Privacy Policy
Protecting people's privacy is our entire business, so we hold ourselves to the standard we sell. This policy explains what personal data Ken collects, why, how we protect it, and the rights you have over it. We keep it in plain language on purpose.
On this page
1. Who we are
Ken (“Ken”, “we”, “us”, “our”) is a personal digital-protection service operated by Britannia Ventures Pte Ltd (Singapore), reachable at hello@kenprivacy.com. For the purposes of Singapore's Personal Data Protection Act 2012 (PDPA) — and, where we serve clients in the UK or EU, the UK GDPR and EU GDPR — Ken is the data controller of the personal data described here.
This policy covers kenprivacy.com and the services we provide through it.
2. Data we collect
Information you give us
- Contact and account details: your name, email address, phone number, and country or city, provided when you enquire, book a call, or engage us.
- Engagement information: the answers you give in our intake and consent form, including what you want protection from and the scope you authorise.
- Billing details: the information needed to take payment. Card details are handled by our payment provider and are not stored by us.
- Correspondence: the content of messages you send us.
Information we gather to deliver your service
- Findings from public sources: when you authorise an audit, we search publicly available sources about you (or a subject you have a lawful right to check) and record what we find — for example exposed contact details, data-broker listings, breach appearances, and old accounts — so we can report and act on it.
- Removal and monitoring records: the requests we submit on your behalf and the alerts we generate while monitoring your exposure.
Information collected automatically
- Basic website data: limited, privacy-respecting information such as pages viewed and general device type, to keep the site working and secure. We do not use advertising or cross-site tracking cookies.
3. How we use your data
We use your personal data only to provide and improve the service you asked for:
- to assess your public exposure and prepare your report;
- to remove your data from third-party sites and monitor for new exposure on your behalf;
- to communicate with you, answer questions, and provide support;
- to take payment and keep required financial records;
- to keep our service secure and meet our legal obligations.
We never sell your personal data, and we never use it for advertising.
4. Our legal basis for processing
We rely on: your consent (which you give at intake and can withdraw at any time); the performance of our contract with you; our legitimate interests in running and securing the service in a way that does not override your rights; and compliance with legal obligations such as tax and accounting rules. Where we rely on consent, you can withdraw it at any time by emailing us, and we will stop the relevant processing.
5. Only public, lawful sources
Ken uses only publicly available, legally accessible information. We do not hack, access private accounts, bypass security measures, or buy stolen or breached data sets to enrich a profile. We act to protect you — we do not investigate, surveil, locate, or monitor any third party without a lawful reason and, where required, that person's consent. We will decline or end any request that falls outside this principle.
6. Who we share your data with
We share personal data only as needed to deliver the service, and only with providers bound to process it on our instructions and to protect it:
- Data-broker and people-search sites — to submit opt-out and removal requests on your behalf (this necessarily involves sending them the identifiers required to remove you).
- Operational tools — such as our email and productivity suite, secure file storage, scheduling, breach-monitoring, and customer-support tools.
- Payment provider — to process payments securely.
- Professional advisers and authorities — where we are legally required to disclose, or to establish or defend legal claims.
We do not disclose your data to anyone else without your consent.
7. International transfers
Because we operate online and use reputable global providers, your data may be processed in countries outside your own. Where it is, we take steps to ensure it remains protected to a standard consistent with the PDPA and, where applicable, the GDPR — for example by using providers that offer appropriate safeguards and contractual protections.
8. How we protect your data
Security is core to what we do. We:
- collect the minimum data necessary and delete what we no longer need;
- encrypt data in transit and at rest where our tools support it;
- restrict access on a need-to-know basis and protect accounts with strong authentication, including two-factor authentication;
- never sell or rent your data, and never expose it in marketing.
No system can be guaranteed perfectly secure, but we take reasonable and appropriate measures to safeguard your information, and we will notify you and any relevant authority of a data breach where the law requires.
9. How long we keep your data
- Enquiries that don't become engagements: deleted within 12 months.
- Audit reports and findings: kept for the duration of your engagement and up to 12 months afterwards, unless you ask us to delete them sooner.
- Monitoring data: kept while your subscription is active and deleted within 30 days of cancellation.
- Billing and tax records: kept for as long as the law requires (in Singapore, generally up to five years).
When a retention period ends, we securely delete or anonymise the data.
10. Your rights
Depending on where you live, you have rights over your personal data. We honour these for all our clients:
- Access — get a copy of the personal data we hold about you.
- Correction — have inaccurate or incomplete data fixed.
- Deletion — ask us to erase your data where we are not legally required to keep it.
- Withdraw consent — at any time, without affecting processing already carried out.
- Restrict or object — to certain processing.
- Portability — receive your data in a portable format, where applicable.
To exercise any right, email hello@kenprivacy.com. We will respond within the time the law allows. If you believe we have mishandled your data, you may also complain to your data-protection regulator — in Singapore, the Personal Data Protection Commission (PDPC); in the UK or EU, your local supervisory authority.
11. Cookies & analytics
We use only the cookies needed to make the site work and keep it secure, plus limited, privacy-respecting analytics to understand how the site is used. We do not use advertising cookies or sell analytics data. You can control cookies through your browser settings.
12. Children
Our services are intended for adults. We do not knowingly collect personal data from children under 18 without the consent of a parent or guardian. Where we help protect a family's or child's online safety, we do so at the request and under the authority of the responsible adult. If you believe a child has given us data without appropriate consent, contact us and we will delete it.
13. Changes to this policy & how to contact us
We may update this policy as our service or the law evolves. We will change the effective date above and, for material changes, let clients know directly. The current version always lives at this page.
Questions, requests, or concerns? Email hello@kenprivacy.com — a real person will reply.