Heading 1
Last Updated: February3, 2026
This Privacy Policy explains how Kalepa, Inc.("Kalepa," "we," "us") collects, uses, discloses,and otherwise processes personal information in connection with our websites(including kalepa.com and related pages), marketing activities, andbusiness-to-business interactions, and describes the rights and choicesavailable to individuals.
1. Who we are and how to contact us
Kalepa Corporation
920 Broadway, Floor 15
New York, NY 10010
United States
Email: privacy@kalepa.com
2. Scope
This Privacy Policy applies to personal information we process as a controller for our websites, marketing, and general business operations. If you use our products or services as an employee, contractor, or representative of a business customer, your use may also be governed by contractual terms and a separate customer agreement. If you apply for a job or are our employee, see Section 12 (HR data).
3. Personal information we collect
We collect personal information from the following sources:
Information you provide:
• Contact details (such as name, work email address, phone number, company name, job title).
• Communications (such as emails, chat messages, and information you submit through forms on our websites).
• Marketing preferences (such as whether you subscribe to updates).
Information collected automatically:
• Device and usage data (such as IP address, browser type, pages viewed, and approximate location derived from IP).
• Cookie and similar technology data (see Section 6).
Information from others:
• Business contact information from referrals, events, or publicly available sources (such as professional networking sites).
4. How we use personal information
We use personal information for the following purposes:
• Provide, operate, and improve our websites and services.
• Respond to inquiries, schedule demos, and communicate with you.
• Send marketing communications (where permitted) and manage subscriptions.
• Analyze website usage and measure campaign performance.
• Maintain security, prevent fraud and abuse, and protect our rights and property.
• Comply with applicable law and enforce our agreements.
5. Legal bases for processing (EEA, UK, and Switzerland)
Where the GDPR, UK GDPR, or Swiss data protection law applies, we rely on one or more of the following legal bases, as appropriate: (a) performance of a contract; (b) our legitimate interests (such as improving our websites, marketing to business customers, and securing our systems), balanced against your rights; (c) compliance with legal obligations; and (d) consent, where required (for example, for certain cookies or marketing in some jurisdictions).
6. Cookies and similar technologies
We use cookies and similar technologies (such as pixels and local storage) to operate our websites, understand usage, and support marketing. You can manage non-essential cookies through our cookie consent tool (implemented via Finsweet) and through your browser settings. If you reject non-essential cookies, some features may not function as intended.
We use the following tools (depending on configuration and your choices):
• Google Analytics: Helps us understand website traffic and usage patterns. We configure it to respect your cookie choices where required.
• HubSpot: Supports website forms, customer relationship management, and marketing communications. Webflow forms may map to HubSpot fields.
• RB2B (U.S. visitors only): We configure RB2B to operate only for U.S. visitors and not to process data for visitors in the EEA, UK, or Switzerland.
7. How we disclose personal information
We do not sell personal information. We disclose personal information in the following circumstances:
• Service providers and processors that support our business (for example, hosting, analytics, customer support, communications, security, and marketing).
• Professional advisors (such as auditors, lawyers, and accountants).
• Compliance and protection (for example, to comply with law, respond to lawful requests, protect rights and safety, and prevent fraud).
• Business transfers (for example, in connection with a merger, acquisition, financing, reorganization, or sale of assets).
8. International data transfers
Kalepa is headquartered in the United States and may process personal information in the U.S. and other countries. Where required for transfers from the EEA, the UK, and Switzerland to the United States, we rely on approved transfer mechanisms, including the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework ("Swiss-U.S. DPF"), and/or other lawful transfer tools (such as standard contractual clauses), as applicable.
9. EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF notice
Kalepa complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union, the United Kingdom (and Gibraltar), and Switzerland to the United States.
If there is any conflict between the terms in this Privacy Policy and the DPF Principles, the DPF Principles shall govern. To learn more about the DPF program and to view our certification, please visit the Data Privacy Framework website at https://www.dataprivacyframework.gov/.
Independent recourse mechanism (free of charge): If you have a complaint about our handling of personal information under the DPF, please contact us first at privacy@kalepa.com. If we cannot resolve your concern, you may submit a complaint to JAMS, our U.S.-based independent recourse mechanism, at https://www.jamsadr.com/dpf-dispute-resolution.
Regulatory oversight: Kalepa is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission.
Onward transfers: If we transfer personal information received under the DPF to a third party acting as an agent, we will do so consistent with the DPF Principles and will remain liable under the DPF Principles if the agent processes the information in a manner inconsistent with the DPF Principles, unless we prove we are not responsible for the event giving rise to the damage.
Binding arbitration: Under certain conditions, individuals may be able to invoke binding arbitration for complaints regarding DPF compliance not resolved by other DPF mechanisms.
HR data:
Kalepa may receive personal information in the context of an employment relationship ("HR data") from the European Union. With respect to EU HR data transferred under the EU-U.S. DPF, Kalepa commits to cooperate with and comply with the advice of the EU data protection authorities (DPAs).
10. Data retention
We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, including to provide services, maintain our relationship with you, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary depending on the type of information, the context in which it was collected, and applicable legal requirements.
11. Your rights and choices
EEA, UK, and Switzerland
Depending on your location and the applicable law, you may have rights to request access, rectification, erasure, restriction, portability, and to object to processing (including certain direct marketing). You may also have rights related to automated decision-making. You also have the right to lodge a complaint with your local supervisory authority.
To exercise rights, contact us at privacy@kalepa.com. We may need to verify your identity before responding.
Marketing communications
You can opt out of marketing emails by using the unsubscribe link in our emails or by contacting us at privacy@kalepa.com. Transactional and service-related communications are not subject to marketing opt-out.
California
If you are a California resident, you may have rights under California privacy laws. For California 'Shine the Light' requests, email privacy@kalepa.com with the subject line 'REQUEST FOR CALIFORNIA PRIVACY INFORMATION'.
12. HR data (job applicants and employees)
If you apply for a job with us or are our employee/contractor, we process personal information for recruitment, employment administration, and related purposes. Where applicable, HR data from the EU may be processed in reliance on the EU-U.S. DPF as described in Section 9.
13. Security
We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information. However, no security measures are perfect. If you believe your interaction with us is no longer secure, please notify us at security@kalepa.com.
14. Children
Our websites and services are not directed to children under 18, and we do not knowingly collect personal information from children under 18.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the 'Last Updated' date above.
16. Questions and complaints
If you have questions or complaints about this Privacy Policy or our privacy practices, contact us at privacy@kalepa.com or write to us at the address in Section 1.