How information supports the programme.
Pre-launch legal checkpoint: add the data controller’s legal identity, address, registration details, privacy contact and confirmed retention schedule before enabling live payments or client data.
Last updated: 16 July 2026. This notice describes the intended handling of personal information in the KW BrandOS website and private-beta workspace.
1. Information collected
The service may collect account and contact details, organisation and project information, diagnostic answers, enquiry content, participant responses, uploaded evidence, decision and activity records, support requests, billing references, book-delivery details supplied by a qualifying annual account owner, security logs and technical information such as IP-derived security hashes.
2. Why it is used
Information is used to provide and secure accounts, recommend a delivery model, process orders, fulfil an annual book bonus, respond to enquiries, operate the strategy programme, maintain evidence and decision records, provide support, detect abuse, improve reliability and meet legal or accounting duties.
3. Legal basis
Depending on the relationship and information, processing may be necessary to take steps before a contract, perform a contract, comply with law, pursue legitimate interests in operating and securing the service, or act on consent. The final notice must be reviewed against the confirmed business and deployment arrangements.
4. Payments
Stripe hosts online Checkout and processes payment and billing information. KW BrandOS stores Stripe customer, checkout, payment and subscription references but does not receive complete card details.
5. AI processing
Ordinary AI consultation uses permission-filtered project context. Persistent evidence indexing is off until project-level and per-file consent are recorded. Anonymous or private pre-work is only included in AI synthesis when the relevant project choice permits it. AI outputs remain draft material for human review.
6. Sharing and processors
Information may be processed by hosting, email, payment, book-order or delivery, security and - where separately enabled - AI service providers. It may also be shared with professional advisers or authorities where required. Provider details, locations and contractual safeguards must be maintained in the production data-processing records.
7. Visibility inside a project
Project roles control access. Responses may be private, anonymous in aggregate or team-visible. Interface labels do not replace server-side permissions, and project owners are responsible for assigning appropriate roles.
8. Retention
Information is kept only for as long as needed for the service, security, support, contracts, disputes and legal duties. The production schedule must define periods for unsuccessful enquiries, incomplete checkouts, expired accounts, project content, audit records and backups.
9. Security
The application uses secure sessions, access roles, CSRF protection, rate limits, audit logging, encrypted private responses and server-side API keys. No internet service can guarantee absolute security; users must protect credentials and report suspected access promptly.
10. Individual rights
Depending on applicable law, people may have rights to access, correct, erase, restrict or object to processing, request portability and complain to a supervisory authority. Some records may need to be retained for legal, contractual or security reasons.
11. Cookies and analytics
The platform uses essential session and security cookies. The website also uses Google Analytics to understand visits and how people use the service. Google may set or read analytics cookies and receive usage information when the Google tag loads. Analytics cookies must be documented and, where required, used only with the visitor’s consent. The website does not intentionally use advertising cookies in this build.
12. Contact
Use the KrisWood enquiry form to raise a privacy question until the dedicated production privacy contact is confirmed.
