
Global Privacy & Data Protection Policy
How K2M collects, uses, protects, and processes personal information across the jurisdictions in which it operates.
01Introduction
Kratos II Management (“K2M,” “we,” “us,” or “our”) respects privacy and is committed to protecting personal information entrusted to us.
This Global Privacy & Data Protection Policy (“Policy”) explains how K2M collects, uses, discloses, protects, retains, and otherwise processes personal information when individuals interact with us, visit our websites, use our digital services, communicate with us, engage with us in a business or professional capacity, participate in our activities, or otherwise provide personal information to us.
K2M operates and conducts business across multiple jurisdictions. Accordingly, personal information may be subject to different privacy and data protection laws depending on where an individual is located, where information is collected, where it is processed, and the nature of the relationship with K2M.
This Policy establishes K2M’s global privacy principles and is intended to be applied consistently with applicable privacy and data protection laws. Where local law provides additional or more specific rights, protections, or obligations, those requirements will apply to the extent applicable.
K2M does not sell personal information for monetary consideration. We seek to collect and process personal information only for legitimate, identified, and lawful purposes and to limit collection to information that is reasonably necessary for those purposes.
For privacy-related questions, requests, or complaints, please contact:
K2M Privacy Office
Email: [email protected]
02Who We Are
Kratos II Management (“K2M”) is an international management, security, intelligence, technology, and strategic services organization.
For purposes of applicable privacy laws, K2M or the relevant K2M-affiliated legal entity may act as a Data Controller, Business, Responsible for the Processing, or equivalent role when it determines the purposes and means of processing personal information.
K2M may also act as a Data Processor, Service Provider, Data Intermediary, Data Processor/Encargado, or equivalent role when it processes personal information on behalf of a client or another organization and according to that organization’s documented instructions.
The specific K2M legal entity responsible for processing may depend on the contractual relationship, service, jurisdiction, and nature of the processing activity.
Where K2M acts as a processor or service provider, the client’s applicable privacy notice and contractual arrangements may also govern the processing.
03Scope
This Policy applies to personal information processed by K2M through or in connection with:
- K2M websites and digital properties;
- online forms, portals, applications, and platforms;
- business communications and correspondence;
- client, partner, supplier, and professional relationships;
- conferences, meetings, events, and other business activities;
- recruitment and professional engagement processes;
- security, intelligence, risk, research, analytical, advisory, and related services;
- contractual and commercial activities; and
- other lawful business activities conducted by K2M.
This Policy does not necessarily apply to personal information that K2M processes solely on behalf of a client as a processor or service provider where the client has primary responsibility for the relevant privacy notice and data subject rights. In such circumstances, K2M will process information in accordance with the applicable agreement and the client’s documented instructions, subject to applicable law.
04Personal Information We May Collect
Depending on the nature of the relationship and the services involved, K2M may collect and process categories of personal information such as:
4.1 Identification and Contact Information
- name and surname;
- business or personal email address;
- telephone number;
- postal or business address;
- professional contact details;
- identification information where necessary and lawful.
4.2 Professional and Business Information
- employer, organization, or affiliation;
- job title and professional role;
- professional qualifications and experience;
- business relationships;
- information contained in business correspondence;
- information required to establish or manage a commercial relationship.
4.3 Technical and Online Information
- IP address;
- browser and device information;
- operating system;
- website activity and interaction data;
- access logs;
- authentication information;
- cookies and similar technologies;
- security and diagnostic information.
4.4 Transaction and Commercial Information
Where applicable, K2M may process information necessary to establish and manage commercial relationships, including billing, payment, contractual, procurement, and transaction-related information.
4.5 Information Relevant to Security, Intelligence, Risk, and Investigative Services
Depending on the specific engagement and applicable law, K2M may process information that is relevant and necessary to provide security, intelligence, investigative, due diligence, risk management, compliance, analytical, or related services.
Such information may include professional, organizational, public-record, corporate, reputational, location, identity, or other information that is lawfully available or provided to K2M for a defined purpose.
K2M will not interpret this section as a general authorization to collect unrestricted personal information. The nature and scope of information processed will depend on the specific purpose, legal basis, engagement, contractual requirements, and applicable law.
