Privacy & Data

Privacy Policy

  • Last updated: 
  • Effective: 
  • ~12 min read
  • Privacy & Data

In plain English: we only collect what we need to reply to you and build your site, we don't sell your data, and you can ask us to delete it anytime. The details below explain exactly how.

 Table of contents (16 sections)

1. Who we are and why this policy exists

In plain English: KVOKA Studio is run by Maks Kvokin. We build websites for small businesses in the US and Canada. This policy spells out exactly what we do with your data.

KVOKA Studio is an independent web studio operated as a sole proprietorship. The founder and the data-contact person is Maks Kvokin. You can reach us by WhatsApp, Telegram, or email at hi@kvoka.com.

This policy explains what personal information we collect through the kvoka.com website, how we use it, who we share it with, and what rights you have. We try to write in plain English, not lawyer-speak, so if anything is unclear, just ask.

This policy applies to every visitor of kvoka.com — including the language sub-paths (/en/, /uk/) — and to any conversation you have with us through our contact form, WhatsApp, or Telegram.

2. What we collect

In plain English: The minimum: what you type in the form (name, contact, niche, message), plus standard page analytics.

We try hard not to collect anything we don't actually need. Here's the complete list.

2.1. Things you type yourself

  • Name — how you want us to address you (form field name).
  • Contact — phone, email, Telegram handle, or WhatsApp number (form field contact). You pick the channel.
  • Niche / business type — what you do (HVAC, plumbing, roofing, etc.) — field niche.
  • Message — any extra context you want to share.

2.2. Technical data (automatic)

  • IP address — used for form spam protection (rate-limit: 5 submissions per IP per minute).
  • User agent — browser and OS string, so we can spot when the site is broken on a specific device.
  • Referrer — the page you came from (Google, Facebook, direct).
  • UTM parameters — if a URL has utm_source/utm_medium/utm_campaign, we save them with the lead so we know which ads work.
  • Current URL and locale — which page you were on when you submitted, and which language you were reading.

2.3. Cookies and localStorage

The full list with purposes and lifetimes is on the Cookie Policy page. Quick version: one cookie to remember your language (kvoka_lang, 1 year), one for Google Analytics (_ga, 13 months, opt-in only), and one localStorage entry for cookie consent (kvoka_cookie_consent, so we don't keep nagging you).

2.4. What we do NOT collect

  • Financial information (card numbers, bank accounts). Payments run through Stripe or wire — we only see "paid", not your card.
  • Precise GPS location.
  • Biometric data.
  • Health data.
  • Data about anyone under 13 (see COPPA below).

3. How we use it

In plain English: To reply to you, scope the project, and ship the site. No data sales to anyone.

We use your data strictly for the following:

  • Replying to you — Maks (or a specialist) writes back through your preferred channel (WhatsApp / Telegram / email).
  • Scoping the project — back-and-forth about the site, your niche, timing.
  • Preparing a quote — pricing, contract, invoice.
  • Doing the work — if you sign on as a client: passing credentials, brand assets, draft links.
  • Post-launch support — 12 months of free edits per the Warranty Policy.
  • Analytics — anonymized aggregate data (Google Analytics 4) so we know which pages work.
  • Abuse protection — IP rate-limiting, honeypot to filter bots.

We do not sell your data, hand it to advertisers, or use it for retargeting without your explicit consent through the cookie banner.

5. Who we share with (subprocessors)

In plain English: Hosting, analytics, messaging. Short list, each with their own privacy policy. Full list lives on the subprocessors page.

To run the site we use a small number of subprocessors. Each has its own privacy policy and security certifications (SOC 2, ISO 27001, etc.):

  • Hostinger (Lithuania, EU) — hosting and database. Form submissions transit their servers. Hostinger Privacy.
  • Google Analytics 4 (Google LLC, US) — anonymized analytics. Property ID: G-Z66BLDX96H. Loaded only after you opt in via the cookie banner. Google Privacy.
  • Telegram Bot API (Telegram FZ-LLC, UAE) — delivers new leads to our internal admin chat. Telegram sees only what the bot forwards (name, contact, message).
  • WhatsApp / Meta (Meta Platforms Inc., US) — if you message us directly through WhatsApp, that conversation rides Meta's servers. We don't control it.
  • Cloudflare (Cloudflare Inc., US) — CDN and DDoS protection if enabled. Sees your IP and request headers.
  • Google Fonts (Google LLC, US) — Inter and Space Grotesk are loaded from Google's CDN. One request to fonts.googleapis.com on first visit.

