Privacy Policy
- Introduction
- Who We Are
- Services Covered
- Information We Collect
- How We Use Information
- Lawful Bases
- Customer Data
- Mobile App Data
- Location Data
- Audit Logs
- Cookies
- Sharing
- International Transfers
- Retention
- Security
- Your Rights
- Children
- Complaints
- Changes
- Contact
1. Introduction
Kraylo Ltd (“Kraylo”, “we”, “our” or “us”) provides cloud-based business management software for organisations that manage inventory, sales, customers, products, vehicles, drivers, orders, banking submissions, approvals, weekly reports and operational reporting through a web dashboard and iOS mobile application.
This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you access kraylo.co.uk, use the Kraylo web application, use the Kraylo iOS application, communicate with support, or otherwise interact with our services.
2. Who We Are
Kraylo Ltd is a company operating under the laws of England and Wales. For website visitors, account administration, support communications, product analytics and our own business operations, Kraylo normally acts as a data controller. For personal information entered into the platform by a customer organisation, Kraylo normally acts as a data processor and processes that information on the customer's behalf.
Where your employer, client or organisation gives you access to Kraylo, that organisation may also provide its own employee, driver, customer or business privacy notices.
3. Services Covered
This policy applies to kraylo.co.uk, the Kraylo web dashboard, the Kraylo iOS mobile application, support services and any related Kraylo services that link to this policy. It covers features including company administration, role-based access, driver management, product and stock records, orders, banking records, banking approvals, weekly reports, image uploads, audit logs, reporting and offline synchronisation.
4. Information We Collect
| Category | Examples | Purpose |
|---|---|---|
| Account information | Name, email address, telephone number, company, role, login credentials, user status. | Account creation, authentication, access control and support. |
| Organisation information | Company name, business contact details, operational settings and configuration. | Tenant setup and service administration. |
| Customer records | Customer names, business names, delivery addresses, phone numbers, email addresses, notes and order history. | Customer management, ordering and delivery operations. |
| Product and inventory data | Product names, SKUs, prices, categories, stock quantities, stock transfers and adjustments. | Inventory and stock management. |
| Order data | Orders, line items, quantities, prices, discounts, approvals, status, delivery notes and customer instructions. | Order fulfilment, approvals and reporting. |
| Driver and vehicle data | Driver names, assigned vehicles, sales records, banking submissions, weekly reports and operational activity. | Field operations, accountability and reporting. |
| Banking records | Deposit amounts, banking dates, receipt images, approval status, review notes, reviewer identity and timestamps. | Operational cash control and approval workflows. Kraylo does not provide banking services or card payment processing. |
| Uploaded files | Receipt images, product photos, supporting documents and operational attachments. | Evidence capture, record keeping and review workflows. |
| Technical data | IP address, device type, browser, operating system, app version, crash logs, performance data. | Security, troubleshooting and service improvement. |
5. How We Use Information
We use personal information to provide, operate, maintain, secure and improve Kraylo. This includes authenticating users, enforcing permissions, supporting multi-tenant company data isolation, processing customer instructions, creating and updating records, synchronising mobile data, supporting approvals, generating reports, detecting abuse, diagnosing errors, communicating with customers, complying with legal obligations and protecting the rights and safety of Kraylo, customers and users.
6. Lawful Bases
Where UK GDPR applies, our lawful bases may include contract, legitimate interests, legal obligation and consent where required. For customer-controlled platform data, the customer determines the lawful basis and Kraylo processes data as processor under the customer's instructions.
| Processing activity | Typical lawful basis |
|---|---|
| Providing SaaS services and user accounts | Contract or legitimate interests |
| Security logging and fraud prevention | Legitimate interests and legal obligation |
| Support communications | Contract or legitimate interests |
| Required accounting or legal records | Legal obligation |
| Non-essential cookies or analytics where used | Consent where legally required |
7. Customer Data and Processor Role
Customer Data belongs to the customer organisation. Kraylo processes Customer Data only to provide the service, comply with documented instructions, maintain security, provide support, meet legal obligations, or as otherwise permitted by the applicable agreement. Customers are responsible for ensuring that they have appropriate notices, lawful bases and permissions for data they enter into Kraylo.
8. Mobile Application Data
The iOS app may process authentication status, assigned driver data, route or operational records, orders, stock, banking submissions, receipt images, offline synchronisation state, app diagnostics and device details. Mobile submission functionality is designed for authorised business users and may store data temporarily on the device to support offline use until synchronisation completes.
9. Location Data
If enabled by a customer organisation and permitted at device level, Kraylo may process location information for operational purposes such as delivery verification, route oversight, driver activity records and reporting. Location use should be configured by the customer in accordance with its employment, contractor and privacy obligations.
10. Audit Logs
Kraylo maintains audit logs for significant platform actions, including approvals, rejections, banking reviews, record changes, login events, permission changes and administrative activity. Audit logs may contain user identifiers, timestamps, affected records, action types, review notes and company identifiers. Audit logs support accountability, security investigations, compliance and operational integrity.
11. Cookies and Similar Technologies
Kraylo may use strictly necessary cookies for authentication, session security, user preferences and service operation. Where non-essential cookies or similar technologies are used, we will provide appropriate notice and obtain consent where required by law. Further details are available in the Kraylo Cookie Policy.
12. How We Share Information
We do not sell personal information. We may share information with hosting providers, authentication providers, email and support tools, analytics providers, professional advisers, regulators, law enforcement where legally required, and subprocessors needed to operate Kraylo. Providers are required to protect personal information and use it only for authorised purposes.
13. International Transfers
Where personal information is transferred outside the United Kingdom or European Economic Area, Kraylo will use appropriate safeguards, such as adequacy regulations, standard contractual clauses, UK international data transfer mechanisms or other lawful transfer tools where applicable.
14. Data Retention
We retain personal information only for as long as necessary for the purposes described in this policy, to provide the service, comply with legal obligations, resolve disputes, enforce agreements and maintain security. Customer Data retention may be controlled by the customer organisation. Audit logs, security logs and financial records may be retained for longer where required for compliance, security or dispute purposes.
15. Security
Kraylo uses technical and organisational measures designed to protect personal information, including HTTPS/TLS encryption in transit, secure authentication, role-based access control, company-level data separation, audit logging, access controls, secure cloud infrastructure, backups where configured, monitoring and least-privilege administrative access. No system is completely secure, and customers must also protect their own accounts and devices.
16. Your Rights
Depending on your location and the applicable lawful basis, you may have rights to access, correct, erase, restrict, object to processing, request portability, withdraw consent, and complain to a supervisory authority. Where Kraylo acts as processor, requests relating to Customer Data should usually be directed to the customer organisation that controls the data.
Right to object: Where processing is based on legitimate interests, you may have the right to object. We will consider your request in accordance with applicable law.
17. Children
Kraylo is intended for business use and is not directed at children under 16. Customers should not create accounts for children or intentionally upload children's personal information unless they have a lawful basis and appropriate safeguards.
18. Complaints
You may contact us first at support@kraylo.co.uk. You also have the right to complain to the UK Information Commissioner's Office if you believe your data protection rights have been infringed.
19. Changes to this Policy
We may update this Privacy Policy to reflect legal, technical or product changes. Material changes will be communicated through reasonable means, such as website notice, platform notice or email.
20. Contact
Kraylo Ltd
Website: https://kraylo.co.uk
Email: support@kraylo.co.uk