Vulnerability Disclosure Policy

Last updated: 19 September 2026 — Clickz Ltd trading as Keviq

Our Commitment to Security

At Keviq, operated by Clickz Ltd, we take the security of our website and our customers’ data seriously. We welcome responsible disclosure of any security vulnerabilities found on keviq.uk.

If you believe you have found a security vulnerability on our website, please report it to us as described below. We ask that you act in good faith and give us the opportunity to investigate and address the issue before any public disclosure.

Scope

This policy applies to the keviq.uk website, its customer-facing checkout and account systems, and systems and services that are directly controlled by Clickz Ltd under the Keviq brand.

It does not apply to third-party payment, delivery or platform providers. Vulnerabilities in those services should be reported to the relevant provider.

How to Report a Vulnerability

Please report any security vulnerabilities by emailing us at:

keviquk@keviq.uk

Please include the following information in your report:

  • A clear description of the vulnerability
  • The URL or area of the website affected
  • Steps to reproduce the issue
  • Any potential impact you have identified
  • Your contact details (optional, but helpful if we need to follow up)

What We Will Do

Keviq will review good-faith vulnerability reports, investigate confirmed issues, keep the reporter informed where practical and work to resolve verified vulnerabilities responsibly. No fixed response-time promise is published until the support process has been operationally verified.

Responsible Disclosure Guidelines

We ask that you:

  • Do not access, modify, or delete data that does not belong to you
  • Do not disrupt our services or degrade the user experience for others
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it
  • Do not share details of the vulnerability publicly before we have had a reasonable opportunity to address it
  • Act in good faith at all times

Clickz Ltd does not intend to pursue legal action against researchers who act in good faith, follow this policy, avoid harm, and report vulnerabilities responsibly. Nothing in this policy authorises unlawful access or activity.

Contact

Security reports and policy questions can be sent to:
Clickz Ltd trading as Keviq
Company number: 16454451
Email: keviquk@keviq.uk
Phone: +1 602 894 1330