Privacy policy
Last updated 31 August 2026. This says what we hold, why we hold it, and who else touches it. It is deliberately specific — a policy that lists no names tells you nothing.
Two different people, two different situations
Klosum holds data about two groups, and they have different relationships with us:
- Users — contractors, office staff, technicians and agency staff who sign in.
- Homeowners — the customers of those contractors. A homeowner never signs in. Their details are on the record because the installation happened at their property.
For homeowner data, the contractor is the controller and we are the processor. We hold it on their instruction. If you are a homeowner asking us to change or remove your details, contact the contractor who did the work — they can do it themselves in seconds, and we will help them if they ask.
What we hold about users
- Name, email address, role and which company you belong to.
- A password, stored only as a salted PBKDF2 hash. We cannot read it and neither can anyone else.
- A session cookie while you are signed in. It is HttpOnly, Secure and SameSite=Strict, and it carries no personal data — only an opaque token.
- An audit record of actions taken on installation records: who, what changed, when.
- Failed sign-in counts and the source address, kept briefly, so that passwords cannot be guessed at machine speed.
What we hold about homeowners
- Name, installation address, and — only if the contractor enters one — an email address, used to send the certificate.
- Photographs of the installed equipment taken by the technician.
- A signature, where the homeowner signed on screen to accept the work, with the time it was taken.
- Equipment details, permit and inspection references, warranty and rebate status.
We do not hold homeowner payment details. We never have.
Why we hold it
To provide the service the contractor is paying for: producing a defensible record of an installation, warning about deadlines that are about to be missed, and issuing the certificate the homeowner keeps. The lawful basis is performance of a contract, and our legitimate interest in keeping the service secure and auditable.
The certificate link
When a certificate is emailed, it contains a link that opens that one record without a login. That link is cryptographically signed and is scoped to a single installation at a single company — it cannot be edited to reach another record, another job number, or another company. Anyone holding the link can view that one certificate, so treat it like the document it is.
Who else processes it
| Who | What they do | What they see |
|---|---|---|
| Netlify | Hosting and data storage | Everything, at rest and in transit |
| Brevo | Sends certificate and password-reset emails | Recipient address and the contents of that email |
| Stripe | Card billing, where used | Billing details. Card numbers go to Stripe directly and never reach us |
| Your agency | Resells and supports your account | Your company and user records, and your usage. Not your homeowners' records |
We do not sell data. We do not share it for advertising. We do not use your installation records to train machine-learning models.
Where it lives
On Netlify's infrastructure in the United States. If you are outside the US, your data is transferred there to provide the service.
How long we keep it
- Installation records and photographs — for as long as the contractor keeps the account, because a warranty claim can arrive ten years after the work.
- After an account closes — at least 30 days to export, then deletion.
- Audit records — kept after a record is deleted. An audit trail you can erase is not an audit trail.
- Password reset links — one hour, single use, destroyed when used.
- Failed sign-in counters — minutes.
Cookies
One cookie, set when you sign in, to keep you signed in. No analytics, no advertising, no third-party trackers, no tracking pixels in the emails. There is no cookie banner because there is nothing to consent to.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Contractors do not need to ask for a copy — the export button gives you everything, whenever you want, without a request. Write to us and we will respond within 30 days.
Security
Every request is served over HTTPS. Passwords are hashed, never stored or logged in the clear. Company data is scoped so one company cannot read another's records, and that is tested by outside testers rather than assumed. Changing your password signs out every other device. If we ever suffer a breach affecting your data, we will tell you and the relevant authority without delay.
Children
This is a tool for trade businesses. It is not directed at children and we do not knowingly collect their data.
Contact
PMV Digital — brian@pmvdigitalmarketing.com. Homeowners should contact the contractor who did the work; they control the record.