This Privacy Policy explains how Certio ("Certio", "we", "us") collects, uses, shares and protects personal data when you use the Certio mobile app and related services (the "Service"). Certio is operated as a sole-trader business established in the United Kingdom and is subject to UK law, including the UK GDPR and the Data Protection Act 2018. We are the data controller described in section 1 below. For the operator's registered details, or for postal correspondence, contact support@certio.uk and we will provide them. General contact: support@certio.uk.
Certio is a business tool for tradespeople. Two different relationships apply:
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, email, password (hashed), business/trading name, team membership & role | You, at sign-up |
| Business content | Quotes, invoices, certificates (EICR/EIC/PAT/MW), bookings, job notes, receipts and their totals, uploaded photos of appliances/boards/receipts | You, in-app |
| Your customers' personal data | Customer names, phone numbers, addresses, emails; the content of WhatsApp and email messages exchanged with them | Ingested via connected WhatsApp / email inbox and manual entry |
| Location | Approximate/precise device location for address auto-fill and drive-time estimates; optional live job-location share; optional worker location trail while clocked in (Teams) | Device, with your permission |
| Contacts | On-device phone contacts read only to match a number to a name (stays on the device); contacts you explicitly import become part of your client book | Device, with your permission |
| Calendar | Free/busy times read to avoid double-booking (event details stay on the device); events written only when you tap "Add to calendar" | Device, with your permission |
| Camera & microphone | Photos you capture; voice dictation audio (transcribed to text) | Device, with your permission |
| Financial & banking | Invoice/payment records; if you connect Open Banking, read-only transaction data used to reconcile payments | You / your bank via a regulated provider |
| Technical | Device/app version, diagnostic and error information | Automatically |
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Provide the Service you signed up for (accounts, certs, quotes, invoices, bookings, messaging assistant) | Performance of a contract |
| Process your customers' data to draft/send messages, detect bookings, generate documents | Processing on the controller's (your) instructions; your customers' lawful basis is your responsibility as controller |
| Location, contacts, calendar, camera, microphone features | Consent (via the device permission prompt; you can withdraw at any time in device settings) |
| Security, fraud/abuse prevention, service reliability, support | Legitimate interests |
| Legal and regulatory compliance | Legal obligation |
We use the following providers to deliver features. Data is shared only as needed for the stated purpose. This list may change; we will keep it current.
| Provider | Purpose | Data shared |
|---|---|---|
| Anthropic | AI assistant that drafts replies, quotes and detects bookings | Message/enquiry text and relevant business context |
| Google (Gemini) | AI reading of certificate/board photos and text | Images and text you submit |
| OpenAI | Speech-to-text transcription of your dictation | Audio you record for transcription |
| ElevenLabs | Optional voice features | Text/voice for the requested feature |
| Google (Calendar / Gmail) | Optional calendar and email connections you enable | Only what the connection requires |
| Stripe | Card payments | Payment and invoice details |
| Open Banking provider — an FCA-authorised Account Information Service Provider, named on the consent screen before you authorise the connection | Optional read-only bank reconciliation (only if you switch it on) | Bank transaction data you authorise |
| Resend | Sending emails on your behalf (invoices/quotes/certs) | Recipient address and message content |
| Hostinger International Limited | Hosting the Certio backend and database (servers located in the United Kingdom) | Data at rest/in transit as needed to operate |
| Cloudflare | Network, TLS termination and protection for certio.uk | Traffic metadata in transit |
We do not sell your personal data or your customers' personal data.
Some providers above process data outside the UK/EEA (e.g. the United States). Where they do, transfers are made under an appropriate safeguard such as the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, or an adequacy decision.
We keep account and business data for as long as your account is active and as needed to provide the Service. Backups are retained on a rolling basis. Where a specific limit applies (for example, worker location trails are retained for no more than 30 days), we apply it. When you delete your account we delete or irreversibly anonymise your data as described below, subject to any legal retention obligations.
