1. Who we are
Sizmic Limited (“Sizmic”, “we”, “us”) is the controller of the personal data described in this policy. We are a company registered in England and Wales, company number 15403344, registered office 78 James Smith Court, Dartford, England, DA1 5XL.
We operate the website at kirak.io and the Kirak Studio service.
Contact: privacy@kirak.io.
We are registered with the UK Information Commissioner’s Office (ICO), registration number ICO_REG_NO.
2. Scope of this policy
This policy explains how we handle personal data when you:
- visit or interact with kirak.io;
- create or use a Kirak Studio account; or
- contact us, sign up to our waitlist, or receive our communications.
What this policy does not cover. When you run a backend on Kirak Studio, your application processes personal data about your end users. For that data, you are the controller and we act as your processor — that processing is governed by our Data Processing Addendum (kirak.io/legal/dpa), not this policy. This policy also does not cover the open-source Kirak runtime when you self-host it; the self-hosted runtime does not send data to us.
3. The personal data we collect
3.1 Data you give us
| Category | Examples |
|---|---|
| Account | Name, email address, password (stored hashed), organisation name, and, for teams, the email addresses of Users you invite. |
| Billing | Billing name, address, country, and the last four digits and expiry of your card. Card details are collected and stored by our payment processor, PAYMENTS — we do not store full card numbers. |
| Support & communications | The content of emails and messages you send us, and our replies. |
| Waitlist & marketing | Email address (and any name/company you provide) when you join our waitlist or subscribe to updates. |
3.2 Data we collect automatically
| Category | Examples | Source |
|---|---|---|
| Product usage | Which Studio features you use, projects and instances you create, actions in the console, and API/console request logs including IP address, timestamps, and user agent. | Kirak Studio |
| Device & connection | IP address, browser type and version, operating system, referring pages, and approximate location (city/country, derived from IP). | Website and Studio |
| Website analytics & tracking | Pages viewed, links and buttons clicked, time on page, scroll depth, session recordings and heatmaps (mouse movements, clicks, scrolls — not keystrokes in input fields, which are masked), and conversion events. Collected via Google Analytics and Microsoft Clarity, loaded through Google Tag Manager. | kirak.io |
| Cookies & similar technologies | See section 5 and our Cookie Policy (kirak.io/legal/cookies). | Website and Studio |
3.3 Data from third parties
We may receive limited data from our payment processor (e.g. payment success/failure, fraud signals) and from analytics providers (aggregated audience data).
We do not collect special category data (such as health, biometric, or political data) about you, and we ask that you do not send it to us.
4. How we use your data, and our lawful bases
| Purpose | Data used | Lawful basis (UK GDPR) |
|---|---|---|
| Create and administer your account; provide the Service | Account, usage, device | Performance of a contract with you |
| Take payment and manage subscriptions | Billing | Performance of a contract; legal obligation (tax/accounting records) |
| Provide support and respond to your requests | Support, account | Performance of a contract; legitimate interests (helping our users) |
| Keep the Service secure; detect, prevent, and investigate abuse, fraud, and outages | Usage, device, logs | Legitimate interests (security of the Service and our users) |
| Understand and improve how the Service and website are used | Usage, analytics, device | Legitimate interests (improving our product); consent for cookie-based website analytics |
| Send service and transactional messages (receipts, security alerts, changes to terms, downtime notices) | Account, billing | Performance of a contract; legitimate interests |
| Send marketing and product updates to existing customers | Account, email | Legitimate interests (marketing to our own customers), with an unsubscribe link in every message |
| Send updates to waitlist and newsletter subscribers | Consent (you can withdraw it at any time) | |
| Comply with legal obligations and enforce our terms | Any of the above | Legal obligation; legitimate interests; establishment/exercise/defence of legal claims |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you can object at any time (section 9).
5. Cookies and similar technologies
Our website uses cookies and similar technologies for three purposes: (a) essential cookies needed to run the site and keep you signed in to Studio; (b) analytics cookies (Google Analytics); and (c) product/experience technologies (Microsoft Clarity session recording and heatmaps). Analytics and product/experience technologies are only set after you consent via our cookie banner, and you can change your choice at any time. Full details, including the specific cookies and their durations, are in our Cookie Policy at kirak.io/legal/cookies.
