TruV Group Limited
Last updated: 30/06/2026
TruV Group Limited (“TruV”, “we”, “us” or “our”) respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, share, store and protect personal data when you interact with us, visit our website, communicate with us, or use our software-as-a-service products and related services.
This Privacy Policy is intended to apply generally across the industries and sectors in which we operate. Where we provide software or services to a customer organisation, that customer may also provide its own privacy notice explaining how it uses personal data within its own business processes.
Who we are
TruV Group Limited is a company registered in England and Wales. For the purposes of this Privacy Policy, our contact details are:
Please mark data protection enquiries for the attention of the Data Protection Lead.
Scope of this Privacy Policy
This Privacy Policy applies to personal data processed by TruV Group Limited in connection with our website, business communications, sales and marketing activity, customer administration, support services, product usage, security operations and the delivery of our SaaS products and services.
This Privacy Policy does not replace the privacy notice of any customer organisation that uses our products or services. Where our customer determines why and how personal data is processed within our platform, the customer is normally the data controller and TruV Group Limited acts as a data processor. In those circumstances, we process personal data in accordance with the customer’s documented instructions, our contract with that customer and applicable data protection law.
Types of personal data we may collect
The personal data we collect depends on your relationship with us and how you interact with our website, products and services. We may collect the following categories of personal data:
Special category and sensitive personal data
We do not intentionally collect special category data through our website or general business communications unless it is provided to us voluntarily or is necessary for a specific service, enquiry or legal obligation.
Where our SaaS products are configured by a customer to process special category data, criminal offence data or other sensitive information, the customer is normally responsible for determining the lawful basis and any additional condition for processing. TruV Group Limited processes that data as a processor and only in accordance with the customer’s documented instructions, unless we are legally required to do otherwise.
How we collect personal data
We may collect personal data directly from you when you contact us, request information, register for services, use our products, submit a support request, attend a meeting or event, or otherwise communicate with us. We may also collect data automatically through our website, applications, cookies, similar technologies, system logs and product usage analytics.
We may also receive personal data from customer organisations, business partners, professional advisers, public sources, analytics providers, identity or security providers, and other third parties where this is lawful and relevant to our business activities or the services we provide.
How we use personal data and our lawful bases
We only use personal data where we have a lawful basis to do so under applicable data protection law. Below, we have provided information that summarises the main purposes for which we use personal data and the lawful bases we commonly rely on:
Purpose: Responding to enquiries and communications:
Purpose: Providing, administering and supporting our SaaS products and services:
Purpose: Managing customer relationships, contracts, billing and service administration:
Purpose: Improving, maintaining and developing our products and services:
Purpose: Security, fraud prevention, audit logging and service monitoring:
Purpose: Marketing and business development:
Purpose: Complying with legal, regulatory, audit and governance obligations:
Purpose: Business operations, reporting and management information:
Where we rely on legitimate interests, we balance our interests against your rights, freedoms and expectations. You have the right to object to processing based on legitimate interests in certain circumstances, including an absolute right to object to direct marketing.
Customer controlled platform data
Our customers may use our SaaS products to process personal data relating to their own users, employees, applicants, contractors, suppliers, service users or other individuals. The categories of data processed in the platform will depend on the customer’s configuration and use case.
Where we act as processor, the customer is responsible for providing appropriate privacy information to individuals, identifying the lawful basis for processing, managing individual rights requests and determining retention requirements. TruV Group Limited provides the platform and related services in accordance with the customer’s instructions, relevant contract terms and applicable data protection law.
Cookies and similar technologies
We use cookies and similar technologies on our website and, where relevant, within our products. These technologies may help us operate our website, remember preferences, understand performance, analyse traffic, improve services and support security.
Strictly necessary cookies and similar technologies are required for the operation of our website or services and do not usually require consent. For analytics, advertising, tracking or other non-essential technologies, we will seek consent where required by law. You can manage cookies through your browser settings and, where available, through our cookie banner.
