KaiZen AI Strategy places particular importance on protecting personal data processed through its website and its international AI Search Visibility, advisory, research, brand-authority and governance services across Europe and Asia.
1. Data controller
The data controller is KaiZen AI Strategy Ltd, a company incorporated under the laws of Thailand and trading under the name KaiZen AI Strategy — KAIS.
Company registration number: 0105550016604Registered office: 349 Happyland Rd, Bangkapi, Bangkok 10240, Thailand
Privacy contact email: gontran@kaizen-ai-strategy.com
Telephone: +66 86 273 0029
Website: kaizen-ai-strategy.com
For any question concerning your personal data or to exercise your rights, you may contact us using the email address above.
Representative in the European Union (GDPR Article 27):
Nathalie Guermachi6 rue de la Baleine, 69005 Lyon, France
nathalie@kaizen-ai-strategy.com
Based on its current processing activities, KAIS has not appointed a Data Protection Officer. This assessment is reviewed whenever the nature, volume or risk level of the processing changes; if an appointment becomes necessary, the officer's contact details will be published here.
KAIS's role under client engagements
KAIS acts as a data controller for the operation of its website, prospect and client management, communications and its own research activities.
Where a client determines the purposes and means of processing personal data and instructs KAIS to perform processing on its behalf, KAIS may act as a data processor. In that case, the parties' responsibilities, documented instructions, security measures, subprocessors, transfers and return or deletion arrangements are set out in the contract or a data-processing agreement.
2. Scope of this policy
This Privacy Policy applies when you:
- visit the KaiZen AI Strategy website;
- complete a contact form or request an audit;
- book a meeting;
- request information about our services;
- download a report, study or other resource;
- subscribe to a newsletter or professional communication;
- communicate with us by email, telephone, video conference or social media;
- become a prospect, client, partner, supplier or service provider;
- request or receive an AI Visibility Test, Snapshot, AI Search Diagnostic or GEO Foundation Sprint;
- participate in an AI Search Advisory, Managed GEO Growth, Authority & Search Everywhere, Enterprise & Regulated AI Search or AI Brand Risk & Governance engagement;
- participate in a study, KVS measurement or research project;
- are identified as a professional contact, expert, author or representative associated with an organisation being analysed.
This Policy applies to information relating to identifiable natural persons. Information relating solely to a company does not, in itself, constitute personal data. It may, however, become personal data when it identifies a director, employee, consultant, representative or other professional contact.
3. Personal data we collect
Depending on your relationship with KAIS, we may process the following categories of personal data.
3.1 Identity and contact details
- first name and surname;
- job title and professional role;
- company or organisation;
- professional or personal email address;
- telephone number;
- country, city or time zone;
- LinkedIn profile or other professional profile;
- preferred language of communication.
3.2 Business and project information
- trading name and legal company name;
- industry or business sector;
- website and associated domains;
- target markets, countries, languages and territories;
- competitors and comparison categories;
- commercial, marketing, reputational and governance objectives;
- products or services offered;
- approved brand facts, official sources, experts, authors and claims;
- regulatory constraints, validation rules and approval workflows;
- information submitted through forms;
- strategic questions, search queries, prompts and responses analysed;
- information and access permissions required for KVS measurement, an AI Search Visibility audit, an authority programme or a governance engagement.
Where access to a client's platform is required, KAIS favours delegated access and named permissions. Passwords should not be sent in plain text by email or form.
3.3 Commercial relationship data
- communication history;
- quotation requests;
- commercial proposals;
- contracts and amendments;
- deliverables;
- meetings and meeting notes;
- support requests;
- communication preferences;
- prospect or client status;
- payment and invoicing information.
KAIS does not normally receive or store complete payment-card details. Payments may be processed by a specialist payment provider operating under its own privacy policy.
3.4 Website usage and technical data
- IP address;
- browser type;
- operating system;
- device type;
- pages visited;
- approximate date, time and duration of visits;
- referring page or traffic source;
- website interactions and events;
- technical identifiers;
- cookie preferences;
- technical logs and security information.
3.5 Communication data
- content of emails and messages;
- attachments;
- questionnaire responses;
- notes taken during meetings;
- meeting recordings, only where appropriate notice or permission has been provided;
- feedback, comments and testimonials.
3.6 Data obtained from public sources
As part of its audits and research activities, KAIS may collect publicly available professional information from:
- company websites;
- search engines;
- answer engines and artificial-intelligence assistants;
- professional social networks;
- directories;
- press releases and publications;
- media sources;
- public registers;
- profiles of company directors or representatives.
Such information is used only where relevant to a clearly defined professional, commercial, analytical or research purpose.
3.7 Sensitive personal data
KAIS does not seek to collect sensitive personal data such as health data, biometric data, political opinions, religious or philosophical beliefs, information concerning a person's sex life or sexual orientation, or criminal-offence data.
