Legal
Privacy policy
What we collect, why we are allowed to, how long we keep it, and what you can make us do about it. Written to be read, not to be survived.
1. Who we are
Verve Vista provides AI call handling and workflow automation to trades and field service businesses in the United Kingdom. For the personal data described in this policy, the controller is Matvei Ciuravin, a sole trader operating under the trading name Verve Vista. A sole trader is an individual, not a company — so the controller is a named person, and that person is accountable for everything in this document.
Who to write to
Matvei Ciuravin, trading as Verve Vista
71 Duesbery Street, Hull, HU5 3QE, United Kingdom
matt@vervevista.co.uk ·
+44 7940 803924
That address is our address for the service of documents, given under section 1202 of the Companies Act 2006 because we trade under a name that is not the proprietor's surname.
We are not a registered company and have no company number. If that changes we will update this page and tell anyone whose data we already hold.
We have not appointed a Data Protection Officer. UK GDPR only requires one in specific circumstances — public authorities, large-scale systematic monitoring, or large-scale special category processing — and none of them apply to us. The contact above reaches the person responsible.
2. The short version
- If you fill in the booking form, we get your name, company, email, phone and your answers to four questions. We use them to prepare for and hold a call.
- If you book a time, Calendly processes that booking on our behalf. It is a US company, and there is a transfer mechanism in place — section 6.
- This site stores two cookies and nothing else. Neither is for advertising. See the full list, or turn them off in the preferences panel.
- We do not sell your data, we do not share it for anyone else's marketing, and we do not run advertising or profiling technology on this site.
- You can ask to see what we hold, correct it, or have it deleted. Section 9.
3. What we collect and why
Everything we collect through this website is listed here. If it is not on this table, we are not collecting it.
| What | Why | Lawful basis | Kept for |
|---|---|---|---|
| Booking enquiry Name, company name, work email, phone number, whether you run a UK trades business, team size, priority, desired start window |
To reply, to judge whether we can actually help, and to arrive at the call already knowing your situation | Article 6(1)(b) — steps taken at your request before entering a contract. Where you turn out not to be a prospective customer, Article 6(1)(f) legitimate interests in responding to business enquiries | 24 months from our last contact |
| Scheduling Name, email, chosen slot, time zone, and the summary we pass to Calendly |
To put a meeting in both diaries and send the confirmation and reminders | Article 6(1)(b) — steps taken at your request | 24 months from the meeting; Calendly's own retention applies to its copy |
| Direct contact Whatever you put in an email or say on the phone |
To answer you and keep a record of what was agreed | Article 6(1)(f) — legitimate interests in running a business and keeping accurate records | 24 months from our last contact |
| Server logs IP address, browser and device string, pages requested, timestamps, referring page |
To serve the site, keep it up, and investigate abuse or attack | Article 6(1)(f) — legitimate interests in the security and availability of our own service | No longer than 30 days unless a specific incident requires it. Our host keeps its own operational logs under its own retention policy |
| Preferences Your light/dark choice and your opt-outs |
To keep the site as you set it | PECR exceptions — see section 4. No separate Article 6 basis is needed beyond Article 6(1)(f) for honouring your own settings | 12 months, or until you clear it |
Where we rely on legitimate interests
Article 6(1)(f) requires us to balance our interest against your rights. Our interest is in replying to people who contact us, keeping the site online, and keeping honest records. The data involved is business contact detail and technical log data, it is not sensitive, and it is not used to build a profile of you. We think that balance is straightforward — but you can object at any time under section 9 and we will stop unless we can show compelling grounds not to.
Do you have to give it to us?
No. There is no statutory or contractual requirement to fill in the form. If you leave it blank we simply cannot arrange a call — email or phone us instead.
Special category data
We do not ask for and do not want health, biometric, racial or ethnic origin, political, religious, trade union, sex life or sexual orientation data. Please do not put any of it in the form.
6. Sending data abroad
Some of the suppliers in section 5 are based in the United States, so some of the data described here leaves the UK. That is lawful only with a recognised transfer mechanism behind it, and each one is named below rather than waved at.
