1. Who Kikit is
Kikit is an independent online-casino review publication operating at the domain kikit.io. For the purposes of the UK GDPR and the EU GDPR, we are the data controller for the personal data described on this page. We run no casinos, we hold no player accounts, and no deposit, wager or withdrawal ever passes through anything we operate. Kikit is part of the H88 network of iGaming publishers, but each publication holds its own reader data separately.
2. Personal data we collect
What we collect stops at what we need to keep the site working and to reply to readers who write to us. In practical terms:
- The only personal data we hold is what you actively send us via the contact form or by email. If you never write in, we simply do not know who you are.
- Aggregated, anonymised analytics tell us which pages are being read and, roughly, which country a visitor is browsing from, without ever identifying an individual.
- Short-lived server logs record IP addresses for security purposes.
- A small set of cookies stores your consent choice and one or two display preferences.
We do not collect payment details, we never request identity documents, we build no advertising profiles of individual readers, and we never sell, rent or trade personal data with anyone. For CCPA purposes, "sale" and "share" of personal information do not happen on Kikit.
3. What we keep, why, and for how long
| Type of data collected | Purpose | How long we keep it |
|---|---|---|
| Messages via the contact form and email (name, email address, message content) | To answer your message and, where useful, refine the site | Deleted 24 months after the final message in the exchange |
| Aggregated analytics (page views, referrer URL, country/region, device type) | To understand which content readers use and where the site could be sharper | Up to 14 months, then retained only in aggregate |
| Server logs (IP address, timestamp, requested URL) | Security, blocking spam and abuse, technical debugging | Rolling 30-day window |
| Cookie-consent record | To remember the choice you made in the consent banner | 12 months, or until you clear it from your browser |
4. Legal grounds under GDPR
Under Article 6 of the UK GDPR and EU GDPR, Kikit relies on two legal bases and no more:
- Consent (Art. 6(1)(a)) for analytics and functional cookies. Aside from strictly necessary cookies, nothing loads until you have accepted it through the cookie banner, and you can withdraw that consent at any time.
- Legitimate interest (Art. 6(1)(f)) for replying to messages you have chosen to send, for running the strictly necessary cookies, and for keeping the short-lived server logs that protect the site from abuse.
5. Cookies and tracking
Kikit uses a small set of cookies. Strictly necessary cookies load on every visit because the site cannot function without them; analytics and functional cookies load only after you have opted in via the banner. The full cookie-by-cookie breakdown, including our use of Matomo and Microsoft Clarity, sits on our Cookies page.
6. Third parties with access
A handful of the site's functions rely on trusted processors. Each one receives no more than it needs, and every one is bound either by GDPR-compliant contractual clauses or by an equivalent legal safeguard.
- Hosting provider. A European host powers the site and retains standard server logs briefly for security.
- Email provider. Anything you send to hello@kikit.io is handled by a European mail host under a signed data-processing agreement.
- Analytics. Aggregated traffic measurement via Matomo (self-hosted) and behavioural insights via Microsoft Clarity only start after you have consented, with IP anonymisation switched on.
- Affiliate networks. If you click an outbound link to a casino, that operator or its affiliate network may drop its own cookie so a subsequent sign-up is credited to Kikit. This happens on the operator's own site, where its own privacy policy takes over the moment you land there.
7. Your rights under GDPR and CCPA
If you live in the UK, the EEA, California or a jurisdiction with equivalent protections, you are entitled to:
- Access the personal data we hold about you.
- Correct anything that is inaccurate or incomplete.
- Erasure, the "right to be forgotten". Email hello@kikit.io to ask us to delete any personal data we hold about you; we resolve verified requests inside the 30-day period the law prescribes.
- Restrict or object to the way we process it.
- Withdraw consent for analytics cookies at any time, with no effect on anything else.
- Data portability, letting you receive your data in a structured, machine-readable form.
- Opt out of "sale" or "share" under the CCPA, though as noted above neither happens on Kikit.
- Lodge a complaint with your local supervisory authority (in the UK the ICO at ico.org.uk; in California the Attorney General's office).
8. Contact for privacy questions
For any privacy question, data-subject access request or concern about how we handle your information, write to hello@kikit.io. Please include enough detail for us to locate your data, usually the email address you previously wrote from and any relevant dates, alongside a clear description of what you would like done.
9. Updates to this policy
Kikit reviews this page whenever the tooling changes or the surrounding regulations move. Any meaningful change bumps the last-updated date at the top, and we keep the previous version archived internally. The version live right now is dated 4 September 2026.