Legal
Privacy Policy
What we collect, why we collect it, who else sees it, and how to ask us to delete it.
Last updated August 5, 2026
01Who this policy covers
KoldOS is a generative engine optimization (GEO) and development agency. This policy explains what personal information [KoldOS legal entity name] (“KoldOS”, “we”, “us”) collects when you visit this website, subscribe to our newsletter or contact us about working together, and what we do with it.
It covers this website and the enquiry, onboarding and marketing activity around it. It does not cover third-party sites we link to. It also does not cover personal information we handle for a client under a services agreement, which is described under information we process for clients.
02Information we collect
We collect three kinds of information.
- Information you give us. Your email address when you subscribe to the newsletter. Your name, email address, company, website and message when you submit a contact or booking form, or book a call. Anything else you choose to send us by email.
- Information collected automatically. When you load a page, our hosting and analytics providers record your IP address, browser and device type, operating system, referring URL, the pages you viewed and when you viewed them. We use this to see which pages work, not to build a profile of you.
- Information from other services. If you reach us through a scheduling tool, a form provider or a social platform, that service passes on the details you submitted there. Its own privacy policy applies to what it collects.
We do not ask for sensitive information such as health data, biometrics, precise location, government identifiers, or details of your race, religion, sexual orientation or union membership. Please do not send it to us.
04How we use your information
We use personal information to:
- reply to your enquiry, scope a project, and send you a proposal or quote;
- deliver and support our services, and administer the contract we have with you or your organization;
- send the newsletter you subscribed to. Every issue has an unsubscribe link, and unsubscribing takes effect immediately;
- understand in aggregate how the site is used, which pages are read and where the performance problems are;
- keep the site secure by detecting abuse, spam submissions, automated scraping and attempted intrusions;
- meet legal, tax and accounting obligations, and to establish, exercise or defend legal claims.
We do not use your information to train machine learning models. We do not make automated decisions about you that produce legal or similarly significant effects.
05Legal bases (EEA and UK visitors)
If you are in the European Economic Area, the United Kingdom or Switzerland, we process personal information on these bases.
- Contract. To take steps at your request before entering into an agreement, and to perform one once it exists.
- Legitimate interests. To run and secure the website, to understand aggregate usage, and to respond to business enquiries, balanced against your rights and freedoms.
- Consent. For the newsletter and for any non-essential cookies. You can withdraw consent at any time. Withdrawing it does not affect processing we carried out beforehand.
- Legal obligation. Where we have to retain records or respond to a lawful request.
07Information we process for clients
GEO and development work usually means access to a client’s systems: analytics accounts, search consoles, content management systems, staging environments, and any personal information those hold.
When we handle that data we act as a processor (a service provider) on the client’s instructions. The client is the controller and the client’s own privacy policy applies. We use the data only to perform the engagement, keep it confidential, and return or delete it at the end of the engagement if asked. If you are a customer of one of our clients, send your privacy request to that client. We will help them respond.
08International transfers
We operate from the United States and use service providers there and in other countries, so your information may be transferred to, stored in and processed in a country whose data protection laws differ from your own. For transfers out of the EEA, the UK or Switzerland we rely on an adequacy decision, or on the European Commission’s Standard Contractual Clauses with the UK Addendum where it applies, together with any further safeguards the transfer needs.
09How long we keep it
- Enquiries that do not become engagements. Up to 24 months, then deleted.
- Newsletter subscriptions. Until you unsubscribe, plus a suppression record so we do not add you back by mistake.
- Client records, contracts and invoices. For the term of the engagement, then for as long as tax, accounting and limitation periods require. This is typically seven years.
- Analytics and server logs. In aggregated or truncated form. Raw logs are kept no longer than security and debugging require.
At the end of a retention period we delete the information or anonymize it irreversibly.
10Security
We use TLS in transit, access controls, least-privilege administration, multi-factor authentication on accounts that support it, and established infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant regulator where the law requires it.
11Your rights and choices
Depending on where you live, you may have the right to ask for a copy of the personal information we hold about you, to have it corrected or deleted, to receive it in a portable format, to object to or restrict how we use it, to withdraw consent, and to opt out of the sale or sharing of personal information. We do neither.
California residents. Under the CCPA as amended by the CPRA you can exercise the rights above, and we will not discriminate against you for it. We will not deny you service, charge a different price, or provide a lower quality of service. An authorized agent can make a request for you with proof of authorization. In the past twelve months we have collected the categories described under information we collect and disclosed them for the business purposes described under how we share information. We have not sold personal information or shared it for cross-context behavioral advertising.
EEA, UK and Swiss residents. You can also complain to your supervisory authority, which in the UK is the Information Commissioner’s Office. We would like the chance to put things right first.
To exercise a right, email [privacy@koldos.example]. We verify requests against information we already hold, usually by confirming the request from the address on file rather than asking for identity documents, and we reply within the time the applicable law allows, generally 30 to 45 days. There is no charge unless a request is manifestly unfounded or excessive.
12Do Not Track and Global Privacy Control
Browsers send Do Not Track signals inconsistently and there is no agreed standard for responding to them, so we do not act on them. We do treat the Global Privacy Control as a valid opt-out of the sale or sharing of personal information where the law says it is, although we do neither.
13Children
This site and our services are meant for businesses. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email [privacy@koldos.example] and we will delete it.
14Changes to this policy
We update this policy when our services, tools or legal obligations change. The date at the top shows the current version. If a change materially affects how we handle your personal information, we will post a notice on the site and email subscribers and clients before it takes effect.
15Contact us
Send privacy questions, requests and complaints to [privacy@koldos.example]. For anything else, use [legal@koldos.example].
[KoldOS legal entity name]
[registered business address]