Now booking projects for Q1 2027 LET'S TALK →

Purpose

Kickass Online Ltd ("KO") is committed to the highest standards of openness, integrity, and accountability. This policy provides a mechanism for employees to raise concerns about wrongdoing in confidence, and confirms that KO will not retaliate against anyone who raises a concern in good faith.

What is Whistleblowing?

Whistleblowing (or making a 'protected disclosure') is the reporting of suspected wrongdoing or dangers in the workplace, including: criminal activity; breach of a legal obligation; miscarriage of justice; danger to health and safety; damage to the environment; or deliberate cover-up of any of the above. A concern must be raised in the public interest (not solely a personal grievance, which should be dealt with via the Grievance Procedure).

Legal Protections

Under the Public Interest Disclosure Act 1998, workers who make a qualifying disclosure are protected from dismissal, detriment, or victimisation. KO will not tolerate any retaliation against an employee who raises a concern in good faith.

How to Raise a Concern

Confidentiality

All concerns raised under this policy will be treated in confidence. The identity of the discloser will be protected to the extent possible, having regard to the need to investigate.

Unfounded Concerns

If an investigation establishes that a concern was raised maliciously or without reasonable grounds, disciplinary action may be considered.

Policy Review

This policy will be reviewed annually.

Last reviewed: May 2026.

Join the Kickass Online Affiliate Programme

Partner with a digital agency that delivers real results — and get rewarded every time you refer a client who signs with us.

Whether you're a marketing consultant, web designer, IT provider, business advisor, or simply well-connected, our affiliate programme offers straightforward, generous commission for quality referrals.


How It Works

Refer a business to Kickass Online. If they become a client, you earn commission — it's that simple. We handle everything else: the sales conversation, the onboarding, the delivery, and the ongoing relationship. Your job is the introduction.


Commission Structure

Project-based work (websites, one-off builds): Choose the structure that works for you at the point of referral:

Retainer and ongoing services (SEO, maintenance, automation):

Tiered bonus:


Terms and Conditions

Eligibility: The programme is open to individuals and businesses based in the UK and internationally, subject to KO's approval. KO reserves the right to decline any application without explanation.

Referral process: Referrals must be submitted via the affiliate referral form or notified to KO in writing before KO has had any prior contact with the referred business. Retrospective referral claims will not be accepted.

Payment trigger: Commission becomes payable only once the referred client has signed a contract with KO and KO has received the relevant payment from that client (deposit for project work; first monthly payment for retainers). No commission is payable on prospects who do not proceed to a paid engagement.

Recurring commission: The 5% monthly retainer commission applies for the first 12 months of a referred client's retainer only, unless a separate written extension is agreed with KO. Commission on retainers ceases immediately if the client cancels their retainer, reduces to a level below the original referred scope, or if the affiliate agreement is terminated.

Clawback: If a referred client cancels and receives a full or partial refund within 60 days of their contract start date, any commission paid in respect of that client will be subject to clawback from the next commission payment. KO will notify the affiliate before any clawback is applied.

Payment: Commission payments are made via bank transfer or PayPal within 30 days of the end of the month in which the payment trigger is met. A minimum payment threshold of £50 applies per transaction. International bank transfers require a minimum of £100 due to transaction fees. KO does not cover PayPal or transfer fees.

Disclosure: Affiliates must disclose their commercial relationship with KO whenever promoting KO's services, in accordance with the ASA/CAP Code and UK consumer protection law. Failure to disclose a commercial relationship when promoting KO may result in termination of the affiliate agreement.

Tax and legal status: Affiliates are independent of KO and are solely responsible for declaring and paying any tax on commission received. Participation in this programme does not create an employment, agency, or partnership relationship between the affiliate and KO.

Confidentiality: Affiliates must not disclose confidential information about KO, its clients, or its pricing to third parties.

Termination: Either party may terminate the affiliate agreement with 30 days' written notice. On termination, commission already earned on payments received by KO before the termination date will be paid in the normal payment cycle. No further commission will accrue after the termination date, including recurring retainer commission.

Changes to terms: KO reserves the right to amend these terms with 30 days' written notice to active affiliates. Continued participation after the notice period constitutes acceptance of the updated terms.

Governing law: This agreement is governed by the laws of England and Wales.


How to Apply

Fill out the affiliate application form and our team will review your submission. Approved applicants will be invited to an onboarding call with our director. Once onboarded, you'll receive your unique referral link and access to our marketing materials.

