Privacy Policy
This policy explains how Koryst handles personal information submitted through the website.
1. Who is responsible for your data
Koryst is responsible for personal data collected through this website. Questions about privacy can be sent through the contact page.
2. What information is collected
Koryst may collect information you choose to submit, including:
- your name;
- your email address;
- your project type, desired outcome, and timeline;
- message content, links, business context, and attachments you mention;
- technical data needed to protect forms and operate the website.
3. How the information is used
Personal information is used to:
- respond to enquiries;
- assess whether Koryst can help with a project;
- prepare a sensible next step, scope, or recommendation;
- protect the website from spam, abuse, and automated submissions;
- keep basic business records where needed.
4. Legal basis
For UK GDPR purposes, Koryst usually relies on legitimate interests to respond to business enquiries and protect the website. Where an enquiry leads to paid work, information may also be processed to take steps before entering into a contract or to perform a contract.
5. Third-party services
The website may use service providers to operate securely, including hosting, database, email, and spam-protection tools. The contact form is protected by hCaptcha. hCaptcha may process technical information to determine whether a submission is made by a human.
6. Data retention
Koryst keeps personal information only for as long as it is reasonably needed to provide the service, manage the relationship, maintain required business records, protect the portal, or resolve a complaint or dispute. Records may be kept longer where a legal, tax, accounting, insurance, contractual, security-investigation, or legal-hold requirement applies.
Current standard review points are: inactive client profiles and portal review records after 24 months; evidence files after 12 months; security and audit events after 24 months; email-delivery metadata and notification read receipts after 12 months; and expired or revoked invitations after 90 days. Encrypted operational backups are normally kept for 35 days, with one month-end copy retained for up to 12 months. At the review point, information is deleted or anonymised unless Koryst documents a continuing need to retain it.
These periods may be shortened where the information is no longer needed. A request to delete information is considered individually because some records may need to be retained for an overriding legal or contractual reason.
7. Sharing information
Koryst does not sell personal data. Information may be shared with service providers that help operate the website, process enquiries, provide hosting, send notifications, or keep systems secure.
8. International transfers
Some service providers may process data outside the UK. Where that happens, Koryst aims to use reputable providers and appropriate safeguards where required.
9. Your rights
Depending on the circumstances, you may have rights to access, correct, delete, restrict, or object to processing of your personal data. You may also complain to the UK Information Commissioner’s Office if you believe your data has not been handled properly.
10. Updates
This policy may be updated as the website, services, or legal requirements change. The latest version will be published on this page.
