Privacy Policy
Privacy Policy
STATUS: DRAFT. This document was authored with knowledge of the 4klyft platform's actual data-handling capabilities. It has NOT been reviewed by qualified legal counsel and MUST be reviewed and adjusted by your data-protection lawyer before publication. Jurisdiction-specific language (referenced as [TODO: …]) needs filling in.
>
Last updated: 2026-06-24.
This Privacy Policy explains how [TODO: legal entity name, registration number, registered address] ("4klyft", "we", "us", "our") collects, uses, shares, and protects personal data when you use the 4klyft platform (the "Service") and our public website at 4klyft.com (the "Site").
This Policy is written to comply with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), the UK GDPR, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), and equivalent legislation where it applies to you. Where local law gives you additional rights, those rights still apply.
If you are a customer ("Customer") of 4klyft and you use the Service to process personal data about your own end-users, end-customers, drivers, or any other natural person, you act as the controller of that data and 4klyft acts as a processor on your behalf. The terms of our Data Processing Addendum (./DATA_PROCESSING_ADDENDUM.md) govern that processing. This Privacy Policy governs personal data we collect about you — the customer, the website visitor, the prospective buyer.
Quick summary
We collect three categories of personal data:
1. Account data — name, work email, company, role — when you sign up, request a demo, or contact sales. 2. Service usage data — pages you view, features you use, errors you hit — to operate, secure, and improve the Service. 3. Marketing data — newsletter subscription status, marketing preferences, lead-source attribution — only when you've given consent or where we have a legitimate interest in B2B outreach.
We do not:
- Sell personal data to third parties.
- Share personal data with advertising networks for ad targeting.
- Use personal data to train AI models.
- Process more data than we need to deliver the Service.
You can exercise your rights at any time by emailing privacy@4klyft.com.
1. Who we are
[TODO: legal entity name] is the data controller for personal data covered by this Policy. Our registered address is [TODO: full registered address]. Our company registration number is [TODO: registration number].
We have appointed a Data Protection Officer: [TODO: name OR statement that no DPO is required and contact remains privacy@…]. You can contact our DPO at dpo@4klyft.com.
For EU data subjects whose personal data is transferred outside the EU/EEA, our EU representative under GDPR Article 27 is [TODO: representative name and address].
For UK data subjects, our UK representative under UK GDPR Article 27 is [TODO: representative name and address].
2. What personal data we collect, and why
| Category | What's in it | How we get it | Why we process it | Legal basis (GDPR Art. 6) |
|---|---|---|---|---|
| Identification | Full name, work email, job title, company name, country | You give it to us (signup, demo form, contact form) | Account creation, customer support, contract performance | Contract (Art. 6(1)(b)) for customers; Legitimate interests (Art. 6(1)(f)) for prospects |
| Authentication | Hashed password, MFA secret, OAuth tokens from Google/Apple/Facebook if you sign in via social | You give it to us; OAuth providers return tokens | Logging you in; securing your account | Contract (Art. 6(1)(b)) |
| Billing | Billing address, tax ID/VAT number, last 4 digits of card, Stripe customer ID | You give it to us via the billing flow; Stripe processes the full card number on our behalf and we never see it | Charging you for the Service; tax compliance | Contract + Legal obligation (Art. 6(1)(b) + (c)) |
| Service usage | Pages viewed, features used, API calls made, IP address, browser/OS, device type, timezone, language | Automatically when you use the Service | Operating the Service; debugging; security monitoring; product improvement | Legitimate interests (Art. 6(1)(f)) |
| Support | Messages you send us, screenshots, account context | You give it to us when you contact support | Resolving your support request | Contract + Legitimate interests (Art. 6(1)(b) + (f)) |
| Marketing | Newsletter subscription, marketing email opt-in, source-attribution (which campaign / which referral) | You give it to us via newsletter form or other opt-in; we receive UTM parameters in URLs | Sending you product updates and marketing emails you've opted into | Consent (Art. 6(1)(a)) for cookies and email; Legitimate interests (Art. 6(1)(f)) for B2B outreach to your work email |
| Cookies & analytics | A small set of essential and analytics cookies; see ./COOKIE_POLICY.md | Automatically when you visit the Site | Operating the Site; understanding aggregate traffic patterns | Strictly necessary cookies: legal obligation / legitimate interests. Analytics cookies: consent |
| Recruitment | CV, work history, contact details — if you apply for a job | You give it to us via our careers page | Evaluating your application | Consent + Pre-contractual measures (Art. 6(1)(a) + (b)) |
We never collect special categories of personal data (Art. 9 GDPR — racial origin, political opinions, religious beliefs, health, sexual orientation, biometric/genetic data) unless you explicitly give it to us in a support message — in which case we delete it from the support record once the matter is resolved.
We never collect children's data. The Service is not directed at children under 16, and we do not knowingly process data from anyone under 16. If you become aware that we hold such data, contact us at privacy@4klyft.com and we will delete it.
