Privacy Policy
Deadspot Ltd. · Krag · Last updated September 2026
1. Who We Are
Deadspot Ltd. (company number 17126355) operates Krag, a web-based health and safety management platform for climbing gyms. We are the data controller for personal data collected through user accounts and platform operation, and a data processor for personal data entered by our gym clients.
Data controller: Deadspot Ltd. Contact: inigo@krag.cc. ICO registration number: ZC232145.
2. What Data We Collect
We collect and process different categories of personal data depending on your relationship with the platform.
2.1 Platform users (gym staff)
When a gym creates an account for you, we process:
- Email address
- Encrypted password (we never store or have access to plain-text passwords)
- Role and gym assignments
- Activity on the platform (for audit trail purposes)
2.2 Data subjects (individuals in records)
Gym staff enter data about individuals involved in incidents. This data is entered and controlled by the gym operator. It may include:
- Name, date of birth, phone number, email, and address
- Membership status
- Injury descriptions, affected body areas, and severity (health data)
- Hospital attendance and ambulance records
- Witness details
- Guardian or supervisor contact details (where minors are involved)
If your data has been recorded in an incident report at a climbing gym that uses Krag, the gym is the data controller for that information. Please contact the gym directly to exercise your data rights.
2.3 Website visitors and demo enquiries
Our public website is separate from the platform and requires no account. If you submit the demo-request form, we process:
- First and last name
- Work email address
- Phone number (optional)
- Whether your organisation is a climbing gym, a mat manufacturer, or something else
- For climbing gyms: whether the gym is independent or part of a chain, how many gyms are in the chain, and whether the gym offers bouldering, ropes, or both
- Anything you write in the free-text field
We use this solely to contact you about your enquiry. We do not add you to a mailing list, and we do not pass it to anyone outside Deadspot Ltd.
2.4 Data we do not collect
We do not serve advertising; we do not collect data from third-party sources; and we do not profile users or make automated decisions. The platform uses no analytics. The public website uses cookieless analytics (page views, referring site, country, device type) which does not identify individuals, set cookies, or track you across other websites.
3. How We Use Your Data
| Purpose | Lawful basis |
|---|---|
| Providing the Krag platform and authenticating users | Performance of a contract (with the gym operator) |
| Recording health and safety incidents | Legal obligation (Health and Safety at Work etc. Act 1974, RIDDOR 2013) |
| Maintaining audit trails of platform activity | Legitimate interest (accountability and compliance) |
| Responding to support requests | Legitimate interest (service delivery) |
| Responding to demo requests submitted on our website | Legitimate interest (responding to a business enquiry you initiated) |
4. Cookies
Krag uses only essential cookies required for the platform to function: an authentication token that keeps you logged in (session / refresh cycle), and a refresh token that securely refreshes your session without re-entering your password (up to 7 days), and a marker that records only that you are signed in, so that visiting krag.cc takes you straight to the platform. It contains no personal data and expires with your session (up to 7 days). We do not use analytics cookies, advertising cookies, or any third-party tracking cookies. No cookie consent banner is required as we only use strictly necessary cookies (ICO guidance, UK PECR Regulation 6).
Our public website sets no cookies at all. Its analytics are cookieless and store nothing on your device, which is why you are not asked to accept anything when you visit.
5. Data Storage and Security
5.1 Where your data is stored
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | AWS eu-west-1 (Ireland) |
| Vercel | Application hosting and uploaded file storage | EU, Dublin (dub1) |
| Sentry | Error monitoring | EU, Germany |
| Resend | Sending platform emails (invites, password resets) and demo-request notifications | EU |
| Amazon Web Services (S3) | Encrypted off-site backups | eu-west-2 (London, UK) |
All data remains within the UK/EEA, covered by the UK adequacy decision for EEA transfers.
5.2 Security measures
All connections are encrypted in transit (TLS) and data is encrypted at rest. We apply role-based access control at both application and database levels, row-level security policies ensuring staff can only access their assigned gyms, server-side authentication verification on every request, audit logging of all data access and mutations, and separate staging and production environments.
6. Data Retention
| Data type | Retention period | Basis |
|---|---|---|
| Accident reports (adults) | 3 years from incident date | Limitation Act 1980 |
| Accident reports (minors) | Until the subject's 21st birthday + 3 years | Limitation Act 1980 |
| RIDDOR-reportable incidents | 3 years from date of report | RIDDOR 2013 |
| Matting inspection records | 3 years | HSE guidance |
| User accounts | Duration of service agreement + 90 days | Contract performance |
| Audit logs | Duration of service agreement + 1 year | Legitimate interest |
| Website demo enquiries | 12 months from our last contact with you | Legitimate interest |
7. Your Rights
Under UK GDPR you have the right to access a copy of the personal data we hold about you; to rectification of inaccurate data; to erasure of your data, subject to legal retention requirements; to portability of your data in a standard, machine-readable format; to restriction of processing; and to object to processing based on legitimate interest.
If you are a gym staff member (platform user), contact us directly at the email above. If your data appears in an incident report, the gym that recorded the data is the data controller; please contact them directly, and they can request our assistance in fulfilling your rights. We will respond to all data rights requests within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Third-Party Services
We use the following third-party services to operate the platform:
| Service | Purpose | Data shared |
|---|---|---|
| Supabase Inc. | Database hosting and user authentication | All platform data (stored), login credentials (encrypted) |
| Vercel Inc. | Application hosting and file storage | Data in transit during request handling; uploaded files (photos, signatures, certificates) stored at rest in the EU |
| Functional Software, Inc. (Sentry) | Application error monitoring | Technical error and diagnostic data. Configured to exclude session replay and personal data |
| Amazon Web Services | Encrypted off-site backups | Full database and file backups, encrypted at rest |
| Resend | Email delivery | Recipient email address and message content for invites, password resets, and demo-request notifications |
We do not share personal data with any other third parties.
9. Children's Data
Krag does not offer services directly to children. However, incident reports may contain data about minors involved in climbing gym incidents. This data is entered by gym staff acting under the gym operator's authority as data controller. Enhanced retention periods apply to records involving minors (see Section 6).
10. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated to gym operators via email. The “last updated” date at the top of this page will always reflect the most recent version.
11. Contact
Deadspot Ltd., company number 17126355. Email: inigo@krag.cc.