Privacy policy

Version 1 · Effective 26 Aug 2026

MachineKeeper Privacy Policy

Version: [1.0] Effective date: [DATE] Last reviewed: [DATE]

1. Who we are

MachineKeeper is operated by [FULL LEGAL ENTITY NAME], a company registered in [England and Wales] under company number [NUMBER], whose registered office is at [ADDRESS] (“Keeper”, “we”, “us” or “our”).

This Privacy Policy explains how we collect, use, disclose and protect personal data when you:

  • visit the MachineKeeper website;
  • create or use a MachineKeeper account;
  • use the MachineKeeper web or mobile applications;
  • purchase or manage a subscription;
  • contact our support team;
  • receive communications from us; or
  • interact with an authorised MachineKeeper distributor.

MachineKeeper is intended for businesses and organisations. It is not intended for use by consumers or children.

Our contact details are:

Data protection enquiries: [PRIVACY EMAIL] Postal address: [REGISTERED ADDRESS] Support: [SUPPORT EMAIL] Website: [WEBSITE]

Our data protection officer, if appointed, may be contacted at [DPO EMAIL].

2. The roles of Keeper, your organisation and distributors

The organisation using MachineKeeper is referred to in this policy as the “Customer Organisation”.

Our role under data-protection law depends on why personal data is being processed.

2.1 When Keeper is the controller

Keeper acts as a controller when we decide why and how personal data is used for our own purposes. This normally includes:

  • managing MachineKeeper accounts;
  • administering subscriptions and payments;
  • communicating with customers and users;
  • providing customer support;
  • securing and monitoring our services;
  • preventing fraud and misuse;
  • improving MachineKeeper;
  • managing distributors and commercial relationships;
  • sending permitted service or marketing communications; and
  • complying with legal and regulatory obligations.

This Privacy Policy primarily describes the processing for which Keeper acts as controller.

2.2 When Keeper is a processor

When a Customer Organisation enters personal data into MachineKeeper for its own business purposes, the Customer Organisation will normally be the controller and Keeper will act as its processor.

This may include information contained in:

  • machinery and equipment records;
  • service, maintenance and repair records;
  • inspection forms and checklists;
  • operator or staff records;
  • machine session and usage records;
  • documents, photographs and attachments;
  • stock and transaction records;
  • form responses;
  • notes, reports and audit records;
  • location or route information, where enabled; and
  • other information uploaded or generated by the Customer Organisation.

Where we act as processor, we process that information on the Customer Organisation’s documented instructions and in accordance with our Data Processing Agreement.

If you are a User of a Customer Organisation and wish to exercise rights concerning information entered or managed by that organisation, you should normally contact the Customer Organisation first. We will assist it with responding where required.

2.3 Distributor-managed customers

A Customer Organisation may purchase or manage its MachineKeeper subscription through an authorised distributor.

Depending on the arrangement, the distributor may:

  • create or configure the Customer Organisation’s account;
  • administer users and subscription options;
  • provide first-line support;
  • view billing and usage information;
  • collect subscription payments; and
  • access operational data where the Customer Organisation has authorised it.

An authorised distributor is an independent organisation and may act as a separate controller or processor. Its handling of personal data is also governed by its own privacy information and any agreement it has with the Customer Organisation.

Keeper may exchange account, subscription, billing, support and service information with the authorised distributor where necessary to administer the Customer Organisation’s subscription.

3. Personal data we collect

The personal data we collect depends on how you interact with MachineKeeper.

3.1 Identity and contact information

We may collect:

  • name;
  • job title and department;
  • employer or organisation;
  • business address;
  • email address;
  • telephone number, including country prefix;
  • account username or identifier; and
  • preferred language, country or region.

3.2 Account and authentication information

We may collect:

  • account identifiers;
  • encrypted or hashed authentication credentials;
  • user roles and permissions;
  • multi-factor authentication status;
  • login dates and times;
  • password-reset records;
  • authentication method;
  • device or session information; and
  • records of acceptance of our terms and policies.

