Legal
Privacy policy.
Everything we know about you, why we have it, how long we keep it and how to make us delete it. We are a very small operation and we collect very little — this page is long because it is complete, not because there is a lot going on.
Who is responsible
The data controller for everything described here — the people who decide what is collected and why — is:
Email us at josephdyoder@gmail.com about anything on this page. There is no separate data protection officer; we are small enough that the same person reads everything.
What we collect
When you send us a message
The contact form collects your name, your email address, the subject, the colour you are interested in, and whatever you write in the message. We also record the IP address the message came from, and the time it arrived.
When you order a clock
Ordering happens over email. To build and post a clock we need a delivery address and a name, and to be paid we need whatever record the payment method produces. We do not see or store your card number: no payment is taken through this website.
If you have an account
Accounts exist for the people who work on Klever Klox. They hold a username, an email address, a password (stored only as a salted hash — we cannot read it), a role, the date you joined, whether your email is verified, and the work records the developer portal is for: hours logged, shares, transactions and an audit trail of actions taken.
Just by visiting
The server writes an access log entry for each request: IP address, time, the page asked for, the response code, the referring page and the browser's user-agent string. Two cookies may be set — see the cookie policy for exactly what they are and how long they last.
Your IP address is also looked up against a country database to decide whether to show prices in euro or dollars. That lookup happens on our own server against a file stored there. Nothing about you is sent anywhere to do it, and the result — a two-letter country code — is not stored.
When something breaks
If a page fails, we record what failed, the path it happened on and the technical detail needed to fix it. Alert emails about a serious failure may include the IP address of the request that triggered it. This is how the site gets repaired; it is not used to build a picture of you.
Fonts, and the one third party on this site
Our pages load two typefaces from Google Fonts. Because your browser fetches those files directly from Google's servers, Google receives your IP address and the fact that a Klever Klox page was loaded. We do not send them anything else, and we get nothing back — but we would rather tell you than have you find out from a network tab.
There is nothing else. No analytics, no tag manager, no advertising pixel, no social media buttons, no embedded video, no chat widget, no A/B testing, no session recording.
Why, and on what legal basis
| What | Why | Lawful basis |
|---|---|---|
| Contact form | To answer you, and to take an order | Steps at your request before a contract |
| Name, address, order detail | To build, post and support your clock | Performance of our contract with you |
| Sales and payment records | Because tax law says we must keep them | Legal obligation |
| Account and portal data | To run the developer portal you signed up for | Contract, and our legitimate interest in running the business |
| IP on the contact form | To spot and block repeated abuse of the form | Legitimate interest in not being flooded with spam |
| Access and error logs | To keep the site up, secure and working | Legitimate interest in a site that works |
| Essential cookies | To keep you signed in and to stop forged form posts | Strictly necessary for a service you asked for |
Where we rely on a legitimate interest, we have weighed it against your privacy and kept the data to the minimum that does the job. You can object — see your rights.
What we do not do
- We do not sell, rent or trade your data. Not to anyone, not ever.
- We do not run advertising, and we do not let anyone else advertise to you off the back of your visit.
- We do not track you across other websites, and we set no cookie for that purpose.
- We do not send marketing email. If you get an email from us it is because you wrote to us, ordered something, or have an account.
- We do not build profiles of visitors or try to identify anonymous ones.
- We do not collect special category data — health, beliefs, biometrics — and please do not send us any.
Sending data outside the EEA
We are based in Ireland and keep the site's data in the EEA where we can. Some of the providers above — an email provider or a font service, for instance — may process data outside it. Where that happens, the transfer relies on an adequacy decision by the European Commission or on Standard Contractual Clauses, which are the mechanisms the GDPR provides for exactly this.
Ask us and we will tell you which providers we currently use and where they are.
How long we keep it
| What | How long |
|---|---|
| Contact messages | 24 months from the last message in the thread |
| Account and portal data | for as long as the account exists, then deleted on request |
| Order and payment records | 6 years, because tax law requires it |
| Server access logs | 90 days |
| Error records | 90 days |
When a period ends the data is deleted. The one thing we cannot delete on request is a record we are legally obliged to keep — a sales invoice, for example — but we will delete everything around it.
Your rights
Under the GDPR you can ask us to:
- Show you what we hold about you, and give you a copy.
- Correct anything that is wrong or incomplete.
- Delete it, where we have no overriding reason or legal duty to keep it.
- Restrict what we do with it while a dispute about it is sorted out.
- Hand it over in a portable, machine-readable form, or send it to someone else.
- Stop processing based on legitimate interests, by objecting.
- Withdraw consent at any time, where we relied on consent — which does not undo what was done before you withdrew it.
Email josephdyoder@gmail.com. We will reply within one month, free of charge. We may ask you to confirm who you are first — not to be difficult, but because handing your data to somebody claiming to be you would be a worse failure than a slow reply.
If you have an account you can see and change most of it yourself on your profile page, and you can delete the account from there.
How we protect it
- The whole site is served over HTTPS, with HSTS on, so traffic cannot be read in transit.
- Passwords are stored as salted hashes using Django's password hashing. Nobody here can read them.
- A Content Security Policy blocks injected scripts; forms are protected against cross-site posting.
- Login attempts and contact-form submissions are rate limited.
- The database is on the server, not in anybody's inbox or spreadsheet, and access to it is limited to the people who run the site.
- Backups are taken nightly and kept on the same terms as the data itself.
No system is perfectly secure. If we ever suffer a breach that puts your rights at risk, we will tell the Data Protection Commission within 72 hours and tell you without undue delay.
Children
This site is not aimed at children, and accounts require you to be at least 16. We do not knowingly collect data from children. If you believe a child has sent us personal data, tell us and we will delete it.
Automated decisions
We do not make decisions about you by automated means, and we do not profile you. The one automatic thing that happens — showing euro or dollar prices based on your IP address — decides which currency symbol you see and nothing else, and you can ask us to quote in either.
Changes to this policy
When this policy changes we update the date at the top of the page. If a change is significant — new data collected, a new recipient, a new purpose — we will say so prominently rather than hope you re-read it.
Contacting us, and complaining
Anything at all about your data: josephdyoder@gmail.com.
If we get it wrong, you can complain to the supervisory authority. In Ireland that is the Data Protection Commission, 6 Pembroke Row, Dublin 2 (dataprotection.ie). If you live elsewhere in the EU you can complain to your own national authority instead. We would rather you told us first, but it is your right either way.