Privacy policy
Written in plain English. Company details in square brackets are still being completed. This privacy policy explains what personal data we hold about you, why we hold it and what you can ask us to do with it.
This privacy policy covers the Klusko website at klusko.com and the Klusko web app at app.klusko.com. It follows the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), as amended by the Data (Use and Access) Act 2025.
We’ve tried to keep it short. Where something is uncertain or still being set up (billing, for one), we say so.
1. Who we are
Klusko is run by [Company name] Ltd, a company registered in England and Wales, company number [number], registered office [address]. We’re registered with the Information Commissioner’s Office under ICO registration number [ZA000000].
In this policy, “we”, “us” and “Klusko” mean [Company name] Ltd. “You” means anyone whose personal data we handle: a visitor to the website, a person with a Klusko account, or someone who emails us.
For anything about privacy, your data or a complaint, email privacy@klusko.com. For everything else, it’s hello@klusko.com.
2. The two roles we play
Data protection law splits organisations into controllers, who decide why and how personal data is used, and processors, who handle it on a controller’s behalf. We are both, depending on the data.
We are the controller for:
- data about visitors to klusko.com
- account data (your name, email address and sign-in details)
- billing and contact details for the company that holds the account
- emails and support messages you send us
We are a processor for the content your company puts in its Klusko workspace. That means tasks, comments, chat messages, files, and the names and email addresses of the people your company invites. Your company is the controller for that content, and we handle it under our data processing terms.
So if you’re a member of a workspace and you want to know what’s held about you in it, or want something removed, ask your company first. If you come to us, we’ll pass the request to your company and help it respond.
3. What we collect
When you visit klusko.com, your browser sends our servers the technical details every browser sends to load a page: IP address, browser type and the page requested. We use them to deliver the page and keep the site secure. The website sets no cookies, runs no analytics and loads no advertising pixels, and we host our fonts ourselves, so your visit isn’t reported to Google or anyone else. If you type your email into a sign-up box on klusko.com, it’s passed to the web app in the link so the sign-up form is filled in for you; nothing is stored on the website itself.
When you create or join an account, we collect:
- your name and email address
- your password, which is stored only in hashed form (we can’t read it)
- your company name, your role (Admin or Member) and which projects you’ve been added to
- settings you choose, such as your theme
- technical data from using the app: IP address, browser and device type, and sign-in times
When billing launches, we’ll also collect billing contact details and invoice information for the account. Card details will go to our payment provider, not to us. Billing isn’t live yet, so we don’t collect any of this today.
When you email us, we keep the email, your address and anything you include.
If you open GIF search in chat, the search terms you type and your IP address go to GIPHY so it can return results. Nothing goes to GIPHY unless you open GIF search.
4. Why we use it, and our lawful basis
The law says we need a lawful basis for each use. Here are ours.
Contract. We use your account data to create your account, sign you in, run the service your company signed up for and send the emails the service depends on: sign-up confirmations, invitations and password resets.
Legitimate interests. We have a legitimate interest in:
- keeping Klusko secure, for example by logging sign-ins and spotting unusual activity
- preventing fraud and abuse
- sending service emails, such as notice of a change to our terms or prices
- improving the product using aggregate usage, such as how many teams use each project view
We’ve weighed these against your interests. None of them involves profiling you or selling anything to you, and you can object (see section 9).
Legal obligation. We keep some records because tax and accounting law requires it.
Consent. If we ever send optional marketing emails, such as product news, we’ll only send them if you’ve agreed. Every one will have an unsubscribe link, and unsubscribing takes one click.
A few things we don’t do. We don’t sell personal data. We don’t use it for advertising. We don’t use your content to train AI models. And we don’t make decisions about you by automated means that have legal or similarly significant effects.
5. Who we share it with
We use a small number of providers (subprocessors) to run Klusko:
- Supabase Inc.: database, sign-in and file storage, hosted on Amazon Web Services in Frankfurt, Germany
- Railway Corporation: hosting and delivery of the web app, in the United States
- Resend: transactional email, such as confirmation, invitation and password-reset emails, in the United States
- GIPHY: GIF search in chat, only when a user opens it, in the United States
Each provider only gets the data it needs for its job, under a contract that requires it to protect that data. The full list, with what each one receives, is on our subprocessors page. When billing launches we’ll add a payment provider, with 30 days’ notice.
