Privacy Policy
Version 1.1 | June 2026 | redundly.co.uk
Important — Please Read Carefully
This Privacy Policy explains how Redundly collects, uses, stores, and protects your personal data when you use our website at redundly.co.uk and our redundancy process service. Please read it carefully before using our service. Redundly processes sensitive information about you and your employees as part of generating your redundancy pack. We take our obligations under UK data protection law seriously.
1. Who We Are
Redundly is a trading name of Korlo Ltd, a company registered in England and Wales.
| Trading name | Redundly |
| Legal entity | Korlo Ltd |
| Companies House number | 17280649 |
| Registered address | [Insert registered address] |
| support@redundly.co.uk | |
| Website | redundly.co.uk |
For the purposes of UK data protection law, Korlo Ltd (trading as Redundly) is the data controller in respect of the personal data we collect through this service.
Redundly is the brand name used for this service. All legal obligations, including data protection responsibilities, are held by Korlo Ltd (company number 17280649). References to 'Redundly', 'we', 'us', or 'our' throughout this policy refer to Korlo Ltd trading as Redundly.
2. What Data We Collect
We collect two categories of data when you use Redundly.
2.1 Your personal data (data about you as the employer)
- Your full name and job title
- Your email address and telephone number
- Your company name and company registration number
- Your company address
- Payment information (processed securely by Stripe — we do not store card details)
- Your IP address and browser information collected automatically when you visit our website
- Session data including your form progress and completion status
- Order history and transaction records
2.2 Third party personal data (data about your employees)
As part of generating your redundancy process pack, you may provide us with personal information about the employees being made redundant. In the current version of the service (MVP), the pack is generated using the information you provide about your situation. Future versions of the service will collect more detailed individual employee data. This section describes the full scope of data that may be collected as the service develops.
Employee data that may be collected includes:
- Employee full name and job title
- Employee work location
- Employee start date and length of service
- Employee salary and weekly pay
- Employee contracted hours
- Notice period and holiday entitlement
- Information about protected characteristics where disclosed (for example pregnancy, disability, or maternity leave status)
- Details of any grievances raised or whistleblowing activity
- Selection pool membership and scoring information
This employee data may constitute special category data or sensitive personal data under UK GDPR. We handle it with additional care and it is used solely for the purpose of generating your redundancy process pack.
Your responsibility as employer. You are entering employee personal data into our service as a data controller in your own right. You must ensure you have a lawful basis for sharing this data with us. By using our service, you confirm that you are authorised to process this employee data for the purpose of managing a redundancy process. You should consider whether your own privacy notices to employees cover sharing their data with third party service providers for HR process management purposes.
3. How We Use Your Data
We use the data you provide for the following purposes:
| Purpose | Legal basis under UK GDPR |
|---|---|
| Generating your personalised redundancy process pack | Performance of a contract (Article 6(1)(b)) |
| Processing your payment | Performance of a contract (Article 6(1)(b)) |
| Sending your pack and follow-up emails | Performance of a contract (Article 6(1)(b)) |
| Maintaining records of your order in our admin system | Legitimate interests (Article 6(1)(f)) — maintaining business records |
| Improving our service and fixing technical issues | Legitimate interests (Article 6(1)(f)) |
| Tracking page views and session analytics | Legitimate interests (Article 6(1)(f)) — understanding service usage |
| Complying with legal obligations including tax and accounting | Legal obligation (Article 6(1)(c)) |
| Sending you information about our services where you have consented | Consent (Article 6(1)(a)) |
For special category employee data (such as information about pregnancy, disability, or other protected characteristics), we process this data on the basis of:
- Article 9(2)(b) UK GDPR: processing necessary for carrying out obligations and exercising rights in the field of employment law
- Article 9(2)(f) UK GDPR: processing necessary for the establishment, exercise, or defence of legal claims
4. How Long We Keep Your Data
We retain your data for as long as necessary to fulfil the purposes for which it was collected, subject to the following specific retention periods:
| Data type | Retention period |
|---|---|
| Order records and payment information | 7 years from date of transaction (required for tax and accounting purposes) |
| Your personal data (name, email, phone) | 3 years from your last interaction with our service, unless you request deletion earlier |
| Employee personal data entered into the form | 3 years from the date the pack was generated. This mirrors the recommended period for retaining redundancy process records under UK employment law. |
| Generated documents | 3 years from the date of generation |
| Website analytics and page view data | 26 months |
| Session and form progress data | 90 days from session creation, or until payment is completed |
| Email correspondence | 3 years from last contact |
After the applicable retention period, your data is securely deleted from our systems. You may request earlier deletion at any time (subject to the exceptions below) by emailing support@redundly.co.uk.
