kraylo← Back to site
Legal & Trust Centre

Privacy Policy

Version 1.0Effective: [Launch Date]Last Updated: [Launch Date]

This Privacy Policy is written for Kraylo Ltd and kraylo.co.uk. Privacy enquiries should be sent to support@kraylo.co.uk until a dedicated privacy email is established.
Contents
  1. Introduction
  2. Who We Are
  3. Services Covered
  4. Information We Collect
  5. How We Use Information
  6. Lawful Bases
  7. Customer Data
  8. Mobile App Data
  9. Location Data
  10. Audit Logs
  11. Cookies
  12. Sharing
  13. International Transfers
  14. Retention
  15. Security
  16. Your Rights
  17. Children
  18. Complaints
  19. Changes
  20. Contact

1. Introduction

Kraylo Ltd (“Kraylo”, “we”, “our” or “us”) provides cloud-based business management software for organisations that manage inventory, sales, customers, products, vehicles, drivers, orders, banking submissions, approvals, weekly reports and operational reporting through a web dashboard and iOS mobile application.

This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you access kraylo.co.uk, use the Kraylo web application, use the Kraylo iOS application, communicate with support, or otherwise interact with our services.

2. Who We Are

Kraylo Ltd is a company operating under the laws of England and Wales. For website visitors, account administration, support communications, product analytics and our own business operations, Kraylo normally acts as a data controller. For personal information entered into the platform by a customer organisation, Kraylo normally acts as a data processor and processes that information on the customer's behalf.

Where your employer, client or organisation gives you access to Kraylo, that organisation may also provide its own employee, driver, customer or business privacy notices.

3. Services Covered

This policy applies to kraylo.co.uk, the Kraylo web dashboard, the Kraylo iOS mobile application, support services and any related Kraylo services that link to this policy. It covers features including company administration, role-based access, driver management, product and stock records, orders, banking records, banking approvals, weekly reports, image uploads, audit logs, reporting and offline synchronisation.

4. Information We Collect

CategoryExamplesPurpose
Account informationName, email address, telephone number, company, role, login credentials, user status.Account creation, authentication, access control and support.
Organisation informationCompany name, business contact details, operational settings and configuration.Tenant setup and service administration.
Customer recordsCustomer names, business names, delivery addresses, phone numbers, email addresses, notes and order history.Customer management, ordering and delivery operations.
Product and inventory dataProduct names, SKUs, prices, categories, stock quantities, stock transfers and adjustments.Inventory and stock management.
Order dataOrders, line items, quantities, prices, discounts, approvals, status, delivery notes and customer instructions.Order fulfilment, approvals and reporting.
Driver and vehicle dataDriver names, assigned vehicles, sales records, banking submissions, weekly reports and operational activity.Field operations, accountability and reporting.
Banking recordsDeposit amounts, banking dates, receipt images, approval status, review notes, reviewer identity and timestamps.Operational cash control and approval workflows. Kraylo does not provide banking services or card payment processing.
Uploaded filesReceipt images, product photos, supporting documents and operational attachments.Evidence capture, record keeping and review workflows.
Technical dataIP address, device type, browser, operating system, app version, crash logs, performance data.Security, troubleshooting and service improvement.

5. How We Use Information

We use personal information to provide, operate, maintain, secure and improve Kraylo. This includes authenticating users, enforcing permissions, supporting multi-tenant company data isolation, processing customer instructions, creating and updating records, synchronising mobile data, supporting approvals, generating reports, detecting abuse, diagnosing errors, communicating with customers, complying with legal obligations and protecting the rights and safety of Kraylo, customers and users.

6. Lawful Bases

Where UK GDPR applies, our lawful bases may include contract, legitimate interests, legal obligation and consent where required. For customer-controlled platform data, the customer determines the lawful basis and Kraylo processes data as processor under the customer's instructions.

