1. Who we are
pylosystem.com is operated by Umeukeje Chigozie Valentine, trading as PYLO, a sole trader established in Nigeria. Our address is 8 Moronu Maduagwu Street, Lagos, 101283, Nigeria and you can reach us at privacy@pylosystem.com.
TODO: no data protection officer is named because none is appointed. If one is appointed, their contact details belong here.2. Two roles, and which one applies
This is the part of the policy that matters most, and it is the part most often written backwards. PYLO holds two different kinds of personal data and has a different role for each.
Data about you, our customer
Your own name, work email, account details and billing information. For this data we are the controller. We decide why and how it is processed, and this policy tells you what we do with it.
Data you put into your workspace
Records about your leads, your customers and your own staff. For this data you are the controller and we are the processor. You decide what goes in and why. We process it on your instructions in order to provide the service, and we do not decide the purposes it is used for.
If you are one of those people rather than one of our customers, for example a lead whose details are held in a workspace, the business that holds that workspace is the controller. Contact them first. You can still contact us and we will pass it on.
3. When a workspace moves to another customer
A client workspace can be transferred from one PYLO account to another, for example when an agency hands a client back to that client, or another agency takes the account on. The workspace carries the personal data described in section 5, including leads’ names, email addresses and their answers to application forms.
PYLO remains the processor throughout. A transfer does not change what we do with the data or why. What changes is which customer instructs us: which of them is the controller giving us instructions about it from that point on.
A transfer only happens when both sides act: the account that holds the workspace offers it, and the receiving account accepts. We record who initiated it, who accepted it, and the time of each, and that record is retained as evidence of when responsibility changed hands. Once it completes, operators of the previous account lose access to the workspace.
The lawful basis for the transfer between the two customers is a matter for them, not for us. If you are a lead or a customer of one of our customers and you want to know who currently controls your data, ask them, or contact us and we will tell you which of our customers holds the workspace your data is in.
4. Two payment flows, and which role applies to each
Money moves through PYLO in two entirely separate ways, with different parties, different data and different roles. They are set out separately here because treating them as one thing would misdescribe both.
Flow one: we charge you for your subscription
Your agency subscription, whichever plan and form you are on, and any seat overage. Paddle.com Market Limited acts as merchant of record for these purchases. Paddle is the seller of record, processes the payment and handles applicable VAT.
The data subject here is you. We are the controller for the account and billing data involved. Paddle processes your payment details under its own privacy policy, as the merchant of record rather than as our subprocessor for that transaction.
Flow two: you charge your own customers
You can use PYLO to collect payments from your own customers, for example a programme fee collected in instalments from someone who has never heard of PYLO. This routes through Hyperswitch and whichever connector you have configured, which may be Whop, PayPal or Stripe.
The data subject here is a third party, not you and not us. You are the controller and we are the processor. Your own agreement with the payment provider applies to the payment itself.
Payment is collected on a payment link, so the payer enters their details on the payment provider’s own hosted page rather than in PYLO. PYLO holds the payment record: who the payment relates to, the amount, the currency, the instalment schedule, the due dates and the status.
TODO: whether any card metadata returned by a payment provider, for example a card brand or the last four digits, is persisted against a payment record has not been confirmed. Payment reconciliation happens on the backend service and could not be verified from this application, so no claim is made here about card data either way. This sentence should be completed once that boundary is confirmed.5. What we process, and why
As controller, about you
- your name and work email address, to create and operate your account
- your workspace and agency details, to provide the service you subscribed to
- billing and subscription records, to charge you and keep accounts
- support correspondence, to answer you
- technical logs generated when the service runs, to keep it working and to investigate faults
As processor, on your behalf
The service is designed to hold, and your workspace will typically contain:
- sales call records and outcomes
- lead and contact details, including names and email addresses
- application form responses submitted by your leads
- calendar bookings
- payment and instalment records
- commission and payout figures for your staff
- end-of-day reports written by your staff
- call recording links. These are links to recordings held on a third-party service such as Fathom, pasted in by your team. PYLO stores the link as text. It does not send anything to that service and does not hold the recording
6. Lawful bases
Where we are the controller, we rely on:
- contract, to create your account, provide the service and take payment
- legitimate interests, to keep the service secure, prevent abuse, fix faults and communicate with you about the service you use
- legal obligation, where we have to keep records or respond to a lawful request
Where we are the processor, the lawful basis for the data in your workspace is yours to establish and to record. You are responsible for having one before you put personal data into the service.
7. Subprocessors
We use the following third parties to run the service. Several of them only ever receive anything if you choose to connect that integration, and the last column says which.
| Subprocessor | Purpose | When active |
|---|---|---|
| Railway | Backend hosting, in Amsterdam, the Netherlands (EU) | Always |
| Supabase | Database and sign-in, hosted in Ireland (AWS eu-west-1, EU) | Always |
| Vercel | Frontend hosting | Always |
| Paddle | Payment processing for PYLO subscriptions, merchant of record | Always |
| Google (Gemini) | AI assistant responses | Always |
| Nango | OAuth connection brokering for integrations | Only if connected |
| Hyperswitch | Payment orchestration for customer payment connectors | Only if connected |
| Whop | Payment processing available to customers | Only if connected |
| PayPal | Payment processing available to customers | Only if connected |
| Mollie | Payment processing available to customers | Only if connected |
| Square | Payment processing available to customers | Only if connected |
| Close | CRM integration | Only if connected |
| GoHighLevel | CRM integration | Only if connected |
| Airtable | Data import integration | Only if connected |
| Calendly | Calendar booking integration | Only if connected |
| Typeform | Application form integration | Only if connected |
| Slack | Outbound notifications to customer workspaces | Only if connected |
Entries marked “only if connected” are per-workspace choices. If you never connect Calendly, no data reaches Calendly. If you never configure a payment connector, no data reaches Hyperswitch or any of the payment providers listed.