4.6 Information Provided by Individuals
We may collect information that individuals voluntarily provide to us, including information submitted through forms, applications, inquiries, communications, or other interactions.
05Sources of Personal Information
K2M may obtain personal information from:
- the individual directly;
- clients, employers, partners, or authorized representatives;
- suppliers and service providers;
- publicly available sources and records, where lawful;
- professional or business databases;
- government or regulatory sources where lawful;
- K2M websites and digital services;
- technology systems and security logs; and
- other lawful sources appropriate to the purpose for which the information is processed.
Where required by applicable law, K2M will provide appropriate notice and obtain consent or another valid legal authorization before collecting or using personal information.
06How We Use Personal Information
K2M may use personal information for purposes including:
- providing and managing services;
- communicating with clients, partners, suppliers, and other stakeholders;
- responding to inquiries and requests;
- managing contracts and commercial relationships;
- conducting due diligence, risk assessment, research, analysis, and related professional services;
- delivering security, intelligence, investigative, and advisory services;
- protecting people, systems, facilities, information, and other assets;
- maintaining the security and integrity of digital services;
- detecting, preventing, investigating, and responding to fraud, abuse, unauthorized activity, or security incidents;
- complying with legal, regulatory, contractual, and professional obligations;
- recruiting and managing professional relationships;
- maintaining business records;
- improving websites, services, systems, and user experience;
- communicating information about K2M and its services where permitted;
- establishing, exercising, or defending legal rights and claims; and
- other purposes that are compatible with the purpose for which information was collected or otherwise permitted by applicable law.
K2M will not use personal information for materially incompatible purposes without appropriate authorization, notice, or other legal basis where required.
07Legal Bases for Processing
The legal basis for processing personal information varies according to the applicable jurisdiction and the circumstances of the processing.
Depending on the applicable law, K2M may rely on:
- consent;
- performance of a contract or steps taken at an individual’s request before entering into a contract;
- compliance with legal or regulatory obligations;
- protection of vital interests;
- legitimate business interests, where permitted by law and appropriately balanced against individual rights;
- the establishment, exercise, or defense of legal claims; and
- other legal bases recognized by applicable law.
Where consent is the applicable legal basis, individuals may have the right to withdraw consent subject to legal and contractual limitations. Withdrawal of consent will not affect processing that occurred before withdrawal where such processing was lawful.
08Sensitive and Special Categories of Personal Information
Certain jurisdictions recognize categories of personal information as sensitive or subject to enhanced protection.
Depending on the engagement and applicable law, K2M may encounter or process sensitive information, including information relating to identity, biometrics, financial matters, health, precise location, criminal or legal matters, or other protected categories.
K2M will process sensitive or specially protected information only when there is an appropriate legal basis and a legitimate, defined purpose for doing so.
Where applicable law requires heightened consent, additional safeguards, specific notices, or other conditions for processing sensitive information, K2M will comply with those requirements.
K2M does not request sensitive information through ordinary website forms unless it is reasonably necessary for a defined purpose.
09Security, Intelligence, Investigative, and Risk Services
Because K2M may provide services involving security, intelligence, risk, investigation, due diligence, research, and analysis, certain engagements may require the lawful processing of information relating to individuals, organizations, assets, events, or activities.
In such engagements:
- K2M will define the relevant purpose and scope of processing;
- K2M will seek to process information that is relevant and reasonably necessary for the engagement;
- K2M will apply appropriate confidentiality and security measures;
- K2M will respect applicable legal restrictions concerning protected or sensitive information;
- K2M will distinguish, where appropriate, between information provided by a client, information generated through analysis, and information obtained from lawful sources; and
- K2M will process information according to applicable contracts, instructions, and laws.
Nothing in this Policy authorizes unlawful surveillance, unauthorized access to systems, unlawful collection of personal information, or processing prohibited by applicable law.
