Citrevo / Legal
Privacy Policy
What Citrevo collects, why it is used, where AI providers are involved, and how to exercise your rights. Includes our cookie and browser-storage notice.
Effective and last updated: · Version 2026-09-27.2
1. Who is responsible for your information
Citrevo is operated by RAXZ LTD. We are the controller of personal information used to operate Citrevo, manage accounts, produce visibility reports and handle enquiries. This notice covers visitors, users, business contacts and people whose public business information appears in a scan.
RAXZ LTDRegistered in England and Wales, company number 17271145.
Registered office: Ground Floor, Radley House, Richardshaw Road, Leeds, United Kingdom, LS28 6LE.
Email: [email protected] · raxz.net
For privacy questions, rights requests or complaints, email [email protected] with “Citrevo privacy” in the subject, or write to our registered office.
2. Information we collect and its sources
- Account information you provide: email address, account identifier, display name where supplied, account memberships and sign-in/session records.
- Scan inputs: website address, business or trading name, aliases, category, services, customer geography and corrections you make to discovered details.
- Public-source information: text and metadata from the public webpage you submit, public business details, source URLs and content referenced in AI responses. This can identify sole traders or named business representatives even when published openly.
- Generated and operational records: questions, AI answers, citations, mention/recommendation matches, report summaries, diagnostics, any enabled page captures, timestamps, scan status, provider usage and error records.
- Enquiries and order records: contact information, messages, interest in weekly reports or expert help, requested offers, order references, acceptance records and any payment status needed for an enabled purchase. Live payments are not enabled in the current release.
- Technical information: IP/network information, browser and request details, access times, security and service logs, and essential cookies or browser-storage records. Hosting and authentication systems can receive IP addresses even where the scan-intake system uses a hashed network identifier.
Sources are you and authorised account users, public websites, AI/API providers, our authentication and hosting systems, and payment providers if checkout is enabled. Do not enter private records, credentials, sensitive personal information or data about children. If such information appears inadvertently, contact us so we can assess restriction or removal.
3. Why we use it and our lawful bases
- Provide your account, checks and reports
- We use account and scan information to perform our contract with you or take steps you request before a contract. Where you represent a company rather than contracting personally, our legitimate interest is providing and administering that company’s service.
- Analyse public business visibility
- Our legitimate interest is providing relevant, evidence-led business research and checking report accuracy. We consider the nature of the public information, its relevance, reasonable expectations and potential effects on individuals. Public availability does not remove your data-protection rights.
- Protect and operate the service
- Our legitimate interests include preventing abuse, authenticating users, protecting accounts, diagnosing faults, controlling provider costs and maintaining a reliable service.
- Respond to enquiries and requests
- We rely on steps requested before a contract, performance of a contract, or our legitimate interest in answering business enquiries. Responding to an expert-help or weekly-report enquiry does not automatically subscribe you to general marketing.
- Meet legal requirements and resolve disputes
- We use necessary records to comply with legal obligations, including applicable accounting and data-protection requirements, and for our legitimate interest in establishing, exercising or defending legal claims.
- Optional marketing or non-essential tracking
- Where introduced and required by law, these require a separate choice and valid consent. They are not a condition of using a free scan or creating an account. You can withdraw consent without affecting earlier lawful processing.
You do not have to provide information, but we cannot supply an account without an email address or produce a meaningful report without the relevant business details. We do not sell personal information or use scan submissions for advertising profiles.
4. AI processing and automated analysis
When a scan is enabled, Citrevo generates business-discovery questions from the selected category, services and customer geography and sends those questions to an AI service. The current integration routes requests through OpenRouter to the configured model/provider; the initial configuration uses Perplexity Sonar. A question can contain personal information if the submitted business details themselves identify a person.
We do not deliberately include your account email, sign-in credentials or payment details in those AI prompts. Public business names, personal names or website details can nevertheless appear in provider answers, citations and report evidence. Providers receive request content and technical information needed to process the request.
AI providers have their own processing terms, retention settings and subprocessors. We do not promise zero provider retention, exclusively UK processing or a universal exclusion from provider model training. Only submit public business information suitable for this analysis. See also Perplexity’s privacy notice.
