KIST / LEGAL
Privacy policy
[TBD — date on publication]
1. Who we are
Kist is a product of Grapeworks Ltd, company number SC782424, registered office Studio One, 89 Middlesex Street, Glasgow, G41 1EE. Data protection questions go to Euan McColm at euan@grapeworks.ai.
We are registered with the Information Commissioner’s Office.
[TBD — ICO registration number]
The ICO registration fee is not yet paid. This clause cannot ship without a real number.
2. The two different relationships on this page
Most privacy policies cover one relationship. This one covers two, and mixing them is how these documents end up saying something untrue.
When you visit this website or contact us, we are the controller. We decide what we collect and why, and this policy is our own account of that. Section 3 covers it.
When an agency buys Kist and connects their client’s data, we are a sub-processor. The agency’s client is the controller, the agency is the processor, and we sit one hop further down. We do not decide what that data is used for, we act on the agency’s documented instructions, and the individual’s rights are exercised through the controller. Section 4 covers it.
3. When we are the controller: this website and our own records
What we collect. If you fill in a form or email us, we get whatever you send: name, email address, company, and whatever is in the message. If you accept analytics, we collect page views and the events described in the cookie policy. If you decline, we collect none of that.
Why. To answer you, to run the business relationship, and to work out which pages are doing a job.
Our lawful basis. Legitimate interest for responding to an enquiry and keeping a record of the conversation. Consent for optional analytics, which you give or refuse on the banner and can withdraw at any time. Contract where you become a customer. Legal obligation where tax and company law require us to keep records.
How long. Enquiries that go nowhere are deleted within twelve months. Customer records are kept for the life of the engagement and then for as long as tax law requires. Analytics data follows the retention setting on the platform, disclosed in the cookie policy.
Where it goes. Our own CRM record of you as a client or prospect sits in HighLevel, which is in the United States under the UK Addendum to the Standard Contractual Clauses. Email and documents sit in Microsoft 365. Both are listed in the sub-processors document.
Your rights. Access, rectification, erasure, restriction, portability and objection, including objecting to marketing at any time. Email euan@grapeworks.ai. We will acknowledge within two working days and answer within the statutory month. You can complain to the ICO at ico.org.uk, and we would rather you came to us first.
4. When we are a sub-processor: client data flowing through Kist
The chain.The agency’s client is the controller. The agency is the processor. Grapeworks is the sub-processor. Nothing moves until there is a signed data processing agreement covering that chain, and the connector step is where that paperwork gate sits.
What we hold. Kist reads from the sources an agency connects. Depending on the engagement that can include:
- Aggregated and pseudonymous analytics and advertising data: traffic, sessions, campaign and placement performance, search queries, cost and conversion counts. This is the bulk of it by volume and it identifies nobody.
- Session recording and behavioural data from Microsoft Clarity, where that connector is enabled.
- Identifiable contact data, where an engagement puts it there. Name, email address, phone number and, in the Kickstarter case, postal address and free-text notes.
[TBD — Kickstarter backer data]
Whether this data is still held, and under what agreement, is an open question for Euan (open question 5).
How identifiable data is handled.It is written to a separate restricted store, held apart from the analytics tables that reports and dashboards read. Access is limited to named Grapeworks staff under a confidentiality obligation. Data is partitioned per client and the query layer asserts a single client per read, so one client’s records cannot be returned in another client’s output. We do not put raw personal data through third-party AI tools; AI-assisted analysis runs on aggregated or anonymised data.
What comes out.Reports and dashboards carry aggregate figures. Where an engagement genuinely requires record-level output, that is stated in that engagement’s own data processing agreement rather than assumed here.
Rights requests.If you are an individual whose data reached us through an agency’s client, we are not the right first stop and we are not allowed to answer you directly. Contact the business you dealt with. If you write to us anyway, we will pass it to the controller within two working days and tell you we have done so.
Deletion. On the end of an engagement, or earlier on request, we return or securely delete the data within thirty days and confirm in writing.
5. Sub-processors
The vendors we engage are listed in the sub-processors document, with what each one does, where it sits, and the transfer safeguard. We give thirty days notice before adding or replacing one.
A client’s own Google Analytics, Meta or Search Console account is not our sub-processor.Those are the client’s own platforms under the client’s own terms with those vendors. We read from them with credentials the client delegates to us.
6. Security
Encryption in transit and at rest. Role-based access with least privilege and multi-factor authentication on administrative accounts. Access revoked on staff change. Documented access logging. Secrets held in a managed secret store, never in configuration files. Backups with a tested restore path. Code review and dependency scanning on the software that runs the pipeline.
[TBD — technical and organisational measures schedule]
A separate sibling deliverable to this policy, not written yet. This section is the summary; a client’s security review will ask for the full schedule.
7. International transfers
Our own infrastructure is in the UK and Europe. Some sub-processors are in the United States. Those transfers are made under the UK Addendum to the Standard Contractual Clauses or another lawful mechanism, and where a vendor lets us choose a region, we choose the one that keeps data closest.
8. Automated decision-making
Kist produces analysis and recommendations. A person decides what to do with them. There is no automated decision producing a legal or similarly significant effect on any individual.
9. Changes
We date this page when it changes. Material changes affecting a live engagement are notified to the agency directly, not left to be discovered here.