PRIVACY POLICY Effective Date: May 29, 2026
1. Introduction, Constitutional Alignment, and Scope Welcome to Klurdy Studios Ltd (“Company”, “we”, “our”, or “us”). This unified Privacy Policy sets out the framework under which we collect, store, safeguard, process, and transfer personal data. This policy is explicitly designed to fulfill our statutory obligations under Article 31(c) and (d) of the Constitution of Kenya (the Right to Privacy), the Kenya Data Protection Act, 2019 (DPA), and its subsidiary General Regulations. To support our global transaction processing infrastructure via Stripe, this policy also covers data interactions managed by our wholly owned merchant clearing subsidiary incorporated in the United Kingdom. This policy universally governs all data processing activities across all digital properties owned, operated, or monitored by Klurdy Studios Ltd, including but not limited to: ● klurdy.com and klurdy.studio (Corporate Ecosystems) ● pulsehog.com (Media Monitoring & Reputation Management) ● safii.cloud (Cybersecurity Remediation & Hardening SaaS) ● ekarer.com (Real Estate Services)
2. Joint Data Controllers & Contact Information For the purposes of the Kenya DPA, the primary Data Controller is: ● Klurdy Studios Ltd, a private limited company whose address is P.O. Box 11925 00100, Kenya. For the purposes of clearing global transaction processing and managing Stripe merchant billing accounts on behalf of the parent studio, our UK subsidiary operates as a Joint Data Controller. All data protection inquiries, statutory rights requests, or compliance communications must be funneled to our centralized legal desk: Email: legal@klurdy.com
3. Centralized Authentication & Special Disclosures for Identity Provider Scopes (Google & Apple Sign-In)
To ensure maximum enterprise-grade security, credential isolation, and seamless data access across our ecosystem, Klurdy Studios Ltd utilizes a dedicated, centralized single-sign-on (SSO) identity management infrastructure hosted at id.klurdy.com. When you create an account, log in, or manage your active sessions on klurdy.com, klurdy.studio, pulsehog.com, safii.cloud, or ekarer.com, your authorization request is securely managed by our centralized authentication desk at id.klurdy.com. This central system handles all third-party integrations, security tokens, and identity protocols. A. Google API Services & User Data Disclosure ● Data Accessed and Processed: When you choose to authenticate via Google Sign-In, our system requests access exclusively to your Google identity metadata, specifically your primary email address, verified full name, and profile picture URL. We do not request, access, read, or store granular profile items, contact indexes, or personal cloud storage files. ● The Authentication Loop: All processing of Google credentials, session states, and verification tokens is executed via id.klurdy.com before authorizing your access to our respective sub-brand software dashboards. ● Google Limited Use Policy Compliance: Our use and transfer of information received from Google APIs to any other app will strictly adhere to the Google API Services User Data Policy, including its Limited Use requirements. We explicitly do not sell, rent, trade, or transfer your Google user data to external advertising networks, data brokers, or third-party marketing firms. B. Sign in with Apple API Disclosure ● Data Accessed and Processed: When you choose to use Sign in with Apple, we receive unique token identifiers generated by Apple Inc., specifically a stable user identifier, your first and last name (as configured in your Apple ID), and your primary email address. ● Support for Apple Email Masking: We fully support Apple’s "Hide My Email" proxy tool. If you select this option during authentication, we only receive and store an anonymous, randomized relay email address (e.g., user@privaterelay.appleid.com). ● Data Protection Commitment: Information received via Sign in with Apple is used strictly to provision your secure account environment, manage active application sessions, and process subscription privileges. Apple authentication data is never used for third-party tracking, profiling, or cross-app behavioral advertising.
4. Types of Data Collected & Lawful Bases for Processing We process personal data only when an explicit lawful basis under Section 30 of the Kenya DPA applies. We collect the following data across our multi-tenant platforms:
Data Category
Specific Elements Collected
Primary Lawful Basis (Kenya DPA)
Platform Context
Identity & Account Data
Centralized single-sign-on (SSO) identity metadata via id.klurdy.com. Captures verified names, primary emails, and profile picture paths from Google & Apple OAuth. Full integration with Apple's "Hide My Email" routing.
Section 30(1)(a) & (b): Explicit Consent & Performance of a Contract.
User authentication, secure access isolation, and cross-domain dashboard session continuity across all platforms (pulsehog.com,
Media Intelligence & Brand Sentiment
Corporate and personal brand keywords, tracked executive profiles, indexed public media texts, social conversations, and raw sentiment scores.
Section 30(1)(b) & (f): Performance of a Contract & Legitimate Interests of the Controller.
Ingestion, NLP parsing, automated alert dispatch, and historical reputation reporting inside pulsehog.com
Real Estate Assets & Spatial Visualizations
Property geographic coordinates, physical addresses, listing descriptions, pricing structures, structural media (photos/videos), and real estate agent/landlord profile details.
