Privacy Policy
- In effect
- 9 August 2026
- Last revised
- 9 August 2026
- Version
- 1.0
Clause 01
At a glance
In short No cookies, no analytics, no advertising, no tracking. The only personal data we hold is what you deliberately send us.
Most privacy policies are long because the operation behind them is complicated. This one is long because it is specific. The short version is on this page, and everything after it is the detail behind each line.
- What we collect
- What you type into the Engagement Brief, and the technical information any web server necessarily sees when it answers a request.
- What we do not collect
- We run no analytics, no advertising or marketing pixels, no session recording, no fingerprinting, and no third-party trackers of any kind. We do not build profiles, and we do not track you across sites.
- Cookies
- This site sets no cookies at all. Two items of browser local storage hold your own choices on your own device, and are never transmitted to us.
- Selling your data
- We have never sold or shared personal information, and we do not intend to. There is no advertising business here to sell it to.
- Who else sees it
- The infrastructure that hosts the site, and the services that carry a submitted brief to us. Each one is named in this policy.
- Your rights
- Access, correction, deletion, portability, objection and complaint available to you wherever you live, not only where the law compels it. Write to satcorpvk@gmail.com.
Clause 02
Who is responsible for your data
In short SATCORP decides what is collected and why, which makes us the controller. Reach us at satcorpvk@gmail.com.
This policy applies to satcorp.io and every establishment presented on it SATCORP, ANU, KYRAX, Ki-Ra Studios, NAMTAR and PULSE and to the enquiries we receive through it.
The controller, in the language of the European and United Kingdom General Data Protection Regulations, is SATCORP, an unincorporated business established in the United States and trading as SATCORP. You can reach us about anything in this policy at satcorpvk@gmail.com. We have not appointed a data protection officer, because the scale and nature of our processing does not require one. Requests come to that address and are handled by the person who runs the operation.
SATCORP has no establishment in the European Economic Area or the United Kingdom. Individuals in those regions should send requests directly to the address above, and they are handled on the same timelines and to the same standard as any other.
Clause 03
What we collect
In short The fields of the Engagement Brief, and the request data a web server cannot avoid seeing.
What you send us in the Engagement Brief
The brief is the only place on this site where you are asked for personal information. It collects exactly these fields, and nothing else:
- Clarity your name; your organisation, if you give one; your preferred contact channel; the address, handle or number to use; a description of the matter; and how you found us.
- Scope the service entries you marked, the retainer class you indicated, your timeline, and a description of assets you already have.
- Execution the reporting cadence you prefer, and any further notes you choose to add.
Only your name, a contact channel, a contact address and a description of the matter are required. Every other field is optional, and leaving one blank has no consequence beyond a slower first conversation. What you write into a free-text box is a matter for you, and we ask you not to include sensitive categories of personal data, third-party personal data, credentials or payment details there.
What the server sees
- Your IP address. Used to enforce a limit of three submissions per minute so that the form cannot be flooded. It is held in memory for sixty seconds for that purpose and is not written to the enquiry record.
- Your browser user-agent string. Stored alongside a submitted brief, so that a malformed or fraudulent submission can be understood after the fact.
- Ordinary server logs. Our hosting provider records requests, including IP address, timestamp, page requested and user-agent, as part of delivering and protecting the site. Those logs are held under that provider’s retention schedule.
Automated screening
The brief carries two silent checks: a form field hidden from people and visible to automated scripts, and a measurement of how long the form was open before it was submitted. Both exist solely to identify automated submissions. Neither is used to evaluate you, neither produces any legal or similarly significant effect, and no profile is built from either.
What we do not collect
We do not knowingly collect special categories of personal data, and we do not process payment information anywhere on this site. Typefaces are compiled into the site and served from our own domain, so simply viewing a page makes no request to any font, analytics or advertising provider.
Clause 04
Why we process it, and on what legal basis
In short To answer you, to run an engagement, to keep the form from being abused, and to meet our own legal obligations.
Where the European or United Kingdom GDPR applies, we rely on the following bases. Where it does not, the purposes are still these.
- Responding to your enquiry
- Taking steps at your request prior to entering a contract, under Article 6(1)(b). Without this data we cannot answer you.
