Privacy Policy
This Privacy Policy explains how Klyro Ltd (“Klyro”, “we”) handles personal data. It applies to the Klyro platform used by UK trade businesses, to their customers using the customer portal, and to visitors of klyro.ai.
1. Who we are
Klyro Ltd is a company registered in England and Wales. For personal data about the businesses that subscribe to Klyro and their users (engineers, office staff) we act as the data controller. For personal data about those businesses’ own customers (homeowners and commercial clients whose details are entered into Klyro) we act as the data processor, processing only on the instructions of the Tenant who is the controller.
2. What we collect
- Account data. Name, email address, phone number, role, business name, trading address, VAT number, Gas Safe registration number and other trade certifications. We collect this when you sign up or when your employer invites you to the platform.
- Usage data. Device and browser type, IP address, and server request logs. Used to keep the service secure and to diagnose errors. We do not run any third-party analytics or tracking on the Klyro app.
- Communications. Content of support chats, emails you send us, and feedback submissions. Used to help you and to improve the product.
- Location data. For engineers who have opted in, real-time location during scheduled working hours. Off-duty location is not captured.
- Customer-portal data. If your trade business uses Klyro, we process the personal data they hold about you (name, address, appointment history, certificates). We process this on their instructions and their Privacy Policy applies alongside ours.
- Accounting integration data. If a Tenant connects Xero or QuickBooks Online, we sync the minimum data needed for bookkeeping: customer/contact names, email and postal addresses where present, invoice numbers, line descriptions, quantities, prices, VAT/tax codes, payment amounts and dates, Stripe processing fees, Klyro platform fees, credit notes, reconciliation references, and chart-of-account names or codes used for mapping.
To close a Klyro account in the app, or to request deletion when you cannot sign in, see our account deletion page.
3. Why we collect it — legal bases
Under UK GDPR we need a legal basis for each use of your personal data. The bases we rely on are:
- Contract. To provide the Klyro service to you or your employer — signing you in, storing jobs, sending reminders, billing.
- Legitimate interest. To keep the service secure (fraud detection, rate-limiting), to debug errors (Sentry telemetry), and to contact you about service-critical changes. We have carried out a legitimate interests assessment for each of these.
- Consent. For marketing emails and engineer-location tracking. You can withdraw consent at any time (see section 7).
- Legal obligation. Where we’re required by law — for example keeping invoice records for HMRC, or responding to valid data-subject requests.
4. Third-party sub-processors
We share personal data with a small set of sub-processors that help us run the service. Every sub-processor has signed a data-processing agreement with us. Where a sub-processor is based outside the UK (for example in the US), we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses to ensure an adequate level of protection. Accounting providers only receive Tenant data when the Tenant chooses to connect that integration.
| Sub-processor | Purpose | Region |
|---|---|---|
| Stripe Payments Europe Ltd | Payment processing and subscription billing | Ireland / US (UK IDTA) |
| Xero group companies | Optional accounting sync for invoices, contacts, payments, fees, account mappings and reconciliation references | UK / New Zealand / global support locations (Xero transfer safeguards) |
| Intuit / QuickBooks Online | Optional accounting sync for invoices, contacts, payments, fees, account mappings and reconciliation references | UK / US / global support locations (UK IDTA / UK Addendum) |
| Twilio | SMS delivery | US (UK IDTA) |
| sms-works | SMS delivery (UK) | United Kingdom |
| Resend | Transactional email | US (UK IDTA) |
| Cloudflare R2 | File storage (photos, certificates, signed documents) | United Kingdom |
| Sentry | Error and performance telemetry | US (UK IDTA) |
| OpenStreetMap (OSRM) | Drive-time routing between jobs. Address only — no customer identifiers. | European Union |
| TomTom / Mapbox | Alternative routing when a Tenant configures their own API key | Netherlands / US (UK IDTA) |
| Google Maps / OSM tiles | Map tile rendering for the customer portal and schedule map | US / EU |
Xero and QuickBooks access is authorised by the Tenant using OAuth. We store OAuth tokens encrypted at rest, use them only to perform the requested sync and reconciliation activity, and attempt to revoke the grant when the Tenant disconnects the integration. Disconnecting stops future syncs from Klyro; records already written inside Xero or QuickBooks remain subject to that provider’s own retention and deletion controls.
We’ll notify Tenants 30 days in advance before adding a new sub-processor. If you object on reasonable data-protection grounds, you can terminate your subscription for a pro-rata refund of the remaining prepaid term.
5. Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you (a subject access request);
- Rectify inaccurate or incomplete data;
- Eraseyour data (the “right to be forgotten”), subject to legal retention obligations;
- Port your data in a machine-readable format;
- Restrict or object to certain processing, including processing based on legitimate interest or for direct marketing;
- Withdraw consent at any time for processing we rely on consent for.
To exercise any of these rights, email [email protected]. We’ll respond within one month. If your personal data is held by Klyro on behalf of a trade business (a Tenant), we’ll normally pass your request to them as the data controller and confirm back to you.
If you’re not happy with how we handle your data you can complain to the UK Information Commissioner’s Office at ico.org.uk/concerns.
6. Cookies & tracking
We use only a small number of strictly necessary cookies. We do not run any optional analytics, advertising, or tracking cookies, so no cookie consent banner is needed.
- Essential. Sign-in session cookies (
klyro-token,klyro-portal), CSRF and security cookies, and a preference cookie for your light/dark mode choice. These don’t require consent because they are strictly necessary for the service you’ve asked for.
If we ever introduce optional analytics or any other non-essential cookie, we will first add a consent banner so you can choose whether to allow it, and we will update this Policy before that happens.
7. Retention
- Active account data is kept for as long as your account is active.
- After termination we keep your data in read-only form for 30 days so you can export it, then begin deletion. All customer-identifiable records are deleted within 90 days.
- Invoices and financial records are retained for 6 years from the end of the relevant accounting period, as required by HMRC.
- Engineer location data is retained for 90 days, then deleted (aggregated statistics may be kept indefinitely).
- Support and legal correspondence is retained for 6 years to comply with limitation periods.
- Sentry error telemetry is retained for 90 days.
8. Children
Klyro is a B2B platform. It is not intended for use by anyone under 18. We do not knowingly collect personal data from children. If you believe a child’s data has been submitted to Klyro, please contact us and we will delete it.
9. Changes to this Policy
We version this Policy using a privacy-YYYY-MM string. The current version is privacy-2026-07. On material changes we bump the version string and prompt existing users to re-accept through an in-app banner. Non-substantive changes (clarifications, typos) are published here without a version bump.
10. Contact
Privacy questions: [email protected].
Our data protection point of contact is the Klyro Privacy Team at the address above. We do not currently meet the UK GDPR threshold for a statutory Data Protection Officer, but we review that position annually.
