Legal
Terms of service
The terms for using Kerova, and the data processing agreement that forms part of them.
1. Terms of Service
These terms are between Kerova Ltd (company no. 17503897, registered office 128 City Road, London, EC1V 2NX, "Kerova", "we") and the business that signs up ("you"). Effective date: 10 October 2026.
1.1 The service
- Kerova provides web-based software for UK fire and security companies to complete, sign, store and share compliance certificates, manage sites, systems, remedials and scheduling, give clients portal access, and send invoice data to Xero (the "Service").
- The Service is a tool. Your engineers remain responsible for the inspections, tests, results, verdicts and signatures they record. Kerova does not inspect, certify or approve any system.
- Calculators, checkers, guides and verdict suggestions are aids only. You must check results against the relevant standard and the manufacturer's data.
1.2 Accounts and users
- You are responsible for who you give access to, for keeping logins secure, and for everything done under your account.
- Tell us straight away at admin@kerova.co.uk if you think an account has been misused.
- You must remove access for staff, subcontractors and clients who should no longer have it.
1.3 Pilot terms
- Pilot customers get the first month free from the day logins are issued.
- Before the free month ends, we will agree the monthly price with you in writing. If you don't wish to continue, your access ends at the end of the free month with no charge.
- During the pilot, features may change and there may be occasional bugs or downtime. We will tell you about planned changes that affect how you work.
- You can stop at any time during the free month with no charge.
1.4 Fees and payment
- The standard price is a flat monthly fee based on the number of engineers, as quoted to you in writing.
- Fees are invoiced monthly in advance and payable within 14 days. Prices exclude VAT, which will be added if Kerova becomes VAT registered.
- We may change prices with at least 30 days' written notice.
- If an invoice is more than 30 days overdue we may suspend access after giving you 7 days' notice.
1.5 Your data
- You own the data you and your users put into the Service ("Customer Data"), including certificates, sites, systems, photos and your clients' details.
- We only use Customer Data to provide and support the Service, as set out in the Data Processing Agreement below, which forms part of these terms.
- You can export your data at any time while your account is active. After cancellation, we keep it for 30 days so you can export it, then delete it, apart from anything we must keep by law.
- You confirm you have the right to give us your clients' and staff's details for this purpose.
1.6 Signed certificates
- Once a certificate is signed it is locked and cannot be edited. Any correction will be made as a new version with an audit trail, when versioning is available.
- Each signed certificate gets a QR code and a verification page so anyone holding it can check it is the genuine signed version. The verification page does not show your clients' personal contact details.
1.7 Acceptable use
You must not use the Service to record false inspections or certificates, try to access other customers' data, reverse-engineer, overload or attack the Service, or resell it without our written agreement.
1.8 Availability and support
- We aim to keep the Service available at all times but do not guarantee it will be uninterrupted or error-free. Engineers can complete certificates offline and sync later.
- Support is by email at admin@kerova.co.uk. We aim to reply within one working day.
1.9 Liability
- Nothing in these terms limits liability for death or personal injury caused by negligence, fraud, or anything else that cannot be limited by law.
- We are not liable for loss of profit, revenue, business, goodwill or data you could have exported, or for any indirect loss.
- We are not liable for the content of any certificate, inspection or decision made using the Service.
- Otherwise, our total liability in any 12 months is limited to the fees you paid us in that period, or £1,000 if greater.
1.10 Ending the agreement
- You can cancel at any time by email, effective at the end of the current paid month.
- We can end the agreement with 30 days' notice, or immediately if you seriously breach these terms.
- On ending, sections 1.5, 1.9 and 1.11 continue to apply.
1.11 General
- We may update these terms with 30 days' notice by email. Continuing to use the Service after that means you accept the change.
- These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
- Contact: Kerova Ltd, admin@kerova.co.uk.
2. Data Processing Agreement
This agreement forms part of the Terms of Service. You are the controller of the personal data you put into Kerova, and Kerova Ltd is your processor under Article 28 of the UK GDPR and the Data Protection Act 2018. Effective date: 10 October 2026.
2.1 What we process
| Item | Detail |
|---|---|
| Subject matter | Providing the Service under the Terms |
| Duration | For as long as you use the Service, plus the 30-day export period |
| Nature and purpose | Storing, displaying and sending certificate, site, system, remedial, scheduling and invoice data so you can run your compliance work |
| Types of personal data | Names, job titles, work emails and phone numbers, signatures, site addresses, photos taken on site, login and usage records |
| Data subjects | Your staff, engineers and subcontractors; your clients and their contacts |
| Special category data | None. Do not put health, criminal or other special category data into the Service |
2.2 Our obligations
- We only process the data on your documented instructions, which are these Terms and how you use the Service, unless the law requires otherwise, in which case we will tell you first if we can.
- Everyone at Kerova with access to the data is bound by confidentiality.
- We keep appropriate technical and organisational security measures in place (section 2.4).
- We help you respond to requests from people exercising their data rights, and with security, breach notification and data protection impact assessments, as far as reasonably possible.
- We tell you without undue delay, and within 48 hours of becoming aware, of any personal data breach affecting your data.
- At the end of the Service we delete your data after the 30-day export period, unless the law requires us to keep it.
- We give you the information you reasonably need to show compliance, and allow a reasonable audit on 30 days' notice, no more than once a year, at your cost.
2.3 Sub-processors
You give general authorisation for the sub-processors below. We will give you 30 days' notice by email before adding or replacing one, and you can object. Each is bound by data protection terms at least as protective as these.
| Sub-processor | What for | Where |
|---|---|---|
| Google (Firebase and Google Cloud) | Hosting, database, file storage, functions, sign-in, push notifications, password-reset emails | Data stored in London (europe-west2); sign-in and push may be processed outside the UK |
| Resend | Sending app emails (invites, reminders, reports, booking notices) | USA, or EU if the account uses the EU region |
| Anthropic | AI features: rewording defects, suggesting rectifications, site summaries, monthly report intro | USA |
| Mapbox | Route planning (site addresses and coordinates) | USA |
| Xero | Invoice data, only if you connect your Xero account | As per Xero's own terms |
2.4 Security measures
- Data is hosted in the UK, in Google's London region, encrypted in transit and at rest.
- Each company's data is separated by access rules that are tested to stop one company seeing another's data.
- Access is role-based (admin, engineer, client portal user) and needs a login.
- Signed certificates are locked against editing, with an integrity check behind the QR verification.
- Daily and weekly backups with point-in-time recovery, kept for 90 days.
- Rate limiting on public pages and no personal data written to logs.
2.5 International transfers
Your data is stored in the UK. Some sub-processors (Resend, Anthropic, Mapbox, and parts of Google's sign-in and push services) process data in the USA. For each, we rely on an approved safeguard: the UK Extension to the EU-US Data Privacy Framework where the vendor is certified, or the UK International Data Transfer Addendum.
2.6 Liability
Liability under this agreement is subject to the limits in section 1.9 of the Terms, except where the law does not allow it to be limited.