Please do not submit sensitive personal data through a form, email, prompt, document or artificial-intelligence tool unless it is strictly necessary, legally permitted and agreed with KAIS in advance.
For healthcare, legal, financial and other regulated engagements, KAIS works by default with brand data, professional content and public or approved sources. Patient, end-client, case-level or other individual data must only be disclosed under written instructions, within an approved environment and with appropriate contractual and technical safeguards. Such data is not submitted to a public artificial-intelligence interface.
4. Sources of personal data
Personal data may be obtained:
- directly from you;
- from your employer or organisation;
- from a partner or person who referred you;
- from publicly available sources;
- through technical service providers;
- through your use of our website, forms or tools;
- from results produced by search engines or artificial-intelligence systems.
Where personal data has not been obtained directly from you, KAIS will provide the information required by applicable law unless a legal exemption applies.
5. Purposes and legal bases for processing
Responding to enquiries and arranging meetings
We use personal data to respond to messages, assess requests, arrange meetings and prepare a potential commercial relationship.
Legal basis: steps taken before entering into a contract, consent where required, or our legitimate interest in responding to professional enquiries.
Performing a measurement, Snapshot, Diagnostic or Foundation Sprint
Personal data may be used to identify an organisation, define its query territory, measure its presence across search and artificial-intelligence systems, compare competitors, analyse sources and produce a report or roadmap.
Legal basis: steps taken before entering into a contract, performance of a contract, or our legitimate interest in providing the requested analysis.
Providing advisory, managed, authority and governance services
We use personal data to deliver AI Search Advisory, Managed GEO Growth, Authority & Search Everywhere, Enterprise & Regulated AI Search and AI Brand Risk & Governance engagements, produce deliverables, coordinate approvals, measure changes and provide ongoing support.
Legal basis: performance of a contract and legitimate interests connected with the effective management of a professional relationship.
Managing payments, invoicing and accounting
We use personal data to issue invoices, monitor payments, maintain accounting records and comply with tax, legal and regulatory obligations.
Legal basis: performance of a contract and compliance with legal obligations.
Operating, improving and securing the website
Technical data may be used to identify errors, prevent unauthorised access, protect forms, maintain website availability and improve performance.
Legal basis: our legitimate interest in protecting and operating our services, together with compliance with legal obligations where applicable.
Measuring website audiences
Subject to your cookie choices, certain data may be used to understand website usage, measure traffic sources and improve our content.
Legal basis: consent where required or, for strictly necessary or legally exempt audience-measurement activities, legitimate interests in accordance with applicable law.
Sending professional communications
KAIS may send news, research findings, invitations and information relating to AI Search Visibility, brand authority, research, governance and its services for B2B companies, professional-services firms and regulated organisations.
Legal basis: consent where required or our legitimate interest in communicating with professional contacts about matters relevant to their activities, subject to a simple and continuing right to object.
Every electronic marketing communication includes a method for unsubscribing.
Producing research and the KVS Barometer
KAIS may use publicly available professional information, artificial-intelligence responses and search-engine results to create sector studies, statistical analyses, rankings, market reports and visibility benchmarks. Where reasonably possible, information is aggregated, pseudonymised or anonymised before publication.
Each publication identifies its collection period, markets, languages, engine panel, number of readings and principal limitations. Results produced under different panels, locations or protocols are not presented as directly comparable.
Legal basis: our legitimate interest in carrying out professional research and publishing useful information about the digital and artificial-intelligence visibility of organisations.
Establishing, exercising or defending legal rights
Information may be retained or used to prevent fraud, manage disputes, enforce contracts, respond to public authorities, and establish, exercise or defend the rights of KAIS.
Legal basis: legitimate interests and compliance with legal obligations.
6. Mandatory and optional information
Information marked as mandatory in a form is required to process your request. Where information is necessary to prepare or perform a contract, failure to provide it may prevent KAIS from:
- responding accurately to your request;
- preparing a quotation;
- performing an audit;
- providing a service;
- issuing an invoice;
- complying with legal obligations.
Other information is optional.
7. Use of artificial-intelligence and search tools
The panel used for an engagement is selected according to the client's market, language, sector and objectives, then defined in the proposal, contract or measurement protocol. KAIS may use ChatGPT, Google's AI search experiences, Gemini, Perplexity, Claude, Copilot, Meta AI, DeepSeek, Kimi or other relevant services.
Information submitted to these services may include:
- an organisation's name, website, sector, markets and languages;
- professional questions, queries and prompts;
- public or approved brand facts, content, expert profiles and official sources;
- information strictly necessary for the agreed engagement.
