Privacy Policy
Last updated: 2026-06-19 // Contact: legal@kairostudio.one
This Privacy Policy explains how Kairo Studio Ltd, a company registered in England and Wales under company number 17285515, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("Kairo Studio", "we", "us"), collects, uses, retains, and shares personal data of visitors to the website kairostudio.one and of clients of its advisory services.
Kairo Studio acts as a data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 and, where applicable to data subjects in the European Union, under Regulation (EU) 2016/679 (EU GDPR). The Policy applies to both Business Clients (organisations and persons acting in the course of a business) and Consumers (individuals acting outside their trade or business).
1. Who we are
The data controller is Kairo Studio. For any privacy question or to exercise any of the rights described in this Policy, contact legal@kairostudio.one.
Kairo Studio has not appointed a Data Protection Officer. The scale and nature of our processing do not require us to appoint one under Article 37 of the UK GDPR or Article 37 of the EU GDPR.
2. What data we collect
We collect only the personal data needed to operate the website and deliver the services:
- Account data: name, email address, hashed password, optional company name, and account timestamps. Collected when you create an account.
- Order and billing data: service purchased, amount, payment method (cryptocurrency or invoice), payment status, invoice and refund records, and timestamps. Collected when you place an order.
- Compliance data: declarations and basic verification information needed to comply with sanctions, anti-money-laundering, and counter-terrorist financing law (for example, your stated country and confirmation that you are not on a sanctions list). Collected at order and, where required, during the Engagement.
- Communication data: contents of messages you send through the contact form or by email, including the email address you wrote from.
- Engagement data: non-public information you share with us during an Engagement, including documents, notes, and interview answers.
- Technical data: IP address, browser user agent, device type, and cookie identifiers. Cookie details are in the Cookie Policy.
We do not collect special category data (personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, or data concerning a person's sex life or sexual orientation).
3. Why we collect it and the lawful basis
Each processing activity is supported by a lawful basis under Article 6 of the UK GDPR / EU GDPR:
- Performance of a contract: creating and managing your account, processing orders, delivering services, issuing invoices, processing refunds, and providing client support.
- Legitimate interests: responding to enquiries submitted via the contact form, securing the website against abuse and fraud, screening orders against sanctions lists, and basic record-keeping. Our legitimate interest is balanced against your rights and freedoms; you can object at any time.
- Consent: loading optional analytics scripts (Google Analytics 4 and Microsoft Clarity) only after you accept analytics cookies in our consent banner. You can withdraw consent at any time through the "Cookie settings" link.
- Legal obligation: retaining financial records for accounting and tax law, complying with sanctions and anti-money-laundering law, and responding to lawful requests from regulators or courts.
4. How long we keep it
Account data is retained for the lifetime of the account. If you close your account, identifying data is erased within thirty (30) calendar days, except where retention is required by law.
Financial, order, and invoice records are retained for six (6) years from the end of the relevant accounting period to comply with UK company and tax record-keeping obligations.
Messages submitted through the contact form, and emails sent to our published addresses, are retained for twenty-four (24) months from the last communication, unless they form part of an active Engagement, in which case they follow the Engagement retention period.
Engagement records (notes, deliverables, supporting documents) are retained for six (6) years from the date of delivery to align with statutory limitation periods under English law and our professional record-keeping obligations.
Google Analytics 4 retains data for fourteen (14) months. Microsoft Clarity retains session data according to the platform default, which is described in the Cookie Policy.
5. Who we share it with
We share personal data only with the processors and recipients listed below, each under a written processing agreement where applicable:
- NOWPayments OU (Estonia) - cryptocurrency payment processor. Receives the order reference and amount. Does not receive your name or email unless you provide them at checkout.
- Resend, Inc. (United States) - transactional email delivery (account confirmations, password reset, invoice delivery, contact form notifications). Receives your name, email, and the message body.
- Cloudflare, Inc. (United States) - bot protection and CAPTCHA via Cloudflare Turnstile on forms; DNS and email routing. Receives IP address, request headers, and challenge tokens.
- Google Ireland Limited and Google LLC (Ireland / United States) - audience analytics via Google Analytics 4. Loaded only after analytics consent.
- Microsoft Corporation (United States) - product behaviour analytics via Microsoft Clarity. Loaded only after analytics consent.
- Vercel Inc. (United States) - hosting and content delivery network. Processes request metadata (IP, headers) for delivery and security.
- Supabase Inc. (United States) - managed PostgreSQL database used to store account, order, and reset-token records.
- Professional advisers, regulators, and authorities - we may disclose data to our accountants and legal advisers, and to regulators, courts, or law enforcement where required by law or to defend our legal rights.
We do not sell personal data and we do not share it with third parties for their independent marketing purposes.
6. International transfers
Some of our processors are located outside the United Kingdom and the European Economic Area, principally in the United States. Where personal data is transferred outside the UK or EEA, we rely on the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, and any UK adequacy regulations in force, supplemented by additional technical and organisational safeguards where appropriate. A copy of the relevant transfer mechanism is available on request from legal@kairostudio.one.
7. Security
We use industry-standard technical and organisational measures to protect personal data, including TLS for all network traffic, password hashing for stored credentials, encrypted database storage, role-based access to client information, and a documented incident-response process. No system is completely secure; if we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify the UK Information Commissioner's Office, and you where required, in line with the UK GDPR.
8. Children
The website and services are intended for individuals aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, write to legal@kairostudio.one and we will take reasonable steps to delete it.
9. Your rights
Under the UK GDPR and, where applicable, the EU GDPR, you have the right to:
- access your personal data and obtain a copy of it;
- request correction of inaccurate or incomplete data;
- request erasure where the legal grounds for processing no longer apply;
- request restriction of processing in defined circumstances;
- receive your data in a portable, machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent at any time where processing is based on consent.
10. How to exercise your rights
To exercise any of the rights above, write to legal@kairostudio.one with sufficient information to identify your account. We respond within one calendar month of receipt of a valid request. We may extend this period by a further two months where the request is complex or where we receive a high number of requests; we will tell you within the initial month if we need to do so.
11. Right to lodge a complaint
If you believe your personal data has been processed in a way that breaches data protection law, you have the right to lodge a complaint with the United Kingdom Information Commissioner's Office at https://ico.org.uk/. Data subjects in the European Union may also lodge a complaint with the supervisory authority in their country of residence.
12. Updates to this Policy
We may update this Privacy Policy from time to time to reflect changes in the service, in our processors, or in applicable law. The date at the top of this page shows the date of the latest revision. Material changes are notified by an in-product notice or by email to active account holders at least thirty (30) days before they take effect, except where the change is required by law and must take effect sooner.