Privacy Policy
1. Data controller
The data controller responsible for personal data processed via this website and our advisory services is:
- Firm: Kuma Partners
- Designated Privacy Officer: Vincent Azé, Managing Partner
- Registered address: Lisbon, Portugal
- Direct privacy inquiries: vincent@kuma.partners (or privacy@kuma.partners)
2. What personal data we collect
We collect personal data strictly where necessary to address inquiries, conduct scoping assessments, or deliver contracted advisory engagements:
- Contact and scoping inquiries: name, executive work email, company name, corporate URL, team size, funding stage, and context regarding strategic challenges submitted via our contact form.
- Executive diagnostic and intake materials: for active mandates (the 14-Day Scan, Executive Alignment Sprint, Strategic Advisory, or Leadership Offsite Facilitation), we process interview transcripts, diagnostic scorecards, organizational charts, and strategic materials provided in confidence.
- Scheduling information: name, email, and meeting parameters processed when booking discovery sessions.
- Technical and aggregated telemetry: anonymized technical metrics (browser type, operating system, aggregate visit duration) gathered via essential session operations or non-essential analytics where consented.
3. Legal bases for processing (GDPR Art. 6)
We process personal data strictly under valid legal grounds:
- Contractual necessity (Art. 6(1)(b)): to take preparatory steps prior to entering an agreement, or to execute and deliver signed advisory engagements.
- Legitimate interests (Art. 6(1)(f)): to communicate with commercial prospects, secure and optimize our web infrastructure, manage executive relationships, and protect firm assets.
- Legal and fiscal obligation (Art. 6(1)(c)): to comply with statutory corporate, tax, accounting, and commercial record-keeping regulations.
- Consent (Art. 6(1)(a)): applied exclusively to non-essential analytics cookies, which remain inactive until explicitly approved via the cookie preferences banner.
4. International data transfers (third countries)
Certain service providers supporting our infrastructure operate outside the European Economic Area (EEA), primarily in the United States. Where personal data is transferred across borders, we ensure adequate safeguards are in place pursuant to GDPR Chapter V, including:
- Utilizing vendors certified under the EU-U.S. Data Privacy Framework (DPF); or
- Executing the European Commission's approved Standard Contractual Clauses (SCCs) with robust supplementary technical safeguards.
5. Third-party sub-processors
We do not sell, rent, or trade personal data. Data is processed exclusively by vetted infrastructure partners under strict Data Processing Agreements (DPAs):
- Web hosting and edge delivery: Netlify, Inc. (United States / global CDN)
- Workplace productivity and communication: Google Workspace (Google Ireland Limited / Alphabet Inc.)
- Calendar scheduling: Cal.com / HubSpot (when active for booking calls)
- Domain and DNS routing: IONOS SE (Germany / EU)
6. Retention periods
We store data only for the period necessary to fulfill its explicit commercial or regulatory purpose:
- Unconverted inquiries: stored for up to 12 months from the last point of contact, then securely deleted.
- Client and diagnostic records: maintained for the duration of the engagement plus 7 to 10 years, in accordance with applicable Portuguese and European tax and commercial retention laws.
- Diagnostic synthesis worksheets: raw interview notes are anonymized or permanently scrubbed upon conclusion of the advisory synthesis debrief.
7. Your statutory rights under GDPR
As an EU/EEA data subject, you hold the following rights:
- Right to access (Art. 15): request confirmation and copies of personal data held about you.
- Right to rectification (Art. 16): correct inaccurate or incomplete records.
- Right to erasure, "right to be forgotten" (Art. 17): request deletion of data no longer required for statutory or contractual compliance.
- Right to restriction of processing (Art. 18): suspend data processing under specific dispute grounds.
- Right to data portability (Art. 20): receive structured, machine-readable copies of your data.
- Right to object (Art. 21): object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)): revoke cookie consent at any time via "Cookie Preferences" in our footer.
To exercise your statutory rights, email vincent@kuma.partners directly. Requests are addressed within 30 days without charge.
8. Right to lodge a complaint with a supervisory authority
If you consider that our processing violates GDPR regulations, you have the right to lodge a formal complaint with the relevant national supervisory authority. In Portugal, the competent lead authority is:
- Comissão Nacional de Proteção de Dados (CNPD)
- Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa
- Website: www.cnpd.pt
9. Automated decision-making and profiling
We do not employ automated decision-making systems, machine learning scoring algorithms, or automated profiling that produce legal or similarly significant effects on individuals.