This Privacy Policy explains how REVAY LTD ("REVAY", "we", "us", or "our") collects, uses, discloses, and otherwise processes personal data in connection with our website at https://revay.digital, our software and database development services, client engagements, support activities, marketing communications, and related business operations. We are committed to protecting personal data and complying with applicable data protection laws, including the UK General Data Protection Regulation ("UK GDPR") as incorporated into the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 ("PECR"), and other relevant legislation in force in England and Wales.
Please read this Privacy Policy carefully. By accessing our website, contacting us, entering into a contract with us, or otherwise providing personal data to us, you acknowledge that you have read and understood the practices described herein. Where we process personal data on behalf of clients as a processor, the terms of our data processing agreement with that client will apply in addition to, and in the event of conflict may prevail over, the general descriptions in this Privacy Policy.
This Privacy Policy was last updated on 20 August 2026. We may update this Privacy Policy from time to time to reflect changes in law, regulatory guidance, technology, or our business practices. Material changes will be communicated where required by law, and the updated version will be posted on our website with a revised "last updated" date.
REVAY LTD is the data controller responsible for personal data processed under this Privacy Policy, except where we act as a processor on behalf of a client. Our registered office and principal place of business is IMPACT BRIXTON 17A Electric Lane, LONDON, SW9 8LA United Kingdom.
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or need to contact us regarding a privacy matter, you may reach us using the following details:
We have not appointed a statutory Data Protection Officer as we are not required to do so under applicable law. Privacy enquiries will be handled by our internal compliance team and escalated where appropriate.
This Privacy Policy applies to personal data we process about:
This Privacy Policy does not apply to third-party websites, services, or platforms that may be linked from our website or integrated into solutions we build for clients. Those third parties are responsible for their own privacy practices. We encourage you to review their privacy policies before providing personal data to them.
Where we process personal data solely on instructions from a client, that client is typically the data controller and we act as a data processor. In such cases, individuals should refer to the client's privacy notice and contact the client directly to exercise rights relating to data processed under that engagement.
The personal data we collect depends on your relationship with us and the services you use. We may collect and process the following categories of personal data:
We may collect names, job titles, company names, postal addresses, email addresses, telephone numbers, and other business contact details provided when you enquire about our services, request a proposal, sign a contract, attend meetings, or communicate with us.
Where we provide access to client portals, staging environments, repositories, or support systems, we may process usernames, account identifiers, role assignments, access credentials or authentication tokens, and security logs associated with your account.
When you visit our website or use our digital services, we may automatically collect IP addresses, browser type and version, device identifiers, operating system, referral URLs, pages viewed, session duration, clickstream data, error logs, and similar technical information. Further details about cookies and similar technologies are set out in our Cookie Policy, which forms part of our approach to transparency regarding online tracking and analytics.
We retain records of emails, messages, call notes, meeting minutes, support tickets, and other correspondence where relevant to our business relationship, legal obligations, or legitimate interests in maintaining accurate records.
For clients and suppliers, we may process billing addresses, purchase order references, invoice details, payment status, tax identifiers where applicable, and bank or payment account information necessary to fulfil contractual and accounting obligations. Payment card data, where collected, is typically processed by regulated payment service providers rather than stored directly by us except as permitted by applicable standards.
In the course of software and database development projects, we may process personal data contained in specifications, test datasets, user stories, bug reports, database records, migration files, audit logs, or application data provided by or generated on behalf of clients. The nature and sensitivity of such data is determined by the client and the project scope.
We may record your marketing preferences, event attendance, newsletter subscriptions, and engagement with our campaigns to ensure communications are relevant and compliant with your choices.
Job applicants may provide CVs, employment history, qualifications, references, interview notes, right-to-work documentation, and other information necessary to evaluate and manage recruitment processes.
We do not routinely seek to collect special category personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation) or data relating to criminal convictions and offences. If such data is incidentally included in materials provided by clients or applicants, we will process it only where permitted by law and with appropriate safeguards, or will request redaction where processing is not necessary.
