Data processing terms
How Anvul handles your customers’ and crew’s personal data for you, as your processor.
1. Who does what
1.1 For the personal data you handle through Anvul — the people who contact you, your customers, the people named in your jobs, and your crew — you are the controller and Anvul is your processor. You decide why and how that data is used; we handle it for you.
1.2 Where we handle personal data for our own purposes — your account, billing, our messages with you, security logs and our own marketing — we are the controller, and our privacy policy applies instead.
1.3 If these terms and the terms of service disagree about personal data, these terms win.
1.4 Your side. You are responsible for having a lawful reason to collect and use the personal data you handle through Anvul, for telling people how you use it, and for the instructions you give us.
2. What we process for you
The details — subject matter, duration, nature and purpose, the types of personal data and the people it is about — are in Annex 1.
3. Your instructions
3.1 We process the personal data only on your documented instructions, including about transfers outside the UK. Your instructions are: the terms of service and these terms; the features and settings you use in Anvul (for example sending a quote, a reminder or a review request); and anything you ask us to do in writing, including in Messages with Anvul, by the account owner or someone they have authorised.
3.2 We only transfer the personal data outside the UK as section 8 allows. If the law requires us to process it in some other way, we will tell you before we do, unless the law forbids that.
3.3 If we think an instruction breaks data protection law, we will tell you straight away, and we need not follow it until it is resolved.
3.4 Standing instructions. You instruct us to:
- let people who contacted you through a website Anvul runs see, download or erase their own details using our self-service tool at anvul.co.uk/legal/data-subject, after they have proved they control the email address involved. We handle those requests straight away on your behalf, and keep a record of each one, which you can ask us for;
- delete enquiries that never became work once nobody has touched them for 24 months (records you need for six years, such as anything linked to a payment, are kept);
- keep backups and security logs, so the service is safe and can be restored; and
- create anonymised, aggregated statistics from the service, as section 12 describes.
4. Our people
Only Anvul staff and contractors who need the personal data to run the service, or to help you when you ask, can access it, and each of them is bound by a duty of confidentiality.
5. Security
We take the technical and organisational measures that UK GDPR Article 32 requires, appropriate to the risk. They are summarised in Annex 2 and on our security page, and we review them as the service changes.
6. Sub-processors
6.1 You authorise us to use the sub-processors listed in Annex 3.
6.2 Before we add or replace a sub-processor, we will email you at least 30 days ahead, saying who it is and what it will do. In an emergency — for example replacing a provider that has failed — we will tell you as soon as we can.
6.3 You can object within that time by emailing [email protected] with your reasons. We will try to address them. If we can’t, you can stop using the affected part of Anvul, or cancel your website, before the change takes effect, and we will refund any part of a month you have paid for but won’t receive.
6.4 Each sub-processor is bound by written terms that protect the personal data at least as well as these terms do. We remain responsible to you for what our sub-processors do.
7. Helping you
7.1 Taking into account what the service does, we help you answer requests from people about their data — access, correction, erasure, restriction, portability and objection. Much of this you can do yourself in the app. If a request reaches us directly, we pass it to you without undue delay, unless the standing instruction in section 3.4 covers it.
7.2 We help you meet your duties under UK GDPR Articles 32 to 36: keeping the data secure, dealing with a personal data breach, carrying out a data protection impact assessment, and consulting the regulator before processing where that is needed. We give you the information we reasonably can about the processing we do for you.
8. Where the data goes
Our servers and database are in London. Some sub-processors handle data outside the UK (see Annex 3). We only make those transfers in one of the ways UK law allows: to a country the UK recognises as giving adequate protection (such as the European Economic Area); to a US company certified to the UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”); or under the UK International Data Transfer Agreement (IDTA), or the European Commission’s Standard Contractual Clauses with the UK Addendum, after a transfer risk assessment. Email [email protected] for a copy of the safeguard for any provider.
9. If something goes wrong
If we become aware of a personal data breach affecting the personal data we process for you, we will tell you without undue delay. We will tell you what happened, what data and roughly how many people are involved, the likely consequences, what we have done about it, and who to contact. We will keep you updated as we learn more, and help you decide whether you need to report it to the regulator (normally within 72 hours of you becoming aware) or tell the people affected.
10. When you leave
When you close your Anvul account, or ask us to, we will — at your choice — give you a copy of the personal data in a common format and then delete it, or simply delete it. You can also download a copy yourself at any time from Settings → Your data in the app. Unless you ask us to delete it sooner, we keep the data for 12 months after you close your account (so that you can come back, or ask for a copy), then delete it. We keep only what the law requires us to keep, and keep it protected. Cancelling your website subscription alone doesn’t close your account (see the terms, section 10).
11. Showing we comply
We will give you the information you reasonably need to show that we meet these terms. Where that isn’t enough, or the regulator requires it, we will allow and contribute to an audit or inspection by you or an auditor you appoint, on at least 30 days’ notice, during working hours, no more than once a year (unless after a breach), under a confidentiality agreement and without access to other customers’ data. Normally we start by answering your written questions. Each side pays its own costs, unless the audit shows we materially broke these terms.
