Keruja Privacy Notice
Version 2.0 · Effective date: 13 August 2026
This Privacy Notice explains how WEMOVEON LTD, trading as Keruja, handles personal information in connection with the Keruja website, platform, portals, customer relationships and related business activities.
Keruja is primarily a business-to-business software-as-a-service platform.
A particularly important distinction is that we sometimes act as a Controller of personal information for our own purposes and, in many Keruja workflows, act as a Processor on behalf of our Customers.
1. Who we are
WEMOVEON LTD trading as Keruja
Company number: 10061558
Registered office:
61 Bridge Street
Kington
United Kingdom
HR5 3DJ
General business enquiries: contact@keruja.com
Privacy enquiries, rights requests and data-protection complaints: contact@keruja.com
In this Notice, “Keruja”, “Wemoveon”, “we”, “us” and “our” mean WEMOVEON LTD.
2. Scope of this Privacy Notice
This Notice may apply when you:
- visit a Keruja website;
- request information or a demonstration;
- communicate with us;
- become a Customer;
- administer a Customer Account;
- use a Keruja portal or application;
- interact with Keruja where we determine the purposes of processing; or
- contact us about privacy or security.
Keruja is also used by Customer organisations to process information about their own staff, employees, workers, freelancers, contractors, job applicants, clients, business contacts and Authorised Users.
Where a Customer controls that information, the Customer’s own privacy notice is particularly important.
3. When Keruja is a Processor
For much of the personal information entered into Keruja by a Customer, the Customer determines why the information is processed and how Keruja is to be used.
In those circumstances, the Customer is normally the Controller and WEMOVEON LTD is normally the Processor.
Examples may include information relating to workforce records, job applicants, recruitment, clients, scheduling, jobs and shifts, availability, timesheets, attendance, expenses, payroll preparation, compliance documents, contracts, messages and reports.
We process that information on the Customer’s documented instructions and in accordance with the Keruja Data Processing Addendum.
If you are a worker, applicant or client whose information has been placed into Keruja by a Customer organisation, that Customer is usually the first organisation to contact about how and why your information is being used.
We assist Customers with applicable data-subject requests where required.
4. When Keruja is a Controller
WEMOVEON LTD may act as an independent Controller for personal information which we process for our own purposes.
Examples include processing relating to:
- website visitors;
- enquiries;
- demo requests;
- prospective Customers;
- Customer relationship management;
- Account administration;
- subscription administration;
- billing and accounting;
- fraud and abuse prevention;
- information security;
- our own legal and regulatory obligations;
- contractual records;
- data-protection requests and complaints; and
- our own business operations.
When we act as Controller, the remainder of this Notice explains how we use that information.
5. Categories of personal information
The information we process depends on how Keruja is used.
Identity and contact information
This may include names, email addresses, telephone numbers, postal addresses, business or organisation details, roles or job titles and Account identifiers.
Account and authentication information
This may include Account and membership information, authentication records, session information, security and login records, authentication factors and related metadata.
Passwords and equivalent authentication secrets should be stored using appropriate protected forms rather than as readable passwords.
Workforce and operational information
Depending on Customer use, this may include roles, skills, qualifications, availability, shifts, assignments, working-time information, leave, expenses, internal operational records and performance or review information.
Recruitment and applicant information
This may include application responses, CVs, uploaded documents, profile information, pipeline status, training progress, quiz results, onboarding information and relevant acknowledgements or consent records.
Client and business-contact information
This may include business contact information, event or job information, approvals, communications, service requests and reviews.
Time, attendance and location information
Where relevant functionality is enabled, this may include check-in and check-out timestamps, attendance status, working-time records, GPS location information, attendance evidence, device-derived information and photographs used as attendance evidence.
Compliance and identity documentation
Where Customers choose to use relevant features, this may include right-to-work documentation, passports or other identity documents, visa or residence documentation, training certificates, DBS-related information or records, and document review and expiry information.
Payroll and financial operational information
This may include pay rates, recorded hours, overtime, allowances, payroll-export information, expense information, and payment and billing records.
Depending on Customer configuration, Customer Data may also contain bank or tax-related information.
Contract and signature information
This may include contract contents, signer identity information, electronic-signature records, signature type, signing timestamps, IP address, browser or user-agent information and contract audit information.
