Data Privacy Policy

Last updated: November 29, 2025

We take the protection of your personal data very seriously. This privacy policy explains how we collect, use, and protect your information in accordance with the General Data Protection Regulation (GDPR) and other applicable laws.


1. Responsible Party

Kukudos UG

hello@kukudos.com


2. Data Collection and Processing

2.1 Personal Data

We collect and process the following personal data:

  • Contact information (e.g., name, email, phone number, address)
  • Payment information (via Stripe)
  • Identity verification data (via Stripe)
  • SMS communication data (via Twilio)
  • Address data (via Geoapify)
  • Social Media Data - Social media service providers such as Google, GitHub, and Meta may provide us with information about you, in accordance with your privacy settings on those sites.

2.2 Purpose of Processing

We process your data for:

  • Fulfilling contracts (e.g., order processing, payment)
  • Identity verification (legal obligation)
  • Address validation and autocomplete (Geoapify)
  • SMS notifications (Twilio)
  • Customer support and communication
  • Art. 6(1)(b) GDPR: Contract fulfillment
  • Art. 6(1)(c) GDPR: Legal obligations (e.g., fraud prevention)
  • Art. 6(1)(f) GDPR: Legitimate interests (e.g., improving services)

3. Third-Party Services

3.1 Stripe (Payment & ID Verification)

  • Data processed: Payment details, name, address, ID documents (if required)
  • Purpose: Secure payment processing and identity verification
  • Privacy Policy: Stripe Privacy Policy
  • Data Transfer: Stripe may process data outside the EU under Standard Contractual Clauses (SCC).

3.2 Geoapify (Address Autocomplete/Validation)

  • Data processed: Address input
  • Purpose: Accurate address validation
  • Privacy Policy: Geoapify Privacy Policy
  • Data Transfer: Geoapify complies with GDPR; data is processed within the EU or under SCC.

3.3 Twilio (SMS Service)

  • Data processed: Phone number, message content
  • Purpose: Order confirmations, notifications
  • Privacy Policy: Twilio Privacy Policy
  • Data Transfer: Twilio complies with GDPR; data may be processed under SCC.

4. Data Sharing

We only share data with third parties when:

  • Required by law (e.g., tax authorities)
  • Necessary for service fulfillment (e.g., Stripe, Twilio, Geoapify)
  • You have given explicit consent

5. Data Retention

  • Payment/ID data: Retained as required by law (e.g., 10 years for tax records)
  • SMS logs: Deleted after 30 days unless required for dispute resolution
  • Address data: Deleted after order fulfillment unless you opt into marketing

6. Your Rights

Under GDPR, you have the right to:

  • Access your data
  • Rectify inaccurate data
  • Erase data (where legally possible)
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent (for marketing)

To exercise these rights, contact: hello@kukudos.com


7. Security

We implement technical and organizational measures to protect your data, including:

  • Encryption (TLS)
  • Access controls
  • Regular security audits

8. Cookies & Tracking

We use cookies for:

  • Session management

9. Changes to This Policy

We may update this policy. The latest version will always be available here.