Truvi | Privacy Policy

Privacy Policy

Truvi Technologies Limited (referred to as ‘’Truvi’’, ‘’we’’, ‘’us’’ or ‘’our’’) values your privacy and respects the rights you have in relation to your personal data. This Privacy Notice (Notice) lets you know how we use your personal data when you interact with Truvi or visit our website and provides details of your rights under data protection law.  

 

It is important that you read this Notice together with any other privacy notice(s) we may provide so that you are fully aware of how and why we are using your personal data. This notice supplements all other privacy notices also called ‘’Privacy Policy’’ provided by us and is not intended to override them. 

1. Who does this notice relate to? 

1.1. This Notice gives you information about how we collect and use your personal data and applies to you: 

1.1.1 as a customer or potential Truvi customer 

1.1.2. A contact person at one of Truvi’s customer or potential customer 

1.1.3. as a visitor of our website www.truvi.com (the ‘’Site’’) 

1.1.4. when you provide services to us and we need to process your personal data to enter into an agreement or contract with you and manage that agreement or contract (Supplier). 

1.2. Our services and our website are not intended for children, and we do not knowingly collect personal data relating to children.  

 

2. Who is the controller of your personal data? 

2.1. Truvi Technologies Limited (registered number 10254155) is the controller for your personal data. Our registered address is 3rd Floor 1 Ashley Road, Altrincham, Cheshire, United Kingdom, WA14 2DT and our website address is www.Truvi.com .   

2.2. Truvi is a wholly owned subsidiary of Truvi Holdings Ltd which is a registered company in England & Wales (Company no. 10784606). Our registered address is 3rd Floor 1 Ashley Road, Altrincham, Cheshire, United Kingdom, WA14 2DT.   

2.3. Truvi is registered with the Information Commissioner’s Office (ICO) with registration number ZA518818.  

 

3. What happens if this Notice is updated or your personal data changes? 

3.1. This Notice was last updated on the date stated at the beginning of the Notice. Any historic versions can be obtained by contacting us at [email protected]. We will publish any changes to this Notice on our website. It is important that the personal data we hold about you is accurate and up to date. Please keep us informed if your personal data changes during your relationship with us. 

 

4. Definitions 

4.1. Please find below some key definitions which are used when describing types of personal data: 

Key term  Definition  
Personal data  Any information about an individual who is identified or identifiable 
Special categories of personal data  Any information about you which relates to your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, your health as well as genetic data and biometric data for the purpose of uniquely identifying you. 
Criminal offence data  Any personal data relating to criminal convictions and offences or related security measures. 

 

5. What personal data do we collect about you? 

5.1. We collect, use, store and transfer different kinds of personal data about you which we have grouped together in the table below. The terms below are mainly used in Section 8 (What do you use my personal data for and why?) to explain why we use the personal data in the way we do: 

Description  Personal data  
Contact Data  Full name, email address (business and personal), telephone number, job role and addresses including where applicable your ZIP code.  
Identity data  Your ID card and selfie. 
Correspondence Data  Information contained in any correspondence or other communications you send us including feedback we receive from you, your enquiries, your claims investigations information provided to us and your requests for compensation made to us. The data also includes the communication content and metadata associated with the communication. 
Marketing Data  This relates to your contact data, your marketing preferences in receiving marketing communications from us, your IP address, session ID, browser fingerprint, cookies ID, device/browser information, usage patterns, your device settings, plugin status, your interaction data, Ad IDs, interaction metrics, browser information, session IDs and platform usage and patterns. 
Transaction Data  Your transaction data may include your contact details, billing information, payment card or bank account information and, if applicable, the transaction details for the purchases of the services you have requested from us or in the case of Suppliers only, that we have requested from you. 
Account Data  This is your Guest and/or Host account information that we hold including information presented to you in your Host dashboard or to you as a Guest, in your account, when your booking has been approved. It also includes any ID information and selfies you sent us as part of the booking verification process. 
Technical data  This relates to your IP address, session ID, browser fingerprint, cookies ID, device/browser information, usage patterns, your device settings, plugin status, your interaction data, Ad IDs, interaction metrics, browser information, session IDs and platform usage and patterns. 

