Legal

Privacy Policy

This Privacy Policy explains how NeonStack Ltd, trading as Native Keeper, collects, uses, shares and protects Personal Data.

Last updated: 10 June 2026 · Version 1.0

1. Introduction

NeonStack Ltd is registered in England and Wales under company number 16933096, with its registered office at The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD. We trade as Native Keeper ("Native Keeper", "we", "us", or "our").

Native Keeper is an HR and workforce compliance platform. Businesses of any size, in any industry, and in any country use us to manage employee records, track compliance with regulatory and internal deadlines, and run HR operations. Because our customers handle data about their own people, we take our responsibilities as a platform very seriously.

This Policy is written in plain English wherever possible. If anything is unclear, contact legal@nativekeeper.com.

The two roles we play

  • Controller: This applies when you visit our website, sign up as a customer, contact us, or use the Service as an account administrator. We decide what happens to Personal Data about you as our customer or website visitor, and this Policy applies in full.
  • Processor: This applies when an employer uses Native Keeper to hold records about employees, workers, contractors, and others. The employer or customer decides what happens to that data, not us, and their privacy notice governs that processing.

If you are an employee, worker, or contractor of a Native Keeper customer and want to know how your employer uses your data or exercise your rights, contact your employer. Section 11 explains the limited things we can help with directly.

2. What Personal Data we collect (when we are the Controller)

These categories apply to visitors and customers of Native Keeper, not to individuals whose records are held in the Service by our customers.

2.1 Information you give us

  • Account information: Name, work email address, hashed password, profile photo, job title, company name and country, collected when you sign up.
  • Billing information: Billing name, address, VAT number where applicable, and payment-card last four digits and expiry. Stripe handles full card numbers directly; we never store them.
  • Communications: Messages and attachments sent through support chat, email or contact forms.
  • Marketing preferences: Your subscription state for newsletters, product updates and similar communications.

2.2 Information collected automatically

  • Usage data: With your consent on public pages: referral source, pages visited, time spent, clicks, navigation paths and privacy-masked visual playback of page interactions. Input values, authenticated account pages and employee records are excluded.
  • Device and technical data: IP address, browser and operating-system details, device type, screen resolution, language settings and time zone.
  • Cookies and similar technologies: Session, authentication and, with consent where required, analytics cookies. See our Cookie Policy.
  • Error and performance data: Diagnostic information when the Service fails or behaves unexpectedly.

2.3 Information from third parties

  • Authentication data: If you use a third-party identity provider such as Google or Microsoft, we receive your name, email and profile image under that provider's privacy notice.
  • Payment confirmations: Transaction confirmations and metadata from Stripe.
  • Public information: Information you publicly share about your business or Native Keeper usage.

2.4 Special categories of Personal Data

As Controller, we do not intentionally collect data revealing health, religion, ethnicity, political opinions, sexual orientation, trade-union membership, biometric or genetic data, or criminal-offence data. Do not include it in support conversations unless strictly necessary. Where customers hold such employee data in the Service, we act as Processor and Section 4 applies.

3. How we use your Personal Data (when we are the Controller)

We process Personal Data for the following purposes and legal bases under UK GDPR and EU GDPR:

  • Providing the Service: Account creation, data hosting and subscribed features — performance of a contract (Art. 6(1)(b)).
  • Billing and payments: Subscription fees, invoices, refunds and debt recovery — performance of a contract and legal obligations for tax records (Art. 6(1)(c)).
  • Service communications: Account notifications, security alerts, terms updates, billing reminders and relevant product notifications — contract and legitimate interests (Art. 6(1)(f)).
  • Customer support: Responding to queries and troubleshooting — contract and legitimate interests.
  • Product improvement: Privacy-masked analytics and visual playback on public website pages — consent (Art. 6(1)(a) UK/EU GDPR and PECR). Operational diagnostics that are strictly necessary to secure and maintain the Service rely on legitimate interests.
  • Marketing communications: Newsletters, product announcements and educational content — consent (Art. 6(1)(a)) or UK PECR soft opt-in where applicable.
  • Security and fraud prevention: Preventing abuse and unauthorised access, protecting against attacks and enforcing our Terms — legitimate interests.
  • Legal compliance: Lawful requests, tax and accounting obligations, and disputes — legal obligations and legitimate interests.
  • Aggregated insights: Anonymous usage statistics that cannot identify you — legitimate interests.