Questions? Email us at info@kickassonline.com

Please wait while the policy is loaded. If it does not load, please click here.
Please wait while the policy is loaded. If it does not load, please click here.
Please wait while the policy is loaded. If it does not load, please click here.

Purpose

Kickass Online Ltd ('KO') is committed to protecting the personal data of its employees, clients, suppliers, and other individuals. This policy sets out how KO complies with the UK General Data Protection Regulation (UK GDPR) as retained and amended by the Data Protection Act 2018 (DPA 2018).

Data Protection Principles

KO processes all personal data in accordance with the following UK GDPR principles:

  1. Lawfulness, fairness, and transparency
  2. Purpose limitation — collected for specified, explicit, legitimate purposes only
  3. Data minimisation — adequate, relevant, and limited to what is necessary
  4. Accuracy — kept up to date
  5. Storage limitation — not kept longer than necessary
  6. Integrity and confidentiality — appropriate security
  7. Accountability — KO can demonstrate compliance

Lawful Basis for Processing

KO will identify and document an appropriate lawful basis for each category of processing. For employee data, the most common bases are: performance of a contract (e.g. payroll); legal obligation (e.g. right-to-work checks); and legitimate interests (e.g. network security monitoring).

Special Category Data

Processing of special category data (including health data, racial or ethnic origin, and trade union membership) requires an additional condition under UK GDPR Art.9, most commonly explicit consent or the employment law exemption. Such data will be processed with heightened security measures.

Data Retention

Personal data will be retained only for as long as necessary for the purpose for which it was collected, and in compliance with legal obligations. Indicative retention periods:

Data Subject Rights

Individuals have the following rights under UK GDPR, which KO will fulfil within the statutory timeframes (generally 1 month): Right of access; Rectification; Erasure ('right to be forgotten'); Restriction of processing; Data portability; Objection to processing; and rights related to automated decision-making.

Data Breach Notification

Supervisory Authority

The UK supervisory authority for data protection matters is the Information Commissioner's Office (ICO). Individuals who believe their data protection rights have not been respected may raise a complaint with the ICO at ico.org.uk.

Data Protection Lead

KO has appointed a Data Protection Lead: Panagiotis Zmpigknief Zavatzki (pazbi@kickassonline.com).

Note: as KO does not currently meet the UK GDPR criteria for a mandatory Data Protection Officer (Art.37), this role is a voluntary lead position.

Policy Review

This policy will be reviewed annually or when legislation changes.

Last reviewed: May 2026.

Purpose

This policy governs the secure and responsible use of information technology, communications systems, and personal devices at Kickass Online Ltd (‘KO’). As a fully remote team, all staff use their own devices to carry out company work. This policy establishes the minimum security standards required, reflects KO’s obligations under UK law, and protects both the company and its employees, clients, and data.

Scope

This policy applies to all employees, contractors, and freelancers working for KO who access company systems, data, or communications — regardless of location or device ownership. It covers all personal devices used for work purposes (BYOD), all KO-provisioned accounts, and all company data however stored.

Legal Framework

This policy is issued in compliance with and with reference to:

PART A — IT & COMMUNICATIONS POLICY

1. Acceptable Use

KO’s IT and communications systems — including Google Workspace, project management tools, and all company accounts — are provided primarily for business purposes. Reasonable personal use is permitted provided it does not:

Employees remain subject to this policy when accessing company systems outside normal working hours.

2. Google Workspace

Google Workspace is KO’s primary productivity and communications platform. All employees are issued a KO Google Workspace account (@kickassonline.com). The following rules apply:

3. Email and Communications Etiquette

4. Internet Use

5. Software and Applications

6. Data Security and Confidentiality

7. Monitoring Notice

KO may, from time to time and in accordance with the Investigatory Powers Act 2016 and Regulation of Investigatory Powers Act 2000, monitor activity on company-provided accounts and systems (including Google Workspace, email, and any other KO-administered service). Such monitoring may include:

Monitoring will only be carried out for legitimate business purposes including: security investigation, compliance with legal obligations, or where there is reasonable suspicion of a policy breach. Employees are notified of this possibility by the existence of this policy. Content monitoring of personal devices or personal accounts is not carried out.

8. Reporting

9. Training

All employees will receive IT security awareness training on induction and at least annually thereafter. This will cover phishing awareness, password hygiene, UK GDPR obligations, and safe use of company tools.

PART B — BRING YOUR OWN DEVICE (BYOD) POLICY

10. Overview

As a fully remote team, all KO employees use their own personal devices — laptops, desktops, tablets, and smartphones — to carry out their work. This section sets out the minimum security requirements that all personal devices used for KO work must meet.