 

6. What happens if you don’t provide us with your personal data? 

6.1. Where we need to collect personal data because: 

6.1.1. we are complying with a legal or regulatory obligation or  

6.1.2. we need it under the terms of a contract we have with you, or  

6.1.3. the information is necessary to enter a contract with you  

6.1.4. and you fail to provide that personal data when requested, we may not be able to perform the contract we have or are trying to enter with you. In this case, we may have to decline to provide the services to you or enter a contract with you, but we will notify you if this is the case at the time.  

 

7. How do we collect personal data about you? 

7.1. We collect personal data from and about you using the following methods: 

 

Collection method  Description  
Direct interactions  Most of the personal data we collect, and use comes directly from you through our website, the completion of forms, in person at networking events, or via email. 
Automated technologies or interactions  As you interact with our website and where we are permitted to do so by you, we automatically collect technical data. We collect this personal data by using cookies and other similar technologies such as web log and beacons. For information about the cookies operating on our website, please refer to our Cookies policy available here 

For more information about the data collected through web log and beacons, please refer to Section 8 below ‘’What do we use your personal data for and why?’’ 

Third parties  We may receive personal data about you from US Federal and National databases via third-party Checkr whose privacy policy is published at https://checkr.com/legal/gdpr-privacy-policy  
Via our IT systems   We collect personal data through our internal IT systems when you interact with our platforms, tools or services. This includes logs generated by our systems when you access or use our website, Host/Guest dashboards, booking verification systems, or internal communication tools. These systems automatically record technical information (for example, IP addresses, device identifiers, login timestamps and activity logs). 

 

Publicly available sources  We receive personal data about you from the public sources set out below: UK Companies House, Host’s website, LinkedIn profiles. 

 

8. What do we use your personal data for and why? 

8.1. We will only use your personal data where the law allows us to. Most commonly, we will use your personal data in the following circumstances: 

8.1.1. To comply with a legal or regulatory obligation for example; 

8.1.2. where it is in our legitimate interest or that of a third party to do so such as ensuring the security of our platform, preventing fraud or managing our relationship with Hosts and Guests. We will always make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our/a third party’s legitimate interest; 

8.1.3. Performance of a contract to which you are a party or to take steps at your request before entering a contract, for example to fulfil contractual obligations with your host or property manager or to process payments; and 

8.1.4. Consent we rely on your consent to process the personal data in the following circumstances: the use of analytical and performance cookies on our website and conducting criminal background checks for Guests who are US residents. You can withdraw your consent for the use of optional cookies via the cookie consent tool on our website. You can also opt out of future marketing communications sent to you by clicking on the link in any email you receive from us or by contacting us at [email protected] 

8.2. The table below explains the way in which we use your personal data and the legal basis which is used: 

 

Individual  Purpose for processing  Data used  Legal basis relied on 
Prospective Client  To contact you to provide you with information about us and our services which you have requested when you are not yet our Client 
  • Identity Data 
  • Contact Data 
  • Communication Data  
  • Legitimate intereststo respond to requests for information from you and to grow our business 

 

Prospective Client and Client  Marketing our services to you by email campaigns, personalised advertising, SMS marketing and social media posts. 
  • Marketing Data  
  • Identity Data  
  • Contact Data  
  • Communication Data 

 

  • Legitimate interests, to grow our business through marketing. Legitimate interests are relied upon where you have engaged with us previously (for example, by requesting information about our services or entering discussions with us) and you have not opted out of receiving marketing communications. 

