DryHome Ventilation — Privacy Policy
Effective date: 28 September 2026.
This notice covers DryHome Ventilation’s website and its private DryHome Business Engine, including its Google connections and the owner’s DryHome Jeffrey assistant. The Business Engine manages enquiries, jobs, bookings, receipts and business reporting. Website visitors do not need to connect a Google account to submit an enquiry.
1. Who is responsible and how to contact us
DryHome Ventilation is operated as a sole-trader business. For questions about information held by DryHome, contact info@dryhomeventilation.co.uk.
2. Information we collect and why
When you contact us or complete the suitability checker, we collect the details you provide, such as your name, telephone number, email address where supplied, installation address, postcode or town, preferred contact method, property details, suitability answers and message. We use these to respond, assess the enquiry and manage requested work. Please avoid including sensitive information that is unnecessary for your enquiry.
Our private records can include enquiry dates and stages, notes, quotations, installation and appointment dates, product/model and serial number, installation details, payment amounts and methods, costs, expenses, receipt references and owner-confirmed sharing or review-request history. These support job administration, receipts, record keeping and reporting. Payment records record amounts, dates and methods; the application does not provide a card-checkout or card-number collection flow.
We also process consent choices, visitor/session identifiers, website interactions, referring pages, campaign parameters and advertising click identifiers. Depending on the interaction, records include timestamps, IP address and browser/user-agent information. These support site operation, attribution, measurement, abuse prevention and audit. Hosting and authentication providers may also process technical connection records.
We use information to respond to enquiries, manage agreed work, maintain business records and protect our systems. Processing needed to take steps you request towards an installation agreement, or to perform that agreement, is based on contract. Optional analytics and advertising measurement use consent. Proportionate security and operational administration rely on legitimate interests in running and protecting the business. Where a specific law requires records, the applicable basis is legal obligation. Google account permission does not replace the lawful basis needed for customer information in a diary.
3. Cookies, local storage and measurement
The website presents analytics and advertising-measurement choices. The site loads Google’s tag with consent defaults set to denied. First-party interaction tracking and explicit analytics events are gated on analytics consent, and the advertising conversion signal is gated on marketing consent. Loading the tag can itself connect your browser to Google before you make a choice. It is designed to avoid sending enquiry names, contact details, addresses and free-text messages as analytics event properties. Google may receive technical identifiers and page/traffic information when its services are used.
The current browser code also stores a visitor identifier, session information, attribution information, selected product and suitability-check progress locally. Attribution includes referring/landing URLs and campaign or click identifiers when present. Visitor and attribution local storage are written before the consent choice. The session record uses a 30-minute expiry value; this is not a deletion period for other stored data. Owner administration uses a separate authentication cookie.
You can manage site data through your browser. Clearing this site’s storage resets the stored consent choice and can remove saved checker progress. The interface offers consent choices when no saved choice exists. You can clear this site’s browser data and reload it to choose again.
4. Google account connections
An authorized business owner connects Google services to the Business Engine. Connections are for DryHome’s operational features, not public customer Google sign-in.
Google Calendar
The dedicated Calendar connection requests https://www.googleapis.com/auth/calendar.events. This permits event access on calendars the connected user can access, rather than access restricted by Google to just one calendar. DryHome configures a single destination for its sync; the scope does not grant calendar-list or calendar-metadata management access.
When synchronization is enabled, the CRM is the source of bookings. The integration can create, update and cancel linked events. Event content can include customer name, installation address, telephone number, job/lead reference, product/system, operational notes, date/time and reminders. Linked event identifiers and sync status are stored with the business records to support updates and avoid repeated creation. Event notifications to attendees are disabled in the implemented sync requests. Access to the destination diary depends on that Google calendar’s sharing settings; “private” event visibility does not make the diary invisible to every authorized account or administrator.
Read-only operational verification can access event details to check the connection and reconcile bookings. The routine sync is CRM-to-Calendar; it does not import the owner’s whole diary into the CRM. The application stores an encrypted renewable authorization token, granted scopes, authorization time and authorizing administrator reference. Access tokens are obtained when needed and cached in memory. DryHome does not receive your Google password through this flow.
