UK & EU data protection

Privacy policy

Last updated 9 August 2026

This policy explains how KGSITES collects and uses personal information from website visitors, prospective clients, clients, suppliers and business contacts.

1. Controller and contact

KGSITES is a trading name used by a sole trader established in England, United Kingdom and is the controller for the processing described here. Privacy requests can be sent to contact@kgsites.com. KGSITES has not appointed a data protection officer because its current processing does not require one.

2. Information collected

  • Enquiry information: name, email, business, website, selected services, budget, timescale and message.
  • Client information: contact, project, contract, billing, transaction and correspondence records.
  • Account and access information: credentials or platform access supplied for project delivery. Passwords should be shared through an agreed secure method, not ordinary enquiry forms.
  • Technical information: IP address, browser, device, requested pages, timestamps, security events and server logs.
  • Analytics preferences and data: consent choice and, only after permission, optional usage measurements.
  • Information from other sources: public business websites, client-authorised platforms, referrals and correspondence involving KGSITES.

3. Purposes and legal bases

Responding to enquiries and preparing proposalsSteps requested before a contract; legitimate interests in business communication.
Delivering and administering client servicesPerformance of a contract and legitimate interests in project management.
Invoices, tax and accountingContract and compliance with legal obligations.
Security, fraud prevention and service reliabilityLegitimate interests in protecting KGSITES, clients and website users.
Optional website analyticsConsent, which can be withdrawn through Cookie settings.
Legal claims and complianceLegal obligations and legitimate interests in establishing or defending rights.

Where legitimate interests are used, KGSITES considers necessity, proportionality and the individual’s reasonable expectations.

4. Whether information is required

Fields marked as required are needed to respond meaningfully to an enquiry. Contract, billing and access information may be necessary to perform an agreed project or meet legal duties. You do not have to allow optional analytics.

5. Sharing and processors

Information may be shared only as reasonably necessary with hosting and infrastructure providers, email services, payment processors, accounting or professional advisers, analytics providers after consent, and platforms needed for an agreed client project. Providers acting as processors are expected to protect information and process it only for the relevant service. KGSITES does not sell personal information.

6. International transfers

Some technology providers may process information outside the United Kingdom or European Economic Area. Where restricted-transfer rules apply, KGSITES relies on a recognised adequacy decision, the UK International Data Transfer Agreement or Addendum, EU Standard Contractual Clauses, or another lawful safeguard. Information about the applicable safeguard can be requested by email.

7. Retention

  • Unsuccessful or inactive enquiries: normally up to 24 months after the last meaningful contact.
  • Client contracts, project and billing records: normally seven years after the relationship ends where needed for tax, accounting and legal purposes.
  • Routine server and security logs: normally up to 12 months unless needed to investigate an incident.
  • Access credentials: removed or returned when no longer required for delivery.
  • Cookie preference: retained in the browser until changed or cleared.

Records may be retained longer where required by law, an active dispute, fraud prevention or a documented client instruction.

8. Your rights

Subject to legal conditions and exemptions, you may request access, correction, erasure, restriction, objection, portability and information about safeguards. You can withdraw consent at any time without affecting earlier lawful processing. KGSITES generally responds within one month and may request proportionate identity verification.

UK complaints may be made to the Information Commissioner’s Office. People protected by EU GDPR may complain to the supervisory authority in the country where they live, work or believe an infringement occurred.

9. EU GDPR and representatives

KGSITES is established in the UK. If EU GDPR Article 27 requires an EU representative for a specific pattern of offering services or monitoring, representative details will be made available before that processing begins. Occasional low-risk business enquiries may fall within the Article 27 exemption.

10. Automated decisions, children and sensitive data

KGSITES does not use website enquiry data to make solely automated decisions with legal or similarly significant effects. Services are directed at businesses and adults, not children. Please do not submit special-category data, criminal-offence data or unnecessary confidential credentials through the public form.

11. Security and changes

Reasonable technical and organisational measures are used to protect information, including access limitation and appropriate service providers. No online system can be guaranteed completely secure. Material policy changes will be shown by the update date and, where appropriate, communicated directly.