privacy policy
this explains what KAI BUSINESS HUB LTD (“we”, “us”) — trading as nowihavea.website — collects when you use https://nowihavea.website, why, and the rights you have under uk data protection law (the uk gdpr and the data protection act 2018). last updated 8 june 2026.
who we are
the data controller is KAI BUSINESS HUB LTD, registered in England & Wales [placeholder — confirm registered office & company number before launch]. for any privacy question, or to exercise your rights, contact us at hello@nowihavea.website.
what we collect
- what you type: the prompt describing the site you want, and the content we generate from it (your site’s name, tagline, links, photos count and “drops”).
- your account: your email address, and a password (handled and stored, hashed, by our authentication provider — we never see your password).
- your details: whether the site is for an individual or a business, your name, and — for a business — the business name.
- your address: the username you claim for your
username.nowihavea.website-style address. - your choices: whether you registered interest in a future dedicated (custom-domain) website.
- essential technical data: a sign-in/session cookie so you stay logged in, and ordinary server logs. no analytics or advertising/tracking cookies.
why we use it (lawful bases)
- to create and run your account and save your site — performance of a contract with you (and steps you ask us to take before one).
- to generate your site content from your prompt — legitimate interests (delivering the thing you asked for), and performance of that contract.
- to keep the service secure and prevent abuse — legitimate interests.
- the privacy/terms agreement you give at sign-up records your acceptance; where we rely on consent you can withdraw it at any time (see your rights).
who processes it (and where)
we keep data minimal and we do not sell it or share it for advertising. we use a small number of processors to run the service:
- supabase — our database and authentication. your account, profile, saved site and reserved address are stored here, in an eu / london region [confirm the exact region in the project settings].
- anthropic — the ai that fills your site content. when you submit a prompt, that prompt text is sent to anthropic’s api (server-side) to generate the content. don’t put anything sensitive in the prompt.
- our hosting — the app is served by our hosting provider, which processes ordinary request data to deliver pages.
- cloudflare — a bot-protection check (turnstile) runs when you generate a site, to keep the service secure and stop automated abuse. it processes limited technical signals from your browser to tell humans from bots; it isn’t used for advertising or to track you across sites. see cloudflare’s turnstile privacy addendum.
where a processor handles data outside the uk/eu (for example the ai provider), that transfer relies on appropriate safeguards such as the uk international data transfer agreement / addendum [confirm with each provider’s dpa before launch].
how long we keep it
we keep your account, profile and saved site for as long as your account exists. delete your account (below) and we remove your rows — your site, profile and reserved address — and, where set up, your underlying login record. demo content you make before signing up lives only in your own browser; clearing your browser data removes it.
your rights
under the uk gdpr you can:
- access a copy of your data, and have inaccurate data corrected;
- have your data erased — there’s a “delete my account” control in your account that removes your data; or email us and we’ll do it;
- restrict or object to processing, and ask for portability of data you gave us;
- withdraw any consent you gave, without affecting past processing.
email hello@nowihavea.website to exercise any of these. if you’re unhappy with how we handle your data you can complain to the uk regulator, the information commissioner’s office (the ico) at ico.org.uk — but we’d appreciate the chance to put things right first.
security
access is protected by row-level security, so a signed-in user can only read and write their own rows; passwords are hashed by our auth provider; traffic is served over https. no system is perfectly secure, but we keep what we collect small to keep the risk small.
children
this service isn’t intended for children under 16. if you believe a child has given us personal data, contact us and we’ll remove it. [confirm the age threshold for your audience before launch.]
changes
we’ll update this page as the service grows (for example when paid plans, custom domains or live hosting arrive) and change the “last updated” date above.
last updated: 8 june 2026.