Book a free call

Privacy Policy

Privacy at KAIRO

Last updated: August 2026

KAIRO Consulting OÜ handles personal data carefully and confidentially. This page explains which data we process, why we process it, which systems we use, and what rights you have.

Personal data is processed in accordance with the General Data Protection Regulation (GDPR) and, where applicable, additional Estonian privacy legislation.

KAIRO Consulting OÜ is the data controller for the processing of personal data.

Company name
KAIRO Consulting OÜ
Registry code
17519232
Registered office
Sepapaja tn 6, 15551 Tallinn, Estonia
E-mail
kairo.consultancy@gmail.com

KAIRO operates fully online; no client sessions take place at this address.

Which data do we process?

Which personal data we process depends on how you get in touch with KAIRO. This may include:

  • your name and e-mail address;
  • your phone number, if provided;
  • the details you enter when booking an appointment;
  • appointment and calendar data;
  • e-mail correspondence and practical communication;
  • information about the service or programme you take part in;
  • invoicing and payment data.

During conversations you may choose to share information about, for example, behaviour, alcohol or drug use, craving, recurring patterns, psychological functioning or other personal circumstances.

Under the GDPR, some of this data may qualify as special categories of personal data, including health data. KAIRO only processes data that is reasonably necessary for the service.

No regular client file

KAIRO is not a healthcare institution and does not keep a regular medical, psychological or psychiatric client file.

Contact details, appointments, contractual information, e-mails, invoices and payment data may of course be processed where this is necessary for the service or for administration.

Where substantive working notes are necessary for a guidance programme, these are kept to what is needed. Directly identifying data is, where possible, not recorded or is removed. Substantive working notes are deleted once they are no longer necessary after the programme has ended.

Why do we process personal data?

We use personal data for purposes including:

  • answering questions or contact requests;
  • scheduling appointments;
  • introductory and exploratory conversations;
  • preparing and delivering guidance programmes;
  • practical communication;
  • invoicing and payment processing;
  • financial and statutory administration;
  • handling complaints;
  • the security and proper functioning of our digital services.

Personal data about behaviour, substance use, health or psychological functioning is not used for advertising profiling, commercial data trading or general marketing purposes. KAIRO does not sell personal data.

Which external services do we use?

For our online services and business operations we use, among others:

Mijn.host
For hosting and the technical operation of the website.
Calendly
For scheduling and managing appointments.
Google
For business e-mail, calendar and online conversations via Google Meet.
WhatsApp
For short, practical communication where appropriate. We ask clients to avoid sharing sensitive substantive information via WhatsApp as much as possible.
Wise
For business payments.
Xolo
For administration, bookkeeping and invoicing.

These organisations process personal data only insofar as this relates to the service in question or to their own legal obligations.

Where an external party processes personal data on behalf of KAIRO, appropriate arrangements are made in accordance with Article 28 GDPR where required.

Working from Thailand

KAIRO Consulting OÜ is a company registered in Estonia, but the service is delivered internationally and, in part, structurally from Thailand.

This means that KAIRO’s director and practitioner may access personal data within KAIRO’s systems from Thailand. This access takes place:

  • on behalf of KAIRO Consulting OÜ;
  • within the same company and responsibility;
  • only for the purposes for which the data was collected;
  • via authorised business devices and accounts.

This does not automatically constitute a transfer to a separate Thai organisation: the processing takes place within the same controller. Access from a country outside the EEA does, however, carry additional security risks. The security and accountability obligations under the GDPR therefore continue to apply in full.

Where personal data is in fact transferred to a separate organisation outside the EEA, KAIRO assesses whether additional safeguards are required under Chapter V of the GDPR.

How do we secure personal data?

KAIRO takes appropriate technical and organisational security measures, including:

  • secured business devices;
  • strong passwords and access codes;
  • multi-factor authentication where available;
  • automatic screen locking;
  • restricted access to personal data;
  • up-to-date software and security updates;
  • limited local storage;
  • data minimisation;
  • timely deletion of data;
  • careful use of external services.

Security measures are matched to the nature and sensitivity of the data being processed.

Recordings, transcripts and AI

KAIRO does not record or transcribe conversations as standard.

If a recording, transcription or AI service that processes client content is used in future, we will assess beforehand:

  • which data is processed;
  • which supplier is used;
  • where data is stored;
  • which retention periods apply;
  • which privacy and security risks exist;
  • whether separate consent is necessary.

If such a way of working is introduced, this privacy statement will be updated beforehand where necessary.

How long do we keep data?

We do not keep personal data longer than necessary. In broad terms:

Substantive working notes
Deleted as soon as they are no longer needed after the programme has ended.
Contact and appointment data
Kept for as long as reasonably necessary for communication, service delivery or administrative handling.
Contractual information and Start Agreements
May be kept for as long as needed to demonstrate agreements, consents and applicable terms.
Invoices and financial administration
Kept for the applicable statutory tax and accounting retention periods.
Complaint or dispute data
May be kept for as long as necessary for handling the matter or for any legal claims.

Your privacy rights

Where the GDPR applies, you may, under certain conditions, exercise the right to:

  • access your personal data;
  • rectification of inaccurate data;
  • erasure of personal data;
  • restriction of processing;
  • data portability;
  • object to certain processing;
  • withdraw consent given earlier.

KAIRO does not use solely automated decision-making that has legal or similarly significant effects on clients.

You can send a privacy request to kairo.consultancy@gmail.com. We respond within one month in principle. The GDPR allows an extension under certain conditions for complex or multiple requests.

We may ask you to sufficiently confirm your identity before personal data is provided or changed.

Data breaches

Where a security incident leads to loss of, unauthorised access to, or other unlawful processing of personal data, KAIRO assesses whether a data breach has occurred.

Where the GDPR requires it, the incident is reported to the competent supervisory authority and the individuals concerned are informed.

Cookies

The website may use functional cookies that are necessary for it to work properly and securely.

Where analytical, marketing or other non-essential cookies requiring consent are used, they are only placed after consent has been obtained.

Questions or complaints

Do you have questions about your privacy or about the processing of your personal data? Please get in touch at kairo.consultancy@gmail.com.

You also have the right to lodge a complaint with a competent data protection supervisory authority. For KAIRO Consulting OÜ, the national privacy supervisory authority in Estonia is the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate).

Under the conditions of the GDPR you may also turn to a competent supervisory authority in the EU country where you habitually live or work.

Full privacy statement

This web page sets out in accessible terms how KAIRO handles personal data.

For a more extensive description of our privacy rules, legal bases, international processing and internal security measures, you can consult the full Privacy Statement of KAIRO Consulting OÜ – version 1.2.

This is a translation provided for convenience. The Dutch version of this privacy statement is the leading version.