We use legitimate interests only after a balancing test. Request our assessments at legal@nativekeeper.com.

We do not sell Personal Data, use Personal Data to train general-purpose AI models, or make solely automated decisions that produce legal or similarly significant effects.

4. Data our customers hold about employees and workers (when we are the Processor)

4.1 Our role and your employer's role

Your employer, agency or similar organisation is the Controller: it decides what data to collect, why and how long to keep it. Native Keeper is the Processor: we store, secure and make the data available only on its instructions under our Data Processing Agreement.

4.2 The kinds of data customers may hold

  • Identifiers, contact details and emergency contacts.
  • Employment details including job title, department, start date, employment type, location and manager.
  • Compliance documents such as Right to Work evidence, qualifications, training certificates, DBS or background checks, driving licences and insurance certificates.
  • Training, competency, absence, leave, attendance, performance, review, and health-and-safety records as those features ship.
  • Payroll-related identifiers as integrations ship, and other information configured by the customer.

This may include Special Category data under Article 9 or criminal-offence data under Article 10. Customers must establish an appropriate lawful basis under applicable law before using the Service to hold it.

4.3 What we do with employee data

We process employee data only on documented customer instructions, to provide, secure and maintain the Service, to send relevant notifications, and to comply with law.

We do not use employee data for our marketing, profiling or commercial purposes; sell or share it; use employee-record content to train AI models; cross-reference data between customers; or share it outside the Sub-processors listed on our Sub-processors page.

4.4 Aggregated and anonymised insights

We may produce aggregated, de-identified statistics to improve the Service, benchmark performance or share generally. They cannot identify a person, customer or employee and do not contain specific employee-record content.

5. AI and automated processing

  • We do not use Customer Personal Data, including employee-record content, to train general-purpose AI models.
  • Third-party AI providers must contractually agree not to use customer data for training.
  • We do not make solely automated decisions producing legal or similarly significant effects.
  • Customers remain responsible for decisions supported by AI, including Article 22 compliance.

We will update this Policy and the DPA when AI features are added to the Service.

6. Who we share Personal Data with

6.1 Sub-processors

We use contracted providers for hosting, databases, payments, email delivery, error monitoring and similar functions. See the full list and safeguards at nativekeeper.com/legal/sub-processors.

6.2 Our customers

Where a customer holds data about you, that customer is the Controller. We do not share data between customers.

6.3 Professional advisers

Lawyers, accountants, auditors, insurers and other advisers may receive access where necessary under confidentiality obligations.

6.4 Authorities

We may disclose Personal Data where legally compelled. We review requests, challenge overbroad or unlawful ones, and notify affected customers where permitted.

6.5 Corporate transactions

Data may transfer during a merger, acquisition, restructuring or asset sale. We will notify you before it becomes subject to a different privacy policy.

6.6 With your consent

We ask for consent before any other sharing.

7. International data transfers

We are based in the UK. Some Sub-processors are outside the UK and EEA, primarily in the United States. Safeguards may include adequacy decisions, EU Standard Contractual Clauses with the UK International Data Transfer Addendum, the EU-US Data Privacy Framework and UK extension, and supplementary technical and organisational measures.

Regional data residency is available on supported plans. Contact legal@nativekeeper.com for details or to request safeguards for a specific transfer.

8. How long we keep Personal Data

8.1 Customer data where we are Controller

  • Account data: Account duration plus 30 days; backups expire within 90 days.
  • Billing and tax records: Seven years from the end of the relevant accounting period.
  • Support communications: Three years from the conversation.
  • Marketing data: Until unsubscribe or three years of inactivity, whichever is sooner.
  • Security and audit logs: 12 months.
  • Cookies: As stated in our Cookie Policy.

8.2 Customer-held employee data where we are Processor

Employment records may have statutory retention periods varying by country, industry and type. UK examples include payroll records typically kept six years, working-time records two to three years, some pension records up to 40 years, health-and-safety incidents three years or more, and regulated-industry records often six years or more.

