Privacy Policy
1. Why Should You Read This Privacy Policy?
This Policy explains how we process your personal data. It helps you understand what we do with your information and what your privacy rights are.
Welcome! This Privacy Policy ("Policy") explains how Koenig Solutions S.L., operating under the KiroSleep brand and other home goods brands ("Company", "we", "us", or "our"), processes your Personal Data ("Personal Data" or "Data") when you:
- visit our sales websites ("Website");
- purchase our products or services ("Goods" or "Service");
- otherwise interact with us (support, social media, contests, affiliate programs, etc.).
This Policy describes the data we collect, the purposes for which it is collected, how we use and share it, how long we retain it, your rights, and how we protect your data. We commit to processing your data lawfully, fairly, and transparently, in accordance with:
- the General Data Protection Regulation (GDPR);
- the ePrivacy Directive 2002/58/EC;
- the UK General Data Protection Regulation (UK GDPR);
- and any other applicable data protection legislation.
This Policy applies worldwide and is based on the principles of the GDPR (General Data Protection Regulation). It reflects high standards of data protection, such as lawfulness, fairness, and transparency. Specific national or regional requirements of the United Kingdom are addressed in the Regional Addenda located at the end of this Policy.
If you do not agree with our practices, please refrain from using the Website, purchasing our Goods or Services, or submitting your Data in any other way. This Policy is effective from June 1, 2026. We may update this Policy from time to time, and all updates become effective upon publication, so we encourage you to check it regularly to stay informed.
2. Who is Responsible for the Protection of Your Personal Data?
We are: Koenig Solutions S.L., your Data Controller.
Company registration number: B16446106
Registered office address: Carrer de Jules Verne, 19, Sarrià-Sant Gervasi, 08006 Barcelona, Spain
Customer support email address: support@kirosleep.com
We have appointed a Data Protection Officer (DPO) to oversee our data protection obligations. You can contact them at support@kirosleep.com by including the title "Personal Data Protection" in the subject line of your email.
3. For What Purposes and What Data Do We Collect?
We generally collect only the Data necessary to deliver our Goods or Services and operate our Website. This section explains why we collect it and how we use it.
We collect only the Data that we genuinely need and use it only for clear and lawful reasons (e.g., to process your purchase, provide services, respond to your inquiries, ensure Website functionality, etc.). You can find a complete list of purposes, the Data we collect, how we use it, and more detailed information in the subsections below:
1. Processing and Fulfilling Your Order
Payment data: Price, currency, credit card brand (payment system), card type, Bank Identification Number (BIN), and issuing country.
Technical information: IP address, language, device type.
2. Payment Processing and Compliance with Legal Obligations
Billing and legal data: name, email address, phone number, billing address, IBAN/bank account number, payment records, invoices, VAT (IVA), and other necessary accounting or legal documentation.
Customs or import/export info: personal identification codes or customs data required by law in certain countries (e.g., for shipments subject to customs clearance).
Article 6(1)(c) GDPR. Legal obligation: to comply with statutory accounting requirements.
3. Providing Customer Support Services
Article 6(1)(f) GDPR. Legitimate interest: providing answers, advising, securing, and processing inquiries when someone initiates initial contact.
4. Providing Transactional Communications
Call details: date, time, duration, and call recordings.
Technical data: copies of electronic messages/SMS, delivery status, open (read) status, links clicked.
5. For Marketing Activities
Article 6(1)(f) GDPR — Legitimate interest: soft opt-in for existing customer relationships.
6. For Interacting with You on Social Media
7. For the Protection of Our Rights and Legitimate Interests
8. For Monitoring Website Performance and Marketing Effectiveness
9. Organizing Contests and Giveaways
10. For Creating and Using Promotional Materials (UGC)
11. For Managing Affiliate Services
12. For Managing Reviews
13. For Maintaining Service Operability and Website Security
Core Global Framework Disclosures
- Legal Framework: Processing relies strictly on contract, consent, legal obligation, or legitimate interest.
- Sensitive Data: We never intentionally harvest biometric, religious, or health sectors. Any voluntary health notes submitted to support desks are handled purely via explicit user consent.
- Automated Tools and AI: Systems like ChatGPT/Gemini handle automated workflows (chatbots/summaries) but do not compile legal or significant automated decision profiles under Art. 22 GDPR.
- Sale of Data: We never sell consumer personal data assets to anyone for monetary compensation.
- Data of Minors: The platform is not built for minors. Accidental data blocks from children are destroyed immediately upon detection.
4. What Sources Do We Obtain Your Data From?
We receive your Data directly from you, during your use of our Website, or from trusted third parties and public sources. This helps us deliver Services and stay in touch with you.
We may collect Data from the following sources:
- Directly from you: Form entries, support queries, checkout inputs, or contest entries.
- Automatically through technology: Tracking tags, cookies, and digital device signatures when browsing our environment.
- Third parties & service providers: Data pipelines via hosting networks, verification platforms, or legal partners.
- Affiliate partners: Information derived from referral loops or tracking codes.
- Internal corporate group channels: Shared for localized administrative needs.
- Publicly available spaces: Government databases, official company registries, or business profiles (e.g., LinkedIn) for B2B contexts.
