Privacy Policy

Last Updated: 16 July 2026

1. Introduction

Welcome to Provero ("we", "us", "our"), the trading name of Horizon Landings Limited.

We are committed to protecting and respecting your privacy. This policy explains how we collect, use, store and protect personal data when you sign up for and use Provero's data validation, verification, fraud prevention, risk signal and related services, including our website, platform and API.

This policy is designed to comply with UK data protection laws, including the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

2. Who We Are

Horizon Landings Limited, trading as Provero, is the controller responsible for your personal data where we act as controller.

Company number: 07675128
Registered address: Charlotte House, 500 Charlotte Road, Sheffield, England, S2 4ER
ICO registration reference: Z2763280

In some circumstances, particularly where our customers submit personal data to Provero for validation or verification checks, Provero acts as processor and the customer acts as controller. This is explained further in Section 4.

If you have any questions about this privacy policy or our data protection practices, please contact us using the details in Section 15.

3. What Information We Collect

3.1 Account and contact information

When you register for a Provero account, use our platform, contact us, or purchase services from us, we may collect:

  • your name;
  • business email address;
  • company or organisation details;
  • account login credentials;
  • billing and payment information;
  • records of correspondence if you contact us;
  • usage, account activity and support information;
  • technical information relating to your use of the website, platform or API.

Personal email addresses may be used to create an account, but Provero is intended for business use.

3.2 Data submitted for validation or verification

When you use Provero's services, you may submit personal data relating to third parties, either by uploading a file, using the platform, or making requests via our API.

Depending on the check or service used, this may include:

  • names;
  • phone numbers;
  • email addresses;
  • postal addresses;
  • IP addresses;
  • device, browser or user-agent information;
  • identity, KYC, age verification, fraud, risk, telecoms, SIM swap, validation, enrichment or suitability information;
  • other data points submitted by or on behalf of the customer for a selected check.

This category of data is handled differently from account and contact information. See Section 4.

4. Data Submitted for Validation — Our Role as Processor

Where you submit personal data relating to third parties for validation, verification, enrichment, fraud, risk, identity, KYC, age, telecoms, SIM swap or similar checks, Provero generally acts as processor and you, our customer, act as controller.

We process this data to run the checks you have requested, return results, provide the service, support the operation of the platform and comply with our contractual obligations.

Customer Data submitted for checks is processed in an automated manner. We do not routinely manually review Customer Data submitted for checks. Access is restricted to authorised personnel and only where necessary to provide support, investigate errors, maintain security, comply with legal obligations, enforce our terms, or as otherwise agreed with you.

We may use account information, service usage information, technical and operational metadata, customer feedback, and aggregated or anonymised information to operate, secure, monitor, develop and improve Provero.

We do not use identifiable Customer Data submitted for checks to train general-purpose artificial intelligence models or for purposes unrelated to providing, securing, supporting and improving the services, unless expressly agreed with the customer.

To perform certain checks, we may reference third-party data sources relevant to that check, such as telecoms data, validation data, fraud prevention data, breach data, identity data or other relevant datasets. These providers process data only as necessary to return a result to Provero and are not permitted to use it for their own unrelated purposes.

4.1 API integrations

Where you integrate with Provero via our API, for example by embedding a check into a website form, landing page, customer journey or sign-up flow, the same processor/controller position applies.

Depending on the check called, an API request may include data such as a name, email address, phone number, address, IP address, user agent, your own reference tag for the request, campaign information, or other technical metadata required to generate and return the requested result.

This data is used to generate and return the requested result via the API and is handled under the same processing and retention terms as other Customer Data submitted for checks.

4.2 Customer responsibilities

If you submit personal data to Provero for validation or verification, whether by file upload, platform use or API, you are responsible for ensuring that you have a valid lawful basis under applicable data protection law to do so.

You are also responsible for providing any required privacy notices, obtaining any required consents or permissions, and ensuring that your use of Provero is lawful, fair and transparent to the individuals concerned.

This obligation is also set out in our Terms of Service, which forms the binding agreement between Provero and its customers.

Provero's checks provide decision-support signals only. We do not make automated decisions that produce legal effects or similarly significantly affect individuals.

Any decision to accept, reject, suppress, onboard, challenge, route, score, contact or otherwise act on an individual's data, including using Provero's outputs as part of that decision, is made by the customer and not by Provero.

4.3 Data subjects whose data has been submitted by a customer

If you are an individual whose personal data has been submitted to Provero by one of our customers, the customer is usually the controller responsible for that data.

You should contact the customer directly if you have questions about why your data was submitted, what lawful basis they relied on, or how they used the result.

You may also contact us using the details in Section 15 and we will assist where appropriate.

4.4 Data Processing Agreements

If you have a separate Data Processing Agreement with Provero, for example as an enterprise customer, that agreement forms part of your contractual terms with us and will apply to the processing of Customer Data.

5. Demo, Sandbox and Restricted Verification Checks

Where you submit your own information through a Provero demo, sandbox, "test this" page or similar non-production feature, Provero may process that information to run the selected demo check and return a test result.

