Privacy Policy

Who we are KH Connect Ltd (trading as KH Connect and KH AI Comms Engine) is the data controller for information collected through this website and the KHAI Comms Engine Workbook.

For any questions or requests about your data, email kate@khconnect.co.

If you sign up for our newsletter

What we collect: your email address and name.

Why we collect it: solely to send you the newsletter you signed up for. We do not sell, share, or use your email address for any other purpose without asking you separately.

Legal basis: your consent, given when you submit the signup form.

How long we keep it: until you unsubscribe or ask us to delete it.

Where it's stored: Squarespace Email Campaigns/ KH Connect Sharepoint.

If you buy the KHAI Comms Engine Workbook

What we collect:

  • Your email address, used to give you access to the workbook and to send you sign-in links

  • Payment confirmation from Stripe (amount, currency, transaction ID). We never see or store your card details

  • Your workbook answers, saved to your account so you can return on any device. This includes anything you type into the workbook: your business name, brand story answers, personas, and, if you paste it in, your brand book

We do not use behavioural tracking or advertising cookies on the workbook.

Why we collect it: to run the workbook you paid for, to keep your account signed in, and to save your progress so you don't have to start over.

Legal basis: contract (we need this data to deliver the workbook you bought) and legitimate interest (for account security and support).

How long we keep it: your workbook answers stay on your account for as long as you want them there. If you ask us to delete your account, we'll remove your answers within 30 days. Payment records we keep for six years, which is what HMRC requires.

Where it's stored: your workbook answers are stored on Supabase (EU servers in Ireland). Payment is processed by Stripe. Sign-in emails are sent by Resend. The website itself is hosted on Netlify. Each of these is a data processor acting on our instructions:

We do not sell your information, share it with advertisers, or use it for marketing beyond communicating with you about your account.

A note on sensitive information: the workbook is designed to hold information about your business, not personal or sensitive information about individuals. Please don't enter medical information, financial account details, or other sensitive information into the workbook. If you're describing customer personas, treat them as archetypes rather than named real people with identifying details.

Your rights

You can, at any time:

  • Ask what data we hold about you and get a copy

  • Correct anything that's wrong (you can edit your workbook answers directly in the tool)

  • Ask us to delete your account and your data. Payment records we're required to keep for six years, but everything else goes

  • Download your workbook outputs at any time using the Download Foundation and Download Prompt Library buttons in the workbook

  • Unsubscribe from the newsletter using the link in every email

To use any of these rights, email kate@khconnect.co.

Complaints

If you're not happy with how we've handled your data, you can complain to the Information Commissioner's Office at ico.org.uk.

Last updated: 24/08/2026

Notes on what changed

  1. Data controller updated to KH Connect Ltd. For a limited company, the company is the controller, not you personally. This is standard practice and protects you personally from claims against "Kate Prowse the individual."

  2. Newsletter section stayed the same in substance. Same voice, same rules. Just tucked under "if you sign up for our newsletter" so it's clearly one of two data flows.

  3. Workbook section written from scratch to cover: what you collect, why, legal basis (contract + legitimate interest, which are the two grounds that apply for a paid product), retention (with the six-year HMRC rule for payments), and the four processors (Supabase, Stripe, Resend, Netlify).

  4. Sensitive information note added. Protects you if a customer types something they shouldn't (e.g. a real person's medical details in a persona) and then complains later.

  5. ICO complaints route added. Legally required for UK data protection to signpost this.

  6. Your rights section combined and expanded. Covers both newsletter and workbook users, with a specific nod to the download buttons in the workbook (which are technically a "portability" right).

What to do next

  1. Copy the policy above into Squarespace, replacing the current version

  2. Update the date at the bottom to today's date

  3. Have a solicitor or someone with data-protection experience skim it. I've written it in plain English rather than legal boilerplate, which is fine and matches your voice, but I'm not a lawyer. If anything looks off to a professional, tell me and I'll adjust the wording to match

  4. Check the security note on your workbook sales page links to this policy correctly. I set the link to khconnect.co/privacy in the security section, but your actual URL is khconnect.co/privacypolicy. If you want, I can update the workbook to match, or you can add a redirect from /privacy → /privacypolicy in Squarespace, whichever is easier

Two things worth mentioning to your solicitor

If they ask why certain choices were made:

  • Legal basis for the workbook: I've used contract + legitimate interest. Contract because you're delivering a paid product. Legitimate interest because things like fraud prevention, account security, and product improvement don't fit neatly under contract. If your solicitor prefers a different basis, easy to change.

  • Data controller vs processor: you're the controller (you decide what data is collected and why). Supabase, Stripe, Resend, and Netlify are processors (they act on your instructions). This is normal and doesn't require additional signed agreements beyond their standard terms of service, which you already accepted when you set up each account. If a corporate customer ever asks for a Data Processing Agreement, both Stripe and Supabase have standard DPAs you can point them to.