Privacy Policy

Privacy Policy

Effective Date: 25 January 2026
Last Updated: 27 August 2026


1. Introduction

Welcome to Keito (“we,” “our,” or “us”). Keito is a time tracking application that helps individuals and teams monitor work hours and productivity. We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025.

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights regarding your data. By using Keito, you agree to the collection and use of information in accordance with this policy.

Data Controller:
Keito is a product of OSO DevOps Limited, a company registered in England and Wales.
Company number: 10889879
Registered office:
The Landing 131 Tileman House
Upper Richmond Road
London
England
SW15 2TL
ICO registration number: ZB179031
Website: https://keito.ai/
Email: support@keito.ai

If you have any questions about this Privacy Policy or how we handle your data, please contact us at the details above.


2. Information We Collect

We collect and process several types of personal data to provide our time tracking services:

2.1 Account Information

  • Collected via: WorkOS authentication service
  • Data types: Full name, email address, profile information
  • Purpose: Account creation, authentication, and service provision

2.2 Time Tracking Data

  • Data types:
    • Work hours and time entries
    • Project names and descriptions
    • Task descriptions and categories
    • Timestamps and duration data
    • Client information (if provided)
  • Purpose: Core functionality of the time tracking service, reporting, and analytics

2.3 Billing and Payment Information

  • Collected via: Stripe payment processing
  • Data types:
    • Billing name and address
    • Payment card details (processed securely by Stripe; we do not store full card numbers)
    • Transaction history
    • Subscription details
  • Purpose: Payment processing, invoicing, and subscription management

2.4 Integration Data

When you choose to connect optional third-party integrations, we collect and process the data needed to provide those integration features.

The integrations currently supported by the Service are described below. Availability may depend on your plan, provider configuration, and whether your workspace is included in a limited preview or beta.

Integration category Services and current status Data processed and direction
Accounting Xero and QuickBooks Online (available) Keito sends the client, contact, invoice, line-item, tax, account, item, employee, approved-time, and mapping data needed for the enabled sync. Payment state can return to Keito.
Online invoice payments Stripe Connect and Stripe Checkout (available) Keito sends invoice and payer-facing checkout details to Stripe and receives payment status and payment references. Full payment-card details are processed by Stripe, not stored by Keito.
Calendars Google Calendar and Microsoft 365 Outlook Calendar (available) Keito reads the authorised user’s calendar list and event details needed to display import candidates. The user chooses whether to create a Keito time entry. Keito does not create, edit, or delete calendar events.
Work management and HR Jira Cloud and CharlieHR (available) Keito can send linked time entries to Jira worklogs and receive identifiers and status. Keito reads configured CharlieHR member, leave-type, and approved-leave data to create planning availability.
Migration Harvest import (available) Keito reads the records selected for migration using credentials supplied by the customer and creates corresponding Keito records.
Limited previews and betas Airtable, Asana, Zendesk, and ClickUp These integrations are available only to expressly enabled workspaces. Their current flows include configured Airtable record imports, Asana-to-Keito time capture, Zendesk ticket context for time capture, and a limited ClickUp time-sync beta.

For connected services, we may store encrypted access or refresh credentials, provider account and workspace identifiers, mappings between provider records and Keito records, synchronisation status, and errors needed to operate, secure, disconnect, and audit the connection.

Additional rules for Google Calendar data

  • We access the connected Google account identifier and email address; calendar IDs, names, primary status, and display colours; and event IDs, titles, start and end times, duration, recurring-event IDs, event links, and declined status needed for the import feature.
  • We use Google Calendar data only to display authorised events and help the user create Keito time entries. Access is read-only.
  • Keito excludes Google Calendar data and data derived from Google Calendar events, including calendar-imported time entries and reports based on those entries, from AI-agent and Model Context Protocol (MCP) integrations. We do not send that data to AI providers.

2.5 Developer, Agent, and MCP Connections

Keito provides an API, command-line interface (CLI), local Agent Skill, and hosted MCP connector. These are data and automation interfaces; Keito does not operate a hosted large-language-model or generative-AI inference service.