We obtain personal data from several sources, including:
Where personal data is provided to us by a third party, we expect that party to have a lawful basis to share the data and, where required, to have informed the data subject accordingly.
Under the UK GDPR, we must identify a lawful basis for each processing activity. We process personal data for the purposes and on the legal bases described below.
We process personal data where necessary to enter into, perform, and administer contracts with clients, suppliers, and contractors, including scoping projects, delivering software and database development services, providing support, issuing invoices, and managing account relationships.
We process personal data where necessary for our legitimate interests, provided those interests are not overridden by your rights and interests. Our legitimate interests include:
Where we rely on legitimate interests, we balance those interests against your privacy rights and implement measures to minimise intrusion, such as pseudonymisation where appropriate and strict access controls.
We process personal data where necessary to comply with legal obligations under UK law, including tax and accounting requirements, employment law, anti-money laundering obligations where applicable, and responses to lawful requests from courts, regulators, or law enforcement.
Where required by law, we rely on consent for certain activities, such as non-essential cookies, certain direct marketing communications, or processing that is not otherwise justified by another lawful basis. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal, though this may limit our ability to provide specific services or communications.
We may process personal data to protect vital interests in emergency situations or where necessary for reasons of substantial public interest as recognised by applicable law, though such processing is rare in the context of our ordinary business activities.
Subject to the legal bases described above, we use personal data for the following purposes:
We do not use personal data for solely automated decision-making that produces legal or similarly significant effects concerning individuals, except where such processing is authorised by law, necessary for contract performance, or based on explicit consent with suitable safeguards.
Our website and certain client-facing tools use cookies, local storage, session storage, pixels, and similar technologies to enable functionality, remember preferences, analyse traffic, and support security. Cookies may be first-party (set by REVAY) or third-party (set by service providers such as analytics or hosting partners).
Non-essential cookies and similar technologies are deployed only where permitted under PECR and the UK GDPR, typically following consent via our cookie banner or preference centre where implemented. Essential cookies necessary for website operation, security, or requested services may be used without consent where lawfully permitted.
For comprehensive information about the types of cookies we use, their purposes, retention periods, and how to manage your preferences, please refer to our separate Cookie Policy available on our website. You may also configure your browser to block or delete cookies, although this may affect website functionality.
We do not sell personal data. We share personal data only as described below and subject to appropriate safeguards.
We engage trusted third parties to support our operations, including cloud hosting providers, database platforms, source control and CI/CD services, email and communications tools, CRM systems, accounting software, payment processors, legal advisers, and IT security vendors. These parties process personal data on our instructions under written contracts that require appropriate security measures and, where applicable, compliance with Article 28 UK GDPR processor terms.
Where you interact with a solution we develop for a client, certain personal data may be accessible to authorised personnel of that client in accordance with the client's policies and our contractual obligations.
We may disclose personal data to solicitors, accountants, auditors, and insurers where reasonably necessary for professional advice, regulatory compliance, or claims handling.
If REVAY undergoes a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the successor entity subject to continuity of protections consistent with this Privacy Policy and applicable law.
We may disclose personal data where required by law, court order, or regulatory authority, or where necessary to protect the rights, property, or safety of REVAY, our clients, or others.
We may share personal data with third parties when you instruct us to do so or provide explicit consent for a specific disclosure.
REVAY is based in the United Kingdom. Personal data may be processed within the UK and, where necessary to deliver services or operate our systems, transferred to countries outside the UK including the European Economic Area ("EEA") and the United States.
When we transfer personal data outside the UK to countries not subject to an adequacy regulation issued by the UK Secretary of State, we implement appropriate safeguards as required by Chapter V of the UK GDPR. Such safeguards may include:
We assess transfer risks and implement supplementary measures where appropriate, such as encryption in transit and at rest, strict access controls, and data minimisation. Copies of relevant transfer safeguards may be made available on request, subject to redaction of confidential commercial terms.
Clients who require personal data to remain within specific geographic boundaries should specify such requirements in contractual documentation so that we can architect solutions and select subprocessors accordingly.
