TruVerify Group Site
TruVerify Group Site

Privacy Policy

TruV Group Limited

Last updated: 30/06/2026


  

TruV Group Limited (“TruV”, “we”, “us” or “our”) respects your privacy and is committed to protecting personal data.   This Privacy Policy explains how we collect, use, share, store and protect personal data when you interact with us, visit our website, communicate with us, or use our software-as-a-service products and related services.


This Privacy Policy is intended to apply generally across the industries and sectors in which we operate.   Where we provide software or services to a customer organisation, that customer may also provide its own privacy notice explaining how it uses personal data within its own business processes.


Who we are


TruV Group Limited is a company registered in England and Wales. For the purposes of this Privacy Policy, our contact details are:

  • Email: info@truvgroup.co.uk 
  • Correspondence address: Challenge House, Sherwood Drive, Milton Keynes, United Kingdom, MK3 6DP. 


Please mark data protection enquiries for the attention of the Data Protection Lead.


Scope of this Privacy Policy


This Privacy Policy applies to personal data processed by TruV Group Limited in connection with our website, business communications, sales and marketing activity, customer administration, support services, product usage, security operations and the delivery of our SaaS products and services.


This Privacy Policy does not replace the privacy notice of any customer organisation that uses our products or services. Where our customer determines why and how personal data is processed within our platform, the customer is normally the data controller and TruV Group Limited acts as a data processor. In those circumstances, we process personal data in accordance with the customer’s documented instructions, our contract with that customer and applicable data protection law.


Types of personal data we may collect


The personal data we collect depends on your relationship with us and how you interact with our website, products and services.   We may collect the following categories of personal data:

  • Contact and business details: Name, work email address, telephone number, job title,   organisation name, department and business address.
  • Account and user details: Username, user ID, authentication information, role or   permission profile, account status and support preferences.
  • Communications data: Enquiries, emails, support requests, meeting notes, feedback,   survey responses and other correspondence.
  • Technical and device data: IP address, browser type, device type, operating system, time   zone setting, log-in information, usage timestamps, system logs and diagnostic information.
  • Product usage data: Information about how authorised users interact with our SaaS   products, including features accessed, activity patterns, configuration choices, audit events and performance data.
  • Commercial and contract data: Information relating to proposals, contracts, subscriptions,   orders, billing, payment status, service levels and customer relationship management.
  • Marketing preferences: Preferences about receiving communications from us, event   attendance, consent records and unsubscribe or opt out choices.
  • Customer controlled platform data: Personal data that our customers choose to input, upload, configure or process through our SaaS products. The exact categories depend on the customer’s use case and configuration.


Special category and sensitive personal data


We do not intentionally collect special category data through our website or general business communications unless it is provided to us voluntarily or is necessary for a specific service, enquiry or legal obligation.


Where our SaaS products are configured by a customer to process special category data, criminal offence data or other sensitive information, the customer is normally responsible for determining the lawful basis and any additional condition for processing.   TruV Group Limited processes that data as a processor and only in accordance with the customer’s documented instructions, unless we are legally required to do otherwise.


How we collect personal data


We may collect personal data directly from you when you contact us, request information, register for services, use our products, submit a support request, attend a meeting or event, or otherwise communicate with us.   We may also collect data automatically through our website, applications, cookies, similar technologies, system logs and product usage analytics.


We may also receive personal data from customer organisations, business partners, professional advisers, public sources, analytics providers, identity or security providers, and other third parties where this is lawful and relevant to our business activities or the services we provide.


How we use personal data and our lawful bases


We only use personal data where we have a lawful basis to do so under applicable data protection law.   Below, we have provided information that summarises the main purposes for which we use personal data and the lawful bases we commonly rely on:

 

Purpose: Responding to enquiries and communications:

  • Data Types: Contact details, business details and communications data
  • Lawful Basis: Legitimate interests in responding to enquiries and managing business communications; pre-contract steps where the enquiry relates to a potential contract.

 

Purpose: Providing, administering and supporting our SaaS products and services:

  • Data Types: Account data, user data, product usage data, customer-controlled platform data and support records
  • Lawful Basis: Performance of a contract with our customer; legitimate interests in delivering and supporting our services; legal obligation where applicable.

 

Purpose: Managing customer relationships, contracts, billing and service administration:

  • Data Types: Commercial, contract, billing and contact data
  • Lawful Basis: Performance of a contract; legitimate interests in managing our business and customer relationships; legal obligation for accounting and tax records.