 

  • Consent via opting into marketing communications. 
Client, Prospective Client and Supplier  To undertake anti-money laundering, anti-corruption, anti-terrorism, and identity checks and conflict checks to ensure we can lawfully engage with you 
  • Identity Data  
  • Contact Data  
  • Financial Data  
  • Transaction Data  
  • To comply with our legal and regulatory obligations under anti-money laundering, anti-corruption and anti-terrorism laws including the Proceeds of Crime Act 2002 and the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017. 

 

Client, Prospective Client and Supplier  To conduct checks to ensure we are not prevented from engaging/working with you by any relevant sanctions’ regime. 
  • Identity Data  
  • Contact Data 
  • To comply with our legal and regulatory obligations 
Client  Providing our services to you and administering our relationship with you, for example communicating with you to understand your requirements, processing payments or handling issues relating to your account. 
  • Communication Data 
  • Contact Data 
  • Financial Data 
  • Identity Data 
  • Transaction Data  
  • Performance of a contract  
Client Prospective Client  Credit checks in order to assess your suitability to obtain credit for our services 
  • Identity Data 
  • Contact Data 
  • Credit Check Data 
  • To comply with our legal and regulatory obligations 
Client, Prospective Client and Supplier  To prevent and detect fraud against you or us by conducting identity checks and monitoring for suspicious or irregular activity. 

 

  • Identity Data 
  • Contact Data 
  • Communication Data 
  • Financial Data 
  • Legitimate interests, to minimise fraud which could be damaging for you and/or us. 

 

Client, Prospective Client  Training our staff in delivering our services effectively, managing customer enquiries, and assessing or investigating incidents. 

 

  • Identity Data 
  • Contact Data 
  • Communication Data 
  • Account Data 

 

  • Legitimate interests, to train our staff so that they can provide a better service to our clients 
Client  Dealing with Client queries and complaints  
  • Contact Data 
  • Transaction Data 
  • Financial Data  
  • Communication Data  
  • Account Data 
  • Legitimate interests, to respond to queries raised by Clients in order to provide a good service and to resolve complaints raised by Clients 
Supplier  To administer our contract with you including managing service levels, payments, fees and charges 
  • Identity Data  
  • Contact Data 
  • Financial Data 
  • Transaction Data 
  • Communication Data 
  • Performance of a contract 

 

All individuals covered by this notice   To enforce legal rights or defend or undertake legal proceedings 
  • Identity Data 
  • Contact Data 
  • Communication Data 
  • Financial Data 
  • Transaction Data 
  • Technical Data 
  • Usage Data  

 

  • To comply with our legal and regulatory obligations 
  • Legitimate interests – to protect our business, interests and rights (for example where we make a claim to recover monies owed to us) 
All individuals covered by this notice   Performing quality control checks, preparing for and taking part in internal and external audits and preparing for and taking part in audits/investigations by relevant regulatory bodies such as the ICO  

 

  • Identity Data 
  • Contact Data 
  • Communication Data 
  • Financial Data 
  • Transaction Data 
  • Technical Data 
  • Usage Data  
  • To comply with our legal and regulatory obligations 
  • Legitimate interests, to ensure we provide a good quality service and run and manage Clients effectively where audits/quality control checks are not required by law or regulation 
All individuals covered by this notice   Business planning and management, including analysing aggregated trends, forecasting demand, allocating resources, improving our internal processes, and planning future services or operational changes. 

 

  • Technical Data 
  • Usage Data 
  • Account Data 
  • Transaction Data 
  • Marketing Data 
  • Legitimate interests, to ensure our business is run effectively and that we can continue to grow our business 
All individuals covered by this notice  To administer and protect our business and our website including, ensuring the confidentiality of sensitive information, protecting the security of our systems and data, troubleshooting, data analysis of aggregated technical information to maintain and improve system performance 

, testing, system maintenance, support and hosting of data 

  • Identity Data 
  • Contact Data 
  • Technical Data 
  • Usage Data 
  • To comply with our legal and regulatory obligations 
  • Legitimate interests, to run our business, provide administration and IT services and ensure information security when this exceeds our legal obligations 
  • Consent is relied upon where you accept nonessential cookies via our cookie banner including analytics and performance cookies used to help us understand how visitors use the website and improve its functionality. 

