This policy explains how personal data is handled on the kvelo.dev website and applies to all information the Operator may obtain about a User through the Site.

1. General

1.1. The Operator is Kvelo, developer and owner of the product of the same name. All enquiries: [email protected].

1.2. Processing is carried out under the personal data law applicable to the Operator. Where a User is located in the European Economic Area or the United Kingdom, the Operator additionally applies the principles of the General Data Protection Regulation (GDPR).

1.3. By using the Site and submitting the form, the User confirms they have read this policy and accept it. A User who does not accept it should stop using the Site.

1.4. This policy covers the kvelo.dev site only. The Operator does not control and is not responsible for third-party sites reached through links.

2. What personal data is processed

2.1. Data the User provides through the request form:

  • name (required);
  • email address (required);
  • phone number (optional);
  • Telegram username (optional).

2.2. Data transmitted automatically while using the Site:

  • IP address and the approximate region derived from it;
  • browser and operating system type and version, device type, screen resolution, interface language;
  • referral source including UTM parameters, and the previous page address;
  • behaviour on the Site: pages viewed, scroll depth, clicks, session duration;
  • cookie identifiers and similar technologies.

2.3. The Operator does not process special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, health, sexual life) or biometric data.

2.4. Working files, conversations, documents and any other data the User handles inside the Product after receiving access are never transmitted to and never processed by the Operator. They remain on the User’s own equipment. This policy concerns the Site only.

3. Purposes of processing

PurposeData used
Handling the request and granting access to the Productname, email, phone, Telegram
Replying to enquiriesname, email, phone, Telegram
Informing about the Product and changes to itname, email
Analysing and improving the Sitetechnical and behavioural data
Site security and protection from automated requestsIP address, technical data

3.2. The Operator does not make decisions producing legal effects for the User based solely on automated processing.

3.3. The Operator does not sell personal data and does not share it with third parties for advertising purposes.

4. Lawful basis

4.1. The User’s consent, given by completing and submitting the form on the Site. The wording of that consent is set out in Data processing consent.

4.2. Performance of a contract to which the User is a party, or steps taken at the User’s request before entering into a contract.

4.3. The Operator’s legitimate interest in keeping the Site working and secure, where this does not override the User’s rights and freedoms.

5. Who processes the data

5.1. The Operator engages the following processors, each acting on the Operator’s instructions:

ProcessorPurpose
Attio (Attio Ltd)customer relationship management, where requests are recorded
Telegram Messengernotifying the Operator that a request arrived
Google Analytics (Google LLC)anonymised visit statistics
PostHog (PostHog Inc.)product analytics, including session recording on the Site
Yandex Metrica (Yandex LLC)visit statistics and click maps
Cloudflare (Cloudflare Inc.)site hosting and form protection

5.2. Session recording. PostHog records pointer movement, scrolling, clicks and navigation between pages. Form field contents are masked and are not visible to the Operator.

5.3. International transfers. Some processors listed above operate outside the Operator’s country, so data may be processed abroad. By submitting the form the User consents to such transfer.

6. Retention

6.1. Form data is kept until the purposes of processing are met, the User withdraws consent, or the Operator ceases to operate, whichever comes first.

6.2. Analytics data is kept for the periods set by each service, typically between a few months and two years.

6.3. Once the purposes are met, or on withdrawal of consent or a User request, data is erased or anonymised within 30 days.

7. Cookies

7.1. The Site uses cookies that are technically necessary for it to work and remember the User’s choices, and analytics cookies set by the processors listed in section 5.

7.2. Cookies can be blocked or deleted in browser settings. Blocking technically necessary cookies may affect some Site functions.

7.3. Continuing to use the Site without changing browser settings constitutes consent to the use of cookies.

8. Your rights

8.1. The User has the right to:

  • obtain information about the processing of their personal data, including the categories of data, purposes, methods, retention periods and who has access;
  • have data corrected, restricted or erased where it is incomplete, outdated, inaccurate, unlawfully obtained or no longer necessary;
  • withdraw consent to processing;
  • receive their data in a structured, commonly used format, and have it transmitted to another controller where technically feasible;
  • lodge a complaint with the competent supervisory authority or bring court proceedings.

8.2. To exercise any of these rights, write to [email protected]. The Operator responds within 30 days.

8.3. The Operator may ask the User to confirm that the request comes from the data subject, for example by writing from the address given in the form.

8.4. Withdrawing consent stops further processing and leads to erasure, except where processing is required by law. It does not affect the lawfulness of processing carried out beforehand.

9. Security measures

9.1. The Operator applies organisational and technical measures to protect personal data against unauthorised access, destruction, alteration, blocking, copying and disclosure.

9.2. These include transmission over HTTPS only, limiting the number of people with access to the data, origin checks and bot protection on the form, and a strict content security policy.

9.3. No transmission over the internet can be guaranteed to be completely secure. The Operator is not liable for the acts of third parties who obtain access through circumstances outside the Operator’s control.

10. Changes

10.1. The Operator may amend this policy. The current version is published on this page with the date of the last change at the top.

10.2. Continuing to use the Site after a change constitutes acceptance of the new version.

11. Contact

For any question about personal data, or to submit a request: [email protected].