Data protection

Privacy policy

How we protect and use personal data across our international AI Search Visibility, research, authority and governance services.

Last updated: 7 August 2026

KaiZen AI Strategy places particular importance on protecting personal data processed through its website and its international AI Search Visibility, advisory, research, brand-authority and governance services across Europe and Asia.

1. Data controller

The data controller is KaiZen AI Strategy Ltd, a company incorporated under the laws of Thailand and trading under the name KaiZen AI Strategy — KAIS.

Company registration number: 0105550016604
Registered office: 349 Happyland Rd, Bangkapi, Bangkok 10240, Thailand
Privacy contact email: gontran@kaizen-ai-strategy.com
Telephone: +66 86 273 0029
Website: kaizen-ai-strategy.com

For any question concerning your personal data or to exercise your rights, you may contact us using the email address above.

Representative in the European Union (GDPR Article 27):

Nathalie Guermachi
6 rue de la Baleine, 69005 Lyon, France
nathalie@kaizen-ai-strategy.com

Based on its current processing activities, KAIS has not appointed a Data Protection Officer. This assessment is reviewed whenever the nature, volume or risk level of the processing changes; if an appointment becomes necessary, the officer's contact details will be published here.

KAIS's role under client engagements

KAIS acts as a data controller for the operation of its website, prospect and client management, communications and its own research activities.

Where a client determines the purposes and means of processing personal data and instructs KAIS to perform processing on its behalf, KAIS may act as a data processor. In that case, the parties' responsibilities, documented instructions, security measures, subprocessors, transfers and return or deletion arrangements are set out in the contract or a data-processing agreement.

2. Scope of this policy

This Privacy Policy applies when you:

This Policy applies to information relating to identifiable natural persons. Information relating solely to a company does not, in itself, constitute personal data. It may, however, become personal data when it identifies a director, employee, consultant, representative or other professional contact.

3. Personal data we collect

Depending on your relationship with KAIS, we may process the following categories of personal data.

3.1 Identity and contact details

3.2 Business and project information

Where access to a client's platform is required, KAIS favours delegated access and named permissions. Passwords should not be sent in plain text by email or form.

3.3 Commercial relationship data

KAIS does not normally receive or store complete payment-card details. Payments may be processed by a specialist payment provider operating under its own privacy policy.

3.4 Website usage and technical data

3.5 Communication data

3.6 Data obtained from public sources

As part of its audits and research activities, KAIS may collect publicly available professional information from:

Such information is used only where relevant to a clearly defined professional, commercial, analytical or research purpose.

3.7 Sensitive personal data

KAIS does not seek to collect sensitive personal data such as health data, biometric data, political opinions, religious or philosophical beliefs, information concerning a person's sex life or sexual orientation, or criminal-offence data.

Please do not submit sensitive personal data through a form, email, prompt, document or artificial-intelligence tool unless it is strictly necessary, legally permitted and agreed with KAIS in advance.

For healthcare, legal, financial and other regulated engagements, KAIS works by default with brand data, professional content and public or approved sources. Patient, end-client, case-level or other individual data must only be disclosed under written instructions, within an approved environment and with appropriate contractual and technical safeguards. Such data is not submitted to a public artificial-intelligence interface.

4. Sources of personal data

Personal data may be obtained:

Where personal data has not been obtained directly from you, KAIS will provide the information required by applicable law unless a legal exemption applies.

5. Purposes and legal bases for processing

Responding to enquiries and arranging meetings

We use personal data to respond to messages, assess requests, arrange meetings and prepare a potential commercial relationship.

Legal basis: steps taken before entering into a contract, consent where required, or our legitimate interest in responding to professional enquiries.

Performing a measurement, Snapshot, Diagnostic or Foundation Sprint

Personal data may be used to identify an organisation, define its query territory, measure its presence across search and artificial-intelligence systems, compare competitors, analyse sources and produce a report or roadmap.

Legal basis: steps taken before entering into a contract, performance of a contract, or our legitimate interest in providing the requested analysis.

Providing advisory, managed, authority and governance services

We use personal data to deliver AI Search Advisory, Managed GEO Growth, Authority & Search Everywhere, Enterprise & Regulated AI Search and AI Brand Risk & Governance engagements, produce deliverables, coordinate approvals, measure changes and provide ongoing support.

Legal basis: performance of a contract and legitimate interests connected with the effective management of a professional relationship.

Managing payments, invoicing and accounting

We use personal data to issue invoices, monitor payments, maintain accounting records and comply with tax, legal and regulatory obligations.

Legal basis: performance of a contract and compliance with legal obligations.

Operating, improving and securing the website

Technical data may be used to identify errors, prevent unauthorised access, protect forms, maintain website availability and improve performance.

Legal basis: our legitimate interest in protecting and operating our services, together with compliance with legal obligations where applicable.

