01
Privacy at a glance
Our privacy commitments.
- We collect only what we need for the services that are currently available.
- We do not sell personal data or use Contact messages for marketing.
- Customer, privacy and complaint handling is carried out in-house by authorised Kiese personnel.
- Private recipient and sender addresses are kept outside the public website.
- We do not activate analytics, advertising or marketing signup without updating this notice and providing any required choices first.
- You can use our secure Contact form to exercise your rights or raise a data-protection complaint.
02
Who controls your data
KIESE LTD is the controller responsible for the Kiese website, Contact form and Feedback service. We are registered in England and Wales under company number 13717005.
Registered office:
University Of Nottingham Innovation Park, The Ingenuity Lab, Triumph Road, Nottingham, United Kingdom, NG7 2TU.
For a privacy question, information-rights request or data-protection complaint, use our secure Contact page and choose Privacy or data protection. Please do not send identity documents unless we ask for the minimum information genuinely needed to verify a request.
03
Current processing
The table describes the services covered by this notice. Contact and Feedback use the private server-backed communication service. Live customer payments and marketing subscriptions are not currently enabled.
| Activity | Data | Why we use it | Lawful basis / interest | Recipients | Retention |
| Website requests |
IP address, time, requested resource, browser and security information in ordinary hosting logs. |
Serve the site, protect it, investigate faults and prevent misuse. |
Legitimate interests: operating a secure, reliable website. |
OVHcloud; authorised Kiese personnel where investigation is needed. |
Only for the period required by hosting and security settings, troubleshooting or a legal need. |
| Basket and interface |
Product IDs, quantities, country preference, catalogue cache and temporary interface state stored on your device. |
Provide the basket, product availability and interface functions you request. |
Requested service and legitimate interests in providing a usable site. |
Normally remains in your browser; no active Kiese analytics backend receives it. |
Local storage remains until replaced or cleared; session storage normally ends with the tab or browser session. |
| Contact form |
Name, reply address, enquiry type and message. The server also uses an IP-derived protected rate-limit key and a short-lived security session. |
Route, investigate and answer your enquiry; protect the form against abuse. |
Legitimate interests in customer communication and security; steps requested before a contract where relevant. |
Authorised Kiese personnel, OVHcloud and the private business-email provider. |
Ordinary messages: normally up to 24 months after the last meaningful contact. Other categories are listed below. |
| Feedback form |
Choice responses, free-text feedback and an optional reply email. The same protected rate-limit key and short-lived security session are used to prevent abuse. |
Read and understand product/service feedback, improve the Kiese experience and reply where you choose to provide an email address. |
Legitimate interests in product and service improvement, customer communication and security. |
Authorised Kiese personnel, OVHcloud and the private business-email provider. |
Raw server-delivered feedback follows the ordinary message retention period unless it is anonymised or aggregated sooner; an attached email is kept only as needed for the stated purpose. |
| Direct-contact reveal |
IP-derived protected rate-limit key, short-lived KIESECONTACT session and one-time reveal nonce. You do not provide contact details to use the reveal. |
Return Kiese direct contact addresses to a verified browser session while reducing automated harvesting and repeated abuse. |
Legitimate interests in making business contact routes available while protecting them against automated harvesting. |
OVHcloud; authorised Kiese personnel only where a security investigation is needed. |
Reveal rate records use a one-hour limit window and stale files are removed after 24 hours when the rate directory is next used; the security session ends with the browser session. |
| Privacy rights and complaints |
Request, correspondence, verification information where necessary, investigation notes and outcome. |
Verify, investigate, respond and demonstrate accountable handling. |
Legal obligation and legitimate interests in fair complaint handling. |
Authorised Kiese personnel; advisers or authorities only where necessary. |
Normally three years after closure, with identity evidence removed earlier when no longer needed. |
| Legal, safety or security matter |
Relevant enquiry, transaction, product-safety, security or dispute information. |
Establish, exercise or defend legal claims; meet safety or legal duties. |
Legal obligation and/or legitimate interests, depending on the matter. |
Authorised Kiese personnel, advisers, insurers, courts or authorities where necessary. |
For the period needed for the legal, safety, insurance or regulatory purpose. |
Your right to object: where we rely on legitimate interests, you may object. We will consider your circumstances and stop unless we have a compelling lawful reason to continue.
