Privacy Policy
At Kokoro AI we handle personal information responsibly and transparently. This policy explains what data we may process, how we use it, and what rights you can exercise.
1. Data Controller
- Controller: Arnau Osorio
- Tax ID: 47126114B
- Registered address: Avinguda de la Mediterrània, 08214 Badia del Vallès (Barcelona)
- Privacy contact: hola.kokoroai@gmail.com
- Trading name: Kokoro AI
- Domain: kokoroai.es
2. Data We May Process
Depending on the context, we may process the following data:
- Name and surname
- Company and job title
- Professional email address
- Phone number and country code
- Country and number of locations
- Content submitted through contact or demo request forms
- Navigation and attribution data (UTMs, referrer, landing page), where applicable
- Platform usage data for authorised Kokoro AI users
- Operational data managed by business customers within Kokoro AI
3. Why We Use Personal Data
- To respond to enquiries and manage demo requests
- To contact prospective customers and prepare commercial proposals
- To provide and maintain the Kokoro AI service
- To manage accounts, users, permissions and technical support
- To ensure the security and integrity of the platform
- To measure campaign performance and website usage, where there is an appropriate legal basis
- To send commercial communications where consent or another lawful basis applies
4. Legal Basis
- Consent: for optional marketing communications or non-essential cookies.
- Pre-contractual steps: to manage demo or contact requests made at your initiative.
- Performance of a contract: to deliver the Kokoro AI service to customers.
- Legitimate interests: to improve the service, prevent fraud, or maintain security, where our interests do not override your rights.
- Legal obligation: where the law requires us to retain or disclose certain data.
5. Data Retention
- Demo requests and contact forms: as long as needed to respond and follow up, then for applicable liability periods.
- Customer data: during the contractual relationship and applicable legal periods.
- Support communications: as needed to deliver the service and maintain security.
- Cookies and analytics: as set out in the Cookie Policy.
6. Service Providers and Recipients
Kokoro AI may use technology providers acting as data processors. All active providers will be verified before this policy is published. Candidate providers include hosting and database infrastructure, email delivery, artificial intelligence, and analytics services. All processors are bound by the contractual safeguards required by applicable law.
7. International Data Transfers
Some providers may process data outside the European Economic Area. Where this occurs, appropriate safeguards will be applied, such as Standard Contractual Clauses or other mechanisms recognised under applicable data protection law.
8. Your Rights
You may exercise the following rights in relation to your personal data:
- Access: to know what data we hold about you.
- Rectification: to correct inaccurate or incomplete data.
- Erasure: to request deletion of your data where applicable.
- Objection: to object to processing based on legitimate interests.
- Restriction: to ask us to limit processing in certain circumstances.
- Portability: to receive your data in a structured, machine-readable format.
- Withdrawal of consent: without affecting the lawfulness of prior processing.
- Complaint: to lodge a complaint with your national supervisory authority, such as the Spanish DPA (AEPD) at www.aepd.es.
To exercise your rights, contact us at: hola.kokoroai@gmail.com
9. Data Processed on Behalf of Customers
When a business customer uses Kokoro AI to manage personal data relating to employees, managers, suppliers or other individuals in their operations, that business customer will generally act as the data controller, and Kokoro AI will process that data as a data processor under the relevant agreement.
10. Security
Kokoro AI applies technical and organisational measures appropriate to the level of risk, including:
- Authentication and role-based access control
- Database-level security policies
- Encrypted communications (HTTPS/TLS)
- Activity logs and audit trails
- Regular data backups
- Least-privilege access for all functions
11. Changes to This Policy
We may update this policy to reflect changes in our practices or applicable law. We will publish the updated version on this page with the last updated date.
Last updated: August 2026