 

All individuals covered by this notice    Compliance with legislation and regulations which govern the running of our business, including compliance with tax, financial reporting, antimoney laundering and data protection requirements. 

 

  • Identity Data, 
  • Contact Data 
  • Transaction Data 
  • Financial Data 
  • Technical Data 
  • Usage Data 
  • To comply with our legal and regulatory obligations under anti-money laundering, anti-corruption and anti-terrorism laws including the Proceeds of Crime Act 2002 and the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017.   

 

8.3. As part of the booking verification process, Truvi uses biometric recognition to verify the unique identity of the person making the booking, by asking Guests to provide ID scans and selfies. Truvi asks for Guests to explicitly consent to this processing of their special category biometric data. Guests can choose not to consent to this processing by not providing their ID scan or selfie, this will not allow them to continue with the guest journey any further and are advised to contact their Host for next steps. Biometric data collected for identity verification purposes is not used for booking risk assessment, protection eligibility decisions, incident resolution, or any other automated processing described in this Notice.  

8.4. Web log data – when you use the Site, we automatically receive and record the following information from your computer (or other device) and your browser: your IP address and domain name, the pages you visit on the Site, the date and time of your visit, the files that you download, the URLs from the websites you visit before and after navigating to the Site, your software and hardware attributes (including device IDs), your general geographic location (e.g., your city, state, or metropolitan region), and certain cookie information (see below). To obtain such information, we may use web logs or applications that recognize your computer and gather information about its online activity. 

8.5. Web beacons – The Site or the emails that you receive from Truvi may use an application known as a “web beacon” (also known as a “clear gif” or “web bug”). A web beacon is an electronic file that usually consists of a single-pixel image. It can be embedded in a web page or in an email to transmit information, which could include personal information. For example, it allows an email sender to determine whether a user has opened a particular email.  

8.6. Third-party online tracking and behavioural advertising – we also may partner with certain third parties to collect, analyse, and use some of the personal and pseudonymized information described in this section. For example, we may allow third parties to set cookies or use web beacons on the Site or in email communications from Truvi. This information may be used for a variety of purposes, including online behavioural advertising. Truvi uses the information that we collect on the Site for a variety of purposes. If we have personal information about you, we may use it to: respond to your questions or requests concerning the Site or other services offered by Truvi or our partners; to fulfil the terms of any agreement you have with us; to fulfil your requests for our services or otherwise complete a transaction that you initiate; to send you information about our services and other topics that are likely to be of interest to you, including newsletters, updates, or other communications; to deliver confirmations, account information, notifications, and similar operational communications; to improve your user experience and the quality of our products and services; and to comply with legal and/or regulatory requirements. We use the pseudonymized information that we collect for: counting and recognizing visitors to the Site; analysing how visitors use the Site and various Site features; improving the Site and enhancing users’ experiences with the Site; creating new products and services or improving our existing products and services; and enabling additional website analytics and research concerning the Site. Truvi may link pseudonymized information gathered using cookies and web beacons with personal information.  

8.7. For Guests who are residents in the United States (US), Truvi offers Hosts an optional Criminal Background Check Service.  Where this service is purchased by Hosts for bookings (to check whether the Guest has a national or federal criminal records), criminal background checks on the Guest will be performed by Truvi.  To complete the criminal background checks, Truvi relies on the Guest’s explicit consent. The Guest’s consent will be sought by Truvi during the Guest verification process. Rest assured that Truvi processing of the criminal background checks information is done in compliance with applicable data protection laws, including the United Kingdom and European Union General Data Protection Regulation (UK and EU GDPR). To perform this service, Truvi processes the following Guest’s identity and contact information. This information is provided by the Guest in the Guest verification process: 

8.7.1. Guest’s full name, date of birth and home address including ZIP code. 

8.8. This data is checked against US federal and national criminal databases to identify potential matches within the past seven years. 

