Privacy Policy

Last updated: December 2024

1. Introduction

Kitsune Squad Ltd ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website kitsunesquad.com or use our services.

We are registered in England and Wales. By using our website or services, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

  • Contact Information: Name, email address, phone number, company name
  • Inquiry Details: Messages submitted through our contact form or chatbot
  • Account Information: Login credentials for the customer portal
  • Project Data: Information related to your projects and support tickets

2.2 Information Collected Automatically

  • Device Information: Browser type, operating system, device type
  • Usage Data: Pages visited, time spent, click patterns
  • IP Address: For security, analytics, and fraud prevention
  • Cookies: Session and preference cookies (see Cookie Policy below)

2.3 Chatbot Conversations

Our AI-powered chatbot (Kitsune) records conversations to:

  • Provide accurate responses to your inquiries
  • Connect you with our team when needed
  • Improve our services and AI responses
  • Create leads and support tickets when you request assistance

Chatbot conversations may be reviewed by our staff and are stored securely.

3. How We Use Your Information

We use your information to:

  • Respond to your inquiries and provide customer support
  • Deliver the services you request
  • Send administrative information (invoices, project updates)
  • Improve our website and services
  • Protect against fraudulent or malicious activity
  • Comply with legal obligations
  • Send marketing communications (only with your consent)

4. Legal Basis for Processing (GDPR)

Under GDPR, we process your data based on:

  • Consent: Where you have given clear consent (e.g., marketing emails)
  • Contract: Processing necessary to fulfill our services to you
  • Legitimate Interests: Operating our business, improving services, security
  • Legal Obligation: Compliance with applicable laws

5. Data Sharing and Disclosure

We may share your information with:

  • Service Providers: Hosting (Vercel), email (Google Workspace), payment processing (Stripe)
  • AI Services: OpenAI for chatbot functionality (conversations processed via API)
  • Analytics: Privacy-focused analytics to improve our website
  • Legal Requirements: When required by law or to protect our rights

We do not sell your personal information to third parties.

6. Data Retention

  • Contact Inquiries: Retained for 3 years after last contact
  • Customer Data: Retained for duration of relationship + 7 years (legal requirement)
  • Chatbot Conversations: Retained for 2 years
  • Analytics Data: Aggregated and anonymized after 26 months

7. Your Rights

Under GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Request limitation of processing
  • Portability: Request transfer of your data
  • Object: Object to processing based on legitimate interests
  • Withdraw Consent: Where processing is based on consent

To exercise these rights, contact us at privacy@kitsunesquad.com.

8. Cookies and Tracking

We use the following types of cookies:

  • Essential Cookies: Required for website functionality and security
  • Preference Cookies: Remember your settings and choices
  • Analytics Cookies: Help us understand how visitors use our site

You can manage cookies through your browser settings. Note that disabling certain cookies may affect website functionality.

9. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • SSL/TLS encryption for data in transit
  • Encrypted database storage
  • Access controls and authentication
  • Regular security assessments
  • Staff training on data protection

10. International Data Transfers

Some of our service providers operate outside the UK/EEA. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

11. Children's Privacy

Our services are not directed at individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us:

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been violated.