Privacy Center
Privacy Policy
Effective Date: 5 February 2026 | Version 1.0
1. Introduction
Keplor Limited ("Keplor", "we", "our", or "us") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, share, and protect your information when you access or use the Keplor platform, our website (keplor.io), and any associated services (collectively, the "Services").
Keplor is a deal advisory and development platform for renewable project finance. Our Services are designed for institutional investors, fund managers, project developers, sponsors, and other professional participants in the infrastructure and energy sectors.
If you have any questions, you may contact our Privacy Officer at privacy@keplor.io.
2. Data Controller
For the purposes of the UK GDPR and EU GDPR, the data controller is:
Keplor Limited
20 Eastbourne Terrace
London W2 6LG
United Kingdom
Privacy Officer: privacy@keplor.io
Where Keplor processes personal data on behalf of an enterprise customer, Keplor acts as a data processor, governed by our Data Processing Agreement ("DPA").
3. Personal Data We Collect
3.1 Data You Provide Directly
- Account Registration: Full name, email address, organisation name, and job title or role.
- Profile Information: Telephone number, professional biography, or profile photograph.
- Project and Deal Data: Information relating to infrastructure projects, assets, deals, financial models, and other professional documentation.
- Communications Data: Email communications and meeting transcripts you explicitly authorise via integrations.
- Correspondence: Messages, feedback, support requests, or other communications sent to us.
3.2 Data Collected Automatically
- Usage Analytics: Pages visited, features used, session duration, click patterns, and navigation paths.
- Device and Technical Data: IP address, browser type, operating system, device identifiers, screen resolution, and language preferences.
- Cookies: See our Cookie Policy for full details.
- Log Data: Access times, referring URLs, and error logs.
3.3 Data We Do Not Collect
- Passwords (managed via secure third-party identity providers)
- Payment card numbers or bank account details
- Special category data (unless incidentally contained in uploaded documents)
- Data from children under 18
4. Legal Bases for Processing
| Legal Basis | Processing Activity |
|---|---|
| Contract Performance (Art. 6(1)(b)) | Account creation, platform access, service delivery |
| Legitimate Interest (Art. 6(1)(f)) | Analytics, security, product improvement, fraud prevention |
| Consent (Art. 6(1)(a)) | Marketing communications, optional integrations, non-essential cookies |
| Legal Obligation (Art. 6(1)(c)) | Regulatory compliance, tax records, legal requests |
5. How We Use Your Personal Data
Service Delivery: Account management, authentication, platform access, data processing, analytical outputs, and collaboration.
Communications: Responding to enquiries, service-related notifications, and marketing communications (with your consent).
Analytics: Understanding usage patterns, improving functionality, developing new features, and monitoring performance.
Security: Detecting fraud and abuse, enforcing our Terms of Service, and complying with applicable laws.
6. Data Sharing and Third-Party Processors
Keplor does not sell, rent, or trade your personal data. We share data only as necessary with carefully selected sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Infrastructure, storage, compute | Europe West 2 (London) |
| Mixpanel | Product analytics | EU data residency |
| Resend | Email delivery | United States |
We may also share data where required by law, to protect rights and safety, in connection with business transfers, or with your explicit consent.
7. International Data Transfers
Your personal data is stored by default in Google Cloud Platform's Europe West 2 region (London, UK). Where we transfer data outside the UK or EEA, we ensure appropriate safeguards including:
- Adequacy Decisions by the UK Secretary of State or European Commission
- UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses
- Supplementary measures including encryption, pseudonymisation, and access controls
8. Data Security
Technical Measures:
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Row-Level Security ensuring each user can only access authorised data
- Dedicated infrastructure option for Enterprise customers
- Role-based access controls and multi-factor authentication
- Comprehensive audit logs and automated monitoring
Organisational Measures:
- All personnel bound by confidentiality obligations
- Regular security assessments and vulnerability testing
- Incident response plan with 72-hour breach notification
9. Data Retention
| Data Category | Retention Period |
|---|---|
| Account information | Duration of account + 12 months |
| Project and deal data | Deleted within 30 days of account closure |
| Communications data | Deleted within 30 days of disconnection |
| Usage analytics | 24 months from collection |
| Support correspondence | 36 months from resolution |
10. Your Rights
Under the UK GDPR and EU GDPR, you have the following rights:
- Access (Art. 15): Request a copy of your personal data
- Rectification (Art. 16): Request correction of inaccurate data
- Erasure (Art. 17): Request deletion of your data
- Restriction (Art. 18): Request restricted processing
- Data Portability (Art. 20): Receive data in machine-readable format
- Object (Art. 21): Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time
To exercise your rights, contact privacy@keplor.io. We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
12. Children's Privacy
Our Services are not directed at individuals under 18. We do not knowingly collect personal data from children. If we become aware of such collection, we will promptly delete the data. Contact our Privacy Officer if you believe a child has provided us with personal data.
13. Additional Disclosures
California Residents (CCPA/CPRA): You may have additional rights including the right to know, right to delete, and right to opt-out of sale (Keplor does not sell personal information). Contact privacy@keplor.io to exercise your California privacy rights.
EEA Users: You benefit from EU GDPR protections. Exercise your rights as described in Section 10.
US Users: Data is stored by default in the UK. All users receive the data protection rights described in Section 10 regardless of location.
14. Enterprise Customers
Enterprise customers may require a Data Processing Agreement ("DPA") covering scope, purpose, sub-processor management, data breach notification, audit rights, and data return upon termination. To request a DPA, contact privacy@keplor.io.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes at least 30 days before they take effect and post a prominent notice on our website. Your continued use after the effective date constitutes acceptance.
16. Contact Us
Privacy Officer
Keplor Limited
20 Eastbourne Terrace
London W2 6LG
United Kingdom
Email: privacy@keplor.io
