
Privacy Policy
1. Introduction
This Privacy Policy explains how K-Defense Monitor (“KDM”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal data when you visit our website and use our services. We are committed to complying with applicable data protection laws, including the EU General Data Protection Regulation (“GDPR”) where it applies. KDM is a consulting firm registered in the State of New Jersey, United States.
2. Data controller and contact details
For the purposes of GDPR, KDM is the **controller** of personal data processed through this website. You can contact us regarding this Privacy Policy or your personal data at:
-
Legal entity: Polemos Analytica LLC
-
Registered location: State of New Jersey, United States
-
Email: mingi@kdefensemonitor.com
3. Personal data we collect
We collect the following categories of personal data:
-
Contact form data
-
Name, email address, phone number, and any information you choose to include in the message.
-
-
Newsletter signup data
-
Email address and marketing preferences.
-
-
Client portal and subscription data
-
Login credentials (such as username or email), password (stored in encrypted form by our systems or service provider), account profile details, billing and subscription information, and records of your interactions within the portal.
-
-
Transaction and billing data (for subscription purchases)
-
Name, contact details, billing address, limited payment‑related information (e.g., last four digits of card, transaction ID) processed via a secure payment processor, and records of services purchased.
-
-
Usage and technical data
-
IP address, device identifiers, browser type, operating system, pages viewed, time and date of visits, and other diagnostic data collected through cookies and similar technologies (including Google Analytics).
-
-
Marketing and communications data
-
Your preferences for receiving marketing communications from us and your communication history with KDM.
-
We do not intentionally collect special categories of data (such as health, racial or ethnic origin, or religious beliefs) through the website. [advisera](https://advisera.com/articles/gdpr-privacy-notice-6-key-elements-to-include/)
4. How we collect personal data
We collect personal data in the following ways:
-
Directly from you when you complete our contact forms, sign up for newsletters, create or use a client portal account, or purchase a subscription.
-
Automatically when you use our website, through cookies, analytics tools (such as Google Analytics), and similar technologies.
-
From service providers (e.g., payment processors, email‑marketing platforms, hosting providers) when necessary to operate our services.
5. Purposes and legal bases for processing
Where GDPR applies, we rely on specific legal bases for processing your personal data. We use your personal data for the following purposes:
-
To respond to inquiries and provide consulting services
-
Data: Contact form data, client portal data.
-
Legal basis: Performance of a contract or steps taken at your request prior to entering into a contract; legitimate interests in responding to inquiries.
-
-
To manage client accounts and subscriptions
-
Data: Client portal and subscription data, transaction data.
-
Legal basis: Performance of a contract; compliance with legal obligations (e.g., bookkeeping).
-
-
To send newsletters and marketing communications
-
Data: Newsletter data, marketing preferences.
-
Legal basis: Your consent (e.g., opt‑in for email marketing), and, where permitted, our legitimate interests in promoting our services.
-
-
To operate, secure, and improve our website and services
-
Data: Usage and technical data, cookies and analytics data.
-
Legal basis: Legitimate interests in running and improving our website, ensuring security and preventing fraud; where required for non‑essential cookies/analytics, your consent.
-
-
To comply with legal and regulatory obligations
-
Data: Any relevant category of data necessary for compliance.
-
Legal basis: Compliance with legal obligations under applicable laws.
-
-
To establish, exercise, or defend legal claims
-
Data: Any relevant category of data.
-
Legal basis: Legitimate interests in protecting our rights and responding to disputes.
-
6. Cookies and similar technologies
We use cookies and similar technologies to operate our website, enable basic functions, analyze traffic, and support future advertising activities. This includes:
-
Strictly necessary cookies required for site functionality and security.
-
Analytics cookies, such as Google Analytics, to understand how visitors use our site and improve performance.
-
In the future, advertising and tracking cookies to support online advertising and measure its effectiveness.
Where required under GDPR and other privacy laws, we will:
-
Display a cookie banner when you first visit the site.
-
Obtain your consent before setting non‑essential cookies (e.g., analytics, advertising cookies).
-
Provide a cookie settings mechanism so you can withdraw or change your consent at any time.