The current full list with data categories, countries, and privacy links lives at Subprocessor List. We update it whenever it changes.

6. How we protect your data

In plain English: HTTPS everywhere, encryption, narrow access, daily backups.

Technical and organizational safeguards:

  • TLS 1.3 / HTTPS on every page. HSTS enabled (Strict-Transport-Security: max-age=31536000; includeSubDomains).
  • HSTS preload — browsers remember kvoka.com is HTTPS-only.
  • Encryption at rest — form submissions land in logs stored on encrypted Hostinger disks.
  • Narrow access — Maks is the only person with SSH to the server; contractors only see client chats they're assigned to.
  • 2FA on every critical account (hosting, registrar, GitHub, Google).
  • Rate limiting on the form (5 per IP per minute) plus honeypot filtering.
  • CSP headers limit what JavaScript is allowed to run.
  • Daily backups, 30-day rolling retention.
  • Token redaction in logs — no API keys or passwords land in plain text.

That said, we're a small studio, not AWS or a bank. If you have a million customers with financial data, you need a bigger shop with SOC 2 audit. More on our approach at Security Practices.

7. How long we keep things

In plain English: Leads: 24 months. Active projects: until done + 36 months. Tax records: 7 years.
  • Unconverted leads — 24 months from the date you submitted. After that we anonymize (name and contact removed; only niche statistics survive).
  • Active projects — for the duration of the engagement plus 36 months after handoff (so we can do warranty edits).
  • Closed projects — client data is archived and retained for an additional 4 years for legal limitation periods.
  • Tax records (invoices, receipts) — 7 years, per applicable tax law.
  • WhatsApp / Telegram conversations — we don't delete the messages inside the apps themselves (we don't control that). To remove them, delete your side of the chat.
  • GA4 analytics — Google's default 14-month anonymized retention.

8. Your GDPR rights (EU)

In plain English: Access, correction, erasure, portability, objection, restriction. We respond within 30 days.

If you're in the EU/EEA, or if we're processing your data in that context, you have the following rights (GDPR Articles 15-22):

  • Right of access (Art. 15) — find out what data we hold about you. We'll send a copy.
  • Right to rectification (Art. 16) — fix any inaccurate data.
  • Right to erasure / "right to be forgotten" (Art. 17) — we delete everything we're not legally required to keep (tax records).
  • Right to restriction (Art. 18) — pause processing while we figure something out.
  • Right to data portability (Art. 20) — receive your data in a machine-readable format (CSV / JSON).
  • Right to object (Art. 21) — opt out of processing based on legitimate interest.
  • Right not to be subject to automated decisions (Art. 22) — we don't do automated decision-making on your data.
  • Right to lodge a complaint with a supervisory authority — the data-protection authority in your country.

Use the Data Deletion Request form or WhatsApp / Telegram. We respond within 30 calendar days, free of charge (unless the request is repeated or unreasonably broad).

9. Your CCPA rights (California)

In plain English: Right to Know, Right to Delete, Right to Opt-Out. We respond within 45 days.

If you're a California resident, you have rights under the California Consumer Privacy Act (CCPA / CPRA):

  • Right to Know — what categories of data we've collected about you in the past 12 months, sources, purposes, recipients.
  • Right to Delete — request deletion (same legal-hold carve-outs as GDPR).
  • Right to Correct — fix inaccurate data.
  • Right to Opt-Out of Sale or Sharing — we don't sell your data, but Google Analytics legally counts as "sharing for cross-context behavioral advertising". To opt out, see Do Not Sell My Personal Information.
  • Right to Limit Use of Sensitive PI — we don't process sensitive PI (biometrics, health, precise geolocation), so this is satisfied by default.
  • Right to Non-Discrimination — using your CCPA rights doesn't change our pricing. on request is on request whether or not you ask to be deleted.

