Privacy Policy
Last updated: 11 March 2025
1. Introduction
Kairos ("we", "our", or "us") is a UK-based managed execution studio that matches vetted talent with startups and SMEs. We are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit our website at itskairos.uk (the "Website") and use our services.
By using our Website, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Website.
2. Who We Are
Kairos is a managed execution studio based in London, United Kingdom. We design and implement operational systems including AI automation, CRM architecture, brand execution, and growth infrastructure for startups and SMEs.
For any questions regarding this Privacy Policy or your personal data, please contact us at: team@itskairos.uk
3. Information We Collect
We collect information in the following ways:
3.1 Information You Provide Directly
When you use our contact form or career application form, we collect:
- Contact Form: Name, email address, phone number (optional), service need, and project description.
- Career Application Form: Name, email address, chosen track, portfolio or LinkedIn URL, resume/CV (PDF), and a message describing your experience.
3.2 Information Collected Automatically
When you visit our Website, we automatically collect certain information through:
- Google Analytics (GA4): We use Google Analytics to understand how visitors interact with our Website. This may include your IP address (anonymised), browser type, device type, pages visited, time spent on pages, referring URLs, and general geographic location.
- Cookies and Similar Technologies: We use cookies to enhance your experience and gather analytics data. See Section 7 for more details.
4. How We Use Your Information
We use the personal data we collect for the following purposes:
- To respond to enquiries: When you submit a contact form, we use your details to review your request and respond within 24 hours.
- To process applications: When you apply through our careers page, we use your information to assess your suitability for available roles within our builder network.
- To schedule consultations: After form submission, you may be redirected to our scheduling tool (Calendly) to book a discovery call.
- To improve our Website: We use analytics data to understand how visitors use our Website, identify areas for improvement, and optimise the user experience.
- To comply with legal obligations: We may process your data where necessary to comply with applicable laws and regulations.
5. Legal Basis for Processing (UK GDPR)
Under the UK General Data Protection Regulation (UK GDPR), we rely on the following legal bases:
- Consent: When you submit a form on our Website, you consent to us processing your data for the stated purpose. You may withdraw consent at any time by contacting us.
- Legitimate Interests: We process analytics data based on our legitimate interest in understanding how our Website is used and improving our services, provided this does not override your fundamental rights and freedoms.
- Contractual Necessity: Where processing is necessary to take steps at your request prior to entering into a contract (e.g., assessing a career application).
6. Data Storage and Security
Your data is stored securely using the following infrastructure:
- Supabase: Contact form submissions and career applications are stored in a Supabase database with row-level security enabled. Supabase provides encryption at rest and in transit.
- Supabase Storage: Resume/CV files uploaded via the careers form are stored in Supabase Storage with secure access controls.
- Vercel: Our Website is hosted on Vercel, which provides SSL/TLS encryption for all data in transit.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or method of electronic storage is 100% secure.
7. Cookies and Tracking Technologies
Our Website uses cookies and similar technologies to enhance your experience and collect analytics data. We use the iubenda Consent Solution to manage your cookie preferences in compliance with applicable laws.
7.1 Types of Cookies We Use
- Strictly Necessary Cookies: Required for the Website to function properly. These cannot be disabled.
- Analytics Cookies (Google Analytics): Help us understand how visitors interact with our Website. These cookies collect information anonymously and report Website trends without identifying individual visitors.
- Preference Cookies (iubenda): Store your cookie consent preferences.
7.2 Managing Cookies
You can manage your cookie preferences at any time via the cookie consent banner provided by iubenda. You may also configure your browser to refuse cookies or alert you when cookies are being sent. Please note that disabling cookies may affect the functionality of certain parts of the Website.
8. Third-Party Services
We use the following third-party services that may process your personal data:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google Analytics | Website analytics and traffic analysis | Google Privacy Policy |
| Supabase | Data storage and file storage | Supabase Privacy Policy |
| Vercel | Website hosting | Vercel Privacy Policy |
| Calendly | Scheduling discovery calls | Calendly Privacy Policy |
| iubenda | Cookie consent management | iubenda Privacy Policy |
9. Data Sharing and Disclosure
We do not sell, trade, or rent your personal data to third parties. We may share your information in the following limited circumstances:
- Service Providers: With trusted third-party services (listed above) that assist us in operating our Website and conducting our business, subject to confidentiality obligations.
- Legal Requirements: If required by law, court order, or governmental regulation, or where disclosure is necessary to protect our rights, property, or safety.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change.
10. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Contact form submissions: Retained for up to 24 months from the date of submission, unless an ongoing business relationship is established.
- Career applications: Retained for up to 12 months from the date of submission. If your application is unsuccessful, we may retain your details to consider you for future opportunities, unless you request deletion.
- Analytics data: Google Analytics data is retained in accordance with Google's data retention policies (typically 14 months).
11. Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data where there is no compelling reason for its continued processing.
- Right to Restrict Processing: Request that we limit the processing of your personal data in certain circumstances.
- Right to Data Portability: Request your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to our processing of your personal data where we are relying on legitimate interests.
- Right to Withdraw Consent: Where we rely on your consent to process data, you may withdraw that consent at any time.
To exercise any of these rights, please contact us at team@itskairos.uk. We will respond to your request within 30 days.
12. International Data Transfers
Some of our third-party service providers (such as Google, Supabase, and Vercel) may process your data outside of the United Kingdom. Where this occurs, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or adequacy decisions, to protect your personal data in accordance with UK data protection law.
13. Children's Privacy
Our Website and services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us at team@itskairos.uk and we will take steps to delete such information.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will post the updated policy on this page with a revised "Last updated" date. We encourage you to review this Privacy Policy periodically. Your continued use of the Website after any changes constitutes your acceptance of the updated policy.
15. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at: