Renew Gas Cert

Privacy Notice — Version 1.1

Version date: 10 August 2026

Who we are

Renew Gas Cert is provided by Ian Cooke trading as EvenAI, 11 Church Road, Great Plumstead, Norwich, NR13 5AB, United Kingdom. Company number: N/A.

Privacy and data-protection contact: [email protected]. General service contact: [email protected]. General enquiries: [email protected].

Your right to object when we rely on legitimate interests

Where we process your personal information on the basis of our legitimate interests, you have the right to object to that processing. Send an objection to [email protected]. We will stop the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for the establishment, exercise or defence of legal claims.

This right is separate from any right to object to direct marketing. Renew does not treat subscription acceptance as consent to direct marketing.

1. Our role

Ian Cooke trading as EvenAI acts as controller for personal information used for Renew Hub account administration, billing, security, service management, support and legal/compliance purposes.

Where a Renew Hub business customer uploads or manages personal information about its own clients, contacts, engineers or sites for that customer's business purposes, the business customer is normally the controller and EvenAI acts as processor under the Renew Gas Cert Data Processing Schedule v1.1.

2. Information we use as controller

Depending on how you interact with Renew Hub, we may use business account-holder and authorised-user names; business contact and organisation details; login, authentication, role and account-security information; subscription, seat, invoice and payment-status metadata; support correspondence; service usage, audit, security and incident records; device/network information reasonably required for security and service operation; and versioned agreement-acceptance records.

We do not need or intend to collect full payment-card credentials directly where Stripe provides the payment interface.

3. Customer-controlled client data

If your organisation uses Renew Hub to manage renewal information about its own clients, contacts, engineers or sites, your organisation determines the purpose and lawful basis for that information and is normally the controller.

Depending on enabled service functions, the information may include client/contact name, email address and telephone/WhatsApp number; site/premises name or address; certificate/compliance type and renewal/expiry dates; engineer/account contacts; reminder preferences; and communication/service-delivery metadata.

Questions or rights requests about customer-controlled client data should normally be directed to the relevant Renew Hub business customer. We assist that customer as required by the Data Processing Schedule.

4. Why we use personal information

We use personal information only where we have an appropriate lawful basis. Depending on the activity, this may include:

  • Contract: where processing is necessary for an individual or sole-trader subscriber's contract or requested pre-contractual steps.
  • Legitimate interests: for proportionate B2B account administration, service security, support, governance/acceptance evidence, legal-claims handling and fraud/payment reconciliation, subject to the applicable balancing assessment.
  • Legal obligation: where a specific applicable UK legal requirement requires processing or retention.

No direct-marketing lawful basis is created by accepting the Renew subscription. Any future direct marketing requires its own UK GDPR and PECR assessment.

5. Service providers and recipients

Cloudflare

Cloudflare Workers provide the application runtime and Cloudflare D1 stores Renew Portal tenant, user, client, site, certificate and reminder data.

Resend (Plus Five Five, Inc.)

When managed email is enabled, Resend handles transactional and renewal-reminder email. This can include recipient email/name, certificate type, site name, expiry date and message content.

Meta / WhatsApp Business Cloud API

WhatsApp is disabled/fail-closed for the first Phase 11 participant. If enabled in future after the separate verification gate, reminder data may include the recipient WhatsApp number, customer name, certificate type, site name and expiry date.

Stripe

Stripe handles subscription/payment collection and receives subscribing business/admin contact, checkout and subscription metadata. The current Renew implementation does not send participant end-client certificate/site/reminder records to Stripe.

We may also disclose information to professional advisers, regulators, courts or authorities where necessary and lawful.

6. International transfers

Renew uses service providers that may process personal information outside the UK.

The current production Cloudflare D1 database has no jurisdiction restriction and is running in Cloudflare's ENAM — Eastern North America region, with read replication disabled. We do not claim that this D1 database is hosted in the UK or EU.

Where a restricted transfer occurs, the applicable provider contractual and transfer safeguards are used as required by UK data-protection law. The current provider/account transfer evidence is maintained as part of Renew's release and governance records.

Resend states that its primary processing operations take place in the United States. Stripe also operates an international processing environment. WhatsApp remains disabled for participant 1 unless its separate Meta account/entity/transfer verification is completed.

7. How long we keep information

  • Active account/user profile: while the service relationship is active.
  • Closed profile data not needed for legal/billing evidence: delete or anonymise within 24 months of closure.
  • Contract/Terms/Privacy/DPA acceptance evidence: 6 years after the relevant customer contract ends.
  • Billing/accounting evidence: for the current sole-trader model, at least 5 years after the 31 January Self Assessment submission deadline for the relevant tax year, and longer where required by a late return, HMRC enquiry or other applicable legal requirement.
  • Ordinary support correspondence: 24 months after closure.
  • Routine authentication/security logs: 12 months.
  • Material incident/security evidence: up to 6 years after incident closure where actually necessary for legal/compliance evidence, retaining only the minimum necessary evidence.
  • Failed/abandoned signup with no customer relationship: 90 days unless a documented fraud/security investigation justifies longer.
  • Customer-controlled client/certificate data: active relationship plus controlled return/deletion period; target deletion from the active service within 30 days after a valid termination/deletion instruction.
  • Residual D1 recovery history: up to 7 days under the currently verified production Cloudflare D1 Time Travel lifecycle. This window must be re-verified after a Workers plan, D1 database or material Cloudflare configuration change.

These are operational maximums, not a reason to keep information unnecessarily. Information is erased or anonymised earlier where the purpose has ended and no other documented purpose or legal requirement justifies continued retention.

A database restore must not be used to deliberately resurrect customer data that should remain deleted except for a documented legitimate recovery purpose. If a restore reintroduces data subject to a valid deletion instruction, that deletion must be reapplied promptly.

8. Security

We use technical and organisational measures designed to protect information against unauthorised access, loss, alteration or disclosure. Measures include authentication and role restrictions, tenant-isolation controls, audit/evidence controls, protected provider credentials, backup/recovery controls and incident-management processes appropriate to the service and risk.

No internet or software service can promise absolute security.

9. Your other rights

Depending on the circumstances and lawful basis, you may also have rights concerning your personal information, including access, correction, deletion, restriction, portability and rights relating to certain automated decision-making.

Where Ian Cooke trading as EvenAI is controller, send requests to [email protected]. Where information is controlled by a Renew Hub business customer, requests should normally be made to that customer.

10. Data-protection complaints

If you believe we have not handled your personal information correctly, contact [email protected]. We maintain a process for data-protection complaints and will acknowledge a complaint within the period required by applicable law.

You also have the right to complain to the UK Information Commissioner's Office (ICO). See the ICO's Make a complaint service.

11. Information obtained from another source

Where we act as controller and obtain personal information from someone other than the individual, we provide required privacy information within the applicable period unless a lawful exemption applies. Where we act only as processor, the business customer remains responsible for its controller transparency duties, with our assistance where required.

12. Changes to this notice

Material changes are versioned. The version presented to and accepted by a Renew customer is recorded, and historical versions/acceptance evidence are preserved where relevant to contractual and audit integrity.