KAIS applies data minimisation: public tests primarily use professional or publicly available information. Confidential information, non-public personal data or sensitive data is used only where there is a documented need, appropriate authorisation and suitable safeguards, and never through an unapproved public interface.
Where appropriate, KAIS favours professional accounts, APIs or settings designed to limit provider retention or reuse. KAIS does not use a client's confidential information to train a general-purpose model of its own.
Outputs produced by search and AI systems are measurement and analytical materials. They are subject to human review, with enhanced validation for legal, medical, financial and other regulated content. Providers may nevertheless process certain data under their own terms, privacy policies and settings; the list applicable to an engagement is available from KAIS on request.
8. Recipients of personal data
Personal data is made available only to persons who require access for legitimate professional purposes. It may be disclosed to:
- authorised KAIS directors, staff and collaborators;
- consultants and service providers involved in a project;
- hosting and infrastructure providers;
- form, email and storage providers;
- customer relationship management providers;
- booking and video-conferencing platforms;
- payment, invoicing and accounting providers;
- analytics providers;
- cybersecurity and anti-spam providers;
- search engines and artificial-intelligence services used in audits;
- lawyers, accountants, insurers and other professional advisers;
- administrative, judicial or regulatory authorities where required by law.
KAIS does not sell personal data to third parties. Service providers acting on behalf of KAIS are selected on the basis of appropriate safeguards and, where required, are subject to suitable contractual data-protection obligations.
9. Technical service providers
The following principal providers may be involved. Engagement-specific tools are identified in the proposal, contract or applicable data-processing documentation.
| Function | Provider | Country or region |
|---|---|---|
| Website hosting | Hostinger International Ltd — Švitrigailos str. 34, Vilnius 03230 | Lithuania (EU) |
| Forms | Forms hosted by KAIS (Hostinger), delivery via Brevo | Lithuania (EU) · France (EU) |
| Brevo | France (EU) | |
| CRM | Brevo | France (EU) |
| Appointment booking | Cal.com | United States |
| Video conferencing | Platform agreed with the client and identified in the invitation; KAIS does not impose one provider | Depends on the selected platform |
| Search and AI services | Engagement-specific panel, including where relevant OpenAI, Google, Perplexity, Anthropic, Microsoft, Meta, DeepSeek or Kimi | European Union, United States or Asia depending on provider and configuration |
| Website analytics | No third-party tool as of the last update | — |
| Payment processing | Stripe · PayPal · Payoneer | Ireland (EU) · Luxembourg (EU) · United States |
| Accounting and invoicing | External accounting firm | Thailand |
| Spam protection | Honeypot field built into the form, no third-party provider | — |
This list does not mean that every provider is used for every client. Where an engagement requires an additional subprocessor or dedicated environment, the client is informed in accordance with the applicable contractual arrangements.
10. International data transfers
KAIS is established in Thailand and may use service providers located in different countries. Your personal data may therefore be processed in Thailand or transferred to other jurisdictions.
Before an international transfer, KAIS considers the parties' roles, the destination country, the type of data and the available legal mechanism. Where required by applicable law, safeguards may include:
- a data-processing agreement and documented instructions;
- an adequacy decision applicable to the recipient;
- recognised standard contractual clauses or other transfer clauses;
- a legally available transfer mechanism offered by the relevant provider;
- supplementary minimisation, encryption, access-control or pseudonymisation measures;
- a derogation or another basis expressly permitted by law.
Where the GDPR applies and the destination is not covered by a relevant adequacy decision, KAIS implements or requires an appropriate transfer mechanism before processing. Where Thailand's PDPA applies, transfers are made in accordance with the conditions established by that legislation.
You may request further information about the safeguards applicable to your circumstances by contacting KAIS.
11. Data retention periods
KAIS retains personal data only for as long as necessary for the relevant purpose.
| Category | Retention period or criterion |
|---|---|
| Contact enquiries and prospect data | Up to three years after the last meaningful interaction, unless you object or a different period is legally required |
| Free tests, Snapshots and Diagnostics | For the time required to perform and follow up the measurement, then for up to three years after the last interaction unless you object or the contract provides otherwise |
| Client data and deliverables | For the contractual relationship and applicable limitation or legal-defence periods; data processed by KAIS as a processor is also subject to the client's return or deletion instructions |
| Contracts, invoices and accounting records | For the period required by applicable accounting, tax and commercial laws |
| Marketing communications | Until consent is withdrawn, an objection is made or after three years of inactivity |
| Website technical logs | According to hosting and security settings and the period required for incident detection |
| Non-essential cookies | Not applicable as of the last update; any retention period will be disclosed before such a tool is activated |
| Security logs | Generally twelve months unless an incident or legal obligation requires a longer period |
| Data-subject requests | For the period necessary to respond to the request and demonstrate compliance |
| KVS readings, prompts and archived responses | For the comparison period defined in the protocol or contract, followed by deletion, anonymisation or evidential retention where necessary |
| Research data | For the duration of the project and its verification; anonymised data may be retained without a fixed time limit |
| Regulated or confidential data entrusted by a client | According to the contract, the client's instructions and applicable legal obligations, with retention limited to what is strictly necessary |
At the end of the applicable retention period, personal data is deleted, destroyed, anonymised or archived where continued retention is legally required.
