Privacy policy

Last updated 31 August 2026. This says what we hold, why we hold it, and who else touches it. It is deliberately specific — a policy that lists no names tells you nothing.

Two different people, two different situations

Klosum holds data about two groups, and they have different relationships with us:

For homeowner data, the contractor is the controller and we are the processor. We hold it on their instruction. If you are a homeowner asking us to change or remove your details, contact the contractor who did the work — they can do it themselves in seconds, and we will help them if they ask.

What we hold about users

What we hold about homeowners

We do not hold homeowner payment details. We never have.

Why we hold it

To provide the service the contractor is paying for: producing a defensible record of an installation, warning about deadlines that are about to be missed, and issuing the certificate the homeowner keeps. The lawful basis is performance of a contract, and our legitimate interest in keeping the service secure and auditable.

The certificate link

When a certificate is emailed, it contains a link that opens that one record without a login. That link is cryptographically signed and is scoped to a single installation at a single company — it cannot be edited to reach another record, another job number, or another company. Anyone holding the link can view that one certificate, so treat it like the document it is.

Who else processes it

WhoWhat they doWhat they see
NetlifyHosting and data storage Everything, at rest and in transit
BrevoSends certificate and password-reset emails Recipient address and the contents of that email
StripeCard billing, where used Billing details. Card numbers go to Stripe directly and never reach us
Your agencyResells and supports your account Your company and user records, and your usage. Not your homeowners' records

We do not sell data. We do not share it for advertising. We do not use your installation records to train machine-learning models.

Where it lives

On Netlify's infrastructure in the United States. If you are outside the US, your data is transferred there to provide the service.

How long we keep it

Cookies

One cookie, set when you sign in, to keep you signed in. No analytics, no advertising, no third-party trackers, no tracking pixels in the emails. There is no cookie banner because there is nothing to consent to.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Contractors do not need to ask for a copy — the export button gives you everything, whenever you want, without a request. Write to us and we will respond within 30 days.

Security

Every request is served over HTTPS. Passwords are hashed, never stored or logged in the clear. Company data is scoped so one company cannot read another's records, and that is tested by outside testers rather than assumed. Changing your password signs out every other device. If we ever suffer a breach affecting your data, we will tell you and the relevant authority without delay.

Children

This is a tool for trade businesses. It is not directed at children and we do not knowingly collect their data.

Contact

PMV Digital — brian@pmvdigitalmarketing.com. Homeowners should contact the contractor who did the work; they control the record.