How Kwilo handles business data, customer details, AI-assisted features, cookies and service responsibilities. Start with the plain-English summary, then open the relevant document for the full wording.
The approach in four short rules, with the longer policies below when you need the exact detail.
You control the business records you add.
Your business normally acts as controller for the customer and business-record data it adds. The privacy notice explains Kwilo’s role, why data is used, and when legal or service reasons mean it must be retained.
We do not sell personal data.
The current privacy notice states that Kwilo does not sell personal data. Business information is used to provide, secure and support the service, subject to the purposes and sharing explained in the notice.
Handled carefully.
Kwilo uses reasonable technical and organisational safeguards for business records, customer details and money workflows. No online service can promise perfect security, so account access remains a shared responsibility.
You stay in charge.
Important customer messages, money actions and tax-related records should be reviewed by you or an authorised person. HMRC filing happens through compatible software or an authorised agent outside Kwilo. AI helps; it does not take responsibility.
What you can verify today.
Trust is not a badge collection. These are the practical points a cautious user is likely to check before moving business records in.
PointWhat to expectStatus
Trying Kwilo
Choose “Give it a try” to see whether requests are open. When they are, submit the form, verify your email and wait for human review. Sign in only if invited.
Access requests opened gradually
Data export and deletion
The privacy notice explains controller and processor roles, retention, individual rights and service or legal limits.
Explained in policy
AI · in plain terms
AI can help. You decide.
AI may help with drafting, transcription, summaries or suggestions. It should stay assistive and reviewable, especially around customers, money and tax.
✓
No public-model training without disclosure and authorisation.The current privacy notice says business data is not used to train public AI models unless that use is explicitly disclosed and authorised.
✓
Every output is reviewable.AI-assisted drafts should be reviewed before they are sent, relied on for pricing, or used for tax or compliance work.
✓
Edit, override, or ignore.If a draft is wrong, change it. If a category looks wrong, review it. If a figure matters, check it before relying on it.
Cookies · in plain terms
Necessary first. Consent for the rest.
The public site should stay light — only what is needed to make it work unless non-essential tools are clearly explained and consented.
✓
Public pages stay available without non-essential consent.Strictly necessary technology may be used where needed. Non-essential use requires a clear explanation and valid consent.
✓
No advertising-tracker default.Advertising or cross-site tracking is not part of the current intended public-site setup. The cookie notice must be updated if that changes.
✓
Consent should be clear.Non-essential cookies should only be used where a proper consent setup explains what they do and how to manage them.
What Kwilo stores, why, and for how long.
The practical categories of data Kwilo may hold, why they are needed, and how retention is handled. The privacy notice carries the full wording and legal context.
DataWhy it is neededHow long it is kept
Your account & sign-in
So Kwilo can recognise your account and send service receipts and reminders.
While needed for the account and legal duties
Quotes, invoices and jobs
So you can find them, send them and use the saved details for billing.
As needed for service or legal duties
Customer contact details
So you can contact customers and route invoices and reminders correctly.
While needed for the record
Voice notes & receipt photos
To turn into quotes, categorise expenses, and back up your records.
As explained in policy
Billing details
To manage subscription billing where payment is set up.
Handled by payment providers
Usage logs
To spot bugs and figure out which features are useful.
As needed to run and secure the service
Protection
Reasonable safeguards, clearly described.
Kwilo uses technical and organisational measures intended to reduce unauthorised access, loss, misuse and disclosure. The security page explains the published boundary.
Access
Access is tied to accounts and permissions.
Signed-in access, workspace roles and permissions help limit who can see or change business records. Businesses still need to manage their users and devices carefully.
Incident
If something goes wrong.
Kwilo investigates reported service and security issues and communicates with affected people where the law or service responsibility requires it.
Read the document that applies.
The summaries above help you find the right subject. These documents contain the detailed wording.