Our automated matching and summaries assess business visibility. We do not use them to make decisions about individuals that have legal or similarly significant effects. You can challenge a match or request a human review of a concern by contacting us.
6. Locations and international transfers
The current Supabase project is configured in its London region, the SMLL application is deployed in its EU Central region, and our Amazon SES sending endpoint is in EU West (Ireland, eu-west-1). Email is also handled by the recipient’s email provider. Regional configuration does not guarantee that every support, delivery, AI-processing or backup operation stays in that location. Our providers may process information in other countries, including the United States.
UK data-protection law requires a valid transfer mechanism for restricted transfers, such as applicable UK adequacy regulations or appropriate contractual safeguards, together with any required assessment and supplementary protections. The mechanism depends on the recipient and processing involved; a provider’s privacy notice alone is not a transfer safeguard.
Contact us for details of the recipients, processing locations and safeguards applicable to your information, or to request a copy of relevant safeguards with confidential information removed where appropriate.
7. How long information is kept
We keep personal information for the purpose for which it was collected, rather than treating it as a permanent archive. Retention depends on the type of record, whether your account or request remains active, the need to explain a report, and applicable legal or dispute requirements:
- Accounts and saved reports: while needed to provide your account and requested report history. When you request closure or deletion, we assess which records can be removed and which must be retained for a specific lawful reason.
- Anonymous checks and supporting evidence: for delivery, recovery, investigation of errors and legitimate disputes. Public business facts may remain personal information and are subject to the same necessity assessment.
- Enquiries: while dealing with the enquiry and any resulting relationship or reasonably anticipated follow-up; you can ask us to stop follow-up or delete it where applicable.
- Transactional email information: as needed to deliver and troubleshoot authentication messages, handle bounces or complaints and prevent abuse, subject to the applicable Supabase, AWS and recipient-provider retention arrangements. The expiry of a sign-in link does not mean that the message or delivery records are immediately erased.
- Security and technical records: as needed to detect abuse, investigate faults or incidents and protect legal claims. Scan-intake rate-limit records older than 24 hours are removed during subsequent intake processing; this is not a 24-hour deletion promise for hosting logs or other records.
- Orders, consent and accounting records: for the applicable statutory accounting period and where necessary to evidence an agreement, payment, cancellation or legal claim.
There is no universal automatic expiry for all report or account records in this release. Deletion requests are handled through the contact above. Any information retained after a request must have a continuing lawful purpose; we will explain relevant exceptions. Backup removal follows the applicable provider’s backup lifecycle, and restricted records may remain there until overwritten. Ask us for the retention position for a particular record.
9. Your data-protection rights
Depending on the circumstances, you can request access to your personal information, correction, erasure, restriction of processing and a portable copy of information you provided. You can object to processing based on legitimate interests and object to direct marketing at any time. Where consent is the basis, you can withdraw it.
These rights can apply to personal information obtained from public websites or generated in reports, not just to registered users. Tell us enough to locate the information, such as a website, report reference or relevant account email. We may need proportionate information to verify identity or authority, but please do not send identity documents unless requested.
We normally respond within one month. Where the law permits more time for a complex or numerous request, we will explain the extension. Requests are normally free; any permitted fee or refusal will be explained. Some rights have exceptions, including records required by law or needed for legal claims.
Where appropriate, we will consider corrections, annotations, restrictions or removal of disputed information and notify relevant recipients as required. We cannot directly alter an independent website or AI provider’s records, but can explain the source and the steps within our control.
10. Security and children
We use measures such as encrypted connections, authenticated account access, report-access tokens and restricted administrative access. No online service can guarantee absolute security. Keep access links and email accounts secure, and contact us promptly if you believe personal information or a report has been exposed.
Citrevo is intended for adults using business information, not for children. Do not submit information about children. If you believe we have collected it, contact us so we can investigate and take appropriate action.
11. Complaints and policy updates
Please contact us first if you have a privacy concern so we can investigate. We will acknowledge a data-protection complaint within 30 days and respond without undue delay. You can also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. You do not have to contact us before exercising your right to complain to a regulator.
We may update this notice as the service or law changes. The date at the top identifies this version. We will bring material changes to your attention where appropriate and seek a new choice where required, rather than treating continued use as consent to unrelated processing.
For the agreement governing use of the service, see our Terms of Service.