12. Cookies and similar technologies
As of the last update, the KAIS website does not place analytics cookies, marketing cookies or advertising trackers.
Strictly necessary mechanisms
The website and its hosting provider may use technical mechanisms strictly necessary for operation, security, form delivery and prevention of misuse. They are not used to build advertising profiles.
Third-party services
When you open an external booking, payment, social-media or video-conferencing page, that provider may place its own cookies under its privacy policy. If a non-essential third-party service is embedded directly on the KAIS website, it will only be activated after consent where consent is required.
If KAIS later introduces analytics, personalisation or marketing tools, this Policy and the relevant choice mechanism will be updated before activation.
13. Security
KAIS implements technical and organisational measures appropriate to the nature of the personal data and the identified risks. These measures may include:
- least-privilege access and restriction to authorised persons;
- delegated access, named permissions and stronger authentication where available;
- no intentional transmission of passwords in plain text;
- encryption of communications where supported;
- logical separation of client files and environments where appropriate;
- appropriate backups, updates and continuity procedures;
- service-provider selection and review;
- human validation of sensitive or regulated content;
- incident-detection, escalation and response procedures;
- deletion, return or anonymisation of data that is no longer required.
No transmission or storage method can be guaranteed to be entirely risk-free. In the event of a personal-data breach, KAIS assesses the incident, takes appropriate containment measures and notifies the relevant authorities and affected individuals within the time limits required by applicable law, including within 72 hours where that obligation applies.
14. Your rights
Subject to the conditions and exceptions established by applicable law, you may have the right to request:
- access to your personal data;
- a copy of your personal data;
- correction of inaccurate or incomplete information;
- deletion of your personal data;
- temporary restriction of processing;
- portability of certain personal data;
- objection to processing based on legitimate interests;
- cessation of direct marketing;
- withdrawal of consent;
- information about the source of data not obtained directly from you;
- the submission of a complaint to a competent supervisory authority.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
To exercise your rights, contact gontran@kaizen-ai-strategy.com. Where the GDPR applies, a request may also be sent to the EU representative identified in section 1. KAIS may request information strictly necessary to verify your identity and prevent unauthorised access to personal data, and will respond within the period required by applicable law.
A request may be refused or restricted where legally permitted, including where necessary to protect the rights of another person, comply with a legal obligation, or establish, exercise or defend legal claims.
Individuals protected by Thai data-protection law may lodge a complaint with the competent Thai personal-data protection authority (PDPC). Where the General Data Protection Regulation applies, individuals may lodge a complaint with the supervisory authority in their country of residence, place of work or location of the alleged infringement — in France, the CNIL, 3 place de Fontenoy, 75007 Paris (cnil.fr).
15. Automated decision-making
KAIS does not make decisions based solely on automated processing where those decisions produce legal effects or similarly significantly affect an individual.
KVS scores, AI Search Visibility measurements, audit results and AI-assisted analyses primarily concern organisations, brands, content and sources. They are subject to human review and do not, by themselves, constitute automated legal, medical, financial, professional or contractual decisions concerning an individual.
16. Children
KAIS services are intended for businesses, professionals and organisations. The website is not directed at children, and KAIS does not knowingly seek to collect personal data from minors. Anyone who believes that a child has submitted personal data may contact KAIS so that the matter can be investigated and appropriate action taken.
17. Links to third-party services
The website may contain links to third-party websites, social networks, tools or platforms. KAIS is not responsible for the privacy practices of independent third parties that determine their own purposes and methods of processing. You should review the privacy policies of those services before providing personal data.
18. Changes to this privacy policy
KAIS may amend this Privacy Policy to reflect changes in law or regulation, changes in service providers, changes to the website, the introduction of new services or changes to our processing activities. The date of the latest update appears at the beginning of this Policy.
Where a change materially affects your rights or the way personal data is used, KAIS may provide additional notice through an appropriate communication channel.
19. Contact
For any question concerning this Privacy Policy or the protection of your personal data:
KaiZen AI Strategy LtdAddress: 349 Happyland Rd, Bangkapi, Bangkok 10240, Thailand
Email: gontran@kaizen-ai-strategy.com
Telephone: +66 86 273 0029
Website: kaizen-ai-strategy.com
See also: Legal notice · Politique de confidentialité (FR)