1. Who we are and why this policy exists
KVOKA Studio is an independent web studio operated as a sole proprietorship. The founder and the data-contact person is Maks Kvokin. You can reach us by WhatsApp, Telegram, or email at hi@kvoka.com.
This policy explains what personal information we collect through the kvoka.com website, how we use it, who we share it with, and what rights you have. We try to write in plain English, not lawyer-speak, so if anything is unclear, just ask.
This policy applies to every visitor of kvoka.com — including the language sub-paths (/en/, /uk/) — and to any conversation you have with us through our contact form, WhatsApp, or Telegram.
2. What we collect
We try hard not to collect anything we don't actually need. Here's the complete list.
2.1. Things you type yourself
- Name — how you want us to address you (form field
name). - Contact — phone, email, Telegram handle, or WhatsApp number (form field
contact). You pick the channel. - Niche / business type — what you do (HVAC, plumbing, roofing, etc.) — field
niche. - Message — any extra context you want to share.
2.2. Technical data (automatic)
- IP address — used for form spam protection (rate-limit: 5 submissions per IP per minute).
- User agent — browser and OS string, so we can spot when the site is broken on a specific device.
- Referrer — the page you came from (Google, Facebook, direct).
- UTM parameters — if a URL has utm_source/utm_medium/utm_campaign, we save them with the lead so we know which ads work.
- Current URL and locale — which page you were on when you submitted, and which language you were reading.
2.3. Cookies and localStorage
The full list with purposes and lifetimes is on the Cookie Policy page. Quick version: one cookie to remember your language (kvoka_lang, 1 year), one for Google Analytics (_ga, 13 months, opt-in only), and one localStorage entry for cookie consent (kvoka_cookie_consent, so we don't keep nagging you).
2.4. What we do NOT collect
- Financial information (card numbers, bank accounts). Payments run through Stripe or wire — we only see "paid", not your card.
- Precise GPS location.
- Biometric data.
- Health data.
- Data about anyone under 13 (see COPPA below).
3. How we use it
We use your data strictly for the following:
- Replying to you — Maks (or a specialist) writes back through your preferred channel (WhatsApp / Telegram / email).
- Scoping the project — back-and-forth about the site, your niche, timing.
- Preparing a quote — pricing, contract, invoice.
- Doing the work — if you sign on as a client: passing credentials, brand assets, draft links.
- Post-launch support — 12 months of free edits per the Warranty Policy.
- Analytics — anonymized aggregate data (Google Analytics 4) so we know which pages work.
- Abuse protection — IP rate-limiting, honeypot to filter bots.
We do not sell your data, hand it to advertisers, or use it for retargeting without your explicit consent through the cookie banner.
4. Legal basis (GDPR)
For visitors in the EU/EEA (GDPR Article 6):
- Performance of a contract (Art. 6(1)(b)) — once you submit the form, we process your data to scope and deliver the project.
- Legitimate interest (Art. 6(1)(f)) — site security (rate-limit, anti-fraud), basic analytics (knowing which pages convert), product improvement.
- Consent (Art. 6(1)(a)) — Google Analytics, marketing cookies, email opt-in. Granted through the cookie banner or an explicit checkbox.
- Legal obligation (Art. 6(1)(c)) — tax records once a transaction happens.
6. How we protect your data
Technical and organizational safeguards:
- TLS 1.3 / HTTPS on every page. HSTS enabled (Strict-Transport-Security: max-age=31536000; includeSubDomains).
- HSTS preload — browsers remember kvoka.com is HTTPS-only.
- Encryption at rest — form submissions land in logs stored on encrypted Hostinger disks.
- Narrow access — Maks is the only person with SSH to the server; contractors only see client chats they're assigned to.
- 2FA on every critical account (hosting, registrar, GitHub, Google).
- Rate limiting on the form (5 per IP per minute) plus honeypot filtering.
- CSP headers limit what JavaScript is allowed to run.
- Daily backups, 30-day rolling retention.
- Token redaction in logs — no API keys or passwords land in plain text.
That said, we're a small studio, not AWS or a bank. If you have a million customers with financial data, you need a bigger shop with SOC 2 audit. More on our approach at Security Practices.
7. How long we keep things
- Unconverted leads — 24 months from the date you submitted. After that we anonymize (name and contact removed; only niche statistics survive).
- Active projects — for the duration of the engagement plus 36 months after handoff (so we can do warranty edits).
- Closed projects — client data is archived and retained for an additional 4 years for legal limitation periods.
- Tax records (invoices, receipts) — 7 years, per applicable tax law.
- WhatsApp / Telegram conversations — we don't delete the messages inside the apps themselves (we don't control that). To remove them, delete your side of the chat.
- GA4 analytics — Google's default 14-month anonymized retention.
8. Your GDPR rights (EU)
If you're in the EU/EEA, or if we're processing your data in that context, you have the following rights (GDPR Articles 15-22):
- Right of access (Art. 15) — find out what data we hold about you. We'll send a copy.
