DRYV-AI Ltd (“we”, “us”, “our”) is committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, store, share, and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
1. Company Information
Legal Entity: DRYV-AI Ltd
Registered Address: 203 West Street, Fareham, PO16 0EN, Hampshire, United Kingdom
Under UK Data Protection law, our role depends strictly on our relationship with the data:
As a Data Controller: We act as a Data Controller for the personal data of our direct business clients, prospects, website visitors, and vendors (e.g., your business email, billing details, and contract information). We determine the purposes and means of processing this data.
As a Data Processor: We act strictly as a Data Processor when we provide our "Done For You" marketing automation platform and services to our corporate clients. In this scenario, our business clients are the Data Controllers of their own consumers' data (their venue guests and patrons). We handle, store, and transmit that consumer data (such as sending review requests and SMS promotions) exclusively on behalf of, and under the strict documented instructions of, our clients.
3. Personal Data We Collect
We may collect and process the following categories of personal data:
Identity Data: First name, last name, and business trading names.
Contact Data: Mobile phone numbers, email addresses, and physical business addresses.
Technical & Usage Data: IP addresses, device types, SMS and email delivery metrics, open rates, and click-through interactions.
Marketing & Communications Data: Individual marketing preferences, opt-in records, review responses, and direct feedback.
4. How We Collect Data
We collect personal data through the following methods:
Direct Interactions: When corporate clients sign up for our services, contact our support team, or fill out forms on our website.
Automated Systems on Behalf of Clients: When consumers opt in via digital web forms, table-side QR codes, or landing pages designed by us under our clients’ instructions.
5. Lawful Basis for Processing
We only process personal data when we have a valid legal framework to do so under Article 6 of the UK GDPR:
Consent: For sending promotional text messages and marketing emails to consumers who have explicitly opted in.
Contractual Necessity: To process data required to deliver, manage, and bill our services to our direct business clients.
Legitimate Interests: For standard, non-intrusive operational review requests following a business transaction, and to improve our software systems.
6. Marketing and Review Automation
All automated communications deployed through our platform adhere strictly to UK PECR regulations:
Strict Distinction: Our systems separate operational review requests from promotional campaigns. Promotional content is only delivered where explicit opt-in consent exists.
Opt-Out Mechanisms: Every marketing SMS or email deployed via our systems features a clear, automated, and cost-free opt-out mechanism (e.g., replying "STOP").
Suppression: Opt-out requests trigger immediate, system-wide automation suppression to prevent further messaging to that individual.
7. Data Sharing and Third-Party Disclosures
We do not sell, rent, lease, or share personal data with third parties for their own independent marketing purposes.
To provide our services, we share data exclusively with trusted cloud sub-processors who meet strict UK GDPR data security standards.
Twilio / Telephony Carrier Partners (For mobile network SMS routing).
Mobile Carrier Compliance:
No mobile phone numbers or SMS consent data collected on behalf of our clients or by our company will be shared, sold, or rented to third parties or affiliates for marketing or promotional purposes under any circumstances.
8. Data Storage, Transfers, and Security
Security: We utilise industry-standard, secure cloud environments featuring advanced encryption protocols, firewalls, and strict access controls (including mandatory Multi-Factor Authentication for system operators) to protect data against unauthorised exposure.
International Transfers: Where data is processed via global sub-processors (such as US-based data centres), we ensure equivalent legal protection frameworks are active, including the utilisation of Standard Contractual Clauses (SCCs) and the UK Extension to the EU-US Data Privacy Framework.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or billing requirements. Client data is maintained during active subscriptions and safely purged upon contract termination. Consumer data handled on behalf of clients is retained or deleted based on the direct parameters instructed by our corporate clients.
10. Your Individual Legal Rights
Under the UK GDPR, individuals have powerful data rights. Depending on the context of the processing, you have the right to:
Access your data via a Subject Access Request.
Rectify inaccurate or incomplete data.
Erase your personal data ("The Right to be Forgotten").
Object to or restrict processing, particularly for direct marketing.
Withdraw Consent at any time where processing is based on consent.
To exercise any of these rights, or if you are a consumer looking to purge your details from one of our client's lists, contact us directly at [email protected]. You also have the right to lodge a formal complaint at any time with the Information Commissioner’s Office (the ICO) (www.ico.org.uk).