CERTIO

Privacy Policy

Last updated 12 September 2026

This Privacy Policy explains how Certio ("Certio", "we", "us") collects, uses, shares and protects personal data when you use the Certio mobile app and related services (the "Service"). The Service is operated by Certio Software Ltd, a company registered in England and Wales under company number 17450320, whose registered office is at 565 Green Lanes, London, England, N8 0RL. Certio Software Ltd is subject to UK law, including the UK GDPR and the Data Protection Act 2018, and is the data controller described in section 1 below. General contact: support@certio.uk.

1. Who is responsible for your data

Certio is a business tool for tradespeople. Two different relationships apply:

2. What personal data we collect

CategoryExamplesSource
Account & identityName, email, password (hashed), business/trading name, team membership & roleYou, at sign-up
Business contentQuotes, invoices, certificates (EICR/EIC/PAT/MW), bookings, job notes, receipts and their totals, uploaded photos of appliances/boards/receiptsYou, in-app
Your customers' personal dataCustomer names, phone numbers, addresses, emails; the content of WhatsApp and email messages exchanged with themIngested via connected WhatsApp / email inbox and manual entry
LocationApproximate/precise device location for address auto-fill and drive-time estimates; optional live job-location share; optional worker location trail while clocked in (Teams)Device, with your permission
ContactsOn-device phone contacts read only to match a number to a name (stays on the device); contacts you explicitly import become part of your client bookDevice, with your permission
CalendarFree/busy times read to avoid double-booking (event details stay on the device); events written only when you tap "Add to calendar"Device, with your permission
Camera & microphonePhotos you capture; voice dictation audio (transcribed to text)Device, with your permission
Financial & bankingInvoice/payment records; if you connect Open Banking, read-only transaction data used to reconcile paymentsYou / your bank via a regulated provider
TechnicalDevice/app version, diagnostic and error informationAutomatically

Website visitors

If you only visit our website without creating an account, we hold no personal data about you beyond the non-identifying page-use measurement described in section 11: no name, no email address, no stored IP address and nothing you typed — with one exception that you control. If you use the “email me the link” box on the sign-up page, we store the email address you enter there to send you the sign-up link, once. We keep it for up to 60 days and then delete it, and we do not use it for anything else. Legal basis: consent, which you can withdraw at any time by emailing support@certio.uk.

3. How we use it, and our legal bases

PurposeLegal basis (UK GDPR)
Provide the Service you signed up for (accounts, certs, quotes, invoices, bookings, messaging assistant)Performance of a contract
Process your customers' data to draft/send messages, detect bookings, generate documentsProcessing on the controller's (your) instructions; your customers' lawful basis is your responsibility as controller
Location, contacts, calendar, camera, microphone featuresConsent (via the device permission prompt; you can withdraw at any time in device settings)
Security, fraud/abuse prevention, service reliability, supportLegitimate interests
Legal and regulatory complianceLegal obligation

4. Sub-processors & third parties we share data with

We use the following providers to deliver features. Data is shared only as needed for the stated purpose. This list may change; we will keep it current.

ProviderPurposeData shared
AnthropicAI assistant that drafts replies, quotes and detects bookingsMessage/enquiry text and relevant business context
Ideal Postcodes / postcodes.ioPostcode lookup for addresses you typeThe postcode being looked up
CARTO / OpenStreetMapMap tiles on the web portal's map viewMap tile requests (approximate viewport, IP address)
getAddress.ioFull address lookup for UK postcodesThe postcode being looked up
Google (Gemini)AI reading of certificate/board photos and textImages and text you submit
OpenAISpeech-to-text transcription of your dictationAudio you record for transcription
ElevenLabsOptional voice featuresText/voice for the requested feature
Google (Calendar / Gmail)Optional calendar and email connections you enableOnly what the connection requires
StripeCard paymentsPayment and invoice details
Open Banking provider — an FCA-authorised Account Information Service Provider, named on the consent screen before you authorise the connectionOptional read-only bank reconciliation (only if you switch it on)Bank transaction data you authorise
ResendSending emails on your behalf (invoices/quotes/certs)Recipient address and message content
Hostinger International LimitedHosting the Certio backend and database (servers located in the United Kingdom)Data at rest/in transit as needed to operate
CloudflareNetwork, TLS termination and protection for certio.ukTraffic metadata in transit

We do not sell your personal data or your customers' personal data.

5. International transfers

Some providers above process data outside the UK/EEA (e.g. the United States). Where they do, transfers are made under an appropriate safeguard such as the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, or an adequacy decision.

6. Retention

We keep account and business data for as long as your account is active and as needed to provide the Service. Backups are retained on a rolling basis. Where a specific limit applies (for example, worker location trails are retained for no more than 30 days), we apply it. When you delete your account we delete or irreversibly anonymise your data as described below, subject to any legal retention obligations.

7. Your rights

Under UK/EU data protection law you have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. To exercise any right, email support@certio.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

If you are one of a tradesperson's customers and want your data corrected or removed, contact the tradesperson (the controller) directly; we will assist them as their processor.

8. Account & data deletion

You can delete your account and its data at any time inside the app (Account → Delete account), which permanently removes your account, your team data, and your stored business and customer data from our systems, and your cloud backups. Data held only on your device is removed when you uninstall the app. If you no longer have the app, email support@certio.uk from your registered address and we will action the deletion. A web request page is also available at certio.uk/delete-account.