12. Our own uses
We may use the personal data to keep the service secure, and to create anonymised, aggregated statistics — for example totals and averages across Anvul — that do not identify you, your customers or anyone else. Once data is truly anonymous it is no longer personal data. We never sell the personal data, use it to market to your customers, or share it with your competitors.
13. Liability
Each side’s liability under these terms is subject to the limits in section 9 of the terms of service, except where the law does not allow it to be limited.
14. Changes
We may update these terms to reflect changes in the law or in our sub-processors. A new sub-processor follows section 6. Any other change that reduces your protection follows the 30-day notice in section 12 of the terms of service.
Annex 1 — Details of the processing
- Subject matter: providing the Anvul service to your business.
- Duration: while you have an Anvul account, then until deletion under section 10.
- Nature: collecting (through your website’s forms and the app), storing, hosting, organising, showing to you and your team, sending the emails and push alerts you trigger or set up, backing up and deleting.
- Purpose: to run your website, Leads and Messages and, where Anvul has switched them on for you while they are being tested, your jobs, diary, customers, quotes, invoices, payments, books and crew app.
- Types of personal data: names; contact details (email, phone, address or area); enquiry messages and notes; photos and videos people send you or your team takes; booking, job, quote and invoice details; payment status (not card numbers — Stripe handles those); and, for your crew: name, contact details, role, time-clock and timesheet entries, team chat messages and any credentials they choose to share with you.
- People the data is about: people who enquire with you, and your customers; people named in your jobs (for example tenants or site contacts); and your crew, staff and any subcontractors you add.
- Special category data: not intended. Please ask your customers not to include health or similar details in their messages; if they do, we protect it in the same way.
Annex 2 — Security measures
- Servers and database in London; HTTPS for every connection; encryption at rest by our hosting providers.
- Each firm’s data kept separate at the database level (row-level security), with role-based access inside each firm.
- One-time sign-in codes instead of passwords; where an older account has a password, it is stored only as a salted hash.
- Audit logs of sensitive actions; continuous backups with a tested restore process.
- Anvul staff access only to run the service or to help you.
- Error reports set up to leave out request contents, contact details and message text.
Annex 3 — Sub-processors
These providers may handle personal data you control, on our instructions and under written terms. Some only take part when you use a particular feature, as the table says.
| Provider | What it does for you | Where | Safeguard for transfers |
|---|---|---|---|
| Fly.io, Inc. | Runs our servers. | London, UK | Data stays in the UK. Any access from the US: the UK–US data bridge where Fly.io is certified to it, otherwise the IDTA or UK Addendum. |
| Neon, Inc. | Hosts our database. | London, UK (AWS eu-west-2) | Data stays in the UK. Any access from the US: the UK–US data bridge where Neon is certified to it, otherwise the IDTA or UK Addendum. |
| Cloudflare, Inc. | Hosts your website; stores photos, files and backups; receives email sent to Anvul inboxes. | Global network; file storage not pinned to one country | The UK–US data bridge where Cloudflare is certified to it, otherwise the IDTA or UK Addendum. |
| Stripe | Takes card payments, including payments your customers make to your own Stripe account. Stripe is also its own controller for the payment data it needs. | UK, EEA and US | The UK–US data bridge where Stripe is certified to it, otherwise the IDTA or UK Addendum. |
| Resend | Delivers the emails Anvul sends for you (enquiry alerts, quotes, reminders, review requests). | United States | The UK–US data bridge where Resend is certified to it, otherwise the IDTA or UK Addendum. |
| Functional Software, Inc. (Sentry) | Error reports, so we can fix faults. Set up to leave out request contents and contact details; an error report may occasionally include part of a record. | United States or EU | The UK–US data bridge where Sentry is certified to it, otherwise the IDTA or UK Addendum. |
| Google LLC (Gemini API) | AI that helps us draft your website’s text from your brief and notes, and — only if you use the contract-inbox feature while it is being tested — reads job packs you receive to pull out job details, which can include residents’ names and addresses. | United States and other countries | The UK–US data bridge where Google is certified to it, otherwise the IDTA or UK Addendum. |
| Google LLC (Maps Platform) | Finds the location of an address (for example a house number and postcode) and shows maps. | United States and other countries | The UK–US data bridge where Google is certified to it, otherwise the IDTA or UK Addendum. |
| Ideal Postcodes | Looks up addresses from a postcode typed into a form on your website. | UK | Not needed (UK). |
| Modal Labs, Inc. | Processes room photos and scan videos — only when you use the photo-measuring or scan features while they are being tested. | United States | The UK–US data bridge where Modal is certified to it, otherwise the IDTA or UK Addendum. |
| Google, Apple and Mozilla push services | Deliver the alerts the app sends to you and your crew. The message content is encrypted, so they can’t read it. | United States and other countries | The UK–US data bridge where the provider is certified to it, otherwise the IDTA or UK Addendum. |
We don’t send text messages for you yet. Before we start, we will add the text-message provider to this list with 30 days’ notice, as section 6 says.