Skip to content
Trelyvo

Privacy

This notice explains how Trelyvo handles personal data in the product and on this website. It is a draft: company and supplier details are completed before launch.

Draft — not yet in force

1.Controller

The controller is To be added: legal company name, business ID To be added: business ID, address To be added: address.

Privacy enquiries: To be added: privacy email.

2.Our role in the processing

The product is used by a service business — for example a painting or remodeling company. When an end customer submits an inquiry on that company's website, the data is processed on that company's behalf. In that situation the customer's business is the controller and Trelyvo acts as a processor.

For visitors to our own website and for people who contact us directly, we act as the controller.

3.What data is processed

An inquiry may involve the following data:

  • contact details: name, email address and phone number
  • project details: property type, location or postal code, size and the work requested
  • photos and free-text descriptions added by the customer
  • handling metadata such as status and timestamps

4.Purpose and legal basis

Data is processed in order to receive the inquiry, prepare an estimate and communicate with the customer. The legal basis is the preparation and performance of a contract, together with the legitimate interest of responding to inbound enquiries.

Data is not used for automated decision-making that produces legal effects. A person at the business always approves anything binding.

5.Recipients and subprocessors

Inquiry data is available to the business the inquiry was addressed to. It is not sold and it is not shared for marketing purposes.

Technical suppliers such as hosting and email providers are used to operate the service. The list of those suppliers is published in this notice before the service goes live.

6.Retention

Data is kept for as long as it is needed to handle the inquiry, maintain the customer relationship and meet statutory obligations. Exact retention periods are defined before launch and will be configurable per business.

7.Security

Access is limited to people whose role requires it. We use technical and organisational safeguards such as access control and encrypted connections.

We do not claim certifications or audits we have not completed. Once the service is in production this section will describe the safeguards in concrete terms.

8.Your rights

Under the GDPR a data subject has the right to:

  • access their own data
  • have inaccurate data corrected
  • have data erased where there is no longer a basis for processing
  • restrict and object to processing
  • receive their data in a portable format where processing is based on a contract

9.Right to lodge a complaint

A data subject has the right to lodge a complaint with a supervisory authority. In Finland this is the Office of the Data Protection Ombudsman.

10.Cookies

We use only cookies necessary for the operation of the website unless stated otherwise in this section. Any analytics and the consent mechanism for it will be described here precisely before it is introduced.

11.Changes to this notice

We update this notice when the product or our processing changes. The version in force is always available on this page.