We’ll also disclose data if the law requires us to, for example in response to a court order. If we ever sell or restructure the business, the data would pass to the new owner, who would have to follow this policy.
6. Transfers outside the UK
Workspace content, account data and files are stored in the EU, in Frankfurt. The UK recognises the EU and EEA as giving adequate protection, so no extra safeguards are needed for data stored there.
Some providers are in the United States. For transfers to them, we rely on the UK Extension to the EU-US Data Privacy Framework (the “UK-US data bridge”) where the provider is certified under it. Where a provider isn’t certified, we use the EU Standard Contractual Clauses with the ICO’s International Data Transfer Addendum. You can ask us for a copy of the relevant safeguards at privacy@klusko.com.
7. How long we keep it
- Account and workspace data: for as long as the account is open.
- After an account is closed: we delete workspace content within 30 days, and it rotates out of our backups within 90 days.
- Support emails: 2 years after the conversation ends.
- Records needed for tax or to deal with legal claims: up to 6 years, and only the minimum needed.
People in your company can delete their own messages and files, and tasks can be deleted or archived, at any time before then.
8. How we protect it
Data is encrypted in transit (TLS) and at rest. Each company’s data is kept separate from other companies’ by row-level security in the database, so one account can’t read another’s rows. Passwords are hashed.
No system is perfectly secure. If a personal data breach happens and it’s likely to put people’s rights at risk, we’ll report it to the ICO within 72 hours of becoming aware of it, and we’ll tell the people affected without undue delay where the risk is high. For workspace content, we’ll tell your company as its processor. There’s more on our security page. To report a security problem, email security@klusko.com.
9. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you and get a copy
- have inaccurate data corrected
- have data erased
- restrict how we use it
- object to our use of it, including any use based on legitimate interests and any direct marketing
- data portability: get data you gave us in a common machine-readable format, or have it sent to another organisation
- withdraw consent at any time, where we rely on consent (this doesn’t affect what we did before)
Some rights have limits. For example, we may need to keep a record for tax even after you ask us to delete it. If we can’t do what you ask, we’ll tell you why.
To use a right, email privacy@klusko.com. We may ask you to confirm your identity first. We’ll reply within one month of receiving your request (or of confirming your identity, if we had to ask). If a request is complicated, or you’ve sent several, we can extend that by up to two more months, and we’ll tell you within the first month if we need to. There’s normally no charge.
If your request is about content in a company’s workspace, we’ll refer you to that company, because it’s the controller. We’ll help it respond.
10. Complaints
If you’re unhappy with how we’ve handled your data, please tell us first at privacy@klusko.com. Put “Complaint” in the subject line so it reaches the right person quickly. You can send it by email, which is the fastest way.
Since 19 June 2026, the Data (Use and Access) Act 2025 has given everyone the right to complain directly to a controller about how it uses their data. When you complain to us, we will:
- acknowledge your complaint within 30 days of receiving it
- take appropriate steps to respond to it without undue delay, including looking into it and keeping you updated
- tell you the outcome without undue delay
You can also complain to the UK regulator. The Information Commissioner’s Office (ICO) becomes the Information Commission on 30 September 2026. Its website is ico.org.uk and its helpline is 0303 123 1113. The regulator will usually expect you to have raised the complaint with us first, but you don’t have to wait for us to finish before contacting it.
11. Who Klusko is for
Klusko is for businesses, charities and other organisations. You must be 18 or over to use it, and we don’t knowingly collect data about children. If you think a child has given us personal data, email privacy@klusko.com and we’ll delete it.
12. Cookies and local storage
The website sets no cookies. The web app uses your browser’s local storage to keep you signed in and to remember the theme you picked. Our cookie policy has the details and explains how to clear them.
13. Changes to this policy
If we change how we use personal data, we’ll update this page and the date at the top. If a change affects what happens to your data, we’ll email account Admins before it takes effect. Spotted something that doesn’t match what Klusko does? Tell us at privacy@klusko.com.
14. Contact
- Privacy, data rights and complaints: privacy@klusko.com
- Security issues: security@klusko.com
- Everything else: hello@klusko.com
By post: [Company name] Ltd, [address].