8.9. This service is only performed on bookings where the Host has purchased the service, and the Guest provides explicit consent to the performance of the service. 

8.10. Where the Host has subscribed to the service and the Guest did not consent for Truvi to complete the criminal background checks, Truvi will not be able to complete the Guest verification. At this point, the Guest verification will not be proceeded further by Truvi, and the Host will be informed. It is up to the Host to proceed with the booking or not. Please note that when consent is provided by the Guest for the criminal background checks to be completed by Truvi, the consent cannot be withdrawn as the check is performed automatically and as soon as the consent is provided. Where the Host has purchased the service, the Guest’s consent will be sought for every booking the Guest makes. 

8.11. To fulfil Truvi’s contract with the Host, Truvi retains background check data up until 14-days after the Guest check-out. Data is shared only with trusted service providers as required to deliver this functionality. 

8.12. To perform the criminal background checks service, we use a third-party background screening provider based in the US. The third-party service provider acts as a data processor on Truvi’s behalf and processes personal data strictly in accordance with Truvi’s instructions and under a binding Data Processing Agreement (DPA). 

8.13. As the third-party provider is based in the US, personal data will be transferred outside the UK and European Economic Area (EEA). Truvi ensures that appropriate safeguards are in place for such transfers, including the use of the UK International Data Transfer Agreement (IDTA). 

8.14. Truvi maintains a Watchlist to ensure safety in the vacation rental industry. A guest will be added to Truvi’s Watchlist if they fail to pay for property damage; they are liable for, in accordance with our terms. If you believe you have been added to the Watchlist and wish to be removed or want to learn more, please contact [email protected]. You may be required to provide certain information or documentation as part of our process. Our team will guide you through the necessary steps. 

8.15. We will only use your personal data for the purposes for which we collected it, unless we consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to obtain an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us at [email protected] 

8.16. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. 

 

9. Automated Decision Making  

9.1. We use limited automated processing to support the operation of our services. This automated processing applies predefined rules and logic to bookinglevel information to support internal risk assessment and determine whether we will offer booking protection to a Host. The processing is designed to operate in a consistent and objective way and does not assess individuals based on personal characteristics. 

9.2. As part of this process, we carry out an automated protection eligibility assessment for bookings where a Host requests protection. The assessment considers bookingrelated operational information, such as booking timing, booking duration, booking source and listing configuration, and uses this information to generate a risk assessment. Personal data such as a Guest’s age, home address or proximity to the booking location is not used by us to assess risk.  

9.3. Hosts are not instructed or advised by us on how to respond to a booking that is not protected. Where protection is not offered, we may present Hosts with a risk outcome and a summary of the criteria applied, so they can understand our reasoning. This information is provided for transparency only and does not constitute advice or recommendations. 

9.4. You have the right to obtain further information about this automated processing and to object to processing carried out on the basis of legitimate interests on grounds relating to your particular situation. If you wish to challenge our use of automated processing or raise a concern about its outcome, you can contact us using the details set out in Section 17 (Contact us and complaints). We will review concerns raised and consider whether further explanation or appropriate action is required.  

10. How do we use your personal data for marketing and how can you opt out? 

10.1. We may use your Identity, Contact, Marketing, Account and Technical data to form a view on what we think you may want or need, or what may be of interest. This is how we decide which promotional communications, including emails or postal mail about the product and services we or our partners offer is sent to you. You will receive promotional communications from us if you have requested marketing communications by email or post or have engaged in negotiations with us for/purchased from us of services and you have not opted out of receiving promotional communications. 