6. Who we share your data with
We do not sell your personal data. We share it only with:
| Recipient type | Who / why |
|---|---|
| Infrastructure & hosting | HOSTING_UK_EU (hosts Sizmic’s own data — accounts, billing database, application logs — in the UK/EU); SITE_HOST (marketing site). Customer instances run on INSTANCE_PROVIDERS in the region the customer selects. |
| Payments | PAYMENTS (processes card payments and stores card details). |
| TXN_EMAIL (service and transactional email); MARKETING_EMAIL (marketing email and waitlist). | |
| Analytics & product | Google (Google Analytics, Google Tag Manager); Microsoft (Clarity). PRODUCT_ANALYTICS (in-app product analytics), ERROR_TRACKING (error and performance monitoring), if used. |
| Support | SUPPORT_TOOL (if used). |
| AI model providers | AI_PROVIDERS — where you use the AI Build Agent, your prompts are sent to these providers to generate output. See the AI Build Agent Terms. |
| Professional advisers | Lawyers, accountants, and auditors, under confidentiality, where needed. |
| Authorities | Regulators, law enforcement, and courts where we are legally required to disclose or need to establish, exercise, or defend legal claims. |
| Business transfers | An acquirer or successor if Sizmic is involved in a merger, acquisition, financing, or sale of assets — subject to this policy. |
Our service providers act as our processors under written contracts and may only use your data to provide services to us. A current list of the sub-processors involved in delivering Kirak Studio is at kirak.io/legal/subprocessors.
Government and law-enforcement requests
We disclose personal data or Customer Content to a government body or law-enforcement agency only when we are legally required to, and only in response to valid legal process: for UK authorities, a court order, warrant, or other instrument that is binding on us; for authorities outside the UK, process that is enforceable in England and Wales, such as a request made through a mutual legal assistance treaty. We review every request, and we push back on or ask to narrow requests that are overbroad, unclear, or not properly served. Unless the law or a court order prohibits it, we notify the affected customer before disclosing their data, so that they can seek to challenge the request. In a genuine emergency involving a risk of death or serious physical harm, we may disclose limited information without legal process, where the law allows. Legal process should be served on Sizmic Limited at our registered office (section 15), with a copy to legal@kirak.io. We intend to publish a regular transparency report on the requests we receive.
7. International transfers
Sizmic’s own data (accounts, billing, logs) is stored in the UK and/or EU.
Some of our service providers are located outside the UK — in particular Google, Microsoft, PAYMENTS, and the AI model providers are in the United States. Where we transfer personal data outside the UK, we rely on an approved safeguard: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional measures needed, or transfers to a country the UK has found to provide adequate protection.
Customer instances. If you choose a US region for your Kirak Studio instance, personal data that your backend processes will be stored and processed in the US. You control that choice; the transfer terms for that data are in the Data Processing Addendum.
You can ask us for a copy of the safeguards we use by emailing privacy@kirak.io.
8. How long we keep your data
| Data | Retention |
|---|---|
| Account and profile | For as long as your account is open. After closure, deleted or anonymised from active systems, with residual encrypted-backup copies purged within 30 days. |
| Customer Content and project data in Studio | Deleted from active systems when you delete the project or close the account (after the 30-day export window in the Terms of Service); residual encrypted-backup copies purged within a further 30 days. |
| AI Build Agent prompts and output | Deleted with the project; a minimal safety-log sample kept up to 30 days (see the AI Build Agent Terms). |
| Billing and transaction records | 6 years, to meet UK tax and accounting law. |
| Support correspondence | Up to 24 months after the matter is resolved. |
| Security and access logs | Up to 12 months, unless needed longer for an investigation. |
| Website analytics | Per each provider’s retention settings (Google Analytics: up to 14 months; Microsoft Clarity: up to 12 months) — configured to the shortest practical period. |
| Marketing and waitlist data | Until you unsubscribe or withdraw consent, then removed from active marketing (a suppression record is kept so we don’t re-contact you). |
9. Your rights
Under UK data protection law you have the right to: access your data; ask us to correct it; ask us to delete it; ask us to restrict or object to processing; ask for portability of data you gave us; and withdraw consent at any time (without affecting processing before withdrawal).
