1. Who we are
This policy is issued by Navrik Limited (“Navrik”, “we”), a company registered in England and Wales under company number [company number], registered office [registered office address]. Navrik is the controller of the personal data described in Section 3 (account and usage data) and, unless a separate Data Processing Agreement says otherwise, acts as a processor on behalf of a workspace for the personal data that workspace uploads or collects about its own customers, leads and staff (“Customer Data”) — in that case, the workspace is the controller and should provide its own privacy notice to its customers.
2. Scope
This policy covers navrik.co.uk, the Navrik portal, our REST API and MCP server, and any workspace pages (storefronts, booking pages) that run on Navrik’s infrastructure. If you’re a customer of a Navrik-powered business (a “buyer”) rather than a workspace operator, that business — not Navrik — is responsible for telling you how your data is used; contact them first, though we’ll assist with a data subject request routed to us.
3. What we collect
Account and workspace data (we are the controller)
- Your email address, and name if you provide one, used to create and secure your account;
- Workspace name, plan, and billing details processed via Stripe (we don’t store full card numbers ourselves);
- Log-in and security events (sign-in timestamps, IP address, device/browser information);
- Product usage and diagnostic data — pages visited, features used, error reports — used to run and improve the Service;
- Support and contact-form correspondence.
Customer Data (we are typically the processor)
- Contacts, leads, deals, bookings, documents, messages and other records a workspace uploads or collects through Navrik about its own customers and staff;
- Content sent to the AI assistant/agent as part of using those features (see Section 6).
4. How we use personal data
We use account and usage data to:
- Provide, secure and maintain the Service (performance of a contract with you);
- Process payments and prevent fraud (performance of a contract; legal obligation);
- Send service, security and billing notices, and — where you’ve agreed — product updates and marketing (legitimate interests / consent, and always with an unsubscribe option for marketing);
- Monitor, debug and improve the Service, including through error tracking and analytics (legitimate interests);
- Comply with legal obligations, and establish, exercise or defend legal claims.
Customer Data is processed only on the instructions of the relevant workspace, to provide the Service to that workspace, and is not used by Navrik for our own marketing or to train general-purpose models without the workspace’s consent.
5. Cookies
We use essential cookies to keep you signed in and to remember basic preferences. We may use limited analytics cookies to understand aggregate product usage. We don’t currently use third-party advertising cookies on navrik.co.uk.
6. AI processing
When you use the AI assistant or agent, the relevant prompt, workspace context and any Customer Data needed to answer or act is sent to our AI sub-processor(s) to generate a response. We select AI providers that contractually commit not to use API-submitted data to train their own models, and we recommend workspaces avoid sending special-category personal data (health, biometric, etc.) through AI features unless they’ve confirmed this is supported.
7. Sub-processors and third parties
We use the following categories of sub-processor to run the Service. An up-to-date named list is available on request to admin@navrik.co.uk.
- Infrastructure & hosting — application hosting and content delivery;
- Database, auth & file storage — workspace data, authentication and document storage;
- Payments — subscription billing and payment processing;
- Email, SMS & WhatsApp delivery — transactional and, where enabled, marketing messages sent on a workspace’s behalf;
- AI providers — large language model providers powering the assistant and agent;
- Error tracking & observability — crash and performance monitoring;
- Sign-in providers — Google, for Google sign-in.
8. International transfers
Some sub-processors are located outside the UK/EEA, including in the United States. Where that’s the case, we rely on the UK International Data Transfer Addendum / EU Standard Contractual Clauses, or the sub-processor’s equivalent certification, to protect transferred personal data.
9. Data retention
We keep account and Customer Data for as long as your workspace is active, plus a reasonable period afterwards to allow export and to meet legal, accounting and dispute-resolution requirements — typically no longer than 90 days after a workspace closes, unless a longer period is required by law or agreed with you. Log and diagnostic data is retained on a shorter rolling basis.
10. Security
We use encryption in transit, role-based access controls, and row-level data isolation between workspaces, and we monitor the Service for security events. No system is completely secure, and we ask that you report suspected vulnerabilities to admin@navrik.co.uk.
11. Your rights
If you’re in the UK or EEA, data protection law gives you the right to:
- Access the personal data we hold about you;
- Correct inaccurate data or complete incomplete data;
- Ask us to erase your data, subject to legal retention requirements;
- Restrict or object to certain processing;
- Receive a portable copy of data you provided to us; and
- Withdraw consent at any time, where processing is based on consent.
To exercise these rights, contact admin@navrik.co.uk. If your data was uploaded to Navrik by a workspace you’re a customer of, we’ll typically direct you to that workspace first, since it controls that data, but we’ll still assist. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk) or your local supervisory authority.
12. Children
The Service is intended for business use and is not directed at children. We don’t knowingly collect personal data from children under 16 through navrik.co.uk itself.
13. Changes to this policy
We may update this policy from time to time. For material changes, we’ll notify workspace owners by email or in-product notice before the change takes effect.
14. Contact
Questions about this policy, or a data subject request, can be sent to admin@navrik.co.uk. See also our Terms of Service.