  • The API and CLI process the records and actions requested by the authenticated user or API key, within that credential’s workspace and permissions.
  • The Agent Skill runs in a customer-chosen local agent environment and can send configured session time, notes, and metadata to Keito. Keito does not send workspace data to an AI provider merely because the skill is installed.
  • If a customer connects the hosted MCP connector to Claude or another compatible customer-chosen service, that service receives only the Keito data returned in response to tools the customer or its agent invokes. The AI service, model, retention settings, and privacy controls are selected and governed by the customer’s relationship with that provider.

We do not use Customer Data to create, train, fine-tune, evaluate, or improve generalized or shared artificial-intelligence or machine-learning models. We do not submit Customer Data to a model provider for inference on our own initiative.

2.6 Technical and Usage Data

  • Data types:
    • IP address
    • Browser type and version
    • Device information
    • Operating system
    • Pages visited and features used
    • Usage patterns and session data
    • Cookies and similar tracking technologies
  • Purpose: Service improvement, security, troubleshooting, and analytics

2.7 Communications Data

  • Data types:
    • Support inquiries
    • Feedback and survey responses
    • Email correspondence
  • Purpose: Customer support, service improvement, and communication

Under UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following legal bases:

3.1 Contract Performance (Article 6(1)(b) UK GDPR)

We process your account information, time tracking data, and billing information to fulfill our contractual obligations to provide you with the Keito service.

3.2 Legitimate Interests (Article 6(1)(f) UK GDPR)

We process technical and usage data for:

  • Service improvement and optimization
  • Security and fraud prevention
  • Technical troubleshooting
  • Understanding user behaviour to enhance features

We have assessed that these legitimate interests do not override your fundamental rights and freedoms.

3.3 Consent (Article 6(1)(a) UK GDPR)

For certain processing activities, such as:

  • Marketing communications (where you have opted in)
  • Optional integrations and connected-service permissions
  • Non-essential cookies and analytics

You have the right to withdraw your consent at any time.

3.4 Legal Obligation (Article 6(1)(c) UK GDPR)

We may process data to comply with legal obligations, such as:

  • Tax and accounting requirements
  • Responding to lawful requests from authorities
  • Data breach notifications

4. How We Use Your Information

We use your personal data for the following purposes:

4.1 Service Provision

  • Creating and managing your account
  • Enabling time tracking functionality
  • Generating reports and analytics
  • Processing payments and managing subscriptions
  • Operating integrations that you choose to connect
  • Executing API, CLI, Agent Skill, and MCP requests made by authorised credentials

4.2 Communication

  • Sending service-related notifications
  • Responding to support inquiries
  • Providing updates about service changes or new features
  • Sending marketing communications (only with your consent)

4.3 Service Improvement

  • Analyzing technical and usage patterns to improve functionality
  • Conducting product research and development using feedback, technical data, and aggregated or de-identified usage information
  • Testing new features
  • Troubleshooting and fixing technical issues

We do not use Customer Data for generalized or shared AI or machine-learning model training or improvement.

4.4 Security and Compliance

  • Detecting and preventing fraud
  • Ensuring platform security
  • Complying with legal obligations
  • Enforcing our Terms of Service

5. Data Sharing, Service Providers, and Integrations

OSO DevOps Limited is a controller for account administration, billing, security, support, marketing, and our own service analytics. When an organisation uses Keito to process personal data contained in its Customer Data, the organisation is normally the controller and we act as its processor under its instructions.

5.1 Service Providers and Sub-processors

We use the following core providers to operate Keito. Where they process personal data on our behalf, they are contractually restricted to the relevant service purpose and appropriate data-protection terms apply.

Provider Function and data More information
WorkOS Authentication, identity, organisation membership, and single sign-on data WorkOS Privacy Policy
Stripe Keito subscription billing and payment processing; billing identity and transaction data. Stripe may also act as an independent controller for parts of payment processing. Stripe Privacy Policy
Amazon Web Services (AWS) Application hosting, databases, file storage, and transactional email through the London (eu-west-2) region AWS Privacy Notice
PostHog Product analytics and service-usage events PostHog Privacy Notice
Zendesk Customer-support inquiries and correspondence Zendesk Privacy Notice
Grafana Labs Infrastructure logs, metrics, traces, and observability data Grafana Labs Privacy Policy

This is our current list of core service providers that may process personal data on our behalf. We will update this policy and notify workspace owners by email at least 30 days before adding or replacing a sub-processor that processes Customer Data, so that customers have an opportunity to raise objections.

