Approved and effective. Version privacy-2026-08-public-v2.
What works today
The Windows estimate stores anonymous answers in your browser so you can go back or refresh. It does not ask for your name, phone number or email address. Optional analytics remains off until you allow it.
Information used by the current tools
Anonymous journey answers and cookie choices can be stored on your device. If you allow anonymous analytics, limited product-use events may be recorded separately. A privacy request includes only the information you choose to submit through that form. A contact enquiry stores your name, reply email address, category, subject, message and the operational timestamps and status needed to manage it. Replies sent through Admin HQ and their delivery status are retained with the enquiry so Nerovia can manage the conversation and avoid duplicate sending.
This information comes directly from you when you use a form or tool, and from your browser when it stores a preference or anonymous journey identifier. Nerovia does not obtain contact-enquiry information from data brokers.
Why information may be used
To operate decision tools, remember your choices, protect the service, respond to a privacy request or contact enquiry and—only when you allow it—measure anonymous product use. Contact details are not used for marketing merely because you send an enquiry. Future quote matching would require separate wording and recipient information before launch.
Nerovia relies on legitimate interests to operate and secure the service and respond to enquiries a person chooses to send, legal obligations when handling data-protection requests, and consent for optional analytics. Marketing consent is separate and is not inferred from an enquiry.
Information you must provide
The contact and privacy-request forms identify their required fields. A reply email and enough detail to understand the request are necessary to respond and manage the record. You do not have to use either form, but Nerovia cannot respond through that channel if the required information is not supplied. Journey-tool answers are optional and do not require your identity.
Retention
Saved Windows and Dehumidifier Finder answers expire 30 days after their last update and are removed when that tool is next opened; you can clear them sooner through your browser. Contact enquiries are retained while the conversation is active and for 12 months after it is resolved. An unresolved enquiry is flagged for administrator review after 90 days without activity; it is not deleted merely because that review date is reached. Once resolved, it is deleted or appropriately anonymised after the 12-month period. A record may be retained longer only for a documented legal claim or dispute, fraud or security investigation, statutory obligation or another recorded legitimate requirement. The retention policy is reviewed at least annually. Automated execution remains protected by a separate audited kill switch, so overdue records remain subject to controlled review until that execution is expressly enabled.
The core accountability record for a privacy-rights request is retained for three years after Nerovia issues its final response and formally closes the case. If the case is reopened, that countdown is suspended and restarts from the later formal closure. Identity-document copies are not retained for that full period by default: Nerovia prefers verification methods that do not require a copy and deletes any copy promptly once verification and any immediately related need are complete. Additional copies of the information supplied in response are not retained merely to preserve the request audit record. A documented legal, security or dispute hold may apply where genuinely necessary. This three-year period is Nerovia's accountability decision, not a period prescribed by the ICO or UK GDPR, and is reviewed at least annually.
Necessary consent-accountability evidence is retained for 24 months after the consent record expires, is withdrawn or is superseded. Nerovia Admin audit events are retained for 24 months from creation. Nerovia-controlled authentication and security records containing personal information are normally retained for 12 months. Operational or application logs containing personal information are normally retained for 90 days, while security events may be retained for 12 months. A core personal-data breach accountability record is retained for six years after formal closure. These are Nerovia's operational decisions rather than periods prescribed by the ICO or UK GDPR. Supplier-managed records follow verified account settings and applicable terms. Documented, scoped legal, security or dispute holds may delay deletion only while the reason remains valid.
Who is responsible for your information
The controller is Mark Desborough, trading as Nerovia. Business address: 33 Churchill Close, Alderholt, SP6 3BG. Contact: info@nerovia.co.uk.
Your rights
Depending on the circumstances, UK data protection law may provide rights of access, correction, deletion, restriction, objection and portability. Where processing relies on consent, you can withdraw it at any time without affecting earlier lawful processing. Cookie choices can be changed on the Cookies page. Identity checks may be necessary before a request is fulfilled.
Make a privacy requestYou may also complain to the UK Information Commissioner's Office. Nerovia would appreciate the opportunity to address the concern first, but this does not restrict your right to complain. Complain to the ICO.
Sharing and marketing
No buyer or provider delivery is active. Marketing permission is separate and off by default. Contact enquiries are visible only to authorised Nerovia administrators. An optional owner notification contains only a message reference and secure Admin HQ link, not the enquiry content or contact details. A configured transactional email provider receives only the information needed to deliver a reply to you. If provider matching launches, recipient information and the relevant service request choice will be shown at the point of collection.
Current infrastructure suppliers are Vercel for application hosting, Supabase for the database and authentication, Cloudflare for domain, security and inbound email routing, and Resend for transactional email delivery. They process the limited service information needed to provide those services on Nerovia's instructions. Their applicable terms may also permit limited processing for their own account, billing, fraud-prevention, security, abuse-prevention or legal-compliance purposes.
International transfers
Some infrastructure suppliers process or may access information outside the United Kingdom. Nerovia reviews whether each data flow is a restricted transfer. Where it is, Nerovia must rely on an applicable UK adequacy regulation, an appropriate safeguard such as an applicable UK International Data Transfer Agreement or UK Addendum, or another lawful basis, and retain evidence of the basis used. Account-specific supplier terms, locations and safeguards are recorded in the internal transfer register and must be rechecked before broader personal-data processing is activated.
Automated decisions
Nerovia does not use automated decision-making that produces legal or similarly significant effects. Current tools provide guidance based on the answers you choose; you decide whether and how to act on that guidance.
Changes to this notice
Material changes are published as a new version with an updated effective date. Historic notice versions are retained for audit purposes. A new commercial or personal-data service will not rely on this notice unless its processing is accurately described first.
Contact
Privacy questions can be sent to info@nerovia.co.uk.