Legal
Privacy Policy
This Privacy Policy explains how Recavo Ltd ("Recavo", "we", "us") collects, uses and protects personal data when you use our website and the Recavo platform (the "Service"). We process personal data in line with UK GDPR and the Data Protection Act 2018.
Last updated 29 June 2026
1. Who we are
Recavo Ltd is a company registered in England & Wales and is the controller of personal data we process about our website visitors and customer relationships. Where we process personal data on behalf of a business customer, we act as a processor and the Data Processing Addendum below applies.
2. Data we collect
We collect:
- Identification and contact data — name, business email, role and department.
- Account and usage data — sign-in activity, preferences, and how you use the Service.
- Expense and transaction data — expense and transaction metadata, receipt content (which may include names and other details), and related records.
- Technical data — device, browser and cookie data (see our Cookie Policy).
3. How and why we use data
We use personal data to provide and secure the Service, to authenticate users, to prevent fraud and abuse, to provide support, to comply with legal and regulatory obligations, and to improve the Service. Our lawful bases include performance of a contract, legitimate interests, legal obligation and, where required, consent.
4. Sharing and sub-processors
We share personal data with regulated payments and card issuing partners, and with service providers (sub-processors) who help us run the Service, each under appropriate data-protection terms. We do not sell personal data.
5. International transfers
Where personal data is transferred outside the UK, we ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
6. Retention
We keep personal data only for as long as necessary for the purposes set out above, including to meet legal, accounting and regulatory requirements, after which it is deleted or anonymised.
7. Your rights
Subject to UK data protection law, you have the right to access, correct, delete or restrict processing of your personal data, to object to processing, and to data portability. You may also withdraw consent and complain to the ICO. To exercise your rights, email privacy@recavo.app.
8. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls and audit logging. See our Security page for more detail.
Data Processing Addendum
This Addendum applies where Recavo processes Customer Personal Data on behalf of a business customer (the "Customer") in connection with the Service.
1. Roles and instructions
1.1 The Customer is the controller and Recavo is the processor of Customer Personal Data processed to provide the Service. Recavo processes Customer Personal Data only on the Customer's documented instructions unless required by law.
2. Subject matter and purpose
2.1 Recavo processes Customer Personal Data for the duration of the agreement for the purpose of hosting, securing and otherwise processing Customer Personal Data to provide spend-management, receipt-capture, expense-policy, approval-routing and reporting functionality, including via the AI features described in our Terms of Service.
3. Types of data and data subjects
3.1 Identification and contact data, role and department data, expense and transaction metadata, receipt content (which may include names and other details), and any other personal data the Customer chooses to submit. Data subjects include the Customer's owners, administrators, employees, contractors and other personnel, and individuals named on receipts or in expense records.
4. Confidentiality and security
4.1 Recavo ensures personnel authorised to process Customer Personal Data are bound by confidentiality obligations.
4.2 Recavo implements appropriate technical and organisational measures taking into account the state of the art and the risks of processing.
5. Sub-processors
5.1 The Customer authorises Recavo to engage sub-processors and others added from time to time. Recavo will give notice of intended changes and impose data-protection obligations on each sub-processor substantially equivalent to these terms. The Customer may object to a new sub-processor on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected Service.
6. Assistance and data-subject requests
6.1 Taking into account the nature of processing, Recavo will assist the Customer (by appropriate measures and so far as possible) with: responding to data-subject rights requests; security of processing; personal data breach notification; data protection impact assessments; and prior consultation with the ICO.
6.2 Recavo will promptly forward to the Customer any request it receives directly from a data subject relating to Customer Personal Data, and will not respond except on the Customer's instruction or as required by law.
7. Breach notification and transfers
7.1 Recavo will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to assist the Customer's own obligations.
7.2 Where Recavo transfers Customer Personal Data outside the UK, it will ensure an appropriate transfer mechanism is in place.
8. Return, deletion and audit
8.1 On termination or on the Customer's request, Recavo will (at the Customer's choice) return or delete Customer Personal Data, except to the extent retention is required by law, within a reasonable period.
8.2 Recavo will make available information reasonably necessary to demonstrate compliance with these terms and allow for audits, subject to reasonable confidentiality, frequency, security and cost conditions.
9. Conflict
9.1 In the event of conflict between this Data Processing Addendum and the rest of the Terms of Service in respect of the processing of Customer Personal Data, this Data Processing Addendum prevails.
Contact
Recavo Ltd, registered in England & Wales. Privacy questions and data-subject requests: privacy@recavo.app.