Communications and support information
This may include messages, notifications, support tickets, service correspondence, email-related records and feedback.
Files and attachments
This may include CVs, photographs, receipts, documents, evidence files, message attachments and associated metadata.
Technical, security and usage information
This may include IP addresses, browser and device information, session records, log information, audit events, notification tokens, security and anti-abuse indicators and diagnostic information.
Privacy and consent information
This may include cookie choices, privacy acknowledgements, consent type and status, timestamps, withdrawal records, source, and IP address or user-agent information associated with privacy records.
Sales, enquiry and Customer information
Where you interact directly with us, this may include your enquiry, business information, demo requirements, correspondence and notes concerning a potential or existing Customer relationship.
6. Special-category and criminal-offence information
Keruja does not require every Customer to process special-category or criminal-offence information.
However, Customers may use particular functionality in a way that involves higher-risk information.
Examples may include health-related information, right-to-work documentation, information relating to criminal-record checks, and sensitive information contained in documents uploaded by a Customer or data subject.
Customers are responsible for determining whether they have an appropriate lawful basis and, where required, an additional legal condition for processing such information.
Where Keruja processes such information as Processor, we process it on the Customer’s documented instructions subject to our applicable security and data-processing obligations.
Photographs used as attendance evidence are not, merely by being photographs, treated by Keruja as biometric identification templates. If a Customer introduces separate biometric processing, the legal position must be assessed separately.
7. How we obtain personal information
We may receive personal information:
- directly from you;
- from a Customer organisation;
- from an Authorised User;
- from an applicant using a Customer’s recruitment form or widget;
- from a staff or client portal user;
- from information submitted through Keruja;
- from integrations enabled by a Customer;
- from technology and infrastructure providers;
- from payment or communications providers;
- from website and Account security systems; or
- from public or professional sources where appropriate and lawful.
Where personal information is obtained from a Customer rather than directly from the individual, the Customer will normally be responsible for providing the relevant privacy information concerning its purposes.
8. Why we use personal information when we are Controller
Providing and managing our relationship with you
We may process information to respond to an enquiry, arrange a demonstration, take steps towards a contract, manage a Customer relationship, administer Accounts and provide Customer communications and support.
Our legal basis may be performance of a contract, taking steps requested before entering into a contract, or our legitimate interests in operating our business.
Billing and accounting
We may process information to administer subscriptions, issue invoices, process or reconcile payments and maintain accounting and tax records.
Our legal basis may be performance of a contract, legal obligation and legitimate interests in administering our business.
Operating and securing Keruja
We may process technical and Account information to authenticate users, protect Accounts, prevent fraud and abuse, investigate security concerns, manage incidents, diagnose technical problems and maintain audit and security records.
We generally rely on our legitimate interests in providing and protecting the Service and, where applicable, legal obligations relating to security and data protection.
Improving and maintaining our Service
We may use appropriate operational information to diagnose defects, improve reliability, understand aggregate use, improve the Service and plan capacity.
We generally rely on legitimate interests, subject to appropriate safeguards.
Where we can achieve a purpose using genuinely anonymised information, we may use anonymised information instead of identifiable personal data.
Legal and regulatory purposes
We may process information to comply with legal obligations, maintain contractual evidence, respond to authorities where legally required, establish, exercise or defend legal claims, and handle data-protection requests and complaints.
Our legal basis may be legal obligation or legitimate interests in protecting our legal rights.
Consent-based processing
Where applicable law requires consent, including for certain non-essential cookies or similar technologies, we rely on consent.
Consent may be withdrawn at any time for future processing based on that consent. Withdrawal does not affect processing which was lawful before withdrawal.
9. Legitimate interests
Where we rely on legitimate interests, those interests may include:
- operating a sustainable SaaS business;
- providing and improving Keruja;
- protecting Keruja, Customers and users from fraud, abuse and security threats;
- managing Customer relationships;
- maintaining appropriate business and audit records;
- understanding aggregate Service performance; and
- establishing or defending legal rights.
We consider whether those interests are overridden by the rights and interests of affected individuals.
Where the right to object applies, you may object to processing based on legitimate interests.
10. Information required to provide our Service
Some personal information may be necessary in order to create or authenticate an Account, enter into or administer a contract, provide requested functionality, process a payment, meet a legal obligation or protect the Service.
If required information is not provided, we may be unable to provide the relevant Account, Service or business relationship.