- Carrying out an engagement
- Performance of a contract with you, under Article 6(1)(b), where an enquiry becomes commissioned work.
- Security, rate limiting and anti-abuse
- Our legitimate interests in keeping the site available and the intake channel usable, under Article 6(1)(f). We have weighed this against your interests and consider the intrusion minimal, since the data is transient and is not used to make decisions about you.
- Keeping business records
- Compliance with a legal obligation, under Article 6(1)(c), for accounting and tax records once you become a client, and our legitimate interests in establishing or defending legal claims under Article 6(1)(f).
- Anything else
- Your consent, under Article 6(1)(a), which you may withdraw at any time without affecting what was done before you withdrew it.
We do not send marketing email. If that ever changes, it will be to people who asked for it, with a working unsubscribe link in every message, and this policy will say so before the first one is sent.
Clause 07
International transfers
In short The site is operated from the United States, and your data is processed there.
SATCORP operates from the United States and the processors named above are United States companies. If you contact us from the European Economic Area, the United Kingdom, Switzerland or another country with transfer restrictions, your personal data is transferred to and processed in the United States.
For those transfers we rely on the European Commission Standard Contractual Clauses and, for the United Kingdom, the International Data Transfer Addendum, as incorporated into our agreements with each processor, together with the supplementary technical measures described under security below. Where you send us an enquiry directly, that transfer is also necessary for the performance of a contract with you or for steps taken at your request before entering one.
You may request details of the safeguards applied to a specific transfer by writing to satcorpvk@gmail.com.
Clause 08
How long we keep it
In short Enquiries that go nowhere are deleted within 24 months. Client records are kept as long as the law requires.
- An enquiry that does not become an engagement
- Kept for up to 24 months from our last correspondence, so that a conversation resumed later still has its context, then deleted.
- An enquiry that becomes an engagement
- Kept for the life of the engagement, and afterwards for as long as needed for accounting, tax and limitation purposes ordinarily seven years from the end of the relationship.
- IP addresses used for rate limiting
- Held in memory for sixty seconds, then discarded.
- Server logs
- Retained by our hosting provider on its own schedule.
- Correspondence
- Email is kept while it remains useful to the relationship, and reviewed periodically.
When a retention period ends, records are deleted or irreversibly anonymised. You can ask us to delete yours sooner, and we will unless we are required to keep it.
Clause 09
How it is protected
In short Encrypted in transit, held in access-controlled places, and kept out of the public repository by design.
The site is served only over HTTPS. Enquiry records are held in access-controlled storage and are excluded from the public source repository by configuration, so a brief cannot be published by accident. Access is limited to the people who need it to answer you. Credentials for third-party services are held as environment secrets and never committed to source control.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within seventy-two hours of becoming aware of it where the law requires, and we will tell you directly and without undue delay where the risk to you is high.
Clause 10
Your rights
In short Access, correction, deletion, restriction, portability, objection, and the right to complain. We extend these to everyone.
Under the European and United Kingdom GDPR you have the rights below. We extend the same rights to everyone who writes to us, whichever country they are in, because operating two standards would be more work than operating one.
- Access a copy of the personal data we hold about you, and an explanation of what we do with it.
- Rectification correction of anything inaccurate, and completion of anything incomplete.
- Erasure deletion, where we no longer need the data or where you withdraw the consent it rested on.
- Restriction a pause on processing while a dispute about accuracy or legitimate interests is worked out.
- Portability the data you gave us, in a structured, commonly used, machine-readable format.
- Objection to processing based on legitimate interests, on grounds relating to your situation, and absolutely to direct marketing at any time.
- Withdrawal of consent at any time, where consent was the basis, without affecting what was lawful before.
To exercise any of them, write to satcorpvk@gmail.com and say what you want. We respond within one month, extendable by two further months for a complex request, and we will tell you if we need that extension and why. There is no charge unless a request is manifestly unfounded or excessive. We may need to confirm your identity before acting, and we will ask for no more information than is needed to do that.
You also have the right to complain to a data protection authority. In the United Kingdom that is the Information Commissioner’s Office; in the European Economic Area it is the supervisory authority in your country of residence, place of work, or where the issue arose. We would rather you raised it with us first, but that is your choice and not a precondition.