10.2. You can ask us to stop sending you promotional communications at any time by following the opt-out links on any promotional communications sent to you or by contacting us at [email protected]  

 

11. What are your rights under data protection law? 

11.1 You have a number of rights in relation to how we use your personal data; these are set out below in more detail: 

11.1.1. Access – This enables you to receive a copy of the personal data we hold about you. 

11.1.2. Rectification – This enables you to have any incomplete or inaccurate personal data corrected. 

11.1.3. Erasure – This enables you to ask us to delete personal data where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request for erasure because of specific legal reasons which will be notified to you, if applicable, at the time of your request.  

11.1.4. Objection – This enables you to object to the processing of your personal data where we are relying on our legitimate interest(s) (or that/those of a third party) and you object to processing on this ground as you feel the processing impacts your fundamental rights and freedoms. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms. You also have the absolute right to object where we are processing your personal data for direct marketing purposes. 

11.1.5. Restriction – This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) where you want us to establish the accuracy of the personal data; (b) where our use of the personal data is unlawful but you do not want us to erase it; (c) where you need us to hold the personal data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) where you have objected to our use of your personal data but we need to verify whether we have overriding legitimate grounds to use it.  

11.1.6. Portability – This enables you, in certain situations, to request transfer of your personal data to you or to a third party. We will provide your personal data (to you, or a third party you have chosen) in a structured, commonly used, machine-readable format.  

11.1.7. Your right to withdraw consent – If we are relying on consent to process your personal data, you can withdraw your consent at any time, however, this will not affect the lawfulness of any processing carried out before you withdraw your consent.  

11.2. If you wish to exercise any of the rights set out above, please contact us using the details set out in Section 2 (Who is the controller of my personal data?). If our legal basis for processing is consent and you wish to withdraw your consent, you can also use the methods set out in Section 8 (What do we use your personal data for and why?) 

11.3. Before we can process your request, we may need information from you to help us confirm your identity. This is a security measure to ensure that rights are being exercised by the correct person and to ensure that personal data is not disclosed to, erased by or altered by any person who has no right to do so.  

For more information on the rights set out above and when they apply, please contact us at [email protected] or see the guidance from the UK Information Commissioner on individuals’ rights. 

12. Who do we share your personal data with and where do we transfer your personal data to? 

12.1. We may have to share your personal data with third parties for the purposes set out in the table in Section 8 (What do you use my personal data for and why? 

12.2. Some of the third parties are based outside the UK and/or the European Economic Area (EEA) so their processing of your personal data will involve a transfer of personal data outside the UK and/or the EEA. Whenever we transfer your personal data out of the UK and/or the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is in place:  

12.2.1 We may transfer your personal data to countries that have been granted an adequacy decision by the European Commission and/or an adequacy regulation by the UK Secretary of State (as applicable) confirming that the country in question provides an adequate level of protection for personal data; or 

12.2.2. We may use specific contracts approved by the European Commission and/or the UK (as applicable) which ensure that personal data is adequately protected. When we rely on this measure, we will conduct risk assessments and take appropriate measures to ensure that the third-party can comply with the provisions of such contracts and we have confirmed that the country to which the personal data is transferred provides enforceable data subject rights and effective legal remedies for data subjects are available there; or 

12.2.3. a specific exception applies under applicable data protection law. 

12.3. Please see below for details of the third parties we share your personal data with and where we send your personal data: 

12.3.1. Service providers who provide IT and systems administration services and access to platforms we use for operational purposes to run our business; 

Third party   Personal data shared  Reason for sharing personal data    Is your personal data sent outside of the UK/EEA? 
Cloud hosting, CRM, analytics, communications and security providers (including Microsoft, HubSpot, Google, Cloudflare, PowerBI and similar service providers)  Identity data, contact data, technical data, usage data, account data  To host, operate, secure, monitor and maintain our IT systems, platforms and website, and to support business operations  Yes – data may be processed in the USA and other jurisdictions. Transfers are protected by adequacy regulations and/or appropriate safeguards such as the UK IDTA or EU SCCs 

 