10Disclosure of Personal Information
K2M may disclose personal information when reasonably necessary and lawful to:
- affiliated K2M entities;
- clients and authorized representatives;
- professional advisers;
- technology providers;
- hosting, cloud, communications, analytics, security, and infrastructure providers;
- contractors and service providers acting on K2M’s behalf;
- auditors and professional service providers;
- insurers and financial institutions where appropriate;
- government authorities, regulators, courts, or law enforcement agencies where required or permitted by law;
- parties involved in corporate transactions; and
- other recipients where the individual has provided appropriate authorization or where disclosure is otherwise permitted by applicable law.
K2M seeks to limit disclosures to information that is reasonably necessary for the relevant purpose.
Where K2M engages a third party to process personal information on its behalf, K2M will use contractual, organizational, technical, or other appropriate measures to require the third party to protect the information and process it only for authorized purposes, subject to applicable law.
11Data Processing by Third Parties
K2M may use third-party service providers for hosting, infrastructure, communications, cybersecurity, analytics, document management, customer relationship management, payment processing, professional services, and other business functions.
Depending on the jurisdiction and relationship, these providers may act as processors, service providers, contractors, or equivalent roles.
K2M will take reasonable steps to select service providers appropriate to the nature and sensitivity of the information involved and, where required, will establish contractual obligations concerning confidentiality, security, use, disclosure, retention, and deletion.
12International Data Transfers
K2M operates and works with clients, partners, suppliers, affiliates, and service providers in multiple jurisdictions.
Personal information may therefore be processed, stored, or accessed in a country other than the country in which it was originally collected.
Where personal information is transferred across borders, K2M will take reasonable and appropriate measures to conduct the transfer in accordance with applicable privacy and data protection laws.
Depending on the applicable jurisdiction, such measures may include contractual protections, appropriate safeguards, consent, legally recognized transfer mechanisms, risk assessments, or other measures required by law.
Individuals should understand that information transferred to another jurisdiction may be subject to the laws of that jurisdiction and may be accessible to courts, law enforcement, national security authorities, or other lawful authorities where permitted by applicable law.
13Data Security
K2M maintains administrative, technical, organizational, and physical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, loss, destruction, or other unlawful processing.
Security measures may include, as appropriate to the circumstances:
- access controls;
- authentication and authorization measures;
- confidentiality obligations;
- security monitoring;
- secure information transmission;
- physical safeguards;
- backup and recovery measures;
- vendor and service-provider controls;
- incident response procedures; and
- personnel awareness and training.
The safeguards applied will depend on the nature, sensitivity, volume, purpose, and risk associated with the information and processing activity.
No method of transmission, storage, or processing can be guaranteed to be completely secure. K2M therefore maintains processes designed to identify, respond to, and mitigate privacy and security incidents.
14Data Retention
K2M retains personal information only for as long as reasonably necessary to:
- fulfill the purpose for which it was collected;
- provide services;
- maintain business and contractual records;
- comply with legal, regulatory, tax, accounting, or professional obligations;
- establish, exercise, or defend legal claims;
- resolve disputes;
- protect K2M and its stakeholders; or
- fulfill another lawful and documented purpose.
Retention periods may vary according to the nature of the information, the purpose of processing, contractual requirements, legal obligations, and applicable jurisdiction.
When personal information is no longer required, K2M will seek to securely delete, destroy, anonymize, or otherwise dispose of it in accordance with applicable requirements.
15Accuracy and Data Quality
K2M seeks to maintain personal information that is reasonably accurate, complete, and current for the purposes for which it is used.
Individuals may contact K2M at [email protected] to request correction or updating of their personal information, subject to applicable law.
Where K2M processes information on behalf of a client, requests may need to be directed to the relevant client or controller.
17Marketing Communications
K2M may send business or marketing communications where permitted by applicable law.
Individuals may unsubscribe from marketing communications by using the applicable unsubscribe mechanism or by contacting [email protected].
Opting out of marketing communications does not necessarily prevent K2M from sending service-related, contractual, security, legal, or other necessary communications.
18Privacy Rights
Depending on applicable law, individuals may have rights relating to their personal information, including the right to:
- know whether K2M processes their personal information;
- access or obtain a copy of personal information;
- request correction or updating of inaccurate or incomplete information;
- request deletion or suppression where legally available;
- withdraw consent where consent is the legal basis;
- object to or restrict certain processing;
- request information about how personal information is used or disclosed;
- challenge K2M’s handling of personal information;
- opt out of certain marketing, sale, sharing, or targeted advertising activities where applicable; and
- lodge a complaint with an applicable privacy or data protection authority.
