LEGAL
Last updated: 23 August 2026
This Privacy Policy explains how Private Agency, trading as Kairo Agency (“Kairo”, “we”, “us” or “our”), collects, uses, shares and protects personal data.
Kairo provides Google Ads, advertising strategy, campaign implementation, tracking, analysis and related digital marketing services, primarily for health and wellness ecommerce businesses.
For questions about this Privacy Policy or how we use personal data, contact:
Email: contact@kairo.agency
Website: https://kairo.agency
This policy applies to personal data relating to:
visitors to our website;
people who complete our qualification, audit or contact forms;
people who book, reschedule or attend calls with us;
prospective and existing clients and their representatives;
suppliers, contractors and business partners; and
individuals whose data we may process when providing services to a client.
Third-party websites and services have their own privacy policies. This policy does not control how those third parties use personal data for their own purposes.
When Kairo is the controller
Kairo is normally the controller of personal data collected directly through our website, qualification forms, booking process, email, telephone or other direct communications.
This means we decide why and how that personal data is used.
When Kairo acts for a client
When providing advertising, analytics, conversion tracking or related services, Kairo may access personal data contained in a client’s advertising accounts, analytics systems, ecommerce platform, CRM or other business systems.
In those circumstances, the client will normally be the controller and Kairo will act as a processor under the client’s documented instructions.
Where required, this processing will be governed by a separate Data Processing Agreement or equivalent provisions in the applicable Client Services Agreement.
If your personal data was collected by one of our clients, you should normally direct your privacy request to that client. We will assist the client where required.
Depending on how you interact with us, we may collect:
Identity and contact information
name;
business or brand name;
job title;
email address;
telephone number and country or dialling code;
business address, where relevant; and
communication preferences.
Qualification and enquiry information
website address;
business type and industry;
whether the business operates in health, wellness or ecommerce;
approximate revenue range;
advertising-spend range;
current advertising activity;
marketing objectives and challenges;
answers submitted through qualification or audit forms; and
information included in emails, calls or other communications.
Booking and communication information
requested appointment date and time;
timezone;
booking, rescheduling and cancellation information;
calendar-event information;
email and SMS delivery status;
reminders and responses; and
notes or correspondence concerning an appointment.
Client and service information
Where you become a client, we may collect:
proposal and contract information;
billing and transaction records;
authorised account users;
account access and permission information;
campaign objectives, budgets and performance data;
advertising, analytics and ecommerce account identifiers;
conversion and attribution information; and
information needed to provide, secure and support the services.
Technical and usage information
IP address;
browser and device information;
operating system;
approximate location;
referral source;
pages viewed;
session activity;
interactions with forms and buttons;
cookie identifiers;
conversion events; and
advertising or analytics identifiers.
Client customer and campaign data
When acting for a client, we may access or process:
online and device identifiers;
advertising audiences;
conversion events;
transaction or purchase events;
campaign-attribution information;
pseudonymous customer identifiers;
customer lists provided for permitted advertising features; and
data held in advertising, analytics, CRM or ecommerce systems.
We ask clients to provide only the data that is reasonably necessary for the services.
Although Kairo specialises in health and wellness ecommerce, our website qualification process is not designed to collect information about an individual’s health or medical conditions.
Some client customer data, such as purchasing or browsing information relating to certain health products, could potentially reveal or allow inferences about an individual’s health.
Clients must not provide Kairo with health data, medical information or other special-category personal data unless:
it is genuinely necessary for the agreed services;
an appropriate lawful basis and additional legal condition have been established;
affected individuals have received appropriate privacy information;
any required consent has been obtained; and
the processing has been expressly agreed in writing and covered by appropriate data-protection terms.
We may obtain personal data:
directly from you;
through our website and forms;
through our booking system;
during calls, emails or meetings;
from a colleague or organisation you represent;
from a client for whom we provide services;
from advertising, analytics, ecommerce and CRM platforms;
from publicly available business sources; and
automatically through cookies, pixels, tags and similar technologies, where permitted.
Where we receive data from a client, the client is responsible for ensuring that it has the necessary rights and lawful basis to provide that data and instruct us to process it.
We may use personal data for the following purposes.
Responding to enquiries and assessing suitability
We use enquiry and qualification information to:
respond to requests;
assess whether our services may be suitable;
prepare for an audit or strategy call;
personalise our response; and
take steps towards a possible business relationship.
Our lawful bases are taking steps before entering into a contract and our legitimate interests in assessing and responding to genuine business enquiries.
Booking calls and sending reminders
We use booking and contact information to:
schedule, reschedule or cancel calls;
create calendar events;
send confirmation messages;
send email or SMS reminders; and
communicate about the appointment.
Our lawful bases are taking steps before entering into a contract, performing a contract where applicable, and our legitimate interests in managing appointments and reducing missed calls.
Providing services
We use client, account and campaign information to:
conduct audits;
install and manage advertising systems;
create and optimise campaigns;
configure measurement and conversion tracking;
analyse performance;
provide reports and recommendations;
communicate with clients; and
administer the business relationship.
Our lawful basis is the performance of a contract. Where we process personal data on a client’s behalf, we do so under the client’s documented instructions.