Further details about the specific cookies and similar technologies we use are provided in our Cookie Policy.
Marketing communications
We may send marketing communications about our products, services, events or updates where permitted by law. This may be based on your consent or, in some business-to-business contexts, our legitimate interests, subject to applicable direct marketing and electronic communications rules.
You can opt out of marketing communications at any time by using the unsubscribe option in our emails or by contacting us at info@truvgroup.co.uk. We may still send service, security, legal or account-related communications where these are not marketing communications.
Sharing personal data
We do not sell personal data. We may share personal data where necessary and lawful with the following categories of recipients shown in the following format recipient category - purpose:
International transfers
We aim to use service providers and hosting arrangements that support appropriate data protection safeguards. Where personal data is transferred outside the United Kingdom, we will ensure that appropriate safeguards are in place. These may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism.
Where we act as processor for a customer, international transfer arrangements may also be governed by the relevant customer contract, data processing agreement or other documented instructions.
Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide services, meet legal, regulatory, contractual, audit, accounting and reporting requirements, resolve disputes, maintain security and enforce agreements. Retention periods may vary depending on the type of data, the relationship we have with you and the legal or contractual context. We have provided some examples below in the following format data type: typical retention period:
When personal data is no longer required, we will delete, anonymise or securely archive it in accordance with our retention procedures and applicable contractual or legal obligations.
Data security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures may include encryption, access controls, authentication controls, audit logging, monitoring, vulnerability management, backup processes, staff awareness, supplier due diligence and incident response procedures.
No system or transmission method is completely secure. We will take reasonable and proportionate steps to protect personal data and to maintain the confidentiality, integrity and availability of our systems and services.
Automated decision making and AI-assisted functionality
Our products and services may include automation, analytics or AI-assisted functionality designed to support workflow efficiency, reporting, configuration, recommendations or decision support. Unless we clearly state otherwise, TruV Group Limited does not promote the use of personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.
Where a customer uses our products in a way that involves automated processing or AI-assisted functionality, the customer remains responsible for determining how those features are used within its own processes and for providing any required privacy information to affected individuals. TruV Group Limited designs such functionality to support human review and operational decision-making (human in the loop), not to remove appropriate human oversight where it is required.
Your data protection rights
Depending on the circumstances and the lawful basis for processing, you may have the following rights under UK data protection law:
These rights are not absolute and may not apply in every case. Where we act as processor for a customer, we may need to refer your request to the relevant customer because they are responsible for deciding how the request should be handled.
How to exercise your rights
To exercise your data protection rights, please contact us at info@truvgroup.co.uk. We may need to verify your identity before responding to your request. We will respond to valid requests within the timeframe required by applicable law, usually within one month, unless an extension is permitted.
If your request relates to personal data processed by one of our customers using our SaaS products, you should normally contact that customer directly. We will assist our customers with rights requests in accordance with our contractual and legal obligations.
Data protection complaints
If you have a concern about how we process personal data, please contact us first at info@truvgroup.co.ukand mark your message for the attention of the Data Protection Lead. We will provide a clear route for raising a data protection complaint, acknowledge complaints within the required timeframe, investigate appropriately and communicate the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection matters. The ICO can be contacted through its website at www.ico.org.uk or by telephone on 0303 123 1113.
Links to other websites
Our website, products or communications may contain links to third-party websites, applications or services. We are not responsible for the privacy practices, content or security of third-party websites or services. We encourage you to read the privacy information provided by those third parties.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, services, technology, legal requirements or data protection practices. When we update this Privacy Policy, we will amend the “Last updated” date at the top of this document. Where changes are significant, we may take additional steps to bring them to your attention.
Contact us
For questions about this Privacy Policy, data protection rights, privacy concerns or complaints, please contact:
Please ensure to mark all correspondence for the attention of the Data Protection Lead