How information supports the engagement.
Pre-launch legal checkpoint: add the data controller’s legal identity, address, registration details, privacy contact and confirmed retention schedule before enabling live payments or wider client data.
Last updated: 31 July 2026. This notice describes the intended handling of personal information in the KW BrandOS website, early-access list and private-beta workspace.
1. Information collected
The service may collect early-access contact details, organisation or practice name, preferred BrandOS route, registration source, marketing and privacy consent records, account and project information, diagnostic answers, enquiry content, participant responses, uploaded evidence, decision and activity records, support requests, historical or future billing references, security logs and technical information such as IP-derived security hashes.
2. Why it is used
Early-access information is used to build and manage the interest list, understand which routes matter, select people for early access, send platform and launch updates, and provide relevant offers including the early-signup discount. Other information is used to provide and secure accounts, recommend a delivery model, respond to enquiries, operate the strategy engagement, maintain evidence and decision records, provide support, detect abuse, improve reliability and meet legal or accounting duties.
3. Legal basis
Early-access news and launch offers are sent on the basis of the consent recorded on the registration form; that consent can be withdrawn at any time. Depending on the wider relationship and information, other processing may be necessary to take steps before a contract, perform a contract, comply with law or pursue legitimate interests in operating and securing the service. The final notice must be reviewed against the confirmed business and deployment arrangements.
4. Payments
KW BrandOS is not currently accepting new online payments. If paid access opens, the privacy notice will identify the payment provider and explain the payment and billing references retained by KW BrandOS; complete card details will not be collected by this website.
5. AI processing
Ordinary AI consultation uses permission-filtered project context. Persistent evidence indexing is off until project-level and per-file consent are recorded. Anonymous or private pre-work is only included in AI synthesis when the relevant project choice permits it. AI outputs remain draft material for human review.
6. Sharing and processors
Early-access contact details, organisation, preferred route, registration source and consent record are processed in HubSpot CRM so KrisWood can manage the enquiry and sales opportunity. Brevo processes the contact details and message content needed to send registration confirmations, internal notifications and consented early-access communications. Information may also be processed by hosting, security and - where separately enabled - AI service providers. Future paid or physical offers may also use payment or delivery providers. Information may be shared with professional advisers or authorities where required. Provider details, locations and contractual safeguards must be maintained in the production data-processing records.
7. Visibility inside a project
Project roles control access. Responses may be private, anonymous in aggregate or team-visible. Interface labels do not replace server-side permissions, and project owners are responsible for assigning appropriate roles.
8. Retention
Information is kept only for as long as needed for early access, communications, the service, security, support, contracts, disputes and legal duties. If marketing consent is withdrawn, the active mailing status is removed; a minimal suppression record may be retained so the person is not added again accidentally. The production schedule must define periods for early-access records, unsuccessful enquiries, expired accounts, project content, audit records and backups.
9. Security
The application uses secure sessions, access roles, CSRF protection, rate limits, audit logging, encrypted private responses and server-side API keys. No internet service can guarantee absolute security; users must protect credentials and report suspected access promptly.
10. Individual rights
Depending on applicable law, people may have rights to access, correct, erase, restrict or object to processing, request portability and complain to a supervisory authority. Marketing consent can be withdrawn at any time by replying to an email or using the unsubscribe option included in marketing communications. Some records may need to be retained for legal, contractual, suppression or security reasons.
11. Cookies and analytics
The platform uses essential session and security cookies. The website uses Google Analytics 4 (measurement ID G-QZTCVNGHKG) to understand visits and how people use the service. The Google tag is loaded only after a visitor accepts analytics. The choice is stored in the visitor’s browser and can be changed using the Cookie settings button. Declining leaves Google Analytics unloaded. Advertising storage and personalisation remain disabled in this implementation.
12. Contact
Use the KrisWood enquiry form to raise a privacy question until the dedicated production privacy contact is confirmed.