If you use biometric authentication, such as Face ID or fingerprint recognition, the biometric check is normally performed by your device’s operating system. Keeper does not receive or store your fingerprint, facial template or other underlying biometric data. We receive only confirmation that authentication succeeded or failed.

3.3 Subscription and billing information

We may collect:

  • selected package, plan level and add-ons;
  • number and type of Users;
  • billing contact details;
  • billing address;
  • purchase orders;
  • invoice and payment status;
  • payment method;
  • transaction references;
  • VAT or tax information;
  • credits, refunds and cancellations; and
  • whether the subscription is direct or distributor-managed.

Card and bank details are generally collected and processed directly by our payment providers. We normally receive a token, mandate reference, payment status and limited payment information, such as the card type and last four digits, rather than full card or bank-account details.

Payment providers may include Worldpay, GoCardless or another provider identified when payment details are collected.

3.4 Customer and User communications

We may collect:

  • support enquiries;
  • emails and messages;
  • support request histories;
  • call notes;
  • feedback and survey responses;
  • complaints;
  • requested features;
  • files or screenshots supplied for support; and
  • records of communications with Keeper or an authorised distributor.

3.5 Technical and usage information

We may automatically collect:

  • IP address;
  • browser type and version;
  • device type and operating system;
  • application version;
  • language and time-zone settings;
  • unique device or installation identifiers;
  • login and access history;
  • pages, screens and features used;
  • actions performed within MachineKeeper;
  • crash, error and performance data;
  • diagnostic logs;
  • security events; and
  • cookie or similar technology identifiers.

3.6 Machinery and operational information

Customer Organisations may enter or generate information relating to machinery, equipment and their operation, including:

  • machine identifiers and details;
  • operator names;
  • service and maintenance records;
  • inspection and pre-start check results;
  • fault and repair information;
  • machine usage sessions;
  • meter, hour or mileage readings;
  • photographs and documents;
  • form responses;
  • stock usage;
  • timestamps;
  • electronic signatures or acknowledgements; and
  • audit-history information.

Some operational information may constitute personal data where it identifies or can be linked to an individual operator, employee, contractor or other person.

Keeper normally processes this information as a processor on behalf of the relevant Customer Organisation.

3.7 Location and route information

Where the relevant feature is enabled and the User or Customer Organisation has granted permission, MachineKeeper may process:

  • device location;
  • machine location;
  • route or journey information;
  • location timestamps;
  • start and end locations; and
  • location information received from GPS devices, telematics equipment or third-party integrations.

Location information is collected only where required for an enabled feature. Mobile Users can control device-level location permissions through their operating-system settings, although disabling permission may prevent the relevant feature from working.

The Customer Organisation is responsible for ensuring it has an appropriate lawful basis, provides any required workforce privacy information and complies with employment and monitoring laws before using location features to monitor staff or operators.

3.8 Push-notification information

If you enable push notifications, we may process:

  • a device or push-notification identifier;
  • application and device information;
  • notification preferences;
  • notification delivery status; and
  • interactions with notifications.

We may use a provider such as OneSignal or the notification services operated by Apple or Google to deliver notifications.

You can disable push notifications through MachineKeeper’s settings or your device settings. Essential service messages may still be sent by email or displayed within MachineKeeper.

3.9 Offline application information

Where offline functionality is enabled, selected MachineKeeper data may be stored locally on your device so that authorised features remain available without an internet connection.

Locally stored changes may be synchronised with MachineKeeper when the device reconnects. The amount and duration of local storage will depend on the enabled features, Customer Organisation settings and application configuration.

Users must protect devices containing offline data using appropriate device security, screen locks and access controls. Removing the application, signing out or remotely revoking a User’s access may remove or restrict locally stored information, although this may not occur until the device next connects.

3.10 Marketing information

We may collect:

  • marketing preferences;
  • email engagement information;
  • event or demonstration registrations;
  • campaign source;
  • areas of product interest; and
  • records of consent, opt-out or objection.

