ZURVIQOSITE

Privacy Policy

Effective date: 2 October 2026. Last updated: 30 September 2026.

This Privacy Policy explains how R200R Solutions Ltd uses personal data when people visit zurviqo.com, create or use a Zurviqo account, subscribe to or use the Zurviqo construction quality-control and defect-recording service, receive an invitation, contact us or otherwise interact with our business.

Zurviqo is designed for business use. Business customers may add information about other people to Project records. This Policy explains both when R200R acts as controller and when it processes Project personal data on a business customer's instructions.

1. Who we are and how to contact us

R200R Solutions Ltd is a company incorporated in England and Wales with company number 17403920 and registered office at Spencer House, 114 High Street, Wordsley, Stourbridge, West Midlands, United Kingdom, DY8 5QR.

For privacy questions, rights requests or complaints, contact [email protected] or write to our registered office address above. Our privacy contact is the Director. Our ICO registration number is ZC178568.

2. When we act as controller and processor

2.1 We act as controller when we decide why and how to use personal data for account administration, subscriptions, operation and security of Zurviqo, support, service communications, business administration, legal compliance and our own business marketing.

2.2 A business customer may use Zurviqo to record and manage information about properties, residents, employees, subcontractors, clients and other Project participants. Where the customer decides why and how that Project personal data is processed and we handle it only to provide Zurviqo on its documented instructions, the customer is controller and we act as processor.

2.3 If your concern relates to Project information controlled by an organisation, you should normally contact that organisation first. We will assist it as required by law and our contract. We remain controller for our own account, security, support, billing and business records relating to you.

3. Personal data we collect

Depending on how Zurviqo is used, we may collect:

  • identity and account data, including name, job title, employer, username, account identifier and profile information;
  • contact data, including email address, telephone number, business address and invitation details;
  • subscription and transaction data, including plan, billing status, purchase history, tax information and limited payment identifiers; payment providers normally retain full card details;
  • Project and user content, including property addresses, unit or plot numbers, photographs, videos, plans, inspection notes, defect records, comments, task assignments, dates, signatures, Reports and uploaded documents;
  • information about property owners, residents, occupants, workers, subcontractors, clients and other people included in Project content;
  • voice input and transcription data when a user chooses speech-to-text for defect entry;
  • device and technical data, including device type, operating system, app version, IP address, identifiers, language, time zone, network information, notification tokens and security logs;
  • usage data needed to operate and secure the Service, including features used, actions, timestamps, session information and performance information;
  • communications, including support requests, feedback, complaints and messages; and
  • business-contact and marketing data, including name, role, employer, professional contact details, source, outreach history and opt-out status.

Zurviqo does not currently request GPS or other location data and does not use non-essential analytics, crash reporting, AI training, image recognition, automated suggestions, automated categorisation, ratings or cost estimates. Speech-to-text is used for transcription only and does not analyse or make decisions about defects.

4. How we obtain personal data

We obtain personal data directly from users; from administrators, customers and other users who create access, send invitations or add Project content; automatically from the app, website and device when Zurviqo is used; from Stripe, RevenueCat, Apple, Google and other payment or subscription services; and from service providers where necessary to deliver and protect the Service.

For business outreach, we may obtain professional contact details from company websites, business directories, professional networking services, referrals and other lawful business sources.

5. How and why we use personal data

Providing and administering Zurviqo

We create and authenticate accounts, manage organisation permissions, provide Projects and Reports, transcribe voice input at the user's request, process subscriptions, sync information, provide support and send essential service messages. Our lawful basis is normally contract or steps requested before contract. For people using Zurviqo for an organisation, it may be our legitimate interests and those of the organisation in providing and administering the Service.

Processing Project content for customers

Where we act as processor, we process Project personal data on the documented instructions of the relevant business customer. That customer determines its lawful basis. We separately process limited account, support, security and billing information as controller for our own purposes.

Payments accounting and fraud prevention

We manage web and, if introduced, app-store purchases; verify subscription entitlement; prevent payment abuse; maintain records; and meet tax and accounting obligations. Our bases are contract, legal obligation and our legitimate interests in receiving payment and keeping accurate records.

Security support and service improvement

We authenticate users, keep appropriate logs, investigate misuse, respond to support requests, maintain the Service and improve usability using necessary operational information. Our bases are contract, legal obligation and our legitimate interests in operating a safe and reliable service. We do not currently use non-essential analytics or identifiable Project content for AI training or benchmarking.