The availability and scope of these rights depend on applicable law. K2M may need to verify identity before fulfilling certain requests and may be permitted or required to retain or process information notwithstanding a request for deletion or restriction.
19Jurisdiction-Specific Privacy Provisions
19.1 United States
Privacy laws in the United States vary by federal, state, and sector-specific requirements.
K2M will comply with applicable U.S. privacy and data protection requirements that apply to its activities and relationships.
Where applicable, K2M may provide additional notices, disclosures, rights, or mechanisms required by a particular U.S. jurisdiction.
19.2 California
Where K2M is subject to the California Consumer Privacy Act, as amended (“CCPA”), California residents may have additional rights concerning personal information.
Depending on the circumstances and applicable law, these rights may include rights to:
- know and access certain personal information;
- request correction;
- request deletion;
- limit certain uses or disclosures of sensitive personal information;
- opt out of certain sales or sharing of personal information; and
- exercise other rights provided by California law.
K2M does not sell personal information for monetary consideration.
If K2M engages in an activity that is considered “sale,” “sharing,” or another regulated activity under applicable California law, K2M will provide the disclosures and opt-out mechanisms required by law.
California privacy requests may be submitted to:
K2M will process such requests in accordance with applicable California law and may take reasonable steps to verify the identity and authority of the requesting individual.
19.3 Canada
Where applicable, K2M will process personal information in accordance with Canada’s federal and provincial privacy laws, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”) where applicable.
K2M’s Canadian privacy practices are based on principles including:
- accountability;
- identifying purposes;
- meaningful consent where required;
- limiting collection;
- limiting use, disclosure, and retention;
- accuracy;
- safeguards;
- openness;
- individual access; and
- mechanisms for challenging compliance.
Where K2M transfers personal information to third-party service providers for processing outside Canada, K2M will use appropriate contractual or other measures and will maintain transparency concerning such processing as required by applicable law.
Privacy inquiries and complaints may be submitted to:
K2M Privacy Office
[email protected]
K2M will maintain appropriate processes for responding to access requests, privacy inquiries, complaints, and other requests in accordance with applicable Canadian law.
19.4 Latin America
K2M recognizes that countries throughout Latin America maintain their own privacy and data protection frameworks.
K2M will comply with the privacy and data protection laws applicable to the jurisdiction in which personal information is collected, processed, stored, transferred, or otherwise handled.
Where local law provides rights or obligations that are more specific or protective than this Policy, K2M will apply those requirements to the extent applicable.
Depending on the jurisdiction, these requirements may include rules concerning:
- prior and informed authorization or consent;
- transparency and notice;
- purpose limitation;
- data minimization;
- security and confidentiality;
- cross-border transfers;
- sensitive personal information;
- access, correction, deletion, or objection rights;
- retention;
- incident management; and
- regulatory or supervisory authority requirements.
19.5 Colombia
For processing activities subject to Colombian law, K2M will comply with applicable Colombian personal data protection requirements, including the framework established by Law 1581 of 2012 and its applicable regulations and subsequent amendments.
Subject to applicable law, Colombian data subjects may have rights including:
- to know, update, and rectify their personal information;
- to request evidence of authorization where applicable;
- to be informed, upon request, about the use made of their personal information;
- to file complaints with the competent authority where applicable;
- to request deletion of personal information or revocation of authorization when legally appropriate; and
- to exercise other rights established by applicable Colombian law.
Requests relating to personal information may be submitted to:
K2M will respond to queries and complaints according to the procedures and statutory periods applicable to the relevant processing activity and jurisdiction.
Where K2M acts as a processor or data intermediary on behalf of another organization, the applicable controller’s privacy policy and instructions may also govern the processing.
20Children’s Privacy
K2M’s services are generally intended for business, professional, and adult users.
K2M does not knowingly seek to collect personal information from children where such collection is prohibited by applicable law.
If we learn that personal information has been collected from a child in circumstances where the collection was not permitted, we will take appropriate steps consistent with applicable law.
