CERTIO

Privacy Policy

Last updated 29 August 2026

This Privacy Policy explains how Certio ("Certio", "we", "us") collects, uses, shares and protects personal data when you use the Certio mobile app and related services (the "Service"). Certio is operated as a sole-trader business established in the United Kingdom and is subject to UK law, including the UK GDPR and the Data Protection Act 2018. We are the data controller described in section 1 below. For the operator's registered details, or for postal correspondence, contact support@certio.uk and we will provide them. General contact: support@certio.uk.

1. Who is responsible for your data

Certio is a business tool for tradespeople. Two different relationships apply:

2. What personal data we collect

CategoryExamplesSource
Account & identityName, email, password (hashed), business/trading name, team membership & roleYou, at sign-up
Business contentQuotes, invoices, certificates (EICR/EIC/PAT/MW), bookings, job notes, receipts and their totals, uploaded photos of appliances/boards/receiptsYou, in-app
Your customers' personal dataCustomer names, phone numbers, addresses, emails; the content of WhatsApp and email messages exchanged with themIngested via connected WhatsApp / email inbox and manual entry
LocationApproximate/precise device location for address auto-fill and drive-time estimates; optional live job-location share; optional worker location trail while clocked in (Teams)Device, with your permission
ContactsOn-device phone contacts read only to match a number to a name (stays on the device); contacts you explicitly import become part of your client bookDevice, with your permission
CalendarFree/busy times read to avoid double-booking (event details stay on the device); events written only when you tap "Add to calendar"Device, with your permission
Camera & microphonePhotos you capture; voice dictation audio (transcribed to text)Device, with your permission
Financial & bankingInvoice/payment records; if you connect Open Banking, read-only transaction data used to reconcile paymentsYou / your bank via a regulated provider
TechnicalDevice/app version, diagnostic and error informationAutomatically

3. How we use it, and our legal bases

PurposeLegal basis (UK GDPR)
Provide the Service you signed up for (accounts, certs, quotes, invoices, bookings, messaging assistant)Performance of a contract
Process your customers' data to draft/send messages, detect bookings, generate documentsProcessing on the controller's (your) instructions; your customers' lawful basis is your responsibility as controller
Location, contacts, calendar, camera, microphone featuresConsent (via the device permission prompt; you can withdraw at any time in device settings)
Security, fraud/abuse prevention, service reliability, supportLegitimate interests
Legal and regulatory complianceLegal obligation

4. Sub-processors & third parties we share data with

We use the following providers to deliver features. Data is shared only as needed for the stated purpose. This list may change; we will keep it current.

ProviderPurposeData shared
AnthropicAI assistant that drafts replies, quotes and detects bookingsMessage/enquiry text and relevant business context
Ideal Postcodes / postcodes.ioPostcode lookup for addresses you typeThe postcode being looked up
CARTO / OpenStreetMapMap tiles on the web portal's map viewMap tile requests (approximate viewport, IP address)
getAddress.ioFull address lookup for UK postcodesThe postcode being looked up
Google (Gemini)AI reading of certificate/board photos and textImages and text you submit
OpenAISpeech-to-text transcription of your dictationAudio you record for transcription
ElevenLabsOptional voice featuresText/voice for the requested feature
Google (Calendar / Gmail)Optional calendar and email connections you enableOnly what the connection requires
StripeCard paymentsPayment and invoice details
Open Banking provider — an FCA-authorised Account Information Service Provider, named on the consent screen before you authorise the connectionOptional read-only bank reconciliation (only if you switch it on)Bank transaction data you authorise
ResendSending emails on your behalf (invoices/quotes/certs)Recipient address and message content
Hostinger International LimitedHosting the Certio backend and database (servers located in the United Kingdom)Data at rest/in transit as needed to operate
CloudflareNetwork, TLS termination and protection for certio.ukTraffic metadata in transit

We do not sell your personal data or your customers' personal data.

5. International transfers

Some providers above process data outside the UK/EEA (e.g. the United States). Where they do, transfers are made under an appropriate safeguard such as the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, or an adequacy decision.

6. Retention

We keep account and business data for as long as your account is active and as needed to provide the Service. Backups are retained on a rolling basis. Where a specific limit applies (for example, worker location trails are retained for no more than 30 days), we apply it. When you delete your account we delete or irreversibly anonymise your data as described below, subject to any legal retention obligations.

7. Your rights

Under UK/EU data protection law you have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. To exercise any right, email support@certio.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

If you are one of a tradesperson's customers and want your data corrected or removed, contact the tradesperson (the controller) directly; we will assist them as their processor.

8. Account & data deletion

You can delete your account and its data at any time inside the app (Account → Delete account), which permanently removes your account, your team data, and your stored business and customer data from our systems, and your cloud backups. Data held only on your device is removed when you uninstall the app. If you no longer have the app, email support@certio.uk from your registered address and we will action the deletion. A web request page is also available at certio.uk/delete-account.

9. Security

We take appropriate technical and organisational measures to protect your data. Data is transmitted over encrypted connections (HTTPS/TLS); access to backend systems is restricted and authenticated; sensitive credentials (such as connected-account tokens) are encrypted at rest using authenticated encryption. We are continually strengthening our safeguards, including expanding encryption-at-rest coverage. No system is perfectly secure; we will notify you and the ICO of a qualifying personal-data breach as required by law.

10. Children

Certio is a business tool intended for users aged 18 and over. It is not directed at children and we do not knowingly collect children's data.

11. Cookies

Our marketing and sign-up website uses only essential cookies needed to operate. If we introduce analytics or non-essential cookies, we will ask for your consent first.

12. Changes

We may update this policy. Material changes will be notified in-app or by email. The "last updated" date at the top shows the current version.

13. Contact

Data protection queries: support@certio.uk. We handle correspondence by email; if you need a postal address for a formal notice, request it at support@certio.uk and we will provide it.


Terms of Service · Privacy & Terms (combined)