GDPR / Data Processing Statement
Effective date: 17 September 2026
Aventura Labs Ltd processes personal data in accordance with UK GDPR and the Data Protection Act 2018.
This statement has two parts. Part 1 covers the personal data we decide the use of ourselves — website visitors, enquiries, billing and our own outreach — where we are the *controller*. Part 2 covers the personal data we handle on behalf of a client, on their instructions, when we run their website, answer their calls or manage their reviews. There we are the *processor* and the client is the controller, and Part 2 sets out the terms required by Article 28 of the UK GDPR.
Part 1 — where we are the controller
Who we are
Aventura Labs Ltd (trading as TradesPlace) Registered in England and Wales, company number 17437645 Registered office: 27 Old Gloucester Street, London, England, WC1N 3AX
Email: privacy@tradesplace.co.uk Website: https://tradesplace.co.uk
Categories of data subjects
- Website visitors and enquiry form submitters
- Prospective business clients (B2B outreach)
- Contracted clients and their staff
Lawful bases
Contract, legitimate interests (B2B outreach to businesses with poor web presence, and measuring the response to it), consent where required, and legal obligation. Our Privacy Policy sets out which basis applies to which activity, and how to object.
Retention
- Enquiries: up to 24 months unless you become a client
- Client records: duration of contract plus 6 years for tax and legal purposes
- Prospect research: while relevant to the active sales pipeline
- Outreach response records: 12 months from the last interaction
Your rights
You may request access, correction, erasure, restriction or portability, and you may object to processing. Contact privacy@tradesplace.co.uk. You may complain to the Information Commissioner's Office (ico.org.uk) or to the Information Commissioner's Office (ico.org.uk).
Data Protection Officer
We are not required to appoint a DPO under Article 37. Privacy queries are handled at privacy@tradesplace.co.uk.
ICO registration
We are registered with the Information Commissioner's Office (ico.org.uk) under registration number ZC239474.
Representative in the European Union
We have not yet appointed a representative in the European Union under Article 27 of the EU GDPR. Data subjects in the EU may contact us directly at the address above, and may complain to their own supervisory authority.
Part 2 — where we are the processor
These terms apply whenever we process personal data on behalf of a client under Article 28 of the UK GDPR. They form part of the agreement between us and that client. Where the client's own signed data processing agreement covers the same ground, that agreement prevails.
Subject matter, duration, nature and purpose
| Service | What we do with personal data | Duration |
|---|---|---|
| Website and hosting | Serve the client's site and pass enquiry form submissions to them | Term of the plan |
| AI Secretary | Answer calls, transcribe what the caller says, and take a message | Term of the bolt-on |
| Missed-Call Rescue | Detect a missed call and send a follow-up message to the caller | Term of the bolt-on |
| Reputation | Retrieve published reviews and draft replies for the client to approve | Term of the bolt-on |
Categories of personal data and data subjects
The data subjects are the client's own customers and enquirers. The personal data is: name, telephone number, email address, postal address or postcode, the content of an enquiry, call audio and its transcript, the message taken from a call, and published review text with the reviewer's display name. We do not ask for, and the services are not designed to receive, special category data under Article 9.
Our obligations
- Documented instructions. We process personal data only on the client's documented instructions, which are the agreement, this statement, and the settings the client configures. We tell the client if an instruction appears to breach data protection law, and if we are required by law to process otherwise, we tell them before doing so unless the law forbids it.
- Confidentiality. Everyone we authorise to process the data is bound by a duty of confidence.
- Security. We keep the measures set out in Annex B, appropriate to the risk under Article 32.
- Assistance. We assist the client, so far as we are able, with data subject requests under Chapter III, and with their obligations under Articles 32 to 36 including security, breach notification and impact assessments.
- Breach notification. We notify the client without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting their data, with the information they need to meet their own reporting duties.
- Return or deletion. On termination we return or delete the personal data at the client's choice, except where we are required by law to keep it. Our offboarding process removes the hosted site, its DNS records and the client's records within 30 days of the request unless the client asks us to hold them longer.
- Audit. We make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits by the client or an auditor they appoint, on reasonable notice and no more than once a year unless a breach or a regulator requires otherwise.
Sub-processors
The client gives general written authorisation for us to engage the sub-processors listed in Annex A. Each is bound by written terms no less protective than these.
We will give the client at least 30 days' notice before adding or replacing a sub-processor. The client may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the client may terminate the affected service without penalty and receive a refund of any fees paid for the unused part of the term.
International transfers
Some sub-processors process personal data outside the UK. Where they do, the transfer is covered by UK adequacy regulations or by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. Annex A names the mechanism for each.
Annex A — sub-processors
| Sub-processor | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| Deepgram | Speech-to-text for the AI Secretary and voicemail transcription | Call audio and the resulting transcript, including anything the caller says | United States | UK International Data Transfer Addendum to the EU Standard Contractual Clauses |
| OpenRouter (onward to Anthropic) | Generating the message taken from a call, qualifying an enquiry, and drafting review replies | Call transcripts, caller name, telephone number, postcode and job description; review text and reviewer name | United States | UK International Data Transfer Addendum to the EU Standard Contractual Clauses |
| Vonage | Telephony: call routing, recording, and SMS delivery | Caller telephone number, call metadata, call audio, SMS content | United Kingdom and European Economic Area | No transfer outside the UK/EEA |
| Railway | Application and database hosting | All data held in the platform, at rest and in transit | European Economic Area | No transfer outside the UK/EEA |
| Cloudflare | DNS, CDN and edge hosting for client websites | Website visitor IP addresses and request metadata; enquiry form submissions in transit | Global edge network | UK International Data Transfer Addendum to the EU Standard Contractual Clauses |
| Resend | Transactional email delivery | Recipient email address and message content | United States | UK International Data Transfer Addendum to the EU Standard Contractual Clauses |
| Google Places | Business listing details and review content for the Reputation service | Business name and address, review text and reviewer display name | United States | UK International Data Transfer Addendum to the EU Standard Contractual Clauses |
| Google reCAPTCHA | Spam and abuse protection on public forms | IP address and interaction signals of the person submitting a form | United States | UK International Data Transfer Addendum to the EU Standard Contractual Clauses |
Annex B — technical and organisational measures
Encryption
- HTTPS with TLS on every public endpoint, including client sites
- Data at rest encrypted by the hosting and database provider
- Enquirers' telephone numbers and email addresses additionally encrypted at the application layer with AES-256-GCM, under a key the database server does not hold
- Backups encrypted with AES-256-GCM before they leave the machine
- Call recordings served only over authenticated, time-limited links
Access control
- Administrative access is individual, password-protected and rate-limited
- Passwords stored with bcrypt; session tokens stored hashed, never in the clear
- Access to production data is limited to those who need it to run the service
Secrets and integrations
- All credentials held in environment configuration; no default passwords in production
- Webhook payloads verified by signature before they are acted on (Stripe, PostGrid, Vonage)
- reCAPTCHA on public forms to keep automated submissions out of the client's leads
Retention and deletion
- Call recordings deleted after 30 days
- Call transcripts deleted after 90 days
- The message taken from a call is kept as the client's lead record and is deleted with their account
- Deletion runs automatically, not on request
Resilience
- Automated database backups with documented restore procedure
- Application and database hosted on managed infrastructure with provider-level redundancy
Governance
- Application logging and error monitoring, reviewed on incident
- Documented incident response, with the 72-hour notification duty above
- Each new sub-processor assessed for security and transfer safeguards before it is engaged
Changes
We may update this statement. The effective date above will change when we do, and material changes affecting sub-processors follow the 30-day notice above.