Effective 2 October 2026 · Version 1.0 · part of the Anvul terms of service

1. Who does what

1.1 For the personal data you handle through Anvul — the people who contact you, your customers, the people named in your jobs, and your crew — you are the controller and Anvul is your processor. You decide why and how that data is used; we handle it for you.

1.2 Where we handle personal data for our own purposes — your account, billing, our messages with you, security logs and our own marketing — we are the controller, and our privacy policy applies instead.

1.3 If these terms and the terms of service disagree about personal data, these terms win.

1.4 Your side. You are responsible for having a lawful reason to collect and use the personal data you handle through Anvul, for telling people how you use it, and for the instructions you give us.

2. What we process for you

The details — subject matter, duration, nature and purpose, the types of personal data and the people it is about — are in Annex 1.

3. Your instructions

3.1 We process the personal data only on your documented instructions, including about transfers outside the UK. Your instructions are: the terms of service and these terms; the features and settings you use in Anvul (for example sending a quote, a reminder or a review request); and anything you ask us to do in writing, including in Messages with Anvul, by the account owner or someone they have authorised.

3.2 We only transfer the personal data outside the UK as section 8 allows. If the law requires us to process it in some other way, we will tell you before we do, unless the law forbids that.

3.3 If we think an instruction breaks data protection law, we will tell you straight away, and we need not follow it until it is resolved.

3.4 Standing instructions. You instruct us to:

4. Our people

Only Anvul staff and contractors who need the personal data to run the service, or to help you when you ask, can access it, and each of them is bound by a duty of confidentiality.

5. Security

We take the technical and organisational measures that UK GDPR Article 32 requires, appropriate to the risk. They are summarised in Annex 2 and on our security page, and we review them as the service changes.

6. Sub-processors

6.1 You authorise us to use the sub-processors listed in Annex 3.

6.2 Before we add or replace a sub-processor, we will email you at least 30 days ahead, saying who it is and what it will do. In an emergency — for example replacing a provider that has failed — we will tell you as soon as we can.

6.3 You can object within that time by emailing [email protected] with your reasons. We will try to address them. If we can’t, you can stop using the affected part of Anvul, or cancel your website, before the change takes effect, and we will refund any part of a month you have paid for but won’t receive.

6.4 Each sub-processor is bound by written terms that protect the personal data at least as well as these terms do. We remain responsible to you for what our sub-processors do.

7. Helping you

7.1 Taking into account what the service does, we help you answer requests from people about their data — access, correction, erasure, restriction, portability and objection. Much of this you can do yourself in the app. If a request reaches us directly, we pass it to you without undue delay, unless the standing instruction in section 3.4 covers it.

7.2 We help you meet your duties under UK GDPR Articles 32 to 36: keeping the data secure, dealing with a personal data breach, carrying out a data protection impact assessment, and consulting the regulator before processing where that is needed. We give you the information we reasonably can about the processing we do for you.

8. Where the data goes

Our servers and database are in London. Some sub-processors handle data outside the UK (see Annex 3). We only make those transfers in one of the ways UK law allows: to a country the UK recognises as giving adequate protection (such as the European Economic Area); to a US company certified to the UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”); or under the UK International Data Transfer Agreement (IDTA), or the European Commission’s Standard Contractual Clauses with the UK Addendum, after a transfer risk assessment. Email [email protected] for a copy of the safeguard for any provider.

9. If something goes wrong

If we become aware of a personal data breach affecting the personal data we process for you, we will tell you without undue delay. We will tell you what happened, what data and roughly how many people are involved, the likely consequences, what we have done about it, and who to contact. We will keep you updated as we learn more, and help you decide whether you need to report it to the regulator (normally within 72 hours of you becoming aware) or tell the people affected.

10. When you leave

When you close your Anvul account, or ask us to, we will — at your choice — give you a copy of the personal data in a common format and then delete it, or simply delete it. You can also download a copy yourself at any time from Settings → Your data in the app. Unless you ask us to delete it sooner, we keep the data for 12 months after you close your account (so that you can come back, or ask for a copy), then delete it. We keep only what the law requires us to keep, and keep it protected. Cancelling your website subscription alone doesn’t close your account (see the terms, section 10).

