Effective: 29 July 2026
The controller for the processing described here is Kitsos Services. Contact: support@services.kitsos.net. This notice explains the processing connected with Kitsos websites, services, APIs, accounts and support channels. Individual services may provide additional notices where their processing differs.
Depending on the service, we process technical connection and security data (for example IP address, time of access, requested URL or hostname, browser and device information, HTTP headers, request identifiers and error information); account and access data (for example account identifier, email address, authentication and session information); communication data supplied by you; and usage or consent data. We process only the data needed to provide, secure, operate and improve the relevant service.
Our services are delivered through a combination of Cloudflare Pages, Cloudflare Workers, Cloudflare Workers KV, Cloudflare D1, Cloudflare Email Routing, Vercel, GitHub Pages, and infrastructure operated by us or for us at Oracle, Google Cloud and on-premises locations. We also operate databases on our own servers. The provider used depends on the specific site or service; not every request uses every provider. These systems may process connection, routing, diagnostic and security data to deliver content, operate applications, prevent abuse and investigate faults.
Cloudflare also provides edge delivery and security functions. Workers KV and D1 are storage components used to retain data required by our systems; they do not themselves act as a content-delivery service. Cloudflare Email Routing is used for routing inbound email. We use Cloudflare Turnstile on the contact form to distinguish legitimate visitors from automated abuse; it processes the information needed for that security check, including connection data and the Turnstile response.
For the authoritative nameservers of kitsos.net and its subdomains, we use our own infrastructure as well as Cloudflare, deSEC and Hurricane Electric. These providers receive the DNS requests and technical network data necessary to resolve our domains, secure the zone and troubleshoot it. This is distinct from our DNS resolver service: the resolver is operated entirely on our own servers. Optional DNS blocking is part of that resolver service. If it is used, the related block pages are delivered through Fly.io; Fly.io processes the technical data required to deliver the page, such as the requested hostname, IP address, time and connection information.
We use Clerk for login and account management and Cloudflare One for access controls. These providers process the identity, authentication, session and access information needed to create accounts, sign in, protect sessions and enforce access rules. If you contact us while signed in, the contact request may be associated with your account so that we can handle it correctly.
When you use the contact form, we process the name, email address, selected service, subject, message and the technical context required to handle the request. This can include the page from which the form was sent, the referrer and query-string parameters, and—where you are signed in—account context. The form is protected by Cloudflare Turnstile. Contact-form emails are sent through Brevo. Brevo and, for other transactional email flows, Mailgun process the email data necessary for delivery.
We use Axiom for technical contact-form lifecycle logging: receipt, validation, Turnstile and email-delivery outcomes, timing, error codes and limited request diagnostics. These events help us investigate failures, abuse and reliability. We do not send the message body, email address or Turnstile token to Axiom. Where account correlation is needed in these logs, we use a pseudonymous identifier rather than the plain account identifier.
API requests may be processed through Cloudflare and our application infrastructure. We keep the technical logs needed to maintain availability, detect misuse, prevent attacks, diagnose errors and improve reliability. Axiom may receive basic API and operational telemetry for these purposes. We do not use this technical logging to build advertising profiles.
If an error occurs, you may be redirected to https://error.kitos.net, where you receive an explanation of the error. The error is automatically reported to us together with the technical information needed to diagnose and resolve it, such as time, requested URL, error code, request identifier, browser or device information and connection data. We use these reports only for security, troubleshooting and service reliability.
We use Google Analytics on kitsos.net and the Kitsos API documentation through Google tags to understand aggregate use of these websites. Google Analytics is loaded only after you consent. Your choice is stored for up to twelve months in the first-party kitsos_consent cookie, which is scoped to kitsos.net and its subdomains so the same choice applies across these websites. The cookie contains only whether analytics was accepted or declined. After consent, Google Analytics may set additional analytics cookies and process usage, browser, device and connection data. We also use Better Stack Real User Monitoring to detect errors and performance issues and, where enabled by its service, to review session replays for troubleshooting and service reliability. Better Stack receives technical browser, device and usage data needed for this purpose. When you are signed in through Clerk, we send Better Stack only your Clerk user ID; we do not send your email address, name, phone number or other Clerk profile data. Fields marked as sensitive, including contact-form entries and Turnstile verification, are excluded from session replay. We also use strictly necessary local storage, cookies or similar technologies for language selection, login/session security, access control and Turnstile. You can decline optional Google Analytics through the cookie choice; this does not affect necessary security and service functions.
We process data to provide requested services and accounts, respond to enquiries, deliver email, secure systems, prevent abuse, maintain reliable infrastructure and comply with legal obligations. Depending on the situation, the legal basis is performance of a contract or steps at your request, our legitimate interests in secure and reliable operation, your consent (in particular for optional analytics), or a legal obligation. We do not make decisions producing legal or similarly significant effects solely by automated means on the basis of this processing.
Recipients are the providers named above and service providers that support the relevant function, each acting only where necessary. Some providers may process data outside the EU/EEA. Where such a transfer occurs, we rely on the applicable transfer mechanism and safeguards required for that provider and processing, such as an adequacy decision or contractual safeguards. Provider locations and safeguards can change; please contact us if you need information about a particular service.
We retain personal data only for as long as necessary for the relevant purpose, configured security and operational retention periods, or applicable legal retention requirements. Contact requests are kept while needed to handle the request and any necessary follow-up. Technical logs are retained for the relevant diagnostic, security and reliability period and then deleted or anonymised in accordance with the applicable system configuration.
Subject to the applicable legal conditions, you can request access, rectification, erasure, restriction of processing, portability, or object to processing based on legitimate interests. You may withdraw consent at any time with effect for the future. To exercise a right, contact support@services.kitsos.net. You may also lodge a complaint with the competent data-protection supervisory authority.
We update this notice when services, processing or legal requirements change. The current version is published on this page.