1. Who we are
We are Trove Data Ltd (“Trove”), a company incorporated in England and Wales with registered number 16234512 at Companies House and whose registered office is at 63 Clapton Square, London, United Kingdom, E5 8HE. Trove (“we,” “our,” or “us”) is committed to protecting the privacy and security of personal data. This privacy notice explains how we collect, use, disclose, and safeguard personal data in accordance with the UK Data Protection Act 2018, UK GDPR, and related data protection legislation.
2. How to contact us
For any privacy-related queries, you can contact our Data Protection Officer at dpo@trove.works. We are also registered with the Information Commissioner’s Office (registration number ZC030292).
3. Information we collect
- Information you give us.
You may give us information about you by using the Trove or by corresponding with us by phone, email or otherwise. The information you give us may include:
Display name and other details to your profile information; Contact information such as name, business email address, and phone number, etc; Payment details to the extent that it comprises personal data; Information about your company, e.g. company name and company contacts to the extent that it comprises personal data; Documentation, screenshots or information that would help resolve an issue submitted to our customer support.
- Information we collect about you.
Each time you visit our website or otherwise use Trove we may collect the following information:
Files and documents you upload to the service, including the information they contain. Usage information about how you interact with our platform, including features used and activity within the service. Log and diagnostic information such as error reports and support interactions. Technical information such as IP address, browser and device details, and connection settings.
4. Legal bases for processing your data
We process personal data on the following legal bases:
- Customer onboarding and account management: Contract performance and legal obligation
- Monthly updates on Trove releases: Consent, legitimate interest
- Customer support: Contract, legitimate interest
- System security and monitoring: Legitimate interest
- Service improvement: Legitimate interest
- Processing of accounting and email data: Contract, legitimate interest
5. Security and retention
We make reasonable efforts to provide a level of security appropriate to the risk associated with the processing of your data. We maintain organisational, technical, and administrative measures designed to protect the personal data covered by this Privacy Notice from unauthorised access, destruction, loss, alteration, or misuse. These include:
- Encryption at rest and in transit
- Access controls and authentication
- Regular security assessments
- Staff training
- Incident response procedures
Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
We encourage you to assist us in protecting your personal data. If you hold a Trove account, you can do so by using email authentication or a strong password, safeguarding your password against unauthorised use, and avoiding using identical login credentials you use for other services or accounts for your Trove account.
We retain your personal data for as long as we continue to provide the service to you, or for a period in which we reasonably foresee continuing to provide the services. Even after we stop providing services directly to you and even after you close your Trove account, we may continue to retain your Personal Data to:
- Comply with our legal and regulatory obligations;
- Comply with our tax, accounting, and financial reporting obligations.
6. Data Sharing and Transfers
We may share personal data with:
- Trusted service providers and subprocessors
- Law enforcement or regulatory bodies when legally required
Any international transfers of personal data are protected by appropriate safeguards, such as:
- Standard Contractual Clauses
- Adequacy decisions
- Other legal transfer mechanisms as required by UK GDPR
7. Your Rights
As a data subject, you have a number of rights over your personal data under the Data Protection Laws:
- Right of access: You can request access to a copy of the personal data which we hold about you, as well as details about why and how we use;
- Right of rectification: You can ask us to change or complete any personal data we hold about you which is inaccurate or incomplete;
- Right to be forgotten/erasure: You have a right, under certain circumstances, to ask us to delete any personal data we hold about Please note that there may be situations where we must retain your personal data after a request for erasure where we have a lawful basis for doing so
- Right of restriction: You can ask us to restrict (i.e. prevent) the processing of your personal data where you have objected to our use of it and we have no lawful basis to continue processing your personal data;
- Right to data portability: In certain circumstances, you can ask us to transfer the data we hold about you to another entity. This would be sent in a structured, commonly used, electronic form;
- Right to object: You can object to us using your personal data for particular purposes; and
- Rights related to automated decision-making: You have a right not to be subjected to automated decision making and profiling in certain circumstances. We do not use your personal data in any automated processes to make decisions about you.
To exercise these rights, please contact us using the details in Section 1.