 

Purpose: Improving, maintaining and developing our products and services:

  • Data Types: Product usage data, technical data, feedback and aggregated analytics
  • Lawful Basis: Legitimate interests in improving product functionality, performance, reliability and user experience.

 

Purpose: Security, fraud prevention, audit logging and service monitoring:

  • Data Types: Technical data, account data, audit logs, security events and access records
  • Lawful Basis: Legitimate interests in protecting our systems, users, customers and services; legal obligation where applicable.

 

Purpose: Marketing and business development:

  • Data Types: Contact details, business details, marketing preferences and engagement data
  • Lawful Basis: Consent where required; legitimate interests for certain business-to-business communications where permitted by law; compliance with direct marketing and electronic communications rules.

 

Purpose: Complying with legal, regulatory, audit and governance obligations:

  • Data Types: Relevant records depending on the obligation
  • Lawful Basis: Legal obligation; legitimate interests in establishing, exercising or defending legal rights.

 

Purpose: Business operations, reporting and management information:

  • Data Types: Commercial records, usage data, aggregated data and customer relationship data
  • Lawful Basis: Legitimate interests in operating, managing and improving our business.


Where we rely on legitimate interests, we balance our interests against your rights, freedoms and expectations.   You have the right to object to processing based on legitimate interests in certain circumstances, including an absolute right to object to direct marketing.


Customer controlled platform data


Our customers may use our SaaS products to process personal data relating to their own users, employees, applicants, contractors, suppliers, service users or other individuals.   The categories of data processed in the platform will depend on the customer’s configuration and use case.


Where we act as processor, the customer is responsible for providing appropriate privacy information to individuals, identifying the lawful basis for processing, managing individual rights requests and determining retention requirements.   TruV Group Limited provides the platform and related services in accordance with the customer’s instructions, relevant contract terms and applicable data protection law.


Cookies and similar technologies


We use cookies and similar technologies on our website and, where relevant, within our products. These technologies may help us operate our website, remember preferences, understand performance, analyse traffic, improve services and support security.


Strictly necessary cookies and similar technologies are required for the operation of our website or services and do not usually require consent.   For analytics, advertising, tracking or other non-essential technologies, we will seek consent where required by law.   You can manage cookies through your browser settings and, where available, through our cookie banner.


Further details about the specific cookies and similar technologies we use are provided in our Cookie Policy.


Marketing communications


We may send marketing communications about our products, services, events or updates where permitted by law.   This may be based on your consent or, in some business-to-business contexts, our legitimate interests, subject to applicable direct marketing and electronic communications rules.


You can opt out of marketing communications at any time by using the unsubscribe option in our emails or by contacting us at info@truvgroup.co.uk.    We may still send service, security, legal or account-related communications where these are not marketing communications.


Sharing personal data


We do not sell personal data.   We may share personal data where necessary and lawful with the following categories of recipients shown in the following format recipient category - purpose:

 

  • Cloud hosting and infrastructure providers - To host, operate, secure and maintain our website, systems and SaaS products.
  • IT, security and support providers - To provide technical support, monitoring, security tooling, issue management and service administration.
  • Analytics and performance providers - To understand website and product performance, subject to cookie and consent requirements where applicable.
  • Identity, verification or integration providers - Where a product feature, customer configuration or service requirement involves identity checking, verification, integrations or related services.
  • Payment, finance and professional advisers - To manage billing, accounting, audit, legal advice, insurance, compliance and business administration.
  • Customer organisations - Where we provide services to a customer, administer user access, handle support requests or act on the customer’s instructions.
  • Regulators, law enforcement, courts or public authorities - Where required by law, regulation, court order or lawful   request, or where necessary to protect legal rights or security.
  • Prospective buyers, investors or corporate advisers - Where necessary in connection with a business reorganisation, investment, merger, acquisition, sale or due diligence process, subject to appropriate confidentiality safeguards.


International transfers


We aim to use service providers and hosting arrangements that support appropriate data protection safeguards. Where personal data is transferred outside the United Kingdom, we will ensure that appropriate safeguards are in place. These may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism.


Where we act as processor for a customer, international transfer arrangements may also be governed by the relevant customer contract, data processing agreement or other documented instructions.