You can also manage cookies through your browser settings; however, disabling certain cookies may impact functionality.
7. How we share personal data
We do not sell your personal data. We may share personal data with:
-
Service providers and vendors who process data on our behalf (such as website hosting, IT support, analytics, email‑marketing tools, CRM systems, and payment processors).
-
Professional advisors (such as legal, tax, or accounting advisors) where necessary.
-
Authorities, regulators, and law enforcement when required by law or in connection with legal claims.
-
Potential buyers or business partners in connection with a merger, acquisition, or similar transaction, subject to appropriate safeguards.
These recipients are required to protect personal data and to use it only for the purposes for which it was disclosed, consistent with this Privacy Policy and applicable law.
8. International data transfers
Because KDM is based in the United States, your personal data may be processed in the U.S. and in other countries that may not provide the same level of data protection as the EEA/UK. Where GDPR applies and your data is transferred from the EEA/UK to a country that is not subject to an adequacy decision, we will use appropriate safeguards, such as Standard Contractual Clauses or equivalent mechanisms, as required by law. You may contact us for more information about these safeguards.
9. Data retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, including for:
-
Providing services and managing our relationship with you.
-
Meeting legal, accounting, and reporting obligations.
-
Resolving disputes and enforcing agreements.
Retention periods vary depending on the type of data and purpose of processing.
When personal data is no longer needed, we will delete it or anonymize it in accordance with our data retention practices and applicable law.
10. Your rights (EEA/UK and similar jurisdictions)
Where GDPR or similar laws apply to your personal data, you may have the following rights, subject to conditions and limitations in applicable law:
-
Right of access: To obtain confirmation whether we process your personal data and receive a copy.
-
Right to rectification: To request correction of inaccurate or incomplete data.
-
Right to erasure: To request deletion of your personal data in certain circumstances.
-
Right to restriction: To request restriction of processing in certain cases.
-
Right to data portability: To receive personal data in a structured, commonly used, machine‑readable format and transmit it to another controller where technically feasible.
-
Right to object: To object to processing based on legitimate interests or to direct marketing, including profiling.
-
Right to withdraw consent: Where we rely on consent, you may withdraw it at any time; this does not affect processing carried out before withdrawal.
To exercise these rights, please contact us using the details in Section 2. You also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
11. Rights under U.S. and New Jersey privacy law
U.S. and New Jersey privacy laws may provide additional rights, including the upcoming New Jersey Data Privacy Act, which grants certain rights such as access, deletion, correction, and opt‑out rights for targeted advertising and sale of personal data.
If and when the New Jersey Data Privacy Act or similar laws apply to KDM, we will update this Privacy Policy and our internal practices to reflect any additional rights and mechanisms for exercising them.
Until then, you may contact us at any time to request information about our data practices or to ask us to update or delete your personal data, subject to legal obligations.
12. Marketing communications
If you subscribe to our newsletter or other marketing communications, we will use your email address and preferences to send you updates about our services, insights, and events. You can opt out at any time by:
-
Clicking the unsubscribe link included in our emails, or
-
Contacting us directly using the contact information in Section 2.
Opting out of marketing communications will not affect service‑related communications (for example, emails about your subscription or account).
13. Security of personal data
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or alteration. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal data, we will notify you and relevant authorities as required by law.
14. Children’s privacy
Our website and services are not directed to children under the age of 16, and we do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us so we can take appropriate steps to delete such information.
15. Third‑party links and services
Our website may contain links to third‑party websites, plug‑ins, or services. These third‑party sites have their own privacy policies, and we are not responsible for their content, practices, or policies. We encourage you to review the privacy policies of any third‑party services you visit or use. Any data you provide to third parties is governed by their policies and not this Privacy Policy.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or other factors. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you through the website or by email. Your continued use of the website after such updates signifies your acceptance of the revised Privacy Policy. Last updated: March 4, 2026
17. How to contact us
If you have questions, concerns, or requests regarding this Privacy Policy or our handling of personal data, you may contact us at:
-
Email: mingi@kdefensemonitor.com
# # #