By using a personal device to access KO systems, data, or communications, employees agree to comply with the requirements in this section. Non-compliance may result in access being suspended or withdrawn, and may lead to disciplinary action.

Important: KO does not have remote management (MDM) software installed on personal devices. Security compliance is therefore based on trust and self-attestation, verified periodically by the line manager.

11. Mandatory Device Requirements

The following requirements are mandatory for any personal device used to access KO systems or data:

FULL-DISK ENCRYPTIONAll devices must have full-disk (device) encryption enabled. On Windows: BitLocker. On macOS: FileVault. On iOS/Android: enabled by default when a device passcode is set. Encryption must be active at all times.
DEVICE PASSCODE / PASSWORDAll devices must be protected by a strong passcode, PIN, or password. Biometric unlock (fingerprint / Face ID) is permitted as a secondary method but must not be the sole means of access. Auto-lock must be set to 5 minutes or less of inactivity.
ANTIVIRUS / ENDPOINT SECURITYAll Windows and macOS devices must have reputable, up-to-date antivirus / endpoint protection software installed and active. Recommended: Malwarebytes, Bitdefender, or equivalent. Real-time scanning must be enabled. iOS and Android devices are exempt from this specific requirement but must meet all other requirements.
OPERATING SYSTEM UPDATESOperating systems and all work-related applications must be kept up to date. Security patches must be applied within 14 days of release. Employees must not use end-of-life operating systems (e.g. Windows 10 after October 2025, older macOS versions no longer receiving security updates).
SCREEN LOCKDevices must be set to lock automatically after a maximum of 5 minutes of inactivity, requiring re-authentication to resume.

12. Password Management — LastPass

KO requires all employees to use LastPass as the company’s approved password manager for all work-related accounts.

Never store the LastPass master password in the vault itself, in a browser, or as a note on your device.

13. Multi-Factor Authentication (MFA)

Multi-factor authentication (MFA) is mandatory on all KO work accounts. There are no exceptions.

Google Workspace admins: enforce MFA organisation-wide via the Google Admin Console (Admin → Security → 2-Step Verification → Enforcement). This should be set to ‘On’ for all users with no exceptions.

14. Google Workspace Security Settings

Because Google Workspace is KO’s primary platform, the following security settings must be maintained:

15. Network Security

16. Personal and Company Data Separation

Recommended: Set up a dedicated work browser profile in Chrome signed in to your KO Google account. This keeps bookmarks, extensions, passwords (via LastPass), and history separate from personal browsing.

17. Lost, Stolen, or Compromised Devices

18. Compliance, Attestation & Audits

On joining KO, and annually thereafter, employees must confirm in writing (via the HR onboarding or annual review process) that their devices meet the requirements of this policy. The compliance checklist below summarises the mandatory requirements:

RequirementMandatoryApplies To
Full-disk encryption enabledYESAll devices
Device passcode / strong password setYESAll devices
Auto-lock set to 5 minutes or lessYESAll devices
Antivirus / endpoint protection installed and activeYESWindows / macOS
Operating system up to date (patches within 14 days)YESAll devices
LastPass installed and KO vault in useYESAll staff
All work passwords stored in LastPass (16+ chars, unique)YESAll staff
MFA enabled on Google WorkspaceYESAll staff
MFA enabled on LastPassYESAll staff
MFA enabled on all other work accountsYESAll staff
MFA method: authenticator app (not SMS only)YESAll staff
Separate browser profile for work (Chrome recommended)RecommendedAll staff
Home Wi-Fi using WPA2/WPA3 encryptionYESAll staff
VPN in use on public Wi-FiYESAll staff
Company data stored in Google Drive only (not personal cloud)YESAll staff

19. Privacy of Personal Devices

KO recognises that employees use their own devices and respects their personal privacy. Accordingly:

20. Departures and Offboarding

When an employee leaves KO, the following steps will be completed on or before the last working day:

Retention of company data, client information, or KO credentials after departure may constitute a breach of the Computer Misuse Act 1990 and/or the UK GDPR, and KO reserves the right to take appropriate action.

Policy Compliance

Compliance with this policy is a condition of employment. Failure to comply may result in:

Employees who are uncertain about any aspect of this policy should contact their line manager before taking any action.

Policy Review

This policy will be reviewed annually or when there are material changes to KO’s technology stack, working arrangements, or applicable legislation.

Last reviewed: May 2026.

magnifiercross
Secret Link