3.11 Information from other sources

We may receive personal data from:

  • your Customer Organisation;
  • an authorised distributor;
  • another User authorised to invite you;
  • payment providers;
  • identity or authentication providers;
  • integrations enabled by the Customer Organisation;
  • telematics or GPS providers;
  • customer support providers;
  • analytics and security providers;
  • publicly available business sources; and
  • another member of the Origin Enterprises group.

4. How we use personal data

We may use personal data for the following purposes.

4.1 Providing MachineKeeper

We use personal data to:

  • create and administer accounts;
  • authenticate Users;
  • provide purchased features;
  • maintain User roles and permissions;
  • store and display Customer Data;
  • synchronise data between devices;
  • process subscriptions and payments;
  • generate invoices and receipts;
  • provide reports and notifications;
  • support integrations; and
  • provide customer support.

4.2 Managing direct and distributor subscriptions

We use personal data to:

  • process direct subscriptions;
  • connect Customer Organisations with authorised distributors;
  • allow distributors to administer authorised accounts;
  • manage distributor transfers;
  • calculate charges;
  • reconcile payments;
  • manage renewals, refunds and cancellations; and
  • respond to billing enquiries.

4.3 Security and fraud prevention

We use personal data to:

  • verify identity and authority;
  • protect accounts and systems;
  • monitor suspicious activity;
  • detect and prevent fraud;
  • investigate security incidents;
  • enforce our terms;
  • maintain audit logs; and
  • protect Keeper, Customer Organisations, Users and third parties.

4.4 Service operation and improvement

We use personal data to:

  • monitor performance and availability;
  • diagnose faults and crashes;
  • understand how features are used;
  • improve usability and accessibility;
  • develop new features;
  • conduct testing and quality assurance; and
  • generate aggregated or anonymised statistics.

We do not use Customer Organisations’ operational data to train public generative artificial-intelligence models.

4.5 Communications

We use personal data to:

  • send account and security alerts;
  • provide service announcements;
  • respond to enquiries;
  • send maintenance and renewal notices;
  • communicate changes to terms or policies;
  • request feedback; and
  • send marketing communications where permitted.

4.6 Legal and business administration

We use personal data to:

  • comply with law and regulatory requirements;
  • maintain financial and tax records;
  • establish, exercise or defend legal claims;
  • respond to lawful requests from authorities;
  • conduct audits;
  • manage corporate transactions; and
  • protect our legal and commercial interests.

5. Our lawful bases

Under UK data-protection law, we must have a lawful basis for processing personal data.

Purpose Normal lawful basis
Creating and administering an individual’s User account Legitimate interests and, where applicable, performance of a contract
Providing MachineKeeper to a sole trader or individual contracting party Performance of a contract
Providing MachineKeeper to Users employed by a Customer Organisation Legitimate interests in delivering the contracted service
Processing Customer Data on behalf of a Customer Organisation The Customer Organisation’s documented instructions under our Data Processing Agreement
Processing subscriptions, invoices and payments Performance of a contract and legitimate interests
Maintaining tax and accounting records Legal obligation
Security, fraud prevention and audit logging Legitimate interests and, where applicable, legal obligation
Customer support and service communications Performance of a contract and legitimate interests
Product analytics and improvement Legitimate interests, or consent where required for cookies or similar technologies
Optional device location Consent or another lawful basis identified by the Customer Organisation, depending on context
Push notifications Consent or legitimate interests, depending on the type of notification and applicable law
Business-to-business marketing Legitimate interests or consent where required
Responding to legal claims or authorities Legal obligation and legitimate interests

Where we rely on legitimate interests, those interests may include operating and improving MachineKeeper, supporting customers, securing our systems, managing our business and communicating with business users. We consider whether those interests are outweighed by the rights and interests of affected individuals.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that took place before consent was withdrawn.

6. When personal data must be provided

Certain personal data is required to create and maintain a MachineKeeper account, provide a subscription, authenticate a User, process payment or meet legal requirements.

If required information is not supplied, we may be unable to:

  • create or maintain an account;
  • provide particular features;
  • process or verify payment;
  • respond to a request; or
  • comply with our contractual or legal obligations.