Submit through the Data Deletion Request form. We respond within 45 calendar days (extendable by another 45 days with notice on complex requests).

10. Your PIPEDA rights (Canada)

In plain English: Similar to GDPR: access, correction, consent withdrawal. Complaints go to the federal Privacy Commissioner.

Canadian visitors are covered by PIPEDA (Personal Information Protection and Electronic Documents Act) and, in Quebec, Law 25:

  • Right of access — we send a copy on request within 30 days.
  • Correction — fix anything that's wrong.
  • Consent withdrawal — you can revoke consent for marketing communications (CASL).
  • Complaints — go to the Office of the Privacy Commissioner of Canada.
  • Quebec Law 25 — Quebec residents have additional rights to data portability and to be informed about automated decision-making.

11. Children under 13 (COPPA)

In plain English: KVOKA isn't for kids. If you're a parent who thinks your child submitted data, email us and we'll delete it.

KVOKA Studio is a B2B service aimed at business owners. We don't target advertising at children, and we don't knowingly collect data from anyone under 13 (or under 16, the GDPR child threshold).

If you're a parent or guardian and you think your child has submitted information to us, email hi@kvoka.com. We'll delete the data within 7 business days, no proof-of-parenthood required (because there's no legitimate reason for a B2B service to hold a child's data).

12. Email and CASL

In plain English: No spam. Any email from us is either replying to you, a project update, or something you explicitly opted into.

KVOKA doesn't do bulk marketing email. If you get a message from us, it's one of:

  • A direct reply to your inquiry (CASL — implied consent from a business inquiry).
  • A transactional project message (invoice, deliverable, credentials).
  • A newsletter you explicitly opted into through a double-opt-in flow (we don't currently run one, but if we ever do, that's how it'll work).

Every non-transactional email has a one-click unsubscribe link. Unsubscribes are processed instantly. Under CASL you can complain to the Spam Reporting Centre.

13. Cross-border data transfers

In plain English: Data may cross US, EU, and Canadian borders. Standard Contractual Clauses are in place.

Our subprocessors live in different countries:

  • Hostinger — Lithuania (EU).
  • Google (Analytics, Fonts) — United States.
  • Telegram — UAE.
  • Meta / WhatsApp — United States.
  • Cloudflare — United States.

That means your data may cross borders. For EU-to-US transfers, we rely on EU-US Standard Contractual Clauses as updated after the Schrems II decision. Each of our subprocessors is either self-certified under the EU-US Data Privacy Framework or has signed the SCCs.

14. Breach notification

In plain English: If anything leaks, we'll notify you and the regulator within 72 hours per GDPR.

If despite our safeguards a data breach happens:

  • We notify the relevant data-protection authority within 72 hours of discovery (GDPR Art. 33).
  • We notify you directly (email or WhatsApp) if the breach is high-risk to your rights (GDPR Art. 34).
  • We post a short notice on the website if a wide user base is affected.
  • The notice explains what happened, what we did, what the risks are, and what you can do.

More on our approach: Security Practices.

15. Changes to this policy

In plain English: When we change something, we update the date at the top and post a one-liner to the Policy Changelog.

This policy will get updated as laws and our processes change. Every change goes into the Policy Changelog with the date and a one-line summary. For material changes (a new subprocessor, a new category of data) we'll notify active clients separately.

The "last updated" date at the top of this page is the authoritative one.

16. Privacy contact

In plain English: WhatsApp / Telegram / email. We usually reply within ~6 minutes during business hours.

All privacy questions go straight to Maks:

During business hours (9 AM – 10 PM ET) we typically reply within ~6 minutes. Overnight, expect a response the next morning.

For formal data-subject requests (GDPR / CCPA / PIPEDA) please use the Data Deletion Request form — that's where we guarantee statutory response times.

Got a privacy question we didn't answer?

Write to Maks — usually a reply within ~6 minutes during business hours. Real human, not a bot.