We cannot delete data where we are required to retain it for legal or regulatory purposes — for example, financial transaction records which must be retained for 7 years for HMRC purposes. We will always explain our reasons if we are unable to fulfil a deletion request in full.
5. Who We Share Your Data With
We do not sell your data. We do not share your data with third parties for their own marketing purposes. We share data only with the following categories of trusted service providers, and only to the extent necessary to provide our service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Secure database storage for order records, session data, and form inputs | EU (Ireland) |
| Stripe | Payment processing. Stripe does not share your card data with us. | UK / EU / US |
| Resend | Transactional email delivery — pack delivery, order confirmation, and follow-up emails | US (SCCs in place) |
| Lovable | Application hosting and frontend delivery | EU / US |
All third party processors are subject to data processing agreements and are contractually required to process your data only on our instructions and in accordance with applicable data protection law.
We may also disclose your data where required to do so by law, court order, or a regulatory authority including the Information Commissioner's Office.
6. Security
We take the security of your data seriously. Our security measures include:
- All data is encrypted in transit using TLS (HTTPS)
- All data stored in Supabase is encrypted at rest using industry-standard encryption
- Access to our admin systems is restricted to authorised personnel only, protected by strong authentication
- Payment card data is never stored by us — all card processing is handled directly by Stripe under their PCI DSS compliance programme
- Our systems are hosted in the EU (Ireland) to maximise data protection standards
- Admin access requires authenticated login and is not accessible from any public-facing URL
No method of transmission over the internet or method of electronic storage is 100% secure. While we use commercially reasonable means to protect your data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office as required by UK GDPR within 72 hours of becoming aware of the breach.
7. Your Rights Under UK GDPR
You have the following rights in relation to your personal data. To exercise any of these rights, email support@redundly.co.uk. We will respond within one calendar month.
| Your right | What it means |
|---|---|
| Right of access | You can request a copy of the personal data we hold about you. We will provide this within one month. |
| Right to rectification | You can ask us to correct any inaccurate or incomplete data we hold about you. |
| Right to erasure | You can ask us to delete your personal data. We will comply unless we are required to retain it for legal or regulatory reasons (for example, financial records for tax purposes). |
| Right to restrict processing | You can ask us to restrict how we use your data in certain circumstances, for example while a dispute is being resolved. |
| Right to data portability | You can ask us to provide your data in a structured, commonly used, machine-readable format. |
| Right to object | You can object to our processing of your data where we rely on legitimate interests as our legal basis. We will stop processing unless we can demonstrate compelling legitimate grounds. |
| Right to withdraw consent | Where we process your data on the basis of consent, you can withdraw that consent at any time. This does not affect the lawfulness of processing before withdrawal. |
| Right not to be subject to automated decision-making | You have the right not to be subject to solely automated decision-making that produces legal or similarly significant effects. Redundly does not use automated decision-making of this kind. |
| Right to complain | You have the right to complain to the ICO at ico.org.uk if you believe we have not handled your data correctly. ICO helpline: 0303 123 1113. |
Note: some of your rights may be limited where they conflict with our legitimate interests, our legal obligations, or the rights of third parties. We will always explain our reasons if we are unable to fulfil a request in full.
