Privacy Policy
This policy explains how TOLVARA LIMITED handles personal data across our website and any mobile applications we publish. It is written to be read, not skimmed past.
1. Who we are (data controller)
The data controller for the processing described in this policy is TOLVARA LIMITED, a company registered in Northern Ireland under company number NI739585, with its registered office at Unit 512 Moat House Business Centre, 54 Bloomfield Avenue, Belfast, Northern Ireland, BT5 5AD. “Tolvara”, “we”, “us” and “our” refer to TOLVARA LIMITED.
You can reach us about anything in this policy at info@tolvara.co.
2. Scope of this policy
This policy covers:
- our website at tolvara.co; and
- any mobile applications published by TOLVARA LIMITED on the Apple App Store or Google Play (together, the “apps”), including any client service-desk companion app we may release.
Where a specific app collects data beyond what is described here, its store listing and in-app notices will say so, and this policy will be updated before release. This policy does not cover third-party websites or services we link to.
Where we process personal data on behalf of business clients under a service agreement (for example, administering a client’s Microsoft 365 tenant), we act as a processor under that agreement, and the client’s own privacy notices apply. This policy covers the processing for which we are the controller.
3. Data we process on the website
The website is deliberately minimal in what it collects:
- Email correspondence. The site contains no contact forms. If you email us at info@tolvara.co, we receive your email address, name (if included) and the content of your message, and we use them to reply and manage the enquiry.
- Server logs. Our website is served by Cloudflare, which processes IP addresses and request metadata in standard server logs for security and delivery purposes (for example, blocking malicious traffic).
- No analytics or advertising cookies. We run no analytics scripts, no advertising pixels and no tracking cookies on this website. See our Cookie Policy for the strictly necessary cookies Cloudflare may set.
4. Data we process in our mobile apps
The following applies to apps we publish. Individual apps may use only a subset of these categories.
4.1 Account information
If an app offers accounts, we collect the details you provide at sign-up — typically name, work email address and organisation — to create and secure your account and to link you to the correct service records.
4.2 User content
Content you create in an app (for example, support tickets, messages, attachments or notes) is stored on our infrastructure hosted with the providers listed in section 6, and used solely to provide the app’s functionality to you and, where applicable, your organisation.
4.3 Device and technical data
Apps may process device model, operating system version, app version, language and similar technical attributes to render correctly and to support you effectively.
4.4 Usage analytics
Where an app includes usage analytics, they are aggregated and used only to understand which features work and which fail. We do not use advertising identifiers.
4.5 Crash diagnostics
Apps may collect crash reports (stack traces, device state at the time of failure) to diagnose and fix defects.
4.6 App permissions
Any permission an app requests serves a stated function and can be declined or revoked at any time in your device settings without losing unrelated functionality:
- Notifications — to alert you to ticket updates or service events. Revocable in system settings; the app continues to work without it.
- Camera / photo library — only if and when you choose to attach an image (for example, a photo of an error screen) to a ticket. Never accessed in the background. Revocable in system settings.
We will not request permissions an app does not functionally need.
4.7 What we do not do
- We do not sell personal data.
- We do not use advertising SDKs.
- We do not track you across other companies’ apps or websites.
- We do not collect precise location data.
5. Purposes and lawful bases
| Purpose | Data | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Responding to enquiries and managing correspondence | Email address, name, message content | Legitimate interests (running our business and answering you) |
| Providing app functionality and accounts | Account information, user content, device data | Performance of a contract (or steps prior to a contract) |
| Website and service security, abuse prevention | IP addresses, server logs | Legitimate interests (protecting our services and users) |
| Improving app reliability and features | Aggregated usage analytics, crash diagnostics | Legitimate interests (maintaining working software) |
| Meeting legal and accounting obligations | Correspondence and contractual records | Legal obligation |
| Any future optional processing (e.g. non-essential cookies) | As described at the time | Consent, sought first |
Where we rely on legitimate interests we have balanced those interests against your rights; you can object at any time (section 9).
6. Recipients and processors
We share personal data only with service providers that host or deliver our services, under contracts that restrict their use of it:
- Cloudflare, Inc. — website hosting, content delivery and security.
- Apple Inc. — app distribution and, where applicable, in-app purchase processing on iOS.
