1. Controller identity
KGF Builds (sole-trader / project entity owned by Kai Alexander Ortega), operating the site kgfbuilds.dev and partner deployments under biz-rocket-engine.lovable.app.
Contact for data-protection matters: dev.kai@kgfbuilds.dev.
2. Personal data we collect
- Account data — name, email, hashed password or OAuth identifier (Google).
- Contact-form leads — name, email, company, message.
- Course / certificate data — enrolment progress, graduation records, signature.
- Payment metadata — Stripe customer / payment-intent IDs (no card data is ever held by us; Stripe is PCI DSS Level 1).
- Operational logs — request IDs, error traces, IP address (truncated where possible) for security and abuse prevention.
3. Lawful bases
- Contract (UK GDPR Art. 6(1)(b)) — to deliver services, courses, certificates and licensed deployments.
- Legitimate interests (Art. 6(1)(f)) — fraud prevention, security logs, product analytics.
- Consent (Art. 6(1)(a)) — marketing email, optional cookies.
- Legal obligation (Art. 6(1)(c)) — tax, accounting, AML where applicable.
- Under PDPA 2010 §6, processing is on the basis of consent recorded at sign-up and, where applicable, performance of contract under §6(2)(b).
4. Sub-processors
A current registry of sub-processors with their compliance certifications (ISO 27017, PCI DSS, ICO registration, BayLDA DPO registration, MY PDPA data-controller filings, signed DPAs) is published at /trust.
Notable sub-processors: Akamai (CDN/edge), Supabase (database / auth), Cloudflare (DNS / edge runtime), Stripe (payments, EU entity), Brevo (transactional email, FR), Resend (transactional email), Google (Sign-In / Workspace APIs).
5. International transfers
Where data leaves the UK / EEA / Malaysia (e.g. Stripe US, Akamai US edge), transfers are protected by the UK International Data Transfer Addendum, EU Standard Contractual Clauses, and equivalent safeguards under PDPA §129 (transfer to a place outside Malaysia). Each sub-processor's DPA on the Trust Center evidences these safeguards.
6. Retention
- Account & profile — for the life of the account + 12 months.
- Certificates & graduation records — 7 years (audit / verifier obligations).
- Payment metadata — 7 years (UK HMRC requirement).
- Operational logs — 30–90 days rolling.
- Marketing consent — until withdrawn.
7. Your rights
Under UK GDPR you may request access, rectification, erasure, restriction, portability, and object to processing. Under PDPA §§30–43 you have rights of access, correction, withdrawal of consent, and to prevent processing for direct marketing.
Exercise any right by emailing dev.kai@kgfbuilds.dev. We respond within 30 days.
UK supervisory authority: Information Commissioner's Office (ICO). Malaysia: Department of Personal Data Protection (JPDP).
8. Security
TLS 1.2+ everywhere, signed JWTs for auth, Row-Level Security on every database table, encrypted secrets at rest, push notifications signed with VAPID, and integrity-checked credentials issued by the /verify endpoint.
