Legal

Privacy Policy

What we collect, why we collect it, who else sees it, and how to ask us to delete it.

Last updated August 5, 2026

01Who this policy covers

KoldOS is a generative engine optimization (GEO) and development agency. This policy explains what personal information [KoldOS legal entity name] (“KoldOS”, “we”, “us”) collects when you visit this website, subscribe to our newsletter or contact us about working together, and what we do with it.

It covers this website and the enquiry, onboarding and marketing activity around it. It does not cover third-party sites we link to. It also does not cover personal information we handle for a client under a services agreement, which is described under information we process for clients.

02Information we collect

We collect three kinds of information.

  • Information you give us. Your email address when you subscribe to the newsletter. Your name, email address, company, website and message when you submit a contact or booking form, or book a call. Anything else you choose to send us by email.
  • Information collected automatically. When you load a page, our hosting and analytics providers record your IP address, browser and device type, operating system, referring URL, the pages you viewed and when you viewed them. We use this to see which pages work, not to build a profile of you.
  • Information from other services. If you reach us through a scheduling tool, a form provider or a social platform, that service passes on the details you submitted there. Its own privacy policy applies to what it collects.

We do not ask for sensitive information such as health data, biometrics, precise location, government identifiers, or details of your race, religion, sexual orientation or union membership. Please do not send it to us.

03Cookies and similar technologies

We use strictly necessary storage to make the site work and to remember interface preferences, plus privacy-preserving analytics to count visits and measure performance.

We do not run advertising cookies, tracking pixels or third-party retargeting on this site. If that changes, we will update this policy and ask for consent where the law requires it before the technology loads.

Your browser can block or delete cookies and local storage. Blocking analytics will not affect the site. Blocking strictly necessary storage may break parts of it.

04How we use your information

We use personal information to:

  • reply to your enquiry, scope a project, and send you a proposal or quote;
  • deliver and support our services, and administer the contract we have with you or your organization;
  • send the newsletter you subscribed to. Every issue has an unsubscribe link, and unsubscribing takes effect immediately;
  • understand in aggregate how the site is used, which pages are read and where the performance problems are;
  • keep the site secure by detecting abuse, spam submissions, automated scraping and attempted intrusions;
  • meet legal, tax and accounting obligations, and to establish, exercise or defend legal claims.

We do not use your information to train machine learning models. We do not make automated decisions about you that produce legal or similarly significant effects.

06How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose it in four situations.

  • Service providers. Hosting and deployment, analytics, email delivery and newsletter distribution, scheduling, customer relationship management, and payment processing. They act on our instructions under contracts that limit them to providing the service.
  • Professional advisers. Lawyers, accountants and insurers, where they need it to advise us.
  • Legal and safety. Where the law, a court order or a valid request from a public authority requires it, or where disclosure is necessary to protect our rights, your safety or the safety of others.
  • Business transfers. If we are involved in a merger, acquisition, financing or sale of assets, information may transfer as part of the transaction. We will tell you if the company controlling your information changes.

07Information we process for clients

GEO and development work usually means access to a client’s systems: analytics accounts, search consoles, content management systems, staging environments, and any personal information those hold.

When we handle that data we act as a processor (a service provider) on the client’s instructions. The client is the controller and the client’s own privacy policy applies. We use the data only to perform the engagement, keep it confidential, and return or delete it at the end of the engagement if asked. If you are a customer of one of our clients, send your privacy request to that client. We will help them respond.

08International transfers

We operate from the United States and use service providers there and in other countries, so your information may be transferred to, stored in and processed in a country whose data protection laws differ from your own. For transfers out of the EEA, the UK or Switzerland we rely on an adequacy decision, or on the European Commission’s Standard Contractual Clauses with the UK Addendum where it applies, together with any further safeguards the transfer needs.

09How long we keep it

  • Enquiries that do not become engagements. Up to 24 months, then deleted.
  • Newsletter subscriptions. Until you unsubscribe, plus a suppression record so we do not add you back by mistake.
  • Client records, contracts and invoices. For the term of the engagement, then for as long as tax, accounting and limitation periods require. This is typically seven years.
  • Analytics and server logs. In aggregated or truncated form. Raw logs are kept no longer than security and debugging require.

At the end of a retention period we delete the information or anonymize it irreversibly.

10Security

We use TLS in transit, access controls, least-privilege administration, multi-factor authentication on accounts that support it, and established infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant regulator where the law requires it.

11Your rights and choices

Depending on where you live, you may have the right to ask for a copy of the personal information we hold about you, to have it corrected or deleted, to receive it in a portable format, to object to or restrict how we use it, to withdraw consent, and to opt out of the sale or sharing of personal information. We do neither.

California residents. Under the CCPA as amended by the CPRA you can exercise the rights above, and we will not discriminate against you for it. We will not deny you service, charge a different price, or provide a lower quality of service. An authorized agent can make a request for you with proof of authorization. In the past twelve months we have collected the categories described under information we collect and disclosed them for the business purposes described under how we share information. We have not sold personal information or shared it for cross-context behavioral advertising.

EEA, UK and Swiss residents. You can also complain to your supervisory authority, which in the UK is the Information Commissioner’s Office. We would like the chance to put things right first.

To exercise a right, email [privacy@koldos.example]. We verify requests against information we already hold, usually by confirming the request from the address on file rather than asking for identity documents, and we reply within the time the applicable law allows, generally 30 to 45 days. There is no charge unless a request is manifestly unfounded or excessive.

12Do Not Track and Global Privacy Control

Browsers send Do Not Track signals inconsistently and there is no agreed standard for responding to them, so we do not act on them. We do treat the Global Privacy Control as a valid opt-out of the sale or sharing of personal information where the law says it is, although we do neither.

13Children

This site and our services are meant for businesses. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email [privacy@koldos.example] and we will delete it.

14Changes to this policy

We update this policy when our services, tools or legal obligations change. The date at the top shows the current version. If a change materially affects how we handle your personal information, we will post a notice on the site and email subscribers and clients before it takes effect.

15Contact us

Send privacy questions, requests and complaints to [privacy@koldos.example]. For anything else, use [legal@koldos.example].

[KoldOS legal entity name]
[registered business address]