Privacy Policy
Last updated: 27 July 2026
1. Who we are
terva.io is operated by TERVA.IO LTD, a company registered in England and Wales under company number 17198553, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ ("Terva," "we," "us," "our").
We are registered with the UK Information Commissioner's Office (ICO), registration reference ZC165584.
Our Data Protection Officer is Marco Cravero, contactable at info@terva.io.
2. Who this policy covers — two different groups
This policy covers two distinct groups of people, because Terva's service works differently for each of them:
- Our customers and their users — the home services businesses (solar installers, heat pump installers, insurance brokers, etc.) who subscribe to app.terva.io, and the individual people at those businesses who use it.
- Homeowners and other individuals whose property data we score — the people whose UK residential addresses are scored using public and licensed data sources, so that our customers can identify who to contact. These individuals do not have an account with Terva and have not signed up for anything — most will never have heard of us. Our obligations to this group, and the lawful basis we rely on, are necessarily different from our obligations to our paying customers, and are addressed separately below.
3. Personal data we collect and process
3.1 About our customers and their users
- Name, business email address, job title, and company details, provided when registering for or using the platform.
- Billing and payment information (processed via our payment provider; we do not store full card details ourselves).
- Usage data relating to how the platform is used (e.g. territories set, verticals selected, outreach drafted or sent).
- Communications with our support team.
3.2 About homeowners and other individuals whose addresses we score
- Property-level data linked to a UK residential address (e.g. EPC rating, planning applications, tenure, roof characteristics, flood risk, broadband availability, and similar signals), drawn from the public and licensed sources listed in Section 4.
- Where reasonably available from those sources, the name of a property's registered owner or occupier may be included (for example, via HM Land Registry title data).
- We do not collect financial account information, special category data (health, religion, ethnicity, etc.), or data about children in relation to this group.
4. Sources of data
We combine data from a number of public and licensed sources, including: HM Land Registry, the DLUHC EPC Register, the UK Planning Portal, Ofcom Connected Nations, the UK Police API, Companies House, the Environment Agency, the British Geological Survey, postcodes.io, and the Google Solar API — plus (where a data partnership is in place) supplementary property datasets such as TwentyCi's, and audience/demographic datasets such as Experian Mosaic.
5. Why we process this data, and our lawful basis
5.1 Our customers and their users
We process this data to provide the platform under contract with our customers (Article 6(1)(b) UK GDPR), to comply with legal obligations such as tax and accounting requirements (Article 6(1)(c)), and for our legitimate interests in improving and securing the service (Article 6(1)(f)).
5.2 Homeowners and other individuals whose addresses we score
It's important to be precise about what Terva itself does here, because two separate things are easy to conflate:
- Terva does not contact homeowners or other individuals directly. We do not send letters, emails, texts, or calls to the people whose addresses we score. That contact, where it happens, is carried out by our customers (the home services businesses who subscribe to the platform), using our AI Outreach Writer as a drafting tool.
- Terva does process and profile this data ourselves, independently of whether any outreach is ever sent. Collecting, combining, scoring, and ranking a property against a "likely to buy" model is processing — and profiling — under UK GDPR (Article 4(2) and 4(4)), and it happens entirely on our own infrastructure, before a customer ever sees or acts on it.
For this processing and profiling, we rely on legitimate interests (Article 6(1)(f) UK GDPR) as our lawful basis — our own legitimate interest, and that of our customers, in identifying which UK properties are likely to need a given home service, so that outreach (when a customer chooses to send it) can be targeted rather than indiscriminate. The fact that Terva itself has no direct contact with the individual, and does not disclose the score to anyone beyond the relevant subscribing customer, is a relevant factor in our own favour when weighing the impact of this processing on the individual. A Legitimate Interests Assessment (LIA) has been carried out and is available on request.
Where a customer goes on to contact an individual directly by email, text message, or automated call as a result of this scoring, the Privacy and Electronic Communications Regulations (PECR) — not UK GDPR — govern whether that specific contact is lawful, and responsibility for PECR compliance in a given piece of outreach rests with the customer sending it, not with Terva.
6. Your right to object
If you are a homeowner or other individual whose address has been scored, and you do not want your property data included in Terva's platform, you can ask us to stop processing it or to delete it via terva.io/data-request, or by emailing info@terva.io. We will action opt-out and objection requests without requiring you to justify the request, in line with Article 21 UK GDPR.
If you have received marketing correspondence generated using Terva's platform and no longer wish to receive it, you can unsubscribe via terva.io/unsubscribe.
7. Who we share data with
- With our customers, we share scored address data and any AI-drafted outreach relevant to their subscribed territories and verticals — this is the core service they pay for.
- With our sub-processors and service providers (listed below) under contract terms requiring them to protect personal data.
- With regulators or law enforcement where we are legally required to do so.
- We do not sell personal data, and we do not license our scored address data to be resold as a contact list independent of the platform.
7.1 Sub-processors
We share only what is strictly needed, only with the parties below, all bound by written Data Processing Agreements:
Infrastructure & hosting
- Supabase (managed Postgres, auth, storage) — EU (Frankfurt) region
- Cloudflare (CDN, DNS, WAF) — global edge, EU termination
- Vercel / Lovable hosting (application runtime) — EU region
Operational tooling
- Google Maps Platform — geocoding postcodes to coordinates (no personal data sent beyond the postcode)
- Stripe — Subscriber payment processing (Stripe is the controller for cardholder data)
- Resend — transactional email to Subscribers (account, billing, product notifications)
- Plausible — cookie-light, EU-hosted first-party site analytics
- Sentry — error monitoring (IP & user-agent only; PII scrubbed)
Professional advisers & authorities
- Our accountants, auditors, and legal advisers, under professional confidentiality
- HMRC, Companies House, the ICO, courts, or law enforcement where legally required
8. International transfers
Where any of our processors or sub-processors are located outside the UK, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement or an adequacy decision, before personal data is transferred there.
9. Data retention
Property/address scoring data is reviewed at least every 12 months and removed or updated as underlying public sources change. Specific retention periods by data category are set out below. When retention expires, data is hard-deleted from primary stores and purged from backups on the next backup cycle.
| Data category | Retention |
|---|---|
| Property & address reference data | Refreshed on each source's cadence; superseded versions kept 24 months for model reproducibility |
| Derived scores delivered to a Subscriber | Life of Subscriber contract + 12 months (audit / dispute window) |
| Subscriber account record | Life of contract + 12 months, then deletion or anonymisation |
| Billing & invoice records | 6 years from end of tax year (HMRC requirement) |
| Authentication & security audit logs | 13 months rolling |
| Product telemetry & error logs | 90 days, then aggregated |
| Marketing emails (B2B prospect outreach) | Until opt-out, then 24 months on a suppression list |
| Backups | Encrypted, rolling 30 days, then overwritten |
10. Security
We implement technical and organisational measures appropriate to the risk, including access controls restricting personal data to staff who need it, encryption in transit and at rest, and regular review of third-party processors.
11. Your rights
Under UK GDPR, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure; restrict or object to processing; request portability of your data; and lodge a complaint with the ICO (ico.org.uk) if you believe we have not handled your data properly. To exercise any of these rights, contact us at info@terva.io or via terva.io/data-request.
12. Children
Terva's platform and website are not directed at children, and we do not knowingly collect personal data from children.
13. Cookies
Our use of cookies on terva.io is described in our separate Cookie Policy at terva.io/cookies.
14. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will reflect the most recent version, and we'll flag material changes to customers where appropriate.
15. Contact us
Marco Cravero, Data Protection Officer
Email: info@terva.io
Post: TERVA.IO LTD, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