arrow_back Back to Overview

Privacy Policy

Last updated: 20 June 2026

1. Who We Are and Our Role

Sprevi ("we", "us", "our") is a data processor. When you connect your business mailbox to Sprevi, you (the business owner) are the data controller — you determine why and how your enquirers' personal data is processed. We process that data only on your instructions, only to provide the Service, and only for as long as you have an active account.

If your enquirers wish to exercise their rights over their personal data (erasure, access, portability), those requests should be directed to you as the data controller. You can fulfil deletion requests using the "Delete all data for this contact" action in your Contacts view, or by requesting full account deletion from us.

We are registered with the Information Commissioner's Office (ICO) as a data processor. Our registration number will be displayed here once issued.

2. What Data We Process and Why

We process the following categories of data, under the legal basis of contract performance (processing necessary to provide the Service you have contracted for):

  • Account Data: Your name, business email address, and authentication credentials (hashed or secured via OAuth). Used to authenticate you and maintain your account.
  • Mailbox Credentials: IMAP passwords or OAuth tokens for your connected email account. Stored encrypted (AES-256-GCM). Used solely to import enquiry messages.
  • Enquiry Message Content: Subject lines, message bodies, sender names and email addresses from your connected inbox. Stored encrypted at rest (AES-256-GCM). Used to classify, score, and display your enquiries, and to generate automated reply drafts for your approval.
  • Structured Metadata: Budget, location, dates, and other fields extracted from message content. Stored in your account to enable filtering and CRM features.
  • Usage and Technical Data: IP addresses, browser type, session identifiers. Used for security and to maintain your login session.

We do not use your data for advertising, profiling, or any purpose unrelated to providing the Service.

3. Data Security and Encryption

We implement the following technical measures to protect your business communications:

  • AES-256-GCM field-level encryption on all sensitive columns: message subjects, bodies, sender names, email addresses, and IMAP/OAuth credentials. The encryption key is held separately from the data.
  • PII-scrubbed search index: Keyword search is performed against a tokenised, non-reversible index — not against decrypted message content. This means full-text search does not expose plaintext PII to the search engine.
  • CSRF protection on all state-changing operations.
  • HTTPS-only transport in production.

In the event of a data breach affecting your personal data, we will notify you and the ICO within 72 hours where legally required.

4. Data Retention

We apply the following retention limits:

  • Message content — Free plan: Messages older than 6 months are automatically purged from our database. They remain in your own email account.
  • Message content — Paid plans: Messages are retained for the duration of your subscription, up to a maximum of 6 years, after which they are automatically purged.
  • Account inactivity: If your account has had no login activity for 23 months, we will send a warning email to the address on file. If no login occurs within 30 days of that warning (24 months total inactivity), your account and all associated data are permanently deleted. Logging in at any point resets this clock.
  • Account closure: On account deletion (whether initiated by you or triggered by inactivity), all messages, extracted fields, contacts, rules, and templates stored in Sprevi are permanently deleted within 30 days.

These purges apply to data held in the Sprevi database only. We do not alter, delete, or move any data in your actual email mailbox.

5. Data Sharing

We do not sell, rent, or share your data with third parties for their own purposes. We may share data with:

  • Hosting and infrastructure providers (processing on our behalf under appropriate data processing agreements).
  • Payment processors (Stripe) — payment card data is handled directly by Stripe; we store only your subscription status.
  • Optional integrations you explicitly enable (e.g. Booking app, WhatsApp notifications) — only the data required for that integration is shared.

All sub-processors are bound by confidentiality and GDPR-compliant data processing terms.

6. Your Rights Under UK GDPR

As the data controller for your account data, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Ask us to correct inaccurate data.
  • Right to erasure ("right to be forgotten"): Request deletion of your account and all associated data. Use the account deletion option in Settings, or contact us.
  • Right to restriction: Ask us to pause processing your data while a dispute is resolved.
  • Right to data portability: Receive your account data in a machine-readable format.
  • Right to object: Object to processing based on legitimate interests.

To exercise any of these rights, contact us at privacy@sprevi.com. We will respond within 30 days. If you are unhappy with our response, you have the right to lodge a complaint with the ICO at ico.org.uk/make-a-complaint.

7. Cookies

We use essential session cookies only: a single cookie to maintain your authenticated login session. We do not use advertising, analytics, or tracking cookies. Disabling cookies will prevent you from logging in.

8. Changes to This Policy

We may update this policy as the Service evolves or as legal requirements change. Material changes will be notified by email to the address on your account at least 14 days before they take effect. The "Last updated" date at the top of this page reflects when the policy was last substantively changed.

Contact

For data protection enquiries: privacy@sprevi.com