This Privacy Policy explains how Certio ("Certio", "we", "us") collects, uses, shares and protects personal data when you use the Certio mobile app and related services (the "Service"). Certio is operated as a sole-trader business established in the United Kingdom and is subject to UK law, including the UK GDPR and the Data Protection Act 2018. We are the data controller described in section 1 below. For the operator's registered details, or for postal correspondence, contact support@certio.uk and we will provide them. General contact: support@certio.uk.
Certio is a business tool for tradespeople. Two different relationships apply:
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, email, password (hashed), business/trading name, team membership & role | You, at sign-up |
| Business content | Quotes, invoices, certificates (EICR/EIC/PAT/MW), bookings, job notes, receipts and their totals, uploaded photos of appliances/boards/receipts | You, in-app |
| Your customers' personal data | Customer names, phone numbers, addresses, emails; the content of WhatsApp and email messages exchanged with them | Ingested via connected WhatsApp / email inbox and manual entry |
| Location | Approximate/precise device location for address auto-fill and drive-time estimates; optional live job-location share; optional worker location trail while clocked in (Teams) | Device, with your permission |
| Contacts | On-device phone contacts read only to match a number to a name (stays on the device); contacts you explicitly import become part of your client book | Device, with your permission |
| Calendar | Free/busy times read to avoid double-booking (event details stay on the device); events written only when you tap "Add to calendar" | Device, with your permission |
| Camera & microphone | Photos you capture; voice dictation audio (transcribed to text) | Device, with your permission |
| Financial & banking | Invoice/payment records; if you connect Open Banking, read-only transaction data used to reconcile payments | You / your bank via a regulated provider |
| Technical | Device/app version, diagnostic and error information | Automatically |
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Provide the Service you signed up for (accounts, certs, quotes, invoices, bookings, messaging assistant) | Performance of a contract |
| Process your customers' data to draft/send messages, detect bookings, generate documents | Processing on the controller's (your) instructions; your customers' lawful basis is your responsibility as controller |
| Location, contacts, calendar, camera, microphone features | Consent (via the device permission prompt; you can withdraw at any time in device settings) |
| Security, fraud/abuse prevention, service reliability, support | Legitimate interests |
| Legal and regulatory compliance | Legal obligation |
We use the following providers to deliver features. Data is shared only as needed for the stated purpose. This list may change; we will keep it current.
| Provider | Purpose | Data shared |
|---|---|---|
| Anthropic | AI assistant that drafts replies, quotes and detects bookings | Message/enquiry text and relevant business context |
| Ideal Postcodes / postcodes.io | Postcode lookup for addresses you type | The postcode being looked up |
| CARTO / OpenStreetMap | Map tiles on the web portal's map view | Map tile requests (approximate viewport, IP address) |
| getAddress.io | Full address lookup for UK postcodes | The postcode being looked up |
| Google (Gemini) | AI reading of certificate/board photos and text | Images and text you submit |
| OpenAI | Speech-to-text transcription of your dictation | Audio you record for transcription |
| ElevenLabs | Optional voice features | Text/voice for the requested feature |
| Google (Calendar / Gmail) | Optional calendar and email connections you enable | Only what the connection requires |
| Stripe | Card payments | Payment and invoice details |
| Open Banking provider — an FCA-authorised Account Information Service Provider, named on the consent screen before you authorise the connection | Optional read-only bank reconciliation (only if you switch it on) | Bank transaction data you authorise |
| Resend | Sending emails on your behalf (invoices/quotes/certs) | Recipient address and message content |
| Hostinger International Limited | Hosting the Certio backend and database (servers located in the United Kingdom) | Data at rest/in transit as needed to operate |
| Cloudflare | Network, TLS termination and protection for certio.uk | Traffic metadata in transit |
We do not sell your personal data or your customers' personal data.
Some providers above process data outside the UK/EEA (e.g. the United States). Where they do, transfers are made under an appropriate safeguard such as the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, or an adequacy decision.
We keep account and business data for as long as your account is active and as needed to provide the Service. Backups are retained on a rolling basis. Where a specific limit applies (for example, worker location trails are retained for no more than 30 days), we apply it. When you delete your account we delete or irreversibly anonymise your data as described below, subject to any legal retention obligations.
Under UK/EU data protection law you have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. To exercise any right, email support@certio.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
If you are one of a tradesperson's customers and want your data corrected or removed, contact the tradesperson (the controller) directly; we will assist them as their processor.
You can delete your account and its data at any time inside the app (Account → Delete account), which permanently removes your account, your team data, and your stored business and customer data from our systems, and your cloud backups. Data held only on your device is removed when you uninstall the app. If you no longer have the app, email support@certio.uk from your registered address and we will action the deletion. A web request page is also available at certio.uk/delete-account.
We take appropriate technical and organisational measures to protect your data. Data is transmitted over encrypted connections (HTTPS/TLS); access to backend systems is restricted and authenticated; sensitive credentials (such as connected-account tokens) are encrypted at rest using authenticated encryption. We are continually strengthening our safeguards, including expanding encryption-at-rest coverage. No system is perfectly secure; we will notify you and the ICO of a qualifying personal-data breach as required by law.
Certio is a business tool intended for users aged 18 and over. It is not directed at children and we do not knowingly collect children's data.
Our marketing and sign-up website uses only essential cookies needed to operate. If we introduce analytics or non-essential cookies, we will ask for your consent first.
We may update this policy. Material changes will be notified in-app or by email. The "last updated" date at the top shows the current version.
Data protection queries: support@certio.uk. We handle correspondence by email; if you need a postal address for a formal notice, request it at support@certio.uk and we will provide it.