12.3.2. Professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services to us; 

Third party   Personal data shared  Reason for sharing personal data    Is your personal data sent outside of the UK/EEA? 
Professional advisers (including lawyers, auditors, accountants and insurers)  Identity data, contact data, financial data, transaction data, correspondence  To obtain legal, financial, insurance and regulatory advice and support  Generally, no. Where transfers occur, appropriate safeguards are in place 

 

12.3.3. HM Revenue & Customs, regulators and other authorities based in the UK who require reporting of processing activities in certain circumstances, for example to ensure we are complying with legal and regulatory obligations; 

Third party   Personal data shared   Reason for sharing personal data   Is your personal data sent outside of the UK/EEA? 
HMRC, courts, regulators and law enforcement authorities  Identity data, contact data, financial and transaction data, compliance records  To comply with legal and regulatory obligations or lawful requests  No, unless required by law 

 

12.3.4. Third parties who require access to the personal data we process for the purposes of the prevention or detection of crime or for the purposes of legal proceedings; 

12.3.5. Fraud prevention agencies and credit reference agencies for the purposes of undertaking anti-money laundering, anti-terrorism and other financial checks to ensure we are complying with our legal and regulatory obligations; 

Third party   Personal data shared  Reason for sharing personal data  Is your personal data sent outside of the UK/EEA? 
Identity verification, screening, sanctions and fraud prevention providers (e.g. SEON, Wilbur, Crimeometer, Checkr)  Identity data, contact data, biometric data, criminal offence data (where applicable)  To prevent fraud, verify identity, conduct screening and meet contractual and regulatory requirements  Yes – including the USA. Transfers safeguarded by adequacy decisions, SCCs and/or UK IDTA 

 

12.3.6. External auditors who provide auditing and similar compliance services to us to ensure we are complying with our legal and regulatory obligations when we provide services to you, process your personal data or where we are certified under any relevant schemes or certifications; 

 

Third party   Personal data shared  Reason for sharing personal data  Is your personal data sent outside of the UK/EEA? 
External auditors and compliance reviewers (appointed from time to time)  Identity data, financial records, transaction data and related correspondence  To conduct audits and compliance reviews and to support Truvi’s compliance with legal and regulatory obligations  No, unless required by the auditor, in which case appropriate safeguards will be put in place 

 

12.3.7. Financial providers who provide us with financial services and facilities;  

Third party   Personal data shared  Reason for sharing personal data  Is your personal data sent outside of the UK/EEA? 
Payment processors, banks and financial service providers (e.g. Stripe, GoCardless, AirWallex, Hyperline, Xero)  Identity data, contact data, payment and bank details, transaction data  To process payments, refunds, deposits, waivers and resolution payouts  Yes – including the USA and other jurisdictions, with adequacy decisions and contractual safeguards 

 

12.3.8. If there is a change of ownership or control of our business, such as a merger, restructure, sale of the business or its assets or we acquire a new business, your information may be shared with the parties involved in this change. We will anonymise the information where possible and any recipients will be bound by contractual terms to keep such information confidential. 

12.3.9. We require all third parties to respect the security of your personal data and to treat it in accordance with the law and the terms of the contract we have in place with them where they are our third-party service providers. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions. 

12.4.10. Please contact us at [email protected] if you want further information on encryptions and technical measures when transferring your personal data out of the UK and/or EEA or you would like more information about the third parties we share your personal data with. 

12.3.11. When you visit our website, we may share personal data and pseudonymised data collected through cookies and similar technologies with trusted third parties. This includes analytics and performance providers, advertising and marketing partners (where permitted by law and your cookie preferences), IT and website service providers, and social media platforms where you choose to interact with embedded features. 

12.3.12. We may also disclose personal data where necessary to comply with legal or regulatory obligations, to protect our rights or the safety of others, or in connection with a business reorganisation or transaction. We do not sell personal data collected via our website. All third parties are required to process personal data in accordance with our instructions and applicable data protection laws. 