9. Security

We take appropriate technical and organisational measures to protect your data. Data is transmitted over encrypted connections (HTTPS/TLS); access to backend systems is restricted and authenticated; sensitive credentials (such as connected-account tokens) are encrypted at rest using authenticated encryption. We are continually strengthening our safeguards, including expanding encryption-at-rest coverage. No system is perfectly secure; we will notify you and the ICO of a qualifying personal-data breach as required by law.

10. Children

Certio is a business tool intended for users aged 18 and over. It is not directed at children and we do not knowingly collect children's data.

11. Cookies and website measurement

Nothing for advertising runs until you say yes. When you first visit we ask a single question, with Accept and Reject offered equally. Until you choose, and for as long as you choose Reject, our site sets no cookies at all, loads nothing from Facebook or any other advertising network, and stores nothing on your device beyond the record of your answer.

If you accept

We load the Meta (Facebook) pixel, so we can tell which of our adverts brought someone to the site and whether it led to a sign-up. It sets two first-party cookies, _fbp and _fbc, and tells Meta the page you are on plus two specific moments: that an account was created, and that a subscription was paid for. We also keep a note in your browser's local storage of the campaign tag you arrived with, so the right advert gets the credit if you come back days later.

We have deliberately switched OFF Meta's "automatic advanced matching", which would otherwise read the fields of any form on the page and send Meta a scrambled copy of what you had typed. We never send an advertising network your name, email address, phone number, password or payment details, we never put those things in a web address, and the only conversion details we send are the plan name and its price.

If you reject, or change your mind

Rejecting costs you nothing — every part of the site works identically. We still count visits, using the anonymous method described below that stores nothing on your device. You can change your answer whenever you like using the Cookie settings link at the bottom of every page. Withdrawing does not merely record a preference: it deletes the advertising cookies and the campaign note from your browser there and then.

Our legal basis for advertising cookies is your consent, and you can withdraw it as easily as you gave it. The record of your choice is itself kept in your browser's local storage; that is strictly necessary to honour your decision, so it stays whatever you choose.

We do measure how our own pages are used, on our own servers, so we can tell which pages and which adverts are worth running. For each page opened we record the page address, the link or campaign you arrived from, the type of device (mobile, tablet or desktop), your screen size and browser language, and then how the page was used: how far down it was scrolled, which buttons and links were tapped, which sections were reached, roughly how long the page was visible, and — on the sign-up form only — which fields were started.

We never record anything you type. There is no keystroke logging, no session recording, no mouse tracking and no reading of form values. On the sign-up form we record the name of a field (for example "postcode") so we can see where the form is confusing; the content you enter is never part of this measurement, and password fields are excluded entirely.

This measurement uses no cookie and stores nothing on your device. To tell one person reading five pages from five people reading one page, our server derives a short code from your IP address and browser description combined with a secret that is thrown away and replaced every day. Your IP address itself is not stored in these records, the code cannot be reversed to identify you, and once the daily secret has rotated the records can no longer be linked to each other or to any later visit. We consider this data non-identifying, which is why the site shows you no consent banner for it; if you would still rather not be counted, any browser setting or extension that blocks analytics requests will stop it, and the site works exactly the same.

More detail on how the site is used

Alongside the measurement above we also record, without cookies: when text is copied (which section it was copied from and how many characters — never the text itself), when an image is saved or long-pressed, when a page is printed or saved as a PDF, repeated or unresponsive taps, whether our video was played, how quickly the page loaded, and the section someone was reading when they left. To understand the kind of connection a visit came through, we look up the name of the network provider for the visitor's IP address (for example a mobile network, a broadband provider, or a VPN or hosting company) using the ipinfo.io service; we store the provider's name, not the IP address. We use this to tell genuine interest apart from automated traffic and market research.

If you accept cookies, the site also keeps a random identifier in your browser so we can tell that a visit on another day came from the same browser. It is not linked to your name or account, and it is removed if you withdraw consent using Cookie settings.

Emails we send you

When you create an account we send you a welcome email. Its links (“Get the app” and “Open Certio in your browser”) go through our own server first, so we can see whether you managed to get set up: we record, against your account, that a link was used and when. We also keep the delivery status our email provider reports (for example “delivered” or “bounced”). Our emails contain no tracking images, so we do not know whether or when you open them, and none of this is shared with anyone or used for advertising.

The support chat

The "Message us" button opens a chat answered by Certio's own assistant. What you type is sent to our server, kept so we can answer you and improve our help, and your questions may be read by our staff. Your browser keeps one item for the length of the visit — an id for the conversation, so refreshing the page does not lose your messages. That is strictly necessary for a service you asked for, so it needs no consent. Please do not send passwords or card details in the chat; we will never ask for them.

12. Changes

We may update this policy. Material changes will be notified in-app or by email. The "last updated" date at the top shows the current version.

13. Contact

Data protection queries: support@certio.uk. We handle correspondence by email; if you need a postal address for a formal notice, write to Certio Software Ltd, 565 Green Lanes, London, England, N8 0RL.


Terms of Service · Data Processing Agreement · Privacy & Terms (combined)