5.2 Customer-Directed Optional Integrations

An optional integration provider is not automatically our sub-processor. When you select a provider, hold the account with it, grant credentials, and instruct Keito to exchange data, that provider may act as your processor or as an independent controller under your agreement with it. You should review its terms, privacy notice, retention, international-transfer, and—where relevant—AI-training settings before connecting it.

Provider Customer-directed purpose Provider privacy information
Xero Accounting, invoice, contact, and payment synchronisation Xero Privacy Notice
Intuit QuickBooks Online Accounting, customer, invoice, payment, employee, item, and approved-time synchronisation Intuit Global Privacy Statement
Stripe Connect Connected-account onboarding and client invoice payments Stripe Privacy Policy
Google Calendar Read-only calendar import Google Privacy Policy
Microsoft 365 / Microsoft Graph Read-only Outlook calendar import Microsoft Privacy Statement
Atlassian Jira Cloud Jira issue lookup and worklog synchronisation Atlassian Privacy Policy
CharlieHR Member, leave-type, and approved-leave import for planning CharlieHR Privacy Policy
Harvest Customer-requested migration into Keito Harvest Privacy Policy
Airtable, Asana, Zendesk, and ClickUp Limited-preview or beta workflows described in Section 2.4 Airtable, Asana, Zendesk, and ClickUp privacy notices

Disconnecting an integration stops new exchanges after Keito revokes or invalidates the available credential. Records already copied to either service normally remain there under the retention rules of the service that holds them.

Google Workspace API data. Keito’s use and transfer of information received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements. We do not sell Google Calendar data, transfer it to data brokers, use it for advertising or creditworthiness, or use it to build advertising profiles. We do not retain or use Google Workspace user data to create, train, fine-tune, evaluate, or improve generalized or non-personalized AI or machine-learning models. Google Calendar event data and data derived from those events are excluded from Keito’s AI-agent and MCP integrations and are not sent to AI providers.

5.3 AI, Agent, and MCP Data Sharing

Keito does not select or operate an LLM on a customer’s behalf and does not send Customer Data to OpenAI, Anthropic, Google Gemini, or another model provider on its own initiative.

If you connect Keito’s MCP server, API, or CLI to an AI service you choose, you instruct Keito to return authorised data to that service when its agent invokes a Keito tool. The provider, model, retention period, model-training settings, and privacy controls are governed by your account and agreement with that AI provider. Keito’s no-training commitment governs our processing and that of sub-processors acting on our behalf; it cannot govern a separate service you independently choose. Google Calendar data remains excluded from AI-agent and MCP access.

We may disclose your personal data if required to:

  • Comply with legal obligations or lawful requests
  • Protect our rights, property, or safety
  • Prevent fraud or security threats
  • Enforce our Terms of Service

6. International Data Transfers

Some of our service providers are located outside the United Kingdom and European Economic Area (EEA). When we transfer your personal data internationally, we ensure appropriate safeguards are in place:

6.1 Transfer Mechanisms

  • Adequacy Decisions: Transfers to countries recognized by the UK as providing adequate data protection (e.g., New Zealand for Xero)
  • Appropriate safeguards: The UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful Article 46 safeguard, together with the required transfer assessment
  • Data Privacy Framework: The UK Extension to the EU-US Data Privacy Framework where the receiving organisation is certified and the transfer is eligible

When you direct Keito to exchange data with an optional integration or AI service, the provider may process that data outside the UK. Your agreement with that customer-chosen provider governs its locations and safeguards; Keito still applies the safeguards required for transfers it makes as your processor.

6.2 Data Security

All international data transfers are encrypted in transit and at rest. Our processors maintain robust security measures that meet or exceed UK GDPR requirements.


7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy and to comply with legal obligations.