 

13. How do we keep your personal data safe? 

13.1. We have appropriate security measures in place to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality. Truvi uses commercially reasonable physical, electronic, and procedural safeguards to protect your personal and pseudonymized information against loss or unauthorised access, use, modification, or deletion. This includes when sharing your data within our firm, group of companies, business, including affiliates, subsidiaries and authorised third parties. However, no security program or website is foolproof, and thus we cannot guarantee the absolute security of your personal or other information. 

13.2. We have in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. 

 

14. How long will we keep your personal data for? 

14.1. We will only keep your personal data for as long as necessary for the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. 

14.2. In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.  

14.3. Details of retention periods are set out in the table below: 

Data type  Retention period 
Client  As a general rule we will keep your personal data for 7 years from the date of your last outstanding invoice is paid. We may however be required to keep your personal data for longer or shorter if we are required to do so for legal or regulatory purposes. 
Prospective Clients  As a general rule we will only keep your personal data for 7 years from our last communication with you.  
Suppliers  We will only retain your personal data, for a period of 7 after our last communication with you. We may however be required to keep your personal data for longer or shorter if we are required to do so for legal or regulatory purposes. 
All website visitors  Please see our cookie notice for details of how long personal data is retained when you visit our website. 

15. Third-party links on our website 

15.1. Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share personal data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit. 

 

16. AI-Based Services and Data Enrichment (how we use Artificial Intelligence) 

16.1. Truvi may share limited personal data, such as email addresses and details of incidents, with trusted third-party service providers that use artificial intelligence (AI) technologies These services process data only on our instructions and are used to support specific internal business processes, including incident resolution and operational decision support. 

16.2. As part of our incident resolution process, Truvi uses an internal AIassisted tool to support the review of incidents once they have reached a decisionready stage. The AI tool reviews relevant incident information and supporting evidence submitted by Hosts, such as incident details, booking information, amounts in dispute, images, image metadata, timestamps and invoices from thirdparty companies, and produces a structured recommendation. This output is recorded as an internal comment linked to the incident and is reviewed by a Truvi Resolutions agent. Final decisions are always made by a human reviewer, and no decisions producing legal or similarly significant effects are made solely by automated means. 

16.3. The purpose of this processing is to help us maintain and improve the accuracy and completeness of our customer records and assess the validity and genuineness of an incident reported to us. This processing is carried out under our legitimate interests to deliver better services and communications, ensure fair and consistent outcomes, reduce error or inconsistency in incident handling, and improve operational efficiency for Hosts.  

16.4. You have the right to object to this processing at any time. For more information about your rights and how to exercise them, please see Section 12 above ‘What are your rights under the data protection laws’.  

 

17. Contact us and complaints  

17.1 You have the right to make a complaint about the processing of your personal data or in relation to the exercise of any of your rights at any time to the relevant supervisory authority. In the United Kingdom (UK) the data protection supervisory authority is the ICO. The ICO website is www.ico.org.uk and can be contacted via post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF or by telephone: 0303 123 1113 or any EU data protection regulator, in particular, the regulator for the Member State in which you reside or work, or in the member state where the activity which gave rise to the complaint occurred or our lead supervisory authority. We would, however, appreciate the chance to deal with your concerns before you approach a regulator. 

17.2. For a list of EEA data protection supervisory authorities and their contact details see here. 

17.3. We have appointed HelloDPO Law Ltd (https://hellodpo.com) as our Data Protection Officer. HelloDPO can be contacted at: [email protected] 

17.4. If you have any questions about this notice, including any requests to exercise your legal rights, please contact us using the details set out below. Please note that the email address provided can be used to reach the DPO: 

e [email protected] 

a: Truvi, 3rd Floor 1 Ashley Road, Altrincham, Cheshire, United Kingdom, WA14 2DT.  

17.5. For individuals in the EEA, you can contact us using the details above. 

 

18. Cookies  

18.1 Please see our cookie notice for details of the cookies we use on our website. 

 

Choose where to log in