1. Who we are and our data-protection roles
Trelyqo is a release-operations product provided by Keephy. When Keephy decides why and how personal data is processed for its own purposes—such as account administration, security, billing, product communications or website operation—Keephy acts as controller.
When a Customer determines why personal data is placed into a Trelyqo workspace and Keephy processes that data to provide the Services on the Customer’s instructions, the Customer is generally controller and Keephy acts as processor. The Data Processing Addendum describes those processor obligations.
2. Scope
This notice applies to visitors, account holders, authorised users, prospective customers, contacts, support requesters and others whose personal data Keephy controls in connection with Trelyqo. It does not replace a Customer’s own privacy notice for personal data that the Customer controls.
3. Categories of personal data
- Identity and contact: name, work email, organisation, role, username and contact details.
- Authentication and account: login identifiers, SSO identifiers, role, permissions, workspace membership and security events. Passwords should be stored using appropriate one-way security mechanisms when production authentication is enabled.
- Workspace operational data: team, platform, release ownership, rota assignment, absence/availability, cover arrangements, demo-hosting information, comments, configuration and audit history.
- Device and technical: IP address, browser/device type, timestamps, diagnostics, security logs, network information and limited first-party website events such as page views or key call-to-action interactions.
- Support and communications: support messages, contact-form content, feedback and related correspondence.
- Commercial: plan, billing contact, invoices, transaction status and tax information when paid services are introduced. Payment-card data should be handled by an authorised payment provider rather than stored directly by Trelyqo where possible.
- Preferences: workspace branding, theme, notification and marketing choices.
4. Sources of personal data
We may receive personal data directly from you, from your employer or workspace administrator, from authentication/integration providers you choose to connect, from service providers, and automatically through security and technical operation of the Services.
5. Purposes and lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Create and administer accounts; provide requested service | Contract or steps at your request before contract; legitimate interests for organisation-managed business accounts where appropriate. |
| Security, fraud prevention, abuse detection, logging and service integrity | Legitimate interests; legal obligation where applicable. |
| Billing, tax, accounting and contractual administration | Contract and legal obligation. |
| Support, product operation and service improvement | Contract and/or legitimate interests depending on context. |
| Legal claims, compliance and lawful authority requests | Legal obligation and legitimate interests. |
| Optional direct marketing where consent is required | Consent; otherwise another lawful basis only where applicable law permits. |
Where we rely on legitimate interests, we consider whether the processing is necessary and whether individual rights override those interests.
6. Customer-controlled workspace data
Customers may add employees, contractors and release-operational information to Trelyqo. The Customer is responsible for its notices, lawful bases, data minimisation, accuracy, access controls, retention decisions and use of that data. Keephy processes it as described in the DPA where Keephy acts as processor.
Customers should not use Trelyqo as a general repository for special-category data, health data, criminal-offence data, government identifiers, passwords, financial-account credentials or other highly sensitive information unless expressly supported and lawfully configured.
7. Automation, recommendations and future AI features
Trelyqo may introduce automation, analytics or AI-assisted features in the future. Unless expressly stated otherwise, such features are intended to assist human users and should not be treated as the sole basis for legal, employment, safety, security or other high-impact decisions. If Keephy introduces processing that triggers specific automated-decision obligations, this notice and relevant controls will be updated before that processing is deployed.
8. Sharing and recipients
We may share personal data with infrastructure, cloud, authentication, communications, support, analytics, security, professional-adviser and payment providers where necessary. We may also disclose data to affiliates, potential acquirers under appropriate confidentiality, authorities where legally required, and parties needed to establish, exercise or defend legal claims.
A maintained list of material processors/subprocessors is available at Subprocessors.
9. International transfers
Providers may process data outside the United Kingdom or the country where the user is located. Where UK data-protection law restricts a transfer, Keephy will use an available lawful transfer mechanism where required, such as adequacy regulations, an approved International Data Transfer Agreement/Addendum or another lawful safeguard, together with supplementary measures where appropriate.
10. Retention
| Data | General approach |
|---|---|
| Account data | While active, then for a reasonable period needed for account closure, security, disputes and legal obligations. |
| Workspace data | According to Customer instructions, contract, backup cycles and retention settings, subject to legal requirements. |
| Security logs | For a proportionate period needed for prevention, detection, investigation and evidential integrity. |
| Billing/tax records | For statutory accounting and tax periods. |
| Marketing choices | Until withdrawn, plus minimal suppression data needed to respect opt-out. |
11. Security
Keephy uses technical and organisational measures designed to protect personal data appropriate to the nature of the service and risk. No internet service can promise absolute security. More detail is provided in the Security page and, where applicable, contractual security schedules.
12. Individual rights
Depending on applicable law and circumstances, rights may include access, correction, erasure, restriction, objection, portability, withdrawal of consent and rights relating to certain automated decisions. Rights are subject to legal conditions and exemptions.
For Customer-controlled workspace data, requests may need to be directed to the relevant Customer first. Keephy will provide processor assistance where legally required.
13. Marketing
Marketing consent is separate from service access and, where consent is required, optional. You can unsubscribe or withdraw consent at any time. Keephy may retain minimal suppression information so an opt-out is respected.
14. Children
Trelyqo is a business service and is not directed to children. Customers must not knowingly create accounts for children or use Trelyqo to process children’s data unless the use has been expressly agreed and all applicable legal requirements are met.
15. Contact, complaints and changes
Contact Keephy through the Trelyqo contact page for privacy requests or questions. Individuals in the UK may complain to the Information Commissioner’s Office at ico.org.uk.
We may update this notice as the Services, providers or law change. Material changes will be notified where required.