Legal · Privacy

Privacy Notice

This notice explains, in plain English, how Quanavo handles personal information when you visit this website, join the Founding 50 or pre-launch list, request a callback, create or use a Quanavo account, receive support, or otherwise interact with us.

Quanavo is built for UK construction businesses, and this notice is written around UK data protection law: the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

Last updated: 24 August 2026

01

Who we are

Patryk Zarzycki trading as Quanavo is responsible for the personal information described in this notice where Quanavo decides why and how that information is used.

  • Legal entity: Patryk Zarzycki trading as Quanavo
  • Registered office: [REGISTERED OFFICE]
  • Privacy contact: privacy@quanavo.com

Quanavo is not always the controller. Where a construction company uses Quanavo to manage its workforce, projects, subcontractors or other people’s information, that customer normally decides why and how the information is used, and is therefore the controller. Quanavo then acts as a processor, handling that information only to provide the service on the customer’s documented instructions.

The two roles can apply at the same time. For example, we are the controller of the account and billing information a customer gives us directly, and a processor of the project information their authorised users enter into Quanavo. Where you are unsure which role applies to your information, contact us at privacy@quanavo.com and we will explain.

02

Information we may collect

Depending on how you interact with Quanavo, we may collect:

  • Account identity and contact information, such as name, work email address, job title and telephone number.
  • Company and business information, such as company name, trading details and the projects a company runs in Quanavo.
  • Authentication and security information, such as sign-in records, session information and security events.
  • Project membership and permissions, including company role, which projects a person can access and what they are allowed to do.
  • Support and communications information, including messages, enquiries and the records needed to handle them.
  • Founding 50 and pre-launch signup information, such as the details submitted through those forms.
  • Callback request information, such as name, company, contact details and anything you tell us about your requirements.
  • Billing and subscription information, such as plan, user counts, invoices and payment status. Card details are handled by our payment providers.
  • Usage, device, browser and technical logs, such as pages or screens used, approximate location derived from IP address, device and browser type, and error information.
  • Project data uploaded or entered by authorised users, which may include personal information about a customer’s workforce, contacts or subcontractors.
  • Documents, photographs, site evidence and files added to projects.
  • Field and mobile sync metadata, such as timestamps, sync state and technical information needed for offline working.
  • Information received from integrations, where a customer chooses to enable them.
Quanavo does not ask users to upload unnecessary special-category personal information (for example health or biometric information). Customers decide what information is appropriate to place in their projects, and are responsible for making sure it is lawful, relevant and proportionate for the work being recorded.

03

How we use personal information and lawful bases

We only use personal information where we have a lawful basis to do so. Consent is not the lawful basis for everything we do — most of our processing is necessary to provide the service, to run the business responsibly, or to meet a legal obligation.

PurposeTypical lawful basis
Provide and operate QuanavoPerformance of a contract, or steps taken at the request of the customer.
Create and secure accountsPerformance of a contract, and our legitimate interests in keeping accounts secure.
Operate permissions, project membership and audit recordsPerformance of a contract, and our legitimate interests in operating a secure, accountable service.
Process subscriptions and billingPerformance of a contract, and legal obligations where these apply.
Provide support and respond to enquiriesPerformance of a contract, or our legitimate interests in answering the enquiry.
Operate the Founding 50 list and callback requestsSteps taken at the request of the person, and/or our legitimate interests in responding to business enquiries.
Maintain security, prevent abuse and investigate incidentsOur legitimate interests in protecting the service, and legal obligations where these apply.
Improve Quanavo using product usage informationOur legitimate interests in improving the service, where appropriate and subject to privacy safeguards.
Business-to-business marketing about QuanavoOur legitimate interests, or consent where consent is required. Electronic direct marketing is handled in line with applicable PECR and UK GDPR rules, and you can opt out at any time.
Cookies and similar technologies, including any analyticsConsent where consent is required. See our Cookie Notice.

Where we rely on legitimate interests, we consider whether the processing is necessary and whether it is fair and proportionate to the people affected. Where we rely on consent, you can withdraw it at any time.

04

Customer project data

Customers generally decide why and how their workforce and project personal information is entered into Quanavo. Where Quanavo processes that information only to provide the service on the customer’s instructions, Quanavo acts as a processor and the customer remains the controller.