Information identified as optional need not be provided unless a particular Customer workflow makes it necessary.
11. AI and automated assistance
AI functionality is not automatically enabled for every Keruja Customer or every Keruja subscription.
Where AI functionality is offered, access may depend on specific Account entitlement, commercial terms, usage allowances and additional data-processing arrangements.
Where external AI processing of Customer Personal Data is contemplated, appropriate contractual, security and privacy review should take place before the relevant Customer functionality is enabled.
Where WEMOVEON LTD acts as Controller, we do not currently intend to make decisions about individuals solely by automated means where those decisions produce legal or similarly significant effects without the safeguards required by applicable law.
Keruja may provide rules-based, algorithmic or AI-assisted decision support. Customer users remain responsible for reviewing outputs and making their own business decisions.
Where a Customer uses Keruja to support its own decisions, the Customer remains responsible as Controller for explaining any relevant automated or profiling activity where data-protection law requires it.
12. Who we share personal information with
We may share or make personal information available to service providers where reasonably necessary to operate Keruja or our business.
Depending on the functionality involved, these may include providers for web hosting, API and application infrastructure, managed databases, cache and queue infrastructure, object and file storage, email delivery, payment processing, monitoring and error reporting, security, and optional Customer integrations.
Current Keruja technology may include services provided by organisations such as:
- Vercel;
- Railway;
- Neon;
- Cloudflare;
- Resend; and
- Stripe.
Not every provider processes every category of information. A provider’s legal role may also differ depending on the particular service it provides.
Where AI functionality is separately enabled and an external AI provider is required to process Customer Personal Data, the applicable provider and processing will be considered as part of the relevant AI and data-processing arrangements.
Malware scanning may be applied to supported file workflows where technically enabled. This does not mean that every Keruja upload is processed through the same malware-scanning service.
We may also disclose personal information where required by law, to a court, regulator or competent authority, to professional legal, accounting or other advisers where reasonably necessary, or in connection with a legitimate investment, merger, restructuring, acquisition or sale subject to appropriate safeguards.
We do not sell personal information to advertisers.
13. International transfers
Some of our service providers may process information outside the United Kingdom.
Where a transfer is a restricted international transfer under applicable data-protection law, we will use an appropriate lawful mechanism or safeguard where required.
This may include an applicable adequacy regulation or decision, the UK International Data Transfer Agreement, an approved UK Addendum to Standard Contractual Clauses, or another transfer mechanism permitted by law.
The appropriate mechanism depends on the provider, destination and processing.
Customers may request further information concerning relevant transfer safeguards where applicable.
Unless expressly agreed for a specific Customer arrangement, Keruja does not promise that all information will remain within one country.
14. How long we keep information
Retention depends on the type of information, why it is being processed, whether Keruja is Controller or Processor, Customer configuration and instructions, contractual requirements, security requirements, applicable legal obligations, and the need to establish, exercise or defend legal claims.
Where Keruja acts as Processor, Customer Personal Data is retained and returned or deleted in accordance with the applicable Customer instructions and Data Processing Addendum.
Where Keruja acts as Controller, we retain information only for as long as reasonably necessary for the relevant purpose, subject to legal, tax, accounting, security, dispute and evidential requirements.
Different Keruja functionality may have different retention behaviour.
We do not promise a universal fixed retention period for all Customer Data or all recovery copies.
When information is no longer required, it may be deleted, anonymised or allowed to expire through applicable system-retention processes.
15. Security
Keruja uses technical and organisational measures intended to provide security appropriate to relevant risks.
Depending on the relevant Service and configuration, those measures may include authenticated access, role-based permissions, organisation and tenant access boundaries, encrypted transport, controlled file access, signed or time-limited access mechanisms, request validation, rate limiting and abuse controls, audit and operational logging, security and error monitoring, protected handling of secrets and authentication credentials, file restrictions, malware controls on supported workflows where enabled, and incident-response processes.
Specific controls may change as technologies and risks evolve.
No internet-connected system can guarantee absolute security. We cannot guarantee that every cyberattack, human error, malicious file, previously unknown vulnerability or third-party failure will always be prevented.
16. Data breaches
Where WEMOVEON LTD acts as Controller, we assess suspected Personal Data Breaches and make notifications to the Information Commissioner’s Office or affected individuals where required by law.