Existing Google business reporting
The application has separate integrations for Google Analytics 4, Search Console, Google Ads and Business Profile. They support reporting on website traffic, search visibility, advertising costs/performance and business-profile metrics. Imported reporting data and authorization/configuration records can be retained in the Business Engine. Availability depends on the connected property/profile and authorization; the existence of an adapter is not a claim that every service is currently connected or importing successfully. Calendar authorization is separate from the existing reporting grants.
The Calendar grant does not include Gmail or Drive access. Other Google reporting integrations use their separate authorizations.
Google-data commitments
DryHome’s handling of Google API data will comply with the Google API Services User Data Policy, including its Limited Use requirements, and applicable Google Workspace policies. Google-derived data will be used for the disclosed operational and reporting features, not sold, supplied to data brokers, used for personalized advertising or used to train generalized AI models. Transfers and human access will be limited to user-authorized functionality and the security, legal or other circumstances permitted by those policies. Relevant staff and suppliers must follow these restrictions. These are DryHome’s commitments governing its handling of Google data. These commitments do not assert that an external provider’s optional account settings have been independently verified.
5. Who receives information
The deployed service uses Hostinger hosting, a persistent private database, private receipt-file storage and server-side backups. Authorized owner/admin users can access relevant business records. Configured email delivery can send enquiry notifications to DryHome’s business mailbox through SMTP; availability depends on saved settings. Auth0 authenticates the owner’s private Jeffrey MCP connection and processes login/security information.
When the owner uses DryHome Jeffrey in ChatGPT, the selected tool results are returned to OpenAI’s ChatGPT service. Tools can return CRM/customer and job information, receipt metadata, Calendar booking information and business reports, including data derived from Google reporting integrations. Writes use controlled service boundaries and confirmation/version safeguards; the interface is not a general SQL or filesystem connection. The Calendar tool reads CRM bookings and sync state, not the owner’s entire Google diary.
If the owner chooses to share a receipt through WhatsApp, email or a device share facility, the selected recipient and service receive the chosen PDF/message. Sharing preparation does not itself send a message. An optional Google review link is separate from the receipt, and a share/review-request record is recorded when the owner confirms it. Selecting a request is not evidence that a customer wrote a review. Public links and external resources may take you to other providers with their own privacy practices.
Information is accessed by authorized personnel and service providers needed to operate these disclosed features.
6. Storage, security, location and retention
The application uses HTTPS, authenticated owner access, permissioned tools and audit/history records. OAuth refresh tokens are encrypted in storage. Receipt PDFs and the SQLite database are kept outside replaceable application releases, with private file permissions; backups support recovery. These controls do not mean that every database field or every provider backup is independently encrypted at rest. Receipt corrections preserve earlier issued documents rather than silently overwriting them.
We retain information according to the need to respond to enquiries, deliver and support installations, handle warranty matters, maintain accounting and tax records, meet legal requirements, resolve disputes and protect the service. Records are reviewed against those needs rather than a single fixed period. Deletion requests are assessed individually, including applicable retention exceptions. Backup copies may persist for a limited period after removal from active records while needed for recovery or legal obligations; they are subject to the same needs-based review. The current backup system does not perform automatic retention deletion.
7. Disconnecting Google and requesting deletion
The account owner can review or remove the connection through Google Account third-party connections. Revocation prevents continued authorized access but does not automatically erase existing CRM records, archived receipts, backups or events already written to Google. Stopping Calendar sync likewise does not remove existing diary events. Contact DryHome to request review of retained data and authorization records. No one-click account/data deletion function is promised by this notice.
Privacy requests should be sent to info@dryhomeventilation.co.uk. Requests will be assessed against applicable rights and lawful retention requirements, including records held by service providers or in backups.
8. Your rights and changes to this notice
Depending on the circumstances and applicable law, you may request access, correction, erasure, restriction, objection or portability of personal information. Where processing relies on consent, you may withdraw it without affecting the lawfulness of prior processing. Some requests have legal exceptions. Contact the privacy mailbox above. You may complain to the Information Commissioner’s Office.
We will date revisions to this notice. Material changes in Google-data use must be disclosed, and additional consent obtained where required, before that new use begins.
Using the website does not waive statutory rights.
