Skip to content
TradesPlace

GDPR / Data Processing Statement

Effective date: 17 September 2026

Aventura Labs Ltd processes personal data in accordance with UK GDPR and the Data Protection Act 2018.

This statement has two parts. Part 1 covers the personal data we decide the use of ourselves — website visitors, enquiries, billing and our own outreach — where we are the *controller*. Part 2 covers the personal data we handle on behalf of a client, on their instructions, when we run their website, answer their calls or manage their reviews. There we are the *processor* and the client is the controller, and Part 2 sets out the terms required by Article 28 of the UK GDPR.

Part 1 — where we are the controller

Who we are

Aventura Labs Ltd (trading as TradesPlace) Registered in England and Wales, company number 17437645 Registered office: 27 Old Gloucester Street, London, England, WC1N 3AX

Email: privacy@tradesplace.co.uk Website: https://tradesplace.co.uk

Categories of data subjects

  • Website visitors and enquiry form submitters
  • Prospective business clients (B2B outreach)
  • Contracted clients and their staff

Lawful bases

Contract, legitimate interests (B2B outreach to businesses with poor web presence, and measuring the response to it), consent where required, and legal obligation. Our Privacy Policy sets out which basis applies to which activity, and how to object.

Retention

  • Enquiries: up to 24 months unless you become a client
  • Client records: duration of contract plus 6 years for tax and legal purposes
  • Prospect research: while relevant to the active sales pipeline
  • Outreach response records: 12 months from the last interaction

Your rights

You may request access, correction, erasure, restriction or portability, and you may object to processing. Contact privacy@tradesplace.co.uk. You may complain to the Information Commissioner's Office (ico.org.uk) or to the Information Commissioner's Office (ico.org.uk).

Data Protection Officer

We are not required to appoint a DPO under Article 37. Privacy queries are handled at privacy@tradesplace.co.uk.

ICO registration

We are registered with the Information Commissioner's Office (ico.org.uk) under registration number ZC239474.

Representative in the European Union

We have not yet appointed a representative in the European Union under Article 27 of the EU GDPR. Data subjects in the EU may contact us directly at the address above, and may complain to their own supervisory authority.

Part 2 — where we are the processor

These terms apply whenever we process personal data on behalf of a client under Article 28 of the UK GDPR. They form part of the agreement between us and that client. Where the client's own signed data processing agreement covers the same ground, that agreement prevails.

Subject matter, duration, nature and purpose

ServiceWhat we do with personal dataDuration
Website and hosting Serve the client's site and pass enquiry form submissions to them Term of the plan
AI Secretary Answer calls, transcribe what the caller says, and take a message Term of the bolt-on
Missed-Call Rescue Detect a missed call and send a follow-up message to the caller Term of the bolt-on
Reputation Retrieve published reviews and draft replies for the client to approve Term of the bolt-on

Categories of personal data and data subjects

The data subjects are the client's own customers and enquirers. The personal data is: name, telephone number, email address, postal address or postcode, the content of an enquiry, call audio and its transcript, the message taken from a call, and published review text with the reviewer's display name. We do not ask for, and the services are not designed to receive, special category data under Article 9.

Our obligations

  • Documented instructions. We process personal data only on the client's documented instructions, which are the agreement, this statement, and the settings the client configures. We tell the client if an instruction appears to breach data protection law, and if we are required by law to process otherwise, we tell them before doing so unless the law forbids it.
  • Confidentiality. Everyone we authorise to process the data is bound by a duty of confidence.
  • Security. We keep the measures set out in Annex B, appropriate to the risk under Article 32.
  • Assistance. We assist the client, so far as we are able, with data subject requests under Chapter III, and with their obligations under Articles 32 to 36 including security, breach notification and impact assessments.
  • Breach notification. We notify the client without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting their data, with the information they need to meet their own reporting duties.
  • Return or deletion. On termination we return or delete the personal data at the client's choice, except where we are required by law to keep it. Our offboarding process removes the hosted site, its DNS records and the client's records within 30 days of the request unless the client asks us to hold them longer.
  • Audit. We make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits by the client or an auditor they appoint, on reasonable notice and no more than once a year unless a breach or a regulator requires otherwise.

Sub-processors

The client gives general written authorisation for us to engage the sub-processors listed in Annex A. Each is bound by written terms no less protective than these.

We will give the client at least 30 days' notice before adding or replacing a sub-processor. The client may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the client may terminate the affected service without penalty and receive a refund of any fees paid for the unused part of the term.

International transfers

Some sub-processors process personal data outside the UK. Where they do, the transfer is covered by UK adequacy regulations or by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. Annex A names the mechanism for each.

Annex A — sub-processors

Sub-processorPurposePersonal dataLocationTransfer safeguard
Deepgram Speech-to-text for the AI Secretary and voicemail transcription Call audio and the resulting transcript, including anything the caller says United States UK International Data Transfer Addendum to the EU Standard Contractual Clauses
OpenRouter (onward to Anthropic) Generating the message taken from a call, qualifying an enquiry, and drafting review replies Call transcripts, caller name, telephone number, postcode and job description; review text and reviewer name United States UK International Data Transfer Addendum to the EU Standard Contractual Clauses
Vonage Telephony: call routing, recording, and SMS delivery Caller telephone number, call metadata, call audio, SMS content United Kingdom and European Economic Area No transfer outside the UK/EEA
Railway Application and database hosting All data held in the platform, at rest and in transit European Economic Area No transfer outside the UK/EEA
Cloudflare DNS, CDN and edge hosting for client websites Website visitor IP addresses and request metadata; enquiry form submissions in transit Global edge network UK International Data Transfer Addendum to the EU Standard Contractual Clauses
Resend Transactional email delivery Recipient email address and message content United States UK International Data Transfer Addendum to the EU Standard Contractual Clauses
Google Places Business listing details and review content for the Reputation service Business name and address, review text and reviewer display name United States UK International Data Transfer Addendum to the EU Standard Contractual Clauses
Google reCAPTCHA Spam and abuse protection on public forms IP address and interaction signals of the person submitting a form United States UK International Data Transfer Addendum to the EU Standard Contractual Clauses

Annex B — technical and organisational measures

Encryption

  • HTTPS with TLS on every public endpoint, including client sites
  • Data at rest encrypted by the hosting and database provider
  • Enquirers' telephone numbers and email addresses additionally encrypted at the application layer with AES-256-GCM, under a key the database server does not hold
  • Backups encrypted with AES-256-GCM before they leave the machine
  • Call recordings served only over authenticated, time-limited links

Access control

  • Administrative access is individual, password-protected and rate-limited
  • Passwords stored with bcrypt; session tokens stored hashed, never in the clear
  • Access to production data is limited to those who need it to run the service

Secrets and integrations

  • All credentials held in environment configuration; no default passwords in production
  • Webhook payloads verified by signature before they are acted on (Stripe, PostGrid, Vonage)
  • reCAPTCHA on public forms to keep automated submissions out of the client's leads

Retention and deletion

  • Call recordings deleted after 30 days
  • Call transcripts deleted after 90 days
  • The message taken from a call is kept as the client's lead record and is deleted with their account
  • Deletion runs automatically, not on request

Resilience

  • Automated database backups with documented restore procedure
  • Application and database hosted on managed infrastructure with provider-level redundancy

Governance

  • Application logging and error monitoring, reviewed on incident
  • Documented incident response, with the 72-hour notification duty above
  • Each new sub-processor assessed for security and transfer safeguards before it is engaged

Changes

We may update this statement. The effective date above will change when we do, and material changes affecting sub-processors follow the 30-day notice above.