Processing activityTypical lawful basis
Providing SaaS services and user accountsContract or legitimate interests
Security logging and fraud preventionLegitimate interests and legal obligation
Support communicationsContract or legitimate interests
Required accounting or legal recordsLegal obligation
Non-essential cookies or analytics where usedConsent where legally required

7. Customer Data and Processor Role

Customer Data belongs to the customer organisation. Kraylo processes Customer Data only to provide the service, comply with documented instructions, maintain security, provide support, meet legal obligations, or as otherwise permitted by the applicable agreement. Customers are responsible for ensuring that they have appropriate notices, lawful bases and permissions for data they enter into Kraylo.

8. Mobile Application Data

The iOS app may process authentication status, assigned driver data, route or operational records, orders, stock, banking submissions, receipt images, offline synchronisation state, app diagnostics and device details. Mobile submission functionality is designed for authorised business users and may store data temporarily on the device to support offline use until synchronisation completes.

9. Location Data

If enabled by a customer organisation and permitted at device level, Kraylo may process location information for operational purposes such as delivery verification, route oversight, driver activity records and reporting. Location use should be configured by the customer in accordance with its employment, contractor and privacy obligations.

10. Audit Logs

Kraylo maintains audit logs for significant platform actions, including approvals, rejections, banking reviews, record changes, login events, permission changes and administrative activity. Audit logs may contain user identifiers, timestamps, affected records, action types, review notes and company identifiers. Audit logs support accountability, security investigations, compliance and operational integrity.

11. Cookies and Similar Technologies

Kraylo may use strictly necessary cookies for authentication, session security, user preferences and service operation. Where non-essential cookies or similar technologies are used, we will provide appropriate notice and obtain consent where required by law. Further details are available in the Kraylo Cookie Policy.

12. How We Share Information

We do not sell personal information. We may share information with hosting providers, authentication providers, email and support tools, analytics providers, professional advisers, regulators, law enforcement where legally required, and subprocessors needed to operate Kraylo. Providers are required to protect personal information and use it only for authorised purposes.

13. International Transfers

Where personal information is transferred outside the United Kingdom or European Economic Area, Kraylo will use appropriate safeguards, such as adequacy regulations, standard contractual clauses, UK international data transfer mechanisms or other lawful transfer tools where applicable.

14. Data Retention

We retain personal information only for as long as necessary for the purposes described in this policy, to provide the service, comply with legal obligations, resolve disputes, enforce agreements and maintain security. Customer Data retention may be controlled by the customer organisation. Audit logs, security logs and financial records may be retained for longer where required for compliance, security or dispute purposes.

15. Security

Kraylo uses technical and organisational measures designed to protect personal information, including HTTPS/TLS encryption in transit, secure authentication, role-based access control, company-level data separation, audit logging, access controls, secure cloud infrastructure, backups where configured, monitoring and least-privilege administrative access. No system is completely secure, and customers must also protect their own accounts and devices.

16. Your Rights

Depending on your location and the applicable lawful basis, you may have rights to access, correct, erase, restrict, object to processing, request portability, withdraw consent, and complain to a supervisory authority. Where Kraylo acts as processor, requests relating to Customer Data should usually be directed to the customer organisation that controls the data.

Right to object: Where processing is based on legitimate interests, you may have the right to object. We will consider your request in accordance with applicable law.

17. Children

Kraylo is intended for business use and is not directed at children under 16. Customers should not create accounts for children or intentionally upload children's personal information unless they have a lawful basis and appropriate safeguards.

18. Complaints

You may contact us first at support@kraylo.co.uk. You also have the right to complain to the UK Information Commissioner's Office if you believe your data protection rights have been infringed.

19. Changes to this Policy

We may update this Privacy Policy to reflect legal, technical or product changes. Material changes will be communicated through reasonable means, such as website notice, platform notice or email.

20. Contact

Kraylo Ltd
Website: https://kraylo.co.uk
Email: support@kraylo.co.uk