Legal

Privacy Policy

How we collect, process and protect personal data. Written in plain English.

Last updated: 26 July 2026

Who we are

Mortevo Audit ("we", "us") provides compliance review software for UK mortgage firms. When your firm uses Mortevo Audit, we act as a data processor for the personal data you enter into the platform. Your firm is the data controller for that data. When you visit our public website or contact us directly, we act as a data controller.

What we collect

Account data

  • Name, email address, role, organisation.
  • Authentication data (hashed passwords, MFA factors).

Usage data

  • Log records of actions taken in the platform (audit trail).
  • Technical metadata: IP address, browser, timestamps.

Customer content

  • Case, review, finding and evidence data your firm creates in the platform.

How we use it

  • To operate the service you or your firm has signed up for.
  • To keep the service secure — detecting suspicious sign-ins, tampering, or abuse.
  • To meet our own legal and regulatory obligations.
  • To communicate service and security updates.

We do not sell personal data. We do not use customer content to train third-party AI models.

Legal bases (UK GDPR)

  • Contract — to provide the service you or your firm signed up for.
  • Legitimate interest — for security, fraud prevention and product improvement.
  • Legal obligation — where the law requires us to retain or disclose information.
  • Consent — for optional communications, which you can withdraw at any time.

AI processing

Some features use large language models to summarise regulatory content, draft findings, or suggest remediation. AI processing happens through vetted providers, is scoped to the specific task, and results are always reviewable by a human. AI outputs are treated as suggestions and cite the underlying regulatory source where possible.

Sub-processors

We use the following categories of sub-processor. A current list is available on request from privacy@mortivoaudit.co.uk.

  • Cloud infrastructure and managed database hosting (UK/EEA).
  • Transactional email delivery.
  • AI model providers (scoped to specific features).
  • Error monitoring and observability.

Retention

  • Account data is retained while your account is active and for a defined period after closure, to meet regulatory record-keeping requirements applicable to UK mortgage firms.
  • Audit records are retained for the minimum period required by law and by your firm's own retention policy.
  • Data on legal hold is preserved until the hold is released, regardless of scheduled retention.

Your rights

Under the UK GDPR you have the right to access, correct, delete, restrict or object to processing of your personal data, and to data portability. Because your firm is the controller of most data you interact with in the platform, please raise these requests with your firm first. For data we hold as a controller (public website, direct contact), email privacy@mortivoaudit.co.uk.

You have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

Cookies

We use strictly necessary cookies for authentication and session management. We do not use advertising or cross-site tracking cookies.

International transfers

Primary storage is in the UK/EEA. Where a sub-processor operates outside the UK/EEA, we rely on the UK International Data Transfer Agreement or equivalent safeguards.

Changes

We will post material changes to this policy on this page and notify account owners by email.