Freelance developer & designer · Fort William, Scotland · Open to select work

ImKyleJK
WorkDesignServicesBlogLabsAboutContact
Client loginWork with me
WorkDesignServicesBlogLabsAboutContact
Work with me
Client login
Legal

Privacy Notice

Last updated 27 July 2026.

This notice explains what personal data imkylejk.me collects, why, how long it's kept, and what rights you have over it. It applies to visitors, contacts, client portal users, supporters, and anyone who submits a review or chats with the site's support bot.

Who's responsible for your data

Kyle Kozlowski, trading as ImKyleJK, is the data controller for personal data collected through this site. I'm a sole trader based in Fort William, Scotland, and I act as my own point of contact for data protection — there's no separate DPO, but any request is handled personally and promptly. Contact: hello@imkylejk.me.

What I collect

  • Contact form submissions — name, email, phone (optional), company (optional), enquiry type, budget/timeline, and whatever you write in the message.
  • Account data for signed-in clients and supporters, via Clerk (email, name, profile photo, session metadata, sign-in history).
  • Project data for client work — files, messages, timeline events, invoices, and payment status tied to your project.
  • Subscription and payment status for the supporter plan and project invoices — handled by Stripe and Clerk Billing, who process card details directly. I never see or store full card numbers.
  • Reviews you submit for publication (name, role, rating, review text) — held privately until approved or rejected.
  • Support bot chats — message content, a random device identifier (not tied to your identity unless you're signed in), rough country (from network-level location, not GPS), and an AI-generated topic category and summary used only to spot patterns in what visitors ask.
  • Blog reactions — a device fingerprint used solely to cap reactions per device/IP, not to identify you personally.
  • Basic technical logs (IP address, timestamps, request metadata) kept briefly for security, abuse prevention, and debugging.
  • Basic, privacy-friendly analytics (no cross-site tracking, no ad identifiers) when enabled.

Why, and the legal basis

  • Contract — delivering client work, issuing invoices, running your portal account, processing the supporter subscription.
  • Legitimate interests — replying to enquiries, moderating reviews and blog reactions, keeping the support bot and site secure, preventing abuse, understanding what visitors ask so the site can be improved.
  • Consent — the support bot's conversation logging (you accept this before chatting), and any non-essential analytics.
  • Legal obligation — keeping financial records for UK tax requirements.

I don't sell your data, and I don't share it with third parties for their own marketing.

Automated processing

Support bot chats are categorised by an AI model (topic + one-line summary) purely so I can see patterns in what people ask — this doesn't affect you individually and isn't used to make any decision about you. The bot can also flag a session as abusive using pre-defined rules (not solely AI judgement) and pause chat access temporarily; this only limits further bot messages, it has no other effect and can be reversed on request.

Where it lives and how it's protected

Client, account, and bot data is stored locally under my direct control, not on a third-party database platform. The infrastructure is physically secured with on-site CCTV, access control, and network monitoring (intrusion detection/prevention), alongside standard technical measures — encryption in transit (HTTPS), access restricted to me alone, and regular backups. Project files are stored in access-controlled cloud object storage, accessed only via short-lived signed links rather than public URLs. Payment and subscription processing is handled by Stripe and Clerk Billing; authentication is handled by Clerk. These are data processors acting under their own privacy terms — see Clerk's privacy policy and Stripe's privacy policy.

International transfers

Where a processor (e.g. Clerk or Stripe) transfers data outside the UK/EEA, they do so under their own safeguards (such as Standard Contractual Clauses) as set out in their respective privacy policies. Core project and account data controlled directly by me stays on infrastructure I operate.

How long I keep it

  • Contact form enquiries that don't convert to a project: up to 24 months, then deleted.
  • Client project data (files, messages, invoices): for the duration of the engagement plus 6 years, to meet UK tax and contract record-keeping requirements.
  • Support bot chat logs: up to 12 months, used only in aggregate/summary form beyond that.
  • Reviews rejected at moderation: deleted within 90 days.
  • Account data for suspended accounts: retained per the Suspension & disputes section below, not indefinitely.

Public supporter list

If you subscribe as a supporter, your name and profile photo may appear in a public supporter list on the homepage. This is opt-in by default but can be switched off at any time from your account settings — turning it off removes you from the public list immediately without affecting your subscription.

Reviews & blog reactions

Reviews are held privately until I approve or reject them for publication; rejected reviews are not published and are deleted per the retention period above. If you submit a review, the name and role you provide may be published alongside your review text and rating — don't include anything you don't want public. Blog reactions are anonymous beyond the device/IP cap used to prevent abuse.

Account suspension & disputes

If a client portal account is suspended (see Terms), relevant account and project data is retained, not deleted, so the suspension and any related dispute (including chargebacks) can be evidenced and resolved. This data is handled under the same protections as active accounts, and is deleted or anonymised once the dispute is resolved and any legal retention period has passed.

Children

This site isn't directed at children, and the client portal and paid services aren't intended for use by anyone under 18. If you believe a child has provided personal data to this site, contact me and I'll delete it.

Your rights

Under UK GDPR, you can:

  • Ask for a copy of the personal data I hold about you.
  • Ask for inaccurate data to be corrected.
  • Ask for your data to be deleted, where I'm not required to keep it for legal reasons.
  • Ask me to restrict or object to certain processing.
  • Ask for a portable copy of data you provided directly.
  • Withdraw consent at any time, where processing is based on consent (e.g. bot chat logging), without affecting processing already carried out.

To exercise any of these, email hello@imkylejk.me. I'll respond within one month. Client project records tied to active invoices, or accounts involved in an unresolved payment dispute, may be retained as required for UK tax record-keeping or to evidence that dispute, even after a deletion request. If you're unhappy with how a request is handled, you can complain to the UK Information Commissioner's Office (ICO).

Data breaches

In the unlikely event of a personal data breach that poses a risk to you, I'll notify affected individuals and, where required, the ICO, in line with UK GDPR timescales.

Changes to this notice

This notice may be updated as the site changes — the "last updated" date at the top always reflects the current version. Material changes affecting client data will be communicated directly where practical.

You've reached the bottom, — the very bottom.

Navigate

  • About
  • Services
  • Design
  • Blog
  • Open source
  • Status

Work

  • Selected work
  • Start a project
  • Reviews
  • Support My Work
  • Current Project

Labs

  • Tailwind.Help
  • GoSIP.space
  • xDemo.tech
  • GitHub

Legal

  • Privacy
  • Terms
  • Cookies
  • Client login

© 2026 Kyle Kozlowski · ImKyleJK · Fort William, Scotland · hello@imkylejk.me