3. Personal data of your end-users
The Service is logistics infrastructure. When you (the Customer) use it to dispatch shipments, you upload personal data about your own end-customers — typically a recipient name, address, phone number, sometimes a delivery instruction or signature.
For that data:
- You are the data controller. We are the data processor.
- Our processing is governed by the Data Processing Addendum (
./DATA_PROCESSING_ADDENDUM.md), which forms part of our contract with you. - We process recipient personal data only on your documented instructions and for the strict purpose of operating the Service for you (planning routes, generating labels, dispatching to carriers, capturing proof of delivery, and producing audit + reporting records).
- We do not sell, share with third parties for their own purposes, or use this data to train AI models.
- We delete or return this data on contract termination per the DPA.
If you are an end-customer (a delivery recipient) and you want to exercise your data-subject rights, please contact the merchant who shipped your parcel (they are the controller). They will instruct us to act on the request via our DPA.
4. How we use personal data
We use personal data for these purposes:
1. To provide the Service. Creating and securing your account, processing your transactions, delivering features, providing support. 2. To bill you. Generating invoices, processing payments through Stripe, complying with tax law. 3. To communicate with you. Service announcements (uptime incidents, breaking-change deprecations, security advisories), support replies, and marketing emails only with your consent (or where a B2B legitimate-interest basis applies under UK/EU rules). 4. To improve the Service. Aggregate analytics on feature use, A/B testing of UI changes, error tracking. We pseudonymise or aggregate this data wherever possible. 5. To secure the Service. Detecting fraud, abuse, security incidents; rate-limiting; bot detection; investigating violations of our Acceptable Use Policy. 6. To comply with legal obligations. Responding to lawful requests from competent authorities; retaining transaction records for tax law; reporting under sanctions and anti-money-laundering regimes where applicable.
We do not make any automated decision about you under Article 22 GDPR that has legal effect or significantly affects you. The Service's route-optimisation engine optimises driver routes algorithmically, but no automated decision is made about you as a website visitor or prospective customer.
5. Who we share personal data with
We share personal data with a small, named set of subprocessors, only as necessary to operate the Service. Each one is bound by a data-processing agreement and provides at least the level of data protection required by GDPR.
| Subprocessor | What they do for us | Where they process data | Safeguards |
|---|---|---|---|
| Stripe Payments Europe Ltd | Payment processing for subscriptions | Ireland (EU) | DPA; Stripe is PCI-DSS Level 1; SCCs for any sub-transfers |
| Amazon Web Services (AWS) — eu-west-1 / eu-central-1 | Hosting of application data | Ireland and/or Germany (EU) | AWS Data Processing Addendum; SCCs |
| Cloudflare, Inc. | DNS, DDoS protection, CDN for the Site | Global edge network; primary processing EU | Cloudflare DPA; Cloudflare is GDPR-compliant; SCCs for any sub-transfers |
| Sentry GmbH | Error tracking | Germany (EU) | Sentry DPA; PII scrubbing enabled |
| Plausible Analytics | Cookie-free aggregate website analytics | Germany (EU) | Plausible does not use cookies and does not process personal data per GDPR's strict reading |
| Postmark / Mailgun / Resend (pick one) | Transactional email delivery | EU and US — we use EU regional sending where available | DPA; SCCs |
| HubSpot, Inc. (or your CRM) | CRM, marketing email | US, with EU data residency option | Standard Contractual Clauses + additional measures |
| Plaid Inc., GoCardless Ltd. (if used) | Direct-debit / bank-account payments | UK + EU | DPA; SCCs |
| Google Cloud — Maps / Routes APIs | Geocoding, routing, distance matrices | US, with EU edge | Google DPA; SCCs |
| SendCloud B.V. (integration) | Carrier integration — labels and tracking | Netherlands (EU) | DPA; both processors under the Customer's controller relationship |
We may also share personal data with professional advisors (lawyers, accountants, auditors) under their professional confidentiality obligations, and with competent authorities when required by law (subpoena, court order, government request that we are legally bound to respond to). Where the law does not prohibit us from doing so, we will notify the affected data subject before disclosure.
We will share personal data with acquirers in the event of a merger, acquisition, or sale of all or substantially all of our assets, subject to standard confidentiality and continuity-of-processing obligations.
We do not share personal data with advertising networks, social-media platforms for ad targeting, data brokers, or anyone else for their independent commercial purposes.
6. International data transfers
Where personal data is transferred outside the European Economic Area (EEA) or the UK to a country that is not on the European Commission's (or the UK ICO's) list of countries with adequate data protection, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) — and, for transfers from the UK, the UK's International Data Transfer Addendum (IDTA) — together with appropriate supplementary measures.
The countries we transfer to outside the EEA/UK are: the United States (Stripe, Cloudflare, Sentry, HubSpot, Postmark, Google) and [TODO: any others]. For each, we conduct a Transfer Impact Assessment under the Schrems II framework and apply additional safeguards (encryption in transit + at rest, access controls, pseudonymisation where practical, sub-processor flow-down clauses) before the transfer takes place.
