Effective date: June 29, 2026
Last updated: June 29, 2026
This policy explains what data Kodainya collects from visitors to www.kodainya.com, how we use it, and the rights you have over your data.
Where a section says “we collect X,” that is a binding statement — if our practice ever changes, this policy changes with it.
For any question about this policy, email hello@kodainya.com. For the granular inventory of cookies and similar technologies, see our Cookie Notice.
1. Who we are
Kodainya is a defense-focused content publication operated by Adaptive Inc (“we,” “us,” “our”).
We are the data controller for personal data processed through www.kodainya.com. Our data-protection contact is hello@kodainya.com.
2. The short version
| What we collect | When | Why | How long |
|---|---|---|---|
| Contact-form submissions (name, email, message) | When you submit the contact form | Reply to your enquiry | Until you ask us to delete |
| Server logs (IP, user agent, request path) | Every page load | Security, abuse prevention, debugging | 30 days |
| Cookie-banner choice (stored in your browser) | When you accept or reject the cookie banner | Remember your preference so we don’t re-prompt | 180 days |
| Aggregate page-view counts (Vercel Analytics) | Every page load | Understand traffic patterns. Cookieless, no personal identifiers | Hash rotates daily; aggregates retained by Vercel |
| Analytics events with identifiers (Google Analytics 4) | Every page load, only after you accept analytics in the cookie banner | Understand which articles people read and how visitors navigate the site | 14 months (GA4 default) |
We do not run advertising, do not build behavioral profiles, and do not sell or share data beyond the named processors in Section 5.
3. What we collect, in detail
3.1 Contact form
When you submit the contact form on /contact, we collect:
- Your name
- Your email address
- Your subject line and message
- The approximate IP address of your submission (for spam prevention)
We process this data to respond to your enquiry (lawful basis: legitimate interest in handling enquiries from prospective contacts; performance of pre-contractual steps where applicable). Submissions are sent server-to-server to HubSpot, our CRM provider, and stored there for our reference. No HubSpot scripts run in your browser.
We retain submissions until you ask us to delete them or until the conversation is no longer relevant to our operations, whichever comes first.
3.2 Server logs
Every request to kodainya.com is logged by our hosting provider. Logs include your IP address, requested URL, user agent, response status, and timestamp.
These logs are retained for 30 days and used only for security monitoring, debugging, and aggregate traffic analysis (lawful basis: legitimate interest in maintaining the security and availability of the site). We do not access individual log entries in the ordinary course of operations.
3.3 Cookie-banner choice
When you accept or reject the cookie banner, your choice is stored in your browser’s local storage under the key kdn.consent.v1for 180 days, after which the banner reappears so you can confirm or change it. No identifier is sent to our servers — the choice stays on your device.
3.4 Analytics
We use two analytics services with different privacy profiles.
3.4.1 Vercel Web Analytics (cookieless, runs by default)
Vercel Analytics measures aggregate page-view counts and unique-visitor counts. It does not set cookies. Per Vercel’s privacy documentation, visitors are identified by a hash of the incoming request that is reset every 24 hours and cannot be used to track a visitor across days or across other websites. No personal identifiers are stored.
Lawful basis: legitimate interest in understanding aggregate site usage with the minimum data necessary. Because the data is anonymous and the processing is non-invasive, this does not require prior consent under the GDPR or DPDP Act 2023. If you would prefer to be excluded entirely, email hello@kodainya.com.
3.4.2 Google Analytics 4 via Google Tag Manager (consent-gated)
Google Analytics 4 (GA4) is loaded through Google Tag Manager. Our implementation of Google Consent Mode v2 sets all four advertising and analytics signals to deniedby default. Until you grant analytics consent, GA4 sets no cookies, transmits no client identifier, and sends no advertising signals. In this state, Google receives only anonymous, identifier-free measurement pings (used by Google’s aggregate modelling system to estimate visitor counts) that cannot be tied to a specific person. We additionally enable ads_data_redaction, which strips further identifiers from these pings.
When you grant analytics consent through the cookie banner, GA4 begins setting first-party cookies (_ga and _ga_<container-id>) and processes the following data: page URL, referrer, device type, browser, screen size, country (derived from a truncated IP), session identifier, and the events fired by GA4’s Enhanced Measurement (clicks, scrolls, outbound links, file downloads). The full IP address is not stored by GA4.
