Privacy Policy
Last updated: 3 August 2026
1. Who We Are and Our Role
Sprevi ("we", "us", "our") is a data processor. When you connect your business mailbox to Sprevi, you (the business owner) are the data controller — you determine why and how your enquirers' personal data is processed. We process that data only on your instructions, only to provide the Service, and only for as long as you have an active account.
If your enquirers wish to exercise their rights over their personal data (erasure, access, portability), those requests should be directed to you as the data controller. You can fulfil deletion requests using the "Delete all data for this contact" action in your Contacts view, or by requesting full account deletion from us.
We are registered with the Information Commissioner's Office (ICO) as a data processor. Our registration number will be displayed here once issued.
2. What Data We Process and Why
We process the following categories of data, under the legal basis of contract performance (processing necessary to provide the Service you have contracted for):
- Account Data: Your name, business email address, and authentication credentials (hashed or secured via OAuth). Used to authenticate you and maintain your account.
- Mailbox Credentials: IMAP passwords or OAuth tokens for your connected email account. Stored encrypted (AES-256-GCM). Used to import enquiry messages, and — on paid plans — to mark messages as read and to send email replies on your behalf once you've approved them. Sprevi does not send email autonomously: every outbound reply requires your explicit one-tap approval, unless you've specifically configured and enabled an automation rule yourself. We never delete messages, change mailbox forwarding or filter rules, or access folders unrelated to identifying enquiries.
- Enquiry Message Content: Subject lines, message bodies, sender names and email addresses. This arrives either from your connected inbox, or — if you've enabled the ChatBubble website widget — directly from a form your website visitor submits, which is stored in the same way as an inbox-sourced enquiry. Stored encrypted at rest (AES-256-GCM). Used to classify, score, and display your enquiries, and to generate automated reply drafts for your approval.
- Structured Metadata: Budget, location, dates, and other fields extracted from message content. Stored in your account to enable filtering and CRM features.
- Enquiry Engagement Data (paid plans only): If you enable open or click tracking, we record that a specific outbound email was opened, and separately, when an enquirer clicks a "status" link in an email (e.g. "still interested?"), the choice they made and when. We do not store the enquirer's IP address against either of these records — known email-security scanners that pre-fetch links are filtered out so they aren't counted as genuine opens.
- Usage and Technical Data: IP addresses, browser type, session identifiers. Used for security and to maintain your login session.
We do not use your data for advertising or for any purpose unrelated to providing the Service. We do apply automated classification and scoring to enquiry content — for example, identifying high-value enquiries or returning clients — solely to deliver the core features you've contracted for. This processing runs entirely within Sprevi's own systems; see Section 5.
3. Data Security and Encryption
Mailbox Access, Precisely
Sprevi requests only the permissions needed to operate: reading enquiry messages, marking them as read, and sending replies you've approved. We do not request or use permission to delete messages, modify your mailbox rules or forwarding settings, or access anything outside your inbox. Disconnecting your mailbox (available any time in Settings) immediately revokes our access and stops all reading, marking, and sending activity; any automation rules you created are disabled at the same moment.
We implement the following technical measures to protect your business communications:
- AES-256-GCM field-level encryption on all sensitive columns: message subjects, bodies, sender names, email addresses, and IMAP/OAuth credentials. The encryption key is held separately from the data.
- PII-scrubbed search index: Keyword search is performed against a tokenised, non-reversible index — not against decrypted message content. This means full-text search does not expose plaintext PII to the search engine.
- CSRF protection on all state-changing operations.
- HTTPS-only transport in production.
In the event of a data breach affecting your personal data, we will notify you without undue delay so that you, as data controller, can meet your own regulatory obligations, including notifying the ICO within 72 hours where required.
4. Data Retention
We apply the following retention limits:
- Message content — Free plan: Messages older than 3 months are automatically purged from our database. They remain in your own email account.
- Message content — Starter plan: Messages older than 1 year are automatically purged from our database.
- Message content — Business plan: Messages older than 2 years are automatically purged from our database.
- Message content — Enterprise plan: Messages older than 6 years are automatically purged from our database.
- Account inactivity: If your account has had no login activity for 23 months, we will send a warning email to the address on file. If no login occurs within 30 days of that warning (24 months total inactivity), your account and all associated data are permanently deleted. Logging in at any point resets this clock.
- Account closure: On account deletion (whether initiated by you or triggered by inactivity), all messages, extracted fields, contacts, rules, and templates stored in Sprevi are permanently deleted within 30 days.
These purges apply to data held in the Sprevi database only. We do not alter, delete, or move any data in your actual email mailbox.
5. Data Sharing
We do not sell, rent, or share your data with third parties for their own purposes. We may share data with:
- Hosting and infrastructure providers (processing on our behalf under appropriate data processing agreements).
- Payment processors (Stripe) — payment card data is handled directly by Stripe; we store only your subscription status.
- Messaging providers (Twilio) — used only if you explicitly enable WhatsApp or SMS notifications on a paid plan; only the notification content and destination number are shared, for that purpose alone.
- Integrations you explicitly configure and enable — for example, the Booking app, a Slack or Microsoft Teams webhook you supply, or connecting your own HubSpot account. For webhook-based integrations (Slack, Teams), we deliver only to the address you provide; we do not hold a relationship with Slack or Microsoft on your behalf. For HubSpot, you authorise the connection directly via HubSpot's own login, and only the data needed for that sync is shared. Nothing outside what a given integration needs is included.
All sub-processors are bound by confidentiality and GDPR-compliant data processing terms. We will notify you by email of any new sub-processor at least 14 days before they begin processing your data, giving you the opportunity to raise concerns.
Enquiry Detection and Classification: Identifying, classifying, and scoring enquiries is currently performed using Sprevi's own proprietary logic, running entirely on our own infrastructure. We do not send your message content to any third-party AI or language model provider for this purpose. If we introduce an optional AI-assisted drafting feature that uses a third-party model provider, it will be clearly opt-in, and we will name the relevant sub-processor here before you can enable it. If you choose to connect your own third-party AI provider or API key, you are instructing that provider directly for that purpose; we will send only the data necessary to fulfil your configured request, and you are responsible for that provider's own data handling terms.
6. Your Rights Under UK GDPR
As the data controller for your account data, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Ask us to correct inaccurate data.
- Right to erasure ("right to be forgotten"): Request deletion of your account and all associated data. Use the account deletion option in Settings, or contact us.
- Right to restriction: Ask us to pause processing your data while a dispute is resolved.
- Right to data portability: Receive your account data in a machine-readable format.
- Right to object: Object to processing based on legitimate interests.
To exercise any of these rights, contact us at privacy@sprevi.com. We will respond within 30 days. If you are unhappy with our response, you have the right to lodge a complaint with the ICO at ico.org.uk/make-a-complaint.
7. Cookies
We use essential session cookies only: a single cookie to maintain your authenticated login session. We do not use advertising, analytics, or tracking cookies. Disabling cookies will prevent you from logging in.
8. Changes to This Policy
We may update this policy as the Service evolves or as legal requirements change. Material changes will be notified by email to the address on your account at least 14 days before they take effect. The "Last updated" date at the top of this page reflects when the policy was last substantively changed.
Contact
For data protection enquiries: privacy@sprevi.com