Privacy notice
Privacy notice
This notice explains what personal data Kwilo may collect through the site and product, why it is used, when Kwilo acts as controller or processor, and how people can exercise their rights.
Kwilo is business software for UK service businesses and the people they work with. In this notice, "we", "us" and "our" mean Kwilo Ltd. This notice covers the primary public website at kwilo.co.uk, its official mirror at hellokwilo.com, the product at app.hellokwilo.com, and related support or service communications.
Who is responsible for the data
Kwilo Ltd is the data controller for most account, billing and marketing activity. When Kwilo processes customer, supplier, employee or business-record data for a business using the service, that business generally acts as controller and Kwilo acts as processor. Questions or rights requests can be sent to hello@kwilo.co.uk.
What data we may collect
- Account and identity data, such as name, email address, sign-in details and business role.
- Business data you create in the service, such as customer details, job records, quotes, invoices, notes, documents and communication history.
- Technical and usage data, such as device information, browser data, timestamps, IP-related security information and service logs.
- Support and trust-centre data, such as enquiries, feedback, issue reports and communications with us.
- AI feature inputs and outputs where AI-assisted features are used to help draft, summarise or transcribe content.
How we use personal data
- To provide and secure access to Kwilo.
- To let users manage jobs, quotes, variations, invoices, tax-related workflow and customer communication.
- To operate, support, troubleshoot and improve the service.
- To meet legal, regulatory, tax, accounting and fraud-prevention obligations.
- To send important service messages, policy updates, support responses and account notices.
- To provide AI-assisted features where they are part of the service, subject to human review and appropriate safeguards.
The main legal bases we rely on
- Contract: where processing is needed to provide the service a user or business has asked for.
- Legal obligation: where we must keep records, respond to lawful requests, or comply with tax, accounting or regulatory duties.
- Legitimate interests: where we need to run, secure, support and improve Kwilo in a reasonable way.
- Consent: where consent is the appropriate basis, for example for non-essential cookies or certain optional communications.
Who we may share data with
We may share data with trusted service providers who help us host, secure, support or run Kwilo. We may also share data where the law requires it, for example because of a court order or a lawful request from an authority. If AI features are used, prompts and outputs may be processed by approved model providers working on our behalf.
We do not sell personal data.
International transfers
Some suppliers may process data outside the UK. When that happens, we expect the right safeguards to be in place, such as adequacy decisions or suitable contractual protections.
Retention
While a Workspace is active, we keep the personal data and business records needed to provide, secure and support the service. The business using Kwilo remains responsible for deciding how long its customer, financial and tax records must be kept and for meeting the legal duties that apply to those records.
If the Owner closes a Workspace through the offboarding process, Kwilo provides a complete, usable export of the Workspace records covered by the offboarding bundle and records that the export was delivered. Kwilo then deletes the active Workspace and remaining service copies under its documented deletion and backup schedule. The business is responsible for keeping the exported records for every statutory period that applies to it. There is no single six-year or seven-year period that applies to every business or record type.
After closure, Kwilo keeps only the minimum evidence needed for its own legal, regulatory, security and contractual purposes. This may include contract, billing and dispute records; export-delivery and deletion logs; security, authorisation and consent evidence; and records covered by a specific legal or regulatory hold. If anti-money-laundering record-keeping duties apply directly to a service Kwilo provides, the required customer-due-diligence and supporting transaction records may also be retained.
Kwilo currently schedules its limited offboarding compliance-operation record for deletion after seven years. That record is evidence that the export and deletion process took place; it is not an archive of the closed Workspace or its invoices, expenses, payments, ledger, receipts, HMRC records, customer records or export bundle.
Encrypted backup copies may take longer to expire than data in the active service. They are put beyond ordinary use, expire through the backup-rotation schedule and are not restored except for controlled disaster recovery. If a backup is restored, the Workspace deletion is applied again before the restored service is returned to use. A legal or regulatory hold delays deletion only for the specific evidence covered by that hold.
AI-assisted features
If AI-assisted features are used, they are there to help users work faster, for example by drafting or transcribing content. AI output can be wrong or incomplete, so important content still needs checking before it is sent to customers or relied on for business or tax purposes.
We do not use business data to train public AI models unless that use is explicitly disclosed and authorised.
Your rights
Depending on the circumstances, UK data protection law may give people rights including:
- access to their personal data;
- correction of inaccurate data;
- erasure in some cases;
- restriction or objection in some cases;
- data portability in some cases; and
- the right to complain to the Information Commissioner's Office.
To make a request, email hello@kwilo.co.uk. We may need to verify identity before responding.
Cookies and similar technologies
We use cookies and similar technologies in the ways described in our cookie notice. Non-essential cookies should not be used on the public site unless proper consent has been given first.
Security
We take reasonable technical and organisational steps to protect data against unauthorised access, loss, misuse and disclosure. No online service can promise perfect security, so users should also use strong passwords, manage access properly and think about what they store in the product.
Changes to this policy
We may update this policy from time to time. If the change is important, we should update the date on this page and let people know before any new use of personal data starts where the law requires that.