To exercise any of these, email privacy@kirak.io. We will respond within one month. We may ask you to verify your identity. These rights have some legal limits — for example, we may keep data we need for legal reasons.
You also have the right to complain to the Information Commissioner’s Office (ico.org.uk, helpline 0303 123 1113) if you think we have handled your data unlawfully, though we would appreciate the chance to address your concern first.
10. Your US state privacy rights
This section applies if you are a resident of a US state with a comprehensive consumer privacy law, including California (under the California Consumer Privacy Act, as amended by the CPRA), Colorado, Connecticut, Virginia, Texas, Oregon, and others. It supplements the rest of this policy. Those laws use the term “personal information”; here it means the personal data described in this policy.
What we collect and why. In the last 12 months we have collected the categories of personal information described in section 3: identifiers (such as name, email address, and IP address); commercial information (such as plans purchased and billing records); internet and other electronic network activity (such as product usage, website analytics, and device data); approximate geolocation derived from IP address; and the content of messages you send us. We collect it from you, from your devices, and from the third parties described in section 3.3. We use it for the purposes described in section 4, and we keep it for the periods described in section 8.
Sale and sharing. We never sell your personal information. If you accept advertising or analytics cookies on kirak.io, those cookies may let third parties collect data about your browsing for advertising, which some state laws treat as a “sale” or “sharing” for cross-context behavioural advertising (see our Cookie Policy). These cookies are only set with your consent, and you can opt out at any time through the cookie banner or the “Cookie settings” link in the website footer. We treat a Global Privacy Control (GPC) signal from your browser as a valid opt-out. We do not knowingly sell or share the personal information of anyone under 16.
Sensitive personal information. We do not use or disclose sensitive personal information to infer characteristics about you, or for any purpose that would give you a right to limit its use under these laws. Account passwords are stored hashed and used only to sign you in.
Your rights. Depending on your state, you may have the right to:
- know what personal information we have collected about you, including the categories, sources, purposes, and the categories of third parties we disclose it to, and to receive a copy of it;
- delete personal information we have collected from you;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information, and of its use for targeted advertising or profiling that produces legal or similarly significant effects (we do not carry out such profiling); and
- appeal a decision we make on your request.
How to exercise your rights. Email privacy@kirak.io. We will confirm receipt within 10 business days and respond within 45 days, which we may extend by a further 45 days where reasonably necessary, telling you why. To protect your data, we will verify your identity by matching information you give us with information we hold, for example by asking you to confirm the request from your account email address. If we deny your request, you can appeal by replying to our decision with the subject line “Appeal”; we will respond to an appeal within 45 days. If you are not satisfied with the outcome of an appeal, you can contact your state attorney general.
Authorised agents. You can use an authorised agent to make a request on your behalf. We will ask the agent for proof of your signed permission, and we may ask you to verify your identity directly with us.
Non-discrimination. We will not deny you the Service, charge you a different price, or provide a different level of service because you exercised any of these rights.
Your customers’ data. For personal information that our Studio customers process about their own end users, the customer is responsible for responding to requests, and we act as their service provider under the Data Processing Addendum.
11. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls and least-privilege access, network isolation for customer instances, logging and monitoring, and regular review of our providers. No system is perfectly secure; if a personal data breach affects you and is likely to result in a high risk to your rights, we will notify you and the ICO as required by law.
12. Children
Kirak Studio is not intended for anyone under 16. We do not knowingly collect personal data from children under 16. If you believe a child has given us personal data, contact privacy@kirak.io and we will delete it.
13. Third-party links
Our website and documentation link to third-party sites and services (for example, GitHub, model providers, and the “ask about Kirak” AI assistants). We are not responsible for their privacy practices; review their policies before using them.
14. Changes to this policy
We may update this policy. If we make a material change, we will notify account holders by email or an in-Service notice before it takes effect. The “effective date” at the top shows the current version.
15. Contact
Sizmic Limited — privacy@kirak.io
78 James Smith Court, Dartford, England, DA1 5XL — company number 15403344
Supervisory authority: Information Commissioner’s Office, ico.org.uk