This Privacy Policy ("Policy") describes how Like a King Inc., together with its owners, officers, directors, employees, contractors, affiliates, successors, and assigns (collectively, "Like a King Inc.", "the Company", "we", "us", or "our"), collects, uses, discloses, retains, and protects information in connection with this website, the REGES AI concierge, and any related services (collectively, the "Site"). By accessing or using the Site, you acknowledge that you have read, understood, and agree to the practices described in this Policy. If you do not agree, you must discontinue use of the Site immediately.
We are committed to handling personal information responsibly and in accordance with applicable data-protection laws. This Policy is intended to be interpreted broadly in favour of lawful processing and the legitimate operation of our business, and should be read together with our Terms of Service, Cookie Policy, and Disclaimer, each of which is incorporated herein by reference.
1. Scope of this Policy
This Policy applies solely to information collected through the Site. It does not apply to information collected offline, through separate written engagement agreements, or by any third party we do not control. Where you engage the Company for services, the data-handling terms of the applicable written agreement shall govern to the extent they differ from this Policy.
2. Information we collect
We collect information in the following categories, in each case only to the extent permitted by law:
a. Information you provide
Contact and identifying details you submit through enquiry or estimate forms, such as your name, company, work email, telephone number, and any information contained in messages you send;
Correspondence and the contents of communications you direct to us, including through the REGES concierge;
Any other information you voluntarily choose to provide.
b. Information collected automatically
Technical data such as IP address, browser type and version, device characteristics, operating system, language preferences, and referring URLs;
Usage data such as pages viewed, time spent, navigation paths, and interaction events, collected in aggregated or pseudonymised form where feasible;
Cookie and similar-technology identifiers, subject to the choices described in our Cookie Policy.
c. Information from third parties
We may receive limited information from analytics providers, infrastructure vendors, and security services acting on our behalf. We do not purchase personal data for marketing purposes.
3. How we use information
We use information for legitimate business purposes, including to: respond to enquiries and requests for estimates; provide, operate, maintain, and improve the Site and our services; personalise and enhance user experience; ensure security, prevent fraud, and protect our rights and the rights of others; conduct analytics and research; comply with legal, regulatory, and contractual obligations; and establish, exercise, or defend legal claims.
We may aggregate or de-identify information so that it no longer reasonably identifies you, and may use and disclose such information for any lawful purpose without restriction.
4. Legal bases for processing
Where applicable law (including the EU/UK General Data Protection Regulation) requires a legal basis, we rely on one or more of the following: your consent; the necessity of processing for the performance of a contract or to take steps at your request prior to entering a contract; our legitimate interests in operating, securing, and growing our business, provided such interests are not overridden by your fundamental rights; and compliance with a legal obligation.
5. Disclosure of information
We do not sell your personal information for monetary consideration. We may disclose information: to service providers and processors who perform functions on our behalf under confidentiality obligations; to professional advisers such as lawyers, auditors, and insurers; to authorities, regulators, or other parties where we believe in good faith that disclosure is necessary to comply with law, enforce our agreements, or protect the safety, rights, or property of any person; and in connection with any merger, acquisition, financing, reorganisation, sale of assets, or insolvency, in which information may be transferred as a business asset.
6. Service providers and processors
We engage third parties to provide hosting, analytics, communications, and AI-model infrastructure (including the provider powering the REGES concierge). These parties are authorised to process information only as necessary to provide their services and are bound by contractual obligations consistent with this Policy.
7. International transfers
Your information may be processed and stored in countries other than your own, which may have different data-protection standards. Where required, we implement appropriate safeguards, such as standard contractual clauses, to protect information transferred internationally. By using the Site, you acknowledge such transfers.
8. Data retention
We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, to comply with our legal, tax, accounting, and regulatory obligations, to resolve disputes, and to enforce our agreements. When information is no longer required, we take reasonable steps to delete or anonymise it.
9. Security
We implement commercially reasonable technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission or storage is completely secure, and we cannot and do not guarantee absolute security. You transmit information to us at your own risk, and you are responsible for maintaining the confidentiality of any credentials or communications on your side.
10. Your rights and choices
Subject to applicable law, you may have the right to request access to, correction of, or deletion of your personal information; to object to or restrict certain processing; to request portability; and to withdraw consent where processing is based on consent. Residents of the European Economic Area and United Kingdom may exercise rights under the GDPR; residents of California may exercise rights under the CCPA/CPRA, including the right to know, delete, and opt out of "sale" or "sharing" (which we do not undertake for monetary consideration), and the right not to be discriminated against for exercising such rights.
