KDD Brands

KDD Brands → Legal → Privacy policy

Privacy policy

This is the corporate policy for this website and for people who email KDD Brands LTD. It is not the policy for the Store Integration Shopify app.

You may be reading the wrong policy

If you are a Shopify merchant looking for how the Store Integration app handles your shop and customer data, read the Store Integration privacy policy instead. That document covers the app; this one does not.

If you are a customer of one of our consumer brands, the storefront you bought from publishes its own privacy policy and is the document that applies to your order.

1. What this policy covers

This policy applies to two things, and only two things:

  • Your visit to this website, kddbrands.com, including every page served from it.
  • Correspondence you send to a @kddbrands.com address, and our reply.

It does not apply to:

  • The Store Integration Shopify app. Merchant and shopper data processed by the app is governed by the Store Integration privacy policy and the data retention policy. Where the app processes shopper data, we act as processor for the merchant, not as controller.
  • The individual brand storefronts in our portfolio. Each storefront is a separate site with its own privacy policy, its own cookies and its own analytics choices. Nothing on this page describes what those sites do. Read the policy published on the storefront you used.

2. Who we are

KDD Brands LTD is the controller for the processing described in this policy.

Controller
KDD Brands LTD
Company number
16411950 (England & Wales)
Incorporated
28 April 2025
Registered office
71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
Privacy contact
privacy@kddbrands.com
General enquiries
hello@kddbrands.com
Security reports
security@kddbrands.com

We have not appointed a Data Protection Officer. We are not required to appoint one under Article 37 of the UK GDPR, and we have not done so voluntarily. Privacy matters are handled at company level and reach us at privacy@kddbrands.com.

3. This website

This site is a static set of HTML files. Being specific about what that means:

ThingOn this site
JavaScriptNone. No scripts of any kind are served or executed
AnalyticsNone. No page-view counter, no session recording, no heatmaps
Tag managerNone
Advertising or social pixelsNone. No Meta pixel, no Google Ads tag, no conversion tracking
Cookies set by usNone. We set no first-party cookies
FormsNone. There is nothing on this site to submit
Accounts, logins, newsletter signupNone. There is nothing to register for
Webfonts and third-party assetsNone. Everything the page loads comes from this domain
Cookies set by our hostCloudflare may set __cf_bm and cf_clearance — see below

Consequently we hold no profile of you, no visit history and no identifier that would let us recognise you on a later visit. Reading these pages leaves nothing with us beyond the transient request data described in the next section.

4. Cloudflare and request data

The site is hosted and delivered by Cloudflare, Inc., which acts as our processor. To serve a page and to keep the site available, Cloudflare processes request metadata, including:

  • your IP address;
  • the URL requested, and the date and time of the request;
  • your browser user-agent string and requested language;
  • the referring URL, where your browser sends one.

This is used for delivery, caching, rate limiting, bot detection and mitigation of denial-of-service attacks. Our lawful basis is legitimate interests (Art. 6(1)(f) UK GDPR): keeping the site online, secure and not abused. We do not use this data to build any profile, and we do not attempt to identify visitors from it.

Cloudflare's bot management may set a strictly necessary cookie named __cf_bm on your device. It distinguishes automated traffic from human traffic, is short-lived, and is not used for advertising or cross-site tracking. If a security challenge is shown, Cloudflare may also set a strictly necessary cookie named cf_clearance to record that the challenge was passed and avoid repeating it. Both are exempt from the consent requirement in the Privacy and Electronic Communications Regulations because they are strictly necessary to provide the service you requested, which is why this site shows no cookie banner. Details are on the cookies page.

5. Email correspondence

If you email us, we hold your message, your email address, and anything else you chose to put in the message, in our mail provider's systems. We hold it in order to read your message, reply to it, and keep a record of what was agreed or answered.

We do not add correspondents to a marketing list. There is no marketing list. We do not sell or rent contact details, and we do not pass them to any brand storefront for promotional use.

Please do not send us special category data, payment card numbers, passwords or API credentials by email. If you send us something we do not need, we will delete it.

6. Lawful bases

ProcessingLawful basis
Serving this website; security, availability and abuse prevention Legitimate interests — Art. 6(1)(f) UK GDPR: operating a secure, available website
General correspondence: reading and answering your email Legitimate interests — Art. 6(1)(f): responding to people who contact our business
Correspondence forming part of a contract or its negotiation Contract — Art. 6(1)(b), where the exchange relates to an agreement with you
Records we are required by law to keep, and responses to lawful requests Legal obligation — Art. 6(1)(c)

7. Retention

We keep correspondence for as long as needed for the matter it concerns, plus our ordinary business record-keeping, after which it is deleted. Where the law requires a record to be kept for a set period, that period governs. We are not going to publish a precise number of years here that we would not actually apply.

Request data processed by Cloudflare is retained according to Cloudflare's own retention practices for logs and security telemetry; it is short-lived operational data and is not copied into any store of ours.

If you want your correspondence deleted sooner, ask at privacy@kddbrands.com and we will do it unless we are required to keep it.

8. Who we share data with

We use two categories of processor for the processing described here:

  • Cloudflare, Inc. — hosting and delivery of this website.
  • Our email provider — receipt, storage and sending of business email.

Beyond that, we disclose personal data only where we are legally required to, or where it is necessary to establish, exercise or defend legal claims. We do not sell personal data. We run no advertising on this site and share nothing with ad networks, because there is nothing here to share.

9. International transfers

Cloudflare operates a global network, so a request to this site is served from whichever edge location is nearest to you and may be processed outside the United Kingdom. Business email may likewise be stored on infrastructure outside the UK.

Where personal data is transferred out of the UK to a country without UK adequacy regulations, the transfer relies on the safeguards in Article 46 UK GDPR — the Standard Contractual Clauses together with the UK International Data Transfer Addendum, incorporated through Cloudflare's data processing addendum and the equivalent terms with our email provider. You can ask us for information about the safeguards that apply.

10. Your rights

Under the UK GDPR you have the following rights over personal data we hold about you. They are not all absolute; some apply only in particular circumstances.

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of inaccurate or incomplete data.
  • Erasure — deletion, where we have no overriding reason or legal duty to keep it.
  • Restriction — a pause on our use of the data while a dispute about it is resolved.
  • Objection — you may object to processing we carry out on the basis of legitimate interests, and we will stop unless we can show compelling grounds that override your interests.
  • Portability — where processing is based on consent or contract and carried out by automated means, a copy in a structured, commonly used, machine-readable format.

To exercise any of these, email privacy@kddbrands.com. We respond without undue delay and within one month, as required by Article 12(3), and we will tell you if the request is complex enough to need an extension. There is no charge. We may need to ask a question or two to satisfy ourselves that the request is genuinely yours.

We take no automated decisions producing legal or similarly significant effects, and we carry out no profiling.

11. Complaints

If you are unhappy with how we have handled your personal data, tell us first at privacy@kddbrands.com — it is usually the fastest route to a fix.

You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office, at ico.org.uk. Complaining to us first is not a precondition of complaining to them.

12. Changes

If we change this policy we update the review date below. If a change materially affects how we handle personal data, we will say what changed rather than quietly re-dating the page. This site has no mailing list, so there is no notification to send — the current version is always the one published here.


Last reviewed 2026-07-26 · KDD Brands LTD (company 16411950)