Legal
Privacy Policy
Effective January 1, 2026
This Privacy Policy explains how KODA ADVANCED TECHNOLOGIES ("KODA", "we", "us") collects, uses, discloses and protects information when you visit kodatech.org, contact us, or engage us to design and build AI systems.
We have written it to be read rather than skimmed past. If anything here is unclear, email [email protected] and we will answer plainly.
1. Scope
This policy covers two distinct categories of information, which we treat differently:
- Website and business-contact information — what we collect when you browse this site, submit the contact form, or correspond with us. This policy governs it directly.
- Client data processed during an engagement — documents, images, telemetry, transaction records and other material you make available so we can build a system. For this category we act as a processor (or service provider) on your behalf, and the governing terms are the Data Processing Agreement and Master Services Agreement executed for that engagement, which take precedence over this policy.
2. Information we collect
2.1 Information you provide
- Contact form submissions: name, work email, company, optional phone number, focus area, your description of the problem you want solved, and how you heard about us.
- Correspondence: the content of emails, scheduled calls and documents you send us during scoping.
- Engagement administration: billing contacts, purchase order details and signatory information needed to contract and invoice.
2.2 Information collected automatically
This site is a static site served from Cloudflare Pages. Our hosting provider processes standard server-log information — IP address, user agent, requested URL, referrer and timestamp — for security, abuse prevention and aggregate traffic measurement.
We do not use advertising cookies, cross-site tracking pixels, or third-party behavioural profiling. If we add privacy-respecting aggregate analytics, we will update this policy and name the provider before deployment.
2.3 Third-party services on this site
- Google Fonts — the Inter typeface is loaded from Google's font CDN, which receives your IP address as a necessary part of serving the request.
- Cloudflare — provides hosting, TLS termination and DDoS protection, and processes request metadata in that capacity.
- Scheduling — if you choose to book a call through our scheduling link, the scheduling provider collects the information you enter under its own privacy policy.
3. How we use information
- To respond to your enquiry and assess whether we are a fit for your problem.
- To scope, deliver, support and invoice engagements.
- To maintain the security, availability and integrity of this site and our systems.
- To comply with legal, tax, audit and contractual obligations.
- To send you occasional updates only where you have asked for them. You can stop these at any time by replying to any message.
We do not sell personal information. We do not share it with third parties for their own marketing purposes.
4. Client data during engagements
These commitments are standard across our engagements and are reflected in our DPA:
- We do not train models for other clients on your data. Models, embeddings, indexes, evaluation sets and fine-tuned weights produced in your engagement are yours and are used only for you.
- Processing happens in your environment wherever possible. Roughly half of our deployments run inside client VPCs, and we regularly deploy fully on-premises including air-gapped environments with no outbound network access.
- Access is least-privilege and logged. Only engagement team members who need access receive it, through your access-control systems where available.
- Working copies are deleted at engagement close, on a documented schedule, with written confirmation on request.
- Subprocessors are disclosed before use. Any third-party model API, hosting or tooling that would process your data is identified and approved during the architecture phase, never introduced silently.
5. Legal bases for processing (UK/EU)
Where the UK GDPR or EU GDPR applies, we rely on:
- Legitimate interests — responding to business enquiries, securing our systems, and operating our business.
- Contract performance — delivering an engagement you have signed.
- Consent — optional communications you have specifically requested.
- Legal obligation — tax, accounting and regulatory record-keeping.
6. Retention
- Enquiries that do not progress: retained for up to 24 months, then deleted.
- Engagement records: retained for the term plus the period required by contract, tax and professional-liability obligations (typically seven years).
- Client working data: deleted at engagement close per the DPA, unless you direct otherwise in writing.
- Server logs: retained by our hosting provider on its standard schedule.
7. Disclosure
We disclose information only:
- to service providers who help us operate (hosting, email, accounting, scheduling), bound by confidentiality and processing terms;
- where required by law, regulation, subpoena or court order;
- to protect the rights, property or safety of KODA, our clients or the public;
- in connection with a merger, acquisition or asset sale, with notice to affected clients.
8. Security
We maintain SOC 2-aligned administrative, technical and physical controls: encryption in transit and at rest, least-privilege access with multi-factor authentication, endpoint hardening, audit logging, vendor review, and documented incident response. Engagement-specific controls are agreed in the architecture phase and documented in the DPA.
No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you without undue delay and in line with applicable law and our contractual commitments.
9. International transfers
We are able to keep processing within a specified jurisdiction when an engagement requires it, and we will say so in the DPA. Where personal information is transferred internationally, we use appropriate safeguards such as Standard Contractual Clauses or the UK International Data Transfer Addendum.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict processing of your personal information, to object to processing based on legitimate interests, and to withdraw consent. California residents have the rights described under the CCPA/CPRA, including the right not to be discriminated against for exercising them — and note again that we do not sell or share personal information for cross-context behavioural advertising.
To exercise any right, email [email protected]. We will respond within 30 days and may need to verify your identity first. If your data was provided to us by a client as part of an engagement, we will refer your request to that client, who controls it.
11. Children
This site and our services are directed to businesses. We do not knowingly collect personal information from anyone under 16.
12. Changes to this policy
We will update the effective date above when this policy changes, and we will notify active clients directly of material changes affecting engagement data.
13. Contact
Privacy questions, requests and complaints: [email protected], addressed to the Privacy Contact, KODA ADVANCED TECHNOLOGIES. If you are in the UK or EU and are unsatisfied with our response, you may lodge a complaint with your local supervisory authority.
This policy is provided for transparency and is not legal advice. Review by your own counsel is recommended before relying on it for a specific compliance obligation.