kraylo← Back to site
Legal & Trust Centre

Data Processing Agreement

Version 1.0Effective: [Launch Date]

Contents
  1. Purpose
  2. Roles
  3. Instructions
  4. Confidentiality
  5. Security
  6. Subprocessors
  7. International Transfers
  8. Data Subject Rights
  9. Security Incidents
  10. Audit
  11. Deletion and Return
  12. Annex A Processing Details
  13. Annex B Security Measures
  14. Annex C Subprocessors

1. Purpose

This Data Processing Agreement (“DPA”) forms part of the agreement between Kraylo Ltd and the Customer and applies where Kraylo processes personal data on behalf of the Customer in connection with the Services.

2. Roles of the Parties

The Customer is the controller of Customer Personal Data. Kraylo is the processor. Each party will comply with applicable data protection laws, including the UK GDPR and Data Protection Act 2018.

3. Processing on Documented Instructions

Kraylo will process Customer Personal Data only on the Customer's documented instructions, including through the Agreement, this DPA, product configuration, user actions and support requests, unless required otherwise by applicable law.

4. Confidentiality

Kraylo will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and access Customer Personal Data only where required for authorised purposes.

5. Security Measures

Kraylo will implement appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and accidental loss, destruction or damage. Measures include access controls, encryption in transit, role-based permissions, tenant separation, audit logging, monitoring and secure infrastructure practices.

6. Subprocessors

Customer authorises Kraylo to use subprocessors necessary to provide the Services. Kraylo will impose data protection obligations on subprocessors that are materially equivalent to those in this DPA. Kraylo will maintain a subprocessor list and provide notice of material changes where required.

7. International Transfers

Kraylo will not transfer Customer Personal Data internationally unless appropriate safeguards are in place, such as adequacy regulations, standard contractual clauses, UK international data transfer agreements or other lawful transfer mechanisms.

8. Assistance with Data Subject Rights

Taking into account the nature of processing, Kraylo will provide reasonable assistance to the Customer for responding to data subject rights requests. Where Kraylo receives a request directly relating to Customer Personal Data, Kraylo may refer the requester to the Customer unless legally required to respond.

9. Security Incidents

Kraylo will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notification will include available information reasonably required for the Customer to meet its legal obligations, subject to investigation status and confidentiality considerations.

10. Audit and Information

Kraylo will make available information reasonably necessary to demonstrate compliance with this DPA. Audits must be reasonable, proportionate, subject to confidentiality, and must not compromise the security or confidentiality of other customers or systems.

11. Return or Deletion

At the end of the Services, Kraylo will delete or return Customer Personal Data in accordance with the Agreement, product functionality and legal requirements, unless retention is required by law or necessary for legitimate security, audit or dispute purposes.

12. Annex A — Processing Details

Subject matterProvision of Kraylo business management software.
DurationFor the term of the Agreement and applicable retention periods.
Nature and purposeHosting, storage, transmission, retrieval, support, synchronisation, reporting, security and maintenance.
Data subjectsCustomer users, administrators, managers, drivers, sales staff, customer contacts, delivery recipients and support contacts.
Data categoriesAccount data, customer contact data, order data, inventory records, banking evidence, operational notes, audit logs, images and technical metadata.
Special categoriesNot intentionally collected or required by Kraylo.

13. Annex B — Technical and Organisational Measures

14. Annex C — Subprocessors

Kraylo may use cloud hosting, authentication, database, email, support and monitoring providers required to operate the Services. A live subprocessor list should be maintained at /legal/subprocessors before enterprise launch.