Our marketing pages also show logos for services we do not currently integrate with. Those are not subprocessors and they are not listed above, because this table describes what actually processes data rather than what is advertised.
TODO: no advance notice period for adding or changing a subprocessor is stated because none is formally set. If one is agreed, it belongs here.8. Where data is stored, and international transfers
Personal data processed through the service is stored in the European Union. The application’s backend runs on Railway in Amsterdam, the Netherlands, and the database is hosted by Supabase in Ireland (the AWS eu-west-1 region). The United Kingdom recognises the European Economic Area as providing adequate protection, so storing data there is not a restricted transfer.
PYLO is operated from Nigeria. Our staff there access personal data held in the service in order to run it, support you and fix faults. That access is a transfer of personal data, including data about people in the United Kingdom, from the United Kingdom to Nigeria. It is the only transfer to us outside the United Kingdom and the European Economic Area.
The United Kingdom has not made an adequacy decision in respect of Nigeria, so that transfer relies on an appropriate safeguard under UK GDPR. The safeguard is the International Data Transfer Agreement (IDTA) issued by the Information Commissioner’s Office. It forms part of our data processing agreement, described in section 12.
The subprocessors listed above operate in various countries, including the United States and the European Economic Area. Where one of them processes personal data outside the United Kingdom and the European Economic Area, that is a transfer on the terms that subprocessor offers for it.
9. How long we keep data
We keep personal data for as long as it is needed for the purpose it was collected for, and then for as long as we need it to meet a legal or accounting obligation.
In practice, data in your workspace stays there for as long as your account is open, because the service is a record and a record that quietly deletes itself is worse than useless to you. Archiving a workspace does not delete anything.
The same is true after you cancel. Your data is retained and stays exportable rather than being deleted on a timer, and you can ask us to delete it at any time. Section 11 says how.
TODO: specific retention periods, including how long data is kept after an account closes, are not stated because no formal schedule is set. Inventing a period here would be a commitment nothing in the product enforces. Deletion on request works today; what is undefined is how long data is kept when nobody asks for it.10. Security
Access to the service requires authentication, and each client workspace is isolated so that one customer’s account cannot reach another’s data. Data is transmitted over encrypted connections. Credentials for connected integrations are held server side and are not exposed to the browser. Access to production systems is limited to those who need it.
We do not hold any formal security certification. We are not SOC 2 certified and we are not ISO 27001 certified, and this policy does not claim otherwise.
Reporting a security issue
If you believe you have found a vulnerability in the service, or you suspect a personal data breach, email security@pylosystem.com. That address exists for this purpose, so a report sent there is not queued behind general support.
Please include enough detail to reproduce what you found. We will not pursue anyone who reports a genuine issue in good faith and does not access, alter or retain other people’s data while investigating it.
TODO: no personal data breach notification timeframe is stated because none is formally set. UK GDPR sets a 72 hour obligation on controllers, and where we act as processor we would need to notify you without undue delay. The specific commitment should be stated here once agreed.11. Your rights
Where UK GDPR applies, you have the right to ask for access to your personal data, to have it corrected, to have it erased, to receive it in a portable form, to restrict how it is processed, and to object to processing carried out on the basis of legitimate interests.
To exercise any of these, email privacy@pylosystem.com. We will need enough information to identify you and to be sure the request is genuinely yours.
Asking us to delete your data
Cancelling a subscription does not delete anything. Your data is retained after you cancel and stays exportable, which is deliberate: a record that quietly erases itself is worse than useless to somebody who later needs it.
You can ask us to delete it at any time, whether or not your subscription is still active, by emailing privacy@pylosystem.com. That request is the erasure route, and it is stated here rather than left implied so that nobody has to work out that retention and deletion are two different things. We will keep only what a legal or accounting obligation requires us to keep, and tell you what that is.
If your data sits in one of our customers’ workspaces then that customer is the controller and the request is properly theirs to answer. Write to them if you know who they are, and to us if you do not, and we will pass it on.
You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner’s Office.
12. Data processing agreement
Where we act as your processor, UK GDPR requires a written agreement between us covering the subject matter of the processing, its duration, and our obligations as processor.
We offer a data processing agreement to every customer. It sets out those terms, lists our subprocessors, and includes the International Data Transfer Agreement for the staff access from Nigeria described in section 8. To request one, email privacy@pylosystem.com with the name of your account.
13. Cookies and analytics
We use cookies that are necessary for the service to work, such as keeping you signed in. These are set only where you have an account and are using it.
Our analytics are aggregate only and do not set cookies or track individuals across sites. We count visits in order to know whether the site is working. There is no advertising network, no cross-site tracking and no profile built about you, which is why this page has no cookie consent banner: there is nothing here that one would be asked to consent to.
14. Changes to this policy
We may update this policy. The date at the top of this page shows when it last changed. Where a change materially affects how we handle personal data we will tell you by email to the account contact, or in the service, before it takes effect.
15. Contact
Umeukeje Chigozie Valentine, trading as PYLO
8 Moronu Maduagwu Street, Lagos, 101283, Nigeria
privacy@pylosystem.com