Parts Requester ← Back to site

Legal

Privacy Policy

Last updated: 9 August 2026

This policy explains how Zylair Ltd handles personal data when you use Parts Requester, our web app for raising and tracking parts, tool and PPE requests. It also explains your rights under UK data protection law.

Parts Requester is a business tool. Your employer or organisation buys a subscription and adds you as a user. For most of the day to day information you enter (requests, photos, comments), your organisation decides how that data is used and is the data controller. Zylair acts as their data processor. For your account and our billing relationship, Zylair is the controller. Both roles are covered below.

1. Who we are

Zylair Ltd ("we", "us", "Zylair") provides the Parts Requester service.

2. When we are controller and when we are processor

We are the controller for:

We are a processor acting on your organisation's instructions for the operational content entered into the app, such as requests, attachments, comments and status history. If you want to exercise your rights over that content, contact your organisation (the controller) first. We will help them respond. Our processor terms are set out in our Data Processing Addendum.

3. The personal data we handle

Account and profile data

DataNotes
Username and full nameUsed to sign in and to show who raised or actioned a request.
Work email and phoneOptional. Used for account setup and status notifications where provided.
Role, department, site, companyControls what you can see and do, and groups your requests.
Profile pictureOptional, if you or an admin upload one.
Last active time and activity logsUsed for security and to keep the service running.

Content you enter

Please only upload photos that are needed for the request. Try not to include people, faces, ID badges or documents unless it is necessary.

Billing data

For the organisation that pays for the service we hold company name, billing address, contact email and phone, and subscription identifiers from our payment provider. We do not store your card details. Card payments are handled directly by Stripe.

Cookies

We use strictly necessary cookies to keep you signed in and the service secure, plus optional product-analytics cookies that you can switch off (see Analytics below). See our Cookie notice for detail.

Analytics

We use privacy-focused analytics to understand how the app and our website are used, so we can improve them. Inside the app we use PostHog (EU region) to measure feature usage and, in some sessions, to record anonymised interactions. Form fields are masked, so the part numbers, prices, suppliers and other details you type are never captured. You can turn this off at any time under Settings → Privacy & analytics. On our public marketing pages we use Umami, which is cookieless and stores nothing on your device.

4. How we use data and our legal basis

PurposeLegal basis (UK GDPR)
Providing the service to you and your organisationPerformance of a contract; and legitimate interests where you are a user under your organisation's account.
The "What is this?" AI part identification and the daily AI stores briefLegitimate interests in helping stores teams identify parts and prioritise work. See section 6.
Status notification emails to the person who raised a requestPerformance of a contract and legitimate interests.
Billing, subscriptions and fraud preventionPerformance of a contract and legal obligation.
Keeping the service secure and diagnosing faultsLegitimate interests in running a safe, reliable service.
Understanding how the app and website are used to improve themLegitimate interests; you can opt out at any time in Settings.
Meeting our legal and tax obligationsLegal obligation.

Where we rely on legitimate interests, we have weighed our interests against your rights. You can ask us for more detail or object at any time.

5. Who we share data with

We do not sell personal data. We share it only with service providers who help us run Parts Requester, and only for that purpose. Our current sub-processors are:

ProviderWhat they doLocation
SupabaseDatabase, login and file storage.EU (Frankfurt, Germany)
VercelApplication hosting and content delivery.EU and USA
StripeSubscription billing and card payments.EU and USA
OpenAIAI part identification from photos and the AI stores brief.USA
ResendSending status notification emails.EU and USA
PostHogProduct analytics — how the app is used (opt-out in Settings).EU (Frankfurt, Germany)
UmamiCookieless visitor analytics for our marketing pages.EU
AttioCustomer relationship management — company and contact records for signups and billing.USA

We may also share data where the law requires it, or to protect our rights, or as part of a sale or reorganisation of our business. We keep an up to date list of sub-processors and will tell customers before we add a new one that materially affects them.

6. AI features

When someone uses the "What is this?" button, the selected photo and related text are sent to OpenAI to return a suggested description. The daily stores brief sends summary request data to OpenAI to produce a short written brief. OpenAI processes this data to return a result and, under its API terms, does not use it to train its models. AI output is a suggestion only. It can be wrong and must be checked by a competent person before acting on it.

7. International transfers

Some providers are based outside the UK, mainly in the USA. Where personal data leaves the UK we rely on appropriate safeguards, such as the UK Addendum to the EU Standard Contractual Clauses or the UK Extension to the EU-US Data Privacy Framework, so your data keeps a similar level of protection.

8. How long we keep data

We keep account and content data for as long as your organisation has an active subscription. After a subscription ends we keep data for a short wind down period and then delete or return it in line with our Data Processing Addendum. Billing and tax records are kept for as long as the law requires (usually six years). Security logs are kept for a limited period.

9. Your rights

Under UK data protection law you have the right to access your data, to have it corrected or deleted, to restrict or object to processing, and to data portability. Where we rely on consent you can withdraw it at any time.

If your data is held because your organisation uses Parts Requester, please contact your organisation first, as they control that data. For account and billing data held by us, email chris@zylair.com. We will respond within one month.

If you are not happy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to put things right first.

10. Security

We use encryption in transit, access controls based on role, and login protections including two factor authentication for privileged accounts. No system is perfectly secure, but we take reasonable steps to protect your data and to detect and respond to problems.

11. Children

Parts Requester is a workplace tool and is not intended for anyone under 16. We do not knowingly collect data about children.

12. Changes to this policy

We may update this policy from time to time. We will change the date at the top and, for significant changes, let customers know.

© 2026 Zylair Ltd. Parts Requester is a product of Zylair Ltd. Contact: chris@zylair.com