We implement technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures are proportionate to the nature of the data and the risks presented by our processing activities, and may include:
No method of transmission or storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of credentials issued to you and for notifying us promptly if you suspect unauthorised access to your account.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, reporting, or archiving requirements. Retention periods vary depending on the category of data and the context of processing.
Indicative retention periods include:
When personal data is no longer required, we securely delete or anonymise it so that it can no longer be associated with an identifiable individual, unless retention is required or permitted by law. Anonymised data may be retained indefinitely for statistical and service improvement purposes.
Under the UK GDPR, individuals whose personal data we process as controller may have the following rights, subject to conditions and exceptions in applicable law:
To exercise any of these rights, contact us at general@revay.digital or write to our address above. We may request information to verify your identity before responding. We aim to respond within one month, which may be extended by a further two months for complex requests as permitted by law, in which case we will inform you of the extension and reasons.
If we act as processor for a client's data, we will forward your request to the relevant controller where appropriate or advise you to contact them directly.
Our website and services are directed at businesses and professional users. We do not knowingly collect personal data from children under the age of eighteen without appropriate parental or guardian authority. If you believe we have inadvertently collected personal data relating to a child, please contact us and we will take steps to delete such data where required.
We may send electronic marketing communications about our services where permitted by PECR and the UK GDPR. Business-to-business marketing to corporate email addresses may be conducted on the basis of legitimate interests where the communication is relevant to the recipient's role, provided a clear opt-out is offered in each message.
You may opt out of marketing emails by using the unsubscribe link in any marketing message or by contacting general@revay.digital. Opting out of marketing does not affect transactional or service-related communications necessary to perform a contract or protect your security.
As a software and database development company, REVAY frequently processes personal data on behalf of clients when building, migrating, testing, or maintaining systems. In such engagements:
Clients remain responsible for establishing lawful bases for processing, providing privacy notices to data subjects, and ensuring that data shared with REVAY for development or testing is adequate, relevant, and limited to what is necessary. Where possible, clients should provide anonymised or synthetic test data rather than live personal data unless production data is strictly required.
We do not engage in profiling that produces legal or similarly significant effects on individuals. Limited automated processing may occur in the context of website analytics, spam filtering, security monitoring, and workflow automation internal to our operations. Such processing is designed to support service delivery and security rather than to make consequential decisions about individuals without human review.
Our website may contain links to third-party websites, documentation, or tools. Integrations built for clients may connect to external APIs, payment gateways, identity providers, or cloud services. We are not responsible for the privacy practices of third parties. We recommend reviewing the privacy policies of any third-party services you choose to use.
If you are dissatisfied with our handling of your personal data or a rights request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
We encourage you to contact us first at general@revay.digital so that we may attempt to resolve your concern promptly.
This Privacy Policy is governed by the laws of England and Wales. Any disputes relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales, without prejudice to mandatory rights available to data subjects under applicable data protection law.
Website visitors should pay particular attention to Sections 3, 7, and 12 regarding technical data, cookies, and rights. Browser settings and our cookie preference tools provide additional control over non-essential tracking technologies.
Individuals designated as contacts for client organisations should ensure that their employer is aware that their business contact details are shared with REVAY for project and account management purposes. Updates to contact details should be communicated promptly to maintain accurate records.
Applicants should provide accurate information in applications and notify us of any changes. We may verify qualifications and right to work as permitted by law. Unsuccessful applicants' data is handled in accordance with Section 11 unless otherwise agreed.
Personal data of supplier and partner contacts is processed for contract administration, performance management, and compliance with applicable procurement and tax obligations.
In accordance with Article 30 UK GDPR, REVAY maintains records of processing activities under our responsibility as controller. These internal records document processing purposes, data categories, recipient categories, international transfers, retention schedules, and security measures. Summaries of these practices are reflected in this Privacy Policy. Detailed records are available to the ICO on request as part of its supervisory functions.
Where processing is likely to result in a high risk to the rights and freedoms of individuals, we conduct data protection impact assessments ("DPIAs") in accordance with UK GDPR requirements. DPIAs are particularly relevant when deploying new database architectures, large-scale data migrations, extensive profiling, or systematic monitoring. Clients engaging us for high-risk processing should collaborate in DPIA activities and provide necessary information about intended processing operations.