That processor activity is governed by the applicable Data Processing Agreement or service contract between Quanavo and the customer, which sets out the scope of the processing, the instructions we act on, confidentiality and the handling of sub-processors.

Hosting or processing customer project data does not give Quanavo ownership of it. It remains the customer’s data.

05

Who information may be shared with

We share personal information with categories of recipients where there is a genuine need, including:

  • Cloud hosting, database and file storage providers.
  • Authentication and security service providers.
  • Payment providers, for subscriptions and invoicing.
  • Transactional email, SMS and push notification providers.
  • AI providers, where an authorised Quanavo AI feature requires processing.
  • Integrations a customer chooses to authorise.
  • Professional advisers, such as legal, accounting and insurance advisers.
  • Regulators, courts or law enforcement, where we are legally required to disclose information.
  • Parties to a potential corporate transaction, subject to appropriate protections and confidentiality.

Where a provider acts as our processor or sub-processor, we require appropriate contractual and data protection safeguards, including confidentiality, security obligations and restrictions on using the information for their own purposes.

We do not publish a named provider list here until it is confirmed. Customers who need the current sub-processor position for a specific project can request it at privacy@quanavo.com.

06

AI and personal information

  • AI features may process permitted project information in order to provide the feature that has been requested.
  • Ask Quanavo is permission-scoped: it works within the projects and permissions the person already has, and does not widen access.
  • AI in Quanavo is assistive. It does not independently make consequential commercial or operational decisions — people remain responsible for approvals, commitments and changes.
  • Support AI is logically separate from project intelligence and does not have unrestricted access to customer project information by default.

We do not claim that AI providers never retain any data. Where retention or training terms matter to a customer, we will confirm the position that is contractually in place at the time rather than making general promises here.

07

International transfers

Some service providers may process personal information outside the United Kingdom. Where a restricted transfer takes place, we will use an applicable UK data transfer mechanism together with any other safeguards required by UK data protection law, and we will assess the transfer before relying on it.

You can request information about the transfer position for a specific provider at privacy@quanavo.com.

08

How long information is kept

We keep personal information for as long as we need it for the purpose it was collected, and then delete it or reduce it. Rather than publishing arbitrary periods, we apply the following principles:

  • Account and service information: while it is needed to provide the service, and for an appropriate period afterwards.
  • Billing and legal records: for as long as required by law, including tax and accounting requirements.
  • Support enquiries: for an appropriate period to manage the request and evidence the interaction.
  • Security and audit records: for an appropriate security and accountability period.
  • Customer project data: in line with the service terms, the customer’s instructions and the Quanavo deletion and recovery rules, including any export window stated in those terms.

Exact retention schedules may be documented internally and reviewed periodically. Where our commercial terms already state a specific post-payment or export window, that wording applies and this notice is not intended to contradict it.

09

Security

We use appropriate technical and organisational measures designed to protect personal information, including access controls, role and project permission boundaries, managed cloud infrastructure, backups and recovery processes, and monitoring.

No online service can be guaranteed to be free from risk, so we focus on reducing risk, limiting access and being able to recover project records. You can read more about how access and control work in Quanavo on our Trust & Control page.

10

Your rights

Under UK data protection law you have rights over your personal information:

  • Access — ask for a copy of the personal information we hold about you.
  • Correction — ask us to correct information that is inaccurate or incomplete.
  • Erasure — ask us to delete information where there is no continuing reason to keep it.
  • Restriction — ask us to limit how we use your information in certain circumstances.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Portability — where it applies, receive certain information in a portable format.
  • Withdraw consent — where processing relies on consent, withdraw it at any time.
  • Automated decisions — rights relating to decisions made solely by automated means, where those apply.

If your employer uses Quanavo

If your personal information is in Quanavo because your employer or another customer organisation put it there, that organisation is usually the controller. In that case we may need to pass your request to them, or act on their instructions, rather than deciding the outcome ourselves. We will tell you when this happens.

11

Complaints

If you are unhappy with how we have handled your personal information, please contact us first at privacy@quanavo.com so we can try to put it right.

You also have the right to complain to the UK Information Commissioner’s Office (ICO), the UK data protection regulator. Current contact routes are published on the ICO website.

12

Changes to this notice

We may update this notice as Quanavo develops, as our providers change, or as legal requirements change. The “Last updated” date at the top of the page shows the current version, and where a change is significant we will communicate it through appropriate channels, such as in-product or by email.