Measuring website audiences

Subject to your cookie choices, certain data may be used to understand website usage, measure traffic sources and improve our content.

Legal basis: consent where required or, for strictly necessary or legally exempt audience-measurement activities, legitimate interests in accordance with applicable law.

Sending professional communications

KAIS may send news, research findings, invitations and information relating to AI Search Visibility, brand authority, research, governance and its services for B2B companies, professional-services firms and regulated organisations.

Legal basis: consent where required or our legitimate interest in communicating with professional contacts about matters relevant to their activities, subject to a simple and continuing right to object.

Every electronic marketing communication includes a method for unsubscribing.

Producing research and the KVS Barometer

KAIS may use publicly available professional information, artificial-intelligence responses and search-engine results to create sector studies, statistical analyses, rankings, market reports and visibility benchmarks. Where reasonably possible, information is aggregated, pseudonymised or anonymised before publication.

Each publication identifies its collection period, markets, languages, engine panel, number of readings and principal limitations. Results produced under different panels, locations or protocols are not presented as directly comparable.

Legal basis: our legitimate interest in carrying out professional research and publishing useful information about the digital and artificial-intelligence visibility of organisations.

Establishing, exercising or defending legal rights

Information may be retained or used to prevent fraud, manage disputes, enforce contracts, respond to public authorities, and establish, exercise or defend the rights of KAIS.

Legal basis: legitimate interests and compliance with legal obligations.

6. Mandatory and optional information

Information marked as mandatory in a form is required to process your request. Where information is necessary to prepare or perform a contract, failure to provide it may prevent KAIS from:

Other information is optional.

7. Use of artificial-intelligence and search tools

The panel used for an engagement is selected according to the client's market, language, sector and objectives, then defined in the proposal, contract or measurement protocol. KAIS may use ChatGPT, Google's AI search experiences, Gemini, Perplexity, Claude, Copilot, Meta AI, DeepSeek, Kimi or other relevant services.

Information submitted to these services may include:

KAIS applies data minimisation: public tests primarily use professional or publicly available information. Confidential information, non-public personal data or sensitive data is used only where there is a documented need, appropriate authorisation and suitable safeguards, and never through an unapproved public interface.

Where appropriate, KAIS favours professional accounts, APIs or settings designed to limit provider retention or reuse. KAIS does not use a client's confidential information to train a general-purpose model of its own.

Outputs produced by search and AI systems are measurement and analytical materials. They are subject to human review, with enhanced validation for legal, medical, financial and other regulated content. Providers may nevertheless process certain data under their own terms, privacy policies and settings; the list applicable to an engagement is available from KAIS on request.

8. Recipients of personal data

Personal data is made available only to persons who require access for legitimate professional purposes. It may be disclosed to:

KAIS does not sell personal data to third parties. Service providers acting on behalf of KAIS are selected on the basis of appropriate safeguards and, where required, are subject to suitable contractual data-protection obligations.

9. Technical service providers

The following principal providers may be involved. Engagement-specific tools are identified in the proposal, contract or applicable data-processing documentation.

FunctionProviderCountry or region
Website hostingHostinger International Ltd — Švitrigailos str. 34, Vilnius 03230Lithuania (EU)
FormsForms hosted by KAIS (Hostinger), delivery via BrevoLithuania (EU) · France (EU)
EmailBrevoFrance (EU)
CRMBrevoFrance (EU)
Appointment bookingCal.comUnited States
Video conferencingPlatform agreed with the client and identified in the invitation; KAIS does not impose one providerDepends on the selected platform
Search and AI servicesEngagement-specific panel, including where relevant OpenAI, Google, Perplexity, Anthropic, Microsoft, Meta, DeepSeek or KimiEuropean Union, United States or Asia depending on provider and configuration
Website analyticsNo third-party tool as of the last update
Payment processingStripe · PayPal · PayoneerIreland (EU) · Luxembourg (EU) · United States
Accounting and invoicingExternal accounting firmThailand
Spam protectionHoneypot field built into the form, no third-party provider

This list does not mean that every provider is used for every client. Where an engagement requires an additional subprocessor or dedicated environment, the client is informed in accordance with the applicable contractual arrangements.

10. International data transfers

KAIS is established in Thailand and may use service providers located in different countries. Your personal data may therefore be processed in Thailand or transferred to other jurisdictions.

Before an international transfer, KAIS considers the parties' roles, the destination country, the type of data and the available legal mechanism. Where required by applicable law, safeguards may include:

Where the GDPR applies and the destination is not covered by a relevant adequacy decision, KAIS implements or requires an appropriate transfer mechanism before processing. Where Thailand's PDPA applies, transfers are made in accordance with the conditions established by that legislation.

You may request further information about the safeguards applicable to your circumstances by contacting KAIS.

11. Data retention periods

KAIS retains personal data only for as long as necessary for the relevant purpose.