To exercise any right, contact us via the enquiry form on the Site. We may need to verify your identity before responding. We will respond within the timeframes required by applicable law. We reserve the right to decline requests where permitted, including where a request is unfounded, excessive, or would adversely affect the rights of others.
11. Children
The Site is intended for business and professional audiences and is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
12. Do Not Track and third-party technologies
The Site does not respond to "Do Not Track" browser signals. Third-party technologies you encounter are governed by their own privacy policies, which we do not control and for which we accept no responsibility.
13. Changes to this Policy
We may amend this Policy at any time, in our sole discretion. Changes are effective upon posting the updated Policy on the Site with a revised date. Your continued use of the Site after any change constitutes acceptance of the revised Policy.
14. Data-subject request procedures
To submit a data-subject request, use the enquiry form on the Site and identify the nature of your request (access, correction, deletion, restriction, objection, portability, or withdrawal of consent). To protect your information, we will take reasonable steps to verify your identity before acting, which may include confirming details already held by us; we will not use verification information for any other purpose. Where permitted, we may charge a reasonable fee or decline to act on requests that are manifestly unfounded, repetitive, or excessive. We aim to acknowledge requests promptly and to respond within the period required by applicable law (generally thirty (30) days under the CCPA/CPRA and one (1) month under the GDPR, each extendable where the law allows). An authorised agent may submit a request on your behalf with proof of authorisation. If we decline a request, we will explain why, to the extent the law requires, and you may have the right to appeal or to lodge a complaint with a supervisory authority.
15. Personal-data breach notification
We maintain procedures to detect, investigate, and respond to security incidents affecting personal data. Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals without undue delay and in accordance with applicable law. Notifications will describe, to the extent known, the nature of the breach, likely consequences, and measures taken or proposed. Nothing in this section creates an obligation beyond what applicable law requires, and our provision of notice is not an acknowledgement of fault or liability.
16. Sub-processors and vendors
We rely on categories of sub-processors and vendors to operate the Site and our services, including: cloud-hosting and content-delivery providers; website-analytics and performance-monitoring providers; communications and email-delivery providers; security, logging, and fraud-prevention services; and artificial-intelligence model providers that power the REGES concierge and the "analyze my business" feature. Each such party is engaged under terms requiring it to process personal data only on our instructions and to maintain appropriate confidentiality and security safeguards. The specific identities of sub-processors may change over time as our operations evolve; a current summary is available on request through the enquiry form, subject to any confidentiality obligations.
17. GDPR-specific information (EEA/UK)
Where the GDPR or UK GDPR applies, Like a King Inc. acts as a "controller" of the personal data described in this Policy and, in certain circumstances, as a "processor" on behalf of clients under separate written agreements. The categories of data, purposes, and legal bases are set out in Sections 2 to 4 above, provided in satisfaction of Articles 13 and 14 where applicable. You have the rights described in Section 10 and the right to lodge a complaint with your local supervisory authority. Where we rely on legitimate interests, you may request further information about the balancing test we have conducted. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. We do not use your personal data for solely automated decision-making that produces legal or similarly significant effects.
18. U.S. state-privacy information
Depending on your state of residence, you may have rights under laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and comparable statutes in other states. These may include the rights to know, access, correct, and delete personal information, to opt out of "sale" or "sharing" of personal information and of targeted advertising, and to limit the use of sensitive personal information. We do not sell personal information for monetary consideration and do not knowingly "share" it for cross-context behavioural advertising. We will not discriminate against you for exercising any right. To exercise a right, use the enquiry form; we will process verifiable requests as described in Section 14.
19. Marketing communications
Where you provide your details, we may contact you to respond to your enquiry and, where permitted, to send information about our services. You may opt out of non-essential marketing communications at any time by following the unsubscribe mechanism in the relevant message or by contacting us through the enquiry form. Transactional and service messages necessary to respond to your enquiry are not marketing communications.
20. Contact
For questions about this Policy or our data practices, or to exercise any right, please contact the Company through the enquiry form on the Site. We will route your request to the appropriate personnel responsible for privacy matters.
© 2026 LIKE A KING INC. All rights reserved.