Legal

Privacy policy

What we collect, why we are allowed to, how long we keep it, and what you can make us do about it. Written to be read, not to be survived.

Version 1.0 Last updated 20 August 2026 Applies to vervevista.co.uk

1. Who we are

Verve Vista provides AI call handling and workflow automation to trades and field service businesses in the United Kingdom. For the personal data described in this policy, the controller is Matvei Ciuravin, a sole trader operating under the trading name Verve Vista. A sole trader is an individual, not a company — so the controller is a named person, and that person is accountable for everything in this document.

Who to write to
Matvei Ciuravin, trading as Verve Vista
71 Duesbery Street, Hull, HU5 3QE, United Kingdom
matt@vervevista.co.uk · +44 7940 803924

That address is our address for the service of documents, given under section 1202 of the Companies Act 2006 because we trade under a name that is not the proprietor's surname.

We are not a registered company and have no company number. If that changes we will update this page and tell anyone whose data we already hold.

We have not appointed a Data Protection Officer. UK GDPR only requires one in specific circumstances — public authorities, large-scale systematic monitoring, or large-scale special category processing — and none of them apply to us. The contact above reaches the person responsible.

2. The short version

  • If you fill in the booking form, we get your name, company, email, phone and your answers to four questions. We use them to prepare for and hold a call.
  • If you book a time, Calendly processes that booking on our behalf. It is a US company, and there is a transfer mechanism in place — section 6.
  • This site stores two cookies and nothing else. Neither is for advertising. See the full list, or turn them off in the preferences panel.
  • We do not sell your data, we do not share it for anyone else's marketing, and we do not run advertising or profiling technology on this site.
  • You can ask to see what we hold, correct it, or have it deleted. Section 9.

3. What we collect and why

Everything we collect through this website is listed here. If it is not on this table, we are not collecting it.

WhatWhyLawful basisKept for
Booking enquiry
Name, company name, work email, phone number, whether you run a UK trades business, team size, priority, desired start window
To reply, to judge whether we can actually help, and to arrive at the call already knowing your situation Article 6(1)(b) — steps taken at your request before entering a contract. Where you turn out not to be a prospective customer, Article 6(1)(f) legitimate interests in responding to business enquiries 24 months from our last contact
Scheduling
Name, email, chosen slot, time zone, and the summary we pass to Calendly
To put a meeting in both diaries and send the confirmation and reminders Article 6(1)(b) — steps taken at your request 24 months from the meeting; Calendly's own retention applies to its copy
Direct contact
Whatever you put in an email or say on the phone
To answer you and keep a record of what was agreed Article 6(1)(f) — legitimate interests in running a business and keeping accurate records 24 months from our last contact
Server logs
IP address, browser and device string, pages requested, timestamps, referring page
To serve the site, keep it up, and investigate abuse or attack Article 6(1)(f) — legitimate interests in the security and availability of our own service No longer than 30 days unless a specific incident requires it. Our host keeps its own operational logs under its own retention policy
Preferences
Your light/dark choice and your opt-outs
To keep the site as you set it PECR exceptions — see section 4. No separate Article 6 basis is needed beyond Article 6(1)(f) for honouring your own settings 12 months, or until you clear it

Where we rely on legitimate interests

Article 6(1)(f) requires us to balance our interest against your rights. Our interest is in replying to people who contact us, keeping the site online, and keeping honest records. The data involved is business contact detail and technical log data, it is not sensitive, and it is not used to build a profile of you. We think that balance is straightforward — but you can object at any time under section 9 and we will stop unless we can show compelling grounds not to.

Do you have to give it to us?

No. There is no statutory or contractual requirement to fill in the form. If you leave it blank we simply cannot arrange a call — email or phone us instead.

Special category data

We do not ask for and do not want health, biometric, racial or ethnic origin, political, religious, trade union, sex life or sexual orientation data. Please do not put any of it in the form.