CategoryRetention period or criterion
Contact enquiries and prospect dataUp to three years after the last meaningful interaction, unless you object or a different period is legally required
Free tests, Snapshots and DiagnosticsFor the time required to perform and follow up the measurement, then for up to three years after the last interaction unless you object or the contract provides otherwise
Client data and deliverablesFor the contractual relationship and applicable limitation or legal-defence periods; data processed by KAIS as a processor is also subject to the client's return or deletion instructions
Contracts, invoices and accounting recordsFor the period required by applicable accounting, tax and commercial laws
Marketing communicationsUntil consent is withdrawn, an objection is made or after three years of inactivity
Website technical logsAccording to hosting and security settings and the period required for incident detection
Non-essential cookiesNot applicable as of the last update; any retention period will be disclosed before such a tool is activated
Security logsGenerally twelve months unless an incident or legal obligation requires a longer period
Data-subject requestsFor the period necessary to respond to the request and demonstrate compliance
KVS readings, prompts and archived responsesFor the comparison period defined in the protocol or contract, followed by deletion, anonymisation or evidential retention where necessary
Research dataFor the duration of the project and its verification; anonymised data may be retained without a fixed time limit
Regulated or confidential data entrusted by a clientAccording to the contract, the client's instructions and applicable legal obligations, with retention limited to what is strictly necessary

At the end of the applicable retention period, personal data is deleted, destroyed, anonymised or archived where continued retention is legally required.

12. Cookies and similar technologies

As of the last update, the KAIS website does not place analytics cookies, marketing cookies or advertising trackers.

Strictly necessary mechanisms

The website and its hosting provider may use technical mechanisms strictly necessary for operation, security, form delivery and prevention of misuse. They are not used to build advertising profiles.

Third-party services

When you open an external booking, payment, social-media or video-conferencing page, that provider may place its own cookies under its privacy policy. If a non-essential third-party service is embedded directly on the KAIS website, it will only be activated after consent where consent is required.

If KAIS later introduces analytics, personalisation or marketing tools, this Policy and the relevant choice mechanism will be updated before activation.

13. Security

KAIS implements technical and organisational measures appropriate to the nature of the personal data and the identified risks. These measures may include:

No transmission or storage method can be guaranteed to be entirely risk-free. In the event of a personal-data breach, KAIS assesses the incident, takes appropriate containment measures and notifies the relevant authorities and affected individuals within the time limits required by applicable law, including within 72 hours where that obligation applies.

14. Your rights

Subject to the conditions and exceptions established by applicable law, you may have the right to request:

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise your rights, contact gontran@kaizen-ai-strategy.com. Where the GDPR applies, a request may also be sent to the EU representative identified in section 1. KAIS may request information strictly necessary to verify your identity and prevent unauthorised access to personal data, and will respond within the period required by applicable law.

A request may be refused or restricted where legally permitted, including where necessary to protect the rights of another person, comply with a legal obligation, or establish, exercise or defend legal claims.

Individuals protected by Thai data-protection law may lodge a complaint with the competent Thai personal-data protection authority (PDPC). Where the General Data Protection Regulation applies, individuals may lodge a complaint with the supervisory authority in their country of residence, place of work or location of the alleged infringement — in France, the CNIL, 3 place de Fontenoy, 75007 Paris (cnil.fr).

15. Automated decision-making

KAIS does not make decisions based solely on automated processing where those decisions produce legal effects or similarly significantly affect an individual.

KVS scores, AI Search Visibility measurements, audit results and AI-assisted analyses primarily concern organisations, brands, content and sources. They are subject to human review and do not, by themselves, constitute automated legal, medical, financial, professional or contractual decisions concerning an individual.

16. Children

KAIS services are intended for businesses, professionals and organisations. The website is not directed at children, and KAIS does not knowingly seek to collect personal data from minors. Anyone who believes that a child has submitted personal data may contact KAIS so that the matter can be investigated and appropriate action taken.

17. Links to third-party services

The website may contain links to third-party websites, social networks, tools or platforms. KAIS is not responsible for the privacy practices of independent third parties that determine their own purposes and methods of processing. You should review the privacy policies of those services before providing personal data.

18. Changes to this privacy policy

KAIS may amend this Privacy Policy to reflect changes in law or regulation, changes in service providers, changes to the website, the introduction of new services or changes to our processing activities. The date of the latest update appears at the beginning of this Policy.

Where a change materially affects your rights or the way personal data is used, KAIS may provide additional notice through an appropriate communication channel.

19. Contact

For any question concerning this Privacy Policy or the protection of your personal data:

KaiZen AI Strategy Ltd
Address: 349 Happyland Rd, Bangkapi, Bangkok 10240, Thailand
Email: gontran@kaizen-ai-strategy.com
Telephone: +66 86 273 0029
Website: kaizen-ai-strategy.com

See also: Legal notice · Politique de confidentialité (FR)