Business outreach and marketing

We may contact named businesspeople at UK construction, fit-out, structural, design and other built-environment firms to introduce Zurviqo and manage those contacts in a business-contact database or customer relationship management system, including HubSpot if implemented. We rely on legitimate interests where appropriate and send electronic marketing only where permitted by law. We identify ourselves, provide a clear way to opt out and keep a limited suppression record to respect an objection. You may object to direct marketing at any time.

Legal and corporate purposes

We comply with law and regulatory requests, handle complaints, obtain professional advice, establish or defend legal claims, and manage a financing, reorganisation, sale or acquisition. Our bases are legal obligation and our legitimate interests in protecting and managing our business.

6. Invitations and information about other people

If a customer or user provides your details to invite you to a Project, we may receive your name, email address, organisation, role, the inviter's identity and relevant Project information. We use it to send and manage the invitation, protect the Service and create access if you accept. Our basis is normally our legitimate interests and those of the inviter or customer in collaborating on the Project.

A person who provides information about someone else must have authority and a lawful basis to do so, give any privacy information required by law and share only what is necessary.

7. Sensitive information

Zurviqo is not designed to require special-category data, criminal-offence data, access codes or other highly sensitive information. Such information may appear incidentally in photographs, correspondence or Project notes. Customers and users must minimise it and ensure that any processing is lawful and appropriately protected.

8. Who receives personal data

We disclose personal data only where necessary, including to organisation administrators, Project owners and authorised participants and to the following principal suppliers:

  • Supabase for database, authentication, storage and backend infrastructure, currently using its EU West region in Dublin;
  • Stripe for web payment processing and related fraud prevention;
  • RevenueCat for subscription and entitlement management;
  • Cloudflare for website hosting, content delivery and security;
  • Resend for transactional email;
  • Google through Firebase Cloud Messaging and Apple through Apple Push Notification service for push notifications;
  • Apple and Google for app distribution, platform services and any app-store purchase or subscription introduced; and
  • HubSpot if implemented for management of business contacts and outreach.

We may also disclose information to professional advisers, insurers, auditors, regulators, courts, law-enforcement bodies, public authorities and a genuine prospective buyer, investor or successor. Some recipients act as our processors; others, including payment platforms and app stores in some circumstances, may act as independent controllers under their own privacy notices.

9. International transfers

Supabase hosting is currently configured in Dublin, Ireland. Some suppliers or their subprocessors may process personal data outside the United Kingdom. Where UK restricted-transfer rules apply, we use a lawful transfer mechanism where required, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any required safeguards. Information about relevant safeguards may be requested using the contact details in clause 1.

10. Retention and deletion

We retain personal data only for as long as reasonably necessary for the relevant contractual, operational, security, legal, accounting and dispute-resolution purpose.

  • Account and Project data is retained while the subscription is active. If a subscription ends without the company account Owner choosing account deletion, data may remain available on a read-only basis for 90 days to allow access or export before deletion from live systems is scheduled.
  • The Owner may instead use the in-app process to schedule company account deletion after a cancellable 30-day read-only period or delete the company account immediately. These routes take effect on their own timetable and override the ordinary 90-day period after subscription cancellation. Clause 17 explains the process.
  • At the point of permanent deletion, Account and Project data is removed from our live systems, subject to lawful retention of separate records. We make reasonable efforts to delete associated stored files and records held by service providers at the same time, in accordance with applicable data-protection obligations.
  • Residual copies may persist for a limited period in routine system backups before being automatically overwritten in accordance with our hosting provider's standard backup retention cycle. Deleted backup data is put beyond ordinary use.
  • Payment, tax, accounting, support, security and legal-claim records are retained only for the period required by law or reasonably necessary for a lawful purpose.
  • Sign-off, quality-control, compliance, handover and building-history records are not exempt from data-protection law. Personal data in a separate retained record may be kept after account closure only where continued retention is necessary and lawful, including to comply with a legal obligation or establish, exercise or defend legal claims. A business customer or other recipient may separately retain a lawful copy of a Report or Project record under its own retention arrangements.
  • A limited marketing suppression record may be retained to respect an opt-out.

