • Processing Caps & Portability (Arts 18 & 20 UK GDPR): Structural system holds and clean transfer downloads.
  • Marketing/Profiling Objections (Arts 21-22 UK GDPR): Immediate halt commands on automated setups or commercial tracking lists.

International UK Data Routing:

Transfers departing the UK environment leverage verified Adequacy Regulations issued via the UK Government, or invoke the official UK International Data Transfer Agreement (IDTA) alongside standard European Addendums linked to technical VRAM server firewalls.

UK Supervisory Oversight: General complaints or escalated structural disputes route to the Information Commissioner's Office (ICO) via their central system portal: ico.org.uk.