8. What happens if Trove changes hands?
We may, from time to time, expand or reduce our business and this may involve the sale and/or the transfer of control of all or part of our business. Any personal data that you have provided will, where it is relevant to any part of our business that is being transferred, be transferred along with that part and the new owner or newly controlling party will, depending on the lawful basis, be permitted to use that data only for the same purposes for which it was originally collected by us.
In the event that any of your data is to be transferred in such a manner, you will be contacted in advance and informed of the changes.
9. Google Workspace APIs
We utilise Google Workspace APIs to enhance our service functionality. Our use of these APIs involves the following:
9.1 Authentication and Profile Information
We use Google authentication services to facilitate login to our platform. When you log in using your Google account, we collect your email address and profile details from Google to populate your user profile within our application.
9.2 Email Sending Functionality
With your explicit consent, we access the gmail.send scope to enable you to compose and send late payment emails directly within the Trove application. You may also consent to making your email available in workflows, which allows you and authorised members of your organisation to configure Trove to automatically send follow-up communications for unpaid invoices according to schedules you determine.
9.3 Email Reading Functionality
With your explicit consent, we access the gmail.readonly scope to enable you to view past conversations with specific contacts within the Trove application. You may additionally consent to making these emails available to other authorised members of your organisation, allowing your colleagues to view these specific customer conversations. Trove will only access and process emails related to the specified customer contacts and will not read or store emails unrelated to the target customers.
9.4 Use of Data for AI and Machine Learning
Trove does not use any data obtained through Google Workspace APIs to develop, improve, or train generalised AI or machine learning models. We are committed to ensuring that your data is not used for training AI systems that would benefit other users or organisations.
Users may explicitly opt-in to personalisation features that use AI technology, such as email style adaptation which can analyze your previous communications to help compose new emails that better match your writing style. In such cases, any AI or machine learning models created are strictly personalised to your account and organisation only, based solely on your data and with your explicit consent. These personalised models may use data you’ve given us access to with the gmail.readonly scope, but remain specific to your organisation and are never used to improve services for other users.
10. Microsoft 365 / Microsoft Graph APIs
We utilise Microsoft 365 and Microsoft Graph APIs to enhance our service functionality. Our use of these APIs involves the following:
10.1 Authentication and Profile Information
We use Microsoft identity services (Azure Active Directory / Microsoft Entra ID) to facilitate login to our platform. When you sign in using your Microsoft account, we collect your email address and basic profile details provided by Microsoft Graph to populate your user profile within our application.
10.2 Email Sending Functionality
With your explicit consent, we access the Microsoft Graph permissions required to send email on your behalf (such as Mail.Send). This enables you to compose and send late-payment emails directly within the Trove application. You may also consent to making your mailbox available in automated workflows, allowing you and authorised members of your organisation to configure Trove to automatically send follow-up communications for unpaid invoices according to schedules you determine.
10.3 Email Reading Functionality
With your explicit consent, we access the Microsoft Graph permissions required to read specific emails (such as Mail.Read or Mail.ReadBasic) to allow you to view past conversations with designated contacts within the Trove application. You may additionally consent to making these relevant emails available to other authorised members of your organisation so your colleagues can view specific customer conversations. Trove will only access and process emails related to the specified customer contacts and will not read or store emails unrelated to those customers.
10.4 Use of Data for AI and Machine Learning
Trove does not use any data obtained through Microsoft 365 or Microsoft Graph APIs to develop, improve, or train generalised AI or machine-learning models. Your data is not used to train AI systems that would benefit other users or organisations.
Users may explicitly opt in to personalisation features that use AI technology, such as email style adaptation that can analyze your previous communications to help compose new messages aligned with your writing style. In such cases, any AI or machine-learning models created are strictly personalised to your account and organisation only, based solely on your data and with your explicit consent. These personalised models may use data accessed via permissions such as Mail.Read, but remain specific to your organisation and are never used to improve services for other users.
11. Making a complaint
If you have concerns about our data processing, please contact us first. You also have the right to complain to the Information Commissioner’s Office (ICO):
Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF Website: https://www.ico.org.uk
12. Changes to This Notice
We may change this privacy notice from time to time (for example, if the law changes). We recommend that you check this page regularly to keep up-to-date. If we make any material changes to the manner in which we process and use your personal data, we will contact you to let you know about the change.
13. Cookie Policy
Our cookie policy is available separately at https://trove.works/cookie-notice.