Privacy Policy
Effective date: September 24, 2026 • View previous version
1. Introduction
Kitchen.co is a white-label client portal platform provided by 2 Create Ltd (the "Company", "we", "us"). Our customers — agencies, studios and professional-services firms — use it to give their clients a branded space for tasks, files, communication, and more.
This Privacy Policy explains what personal data we process as a controller in connection with the Kitchen.co website and platform, for what purposes and on what basis, with whom we share it, how long we retain it and what rights you have.
We are committed to transparency and process personal data lawfully, fairly and in accordance with the principles of data minimisation and purpose limitation. This Policy should be read together with the Cookie Policy and — for our customers — with the Data Processing Agreement (DPA).
This Policy is published on the website and is presented upon registration; by creating an account you confirm that you have read it. It is informational in nature and does not limit your rights under the law.
2. Roles and scope
For account and profile data, the workspace, billing, support, marketing and usage data we are the controller and this Policy applies in full.
For the content entered into Kitchen.co by our customers and the people they invite — such as tasks, files, messages, comments, including any personal data of third parties contained in them — we act as a processor on behalf of the customer, who is the controller. That processing is governed by the DPA.
If you are an invited team member, guest or end-client in another party's workspace, the processing of your data within that workspace is determined by the relevant controller (the customer) who invited you.
3. Controller and contact details
Controller: 2 Create Ltd, UIC 200659554, with its registered seat and address at 8 Neptun Street, Varna 9000, Bulgaria.
Data protection contact: for questions and requests relating to personal data, contact us at [email protected].
4. How we collect personal data
Directly from you: when you create and manage an account, use the platform, contact us and pay for a subscription/lifetime plan.
Automatically: when you use the service — log records, IP address, device and browser data, timestamps of actions, session identifiers and cookies.
From third parties: from the controller who invited you; from an SSO or social login provider, if you use one; from participants in our affiliate programme.
5. What personal data we process
Kitchen.co is a white-label platform. We process personal data in two capacities: (i) as a controller — to create and manage our customer's account (the agency or business using the platform) and for our own activities described below; and (ii) as a processor — in respect of the content and data that our customer and its own end-clients enter into or exchange within the workspaces. Except where expressly stated, the categories below relate to our processing as a controller. Processing as a processor is governed by Section 2 and the Data Processing Agreement (DPA).
Account and profile: names, e-mail address, phone (optional), password (stored in hashed form), organisation, job title/role, profile picture (optional), language, time zone.
Workspace and team: team members, roles and access permissions, workspace settings and preferences. Where our customer invites its own end-clients or collaborators into a workspace, we process their identification and contact data (names, e-mail addresses) and role and access data in order to operate the portal.
Usage and technical data: log records, IP address, device and browser type, operating system, session identifiers, events and actions within the platform, error diagnostics.
Payment and billing: billing name and address, subscription details, payment history; payments themselves are processed by a payment service provider (e.g., Stripe) and, as a rule, we do not store payment card data.
Communications and support: content of enquiries, tickets and correspondence, feedback and ratings.
Marketing: e-mail address, marketing preferences, newsletter subscription status, interaction with our communications.
Integration and login data: when you use SSO login or connect an external service — identifiers and data that the relevant service shares on your instruction.
Customer content and end-client data (processing as a processor): our customer and the persons it invites enter into the platform project, task, file, comment and message content, which may contain personal data — including personal data of our customer's own end-clients and of third parties. This content is customer content that we process as a processor, only on the instructions of our customer (the controller) and in accordance with Section 2 and the Data Processing Agreement (DPA). Our customer determines what data it enters, on what basis and for what purposes, and is responsible for informing its own end-clients and data subjects. We do not use customer content for our own purposes.
Special categories of data: we do not intentionally collect special categories of personal data (Art. 9 GDPR). If our customer enters such data into the customer content, it is responsible for the existence of a legal basis.
6. Collaboration and integrations
Kitchen.co is a white-label client portal built for agencies and professional-services firms. Our customers use the platform to give their own end-clients a branded workspace — with the customer's own logo, colour theme and custom domain, and with Kitchen.co's branding fully removed. To end users, the portal appears as a product of that agency rather than of Kitchen.co.
Within each workspace, the agency decides which of its team members and which of its end-clients to invite, what roles and permissions they hold, and what content they may access. When people are invited, content is shared or tasks are assigned, the participants' names, e-mails and actions become visible to other members of the same workspace according to the roles and permissions configured by the agency. The scope, configuration and branding of each workspace are managed entirely by the relevant agency in its capacity as controller; 2 Create Ltd provides the underlying technical platform as a processor acting on the agency's instructions.
The platform allows connection to external services chosen by the agency (e.g., file storage — Google Drive, Dropbox, OneDrive; payments — Stripe, PayPal and others). When the agency enables an integration, the exchange of data takes place on its instruction and under the terms of the relevant external provider; the configuration and scope of the integration are managed by the agency.