Clause 11
If you are in the United States
In short California and the other state privacy laws give you specific rights. We do not sell or share personal information, and we never have.
This section applies to residents of California, and of the other states with comprehensive privacy laws including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and those that follow.
Notice at collection. The categories of personal information we collect are identifiers such as your name, email address, telephone number, online identifier and IP address; commercial information in the form of the services you enquired about and the budget band you indicated; internet activity in the form of server logs and your user-agent; and professional or employment information where you choose to give it. All of it comes from you, or from your device making a request. It is collected for the business purposes described in this policy, and retained as described above. We do not collect sensitive personal information as that term is defined by the California Privacy Rights Act.
No sale, no sharing, no targeted advertising. We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding twelve months or at any time. We do not process personal information for targeted advertising or for profiling in furtherance of decisions producing legal or similarly significant effects. We do not knowingly sell or share the personal information of anyone under sixteen.
You have the right to:
- know what personal information we have collected, used, disclosed and for what purpose;
- obtain a portable copy of it;
- correct inaccurate personal information;
- delete personal information, subject to the exceptions the statutes allow;
- opt out of sale, sharing and targeted advertising there is nothing to opt out of here, and an opt-out signal is honoured regardless;
- limit the use of sensitive personal information, which we do not collect;
- appeal a refusal of any request, where your state law provides for an appeal, by replying to our decision;
- not be discriminated against for exercising any of these rights. We offer no financial incentive in exchange for personal information.
Submit a request to satcorpvk@gmail.com. We confirm receipt within ten business days and respond within forty-five days, extendable once by a further forty-five days where reasonably necessary, and we will tell you if that is needed. An authorised agent may act for you with written permission that we can verify. Because we set no cookies and run no advertising technology, browser-level opt-out preference signals including Global Privacy Control encounter nothing to disable, and are honoured by default.
California residents may also request, under the Shine the Light law, details of personal information disclosed to third parties for their direct marketing purposes. We make no such disclosures.
Clause 12
If you are elsewhere
In short Canada, Brazil, Australia, Switzerland and beyond the same rights, exercised the same way.
Canada. We handle personal information consistently with the Personal Information Protection and Electronic Documents Act. You may access and correct your information and challenge our handling of it by writing to us, and you may complain to the Office of the Privacy Commissioner of Canada.
Brazil. Under the Lei Geral de Proteção de Dados you have rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent, exercisable at the address above.
Australia. We handle personal information consistently with the Australian Privacy Principles, and complaints may be made to the Office of the Australian Information Commissioner.
Switzerland. The rights described in the GDPR section are available to you under the Federal Act on Data Protection, and you may contact the Federal Data Protection and Information Commissioner.
If you are somewhere not named here, write to us anyway. The rights in this policy are offered to everyone.
Clause 13
Children
In short This site is not for children, and we do not want their data.
This site is intended for adults acting in a professional capacity. It is not directed at children, and we do not knowingly collect personal data from anyone under sixteen, or under thirteen in the United States. If you believe a child has sent us personal data, write to satcorpvk@gmail.com and we will delete it promptly.
Clause 14
Automated decisions and profiling
In short There are none. A person reads every brief.
We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not profile you. The two anti-automation checks on the Engagement Brief filter scripted submissions only; they do not evaluate you, and a legitimate enquiry caught by one can simply be resent, or sent to satcorpvk@gmail.com instead. Every brief that reaches us is read by a person.
Clause 15
Changes to this policy
In short The date at the top moves whenever the substance does. Material changes are flagged.
We revise this policy when what we do changes, and the revision date at the head of the document always reflects the current version. Where a change materially affects your rights or how your data is used, we will make that plain on this page, and where the law requires consent for the change, we will ask for it before it takes effect. A policy quietly rewritten is not a policy, so we do not do that.
Clause 16
Contact
In short Everything in this document is answered at satcorpvk@gmail.com.
Questions, requests, corrections, complaints and requests for the detail behind any statement in this policy all go to the same place:
SATCORP
satcorpvk@gmail.com
satcorp.io
Related reading: the Terms of Service, which govern the use of this site and the work commissioned through it.