Data retention


We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide services, meet legal, regulatory, contractual, audit, accounting and reporting requirements, resolve disputes, maintain security and enforce agreements. Retention periods may vary depending on the type of data, the relationship we have with you and the legal or contractual context.  We have provided some examples below in the following format data type: typical retention period:


  • Website enquiries and general correspondence: Usually up to 24 months after the last meaningful interaction, unless a longer period is needed for legal, contractual or business purposes.
  • Customer account, contract and billing records: For the duration of the customer relationship and normally up to 6 years after the relationship ends, unless a longer period is required by law or contract.
  • Support records and service desk communications: For the duration needed to provide support, maintain service history and meet contractual obligations; normally up to 6 years where linked to service delivery or contractual records.
  • Security logs, access logs and audit records: For a period appropriate to security, audit, legal and contractual requirements. Specific periods may vary by system, customer requirement and risk profile.
  • Marketing records and preferences: Until you unsubscribe, withdraw consent or object to marketing, subject to maintaining a suppression record to ensure we respect your preferences.
  • Customer-controlled platform data: As determined by the relevant customer and our contract with that customer. Where we act as processor, we retain or delete data in accordance with the customer’s documented instructions.
  • Legal, regulatory, dispute and compliance records: For as long as necessary to comply with legal obligations or establish, exercise or defend legal rights.


When personal data is no longer required, we will delete, anonymise or securely archive it in accordance with our retention procedures and applicable contractual or legal obligations.


Data security


We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.   These measures may include encryption, access controls, authentication controls, audit logging, monitoring, vulnerability management, backup processes, staff awareness, supplier due diligence and incident response procedures.


No system or transmission method is completely secure.   We will take reasonable and proportionate steps to protect personal data and to maintain the confidentiality, integrity and availability of our systems and services.


Automated decision making and AI-assisted functionality


Our products and services may include automation, analytics or AI-assisted functionality designed to support workflow efficiency, reporting, configuration, recommendations or decision support. Unless we clearly state otherwise, TruV Group Limited does not promote the use of  personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.


Where a customer uses our products in a way that involves automated processing or AI-assisted functionality, the customer remains responsible for determining how those features are used within its own processes and for providing any required privacy information to affected individuals. TruV Group Limited designs such functionality to support human review and operational decision-making (human in the loop), not to remove appropriate human oversight where it is required.


Your data protection rights


Depending on the circumstances and the lawful basis for processing, you may have the following rights under UK data protection law:

  • Right of access - to request a copy of the personal data we hold about you.
  • Right to rectification- to ask us to correct inaccurate or incomplete personal data.
  • Right to erasure - to ask us to delete personal data in certain circumstances.
  • Right to restriction - to ask us to restrict the way we use personal data in certain circumstances.
  • Right to data portability- to receive certain personal data in a structured, commonly used and machine-readable format.
  • Right to object - to object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent- where we rely on consent, you may withdraw that consent at any time.
  • Right not to be subject to solely automated decision-making - in circumstances where this right applies.


These rights are not absolute and may not apply in every case.   Where we act as processor for a customer, we may need to refer your request to the relevant customer because they are responsible for deciding how the request should be handled.


How to exercise your rights


To exercise your data protection rights, please contact us at info@truvgroup.co.uk.   We may need to verify your identity before responding to your request. We will respond to valid requests within the timeframe required by applicable law, usually within one month, unless an extension is permitted.


If your request relates to personal data processed by one of our customers using our SaaS products, you should normally contact that customer directly.   We will assist our customers with rights requests in accordance with our contractual and legal obligations.


Data protection complaints


If you have a concern about how we process personal data, please contact us first at info@truvgroup.co.ukand mark your message for the attention of the Data Protection Lead.   We will provide a clear route for raising a data protection complaint, acknowledge complaints within the required timeframe, investigate appropriately and communicate the outcome without undue delay.


You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection matters.   The ICO can be contacted through its website at www.ico.org.uk or by telephone on 0303 123 1113.


Links to other websites


Our website, products or communications may contain links to third-party websites, applications or services.   We are not responsible for the privacy practices, content or security of third-party websites or services.   We encourage you to read the privacy information provided by those third parties.


Changes to this Privacy Policy


We may update this Privacy Policy from time to time to reflect changes in our business, services, technology, legal requirements or data protection practices.   When we update this Privacy Policy, we will amend the “Last updated” date at the top of this document.   Where changes are significant, we may take additional steps to bring them to your attention.


Contact us


For questions about this Privacy Policy, data protection rights, privacy concerns or complaints, please contact:

  • Email: info@truvgroup.co.uk 
  • Correspondence address:Challenge House, Sherwood Drive, Milton Keynes, United Kingdom, MK3 6DP


Please ensure to mark all correspondence for the attention of the Data Protection Lead

Copyright © 2026 TruV Group Limited - All Rights Reserved.

Powered by

  • Privacy Policy

This website uses cookies.

We use cookies to make our website work properly, improve user experience and understand how visitors use our site. You can accept or decline these cookies.

DeclineAccept