7.1 Retention Periods

  • Account data: Retained while your account is active
  • Customer Data: Retained while your account is active. If your account or subscription is terminated, Customer Data is retained for 30 days so that you can export it, and is then deleted, in line with Section 15.4 of our Terms of Service. Where a workspace owner requests deletion (see Section 7.2), data is deleted as part of that process.
  • Billing and transaction data: Retained for 7 years to comply with UK tax and accounting regulations
  • Integration credentials and active connection data: Retained while the integration is connected or while an import or synchronisation job needs the credential, then revoked, deleted, or invalidated when the connection is removed. We may retain non-secret provider record identifiers and sync history with the related Customer Data where needed for auditability and to prevent duplicate syncs.
  • Google Calendar OAuth tokens and connection data: Retained while your Google Calendar account is connected, then deleted or invalidated when you disconnect
  • Google Calendar event metadata copied into time entries: Time entries you create from calendar events remain part of your Keito time tracking records unless you delete the entries or request account/workspace deletion. When you disconnect Google Calendar, Keito removes stored Google calendar identifiers and recurring event memory from your Keito account.
  • Technical logs: Retained for 90 days for security and troubleshooting purposes
  • Marketing data: Retained until you withdraw consent or request deletion

7.2 Account Deletion

Workspace owners can request permanent account and workspace deletion from the Keito app. When confirmed, Keito queues a deletion job that:

  • Removes access to the workspace
  • Deletes active workspace data, files, integrations, and exclusive user accounts from Keito systems
  • Cancels the active subscription and removes workspace billing state where no legal retention obligation applies
  • Keeps user accounts that also belong to another Keito workspace, so those other workspaces continue to work
  • Retains limited operational records where required for security, compliance, support, dispute handling, legal obligations, or to verify the deletion outcome

After deletion, the only usage information we retain is aggregated or anonymised analytics that cannot be used to identify you or your workspace.

Third-party providers may retain their own records under their own retention policies. Disconnecting or deleting data in Keito does not automatically delete copies already held by a customer-chosen integration or AI provider.

7.3 Google Calendar Disconnection

You can disconnect Google Calendar at any time from Keito. When you disconnect:

  • Keito stops using your Google Calendar connection
  • Keito attempts to revoke the Google OAuth token
  • Keito deletes or invalidates stored Google Calendar OAuth tokens
  • Keito removes stored Google calendar identifiers and recurring event memory used for import suggestions
  • Time entries that you already created from calendar events remain in Keito as normal time tracking records, but are no longer linked to Google Calendar

8. Data Security

We implement robust technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration.

8.1 Technical Measures

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access controls: Role-based access with the principle of least privilege
  • Authentication: Secure authentication through WorkOS with support for multi-factor authentication (MFA)
  • Infrastructure security: Secure cloud hosting with regular security audits
  • Monitoring: Continuous monitoring for security threats and anomalies

8.2 Organizational Measures

  • Staff training: Regular data protection and security training for all personnel
  • Data protection policies: Comprehensive internal policies and procedures
  • Incident response: Documented procedures for handling security incidents and data breaches
  • Vendor management: Due diligence and contracts with all third-party processors
  • Limited human access: We do not routinely review Customer Data. Human access is limited to cases where you request support, where access is necessary for security or abuse investigation, where required by law, or where data is aggregated or de-identified for internal operations. Google Workspace data is subject to the additional human-access restrictions in Google’s Limited Use requirements.

8.3 Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the UK Information Commissioner’s Office (ICO) within 72 hours
  • Notify affected users without undue delay
  • Provide information about the nature of the breach and steps to mitigate harm

9. Your Data Protection Rights

Under UK GDPR and the Data (Use and Access) Act 2025, you have the following rights:

9.1 Right to Access (Article 15)

You have the right to request a copy of the personal data we hold about you. You can access most of your data directly through your Keito account dashboard.

9.2 Right to Rectification (Article 16)

You have the right to request correction of inaccurate or incomplete personal data. You can update most of your information directly in your account settings.

9.3 Right to Erasure / “Right to be Forgotten” (Article 17)

You have the right to request deletion of your personal data in certain circumstances, such as:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent (where processing is based on consent)
  • You object to processing based on legitimate interests
  • The data has been unlawfully processed

Please note that we may retain certain data where required by law or for legitimate business purposes (e.g., financial records).