11. Showing we comply

We will give you the information you reasonably need to show that we meet these terms. Where that isn’t enough, or the regulator requires it, we will allow and contribute to an audit or inspection by you or an auditor you appoint, on at least 30 days’ notice, during working hours, no more than once a year (unless after a breach), under a confidentiality agreement and without access to other customers’ data. Normally we start by answering your written questions. Each side pays its own costs, unless the audit shows we materially broke these terms.

12. Our own uses

We may use the personal data to keep the service secure, and to create anonymised, aggregated statistics — for example totals and averages across Anvul — that do not identify you, your customers or anyone else. Once data is truly anonymous it is no longer personal data. We never sell the personal data, use it to market to your customers, or share it with your competitors.

13. Liability

Each side’s liability under these terms is subject to the limits in section 9 of the terms of service, except where the law does not allow it to be limited.

14. Changes

We may update these terms to reflect changes in the law or in our sub-processors. A new sub-processor follows section 6. Any other change that reduces your protection follows the 30-day notice in section 12 of the terms of service.

Annex 1 — Details of the processing

Annex 2 — Security measures

Annex 3 — Sub-processors

These providers may handle personal data you control, on our instructions and under written terms. Some only take part when you use a particular feature, as the table says.

ProviderWhat it does for youWhereSafeguard for transfers
Fly.io, Inc. Runs our servers. London, UK Data stays in the UK. Any access from the US: the UK–US data bridge where Fly.io is certified to it, otherwise the IDTA or UK Addendum.
Neon, Inc. Hosts our database. London, UK (AWS eu-west-2) Data stays in the UK. Any access from the US: the UK–US data bridge where Neon is certified to it, otherwise the IDTA or UK Addendum.
Cloudflare, Inc. Hosts your website; stores photos, files and backups; receives email sent to Anvul inboxes. Global network; file storage not pinned to one country The UK–US data bridge where Cloudflare is certified to it, otherwise the IDTA or UK Addendum.
Stripe Takes card payments, including payments your customers make to your own Stripe account. Stripe is also its own controller for the payment data it needs. UK, EEA and US The UK–US data bridge where Stripe is certified to it, otherwise the IDTA or UK Addendum.
Resend Delivers the emails Anvul sends for you (enquiry alerts, quotes, reminders, review requests). United States The UK–US data bridge where Resend is certified to it, otherwise the IDTA or UK Addendum.
Functional Software, Inc. (Sentry) Error reports, so we can fix faults. Set up to leave out request contents and contact details; an error report may occasionally include part of a record. United States or EU The UK–US data bridge where Sentry is certified to it, otherwise the IDTA or UK Addendum.
Google LLC (Gemini API) AI that helps us draft your website’s text from your brief and notes, and — only if you use the contract-inbox feature while it is being tested — reads job packs you receive to pull out job details, which can include residents’ names and addresses. United States and other countries The UK–US data bridge where Google is certified to it, otherwise the IDTA or UK Addendum.
Google LLC (Maps Platform) Finds the location of an address (for example a house number and postcode) and shows maps. United States and other countries The UK–US data bridge where Google is certified to it, otherwise the IDTA or UK Addendum.
Ideal Postcodes Looks up addresses from a postcode typed into a form on your website. UK Not needed (UK).
Modal Labs, Inc. Processes room photos and scan videos — only when you use the photo-measuring or scan features while they are being tested. United States The UK–US data bridge where Modal is certified to it, otherwise the IDTA or UK Addendum.
Google, Apple and Mozilla push services Deliver the alerts the app sends to you and your crew. The message content is encrypted, so they can’t read it. United States and other countries The UK–US data bridge where the provider is certified to it, otherwise the IDTA or UK Addendum.

We don’t send text messages for you yet. Before we start, we will add the text-message provider to this list with 30 days’ notice, as section 6 says.