Optional information and permissions will be identified where reasonably practicable.

7. Who we share personal data with

We may share personal data with:

7.1 Customer Organisations

If your account belongs to a Customer Organisation, its authorised administrators may access information about your account and your use of MachineKeeper, including records you create and actions you perform.

7.2 Authorised distributors

Where a subscription is distributor-managed, we may share account, subscription, billing, support and usage information with the relevant authorised distributor.

Operational Customer Data will only be accessible to the distributor where access has been authorised by the Customer Organisation or is reasonably necessary to provide an agreed service.

7.3 Origin Enterprises group companies

We may share personal data with other members of the Origin Enterprises group where necessary for administration, technical support, security, finance, compliance or other legitimate business purposes.

7.4 Service providers

We may use service providers for:

  • cloud hosting and storage;
  • content-delivery networks;
  • email delivery;
  • push notifications;
  • payment processing;
  • direct-debit collection;
  • customer support;
  • system monitoring;
  • error and crash reporting;
  • analytics;
  • security and fraud prevention;
  • data backup;
  • authentication; and
  • professional advisory services.

These providers may process personal data only for the agreed purpose and under appropriate contractual and security obligations.

7.5 Third-party integrations

If a Customer Organisation enables an integration, we may exchange information with the selected third-party service as required to operate that integration.

The third party may process the information as a separate controller under its own privacy policy. Customer Organisations should review the terms and privacy information of integrations before enabling them.

7.6 Legal and corporate disclosures

We may disclose personal data:

  • where required by law, court order or a competent authority;
  • to establish, exercise or defend legal rights;
  • to investigate suspected fraud, crime or security incidents;
  • to protect the vital interests of a person;
  • as part of a merger, acquisition, restructuring or sale of a business; or
  • with your consent or at your direction.

We do not sell personal data.

8. International transfers

Some service providers or group companies may process personal data outside the United Kingdom.

Where personal data is transferred to a country not covered by UK adequacy regulations, we will use an appropriate safeguard where required, such as:

  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses; or
  • another lawful transfer mechanism.

We will also undertake any required transfer-risk assessment and apply supplementary safeguards where appropriate.

You may contact us for further information about the safeguards used for international transfers.

9. How long we retain personal data

We retain personal data only for as long as reasonably necessary for the relevant purpose, including legal, accounting, security and contractual requirements.

Our normal retention approach is:

Information Typical retention
Active account and profile information For the life of the account
Subscription and contract records Subscription term plus up to 7 years
Invoices, payments and tax records Normally 6 years after the relevant financial period
Support requests and communications Normally up to 3 years after closure
Security and authentication logs Normally between 12 and 24 months
Marketing preferences and suppression records Until consent is withdrawn or an objection is made; suppression records may be retained to honour the opt-out
Free-trial data [30/60/90] days after trial expiry unless converted to a paid account
Customer Data following subscription termination Available for export for [30] days and then deleted or anonymised in accordance with our deletion process
Backup copies Until overwritten through the normal backup cycle, normally within [90] days
Local offline data Until synchronised, removed by the app, the User signs out, access is revoked or the app is uninstalled, subject to device behaviour

We may retain information for longer where:

  • required by law;
  • necessary for a legal claim or investigation;
  • requested by the Customer Organisation;
  • subject to a legal hold; or
  • retained in an anonymised form that no longer identifies an individual.

Where Keeper processes Customer Data as a processor, retention is also governed by the Customer Organisation’s instructions and our Data Processing Agreement.

10. Cookies and similar technologies

Our websites and web applications may use cookies, local storage, software development kits and similar technologies.

These may be used to:

  • keep Users signed in;
  • maintain security;
  • remember preferences;
  • provide requested functionality;
  • understand service usage;
  • measure website performance; and
  • support marketing where permitted.

Essential technologies may be used where necessary to provide or secure the service. Non-essential analytics, advertising or similar technologies will be used in accordance with applicable consent requirements.

Our cookie banner allows website visitors to accept or reject non-essential cookies. More information about the technologies we use, their providers and duration is available in our Cookie Policy at [COOKIE POLICY URL].