4. Cookies and similar storage

UK cookie rules sit in the Privacy and Electronic Communications Regulations (PECR), not in UK GDPR. Since 5 February 2026, Schedule A1 of PECR — inserted by the Data (Use and Access) Act 2025 — exempts certain uses from the consent requirement, on condition that we give clear information and a free way to object. That is exactly what this section and the preferences panel are.

CookieWhat it holdsWhy it is allowedLife
vv_theme Either dark or light — the choice you made with the switch in the header PECR Schedule A1 — storage used solely to customise the appearance of the service at your request 12 months
vv_prefs Whether you have seen the notice, and which of the options in the preferences panel you have switched off Strictly necessary — Regulation 6(4). Without it we cannot remember that you asked us to stop 12 months

What we do not set

No advertising cookies. No third-party trackers. No cross-site identifiers, no fingerprinting, no pixels, no social plug-ins. We do not currently run analytics of any kind — there is a switch for it in the preferences panel, held off, so that the control exists before the thing it controls does.

If we ever add analytics that shares data with a third party for that third party's own purposes, the exception above stops applying and we will ask for your opt-in consent first.

Turning them off

Open the preferences panel. Switching an option off deletes what was stored for it straight away — it does not merely stop future writes. You can also block or delete cookies in your browser settings; the site keeps working, it just forgets your appearance choice between visits.

Calendly

The scheduling step embeds Calendly in a frame. Calendly sets its own cookies inside that frame under its own privacy notice. Nothing loads from Calendly until you submit the enquiry form and reach the scheduling step — if you never get there, nothing of theirs runs.

5. Who else sees it

We do not sell personal data and we do not share it for anyone else's marketing. We use a small number of suppliers who process data on our written instructions as processors under Article 28:

  • Calendly LLC — scheduling. Receives your name, email and the summary of your answers when you book a slot.
  • Vercel Inc. — hosting. Serves every page of this site, and so handles the server log data described in section 3.
  • Cloudflare, Inc. — DNS for vervevista.co.uk, which resolves the address your browser asks for before it reaches us.
  • Google Ireland Limited (Google Workspace) — email. Holds the correspondence sent to and from matt@vervevista.co.uk.

We will also disclose data where the law requires it — to a court, a regulator, or law enforcement acting on a valid request — and to our professional advisers where necessary. If the business is ever incorporated as a limited company, or sold, records may pass to that company or buyer, who would be bound by this policy until they lawfully tell you otherwise. We will post notice of that here first.

6. Sending data abroad

Some of the suppliers in section 5 are based in the United States, so some of the data described here leaves the UK. That is lawful only with a recognised transfer mechanism behind it, and each one is named below rather than waved at.

WhoWhat reaches themMechanism
Vercel Inc.
United States
Everything needed to serve a page — your IP address, browser string and the pages you request Certified under the UK Extension to the EU–U.S. Data Privacy Framework, with the Standard Contractual Clauses and the UK International Data Transfer Addendum as the fallback in its data processing addendum
Calendly LLC
United States
Your name, email and the summary of your answers — but only if you reach the scheduling step Certified under the UK Extension to the EU–U.S. Data Privacy Framework, with SCCs and the UK Addendum (Module 2) as the fallback in its data processing addendum
Google Ireland Limited
Ireland, with onward processing by Google LLC in the United States
Anything you put in an email to us, and our replies Google LLC is certified under the UK Extension to the EU–U.S. Data Privacy Framework. Google's data processing amendment also incorporates the Standard Contractual Clauses with UK supplementary terms
Cloudflare, Inc.
United States
The DNS lookup your browser makes for our domain Certified under the UK Extension to the EU–U.S. Data Privacy Framework, with SCCs and the UK Addendum as the fallback

The UK Government has recognised the UK Extension to the Data Privacy Framework as providing an adequate level of protection for transfers to certified US organisations. Where a certification lapses or the framework is withdrawn, each of the addenda above falls back to the Standard Contractual Clauses with the UK Addendum, so a transfer never runs without a mechanism.

