The Best Fluffy Pancakes recipe you will fall in love with. Full of tips and tricks to help you make the best pancakes.
Last updated: 24 July 2026
Next review: July 2027
Kima Recipes is a small food blog run by one person, hosted in the United States and read mostly by people in the United States. Because it is written in English and open to anyone, some of our readers are in Europe — so the EU General Data Protection Regulation and the UK GDPR are relevant to us, and we would rather meet them properly than pretend they do not apply.
This page explains how we do that, and how you can exercise your rights. It sits alongside our Privacy Policy, which describes in detail what we collect.
1. The principles we work to
Article 5 of the GDPR sets out seven principles. Here is what each one means in practice on this site:
| Principle | How we apply it |
|---|---|
| Lawfulness, fairness, transparency | Every use of your data has a legal basis, and all of them are published in section 3 below |
| Purpose limitation | Email addresses left with a comment are never added to the newsletter. Newsletter addresses are never sold, rented or repurposed |
| Data minimisation | The newsletter asks only for an email address. The comment form’s website field is optional. We do not ask for anything we do not need |
| Accuracy | You can have anything we hold corrected by emailing us |
| Storage limitation | Defined retention periods, listed in section 6, after which data is deleted or anonymised |
| Integrity and confidentiality | HTTPS across the whole site, Cloudflare filtering, two-factor authentication on the admin account, encrypted backups |
| Accountability | We keep an internal record of our processing activities and our consent logs |
2. Who is responsible
| Data controller | Kima, owner and author of Kima Recipes |
|---|---|
| Site | https://kimarecipes.com |
| Contact for all privacy matters | [email protected] |
| Data Protection Officer | Not appointed. Article 37 requires one only for public authorities, for large-scale systematic monitoring, or for large-scale processing of sensitive data. A recipe blog meets none of these thresholds |
| Establishment | Outside the European Union. Our servers are in the United States and our audience is predominantly American |
3. What we process, and on what basis
| Activity | Data involved | Legal basis | Kept for |
|---|---|---|---|
| Publishing comments and recipe ratings | Name, email, optional website, IP address, browser string, comment text | Consent and legitimate interests | Indefinitely; deleted on request |
| Spam filtering | Comment data and IP address | Legitimate interests | Per Akismet’s policy |
| Answering contact form messages | Name, email, message | Legitimate interests | 24 months |
| Newsletter | Email address, open and click data | Consent — Art. 6(1)(a) | Until you unsubscribe, plus 30 days |
| Analytics | Pseudonymous usage data, truncated IP | Consent | 14 months |
| Security and server logs | IP address, request data | Legitimate interests | Up to 30 days |
| Consent records | Consent choice, timestamp, IP | Legal obligation — proof under Art. 7(1) | 12 months |
| Display advertising | Not yet active | Will require consent | — |
We do not process special category data under Article 9 — nothing about health, religion, politics or ethnicity. One caveat worth knowing: if you mention in a comment that you are coeliac, diabetic, pregnant, or that you keep halal or kosher, that comment technically reveals health or religious information about you, and it is published publicly. Please do not share anything you would not want visible. Ask us and we will remove it.
We carry out no profiling and no automated decision-making that produces legal or similarly significant effects on you (Article 22).
4. Consent, done properly
Under the GDPR and the ePrivacy Directive, consent has to be freely given, specific, informed and unambiguous — an active choice, not an assumption. Here is our standard:
- Analytics and, in future, advertising scripts do not run until consent is given. They are blocked by default, not merely ignored.
- The cookie banner offers “Accept all” and “Reject all” with equal prominence, on the first screen, one click each. Refusing is exactly as easy as accepting.
- No pre-ticked boxes. No cookie walls. No “by continuing to browse, you agree”.
- Consent is separated by purpose, so you can allow analytics while refusing advertising.
- Each choice is logged with a timestamp so we can demonstrate it, as Article 7(1) requires.
- Withdrawing is as easy as consenting — the “Cookie settings” link in the footer reopens the banner at any time (Art. 7(3)).
- We ask again every 12 months, and immediately whenever we add a new purpose or a new vendor.
- Newsletter sign-up is a deliberate, separate action. It is never bundled with leaving a comment, and we never add an address that was given to us for some other reason.
