Privacy notice
Version 2026-09-07.1 · effective 7 September 2026
Who we are
Keldra is a construction accountability platform. Each customer organisation is the data controller for the project data it puts into Keldra and for the people it names in that data. Keldra operates as the processoracting on that organisation’s instructions.
If you want your data removed and you know which contractor entered it, they are the fastest route. If you do not, contact us and we will identify the controlling organisation and pass the request on.
What we hold
- Names, email addresses and job roles of people working on a project.
- Records of commissioning work: tasks, blockers, asset tags, gate sign-offs, and who was responsible for each.
- Email sent through and into the platform — sender, recipient, subject, body and attachments — where it relates to a tracked task.
- Notes, comments and photographs uploaded against site work.
- For account holders: sign-in details and access history.
Keldra does not use personal data for advertising, does not sell it, and does not use customer data to train machine-learning models.
Sub-processors
These are the third parties that process personal data on Keldra’s behalf, the region they operate in, and the basis for any transfer outside the UK/EEA.
| Processor | Purpose | Region | Data shared | Transfer basis |
|---|---|---|---|---|
| Supabase | Primary database, authentication and file storage | eu-west-1 (Ireland) | All account and project data: names, email addresses, task and blocker records, email content, uploaded files | Stored in the EU — no transfer out |
| Vercel | Application hosting and serverless execution | Serverless compute in Dublin (eu-west); edge routing worldwide | Data in transit through the application, plus request metadata (IP address, user agent) | Compute co-located with the database in the EU; edge routing may terminate TLS outside the UK/EEA under Standard Contractual Clauses |
| Resend | Outbound chase email and inbound email capture | United States | Recipient and sender email addresses, subject lines, message bodies, attachments | Standard Contractual Clauses |
| Google (Gemini API) | Generating project insights and summarising task email threads | United States | Blocker descriptions, asset identifiers, the names of people responsible for work, and email thread content submitted for summarising | Standard Contractual Clauses |
Insight and summary features send project content — including the names of people responsible for work — to Google’s Gemini API. If your organisation would rather that did not happen, those features can be turned off per organisation; ask your administrator.
How long we keep it
| Data | Kept for | Notes |
|---|---|---|
| Inbound email content (subject and body) | 12 months from receipt | Automatically purged nightly. The record that an email was received, and when, is kept. |
| Account details (name, email address, role) | For as long as the account exists | Erased on request or when the account is deleted. |
| Commissioning accountability record (blocker events, asset tag events, gate sign-offs) | Retained for the life of the project record | Append-only and cryptographically chained. Retained under Art 17(3)(e) for the establishment, exercise or defence of legal claims; not erased on request. See 'What we cannot erase'. |
| Contact lists, rosters and pending invitations | Until removed by the organisation, or on erasure request | Deleted outright. |
Your rights
Under UK and EU data protection law you can ask for a copy of your data, ask for it to be corrected, ask for it to be erased, object to how it is used, or complain to a supervisory authority (in the UK, the Information Commissioner’s Office).
To exercise any of these, contact the organisation that entered your data, or email us and we will route it. We respond within one month.
What we cannot erase, and why
Keldra keeps a tamper-evident record of commissioning decisions: who accepted responsibility for a piece of work, who signed off a gate, when a blocker was raised and by whom. Those records are append-only and cryptographically chained — each entry is sealed against the one before it, so that the record can be trusted months later in a dispute.
Editing a name out of that chain would break it, and would defeat the purpose of keeping it. So when an erasure request is carried out, we remove contact details, account details, rosters, pending invitations and email content — but the accountability record itself is retained. We rely on Article 17(3)(e) of the UK/EU GDPR: retention necessary for the establishment, exercise or defence of legal claims.
Every erasure we perform records exactly what was removed and what was retained, so that you can be told precisely what remains rather than being given a vague answer.
Security
Data is encrypted in transit and at rest. Each organisation’s data is isolated at the database level, and that isolation is tested by an automated suite that attempts cross-organisation access on every audit. Access to production is limited and logged.
Changes to this notice
When this notice changes materially we publish a new version number. Consent recorded against an earlier version is not treated as agreement to a later one.