- Google LLC — app distribution and, where applicable, in-app purchase processing on Android.
If we adopt additional processors (for example, a cloud hosting or crash-reporting provider for a specific app), we commit to keeping this section current, and app store listings will reflect the change. We may also disclose data where the law requires it, or as part of a genuine corporate transaction with equivalent safeguards.
7. International transfers
Some providers above process data outside the United Kingdom, including in the United States. Where personal data leaves the UK, we rely on one or more of: a UK adequacy regulation covering the destination; the UK International Data Transfer Agreement (IDTA); or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures needed. Copies of relevant safeguards can be requested via info@tolvara.co.
8. How long we keep data
- Enquiry correspondence (no contract results): deleted within 24 months of the last exchange.
- Contractual and client records: retained for the duration of the agreement plus 6 years, reflecting limitation periods for contract claims.
- App account data and user content: retained while the account is active; deleted within 30 days of account deletion (section 12), except minimal records we must keep by law.
- Crash diagnostics and aggregated analytics: raw crash data deleted within 12 months; aggregates contain no personal data.
- Cloudflare server logs: retained by Cloudflare for its standard short operational periods.
9. Your rights
Under UK GDPR you have the right to:
- be informed about how your data is used (this policy);
- access a copy of your personal data;
- rectification of inaccurate or incomplete data;
- erasure (“right to be forgotten”) in applicable circumstances;
- restrict processing in applicable circumstances;
- data portability of data you provided to us, in a machine-readable format;
- object to processing based on legitimate interests; and
- not be subject to automated decision-making with legal or similarly significant effects — we do not carry out such decision-making.
To exercise any right, email info@tolvara.co. We will respond within one month of receiving your request (extendable by two further months for complex requests, in which case we will tell you within the first month). Exercising these rights is free of charge except where requests are manifestly unfounded or excessive.
10. Complaints to the ICO
You are entitled to complain to the UK supervisory authority, the Information Commissioner’s Office (ICO): ico.org.uk, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113. We would appreciate the chance to address your concern first, but you may contact the ICO at any time.
11. Children
Our website and apps are designed for business use and are not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, contact info@tolvara.co and we will delete it promptly.
12. Account and data deletion
For any app we publish that supports accounts, you can delete your account and associated data:
- In the app (once our apps ship): Settings → Account → Delete account. This starts deletion immediately and requires no contact with us.
- By email: send a request to info@tolvara.co with the subject line “Account deletion request” from the email address linked to the account.
Either route deletes your account and personal data within 30 days. We may retain the minimum records the law obliges us to keep (for example, billing records required for tax purposes), and we will tell you if that applies.
13. iOS App Tracking Transparency
Our apps do not track users across apps or websites owned by other companies, as “tracking” is defined by Apple’s App Tracking Transparency framework. Accordingly, our apps do not need to and do not display the ATT permission prompt. If this ever changed, we would ask for your consent through the ATT prompt before any such tracking occurred — tracking would never be enabled silently.
14. Google Play Data Safety
For apps distributed on Google Play, the Data Safety section of each store listing is completed to be consistent with this policy — the same categories, purposes and sharing described here. If you ever find a discrepancy between a listing and this policy, tell us at info@tolvara.co and we will correct it.
15. Security measures
We apply the same discipline to our own data that we sell to clients, including: encryption of data in transit (TLS) and at rest on our systems; multi-factor authentication and least-privilege access on all administrative accounts; segregated credentials and audited access to production systems; tested backups; timely security patching; and a documented incident-response process. Where a personal data breach is likely to result in a risk to your rights, we will notify the ICO within 72 hours and affected individuals without undue delay, as UK GDPR requires.
16. Changes to this policy
We review this policy at least annually and whenever our processing changes. Material changes will be signposted on this page with an updated effective date and version number and, for app users, through an in-app or store notice where appropriate. The current version always lives at tolvara.co/privacy.html.
17. Contact
Questions, requests and complaints about this policy or your personal data: info@tolvara.co, or by post to TOLVARA LIMITED, Unit 512 Moat House Business Centre, 54 Bloomfield Avenue, Belfast, Northern Ireland, BT5 5AD. We reply within one business day to acknowledge, and within one month substantively for rights requests.
↑ Back to top