We maintain procedures to address personal data breaches. Where we act as controller and a breach is likely to result in a risk to individuals' rights and freedoms, we will notify the ICO without undue delay and, where feasible, within seventy-two hours of becoming aware of the breach. Where the breach is likely to result in a high risk to individuals, we will also communicate the breach to affected data subjects without undue delay, unless an exception applies under applicable law.
Where we act as processor, we will notify the relevant client without undue delay after becoming aware of a personal data breach affecting client data, and cooperate with the client in meeting its notification obligations. Clients should provide contact details for security incident reporting in project documentation.
As REVAY expands its service offerings, adopts new technologies, or responds to client requirements, our processing activities may evolve. We review this Privacy Policy periodically and update it when changes materially affect how personal data is handled. Continued use of our services after an update constitutes acknowledgement of the revised policy where permitted by law, and we will seek fresh consent where required for specific processing activities.
For any questions, concerns, or requests relating to this Privacy Policy or our handling of personal data, please contact:
REVAY LTD
IMPACT BRIXTON 17A Electric Lane, LONDON, SW9 8LA United Kingdom
Telephone: +44 7345 112244
Email: general@revay.digital
Website: https://revay.digital
We will endeavour to respond to all legitimate enquiries promptly and in accordance with applicable data protection law.
REVAY LTD recognises that transparency is fundamental to trust in data processing relationships. This supplementary section provides additional detail regarding our approach to privacy governance, accountability, and continuous improvement in our capacity as a UK-based software and database development company serving domestic and international clients.
Our privacy governance framework includes periodic review of processing activities, vendor due diligence for subprocessors with access to personal data, documented information asset registers, and alignment with recognised security and privacy standards appropriate to the scale and nature of our operations. Senior management allocates resources for privacy compliance, and personnel with access to personal data receive guidance on confidentiality, secure handling, and incident escalation pathways.
When designing database schemas, application architectures, and data pipelines for clients, we apply privacy-by-design and privacy-by-default principles where practicable. This includes data minimisation in collection forms, configurable retention policies, role-based access to production data, separation of development and production environments, and preference for pseudonymisation or anonymisation in non-production environments. Clients retain ultimate responsibility for configuring deployed systems in accordance with their legal obligations, and we provide documentation and recommendations to support compliant deployment.
We maintain inventories of personal data processed in our own business systems and in recurring categories of client projects. These inventories support response to data subject access requests, facilitate deletion upon contract termination where instructed, and enable accurate privacy notices. For multi-tenant or hosted solutions, logical separation and tenant-specific access controls are implemented to prevent unauthorised cross-client access.
Requests from public authorities for access to personal data are handled carefully. Unless prohibited by law, we notify affected clients before disclosing client-controlled data in response to such requests, and we verify the legal validity and scope of demands before compliance. We document significant requests and our responses for accountability purposes.
Training on data protection is provided to developers, project managers, and support staff commensurate with their roles. Topics include secure coding practices, handling of credentials and secrets, recognition of personal data in logs and exports, lawful basis awareness for marketing activities, and procedures for reporting suspected data incidents. Contractors and temporary personnel are bound by confidentiality obligations and access is revoked upon engagement termination.
We evaluate new tools and cloud services for privacy and security implications before adoption, considering data residency options, encryption capabilities, subprocessors used by the vendor, and contractual data protection terms. Preference is given to vendors offering UK or EEA data hosting where feasible for client requirements, and international transfers are documented with appropriate safeguards as described in Section 9 of this Privacy Policy.
If you represent an organisation seeking a copy of our standard data processing terms, subprocessor list, or security overview for vendor assessment purposes, please contact general@revay.digital with your requirements. We respond to reasonable due diligence requests as part of pre-contractual discussions, subject to mutual confidentiality arrangements where appropriate.
This appendix forms an integral part of our Privacy Policy and should be read together with all preceding sections. Defined terms used herein have the meanings given in the main body of this Privacy Policy unless otherwise stated.