We use only the information needed to create, secure and operate a Tynevolt Passport. We do not sell personal information, use it for advertising or run tracking analytics. You can ask us for a copy, correction, restriction, objection or deletion review.
1. Who is responsible?
Tynevolt Ltd is the controller of personal information used in Tynevolt Passport. We are registered in England and Wales under company number 17331271. Our registered office is 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. For privacy enquiries, email info@tynevolt.co.uk.
2. What this notice covers
This notice covers information used to create and operate the Passport, provide electrical records and files, set service reminders, respond to customer requests, protect the system and keep an accountability record. It does not replace the terms applying to electrical work or certificates.
3. What we collect and where it comes from
- Customer and contact details: name, email address, telephone number and preferred contact method.
- Property details: address, property type and relevant installation notes.
- Electrical history: work records, dates, outcomes, certificate references, photographs, documents and reminders.
- Requests and correspondence: corrections, access questions, privacy requests and messages sent through the Passport.
- Security and accountability information: sign-in outcomes, terms acceptance records, pseudonymised network-address records, access events and staff actions.
Information normally comes from you, from Tynevolt's work and inspection records, or from the person arranging the work, such as a property owner, landlord, managing agent or contractor. If someone else gives us your information, we will make this notice available as soon as reasonably possible.
4. Why we use it and our lawful bases
- Contract: to take requested steps, provide agreed services, create the Passport and answer service questions.
- Legitimate interests: to maintain useful and accurate electrical, safety, warranty and quality records; provide service reminders; protect the system; prevent misuse; and manage claims or complaints. We consider the need, impact and reasonable expectations before relying on this basis.
- Legal obligation: where we must keep or disclose information to meet legal, regulatory, tax, insurance or data-protection duties.
Passport service messages and recorded-date reminders are not used to add advertising. If Tynevolt later wants to send marketing, it will be handled separately under the applicable electronic-marketing rules.
5. What you need to provide
A customer name, property address and at least one contact method are needed to create a working Passport. Without them we cannot provide the service. Other notes and documents are optional unless needed for the particular electrical work, certificate, legal duty or claim. Tynevolt Passport does not make decisions about you solely by automated means and does not profile customers.
6. Who can see or receive information
Access is limited to approved Tynevolt staff who need it for their work. We also use service providers for secure website hosting, staff authentication, database storage, private file storage, security and technical support. These currently include OpenAI-hosted site services and Cloudflare infrastructure. We may share limited information with professional advisers, insurers, regulators, law enforcement or another recipient where lawfully necessary, or with a person you authorise. We do not sell personal information.
7. Processing outside the UK
Some service providers may process or support information outside the UK. Where this happens, Tynevolt requires an applicable lawful safeguard, such as UK adequacy regulations or approved contractual safeguards. You can ask us for more information about the safeguard relevant to your data.
8. How access is protected
Customer access uses a long unique link and a separate six-digit PIN. The PIN is stored as a salted one-way hash; handover credentials are encrypted; sessions expire automatically; repeated failed attempts are limited; and links can be revoked. Files are held in private storage. Staff access requires a verified identity and separate Tynevolt approval, with administrator controls and an audit history. Connections use HTTPS and restrictive browser security controls. No online system is risk-free. Uploaded files are limited to necessary document and image formats, checked against their actual contents, fingerprinted for integrity and stored with a separate private recovery copy. Tell us promptly if a link or PIN may have been exposed.
9. How long we keep information
Each Passport is scheduled for review six years after its last meaningful activity. The system flags the review; it does not automatically delete electrical safety history. An administrator must record whether personal details are still needed and why. If they are retained, the Passport is flagged for another review in 12 months. Tynevolt will anonymise customer contact details that are no longer needed and retain only a proportionate electrical safety history for the property. A shorter or longer period may apply where a continuing service, legal, insurance, warranty, complaint, dispute or safety need justifies it. Security and audit information is kept only for as long as needed for protection and accountability. When staff remove a document, it is hidden from normal staff and customer access immediately. An administrator can restore its private recovery copy for up to 30 days, or permanently erase both copies sooner where appropriate. Expired recovery copies are cleared during system maintenance. Deletion requests are considered individually because the right to erasure is not absolute.
10. Your data-protection rights
Depending on the circumstances, you may ask for access to your personal information, correction, erasure, restriction, data portability or a review of how it is used. You can begin a request inside your Passport or email us. Tynevolt records a conservative 28-day internal response target so that it can respond without undue delay and within the usual one-calendar-month legal maximum. If a request is complex, or you make several requests, the law may allow up to two further months; Tynevolt will tell you within the first response period and explain why. We may ask for proportionate identity information only where reasonably necessary. In that case the response period begins when we receive enough information to verify identity. The Passport records the check and date; it is not designed to store copies of identity documents.
You may object to processing based on Tynevolt's legitimate interests. Tell us what you object to and why. We will stop unless we can demonstrate compelling legitimate grounds or the information is needed for legal claims. You may object to direct marketing at any time; Tynevolt Passport does not currently send marketing.
11. Reminders and customer control
You can save a recorded due date to your own phone calendar. Those calendar alerts happen on your device. Tynevolt may separately contact you about an electrical-service date using your preferred contact details. You can ask us to correct a date, stop a reminder or replace access credentials.
12. Cookies
The Passport uses only essential security and session cookies. It does not use advertising or analytics cookies. Read the cookie notice for the cookie purposes and durations.
13. Complaints and changes
Please contact Tynevolt first so we can investigate and help. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We will date material changes and keep the current notice available here.
Privacy contact
Tynevolt Ltd
Registered in England and Wales • Company no. 17331271
Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
info@tynevolt.co.uk