Introduction
Revyva Labs Ltd ("we", "us", or "our") is committed to protecting your personal information and respecting your privacy rights. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you visit our website, utilise our custom web applications, or interact with our automated systems, including when you opt in to receive SMS or text message communications.
Information We Collect
We collect information from you when you complete a web form, request an interactive pricing estimate, engage with an automated chat assistant, or opt in to SMS communications.
2.1 Information You Provide Directly
- Full name and business contact details
- Email address and professional phone number
- Business location and industry category
- Project requirements, measurements, or scoping details entered into our custom web apps
2.2 SMS / Text Message Opt-In Data
When you opt in to receive communications from us, we collect your mobile number and maintain a verified record of your consent. Your mobile number and SMS consent data will never be shared with, sold to, or utilised by third parties for their independent marketing activities. This data is handled exclusively by Revyva.
Our Role
We deploy custom applications and AI automation infrastructure across client environments:
- For automated platforms deployed within a client's dedicated environment, the client operates as the Data Controller.
- Revyva acts as a Data Processor in these scenarios, providing technical configuration, API integration, and ongoing system maintenance.
AI Processing & Transparency
In full compliance with the Data (Use and Access) Act 2025, we declare the following operational practices regarding our automated workflows:
- We utilise automated agents to facilitate website lead triage, instant quote estimations, and scheduling workflows.
- Interactions with our Voice AI agents may be recorded or transcribed solely for service execution and quality control.
- You retain the right at any time to request human intervention or contest significant decisions processed through automated logic.
How We Use Your Information
- To personalise your system walkthroughs and deliver instant job scoping estimates.
- To improve our web applications and customer communication workflows.
- To dispatch transactional emails, instant callback triggers, and SMS updates where explicit consent has been given.
- To fulfil legal, regulatory, and audit obligations under UK law.
Cookies and Consent Mode
We deploy Google Consent Mode (Advanced) across our web properties. This mechanism communicates your explicit privacy choices directly to Google tags. If you decline tracking consent, analytical services will not store cookies, though anonymised pings may still be transmitted for aggregated traffic performance metrics.
Data Retention Standards
- Analytical & Lead Enquiries: Retained for 14 months for comparative annual reporting.
- SMS Records & Consent Audit Logs: Retained for a minimum of 4 years to satisfy telecommunications regulations.
- Active Client System Records: Retained for the contract duration plus 6 years to satisfy legal, statutory, and accounting obligations.
Third-Party Infrastructure
We host messaging, customer relationship management, and workflow automations using secure enterprise cloud platforms, and deploy custom web applications through dedicated cloud hosting infrastructure. Automated logic connects to enterprise artificial intelligence APIs. All customer payloads are encrypted and are strictly prohibited from being used to train public machine learning models.
Regulatory Compliance
We operate in strict accordance with the Data (Use and Access) Act 2025, UK GDPR, and the Privacy and Electronic Communications Regulations (PECR). Our digital infrastructure relies on enterprise-grade ISO-certified data centres. All cross-border data transfers are safeguarded using AES-256 encryption at rest and TLS 1.2+ encryption in transit.
Security Architecture
- Data Encryption: End-to-end encryption applied at rest (AES-256) and during transit (TLS 1.2+).
- Data Minimisation: Automated pipelines filter out unnecessary personally identifiable information before processing.
- Access Control: Multi-Factor Authentication (MFA) is strictly enforced across all internal administrative tools.
Your Individual Rights
Under UK GDPR, you maintain full rights to access your personal data, request corrections or erasure, object to specific processing workflows, and request human oversight for any automated communication system.
Complaints Procedure
If you have questions regarding data privacy, please contact our team directly. If you feel your concerns have not been satisfactorily resolved, you have the right to lodge a formal complaint with the UK Information Commissioner's Office (ICO).
Contact Us
Revyva Labs Ltd
The Granary Barn, Valley Farm, Valley Road, Sudbury, CO10 0QQ
Legal & Privacy Contact: [email protected]