You can request the most recent list of subprocessors and the safeguards we apply by emailing privacy@4klyft.com.
7. How long we keep personal data
| Category | Retention period | Why |
|---|---|---|
| Account data (active customer) | Duration of your subscription + 12 months | To allow account recovery and reconciliation |
| Account data (closed account) | Deleted within 90 days of contract termination, except where required for legal retention | Default deletion |
| Billing records | 7 years from invoice date | Tax law (UK + EU baseline) |
| Service usage logs (raw) | 90 days | Then aggregated, identifiers stripped |
| Service usage logs (aggregated) | Indefinitely | No personal data after aggregation |
| Support tickets | 3 years from last activity | For audit + dispute resolution |
| Marketing email subscribers | Until you unsubscribe + 30 days | Confirmation grace period |
| Recruitment applications | 12 months from rejection, then deleted, unless you ask us to keep them on file | Re-evaluation if a similar role opens |
| Cookies | See ./COOKIE_POLICY.md | Per-cookie retention varies |
| Backups | 35 days rolling | Then overwritten |
If a data-subject erasure request is granted, we delete the relevant data from production systems within 30 days. Backups follow the rolling 35-day overwrite cycle and are not separately purged — we instead suppress restoration of the deleted data through documented technical controls.
8. Your rights under GDPR / UK GDPR
If you are an EU or UK data subject, you have these rights:
- Right of access — to be told what personal data we hold about you, and to receive a copy.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure ("right to be forgotten") — to have data deleted where one of the GDPR grounds applies.
- Right to restriction of processing — to have processing paused while a dispute is resolved.
- Right to data portability — to receive your data in a structured, machine-readable format and to have it transmitted to another controller where technically feasible.
- Right to object — to processing based on legitimate interests, and to direct marketing.
- Right not to be subject to automated decision-making — including profiling — that has legal or similarly significant effects.
- Right to withdraw consent — at any time, where consent was the legal basis.
To exercise any of these rights, email privacy@4klyft.com with the request. We will respond within one month of receipt (extendable by two further months for complex requests, with notice). We may ask you for proof of identity before acting on the request.
You also have the right to lodge a complaint with your local data protection authority. For the UK that is the Information Commissioner's Office (ico.org.uk). For the EU it is the supervisory authority in your member state; for residents in [TODO: company HQ jurisdiction] it is [TODO: lead supervisory authority].
9. Your rights under California law (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what categories of personal information we collect, the purposes, and the categories of third parties we share with.
- Access the specific pieces of personal information we hold about you, going back 12 months.
- Delete personal information, subject to certain exceptions (e.g. records required for legal compliance).
- Correct inaccurate personal information.
- Opt out of sale or sharing — although we do not sell personal information as the CCPA defines it, you can confirm this status at any time.
- Limit use of sensitive personal information — we do not collect sensitive personal information as defined by the CPRA.
- Non-discrimination — we will not deny you the Service or charge a different price because you exercised these rights.
To exercise these rights, email privacy@4klyft.com or call [TODO: toll-free number if you have one — required by CCPA above a certain revenue threshold]. We do not require an account to make a request. You may also use an authorised agent; we will ask you to verify the agent's authorisation in writing.
10. Security
We protect personal data with reasonable and appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2+ for all client-to-server and server-to-server traffic).
- Encryption at rest for all production databases and object stores.
- Role-based access control for production systems; no engineer has standing access to customer personal data without an audited approval flow.
- Audit logging of every operator action inside the platform.
- Multi-factor authentication required for all employee access to production systems.
- Network isolation — production database access is restricted to application servers within the same VPC.
- Dependency scanning + SAST on every commit.
- Annual penetration testing by a third-party firm.
- Bug bounty programme — see
[TODO: security.txt URL]. - Security incident response — we maintain a documented incident response plan and conduct annual tabletop exercises.
Despite our best efforts, no security measure is perfect. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33, and we will notify affected data subjects without undue delay if the breach is likely to result in a high risk to your rights and freedoms (Article 34).
For more on our security posture, see our Security page at 4klyft.com/security.
11. Cookies and similar technologies
We use cookies and similar technologies on the Site. The categories, their purposes, and how to manage them are described in our Cookie Policy (./COOKIE_POLICY.md). Essential cookies are set without consent because they are strictly necessary to operate the Site. Analytics and marketing cookies are only set after you give consent via the cookie banner.
12. Changes to this Policy
We may update this Policy from time to time. When we do, we will:
- Update the "Last updated" date at the top.
- Maintain the previous version on a publicly accessible archive at
4klyft.com/legal/privacy/archive. - For material changes — those that broaden how we use personal data — notify active customers by email at least 30 days before the change takes effect.
13. How to contact us
- For general privacy questions:
privacy@4klyft.com - For DPO matters:
dpo@4klyft.com - For security incident reports:
security@4klyft.com - Postal mail: [TODO: legal entity full postal address]
If you contact us and we have not responded within one month, you have the right to lodge a complaint with your supervisory authority. We hope it won't come to that.