Legal
Privacy
What this site records, what it does not, who else sees any of it, and how long it is kept. Written against the code rather than from a template, so it describes what actually happens.
Last updated 19 August 2026. Kaymen Group LLC.
Who this is
Kaymen Group LLC operates kaymen.dev. If you want anything on this page explained, or you want your data removed, write to elor@kaymengroup.com and a person will answer.
TO CONFIRM: registered address and jurisdiction of incorporation.
If your browser says do not track, we do not
The tracking script checks navigator.doNotTrack before it does anything else and stops there if it is set. No identifier is created, no request is made, nothing is recorded. That is a real check in the code, not a policy we promise to honour manually.
What is recorded when you browse
If you have not opted out, we record: the pages you open and their titles, the site you arrived from, any campaign tags in the URL, your screen and window size, your time zone and browser language, roughly how long you were actively reading, and your IP address and browser user-agent string.
Two identifiers are stored in your own browser. A visitor id in localStorage (_k_vid) which persists so returning visits can be counted as returning rather than new, and a session id in sessionStorage which disappears when you close the tab. Neither is a cookie and neither is shared with anyone.
We do not run advertising trackers, we do not embed third-party analytics, and we do not sell or share this data with anyone for marketing. Two third parties do see something, and they are named below rather than buried.
Your IP address is sent to one third party
To turn an IP address into an approximate location, we send it to ip-api.com, which returns a country, region, city, approximate latitude and longitude, time zone and network operator. That request is made from our server, not your browser.
Two things about that are worth stating plainly. It is sent over plain HTTP, not HTTPS, because that is what their free tier allows — so anyone able to observe traffic between our server and theirs could see the IP and the location that comes back. And ip-api.com is an independent company with its own privacy policy that we do not control.
If that is not acceptable to you, setting Do Not Track prevents it entirely, because nothing is recorded to look up.
The fonts on this page come from Google
The typefaces are loaded from Google's font service, which means your browser requests them from Google directly and Google receives your IP address on every page you open here. That happens before any of our own tracking, and setting Do Not Track does not prevent it, because it is your browser fetching a file rather than us recording anything.
We are not happy about it either. Self-hosting the fonts removes Google from the process entirely and makes the page load faster; it is on the list.
Signing in with Google
Client portal accounts can optionally sign in with a Google account. If you choose that, Google tells us your name, email address and Google account id, and Google knows you signed in here. If you would rather not, use an email address and password instead — the option exists for convenience, not because we need it.
Security records
Every request to this site passes a filter that looks for attacks. When something scores high enough it is recorded — the IP address, what was requested, and what was done about it — and the address may be blocked temporarily. Blocks expire; they escalate from an hour to seven days for repeat offenders and are never permanent, because IP addresses get reassigned to other people.
This is done to keep the site and our clients' systems up. It is not used for advertising or profiling.
If you contact us
The form on this site records your name, email address, what you said, the project name if you give one, the time you sent it, and the IP address it came from. It is stored so we can reply and emailed to us so we notice. The address is kept because the form is a spam target and it is how a flood gets traced; it is not used for anything else. If you would rather not use the form, the phone number and email address beside it reach the same person.
If you have a client portal login
For clients with an account we hold your name, email address, a hashed password, and a record of sign-ins and password resets. Sign-in records exist so we can tell you whether an account was accessed and by whom.
How long any of it is kept
Old raw analytics and security records are deleted automatically, on the schedule above — that is a job that runs hourly, not a policy we promise to remember. What survives indefinitely from browsing is a daily count — how many people visited on a given day, from which country, on which kind of device — with nothing in it that identifies anybody.
The last two rows work differently, and it is worth being plain about it: nothing deletes an enquiry or a client record on a timer. An enquiry is kept so we can pick the conversation back up, and client records are kept while we are running the system they describe. Both are deleted when you ask — write to elor@kaymengroup.com and a person will do it.
| Analytics events (clicks, engagement) | 60 days |
|---|---|
| Page views | 120 days |
| Visits and geo cache | 120–240 days |
| Security and blocking records | 240 days |
| Sign-in records for the client portal | 400 days |
| Daily totals with no personal data in them | kept indefinitely |
| What you send through the contact form | until you ask us to delete it |
| Client records — organisations, projects, documents | for the life of the working relationship, then on request |
Where it lives
On servers we operate ourselves rather than on a third-party analytics platform. Nothing on this site is processed by Google Analytics, Meta, or any advertising network.
What you can ask for
Ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted, and we will do it. There is no form and no ticketing system — write to elor@kaymengroup.com.
TO CONFIRM: whether GDPR, UK GDPR, CCPA or the Israeli Privacy Protection Law apply, which depends on where the company is established and where its visitors are. That determines what rights are legally enforceable rather than simply offered.
Data belonging to our clients
Separately from this website, we build and run systems for clients that hold their data — their customers, their staff, their records. In those systems we act on the client's instructions and the client decides what is collected and why. This page does not cover that data; the agreement with each client does.
TO CONFIRM: whether a written data processing agreement is offered to clients as standard. If any client is subject to GDPR or the Israeli Privacy Protection Law, they will need one from us.