Where we act as Processor and become aware of a Personal Data Breach affecting Customer Personal Data, we notify the relevant Customer without undue delay where required under our Data Processing Addendum.
We may provide information about an incident in stages where full information is not immediately available.
17. Your data-protection rights
Depending on the circumstances, applicable data-protection law may give you rights including:
- the right to be informed;
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restriction;
- the right to data portability;
- the right to object;
- rights concerning certain automated decision-making; and
- the right to withdraw consent where processing is based on consent.
These rights are not absolute and may depend on the legal basis and circumstances.
Your right to object
Where we rely on legitimate interests, you may have the right to object to our processing.
Where the law requires us to stop processing following an objection, we will do so unless an applicable legal reason permits continued processing.
Processor-held information
If Keruja processes your information solely on behalf of a Customer organisation, please normally contact that Customer first. The Customer controls the relevant processing and is responsible for responding to your request. Keruja will provide applicable assistance to the Customer.
Information controlled by WEMOVEON LTD
Where we act as Controller, you can contact contact@keruja.com.
We may need to verify your identity before disclosing or changing personal information.
18. Data-protection complaints
You have the right to raise a data-protection complaint if you believe WEMOVEON LTD has not handled your personal information in accordance with data-protection law.
Where WEMOVEON LTD is the Controller, you may make a complaint using:
Email: contact@keruja.com
or by writing to:
WEMOVEON LTD trading as Keruja
61 Bridge Street
Kington
United Kingdom
HR5 3DJ
When we receive a data-protection complaint, we will:
- acknowledge receipt within 30 days, unless we have already been able to provide a substantive outcome within that period;
- take appropriate steps to investigate the complaint without undue delay;
- make appropriate enquiries;
- keep you appropriately informed where investigation continues; and
- communicate the outcome without undue delay.
We may request information reasonably necessary to understand the complaint, verify identity or confirm authority where somebody complains on another person’s behalf.
If your complaint concerns processing undertaken by a Keruja Customer as Controller, we may direct you to that Customer and assist it where required.
You also have the right to complain to the Information Commissioner’s Office (ICO).
You do not have to give up your right to complain to the ICO by first contacting us.
19. Cookies and similar technologies
Keruja websites and applications may use cookies, browser storage and similar technologies.
Essential
Essential technology is used where reasonably necessary for functionality such as authentication, session management, security, service operation and recording privacy choices.
Where an applicable exemption applies, consent is not required for technology that is strictly necessary to provide a service requested by the user, although we still provide information about its use.
Preferences
Preference technology may remember optional settings such as language, timezone or display choices.
Statistics
Statistics technology may help us understand how the website or Service is used.
Marketing
Marketing technology, where used, may support advertising or cross-site marketing activity.
We will not intentionally use non-essential cookies or similar technologies which legally require consent before the required consent has been obtained.
You can accept optional categories, reject optional categories, choose individual categories where available and change your choices later through .
Withdrawing consent applies to future use of the relevant non-essential technologies.
20. Third-party links and integrations
Keruja may contain links to or integrations with independent third-party services.
Those organisations may process information under their own privacy notices and legal responsibilities.
Customers choosing optional integrations should review the relevant third-party terms and privacy information.
21. Children and young people
Keruja is a business platform and is not intended to be purchased by children as Customers.
Customer organisations are responsible for assessing whether it is lawful and appropriate for them to process information relating to younger workers, applicants or other young people through their own Keruja Account.
Where enhanced legal protections apply to a young person’s information, the relevant Controller must take those protections into account.
22. Changes to this Privacy Notice
We may update this Privacy Notice where necessary to reflect changes in law, Keruja, our providers or our processing activities.
We will update the effective date when we make changes.
Where appropriate, we may provide additional notice of a material privacy change.
23. Contact
For privacy questions, rights requests or data-protection complaints where WEMOVEON LTD is Controller:
WEMOVEON LTD trading as Keruja
Company number: 10061558
61 Bridge Street
Kington
United Kingdom
HR5 3DJ
Privacy enquiries, rights requests and data-protection complaints: contact@keruja.com
General business enquiries: contact@keruja.com
If your information is controlled by a Keruja Customer, please normally contact that Customer first.
© 2026 WEMOVEON LTD. Keruja™ is a trade mark of WEMOVEON LTD.