Retention is controlled by the customer. Customers can configure rules, manually delete records and export data. On account termination, we delete data under Section 10 of our DPA.

9. How we keep Personal Data secure

Measures include TLS 1.2 or later in transit, AES-256 encryption at rest, role-based access, multi-factor authentication, least privilege, firewalls, DDoS protection, intrusion detection, code review, dependency scanning, vulnerability management, personnel confidentiality and training, vendor due diligence, tested backups and disaster recovery, and incident procedures designed for 72-hour breach-notification duties.

More detail is available on our Security page. No system is perfectly secure; report concerns to legal@nativekeeper.com.

10. Your rights

Subject to applicable conditions and exemptions, you may have rights of access, rectification, erasure, restriction, portability, objection, consent withdrawal, and protection from solely automated decisions producing legal or similarly significant effects.

How to exercise your rights

Email legal@nativekeeper.com. We normally respond within one month, extendable by up to two months for complex requests with notice. We verify identity and charge no fee unless a request is manifestly unfounded, excessive or repetitive.

Right to complain

You may complain to a Supervisory Authority. In the UK, contact the Information Commissioner's Office, or contact the authority where you live, work or believe an infringement occurred. We would appreciate the opportunity to address your concern first.

11. If your data is held by your employer

Your employer is the Controller and primary privacy contact. Contact it to exercise rights over information it uploaded.

If you cannot identify the Controller or it does not respond, email legal@nativekeeper.com. We can help identify and forward a request, but cannot disclose, delete or modify Controller-held records without authorisation unless legally required.

If you believe data is being misused, raise it with the employer, complain to the ICO or local authority, or report it to us. We take reports seriously and may act under our Acceptable Use Policy.

12. Cookies and tracking technologies

We use cookies and similar technologies on nativekeeper.com. Optional PostHog analytics and privacy-masked visual playback begin only after consent and are limited to public marketing pages. Form inputs, authenticated areas, employee portals, registration, login, signup and quote routes are excluded.

You can refuse without losing access to the website, withdraw consent at any time through "Cookie preferences" in the footer, and exercise rights of access, erasure, restriction and consent withdrawal as described in Section 10. Categories, providers, durations and controls are detailed in our Cookie Policy.

13. California residents (CCPA/CPRA)

In the past 12 months, we have collected identifiers; customer records; commercial information; internet activity; approximate geolocation derived from IP; professional or employment information for account holders; and analytics inferences. Sources, uses and recipients are described in Sections 2, 3 and 6.

California residents may have rights to know, delete, correct, opt out of sale or sharing, limit sensitive-information use, and receive non-discriminatory treatment. We do not sell Personal Information or share it for cross-context behavioural advertising.

To exercise these rights, email legal@nativekeeper.com. We verify identity and accept requests from authorised agents.

14. Other jurisdictions

Depending on location, the EU GDPR, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection, Canadian PIPEDA, Brazilian LGPD, Australian Privacy Act, and other national or sub-national laws may apply. We honour additional rights where legally required. Contact legal@nativekeeper.com.

15. Children's data

The Service is not directed to children under 16 as a consumer product, and we do not knowingly collect their data as Controller. Customers managing young workers, apprentices or students are responsible for establishing a lawful basis and obtaining parental consent where required.

16. Links to other websites

The Service may link to third-party websites. We are not responsible for their privacy practices; review their notices separately.

17. Data Protection Officer and Representatives

Data Protection Officer

Native Keeper is not currently required to appoint a DPO under Article 37 UK/EU GDPR. Our legal and privacy team handles queries at legal@nativekeeper.com. We keep this under review.

EU Representative

Native Keeper is not established in the EEA. We will appoint an Article 27 EU Representative and update this Policy when our EEA offering reaches a scale that requires one.

UK Representative

Not required because NeonStack Ltd is established in the United Kingdom.

18. Changes to this Policy

We may update this Policy from time to time. We will update the date above and, for material changes, notify you by email and/or in-product notice at least 30 days before the change takes effect. Continued use after the effective date constitutes acceptance of the updated Policy.

19. Contact us

NeonStack Ltd
The North Colchester Business Centre
340 The Crescent
Colchester, England, CO4 9AD
United Kingdom

UK complaints: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone: 0303 123 1113.