Operator and correspondence
Charlie Miller, sole trader trading as Keepalto.
Who is responsible
Charlie Miller operates Keepalto and is responsible for account administration, support and service-security information. A business using the platform normally decides why and how its customer, staff and operator records are used; Keepalto handles those records on its instructions. A business data-processing agreement and provider-transfer review must be completed before general commercial onboarding.
Information processed
Sign-in supplies an account identifier, email and, when available, a name. Users may add business details, staff roles, customer contact details, operator competencies, locations, equipment photos and documents, bookings and activity records. Support enquiries contain the information you send. Hosting and sign-in providers may also handle connection and security information. Records about you may come from the business that employs you or supplies your equipment.
Why it is used
Account information is used to provide the service and manage access. Support information is used to answer requests. Security and activity records support our legitimate interests in protecting the service and investigating misuse. We may retain information to meet legal duties. Business-entered records are used for that business’s operational instructions. We do not use the application to make solely automated decisions with legal or similarly significant effects.
Who can access it
Authorised members of the relevant business can access records according to their roles. The platform operator can access administrative information and may need to investigate support or security problems. The published Sites preview uses OpenAI Sites and Cloudflare-backed D1/R2 for operational business records and uploaded files; the current source uses individual email/password accounts through Supabase Auth when configured. Supabase Auth stores account identities and authentication information, while the separate Supabase Postgres schema is not the operational database used by this source. The service-owner portal has separate restricted sign-in. The Netlify staging deployment is a separate, divergent runtime and its data-provider configuration has not been verified. Public paid signup is unavailable in the evaluation preview; Stripe subscription billing code is present, but no live billing is active. No application advertising or marketing analytics has been added.
Location and retention
The preview is not represented as UK-only storage. Hosting and authentication providers may process information internationally; contractual roles, locations and transfer safeguards are being reviewed before commercial launch. Records currently remain while the evaluation account is used; no automated retention purge runs. Retention decisions consider service need, a business’s instructions, deletion requests, security investigations and legal obligations. Support can explain what applies to a specific record.
Your choices and rights
You may request access, correction, erasure, restriction or portability where applicable. You can object to processing based on legitimate interests, and withdraw any consent relied upon. Contact support@phantiqstudios.com; we may need proportionate identity checks. Where a business controls the record, contact that business too. Deletion rights have legal exceptions and do not automatically erase shared operational history.
Complaints and required information
You can complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, and to another competent authority where applicable. Login identifiers are necessary for the signed-in service; optional descriptive information should be limited to what the business needs. You can explore the fictional demo without an account. Changes to processing will be reflected in this notice.