This may include age verification, KYC, identity, SIM swap, telecoms risk, fraud prevention or similar verification checks.

These demo checks are provided for evaluation and demonstration only. They are not intended for live onboarding, regulated KYC or AML compliance, legal age-restricted sales, credit decisions, employment screening or any other production or legally significant decision.

Where you submit information through a demo or test page, you confirm that you are submitting your own information or information you are lawfully authorised to use for that purpose.

Depending on the context, we rely on your explicit request to perform the demo check, performance of a contract or pre-contractual steps, and/or our legitimate interests in demonstrating and providing our services.

Certain checks, including age verification, KYC, identity, SIM swap, telecoms risk and other higher-risk or regulated checks, may require Provero's prior approval before they are enabled for live, API or production use.

Before enabling access to restricted checks, Provero may require you to provide details of your intended use case, customer journey, lawful basis, privacy notices, consent wording where applicable, permission wording, data retention approach, decisioning process and any other compliance information reasonably required by Provero or its suppliers.

You must not use restricted checks on consumers, end users or other individuals unless you have all required lawful bases, notices, consents, permissions, authorisations and safeguards in place for that use case.

Where a check requires explicit consent, permission or specific customer-facing wording, you must ensure that such wording is clear, specific, informed, unambiguous and presented before the relevant data is submitted or checked.

Provero may refuse, restrict, suspend or withdraw access to restricted checks where Provero reasonably believes that your use case, customer-facing wording, lawful basis, consent process, notices, safeguards or compliance arrangements are inadequate, incomplete, misleading, unlawful or create legal, regulatory, supplier, security, reputational or commercial risk.

6. How We Use Your Information and Our Lawful Basis

Where we act as controller, we use personal data for the following purposes.

6.1 To provide our services

We use your account and contact information to create and manage your account, process payments, provide access to Provero, deliver checks, manage billing, provide customer support and administer your use of the services.

Lawful basis: Contract. Processing is necessary for the performance of a contract with you or to take steps before entering into a contract.

6.2 To operate, secure and protect the services

We may process account activity, API usage, request metadata, security logs, fraud-prevention signals, audit records and operational information to monitor service performance, prevent misuse, investigate errors, enforce limits, maintain billing records, support customers and protect Provero, our customers, suppliers and individuals.

Lawful basis: Legitimate interests. We have a legitimate interest in operating, securing, administering and protecting our services, preventing misuse and fraud, maintaining accurate operational records and meeting supplier and customer support requirements.

6.3 To send service communications

We may send you service-related communications, including account notices, security alerts, billing notices, API updates, outage information, changes to our services, changes to our terms and other administrative messages.

Lawful basis: Contract and legitimate interests. These communications are necessary to provide, administer and protect the services.

6.4 To send B2B marketing and product communications

We may use your business contact details to send information about Provero's products, services, updates, features, use cases, offers and related content that we believe is relevant to you and your business.

This may include onboarding emails, product updates, usage guidance, feature announcements, educational content and relevant commercial communications about Provero.

Every marketing email includes a clear way to unsubscribe or opt out. You can object to direct marketing at any time and we will stop sending non-essential marketing communications to you.

Lawful basis: Legitimate interests. We have a legitimate interest in promoting our B2B services to customers, users and prospects. We believe this marketing is relevant and would be reasonably expected in a B2B context. We have balanced our interests against your rights and freedoms.

6.5 To improve our services

We may analyse usage patterns, support requests, product performance, operational data, customer feedback and aggregated or anonymised results to understand how our platform is used and to improve our services.

Where personal data is involved, we only process it in accordance with the applicable customer instructions, contractual terms and data protection law.

Lawful basis: Legitimate interests. We have a legitimate interest in understanding how our platform is used, improving our services and developing better functionality for customers.

6.6 For advertising and marketing analytics

Where you consent via our cookie banner, we use tracking technologies from providers such as LinkedIn and Meta on our website to measure the effectiveness of our advertising and understand visitor engagement.

This may include the LinkedIn Insight Tag, Meta Pixel or similar technologies. See our Cookie Policy for further details of the technologies we use and how to manage your preferences.

Lawful basis: Consent. This processing relies on your consent given via our cookie banner in accordance with UK PECR rules on non-essential cookies. You can withdraw consent at any time via our cookie settings tool.

6.7 To comply with legal obligations

We may process personal data where necessary to comply with legal, accounting, tax, regulatory or reporting obligations.

Lawful basis: Legal obligation.

7. Data Storage and Security

Account and platform data is hosted using Amazon Web Services infrastructure in the EU, currently the Ireland region.

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, encryption at rest, access controls, credential controls, logging, monitoring and operational security measures.

Our platform is designed with ISO 27001 information security principles in mind. Access to personal data is restricted to authorised personnel only.

While we take data security seriously, no system can be guaranteed to be completely secure.

If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay in accordance with our legal obligations, and will inform affected customers or data subjects where required to do so.

8. International Data Transfers

Our primary hosting infrastructure is located in the EU, currently Ireland.

The UK government recognises the European Economic Area as providing an adequate level of protection for personal data, so no additional safeguards are required for transfers from the UK to the EEA.