8. Cookies
Our website uses cookies. A cookie is a small text file stored on your device when you visit a website. We use the following categories of cookies:
- Strictly necessary cookies: Required for the website to function. They cannot be disabled. They include session cookies that maintain your form progress and security cookies that protect the site.
- Analytics cookies: We use anonymised analytics to understand how visitors use our site and to improve it. No personally identifiable information is collected through analytics cookies.
- Functional cookies: These remember your preferences and session progress as you complete the redundancy questionnaire.
We do not use advertising cookies or sell your browsing data to any third party. You can control cookie settings through your browser. Disabling strictly necessary cookies may prevent the service from working correctly.
9. International Data Transfers
Some of our service providers are based outside the UK. Where we transfer personal data to countries not recognised as providing an adequate level of data protection, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the ICO
- The ICO International Data Transfer Agreement (IDTA) where applicable
Specifically, Resend is a US-based provider. We have a data processing agreement in place that includes appropriate transfer mechanisms. Stripe operates globally and is subject to its own Privacy Shield and SCC arrangements. Full details of transfer mechanisms are available on request.
10. Employee Data: A Note for Users
When you use Redundly, you may enter personal data about individuals who are not parties to our service agreement — specifically, your employees. These individuals have not consented to their data being provided to us. You are the data controller for that employee data. We process it as your data processor, solely for the purpose of generating your redundancy process pack.
You should ensure that your use of Redundly is consistent with your own obligations to your employees under UK GDPR. In practice, this means:
- You should be able to identify a lawful basis for entering this data into our service (typically legitimate interests in managing an employment process, or performance of an employment contract)
- You should consider whether your employees' privacy notices or your organisation's privacy policy covers the sharing of their personal data with third party HR process tools
- You should not enter more employee data than is strictly necessary for the redundancy process
- You should be aware that data you enter about protected characteristics (such as pregnancy, disability, or trade union membership) constitutes special category data under UK GDPR and requires a specific lawful basis
Redundly will retain employee personal data in accordance with the retention periods set out in Section 4. If you require Redundly to delete employee personal data earlier than these periods — for example to comply with your own obligations as the data controller — you may request this at any time by emailing support@redundly.co.uk.
If you are uncertain about your obligations as a data controller in relation to your employees' personal data, we recommend seeking independent data protection advice before using the service.
11. Automated Processing
Redundly uses automated processing to generate your redundancy process pack based on the information you provide through the questionnaire. This automated processing determines which documents are generated, which risk flags are displayed, and which consultation routes are recommended.
This automated processing does not make decisions about your employees. It generates document templates and process guidance for you as the employer to use. All decisions regarding the redundancy process remain with you. Redundly does not make any employment decisions on your behalf.
If you believe the automated processing has produced an incorrect output based on your inputs, please contact support@redundly.co.uk and we will review your case manually.
12. Children
Our service is intended for use by business owners, HR professionals, and managers acting in a professional capacity. It is not directed at individuals under the age of 18 and we do not knowingly collect personal data from children. If you believe a child has provided personal data through our service, please contact us immediately at support@redundly.co.uk.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our service, our data practices, or applicable law. When we make material changes, we will:
- Update the version number and date at the top of this document
- Where appropriate, notify you by email at the address associated with your account
- Display a prominent notice on our website for 30 days following publication of material changes
The current version and date are shown at the top of this document. Your continued use of our service after any changes constitutes your acceptance of the updated Privacy Policy. We recommend reviewing this page periodically.
14. How to Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or want to raise a concern about how we handle your data, please contact us:
| support@redundly.co.uk | |
| Post | Korlo Ltd (trading as Redundly), [Insert registered address] |
| Response time | We aim to respond to all data-related enquiries within one calendar month |
| ICO registration | [Insert ICO registration number once obtained] |
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office:
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Korlo Ltd (trading as Redundly) | Company number: 17280649 | redundly.co.uk | support@redundly.co.uk
This document should be reviewed by a qualified solicitor or data protection specialist before publication.