04
Contact messages and sensitive information
The Contact form is for ordinary customer-service, press, wholesale and privacy enquiries. The separate Feedback page sends the answers and free text you choose through the same private server-backed service. We use submitted details to respond, understand feedback and protect the services against misuse. We do not use Contact or Feedback messages for marketing.
Please do not include medical records, detailed treatment information, passwords, payment-card details or other information that is not needed for the enquiry.
We do not intentionally collect health, heritage, religious, biometric or other special-category information through the Contact or Feedback forms. If such information is sent unexpectedly, we restrict access and normally delete it or ask for a replacement message without the sensitive detail, unless there is a specific lawful reason to retain it.
Contact messages are not stored in browser local storage. The page shows success only after the server accepts the message for delivery to the private business inbox.
05
Cookies and device storage
The Contact form, Feedback form and direct-contact reveal use the same essential KIESECONTACT session cookie with separate short-lived security tokens/nonces. The basket and interface use browser storage to provide requested functions. The website does not activate advertising pixels or Kiese first-party analytics.
Read the separate Cookies & Device Storage notice for the current inventory, purposes and durations.
Google Fonts: the current design requests typeface files from Google Fonts. The provider may receive technical request information such as an IP address and browser details.
06
Recipients and international transfers
Day-to-day customer, privacy and complaint handling is performed in-house. We do not outsource customer-service decision-making and do not sell Contact information.
OVHcloud provides website hosting and the server environment used by the Contact form.
Our private business-email provider receives Contact messages so authorised Kiese personnel can respond.
Google Fonts supplies the typeface files requested by the current visual design.
Professional advisers, insurers or authorities receive information only where reasonably necessary for legal, safety, insurance, accounting, security or regulatory purposes.
Some infrastructure providers may process technical information outside the UK. Where data-protection law requires safeguards, we rely on the provider’s applicable transfer arrangements. You may ask for more information through the secure Contact form.
07
Retention schedule
| Record | Normal period or criterion | Reason |
| Ordinary Contact enquiry | Up to 24 months after the last meaningful contact. | Answer follow-up questions and keep a proportionate service record. |
| Privacy right or complaint | Normally three years after closure. | Demonstrate handling and respond to follow-up or regulatory questions. |
| Identity evidence | Deleted as soon as verification is complete and the evidence is no longer necessary. | Data minimisation and security. |
| Rate-limit records | Used within a one-hour limit window; stale files are removed after 24 hours when the rate directory is next used. | Prevent repeated automated submissions without retaining message content or email addresses. |
| Contact security session | Browser-session cookie; server records follow secure session cleanup. | CSRF protection and form security. |
| Hosting/security logs | According to the hosting and security period needed to operate, troubleshoot and protect the service. | Website delivery, fault investigation and security. |
| Basket/local interface data | Until the browser replaces it or the visitor clears site data. | Provide basket, catalogue and interface functions on the device. |
| Legal, safety or dispute record | For the period reasonably required by the applicable claim, safety duty, insurance or legal obligation. | Protect people, the business and legal rights. |
08
Your rights
Depending on the processing and lawful basis, you may have rights to be informed, access personal data, correct inaccurate data, erase data, restrict processing, receive portable data and object to processing.
Use the secure Contact page and choose Privacy or data protection. We may ask for the minimum information reasonably needed to confirm identity or authority before disclosing personal data.
The website does not make solely automated decisions that produce legal or similarly significant effects.
09
Data-protection complaints
You may complain directly through the secure Contact page by choosing Privacy or data protection. You do not need to use legal language.
We acknowledge a data-protection complaint within 30 days, investigate it without undue delay, keep you informed where appropriate and explain the outcome and any action taken.
You may also complain to the UK Information Commissioner’s Office. Raising a complaint with Kiese first may allow us to resolve it more quickly, but it does not remove your right to contact the ICO.
10
Children
The current website and Contact form are intended for adults and are not designed for children to submit personal data independently. A parent or guardian should contact us on behalf of a child.
11
Changes and version history
We review this notice when the site, providers or data uses change. Material new uses will be explained before they start.
7 August 2026: server-backed Feedback, the server-gated direct-contact reveal and standalone website wording added to the notice.
6 August 2026: controller details, current-processing table, retention schedule, complaint route, children section and separate device-storage notice expanded.