If you would rather nothing of yours went to the United States: do not use the scheduling step — email or ring us and we will arrange the call by hand. Hosting and DNS cannot be avoided while you are reading this page, because they are how the page reached you; but nothing beyond ordinary server log data is involved in that.

Our own working records — notes, quotes, the file we keep on an enquiry — are held in the United Kingdom or the European Economic Area.

7. How long we keep it

The retention column in section 3 is the rule. Two things sit outside it:

  • Accounting records. Where we have invoiced you, we keep what tax law requires — currently six years from the end of the accounting period.
  • Anything under dispute. If there is a live complaint or claim, we keep the relevant records until it is resolved and the limitation period has run out.

When a retention period ends we delete or irreversibly anonymise the data. We review what we are holding at least once a year.

8. When we act for a client

This is the part most policies skip, and it matters. There are two different relationships:

  • You contact us about our service. We are the controller. This policy applies in full.
  • You ring a business that uses our call handling. That business is the controller of your call and the details you give. We are their processor — we handle the call on their instructions under an Article 28 contract, and we do not use what we hear for our own purposes.

In the second case, ask that business for its privacy notice, and send rights requests to them. If you send one to us, we will pass it on promptly and tell you who we sent it to.

Calls handled on a client's behalf may be recorded and transcribed where that client has set it up and told callers so. The client decides that, not us.

9. Your rights

Under UK GDPR you have the following rights over personal data we hold as controller. They are not absolute — some only apply in particular circumstances, and we will explain plainly if one does not apply to your request.

  • Be informed — this document.
  • Access — a copy of what we hold about you.
  • Rectification — correct anything inaccurate or incomplete.
  • Erasure — deletion, where we no longer need it or you successfully object.
  • Restrict processing — make us hold it but stop using it while something is checked.
  • Data portability — receive the data you gave us in a machine-readable form, where we relied on consent or contract.
  • Object — to processing based on legitimate interests, and absolutely to direct marketing.
  • Withdraw consent — where we relied on consent, at any time, without affecting what was lawful before.
  • Not be subject to solely automated decisions that produce legal or similarly significant effects — see section 12.

How to exercise them

Email matt@vervevista.co.uk and say which right you are using. You do not need a form or a particular wording. We may ask for enough information to be sure who you are, which protects you as much as us.

We respond within one month. If a request is complex or you have made several, we can extend by up to two further months — we will tell you within the first month if that happens, and why. It is free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse and explain why.

10. Complaining

Please raise it with us first — we would rather fix it than have it escalated. But you have the right to go straight to the supervisory authority, and using it does not affect any other remedy.

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint

You may also seek a judicial remedy in the courts.

11. Security

The site is served over HTTPS. Access to enquiry data is limited to people who need it to do their job, accounts are protected with multi-factor authentication, and we choose suppliers who commit to appropriate technical and organisational measures under Article 32.

No system is perfect. If a breach happens that is likely to risk your rights and freedoms, we will tell the ICO within 72 hours of becoming aware, and tell you directly where the risk to you is high.

12. Automated decisions

On this website: none. Nothing you submit here is decided by a machine. A person reads every enquiry.

In the service we sell: our software answers calls, works out what the caller wants and how urgent it is, and books appointments. Those are operational decisions about scheduling — they do not produce legal effects or similarly significant effects for the caller, and a person can always review or override them. Where a client configures anything that could have a significant effect, that client is the controller and must have its own basis and safeguards under Article 22.

13. Children

This site and this service are aimed at businesses. We do not knowingly collect data from anyone under 18 through this website. If you believe a child has sent us personal data, tell us and we will delete it.

14. Changes

When this policy changes we update the version and date at the top. If a change materially affects how we use data you have already given us, we will tell you directly rather than relying on you noticing. Previous versions are available on request.

Back to the site Terms of use