Last updated 31 July 2026.
This notice explains what personal data imkylejk.me collects, why, how long it's kept, and what rights you have over it. It applies to visitors, contacts, client portal users, supporters, and anyone who submits a review or chats with the site's support bot.
Kyle Kozlowski, trading as ImKyleJK, is the data controller for personal data collected through this site. I'm a sole trader based in Scotland, United Kingdom, and I act as my own point of contact for data protection — there's no separate DPO, but any request is handled personally and promptly. Contact: hello@imkylejk.me.
I don't sell your data, and I don't share it with third parties for their own marketing.
Support bot chats are categorised by an AI model (topic + one-line summary) purely so I can see patterns in what people ask — this doesn't affect you individually and isn't used to make any decision about you. The bot can also flag a session as abusive using pre-defined rules (not solely AI judgement) and pause chat access temporarily; this only limits further bot messages, it has no other effect and can be reversed on request.
Client, account, and bot data is stored locally under my direct control, not on a third-party database platform. The infrastructure is physically secured with on-site CCTV, access control, and network monitoring (intrusion detection/prevention), alongside standard technical measures — encryption in transit (HTTPS), access restricted to me alone, and regular backups. Project files are stored in access-controlled cloud object storage, accessed only via short-lived signed links rather than public URLs. Payment and subscription processing is handled by Stripe and Clerk Billing; authentication is handled by Clerk. These are data processors acting under their own privacy terms — see Clerk's privacy policy and Stripe's privacy policy.
Where a processor (e.g. Clerk or Stripe) transfers data outside the UK/EEA, they do so under their own safeguards (such as Standard Contractual Clauses) as set out in their respective privacy policies. Core project and account data controlled directly by me stays on infrastructure I operate.
If you subscribe as a supporter, your name and profile photo may appear in a public supporter list on the homepage. This is opt-in by default but can be switched off at any time from your account settings — turning it off removes you from the public list immediately without affecting your subscription.
Reviews are held privately until I approve or reject them for publication; rejected reviews are not published and are deleted per the retention period above. If you submit a review, the name and role you provide may be published alongside your review text and rating — don't include anything you don't want public. Blog reactions are anonymous beyond the device/IP cap used to prevent abuse.
If a client portal account is suspended (see Terms), relevant account and project data is retained, not deleted, so the suspension and any related dispute (including chargebacks) can be evidenced and resolved. This data is handled under the same protections as active accounts, and is deleted or anonymised once the dispute is resolved and any legal retention period has passed.
This site isn't directed at children, and the client portal and paid services aren't intended for use by anyone under 18. If you believe a child has provided personal data to this site, contact me and I'll delete it.
Under UK GDPR, you can:
To exercise any of these, email hello@imkylejk.me. I'll respond within one month. Client project records tied to active invoices, or accounts involved in an unresolved payment dispute, may be retained as required for UK tax record-keeping or to evidence that dispute, even after a deletion request. If you're unhappy with how a request is handled, you can complain to the UK Information Commissioner's Office (ICO).
In the unlikely event of a personal data breach that poses a risk to you, I'll notify affected individuals and, where required, the ICO, in line with UK GDPR timescales.
This notice may be updated as the site changes — the "last updated" date at the top always reflects the current version. Material changes affecting client data will be communicated directly where practical.