If you withdraw consent (via the “Manage cookies” footer link, then rejecting), Kodainya immediately deletes any _ga and _ga_<container-id> cookies that were previously set on your device and returns GA4 to the cookieless-pings state described above.
Lawful basis: consent (GDPR Article 6(1)(a) / DPDP Act Section 7). You can withdraw consent at any time by clicking “Manage cookies” in the site footer.
Retention: 14 months at the GA4 property level. Cookie lifetimes are listed in our Cookie Notice.
3.5 Bot protection on the image subdomain
Images and other media are served from image.kodainya.com, which is fronted by Cloudflare. Cloudflare sets a __cf_bmbot-protection cookie scoped to that subdomain, expiring after 30 minutes of inactivity. Per Cloudflare’s documentation, the cookie contains an encrypted bot score and does not correspond to any user identifier or track visitors across sites. Lawful basis: legitimate interest in protecting the service against automated abuse.
4. What we don’t collect
For clarity, we are explicit about what we do not do:
- We do not run advertising on this site.
- We do not run retargeting pixels, social media tracking pixels (Meta, LinkedIn, X, TikTok, Pinterest), or affiliate trackers.
- We do not use session-replay tools such as Hotjar, FullStory, Microsoft Clarity, or LogRocket.
- We do not use visitor-identification tools such as Leadfeeder, Clearbit, or 6sense.
- We do not build behavioral profiles of visitors beyond the aggregate analytics described in Section 3.4.
- We do not sell, rent, or share your data with brokers, advertisers, or any party not named in this policy.
- We do not require account creation for readers.
- We do not collect special-category data (health, religion, political views, biometrics) as defined by GDPR Article 9 or the DPDP Act 2023.
If we add a tool that changes the above, this policy will be updated before that tool launches.
5. Who we share data with
We share data only with the following processors, each of which processes data on our behalf under a written agreement:
| Processor | Data category | Lawful basis | Country |
|---|---|---|---|
| HubSpot, Inc. | Contact-form submissions | Legitimate interest | USA |
| Vercel, Inc. | Server logs and aggregate cookieless analytics | Legitimate interest | USA |
| Google LLC | Analytics events through Google Analytics 4 and Google Tag Manager | Consent | USA |
| Cloudflare, Inc. | Media-subdomain requests; bot-protection cookie | Legitimate interest | USA |
All US-based processors are subject to the EU-US Data Privacy Framework or equivalent Standard Contractual Clauses for EU/EEA data transfers. Indian data is processed under the terms of the DPDP Act 2023.
We do not share data with any party not listed above, except where required by law. Where lawful, we will challenge such requests and notify affected users.
6. International transfers
All processors listed above store data outside India and outside the EEA. We rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses as appropriate safeguards.
If you are in a jurisdiction with specific cross-border-transfer rules, you may request details of the safeguards in place at hello@kodainya.com.
7. Your rights
You have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Delete your data
- Object to processing
- Withdraw consentat any time, including analytics consent (via the “Manage cookies” link in the footer)
- Complain to a supervisory authority (see Section 11)
If you are a resident of the EU, UK, California, or India, additional specific rights under GDPR, CCPA/CPRA, or the DPDP Act 2023 may apply.
To exercise any right, email hello@kodainya.com with the subject line “Privacy request” and a brief description of what you want. We aim to respond within 30 days.
If we cannot identify you from the data we hold — for example, if you have only read articles and never submitted the contact form — there may be nothing specific to delete. We will explain this in our response.
8. Children
Kodainya is intended for an adult, professional readership. The site is not directed at children under 18, and we do not knowingly collect data from anyone under 18.
If we learn that we have inadvertently collected data from a child, we will delete it. If you are a parent or guardian and believe your child has provided data to us, contact hello@kodainya.com.
9. Security
We use industry-standard security practices to protect data in transit and at rest, including transport encryption and access controls.
No system is perfectly secure. If we experience a breach affecting your data, we will notify you in accordance with applicable law.
10. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent change.
Material changes — changes that expand what we collect, change who we share with, or affect your rights — will be notified by a banner on the homepage for at least 30 days.
Minor clarifications (typos, restructuring without practice changes) will not trigger notification.
11. Complaints
If you believe we have mishandled your data, email hello@kodainya.com first — we’d like the chance to fix it.
If you remain unsatisfied, you have the statutory right to lodge a complaint with the data protection supervisory authority in your jurisdiction.
12. Contact
Adaptive Inc
Email: hello@kodainya.com
Response SLA for privacy requests: within 30 days
Questions? Get in touch.