An account-deletion option does not replace or restrict your statutory right to request erasure. We deal with such requests under clause 12 and applicable data-protection law. Where another organisation controls Project personal data, we act on its lawful instructions and assist it as required.

11. Security

We use appropriate technical and organisational measures designed to protect personal data, including access controls and measures intended to preserve confidentiality, integrity, availability and resilience. No online service is completely secure. Users must protect their credentials and devices and report suspected unauthorised access promptly to [email protected].

12. Your rights

Depending on the circumstances, you may have rights to access and correct your personal data; request erasure or restriction; object to processing based on legitimate interests and to direct marketing; receive certain data in a portable format; withdraw consent where processing relies on consent; and complain to us or the Information Commissioner's Office.

To exercise a right, contact [email protected]. We may need information to verify your identity and locate the records. We normally respond within one month, subject to lawful extensions and exceptions. Where another organisation controls the relevant Project content, we may refer the request to that organisation or assist it in responding.

13. Data protection complaints

Send a data-protection complaint to [email protected] with enough information for us to understand the concern. We will acknowledge it within 30 days, make appropriate enquiries, keep you informed where needed and tell you the outcome without undue delay.

You may complain to the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or by post at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You are not required to contact us before approaching the ICO.

14. Automated decisions and artificial intelligence

Zurviqo does not currently use AI, image recognition, automated suggestions, categorisation, ratings or cost estimates and does not make solely automated decisions about individuals that produce legal or similarly significant effects. Speech-to-text transcribes voice input but does not analyse defects, assess compliance or make decisions.

15. Children

Zurviqo is intended for business users aged 18 or over. You must be at least 18 to create a Zurviqo account. The Service is not directed to children. Contact us if you believe a child's personal data has been provided contrary to this Policy.

16. App permissions cookies and similar technologies

The app may request access to the camera, photo library, files, microphone and notifications when needed for a feature selected by the user. It does not currently request GPS or other location access. Push notifications are delivered through Firebase Cloud Messaging for Android and Apple Push Notification service for iOS.

Zurviqo may use necessary cookies, software development kits, local storage and similar technologies for authentication, preferences, security, subscription management and operation. It does not currently use non-essential analytics, advertising tracking or crash-reporting tools. If those practices change, we will update the relevant notice and obtain consent where required.

17. Account deletion

Deleting a company account

The company account Owner can use the in-app self-service process to schedule deletion or delete the company account immediately. The Owner should export any records the business wishes to retain before permanent deletion takes effect.

Scheduled deletion makes the company account read-only for 30 days from scheduling. The Owner may cancel it at any point before that period ends, restoring normal account access subject to the applicable subscription and permissions. If it is not cancelled, the company account is permanently deleted at the end of the 30 days. Immediate deletion takes effect straight away and cannot be reversed.

Deleting a Team member login

A Team member can delete their own individual login through the in-app process. This deletion is always immediate. It does not delete the company account or its Project data and has no effect on the company subscription. Personal data about that person in Project content or other lawfully retained records is addressed separately under clauses 10 and 12.

Data backups and billing

Account and Project data is removed from live systems when permanent deletion takes effect, subject to lawful retention of separate records. Associated stored files, service-provider records and residual backup copies are dealt with as explained in clause 10. Account deletion does not automatically remove lawful copies separately held by a business customer or another recipient.

For website subscriptions paid through Stripe, scheduled deletion stops renewal at the end of the current billing period; cancelling scheduled deletion within the 30-day period restores normal renewal. Any subscription still active at the end of that period is cancelled on permanent deletion. Immediate company account deletion cancels the website subscription straight away.

An Apple App Store or Google Play subscription must be cancelled separately in the relevant platform account settings. Scheduling or completing account deletion does not cancel it. Account deletion does not automatically generate a refund or credit for unused paid time. The Terms of Service explain the billing and refund arrangements, subject to applicable law.

For help with the account-deletion process, contact [email protected]. For a request to exercise a data-protection right, contact [email protected]. You do not need to use an account-deletion option to exercise your statutory rights.

18. Changes to this Policy

We may update this Policy to reflect changes in law, Zurviqo or our processing. We will post the current version at zurviqo.com/privacy, change the last-updated date and provide additional notice where a change is material or consent is required.

R200R Solutions Ltd · [email protected] · Privacy Policy