21Third-Party Websites and Services
K2M websites or communications may contain links to websites, applications, platforms, or services operated by third parties.
K2M is not responsible for the privacy practices of third parties that it does not control.
Individuals should review the privacy policies and terms applicable to third-party services before providing personal information.
22Corporate Transactions
Personal information may be transferred or disclosed as part of a merger, acquisition, restructuring, financing, sale of assets, change of control, bankruptcy, or other corporate transaction, subject to applicable law and appropriate safeguards.
Where required, K2M will provide notice or obtain authorization in connection with such transfers.
23Legal and Regulatory Disclosures
K2M may disclose personal information when reasonably necessary to:
- comply with applicable law or legal process;
- respond to lawful requests from governmental, regulatory, judicial, or law enforcement authorities;
- protect the rights, property, security, or safety of K2M, its clients, personnel, users, or other persons;
- investigate fraud, security incidents, misconduct, or unlawful activity; or
- establish, exercise, or defend legal claims.
K2M will seek to limit such disclosures to what is reasonably necessary and permitted by applicable law.
24Data Processing Addenda and Client Relationships
Where K2M processes personal information on behalf of a client, the parties may enter into a Data Processing Addendum (“DPA”) or equivalent contractual arrangement.
Such an agreement may define:
- the subject matter and duration of processing;
- the nature and purpose of processing;
- categories of personal information;
- categories of data subjects;
- instructions from the controller;
- confidentiality obligations;
- security measures;
- use of subprocessors;
- international transfers;
- incident notification;
- assistance with data subject requests;
- retention and deletion; and
- other responsibilities required by applicable law.
Where there is a conflict between this public Policy and a specific contractual data protection agreement, the contractual agreement will govern the relevant processing to the extent permitted by applicable law.
25Privacy and Security Incidents
K2M maintains processes designed to identify, assess, contain, investigate, and respond to suspected privacy or security incidents involving personal information.
Where applicable law requires notification to affected individuals, clients, regulators, or other parties, K2M will make such notifications within the time and in the manner required by law or applicable contractual obligations.
Where K2M acts as a processor or service provider, notification obligations may be governed by the applicable client agreement and applicable law.
26Changes to This Policy
K2M may update this Policy from time to time to reflect changes in our services, business operations, technology, legal requirements, or privacy practices.
The “Last Updated” date at the beginning of this Policy indicates when the Policy was most recently revised.
Where required by applicable law, K2M will provide additional notice or obtain consent for material changes.
27Contact K2M
For privacy and data protection questions, requests, complaints, or inquiries, contact:
K2M Privacy Office
Email: [email protected]
When submitting a privacy request, individuals should provide sufficient information for K2M to understand the request and, where required, verify identity and authority.
K2M may request additional information where reasonably necessary to verify identity, protect personal information, prevent fraud, or comply with applicable law.
28Governing Principles
This Policy is based on the following principles:
- Lawfulness and accountability — K2M seeks to process personal information lawfully and responsibly.
- Purpose limitation — information is collected and used for defined and legitimate purposes.
- Data minimization — K2M seeks to collect and retain only information reasonably necessary for the relevant purpose.
- Transparency — K2M seeks to provide clear information about its privacy practices.
- Security and confidentiality — K2M applies safeguards appropriate to the nature and risk of processing.
- Accuracy — K2M seeks to maintain accurate and appropriately current information.
- Retention limitation — information is retained only as long as reasonably necessary or legally required.
- Individual rights — K2M respects applicable rights concerning personal information.
- Responsible international processing — cross-border processing is conducted with appropriate safeguards.
- Continuous improvement — K2M reviews its privacy and data protection practices as its operations, technology, and legal obligations evolve.
29Important Notice
This Policy establishes K2M’s general privacy and data protection framework. It is not intended to replace jurisdiction-specific legal requirements, contractual obligations, client instructions, employment privacy notices, recruitment notices, cookie notices, or Data Processing Addenda where those documents are required.
K2M may adopt additional policies, procedures, notices, contractual provisions, or jurisdiction-specific supplements as necessary to comply with applicable law and the nature of particular services or processing activities.
End of Policy