Data Processing Agreement

Last updated: 23 July 2026

1. Parties

This Data Processing Agreement (“DPA”) is entered into between:

  • Controller:the individual or business that has created an account on Kelo (“you” or “the Controller”); and
  • Processor:the operator of Kelo, a sole trader based in England (“Kelo”, “we”, “us”). Contact: [email protected]

This DPA forms part of the terms of service you accepted when creating your account and governs all processing of personal data carried out by Kelo on your behalf.

2. Definitions

The terms “personal data”, “processing”, “data subject”, “controller”, “processor”, and “supervisory authority” have the meanings given in the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“DPA 2018”).

3. Subject matter and purpose

Kelo processes personal data solely to provide you with a revenue operations dashboard, including weekly pipeline tracking, revenue leak analysis, and guided fix flows. Processing is carried out on your documented instructions as set out in this DPA and in the platform itself.

4. Categories of personal data and data subjects

The data processed may include:

  • Account data: your name, business name, email address, industry, and account settings.
  • Business metrics: weekly pipeline figures you enter (enquiries, quotes sent, jobs booked, jobs completed, revenue invoiced, cash collected). These are business figures, not personal data about identifiable individuals, unless you include personal names in free-text fields.
  • Fix flow data: names, values, and contact methods you enter when working through guided fix flows (e.g. names of open quotes or outstanding invoices). You should not enter special category data into any field.

Data subjects: primarily you (the account holder). Fix flow fields may incidentally contain first names or reference codes for your own customers - you are responsible for ensuring you have a lawful basis to enter that data.

Special category data: you must not enter special category data (health, ethnicity, religion, etc.) into Kelo. The platform is not designed or assessed for this purpose.

5. Duration

This DPA applies for the duration of your Kelo subscription. On termination, your data will be deleted within 30 days in accordance with clause 10, unless a longer retention period is required by law.

6. Processor obligations

Kelo shall:

  1. Process personal data only on your documented instructions, unless required to do so by UK law - in which case Kelo will inform you before processing, unless prohibited by law.
  2. Ensure that persons authorised to process the data are bound by appropriate confidentiality obligations.
  3. Take all measures required by Article 32 UK GDPR to ensure appropriate security of the data, including the technical and organisational measures described in clause 8.
  4. Not engage a sub-processor without your prior written consent, except for the sub-processors listed in clause 7 (to which you give general authorisation by accepting this DPA). Kelo will inform you of any intended changes concerning sub-processors, giving you the opportunity to object.
  5. Assist you, by appropriate technical and organisational measures, in fulfilling your obligation to respond to requests by data subjects exercising their rights under Chapter III of UK GDPR.
  6. Assist you in ensuring compliance with Articles 32–36 UK GDPR (security, breach notification, DPIA, prior consultation), taking into account the nature of the processing and information available.
  7. At your choice, delete or return all personal data after the end of the provision of services, and delete existing copies unless UK law requires storage.
  8. Make available to you all information necessary to demonstrate compliance with Article 28 UK GDPR, and allow for and contribute to audits conducted by you or a mandated auditor, subject to reasonable prior notice and confidentiality obligations.
  9. Notify you without undue delay (and in any case within 72 hours where feasible) upon becoming aware of a personal data breach affecting your data.

7. Sub-processors

You authorise Kelo to engage the following sub-processors. Kelo has assessed each for compliance with UK GDPR standards.

Sub-processorPurposeLocationSafeguards
Supabase Inc.Database, authentication, and file storageEU (AWS eu-west-2)Standard Contractual Clauses (SCCs); ISO 27001
Vercel Inc.Application hosting and edge deliveryEU / USSCCs; SOC 2 Type II
Resend Inc.Transactional email delivery (weekly summaries)USSCCs; only email address and content transmitted
Anthropic PBCChase email draft generation. The following invoice data is transmitted: customer name, invoice reference number, amount outstanding (GBP), days overdue, and ICP type. No special-category data is included. Draft text is retained for up to 12 months.USSCCs; data not used to train models under API terms; model: claude-haiku-4-5-20251001

Kelo will notify you of any proposed addition or replacement of a sub-processor with at least 14 days' notice. You may object in writing within that period; if no resolution is reached, you may terminate your subscription without penalty.

8. Technical and organisational security measures

Kelo implements the following measures (Article 32 UK GDPR):

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256 via Supabase)
  • Row-level security (RLS) enforced at database level - each client can access only their own data
  • Supabase Auth for authentication; passwords never stored in plaintext
  • Access to production systems restricted to authorised personnel only
  • Regular dependency and security updates
  • No personal data processed in logs or analytics beyond what is strictly necessary

9. International transfers

Some sub-processors (Vercel, Resend, Anthropic) are based in or transfer data to the United States. Kelo relies on Standard Contractual Clauses (SCCs) as the transfer mechanism under Article 46 UK GDPR / the UK International Data Transfer Agreement (IDTA) where applicable. A copy of the relevant SCCs or IDTAs is available on request.

10. Retention and deletion

Your data is retained for the duration of your active subscription plus 30 days following cancellation, after which it is permanently deleted. You may request immediate deletion at any time by emailing [email protected]. Deletion requests will be fulfilled within 30 days.

11. Your rights as Controller

As data controller, you are responsible for:

  • Having a lawful basis for any personal data you enter into the platform
  • Responding to data subject requests from your own customers
  • Notifying your own customers of how their data is used
  • Ensuring you are registered with the ICO where required

Kelo will assist you in fulfilling data subject access requests, erasure requests, and portability requests relating to data held in the platform. Contact [email protected] to make such a request.

12. Liability and indemnity

Each party shall be liable for the damage caused by processing where it has not complied with UK GDPR obligations specifically directed to processors, or where it has acted outside or contrary to the lawful instructions of the other party. Kelo's liability under this DPA is subject to any limitation of liability set out in the main terms of service.

13. Governing law

This DPA is governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

14. Contact

For any questions about this DPA, data subject requests, or to report a suspected breach, contact: [email protected]

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.