Mobile applications may use device identifiers, local storage and software development kits that perform similar functions to cookies. Relevant choices are provided through the application, device settings or operating-system permissions.

11. Marketing communications

We may send relevant business-to-business marketing communications about MachineKeeper, related Keeper products, events, features or services where permitted by law.

You may opt out at any time by:

  • selecting the unsubscribe link in a marketing email;
  • changing available communication preferences; or
  • contacting us at [PRIVACY OR MARKETING EMAIL].

Opting out of marketing does not prevent us from sending necessary account, billing, security, legal or service communications.

Authorised distributors are responsible for their own marketing activities and must provide their own opt-out mechanism.

12. Automated decision-making

We do not currently use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.

We may use automated tools to identify potential fraud, security threats, unusual account activity or service misuse. These tools support security review and do not normally make legally significant decisions without appropriate human involvement.

If this changes, we will update this Privacy Policy and provide any additional information required by law.

13. Information security

We use appropriate technical and organisational measures designed to protect personal data, including measures relating to:

  • access controls and permissions;
  • authentication;
  • encryption in transit and, where appropriate, at rest;
  • system monitoring and logging;
  • vulnerability and patch management;
  • backups and recovery;
  • staff confidentiality;
  • supplier due diligence;
  • incident response; and
  • business continuity.

No internet-based system can be guaranteed completely secure. Customer Organisations and Users also have responsibilities for securing their accounts, passwords and devices.

If we become aware of a personal-data breach, we will investigate and notify affected Customer Organisations, individuals and regulators where required by law.

14. Your data-protection rights

Depending on the circumstances, you may have the right to:

  • be informed about how your personal data is used;
  • request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request erasure of personal data;
  • request restriction of processing;
  • receive certain data in a portable format;
  • object to processing based on legitimate interests;
  • object to direct marketing;
  • withdraw consent;
  • request human review of certain automated decisions; and
  • complain to a supervisory authority.

These rights are not absolute and may be subject to legal exceptions.

Where Keeper acts as controller, requests may be sent to [PRIVACY EMAIL]. We may need to verify your identity and authority before responding.

Where personal data was entered or is controlled by a Customer Organisation, you should normally submit your request to that organisation. If you send the request to Keeper, we may refer it to the Customer Organisation and assist it in responding.

We will not normally charge a fee for a rights request. A reasonable fee may apply, or a request may be refused, where permitted by law because it is manifestly unfounded or excessive.

15. Complaints

Please contact us first if you have a concern about how we use personal data. We will investigate and attempt to resolve the issue.

You also have the right to complain to the UK Information Commissioner’s Office:

Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF United Kingdom

Website: https://ico.org.uk/ Telephone: 0303 123 1113

If you are located outside the United Kingdom, you may also have the right to contact the data-protection authority in your country.

16. Children

MachineKeeper is a business service and is not intended for children. Users must normally be at least 18 years old or otherwise legally permitted and appropriately authorised to use the service in a workplace context.

We do not knowingly collect personal data directly from children for our own purposes.

Customer Organisations must not enter children’s personal data into MachineKeeper unless the processing is lawful, necessary for an intended feature and subject to appropriate safeguards.

17. External websites and services

MachineKeeper may contain links to external websites or services. We do not control and are not responsible for their privacy practices.

You should review the privacy policy of an external service before providing personal data to it.

18. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to:

  • MachineKeeper;
  • our data-processing activities;
  • service providers;
  • legal or regulatory requirements; or
  • our organisational arrangements.

We will publish the updated policy and change the effective date shown above.

If a change materially affects how we use personal data, we will provide reasonable notice through MachineKeeper, by email or by another appropriate method before the new use begins.

19. Contact us

Questions, complaints and requests concerning this Privacy Policy may be sent to:

Data Protection Contact [FULL LEGAL ENTITY NAME] [REGISTERED ADDRESS] Email: [PRIVACY EMAIL]

For ordinary product or account support, please contact [SUPPORT EMAIL].