Operating and protecting our business
We may process data to:
maintain and secure our website and systems;
detect misuse, fraud or security incidents;
troubleshoot technical issues;
manage suppliers and professional advisers;
keep business and accounting records;
establish or defend legal claims; and
comply with legal or regulatory requirements.
Our lawful bases are our legitimate interests in operating and protecting the business and compliance with legal obligations.
Analytics, advertising and improvement
Subject to the required consent, we may use technical and usage information to:
understand how visitors use the website;
measure form and booking conversions;
improve pages, content and user experience;
measure advertising effectiveness;
create or use remarketing audiences; and
display or measure relevant advertising.
Our lawful bases are consent where required for cookies or similar technologies and, after that consent, our legitimate interests in measuring and improving our marketing.
Marketing communications
We may use contact information to send relevant business-to-business information about our services where:
you have requested it;
you have provided consent where required; or
applicable law permits us to rely on legitimate interests.
Every electronic marketing message will provide an appropriate method of opting out. Service-related and appointment-related communications are not marketing messages.
Our forms and connected systems may use answers such as business type, revenue range, advertising activity or ad spend to route, prioritise or categorise an enquiry.
This helps us determine which next step or booking option may be appropriate.
This routing does not itself produce a legal or similarly significant effect. Where appropriate, you may ask us to review a decision or qualification outcome manually by contacting contact@kairo.agency.
Our website may use cookies, pixels, conversion tags and similar technologies for:
essential site functionality and security;
remembering preferences;
analytics;
conversion measurement;
attribution;
advertising; and
remarketing.
Strictly necessary technologies may operate without consent where legally permitted.
Analytics, advertising, conversion-tracking and remarketing technologies will only be used where the necessary consent or other legal permission has been obtained. Visitors must be able to reject non-essential technologies as easily as they can accept them.
Further information about the technologies currently used, their providers, purposes and durations should be provided through our cookie controls or a separate Cookie Notice.
We may share personal data with service providers where reasonably necessary, including:
Framer, for website hosting and delivery;
GoHighLevel or LeadConnector, for CRM, forms, communications and workflow management;
Cal.com, for appointment scheduling and booking management;
Zapier, for connecting systems and automating authorised workflows;
Google, including Google Ads, Google Analytics, Google Tag Manager and related advertising or measurement services;
email, telephone and SMS providers;
cloud-storage, security and IT providers;
accounting, billing or payment providers;
professional advisers such as accountants, insurers and legal advisers;
contractors or subprocessors helping us provide services; and
public authorities, courts or regulators where disclosure is legally required.
Providers may process data under their own privacy terms when acting as independent controllers. When they process data solely for Kairo, we require them to use it only for authorised purposes and protect it appropriately.
We do not sell personal data.
If Kairo or Private Agency is involved in a sale, merger, restructuring, investment, acquisition or transfer of all or part of its business or assets, relevant personal data may be disclosed to advisers, prospective parties and the resulting organisation.
Any such disclosure will be limited to what is reasonably necessary and subject to appropriate confidentiality and data-protection safeguards.
Some of our service providers may process personal data outside the United Kingdom.
Where personal data is transferred internationally, we will use an appropriate legal mechanism where required, such as:
UK adequacy regulations;
the UK International Data Transfer Agreement;
the UK Addendum to approved standard contractual clauses; or
another legally recognised safeguard.
You may contact us for information about the safeguards relevant to a particular transfer.
We use reasonable technical and organisational measures designed to protect personal data from accidental loss, misuse, alteration, unauthorised access or disclosure.
These measures may include access controls, secure authentication, restricted permissions, provider security reviews, confidentiality obligations and appropriate account-management procedures.
No internet or storage system can be guaranteed completely secure.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected.
When deciding how long to retain information, we consider:
the nature, amount and sensitivity of the data;
the purpose for which it is used;
whether the purpose can be achieved another way;
the status and duration of our relationship;
whether an enquiry remains active;
contractual, accounting and legal requirements;
potential disputes or legal claims;
client instructions where we act as processor; and
the risk of harm from unauthorised use or disclosure.
When personal data is no longer required, we will delete it, anonymise it or securely isolate it, subject to applicable legal and technical limitations.
Depending on the circumstances, you may have the right to:
request access to your personal data;
ask us to correct inaccurate or incomplete data;
request deletion of your data;
request restriction of processing;
object to processing based on legitimate interests;
object to direct marketing at any time;
request transfer of eligible data;
withdraw consent at any time where processing relies on consent; and
ask for human review of an applicable automated decision.
These rights are not absolute and may depend on the lawful basis and circumstances of the processing.
To exercise a right, contact contact@kairo.agency. We may need to verify your identity before completing a request.
Please contact us first if you have concerns so that we can try to resolve them.
You also have the right to complain to the Information Commissioner’s Office:
Website: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113
Our website and services are intended for business owners and business representatives. They are not directed at children, and we do not knowingly collect personal data from children through our qualification process.
We may update this Privacy Policy to reflect changes in our services, systems, providers or legal obligations.
The latest version will be published on our website with an updated revision date. Where a change materially affects how we use personal data, we will take reasonable steps to provide additional notice where required.
For privacy questions, rights requests or complaints, contact:
Private Agency, trading as Kairo Agency
Email: contact@kairo.agency
Website: https://kairo.agency