Where any of our service providers store or process personal data outside the United Kingdom or a country recognised as adequate by the UK government, we rely on appropriate safeguards, such as the UK Extension to the EU-U.S. Data Privacy Framework, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or other safeguards permitted under applicable data protection law.

9. Data Retention

We retain account and contact information for as long as necessary to provide our services to you and for a reasonable period afterwards to meet legal, accounting, tax, security, dispute-resolution and administration requirements.

Customer Data submitted for validation, including uploaded files, API payloads and validation results, is retained according to the retention settings configured in your Account.

Where configurable retention settings are available, you are responsible for selecting the retention period appropriate for your use case, lawful basis and compliance obligations.

You may delete submitted Customer Data or validation results through your Account where this functionality is available, or by contacting us using the details in Section 15.

Where no custom retention setting has been configured, we apply our standard default retention period of 3 months, after which the relevant Customer Data and validation results are deleted or anonymised.

If your Account is suspended or terminated, Customer Data submitted for validation will continue to be handled according to the applicable retention setting unless we agree or are legally required to delete it earlier.

We may retain limited account, billing, payment, security, audit, operational, legal or support records for longer where necessary to operate the services, evidence transactions, prevent misuse, comply with legal obligations, resolve disputes, enforce our Terms of Service or administer the services.

These records are separate from Customer Data submitted for validation.

If you have received marketing communications based on our legitimate interests, we will retain your email address for this purpose until you object or opt out, or until we determine the data is no longer necessary for our legitimate interests.

After applicable retention periods expire, personal data will be securely deleted or anonymised.

10. Your Data Protection Rights

Under UK data protection law, you have rights including:

  • Right of access: to ask for copies of your personal data.
  • Right to rectification: to ask us to correct inaccurate information or complete incomplete information.
  • Right to erasure: to ask us to erase your personal data in certain circumstances.
  • Right to restriction of processing: to ask us to restrict the processing of your data in certain circumstances.
  • Right to object: to object to processing where we rely on legitimate interests, including direct marketing.
  • Right to data portability: to ask that we transfer the data you gave us to another organisation, or to you, in certain circumstances.
  • Right to withdraw consent: where we rely on consent, you may withdraw that consent at any time.

You can object to direct marketing at any time and we will stop processing your personal data for that purpose.

To exercise your rights, please contact us using the details in Section 15. We will respond to your request within one month, unless the law allows us to extend this period.

These rights apply to data where we act as controller.

Where we act as processor for Customer Data submitted by one of our customers, the relevant customer is usually responsible for responding to data subject rights requests. If we receive such a request directly, we may refer the request to the relevant customer or assist them in responding, where appropriate.

Where you are a Provero customer, you may also delete Customer Data submitted for validation through your Account where this functionality is available, or by contacting us. Where we process Customer Data as your processor, we will handle deletion requests in accordance with your instructions, our Terms of Service, any applicable Data Processing Agreement and applicable law.

11. Cookies

Our website uses cookies and similar technologies.

Some cookies are necessary for the website and platform to function. Others, such as analytics, advertising or tracking cookies, are only used where required consent has been obtained.

For more information about the cookies we use and how to manage your preferences, please see our separate Cookie Policy.

12. Third Parties and Sub-processors

We use trusted third-party providers to help us deliver our services, including hosting providers, payment processors, support tools, analytics tools, communication providers, security providers and data sources used for specific validation and verification checks.

Where we act as processor, these third-party providers may act as sub-processors. We require sub-processors to process personal data only for the relevant service purpose, keep it secure, and provide data protection commitments consistent with our obligations to customers.

Our use of sub-processors is subject to the authorisation and objection process set out in our Data Processing Agreement, where applicable.

We do not publish a full public list of all specific third-party providers used to deliver individual checks, as some provider relationships and check configurations are commercially sensitive. However, a current list or summary of relevant sub-processors can be made available to active customers through our Data Processing Agreement, platform, support process, or contract due diligence process.

We will not share your personal data with third parties for their own marketing purposes without your consent.

Where you consent to cookies from providers such as LinkedIn or Meta via our cookie banner, those companies may act as independent controllers for data collected through their tracking technologies. This means they may determine their own purposes for that data, separate from Provero. Please refer to their own privacy policies for information on how they process personal data.

13. Changes to This Privacy Policy

We may update this privacy policy from time to time.

Where changes are material, we will take reasonable steps to notify customers, which may include notice by email, in-app notification or publication on this page with an updated revision date.

We encourage you to review this policy periodically.

14. How to Complain

If you have any concerns about our use of your personal information, you can contact us using the details in Section 15.

You also have the right to lodge a complaint with the UK's data protection regulator, the Information Commissioner's Office.

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline number: 0303 123 1113
Website: https://www.ico.org.uk

15. Contact Us

If you have any questions about this privacy policy or wish to exercise your data protection rights, please contact us at:

Horizon Landings Limited trading as Provero
Charlotte House, 500 Charlotte Road
Sheffield
England
S2 4ER

Email: support@provero.io