| Who | What reaches them | Mechanism |
|---|---|---|
| Vercel Inc. United States |
Everything needed to serve a page — your IP address, browser string and the pages you request | Certified under the UK Extension to the EU–U.S. Data Privacy Framework, with the Standard Contractual Clauses and the UK International Data Transfer Addendum as the fallback in its data processing addendum |
| Calendly LLC United States |
Your name, email and the summary of your answers — but only if you reach the scheduling step | Certified under the UK Extension to the EU–U.S. Data Privacy Framework, with SCCs and the UK Addendum (Module 2) as the fallback in its data processing addendum |
| Google Ireland Limited Ireland, with onward processing by Google LLC in the United States |
Anything you put in an email to us, and our replies | Google LLC is certified under the UK Extension to the EU–U.S. Data Privacy Framework. Google's data processing amendment also incorporates the Standard Contractual Clauses with UK supplementary terms |
| Cloudflare, Inc. United States |
The DNS lookup your browser makes for our domain | Certified under the UK Extension to the EU–U.S. Data Privacy Framework, with SCCs and the UK Addendum as the fallback |
The UK Government has recognised the UK Extension to the Data Privacy Framework as providing an adequate level of protection for transfers to certified US organisations. Where a certification lapses or the framework is withdrawn, each of the addenda above falls back to the Standard Contractual Clauses with the UK Addendum, so a transfer never runs without a mechanism.
If you would rather nothing of yours went to the United States: do not use the scheduling step — email or ring us and we will arrange the call by hand. Hosting and DNS cannot be avoided while you are reading this page, because they are how the page reached you; but nothing beyond ordinary server log data is involved in that.
Our own working records — notes, quotes, the file we keep on an enquiry — are held in the United Kingdom or the European Economic Area.
7. How long we keep it
The retention column in section 3 is the rule. Two things sit outside it:
- Accounting records. Where we have invoiced you, we keep what tax law requires — currently six years from the end of the accounting period.
- Anything under dispute. If there is a live complaint or claim, we keep the relevant records until it is resolved and the limitation period has run out.
When a retention period ends we delete or irreversibly anonymise the data. We review what we are holding at least once a year.
8. When we act for a client
This is the part most policies skip, and it matters. There are two different relationships:
- You contact us about our service. We are the controller. This policy applies in full.
- You ring a business that uses our call handling. That business is the controller of your call and the details you give. We are their processor — we handle the call on their instructions under an Article 28 contract, and we do not use what we hear for our own purposes.
In the second case, ask that business for its privacy notice, and send rights requests to them. If you send one to us, we will pass it on promptly and tell you who we sent it to.
Calls handled on a client's behalf may be recorded and transcribed where that client has set it up and told callers so. The client decides that, not us.
9. Your rights
Under UK GDPR you have the following rights over personal data we hold as controller. They are not absolute — some only apply in particular circumstances, and we will explain plainly if one does not apply to your request.
- Be informed — this document.
- Access — a copy of what we hold about you.
- Rectification — correct anything inaccurate or incomplete.
- Erasure — deletion, where we no longer need it or you successfully object.
- Restrict processing — make us hold it but stop using it while something is checked.
- Data portability — receive the data you gave us in a machine-readable form, where we relied on consent or contract.
- Object — to processing based on legitimate interests, and absolutely to direct marketing.
- Withdraw consent — where we relied on consent, at any time, without affecting what was lawful before.
- Not be subject to solely automated decisions that produce legal or similarly significant effects — see section 12.
How to exercise them
Email matt@vervevista.co.uk and say which right you are using. You do not need a form or a particular wording. We may ask for enough information to be sure who you are, which protects you as much as us.
We respond within one month. If a request is complex or you have made several, we can extend by up to two further months — we will tell you within the first month if that happens, and why. It is free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse and explain why.
10. Complaining
Please raise it with us first — we would rather fix it than have it escalated. But you have the right to go straight to the supervisory authority, and using it does not affect any other remedy.
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint
You may also seek a judicial remedy in the courts.
11. Security
The site is served over HTTPS. Access to enquiry data is limited to people who need it to do their job, accounts are protected with multi-factor authentication, and we choose suppliers who commit to appropriate technical and organisational measures under Article 32.
No system is perfect. If a breach happens that is likely to risk your rights and freedoms, we will tell the ICO within 72 hours of becoming aware, and tell you directly where the risk to you is high.
12. Automated decisions
On this website: none. Nothing you submit here is decided by a machine. A person reads every enquiry.
In the service we sell: our software answers calls, works out what the caller wants and how urgent it is, and books appointments. Those are operational decisions about scheduling — they do not produce legal effects or similarly significant effects for the caller, and a person can always review or override them. Where a client configures anything that could have a significant effect, that client is the controller and must have its own basis and safeguards under Article 22.
13. Children
This site and this service are aimed at businesses. We do not knowingly collect data from anyone under 18 through this website. If you believe a child has sent us personal data, tell us and we will delete it.
14. Changes
When this policy changes we update the version and date at the top. If a change materially affects how we use data you have already given us, we will tell you directly rather than relying on you noticing. Previous versions are available on request.