Data Processing Terms
These terms form part of the agreement with each business using KAIRO where Safewaysuk LTD processes personal data on that business’s behalf.
Last updated: 25 September 2026
1. Roles
For personal data a business places into KAIRO or collects from its customers and staff through KAIRO for the business’s own purposes, the business is the controller and Safewaysuk LTD acts as processor, except where Safewaysuk LTD uses information for its own independent purposes such as account administration, security, fraud prevention or legal compliance.
2. Processing instructions
Safewaysuk LTD will process controller data only on documented instructions from the business, including instructions arising from normal use of KAIRO, unless processing is required by applicable law.
The business instructs KAIRO to host, organise, display, transmit and otherwise process booking and staff information as needed to provide the platform’s functions.
3. Subject matter and duration
The subject matter is the provision of KAIRO’s booking, customer-account, staff, scheduling and related software services. Processing continues for the duration of the business’s use of KAIRO and for any limited period afterwards needed for deletion, backup, legal or security purposes.
4. Nature and purpose of processing
- collecting and storing booking requests and appointment records;
- displaying bookings to authorised business and staff users;
- managing services, staff availability and booking times;
- sending transactional booking emails and reminders;
- linking eligible bookings to customer accounts;
- providing export, support, security and recovery functions;
- maintaining business-controlled blocked-customer records to prevent future online bookings where the business chooses to use that feature.
5. Types of personal data and people
Data subjects may include customers, prospective customers, staff members, contractors and business contacts.
Personal data may include names, email addresses, phone numbers, service addresses where relevant, appointment dates/times, services, assigned staff, booking notes, staff working times, staff profile photos and public introductions, account identifiers and business-controlled blocked-customer records.
6. Business responsibilities
The business is responsible for ensuring that its instructions and use of KAIRO comply with data protection law. This includes having a lawful basis, giving appropriate privacy information to its customers and staff, responding to rights requests and limiting the information it asks people to provide.
KAIRO is not intended to be a medical-record system. A business should not use free-text booking fields to collect special-category information unless it has determined that doing so is lawful, necessary and appropriately protected.
7. Confidentiality and security
Safewaysuk LTD will take appropriate technical and organisational measures designed to protect controller data, taking account of the nature of the processing, available technology, implementation costs and the risks to individuals.
People authorised to process controller data on our behalf will be subject to appropriate confidentiality obligations.
8. Subprocessors
The business authorises Safewaysuk LTD to use subprocessors reasonably necessary to operate KAIRO, including providers of application infrastructure, hosting/storage, authentication, transactional email, support and security services.
Where required by data protection law, we will place appropriate data protection obligations on subprocessors and remain responsible for our obligations as processor.
9. International transfers
If a subprocessor processes controller data outside the United Kingdom and the transfer requires safeguards, Safewaysuk LTD will use a legally recognised transfer mechanism where required.
10. Assistance
Taking into account the nature of the processing, we will provide reasonable assistance to a business with data-subject requests, security obligations, breach response and other controller duties where required by UK data protection law and where the relevant information is available to us.
11. Personal data breaches
If we become aware of a personal data breach affecting controller data, we will notify the affected business without undue delay where required by law and provide available information reasonably needed for the business to assess its obligations.
12. Return and deletion
Businesses can use available KAIRO tools to access or export relevant business data. Following termination, we will delete or return controller data as required by applicable law and our service processes, unless law requires retention. Residual copies may remain temporarily in secure backups until normal backup expiry.
13. Audits and information
We will make available information reasonably necessary to demonstrate compliance with our processor obligations. Any audit request must be reasonable, proportionate, protect the security and confidentiality of other customers and, where possible, use existing reports or information before requiring a bespoke audit.
14. Contact
Data protection questions can be sent to contact@safewaysuk.co.uk.