Privacy.
What this site collects, why, who else handles it, and how long it is kept. It is short because there is not much to say.
Last updated 9 September 2026
The short version
This site sets no cookies, runs no analytics, and loads nothing from third parties. What we keep is what you type into a form, what you buy, and the address of the site you ask us to look at. We do not sell it, share it for marketing, or use it for anything other than replying to you and doing the work.
Who we are
Kay Konsulting Limited, company number 17445525, registered in England and Wales. Registered office: 66 Paul Street, London EC2A 4NA. We are the data controller for the personal data described on this page. For anything about your data, email hello@kaykonsulting.com.
What we collect, and why
When you send an enquiry. The contact form collects your name, email address, company and budget band if you give them, your message, and whether you asked for an NDA before going into detail. We use this to reply and to quote. The legal basis is taking steps at your request before a contract, and our legitimate interest in running the business.
When you buy something. Payment is handled by Stripe on Stripe’s own pages, so card details never reach this site. Stripe passes us your name, email address, the amount, the website you entered at checkout, and identifiers for the payment session, customer and invoice. We keep these as the record of the order. The legal basis is performing the contract with you, and the legal duty to keep accounting records.
When the automated scan runs. For the automated services, our servers fetch the public address you gave, in the same way any browser would, and look up its public DNS records for email authentication. The DNS lookups go to Cloudflare’s public resolver, which means the domain name is sent to Cloudflare. The report is emailed to the address on the order, and a copy is kept with the order. Nothing beyond ordinary HTTP requests and public DNS lookups is sent to the site.
When we email you. Receipts, reports and replies are sent through Resend, an email provider, so your address and the content of the message pass through their systems.
When you visit. Our host, Vercel, keeps request logs that include your IP address for a short period, for security and debugging. To stop the forms being abused, we also hold your IP address in our database, paired with the name of the form, for the duration of the rate-limiting window and until the limiter next clears expired entries. IP addresses are not stored with enquiries or orders. The legal basis is our legitimate interest in keeping the site up and the forms usable.
During an engagement. Anything you share for the work itself, such as access to a repository or staging environment, screenshots, or findings, is handled under the engagement’s own confidentiality terms. Where your systems contain personal data about your customers or staff, we process it only on your instructions, only as far as the work requires, and we do not copy it out. It is deleted or returned when the work ends unless we agree otherwise in writing.
Cookies
The public site sets no cookies and uses no analytics, pixels or tracking of any kind. The administration area, on its own hostname and used only by us, sets a single session cookie that is strictly necessary to sign in. It is never set on the public site.
Who else handles it
We use a small number of providers to run the site. Each processes data only to provide its service to us.
- Vercel hosts the site and keeps request logs. Vercel is a United States company; pages are served from the country nearest you and processed in the United States and the European Union.
- Neon hosts the database, in London.
- Stripe takes payments and issues receipts and invoices. Stripe is the controller of the card and payment data it collects, under its own privacy policy.
- Resend delivers email we send.
- Cloudflare answers the public DNS lookups the automated scan makes. It receives the domain name being checked and nothing else.
Where a provider processes data outside the United Kingdom, it does so under the UK International Data Transfer Addendum or the UK Extension to the EU–US Data Privacy Framework. We do not sell personal data, and we do not share it with anyone for their own marketing.
How long we keep it
| What | How long |
|---|---|
| Enquiries | Two years after our last exchange, then deleted |
| Orders, invoices and scan reports | Six years after the end of the financial year they fall in, which is what company law requires |
| Rate-limiting records | The ten-minute window, then until the next clean-up |
| Hosting logs | A short period set by Vercel |
| Material shared for an engagement | Deleted or returned when the work ends, unless agreed otherwise |
Your rights
You can ask for a copy of the personal data we hold about you, ask us to correct or delete it, restrict or object to how we use it, or ask for it in a portable form. Email hello@kaykonsulting.com and we will reply within a month. We may need to keep order records where the law requires it, and we will say so if that applies.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather hear from you first.
Security
Card details never touch our systems. The site is served only over HTTPS, with a strict content security policy and no third-party scripts. The database is accessed by a role that can read and write only the tables it needs, and the administration area sits on its own hostname behind a password. No system is perfect; if we discover a breach that affects you, we will tell you, and the ICO where the law requires it.
Changes
Our services are for businesses and are not aimed at anyone under 18. If this page changes materially, the date at the top will change with it. Purchases are also covered by our terms of business.