9.4 Right to Restrict Processing (Article 18)

You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

9.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller. You can export your time tracking data from your account dashboard.

9.6 Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

Where we process your data based on consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing before the withdrawal.

9.8 Right to Complain

You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe we have not handled your data properly.

Information Commissioner’s Office (ICO)
Website: https://ico.org.uk/
Telephone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

9.9 Exercising Your Rights

To exercise any of these rights, please contact us at:

We will respond to your request within 30 days. For complex requests, we may extend this period by an additional 60 days and will inform you of any such extension.


10. Data Protection Complaints Process

In accordance with the Data (Use and Access) Act 2025, we have established a formal process for handling data protection complaints:

10.1 How to Raise a Complaint

If you wish to raise a data protection complaint, please contact us at:

Please provide:

  • Your name and contact details
  • A description of your complaint
  • Any relevant supporting information

10.2 Our Response Process

  • Acknowledgment: We will acknowledge receipt of your complaint within 30 days
  • Investigation: We will investigate your complaint without undue delay
  • Resolution: We will inform you of the outcome and any actions taken
  • Escalation: If you are not satisfied with our response, you may escalate your complaint to the ICO

11. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience and analyze usage patterns.

11.1 Types of Cookies We Use

Essential Cookies

  • Required for the operation of our service
  • Include authentication and security cookies
  • Cannot be disabled

Functional Cookies

  • Remember your preferences and settings
  • Enhance user experience
  • Can be controlled through your browser settings

Analytics Cookies

  • Help us understand how users interact with Keito
  • Used to improve our services
  • Can be disabled through cookie preferences

11.2 Managing Cookies

You can control and delete cookies through your browser settings. Please note that disabling essential cookies may affect the functionality of Keito.

For more information about cookies and how to manage them, visit: https://www.aboutcookies.org/


12. Children’s Privacy

Keito is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child under 16, we will take steps to delete that information promptly.

If you believe we have collected data from a child, please contact us immediately at support@keito.ai.


13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will:

  • Update the “Last Updated” date at the top of this policy
  • Notify you of material changes via email or through a prominent notice in our service
  • In some cases, seek your consent for significant changes that affect how we process your data

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.


14. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:

Data Protection Inquiries:
Email: support@keito.ai
Website: https://keito.ai/contact

Mailing Address:
Keito (OSO DevOps Limited)
The Landing 131 Tileman House
Upper Richmond Road
London
SW15 2TL
United Kingdom

We aim to respond to all inquiries within 5 business days and to fulfill data subject requests within 30 days as required by UK GDPR.


15. Specific Information for Employees and Teams

15.1 Employer-Employee Relationships

If you are using Keito as part of a team or organization:

  • Data Controller: Your employer or organization administrator is the data controller for time tracking data
  • Our Role: Keito acts as a data processor on behalf of your employer
  • Employee Rights: You maintain all data protection rights under UK GDPR
  • Transparency: Your employer must inform you about time tracking and how your data is used
  • Legitimate Basis: Time tracking must be based on a lawful basis (typically legitimate business interests or contractual necessity)

15.2 Employer Responsibilities

Organizations using Keito for employee time tracking must:

  • Inform employees about data collection and processing
  • Have a legitimate business justification for time tracking
  • Implement appropriate security measures
  • Respect employee data protection rights
  • Comply with UK employment law and GDPR

15.3 Data Minimization

We encourage employers to:

  • Track only necessary information for business purposes
  • Avoid excessive monitoring
  • Implement transparent policies
  • Provide employees with access to their own time tracking data

16. Automated Decision-Making

Keito does not use personal data in its capacity as controller to make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. The Service itself does not make those decisions about individuals using Customer Data. A customer that configures an external agent or automated workflow is responsible for assessing and explaining any decisions made through that workflow.


17. Data Protection Officer (DPO)

While Keito is not currently required to appoint a Data Protection Officer under UK GDPR, we have designated a data protection lead responsible for overseeing compliance with data protection laws and handling data protection inquiries.

For data protection matters, please contact: support@keito.ai


Acknowledgment

By using Keito, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your personal data as described herein.


End of Privacy Policy