7. Purposes and legal bases
We process personal data for the purposes and on the legal bases under Art. 6 GDPR set out below. Where we rely on legitimate interest (Art. 6(1)(f)), we state the specific interest; the balancing assessment between it and your rights is available on request.
| Purpose | Data subjects & data | Legal basis | Retention |
|---|---|---|---|
| Account registration | account holders & users; registration data | Contract, Art. 6(1)(b) | for the duration of the account + 1 year |
| Providing the platform | users; account, usage | Contract, Art. 6(1)(b) | for the duration of the account |
| Workspace & team administration | holders, members; team & role data | Contract, Art. 6(1)(b) | for the duration of the account |
| Authentication & access management | users; identifiers, logs | Contract & legitimate interest (access security) | up to 3 years |
| Billing, subscriptions & payments | holders; billing data | Contract & legal obligation | accounting data: 10 years |
| Accounting & tax compliance | holders; accounting data | Legal obligation | 10 years |
| Customer support | users; communications | Contract & legitimate interest (support quality) | up to 5 years |
| Security & fraud prevention | users; technical, logs | Legitimate interest (network & information security) | up to 5 years |
| Analytics & service improvement | users; usage, cookies | Consent (cookies) & legitimate interest (improvement) | see Cookie Policy |
| Direct marketing & newsletter | contacts, customers; email, preferences | Consent or legitimate interest (soft opt-in) | until withdrawal of consent |
| Affiliate programme | affiliates; affiliate data | Contract, Art. 6(1)(b) | for the duration + 1 year |
| Legal compliance & claims | as relevant | Legal obligation & legitimate interest (defence of rights) | as required by law |
| Aggregated & anonymised statistics | users; aggregated data | Legitimate interest; anonymised data fall outside the GDPR | indefinitely (anonymous) |
| Marketing data | Website data subjects | Consent | until consent is withdrawn or you object |
8. Marketing and communications
We send marketing communications and newsletters only on the basis of your consent or, for existing customers, on our legitimate interest to offer similar services (a "soft opt-in"). Every message contains an unsubscribe option, and you can withdraw your consent at any time, without affecting processing before withdrawal.
We do not disclose your data to third parties for their own marketing purposes and do not carry out profiling with legal effects for marketing purposes.
9. Recipients and sub-processors
We share personal data with categories of recipients acting on our behalf as processors: hosting and infrastructure (DigitalOcean), object storage and CDN (Cloudflare), file storage (Amazon Web Services), file preview and metadata generation (Filepreviews), e-mail delivery (AWS SES, Postmark), error and performance monitoring (Sentry, Laravel Nightwatch), customer support (Intercom), push notifications (Firebase), payment processing (Stripe), e-mail marketing (Mailchimp), affiliate/referral tracking (First Promoter) and analytics (Google). We also share data with professional advisers (e.g., accountants, lawyers) and with competent authorities where required by law.
The providers that process personal data on our behalf act only on our instructions. These relationships are governed by data processing agreements (DPAs) that apply through acceptance of each provider's standard terms and that contain the obligations required under Art. 28 GDPR. We do not sell personal data and do not disclose it to third parties for consideration.
10. International transfers
Some of our providers are established outside the European Economic Area (EEA), including in the USA (e.g., Google, Stripe, Intercom and e-mail providers). When we transfer personal data outside the EEA, we ensure appropriate safeguards under Chapter V GDPR:
- an adequacy decision of the European Commission — for US providers certified under the EU–US Data Privacy Framework (DPF);
- the European Commission's standard contractual clauses — for other cases or as a fallback, accompanied by a transfer impact assessment (TIA).
A copy of the applicable safeguards (e.g., the standard contractual clauses) and information about the transfer impact assessment are available on request.
11. Retention periods
We keep personal data only for as long as necessary for the relevant purposes. The criteria include the term of the account and our relationship with you, statutory retention periods and any legal claims. After they expire, data are deleted or anonymised.
12. Your rights
Under the GDPR you have the following rights, which you can exercise at any time:
Access: to obtain confirmation of whether we process your data and a copy of it, together with information about the processing.
Rectification: to request correction of inaccurate, or completion of incomplete, data.
Erasure ("right to be forgotten"): to request deletion of the data where there are grounds.
Restriction: to request restriction of processing in certain cases.
Portability: to receive your data in a structured, commonly used and machine-readable format or to request its transfer.
Objection: to object to processing based on legitimate interest and, at any time, to direct marketing.
Withdrawal of consent: to withdraw a given consent at any time, without affecting the lawfulness of processing before withdrawal.
Complaint: to lodge a complaint with the supervisory authority (Section 18).
To exercise your rights, contact us at [email protected]. We may request additional information to verify your identity. We respond free of charge and without undue delay, within one month, which may be extended by a further two months for complex or numerous requests (Art. 12 GDPR).
13. Security
We implement appropriate technical and organisational measures commensurate with the risk, including:
- access control and authentication on a least-privilege basis;
- encryption of data in transit (TLS) and measures to protect data at rest;
- logging and monitoring, backups and restoration capability;
- vulnerability management and regular updates; environment segregation;
- staff training, confidentiality commitments and a personal data breach procedure.
No service can guarantee absolute security. In the event of a personal data breach, we act in accordance with our internal procedure and applicable law, including notification obligations.
14. Automated decision-making and profiling
We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing within the meaning of Art. 22 GDPR. To the extent we use analytics tools, they serve aggregated statistics and service improvement and do not lead to such decisions.
15. Children
The service is intended for business users and is not directed at children. We do not knowingly process personal data of children under 14 — the age of valid consent for information society services under Bulgarian law (the Personal Data Protection Act). If we learn that we have collected such data without the required consent, we delete it.
16. Third-party links
Our platform and website may contain links to third-party sites and services with their own privacy policies. We are not responsible for their content or practices and recommend that you review their policies.
17. Changes to this policy
We may update this Policy when the processing, the technologies used or the applicable requirements change. The current version is published on the website with an effective date; for material changes we will notify you by appropriate means (e.g., by e-mail or via a notice in the platform).
18. Contact and supervisory authority
Controller: 2 Create Ltd, UIC 200659554, 8 Neptun Street, Varna 9000, Bulgaria; [email protected].
If you believe we process your data unlawfully, you have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, [email protected], www.cpdp.bg, as well as with the supervisory authority of your habitual residence in the EU.