Privacy Policy
Your privacy and data protection are fundamental to how we operate
Last Updated: November 20, 2025
Table of Contents
- 1. Introduction
- 2. Data Controller Information
- 3. What Data We Collect
- 4. How We Use Your Data
- 5. Legal Basis for Processing
- 6. Data Sharing and Third Parties
- 7. Data Retention
- 8. Your Rights Under GDPR
- 9. Data Security
- 10. Cookies and Tracking
- 11. International Data Transfers
- 12. Children's Privacy
- 13. Changes to This Policy
- 14. Contact Us
1. Introduction
Kaiv Solutions Ltd ("we", "us", or "our") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website, services, or interact with us.
This policy complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable data protection laws.
2. Data Controller Information
The data controller responsible for your personal data is:
Kaiv Solutions Ltd
Company Number: 16617966
Registered in England & Wales
Location: Crawley, West Sussex
Email: info@kaivsolutions.co.uk
3. What Data We Collect
We may collect and process the following categories of personal data:
3.1 Information You Provide Directly
- Contact Information: Name, email address, phone number, company name, job title
- Enquiry Details: Information you provide in contact forms, assessment requests, or consultation bookings
- Project Information: Technical requirements, current infrastructure details, budget ranges for Azure assessments
- Communication Records: Records of correspondence via email, phone, or other channels
- Payment Information: Billing address and payment details (processed securely through third-party payment providers)
3.2 Information Collected Automatically
- Technical Data: IP address, browser type and version, operating system, device information
- Usage Data: Pages visited, time spent on pages, navigation paths, referring websites
- Cookies and Tracking: Data collected through cookies and similar technologies (see our Cookie Policy)
3.3 Information from Third Parties
- LinkedIn: Professional profile information if you connect with us via LinkedIn
- Analytics Providers: Aggregated usage statistics from Google Analytics
- Business Partners: Referral information from trusted partners (with your consent)
4. How We Use Your Data
We use your personal data for the following purposes:
4.1 Service Delivery
- Responding to enquiries and providing requested information
- Conducting Azure assessments and technical consultations
- Delivering contracted services (website development, cloud architecture, etc.)
- Managing client relationships and project communications
- Processing payments and managing invoices
4.2 Business Operations
- Improving our website, services, and customer experience
- Analyzing usage patterns to optimize our offerings
- Conducting market research and business planning
- Maintaining security and preventing fraud
4.3 Marketing and Communications (With Consent)
- Sending newsletters and service updates
- Notifying you about new services, packages, or offers
- Sharing relevant technical insights or industry updates
- Inviting you to events or webinars
4.4 Legal Compliance
- Complying with legal obligations and regulatory requirements
- Establishing, exercising, or defending legal claims
- Maintaining records for tax and accounting purposes
5. Legal Basis for Processing
Under UK GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to fulfill our contractual obligations to you
- Legitimate Interests: Processing for our legitimate business interests (e.g., improving services, security) where not overridden by your rights
- Consent: Where you have given explicit consent for specific processing activities (e.g., marketing communications)
- Legal Obligation: Processing required to comply with legal or regulatory requirements
6. Data Sharing and Third Parties
We may share your personal data with the following categories of recipients:
6.1 Service Providers
- Cloud Hosting: Microsoft Azure (for website hosting and application infrastructure)
- Email Services: Email delivery and communication platforms
- Analytics: Google Analytics (anonymized data for website analytics)
- Payment Processors: Secure payment gateway providers for transaction processing
6.2 Professional Advisors
- Accountants, auditors, lawyers, and other professional advisors
- Insurance providers (Professional Indemnity Insurance)
6.3 Legal and Regulatory Bodies
- Law enforcement, courts, or regulatory authorities when legally required
- Tax authorities (HMRC) for compliance purposes
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Enquiries (No Contract): 2 years from last contact
- Client Data (Active Projects): Duration of contract plus 6 years (legal requirement)
- Accounting Records: 6 years from end of financial year (HMRC requirement)
- Marketing Consent: Until consent is withdrawn or 3 years of inactivity
- Website Analytics: 26 months (Google Analytics default)
After the retention period expires, we securely delete or anonymize your personal data.
8. Your Rights Under GDPR
Under UK GDPR, you have the following rights regarding your personal data:
8.1 Right of Access
You can request a copy of the personal data we hold about you.
8.2 Right to Rectification
You can request correction of inaccurate or incomplete personal data.
8.3 Right to Erasure ("Right to be Forgotten")
You can request deletion of your personal data in certain circumstances (e.g., when no longer needed for original purpose).
8.4 Right to Restrict Processing
You can request limitation of processing in specific situations (e.g., while accuracy is being verified).
8.5 Right to Data Portability
You can request a copy of your data in a structured, commonly used, machine-readable format.
8.6 Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
8.7 Right to Withdraw Consent
Where processing is based on consent, you can withdraw consent at any time.
8.8 Right to Lodge a Complaint
You can lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
9.1 Technical Measures
- SSL/TLS encryption for all data transmission
- Secure hosting on Microsoft Azure with enterprise-grade security
- Regular security updates and patch management
- Firewalls and intrusion detection systems
- Encrypted backups and disaster recovery procedures
9.2 Organizational Measures
- Access controls and role-based permissions
- Staff training on data protection and security
- Confidentiality agreements with employees and contractors
- Regular security audits and risk assessments
- Incident response and breach notification procedures
While we implement robust security measures, no method of transmission or storage is 100% secure. We continuously review and enhance our security practices to protect your data.
11. International Data Transfers
We primarily store and process data within the United Kingdom and European Economic Area (EEA). However, some third-party service providers may process data outside the UK/EEA.
Where data is transferred internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses approved by UK authorities
- Adequacy decisions recognizing equivalent data protection standards
- Service providers certified under recognized data protection frameworks
12. Children's Privacy
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately, and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements. The "Last Updated" date at the top of this page indicates when the policy was last revised.
Significant changes will be communicated through:
- Email notification to registered users
- Prominent notice on our website
- Update to the "Last Updated" date
Continued use of our services after changes constitute acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Contact
Email: info@kaivsolutions.co.uk
Address: Kaiv Solutions Ltd, Crawley, West Sussex
Response Time: We aim to respond to all data protection enquiries within 48 hours and will resolve requests within one month as required by UK GDPR.
Have Questions About Our Privacy Practices?
We're committed to transparency and protecting your data. Contact us with any questions or concerns.
Get in Touch