KPA Cashmere - Home

GDPR Compliance

Last updated: September 2026

1. GDPR Overview

The General Data Protection Regulation (GDPR) is a European Union regulation that governs the collection, processing, and protection of personal data. KPA Cashmere is committed to full compliance with GDPR requirements, regardless of whether you are a resident of the EU or not.

This page explains how we comply with GDPR and the rights you have as a data subject under the regulation. If you have any questions about our GDPR compliance, please contact us using the information provided in the "Contact Us" section.

2. Legal Basis for Data Processing

We process your personal data only when we have a legal basis to do so under GDPR. The legal bases we rely on are:

2.1 Consent

We collect and process certain data (such as analytics data) only with your explicit consent. You can withdraw consent at any time through our cookie consent tool or by contacting us.

2.2 Legitimate Interest

We process data for legitimate business interests, such as:

  • Improving our website and services
  • Preventing fraud and ensuring security
  • Responding to inquiries and providing customer support
  • Analyzing website traffic and user behavior

2.3 Contractual Obligation

When you request a quotation or enter into a business relationship with us, we process data necessary to fulfill those contracts.

2.4 Legal Compliance

We process data when required by applicable laws, regulations, or court orders.

3. Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

3.1 Right of Access

You have the right to request a copy of the personal data we hold about you, including what data we process, why we process it, and how long we retain it.

3.2 Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to request correction or completion.

3.3 Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data under certain circumstances, such as when the data is no longer necessary or when you withdraw consent. Note that some data may need to be retained for legal compliance.

3.4 Right to Restrict Processing

You can request that we limit how we process your data while we verify its accuracy or lawfulness.

3.5 Right to Data Portability

You can request your personal data in a structured, commonly used, and machine-readable format, and have it transferred to another service provider.

3.6 Right to Object

You can object to processing of your personal data for legitimate interest or marketing purposes. We will cease processing unless we have compelling reasons to continue.

3.7 Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing if it has a legal or similarly significant effect on you.

4. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy and Cookie Policy, or as required by law. Retention periods vary depending on the type of data:

  • Contact Form Data: Retained for 2 years or until you request deletion
  • Analytics Data: Retained for 13-26 months
  • Marketing Data: Retained for up to 1 year from last interaction
  • Business Records: Retained per applicable law (typically 7 years)

5. Data Transfers Outside the EU/EEA

Our website and services may involve transfers of personal data to countries outside the European Union/European Economic Area. When we transfer data internationally, we implement appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules where applicable
  • Your explicit consent prior to transfer
  • Verification of adequate protection in the destination country

Vercel (our hosting provider) participates in mechanisms that ensure adequate data protection for EU/EEA data transfers.

6. Data Processors and Third Parties

We use the following data processors who assist us in providing our services:

  • Vercel: Website hosting and deployment (Privacy Policy: vercel.com/privacy)
  • Google Analytics/GTM: Analytics and tag management (Privacy Policy: google.com/policies/privacy)
  • Email Services: Communication and support inquiries

All processors have Data Processing Agreements (DPAs) in place to ensure GDPR compliance.

7. Data Breach Notification

In the event of a data breach affecting your personal data, we will notify you and relevant authorities without undue delay (within 72 hours) as required by GDPR Article 33, unless the breach poses no risk to your rights and freedoms.

We maintain comprehensive security measures to prevent unauthorized access, alteration, or disclosure of personal data.

8. Data Protection Officer

While we do not have a dedicated Data Protection Officer, we have designated a privacy contact who oversees GDPR compliance. You can reach our privacy contact using the information in the "Contact Us" section below.

9. How to Exercise Your Rights

To exercise any of your GDPR rights, please submit a written request to us using the contact information below. We will verify your identity and respond to your request within 30 days (or up to 60 days for complex requests) in accordance with GDPR requirements.

No fee is required to exercise your rights unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee.

10. Complaints to Supervisory Authorities

If you believe we have violated your GDPR rights, you have the right to lodge a complaint with your local data protection authority. For EU/EEA residents, you can file a complaint with your national data protection authority:

  • European Data Protection Board (EDPB): edpb.ec.europa.eu
  • Your country's national data protection authority

We encourage you to contact us first to resolve any concerns before filing a complaint.

11. Children's Data Protection

Our website is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16 without parental consent, we will take steps to delete it immediately.

12. Changes to This GDPR Compliance Statement

We may update this GDPR Compliance statement to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by updating the "Last updated" date at the top of this page.

13. Contact Us

For GDPR-related inquiries or to exercise your data subject rights, please contact us:

Please allow 30 days for us to respond to GDPR-related requests.