LEGAL

Privacy Policy.

What we collect about your business and your guests, why we collect it, who ever sees it, and the rights you and the people in your data can exercise. Written to be read alongside the Terms of Use.

Last updated 15 August 2026

1.Introduction

When you use Pello, you trust us with information about your business and, sometimes, about people — your team members and your guests. This Privacy Policy explains what information we collect, why we collect it, how we use it, how we protect it, and the choices and rights you have. It is written to be read alongside the Pello Terms of Use, and where the two overlap we point you to the relevant section of the Terms.

Pello is an AI-powered revenue assistant for lodges, hotels and hospitality businesses. It analyses business information you upload — such as cashflow data, room rates, occupancy figures and booking records — to provide benchmarking insights, revenue suggestions and marketing campaign recommendations (Terms s.2).

Who we are

Pello is operated by Purple Kenyan Ventures Limited, registered in the United Kingdom with registered address Techno Centre, Station Road, Horsforth, Leeds, LS18 5BJ, United Kingdom (“Pello”, “we”, “us”). For personal data contained in the Customer Data you upload, your business is the data controller and we act as data processor on your instructions (Terms s.3.6). For account and usage data described in section 2 below, we act as data controller.

2.Information We Collect

2.1Information you give us

  • Account information: your name, business name, email address, phone number, role, and login credentials when you create an account.
  • Customer Data you upload: business and financial information such as cashflow statements, rate cards, occupancy data, and booking records. Booking records may include personal data about your guests (e.g. names, stay dates, nationality, contact details). You are responsible for ensuring you have a lawful basis to upload this data (Terms s.3.6).
  • Communications: messages you send us, support requests, and feedback, including reports you make through the in-app content flagging mechanism (Terms s.5.1).

2.2Information we collect automatically

  • Usage information: features used, queries run, Outputs generated, and interactions with suggestions, so we can operate and improve the service.
  • Device and log information: IP address, browser or app version, device type, operating system, access times, and crash data.
  • Cookies and similar technologies: we use strictly necessary cookies to keep you signed in and, with your consent where required, analytics cookies to understand usage. You can manage cookies through your browser or in-app settings.

2.3Information we do not collect

We do not collect payment card details directly — payment processing is handled by Purple Kenyan Ventures Limited. We do not knowingly collect information from anyone under 18: Pello is a business tool and is not directed at children (Terms s.5.2).

3.Why We Collect Information and How We Use It

We use information for the following purposes, and only these purposes:

  • To provide the service: generating benchmarks, revenue suggestions and marketing campaigns from your Customer Data (Terms s.3.3(a)).
  • To maintain and improve the service: troubleshooting, security monitoring, and understanding how features are used so we can make them better (Terms s.3.3(b)).
  • To provide benchmarking: using aggregated and anonymised data across Pello customers. Aggregated data never identifies you, your business, or your figures, and no customer can see another customer’s underlying data (Terms s.3.4).
  • To communicate with you: service announcements, security alerts, support responses, and — with your consent — product updates you can opt out of at any time.
  • To meet legal obligations: complying with applicable law, lawful requests from authorities, and enforcing our Terms (Terms s.3.3(c)).

What we do not do

  • We do not sell your data. We do not share your Customer Data with third parties for their own marketing or commercial purposes (Terms s.3.2).
  • We do not use your Customer Data to train generalised AI models, and we contractually require our AI model providers not to do so (Terms s.3.8).
  • We do not use your data for advertising, and we do not build advertising profiles.

3.1Legal bases (where GDPR/UK GDPR applies)

Where we act as controller, we rely on: performance of a contract (providing the service you signed up for); legitimate interests (securing and improving the service, in ways you would reasonably expect and that do not override your rights); consent (optional analytics cookies and marketing communications); and legal obligation (where law requires processing). We also comply with other data protection laws applicable where our customers operate, including the Kenya Data Protection Act, 2019 where it applies.

