Security & Data Protection

Last updated: 8 July 2026

Vento holds the details of your customers, their properties and their homes. This page sets out who we are, how that data is protected, and how you get it back whenever you want it.

Registered entity

  • Vento Group Solutions Ltd, registered in England and Wales, company number 17334563.
  • Registered office: 66 Paul Street, London EC2A 4NA, United Kingdom.
  • Data-protection contact: privacy@ventogroup.uk.

ICO registration

Vento Group Solutions Ltd is registered with the UK Information Commissioner's Office as a data controller.

  • Registration reference: ZC218149
  • Registered: 9 August 2026
  • Renews: 8 August 2027

You can confirm this independently on the ICO's public register — the register, not this page, is the authoritative source. A copy of our registration certificate (PDF) is available if your procurement process needs one on file.

Where your data is held

Application data and uploaded files are stored in the EU (Ireland). Some subprocessors operate outside the UK and EU; those transfers are covered by Standard Contractual Clauses. The full list is below and in our Privacy Policy.

Keeping one installer's data away from another's

  • Row-level security on every table.Access is scoped to your organisation in the database itself, not only in application code, so a bug in a page cannot return another firm's records.
  • File storage is scoped the same way. Survey photos, proposals and documents are private objects filed under your organisation; a request from outside it returns nothing.
  • Role-based access within your own team — owner, admin and engineer roles, with changes to roles and removals written to an audit log.

Accounts and sign-in

  • Minimum ten-character passwords, enforced on the server as well as in the browser.
  • New passwords are checked against known breached-password corpora using k-anonymity — only a partial hash ever leaves our servers, never your password.
  • Two-factor authentication (TOTP) is available on every account.
  • Bot protection and rate limiting on registration, proposal signing and payment.

In transit and at rest

  • HTTPS everywhere, with HSTS and a scoped content-security policy.
  • Stored third-party access tokens are encrypted at rest with AES-256-GCM and decrypted only on the server.
  • We never store card numbers. Card details go directly to Stripe; Direct Debit mandates are held by GoCardless.
  • Proposal signing links are unguessable single-purpose tokens.

Audit logging

Jobs, rooms, proposals and signing events are recorded in an organisation-scoped audit log, along with security-sensitive changes: team role and status changes, member removals, API-key creation and revocation, and connecting or disconnecting a payment provider.

Who else processes data on our behalf

ProviderPurposeLocation
SupabaseDatabase, authentication, file storage & backend hostingEU (Ireland)
VercelApplication hosting & content delivery networkEU & global edge
StripeCard payment processing & subscription billingEU / USA (SCCs)
GoCardlessDirect Debit payment processingUnited Kingdom
ResendTransactional email deliveryUSA (SCCs)
AnthropicAI assistant, proposal text generation, and room measurement from photos (Claude)USA (SCCs)
Google Maps PlatformAddress autocomplete & static map imagesUSA (SCCs)

Your data stays yours

  • Proposals, invoices and compliance documents download as PDFs at any time, and your job and customer records can be exported.
  • You can close your account and have its data deleted from the account deletion page.
  • For the customer data you enter about your clients, you are the controller and we are your processor. Our Terms of Service include the data-processing agreement that governs it.

Reporting a security problem

If you believe you have found a vulnerability, email privacy@ventogroup.uk with enough detail to reproduce it. We will acknowledge it and keep you updated. Please give us a reasonable window to fix an issue before disclosing it publicly, and do not access or modify data belonging to anyone else while testing.

Questions from procurement

If you need answers to a security questionnaire, a copy of the ICO certificate, or detail on any control above, email support@ventogroup.uk and we will respond directly rather than pointing you back at this page.