Privacy Policy
Last updated: 4 October 2026
This Privacy Policy explains how DEA Bookkeeping and Payroll Services (Sole Trader), trading as Delayo. ("we", "us", "our"), collects, uses, stores and protects your personal data when you use delayo.uk (the "Service") to prepare and submit a UK train Delay Repay claim. We act as the Data Controller for the personal data described below.
1. Who we are
DEA Bookkeeping and Payroll Services (Sole Trader) operates Delayo. as an independent claim-preparation and digital representation service. We are not National Rail, the Rail Delivery Group, or any Train Operating Company ("TOC"). For any data protection query, contact us at dea.payroll@gmail.com.
2. What personal data we collect
- Identity & contact data: full name, email address, postal address/postcode.
- Journey data: departure/arrival stations, journey date, scheduled and actual arrival times, Train Operating Company, ticket price.
- Ticket proof: a photo or PDF of your train ticket, uploaded by you and, if you use the AI scanner, processed by an OCR model to pre-fill the form.
- Payment data: we never see or store your card details. Payments are processed entirely by Stripe, our PCI-DSS compliant payment processor.
- Technical data: IP address and request metadata, processed transiently for rate-limiting and fraud/abuse prevention (see Section 7).
- Analytics data: if you consent via our cookie banner, Google Analytics 4 collects standard usage data (pages viewed, approximate location from IP, device/browser type, referral source) to help us understand how the Service is used. This is only collected if you actively consent — see our Cookie Policy.
3. Why we process your data (legal basis)
- Performance of a contract (UK GDPR Art. 6(1)(b)): to generate your Letter of Authority, verify eligibility, and submit your claim to the relevant TOC on your behalf once you pay the £2.00 processing fee and confirm your consent.
- Consent (Art. 6(1)(a)): for optional, non-essential cookies and for the specific authorisation you grant us to act as your representative (see our Authority to Act explanation).
- Legitimate interests (Art. 6(1)(f)): to secure the Service against abuse (rate limiting), and to keep accounting records of fees paid.
4. How your data is protected
Personal identifiers you submit are encrypted at rest using AES-256-GCM authenticated encryption before being included in any stored payload. Traffic to and from delayo.uk is secured with TLS/HTTPS. Uploaded ticket files are held only in server memory for the duration needed to generate your claim documents and are never written to disk.
5. Data retention & automatic deletion
Claim data (your details and uploaded ticket) is held only for as long as necessary to complete your claim. Once your Letter of Authority has been generated, paid for, and dispatched to the Train Operating Company, it is deleted from our active systems. If a claim is started but never paid for, it is automatically purged after a short retention window (currently within 48 hours) so no personal data lingers indefinitely.
Copies of the Letter of Authority sent to you and to the operator by email exist in your own mailbox and the operator's mailbox, which are outside our control and subject to your/their own retention settings.
6. Who we share your data with
- The relevant Train Operating Company — necessary to submit your claim.
- Stripe, Inc. — payment processing for the £2.00 fee.
- Resend — transactional email delivery of your claim and confirmation emails.
- OpenAI — only if you use the optional "Scan Ticket" AI feature, your ticket image is sent to OpenAI's Vision API purely to extract journey text; it is not used by us to train any model.
- Sentry — error monitoring. Error reports are configured to avoid including passenger PII (name, email, address); only technical context (claim reference, error type) is captured.
- Google Analytics 4 (Google Ireland Ltd. / Google LLC) — website usage analytics, and only if you have given cookie consent for analytics (see Section 9 and our Cookie Policy).
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
7. International transfers
Some of our processors (e.g. OpenAI, Stripe, Resend, Sentry, Google Analytics) may process data outside the UK/EEA. Where this happens, we rely on those providers' UK/EU-approved safeguards (such as Standard Contractual Clauses) as required by UK GDPR.
8. Your rights
Under UK GDPR you have the right to: access your data; rectify inaccurate data; request erasure; restrict or object to processing; and data portability. To exercise any of these rights, email dea.payroll@gmail.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
9. Cookies
See our separate Cookie Policy for full details of the cookies and similar technologies used on this site, and how to control them via the cookie banner.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
11. Contact
Questions about this policy or your data: dea.payroll@gmail.com.
This page is provided for transparency and general information and does not constitute legal advice. If you require a policy tailored and signed off for regulatory purposes, please have it reviewed by a qualified UK data protection solicitor.