5. Do We Share Your Data with Third Parties?
Yes, but only when necessary, and with robust safeguards, always ensuring the protection of your privacy.
Parties processing data on our behalf act as official Data Processors bound securely under robust Data Processing Agreements (DPAs). They follow strict direction, maintain absolute security configs, and cannot utilize vectors for third-party use cases. We share data blocks across:
- Service providers (Processors): IT networks, hosting servers, payment terminals, analytics, auditing, and logistics.
- Corporate group units: Handled for central management operations.
- Public institutions / Independent Controllers: Courts, tax structures, enforcement groups, or corporate auditors during asset mergers.
- Any external third party: Only when authorized via explicit user consent.
6. How Long Do We Retain Your Data?
We retain your data only for as long as necessary for legal, contractual, or service-related purposes; we then securely delete or anonymize it.
Specific retention parameters are contextualized item-by-item inside Section 3 of this document. Upon passing retention bounds, vectors are systematically scrubbed via irreversible digital purging or complete anonymization pipelines.
7. How Do We Guarantee the Security of Your Data?
We use robust technical and organizational measures to ensure the security of your Data and constantly work to prevent unauthorized access.
Our standard infrastructure covers advanced cryptographic encryption layers, highly restricted operational data access, systematic internal training models, rolling data recovery backups, and external technical security audits. Note: no digital matrix over the open web is 100% bulletproof. Please keep local credentials complex and secure.
8. Do We Transfer Your Data Internationally?
Yes, sometimes, but only when necessary and always with reliable legal safeguards.
While primary processing sits directly within the European Economic Area (EEA), operational logistics demand global pipelines.
Special Case: Logistics Pipeline for Orthopedic Pillows
To properly arrange direct logistics and manufacturing delivery routes, key shipping metrics (name, physical address, phone number) are routed directly to logistical systems registered inside the People's Republic of China (PRC). Our Chinese partners operate bound under rigid processing clauses that align with standard GDPR benchmarks.
International validation mechanisms utilized include:
- Adequacy Decisions: Explicit data framework matching recognized by the European Commission or UK Government.
- Standard Contractual Clauses (SCCs): Employed systematically for zones lacking adequacy rules (e.g., the PRC).
- UK Safeguards: Incorporating the International Data Transfer Agreement (IDTA) or UK Addendum layers.
- Transfer Impact Assessments (TIA): Mandatory pre-deployment assessment under Schrems II guidelines.
- Additional layers: Full end-to-end encryption protocols in transit and operational access blocks.
9. Do We Use Automated Decision-Making or Profiling?
Yes, but we do not make important decisions about you based solely on AI. All important decisions are made by real people.
Automated algorithms or customer support matrices may generate draft suggestions, but they completely lack authority to invoke binding legal impacts under Art. 22 GDPR. Humans govern all crucial paths, and you retain rights to trigger human review pipelines at any time.
10. What Are Your Rights?
You have rights over your personal data (access, rectification, erasure, objection, etc.).
| GDPR Article | Your Privacy Right | Functional Scope |
|---|---|---|
| Articles 12–14 | Right to be informed | Clear transparency on collection and usage vectors. |
| Article 15 | Right of access | Requesting a complete local copy of your data file. |
| Article 16 | Right to rectification | Correcting broken, incomplete, or outdated data fields. |
| Article 17 | Right to erasure | The "Right to be forgotten" (exempt where tax/accounting law holds data). |
| Article 18 | Restriction of processing | Halting active processing paths under specific technical disputes. |
| Article 20 | Data portability | Receiving your data parameters in a structured machine-readable array. |
| Article 21 | Right to object | Absolute power to instantly halt direct marketing profiles. |
| Article 7(3) | Withdraw consent | Revoking previously provided permissions completely free of charge. |
Filing a Complaint: If you run into issues, email us at support@kirosleep.com first, and we will do our best to resolve it. You maintain absolute legal rights to file operational claims with the Spanish Data Protection Agency (Agencia Española de Protección de Datos — AEPD) via www.aepd.es, or your local regional supervisory hub.
11. How Else to Exercise Your Rights or Contact Us?
Direct all inquiries to support@kirosleep.com.
Our global SLA window handles intake without undue delay and within one calendar month (extendable by an extra month for highly complex technical data cases).
12. Regional Addenda — United Kingdom (UK)
For users residing in the United Kingdom or impacted by processing vectors inside Great Britain, all pathways map directly onto the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
UK Data Subject Rights Structure:
- Information & Access (Arts 13-15 UK GDPR): Transparent intake maps and clear local data copies.
- Rectification & Erasure (Arts 16-17 UK GDPR): Rapid updates and full account purging options (barring HMRC legal limits).
- Processing Caps & Portability (Arts 18 & 20 UK GDPR): Structural system holds and clean transfer downloads.
- Marketing/Profiling Objections (Arts 21-22 UK GDPR): Immediate halt commands on automated setups or commercial tracking lists.
International UK Data Routing:
Transfers departing the UK environment leverage verified Adequacy Regulations issued via the UK Government, or invoke the official UK International Data Transfer Agreement (IDTA) alongside standard European Addendums linked to technical VRAM server firewalls.
UK Supervisory Oversight: General complaints or escalated structural disputes route to the Information Commissioner's Office (ICO) via their central system portal: ico.org.uk.