Last updated: 26 July 2026
This policy explains what personal data Vokio collects, why, how it is protected, and the rights you have over it. It is written to meet the UK GDPR and the Data Protection Act 2018.
Vokio is a live-interaction platform (anonymous-style suggestion boxes, live quizzes and word clouds) operated by Seb Nastarowicz, trading as dotright ("we", "us", "our"). We are the data controller for the personal data described in this policy.
Two groups use Vokio:
Purpose: to create and secure your account and let you operate the platform. Lawful basis: performance of a contract / our legitimate interest in providing the service.
Purpose: to run the live session and show results. Lawful basis: our legitimate interest in delivering the interactive session you chose to join.
Purpose: security, fraud/abuse prevention and accountability. Lawful basis: our legitimate interest in keeping the service and its users safe, and our legal obligation to secure personal data.
Vokio uses only essential and preference cookies - no analytics, advertising or tracking cookies. Full details are in our Cookie Policy.
We do not sell your data or use it for advertising. We share it only with the service providers we need to run Vokio, acting as our processors:
We may also disclose data if required by law or to protect our legal rights.
Our hosting and database are located in the United Kingdom, so your core data is not transferred abroad. Where a provider processes data outside the UK - for example our email provider within the EU - we rely on a UK adequacy decision or the UK International Data Transfer Agreement/Addendum to keep your data protected to UK standards.
Under UK data protection law you have the right to access your data; to have inaccurate data corrected; to have your data erased; to restrict or object to processing; and to data portability. To exercise any of these, email sebnastarowicz@dotright.co.uk. We will respond within one month.
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, though we would welcome the chance to resolve any concern first.
We apply appropriate technical measures, including: encryption of traffic over HTTPS; passwords stored using strong one-way hashing (never in plain text); protection against cross-site request forgery; brute-force lockouts; role-based access controls; and a hardened content security policy.
Administrator accounts must use two-factor authentication. You may choose to skip the code prompt on a device you have marked as trusted; this does not switch two-factor authentication off, lasts at most 30 days, and can be revoked by you at any time.
Vokio is intended for use in workplace and event settings and is not directed at children. If a session is run with participants under 13, the session organiser is responsible for obtaining any consent required.
We may update this policy from time to time. The "last updated" date above shows when it last changed. Material changes affecting administrators will be notified where practical.