Under UK/EU data protection law you have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. To exercise any right, email support@certio.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
If you are one of a tradesperson's customers and want your data corrected or removed, contact the tradesperson (the controller) directly; we will assist them as their processor.
You can delete your account and its data at any time inside the app (Account → Delete account), which permanently removes your account, your team data, and your stored business and customer data from our systems, and your cloud backups. Data held only on your device is removed when you uninstall the app. If you no longer have the app, email support@certio.uk from your registered address and we will action the deletion. A web request page is also available at certio.uk/delete-account.
We take appropriate technical and organisational measures to protect your data. Data is transmitted over encrypted connections (HTTPS/TLS); access to backend systems is restricted and authenticated; sensitive credentials (such as connected-account tokens) are encrypted at rest using authenticated encryption. We are continually strengthening our safeguards, including expanding encryption-at-rest coverage. No system is perfectly secure; we will notify you and the ICO of a qualifying personal-data breach as required by law.
Certio is a business tool intended for users aged 18 and over. It is not directed at children and we do not knowingly collect children's data.
Our marketing and sign-up website uses only essential cookies needed to operate. If we introduce analytics or non-essential cookies, we will ask for your consent first.
We may update this policy. Material changes will be notified in-app or by email. The "last updated" date at the top shows the current version.
Data protection queries: support@certio.uk. We handle correspondence by email; if you need a postal address for a formal notice, request it at support@certio.uk and we will provide it.
Certio provides tools for tradespeople to manage enquiries, quotes, invoices, certificates, bookings and customer communications, including AI-assisted drafting and, optionally, an automated messaging assistant. Features depend on your subscription tier and the integrations you enable.
You must provide accurate information, keep your login secure, and are responsible for activity under your account and any team members you add. You must be 18+ and using Certio for business purposes.
You are the data controller for your customers' data and are responsible for having a lawful basis to contact them (including compliance with PECR and applicable marketing/consent rules). The AI assistant drafts and, where you enable it, sends messages on your behalf; you are responsible for the content sent from your account. You must review outputs where appropriate and must not use Certio to send unlawful, misleading or unsolicited communications.
AI-generated drafts, price suggestions, booking detections and document text are provided to assist you and may contain errors. They are not professional, legal, electrical-compliance or financial advice. You are responsible for checking anything before you rely on or send it. Certificates and compliance records remain your professional responsibility under the applicable standards (e.g. BS 7671).
You must not misuse the Service, attempt to access other tenants' data, reverse-engineer it, use it to break the law, or overload or abuse the AI or messaging features. We may suspend accounts that do.
Certio is offered on three tiers:
All prices are exclusive of VAT, which is added where applicable. Paid tiers include a 7-day free trial; no charge is taken during the trial, and if you do not continue, your account reverts to the Free tier. After the trial, subscriptions renew monthly in advance until cancelled. You can cancel at any time from Billing in the app or the web portal; cancellation takes effect at the end of the period you have already paid for, and part-months are not refunded. Payments are taken by Stripe, our payment processor — we do not store your card details. Prices may change on at least 30 days' notice given by email or in-app, and any change takes effect from your next renewal, so you can cancel first if you do not want to continue.
Certio and its software remain our property. Your data and documents remain yours; you grant us the limited licence needed to operate the Service for you.
The Service is provided "as is" to the extent permitted by law. We do not exclude liability for death or personal injury caused by negligence, fraud, or anything else that cannot be excluded under law. Subject to that, our total liability to you for all claims arising in any 12-month period is limited to the total fees you paid us for the Service in the 12 months before the claim arose (or £100, if that is greater). We are not liable for indirect or consequential loss, or for the acts of your customers or of third-party providers.
You may stop using and delete your account at any time. We may suspend or terminate access for breach of these Terms or where required by law.
These Terms are governed by the laws of England & Wales, and the courts of England & Wales have exclusive jurisdiction.