4.When We Share Information

We share information only in these limited circumstances:

  • With your consent or at your direction — for example, if you connect Pello to another tool or export a campaign to a marketing platform.
  • With service providers (sub-processors): trusted providers such as cloud hosting and AI model providers who process data only on our instructions, under confidentiality obligations, and only as necessary to deliver the service (Terms s.3.5). A current list is available on request.
  • For legal reasons: where disclosure is required by law, regulation, legal process, or enforceable governmental request, or to protect the rights, property or safety of Pello, our customers, or the public. Where lawful, we will notify you before disclosing your Customer Data.
  • Business transfers: if we are involved in a merger, acquisition or asset sale, we will ensure the confidentiality of your data, notify you before your data becomes subject to a different privacy policy, and honour the commitments in this policy.

We never share Customer Data between customers: no customer can see another customer’s underlying data (Terms s.3.4).

5.International Data Transfers

Your information may be stored or processed outside the United Kingdom, for example on cloud infrastructure or by AI model providers located abroad. Where personal data is transferred internationally, we comply with applicable transfer rules — including, under the UK GDPR and GDPR, approved mechanisms such as adequacy regulations or decisions, the UK International Data Transfer Agreement or Addendum, and Standard Contractual Clauses (Terms s.3.7).

6.How We Keep Information Secure

We work hard to protect your information from unauthorised access, alteration, disclosure or destruction. Our measures include encryption in transit and at rest, access controls and least-privilege access for staff, logging and monitoring, and regular review of our security practices (Terms s.3.9).

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and assist with your own notification obligations, including to the UK Information Commissioner’s Office (ICO) or other applicable regulators where required (Terms s.3.9).

7.How Long We Keep Information

  • Customer Data: retained while your account is active. On termination, deleted or anonymised within 90 days, except where retention is required by law (Terms s.3.10).
  • Account information: retained while your account is active and for 12 months afterwards for legal and audit purposes.
  • Usage and log data: retained for 12 months, then deleted or anonymised.
  • Aggregated, anonymised data (which no longer identifies anyone) may be retained for benchmarking.

8.Your Rights and Choices

Depending on applicable law (including the UK GDPR and, where applicable, the GDPR and other local data protection laws), you and the individuals whose data you upload have the right to:

  • Access the personal data we hold, and receive a copy;
  • Correct inaccurate or incomplete data;
  • Delete data, and export Customer Data at any time (Terms s.3.10);
  • Object to or restrict certain processing;
  • Withdraw consent where processing is based on consent, without affecting prior processing;
  • Portability — receive personal data in a structured, commonly used, machine-readable format;
  • Complain to a supervisory authority — in the UK, the Information Commissioner’s Office (www.ico.org.uk); elsewhere, your local data protection authority.

Where we process guest personal data as your processor, we will assist you in responding to requests from those individuals (Terms s.3.10). To exercise any right, contact us at pello@purpleelephant.ventures. We respond within the timelines required by applicable law.

9.AI and Automated Processing

Pello uses artificial intelligence to generate benchmarks, suggestions and campaigns. These Outputs are informational suggestions only and require human review before implementation (Terms ss.4.1, 4.5). Pello does not make automated decisions that produce legal or similarly significant effects on individuals, and the Terms prohibit customers from using it that way without meaningful human review (Terms s.4.5).

10.Children

Pello is not directed at, or intended for use by, anyone under 18 (Terms s.5.2). If you believe a child has provided us personal data, contact us and we will delete it.

11.Changes to This Policy

We may update this policy from time to time. We will not reduce your rights under this policy without your explicit consent. Material changes will be notified to you by email or in-app at least [14] days before taking effect, consistent with the Terms (Terms s.10), and we will keep prior versions available on request.

12.Contact Us

Data protection queries, rights requests, or complaints: pello@purpleelephant.ventures.

GET IN TOUCH

Questions before you join?

We're a small team building Pello for hospitality properties across Africa — and we read every message. Your data stays yours; we never share it.

Join the beta
Pello· Made with love at Purple Elephant Ventures · © 2026