Section 30(1)(b): Performance of a Contract (Fulfilment of listing agreements).
Property database indexing, real-time matching, conversational chatbot ingestion, and the generation of proprietary 3D Gaussian Splatting (3DGS) spatial models on ekarer.com.
User Search Intent & Match Queues
User-configured search bounds, target budgets, geographic location preferences, and contact channel selections.
Section 30(1)(a): Explicit, voluntary Opt-In Consent.
Powering real-time automated match queues and dispatching "Notify Me" notifications when targeted properties are identified on ekarer.com.
safii.cloud, ekarer.com, klurdy.studio).
Cybersecurity Infrastructure Logs
Specialized application layer logs, server configuration file paths, error dumps, core database schemas, raw file directories, and isolated malicious code strings.
Section 30(1)(b) & (c): Performance of a Contract & Legal Obligation (Safeguarding digital infrastructure against cyber threats).
Scanning infrastructure directories, tracking system anomalies, uncovering web spam, and deploying automated malware remediation workflows on safii.cloud.
Financial & Clearing Operations
Transaction histories, subscription logs, obscured payment tokens, and joint processing records split between your Kenyan parent firm and your UK payment subsidiary.
Section 30(1)(b) & (c): Performance of a Contract & Compliance with financial reporting regulations. .
Facilitating automated monthly/annual subscription clearing via Stripe through your UK entity on behalf of the Kenyan parent studio.
5. Algorithmic Processing, Embedded AI Agents, and Machine Learning Training Disclosures To deliver automated media intelligence, advanced cybersecurity protection, predictive property matching, and immersive spatial renderings, Klurdy Studios Ltd deploys specialized, domain-isolated Artificial Intelligence (AI) and Machine Learning (ML) engineering workflows across our ecosystem. A. Core AI Agent Functional Domains We embed autonomous AI agents within our software instances to handle specialized computing workloads: ● Information Retrieval & Media Analytics (pulsehog.com): Natural Language Processing (NLP) models parse public media streams against your configured corporate and competitor keywords to structure conversational analytics and track sentiment trends. ● Autonomous Crisis Resolution (pulsehog.com): When critical reputational anomalies are flagged, embedded agents evaluate the context of the threat vector and dynamically draft mitigation paths or automated alert escalations based on standard playbooks. ● Conversational Property Selection (ekarer.com): Natural language virtual assistants process unstructured user searches, preferences, and conversational intents to safely query our property index and surface contextual real estate recommendations. ● Automated 3D Spatial Visualization (ekarer.com): Computer vision frameworks ingest standard multi-angle photographs and video walkthroughs uploaded by listing
agents to synthetically construct interactive, three-dimensional spatial environments using 3D Gaussian Splatting (3DGS) techniques. ● Security Threat Analyzers (safii.cloud): Autonomous cybersecurity agents continuously scan system files, code repositories, and operational server logs on client infrastructure to isolate web spam, track indicators of compromise (IoCs), and execute automated malware remediation scripts. B. Utilization of Enterprise Foundational Models (Azure OpenAI & AWS Bedrock) For high-tier semantic reasoning, information retrieval, and conversational orchestration, our infrastructure hooks into top-tier foundational models via secure Application Programming Interfaces (APIs). Specifically, we route text and telemetry inputs through Azure OpenAI Services and Amazon Web Services (AWS) Bedrock. ● Enterprise Isolation Safeguards: All data routed through Azure OpenAI and AWS Bedrock is handled within containerized, private enterprise cloud environments. Your operational inputs, database keywords, property lists, and server logs are encrypted in transit and at rest. ● No Public Model Training: In accordance with our enterprise vendor agreements, neither Microsoft, Amazon, nor any open-source model provider can access, retain, or utilize your personal or business data to train their public, foundational, or consumer-facing model suites. C. Internal Machine Learning Optimization and Proprietary Model Training Klurdy Studios Ltd processes platform metadata, aggregated system telemetry, structural code logs, and anonymized user search constraints to build, train, fine-tune, and optimize our own internal, proprietary machine learning models, custom neural networks, and specialized automated agents. ● Lawful Basis & Scope: Where we utilize platform metrics to train our proprietary models, processing is executed under the lawful basis of our Legitimate Interests to optimize platform security, improve search accuracy, and advance our 3D visualization algorithms. ● Data Minimization & Anonymization: Prior to pulling any data into our internal model training pipelines, the information undergoes strict data minimization processing. All direct personal identifiers (such as names, personal email addresses, phone numbers, and explicit account IDs) are scrubbed, masked, or completely anonymized. ● Strict Privacy Isolation: We explicitly guarantee that your proprietary brand secrets, core server configurations, custom security logs, and unpublicized corporate operational files are never mixed across client instances or used to train models that are exposed to other tenants. Your data remains containerized and isolated within your specific enterprise boundary.