5. Your rights and how to use them
- Access (Art. 15) — a copy of everything we hold about you, and an explanation of what we do with it
- Rectification (Art. 16) — correction of anything wrong or incomplete
- Erasure (Art. 17) — deletion, where we have no overriding reason to keep it
- Restriction (Art. 18) — freezing our use of your data while a dispute is resolved
- Portability (Art. 20) — the data you gave us, in a structured machine-readable file. We provide CSV or JSON
- Objection (Art. 21) — to anything based on legitimate interests, and to direct marketing at any time, absolutely and without argument
- Withdrawal of consent (Art. 7(3)) — whenever you like, with no effect on what was lawful before
- Automated decisions (Art. 22) — not applicable, since we make none
Making a request
Email [email protected] with the subject “GDPR request”. Tell us which right you want to use and which email address or comment name you used on the site, so we can find you.
| Step | Timing |
|---|---|
| We acknowledge your message | Within 3 working days |
| We verify your identity, proportionately — a reply from the same email address is normally enough | Within 5 working days |
| We give you a full answer | Within one month of receiving the request |
| Extension for complex requests, with our reasons explained to you | Up to two further months — Art. 12(3) |
| Cost | Free. Only a manifestly unfounded or repetitive request could attract a fee, and we would explain why first |
If we ever refuse a request, we will tell you why and remind you that you can complain to a supervisory authority or go to court.
You can also do these yourself, immediately: unsubscribe using the link at the bottom of any newsletter email; change your cookie choices with the “Cookie settings” link in the footer; ask us to delete a comment.
6. The companies that handle data for us
We only use providers that offer adequate guarantees under Article 28, and each is bound by a data processing agreement.
| Provider | Role | Where | Transfer safeguard |
|---|---|---|---|
| Hostinger | Web hosting, backups | United States | Standard Contractual Clauses |
| Cloudflare, Inc. | CDN, security, bot filtering | Global | EU–US Data Privacy Framework and SCCs |
| Google Analytics | United States | EU–US Data Privacy Framework and SCCs | |
| Kit (formerly ConvertKit) | Newsletter delivery | United States | Standard Contractual Clauses |
| Automattic | Akismet spam filtering, Gravatar avatars | United States | Standard Contractual Clauses |
| Advertising network | Not yet appointed | — | To be published before ads launch |
We keep this list current, and we will tell you before we add or replace a provider.
7. International transfers
Because the site is hosted in the United States, data about European visitors leaves the EEA. We rely on the safeguards in Chapter V of the GDPR: adequacy under Article 45 where the provider is certified under the EU–US Data Privacy Framework, and the European Commission’s Standard Contractual Clauses (Decision 2021/914) under Article 46(2)(c), with the UK Addendum where the UK GDPR applies. On top of that, everything is encrypted in transit and we enable IP anonymisation wherever the tool supports it. Copies of the relevant clauses are available on request.
8. Records of processing — Article 30
Article 30(5) exempts organisations with fewer than 250 staff from keeping full records, but only where processing is occasional. A website that receives visitors continuously is not occasional, so the exemption does not really apply to us. We therefore keep an internal record covering the purposes of our processing, the categories of data and of people involved, who receives it, transfers outside the EEA, retention periods and security measures. It is available to any supervisory authority that asks.
9. Privacy by design and by default — Article 25
- Forms ask for the minimum; optional fields are labelled as optional
- IP anonymisation is switched on wherever the service allows it
- Trackers stay off until consent is given — the privacy-protective setting is the default, not something you have to hunt for
- Location metadata is stripped from every photograph before publication
- New plugins and embeds are checked for what they send out before being installed, and anything that phones home without consent is blocked or rejected
- Administrative access is limited to a single account with two-factor authentication
We have not carried out a Data Protection Impact Assessment under Article 35, because our processing is not high risk: no large-scale monitoring, no sensitive data, no decisions with significant effects. We will complete one if that changes — for example if we add reader accounts, saved recipe boxes tied to individuals, or personalised recommendations built on tracked behaviour.
10. If something goes wrong — Articles 33 and 34
If personal data is lost, exposed or accessed without authorisation, our procedure is:
- Contain and assess. Stop the exposure, then work out what data was involved and how risky it is.
- Record. Every incident goes in an internal breach log, whether or not it needs reporting.
- Notify the authority within 72 hours of becoming aware, unless the breach is unlikely to pose a risk to anyone’s rights and freedoms.
- Notify affected people without undue delay where the risk to them is high — in plain language, explaining what happened, what it means for them, what we have done, and who to contact.
- Review afterwards, and change whatever allowed it to happen.
Our providers are contractually required to alert us promptly if a breach happens on their side, so that we can meet these deadlines.
11. Complaints
Please come to us first at [email protected] — most problems are quicker to fix directly.
You also have the right under Article 77 to complain to a supervisory authority, in the EU or EEA country where you live, where you work, or where you think the problem occurred. A directory of authorities is published at edpb.europa.eu. In the United Kingdom, the authority is the Information Commissioner’s Office, ico.org.uk. You may also seek a judicial remedy and compensation for any damage suffered, under Articles 79 and 82.
12. Reviews and changes
We review this page at least once a year, and whenever we add a service, a provider or a new way of earning money from the site — including before display advertising goes live. Changes are dated at the top.
13. Contact
Email: [email protected]
Contact form: kimarecipes.com/contact
Response time: 3 working days to acknowledge, one month for a full answer