- Right to rectification (Art. 16) — fix any inaccurate data.
- Right to erasure / "right to be forgotten" (Art. 17) — we delete everything we're not legally required to keep (tax records).
- Right to restriction (Art. 18) — pause processing while we figure something out.
- Right to data portability (Art. 20) — receive your data in a machine-readable format (CSV / JSON).
- Right to object (Art. 21) — opt out of processing based on legitimate interest.
- Right not to be subject to automated decisions (Art. 22) — we don't do automated decision-making on your data.
- Right to lodge a complaint with a supervisory authority — the data-protection authority in your country.
Use the Data Deletion Request form or WhatsApp / Telegram. We respond within 30 calendar days, free of charge (unless the request is repeated or unreasonably broad).
9. Your CCPA rights (California)
If you're a California resident, you have rights under the California Consumer Privacy Act (CCPA / CPRA):
- Right to Know — what categories of data we've collected about you in the past 12 months, sources, purposes, recipients.
- Right to Delete — request deletion (same legal-hold carve-outs as GDPR).
- Right to Correct — fix inaccurate data.
- Right to Opt-Out of Sale or Sharing — we don't sell your data, but Google Analytics legally counts as "sharing for cross-context behavioral advertising". To opt out, see Do Not Sell My Personal Information.
- Right to Limit Use of Sensitive PI — we don't process sensitive PI (biometrics, health, precise geolocation), so this is satisfied by default.
- Right to Non-Discrimination — using your CCPA rights doesn't change our pricing. on request is on request whether or not you ask to be deleted.
Submit through the Data Deletion Request form. We respond within 45 calendar days (extendable by another 45 days with notice on complex requests).
10. Your PIPEDA rights (Canada)
Canadian visitors are covered by PIPEDA (Personal Information Protection and Electronic Documents Act) and, in Quebec, Law 25:
- Right of access — we send a copy on request within 30 days.
- Correction — fix anything that's wrong.
- Consent withdrawal — you can revoke consent for marketing communications (CASL).
- Complaints — go to the Office of the Privacy Commissioner of Canada.
- Quebec Law 25 — Quebec residents have additional rights to data portability and to be informed about automated decision-making.
11. Children under 13 (COPPA)
KVOKA Studio is a B2B service aimed at business owners. We don't target advertising at children, and we don't knowingly collect data from anyone under 13 (or under 16, the GDPR child threshold).
If you're a parent or guardian and you think your child has submitted information to us, email hi@kvoka.com. We'll delete the data within 7 business days, no proof-of-parenthood required (because there's no legitimate reason for a B2B service to hold a child's data).
12. Email and CASL
KVOKA doesn't do bulk marketing email. If you get a message from us, it's one of:
- A direct reply to your inquiry (CASL — implied consent from a business inquiry).
- A transactional project message (invoice, deliverable, credentials).
- A newsletter you explicitly opted into through a double-opt-in flow (we don't currently run one, but if we ever do, that's how it'll work).
Every non-transactional email has a one-click unsubscribe link. Unsubscribes are processed instantly. Under CASL you can complain to the Spam Reporting Centre.
13. Cross-border data transfers
Our subprocessors live in different countries:
- Hostinger — Lithuania (EU).
- Google (Analytics, Fonts) — United States.
- Telegram — UAE.
- Meta / WhatsApp — United States.
- Cloudflare — United States.
That means your data may cross borders. For EU-to-US transfers, we rely on EU-US Standard Contractual Clauses as updated after the Schrems II decision. Each of our subprocessors is either self-certified under the EU-US Data Privacy Framework or has signed the SCCs.
14. Breach notification
If despite our safeguards a data breach happens:
- We notify the relevant data-protection authority within 72 hours of discovery (GDPR Art. 33).
- We notify you directly (email or WhatsApp) if the breach is high-risk to your rights (GDPR Art. 34).
- We post a short notice on the website if a wide user base is affected.
- The notice explains what happened, what we did, what the risks are, and what you can do.
More on our approach: Security Practices.
15. Changes to this policy
This policy will get updated as laws and our processes change. Every change goes into the Policy Changelog with the date and a one-line summary. For material changes (a new subprocessor, a new category of data) we'll notify active clients separately.
The "last updated" date at the top of this page is the authoritative one.
16. Privacy contact
All privacy questions go straight to Maks:
- 📱 WhatsApp: wa.me/37120469306
- 💬 Telegram: @maks_kvoka
- ✉️ Email: hi@kvoka.com
During business hours (9 AM – 10 PM ET) we typically reply within ~6 minutes. Overnight, expect a response the next morning.
For formal data-subject requests (GDPR / CCPA / PIPEDA) please use the Data Deletion Request form — that's where we guarantee statutory response times.
Got a privacy question we didn't answer?
Write to Maks — usually a reply within ~6 minutes during business hours. Real human, not a bot.