6. Detailed Cookie and Tracker Infrastructure
Our digital properties deploy structural and analytical cookies to maintain network security, verify sessions, and track performance indicators. In compliance with Kenyan data principles, cookies are strictly classified into clear functional buckets: ● Strictly Necessary Cookies: Required for system stability, user authentication persistence, load balancing, and firewall monitoring via Cloudflare Analytics. These do not require opt-in consent as the platform cannot securely function without them. ● Performance & Telemetry Trackers: We utilize Google Analytics and Bugsnag to log application crashes, track user workflows, and isolate software bugs in real time. These trackers are deactivated by default and will only execute after you provide affirmative, explicit consent via our cookie notification banner. You can adjust your tracking preferences at any time within your application dashboard.
7. Commercial Use & Direct Marketing Data (Section 37 Compliance) In strict compliance with Section 37 of the Kenya DPA, Klurdy Studios Ltd enforces an explicit opt-in regime for all direct marketing, newsletters, or promotional campaigns. ● We will never treat account registration as an blanket license to send you marketing materials. ● Commercial newsletters require an independent, unbundled check-box affirmation. ● You maintain an absolute, unconditional right to object to commercial processing and withdraw your consent instantly by selecting the "Unsubscribe" mechanism in any message or by contacting legal@klurdy.com.
8. Cross-Border Data Transfers (Section 48 Compliance) To maintain an interconnected, secure cloud ecosystem, personal data collected within Kenya may be transferred to and processed on infrastructure hosted outside of Kenya (including servers operated by cloud utility providers in the United States and the European Union). Furthermore, account-related billing details are transferred securely to our United Kingdom infrastructure to enable automated payment cycles via Stripe. We ensure that all cross-border data routing strictly complies with Section 48 of the Kenya DPA by: 1. Implementing standard data protection contractual clauses with our international technology infrastructure sub-processors (e.g., AWS, Azure, Bugsnag, Stripe). 2. Verifying that the target destination possesses a binding adequacy decision or robust institutional security safeguards. 3. Carrying out a Data Protection Impact Assessment (DPIA) where cross-border workflows pose elevated risks to data privacy.
9. The 72-Hour Security Breach Protocol While we use enterprise-grade technical and organizational protocols to shield data from unauthorized interception, we maintain an active, auditable Incident Response Plan. In accordance with Sections 43 of the Kenya DPA:
● To the Regulator: In the event of a confirmed or suspected personal data breach that poses a real risk of harm to our users, the Company will formally notify the Office of the Data Protection Commissioner (ODPC) Kenya within 72 hours of breach realization. ● To the Affected Users: Where the security breach is likely to result in high risks to your personal rights and freedoms, we will notify you directly via your verified email address without undue delay, outlining clear mitigation steps. ● Processor Obligations: All third-party infrastructure processors utilized by Klurdy Studios Ltd are contractually bound to notify our legal desk within 48 hours of identifying any data anomaly.
10. Statutory Data Subject Rights under the Kenya DPA As a data subject interacting with our infrastructure, you hold the following explicit, non-negotiable legal rights under the Kenya Data Protection Act, 2019: ● Right to be Informed: To receive clear, transparent details on how your data is collected and utilized. ● Right of Access: To request a structured, clear copy of all personal information we hold regarding your profile. ● Right of Rectification: To compel the correction of inaccurate, incomplete, or outdated records. ● Right of Erasure (Right to be Forgotten): To demand the complete deletion of your data where it is no longer legally required to maintain processing. ● Right to Restriction / Object: To limit automated processing or object to the commercial utilization of your structural metadata. To execute any of these statutory rights, please send a written directive to legal@klurdy.com. In line with local regulatory rules, we may ask you to verify your identity before processing the request to ensure no unauthorized data disclosure occurs.
11. Data Retention Framework We store your personal data only for the minimum timeframe strictly necessary to satisfy the specific purposes detailed in Section 4 of this policy, or as mandated by prevailing commercial, accounting, or regulatory laws in Kenya. ● Active Profiles: Data linked to active accounts is preserved throughout your subscription duration. ● Post-Termination Deletion: Upon account cancellation or contract termination across pulsehog.com, safii.cloud, or ekarer.com, all linked user profiles and uploaded backup files are completely purged or permanently anonymized within thirty (30) days, subject to any outstanding legal holds or compliance obligations.
12. Regulatory Compliance and Enforcement Right Klurdy Studios Ltd operates in full alignment with the Office of the Data Protection Commissioner (ODPC) of Kenya. If you believe that our internal legal desk has failed to
satisfactorily resolve a data privacy grievance, you maintain an absolute statutory right to file an official complaint with the local regulator: ● Regulatory Body: Office of the Data Protection Commissioner (ODPC) Kenya ● Official Web Portal: www.odpc.go.ke