About this policy
This Privacy Policy explains how we collect, use, share and protect personal data as a controller, except where we state otherwise or process data on behalf of another controller under separate terms.
It applies to visitors to our website, account holders and their authorised users, and individuals whose contact details are submitted to the Platform. Please, read this document together with our Terms of Use.
Lite Blue Services Ltd. (trading as "Revert"), a company incorporated in England and Wales (company number 16357557) whose registered office is at 85 Great Portland Street, London, England W1W 7LT, is the controller of the personal data described in this Privacy Policy unless stated otherwise.
Revert operates a B2B marine-fuel procurement Platform providing lead generation, introductions, market data, chat/Al functionality, APIs and MCP tooling to business users (Buyers, Brokers, Traders and Suppliers of marine fuels, lubricants and related products and services).
Because our users and their counterparties operate globally, we process personal data under both the UK GDPR (and the Data Protection Act 2018) and, where applicable, the EU GDPR. References to "GDPR" mean whichever applies to you.
The Services are intended solely for business users acting in the course of trade. They are not directed at consumers or children, and we do not knowingly process the personal data of children.
Personal data we collect
We may collect and process the following categories of personal data:
-
Account & Identity: name, work email address, telephone number, company name, job title, country, address and business contact details, username, account settings, authorised users, login details, security events and access permissions.
-
Contact & lead data: Contact names, emails, phone numbers, company details and enquiry details submitted by users or generated through the Services (including data about a user's counterparties).
-
User Content: messages, attachments, voice notes, metadata and other communications sent through website forms, email, WhatsApp, Telegram or other integrated messaging channels.
-
Transaction & billing: Subscription and billing details, invoicing information (If we use a payment provider such as Stripe, it may process payment details under its own terms). We do not store full payment card numbers. Payment card information is processed by our payment service providers under their own privacy notices and security standards.
-
Al inputs & outputs: Prompts, uploaded documents and other inputs you provide to Al-assisted features, and the outputs generated, API keys, MCP credentials, calls, request metadata, feature usage, logs, rate-limit information, device identifiers and interaction history.
-
Usage & Technical data: IP address, device/browser information, operating system, log data, features used, timestamps, session and authentication tokens, and the country derived from your login IP (for login-security checks), device information, referral source, pages visited, errors, session data and cookie identifiers.
-
Marketing data: communication preferences, campaign engagement, survey responses and event interactions.
-
Compliance data: information reasonably needed for onboarding, security, fraud prevention, sanctions, KYC, AML or legal compliance checks.
We do not intentionally collect special-category personal data, such as health, political opinion, religious belief, racial or ethnic origin or similar sensitive information. Please do not submit such information unless specifically requested and lawful.
We collect personal data when you visit the website, create an account, request access, submit an enquiry, quote request, lead, message or form, use the Platform, chat services, APIs or MCP tools, communicate with us, or when another buyer, supplier, colleague, partner, service provider or third party provides information about you.
We may receive your business contact details from another platform user who wishes to introduce you to a commercial opportunity. Unless an exemption applies, we will provide appropriate privacy information within the time required by applicable law.
We collect personal data directly from you, from your authorised users, automatically through your use of the Services, and from other users who submit information about their counterparties.
Personal data you provide about other people
If you submit personal data about any individual (for example a counterparty contact, colleague or their staff), you confirm you have a valid lawful basis to do so and to allow us and other recipients to process it as described here, and that you have given any notices and obtained any consents required by law. Uploaded operational documents or files may incidentally contain individuals' names; we process them only to provide the requested analysis and the Services, and do not repurpose them. You will indemnify us against claims arising from a breach of this section as set out in the Terms of Use.
4. How we use personal data and our lawful bases
We use personal data only where we have a lawful basis to do so under Article 6 of the UK GDPR (and, where applicable, the EU GDPR). Depending on the circumstances, we rely on one or more lawful bases, including the performance of a contract, our legitimate interests, compliance with legal obligations and, where required, your consent.
| Purpose | Lawful basis |
|---|---|
| Providing, operating, maintaining and securing the Services; creating and managing accounts; responding to enquiries and support requests | Performance of a contract |
| Facilitating introductions and passing leads, contact details, enquiries and related messages between Buyers and Suppliers | Legitimate interests – operating and administering a B2B lead-generation and introduction platform |
| Processing prompts, uploaded documents and other inputs through AI-assisted features; operating chatbot workflows; generating outputs and providing requested AI-assisted functionality | Performance of a contract; Legitimate interests |
| Providing login security, fraud prevention, abuse detection, platform integrity, cybersecurity, authentication and country-based login checks | Legitimate interests; Legal obligation, where applicable |
| Billing, invoicing, processing payments and collecting sums due | Performance of a contract; Legal obligation |
| Monitoring usage, producing product analytics, improving, maintaining and troubleshooting the Services | Legitimate interests |
| Producing aggregated, anonymised or statistical information and market data that does not identify individuals | Legitimate interests |
| Complying with applicable law; responding to regulators, courts and competent authorities; enforcing our Terms of Use; protecting our rights; preventing fraud; maintaining audit trails and records | Legal obligation; Legitimate interests |
| Sending service, security, legal, operational and administrative communications | Performance of a contract; Legitimate interests |
| Sending business-to-business marketing communications about our services, market insights, events and updates | Legitimate interests; Consent, where required by applicable law |
Where we rely on legitimate interests, those interests include operating, maintaining, improving and securing the Platform and Services; facilitating business introductions between Buyers and Suppliers; preventing fraud and abuse; protecting our systems, users and Intellectual Property Rights; enforcing our contractual and legal rights; conducting internal administration, analytics and business planning; and developing and improving our products and services.
We have balanced these legitimate interests against the rights and freedoms of the individuals concerned and will only rely on them where we consider that such interests are not overridden by those rights. You may contact us if you would like further information about that assessment or wish to object to processing based on our legitimate interests where applicable.
AI, matching and automated processing
Some features use AI-assisted functionality (including chatbots, matching, document analysis, APIs and MCP tooling) to interpret messages, draft responses, extract structured details from conversations, classify requests and support service workflows. Inputs you provide—including prompts, uploaded documents and other content you submit—may be processed by third-party AI service providers acting as our processors or sub-processors to generate outputs and provide the requested AI-assisted functionality.
We may also use User Content, where permitted by applicable law, to improve, evaluate, develop and enhance our Services, including AI-assisted features. Where Revert processes User Content for AI model training or other product development purposes beyond providing the requested Services, Revert will do so only where permitted by Applicable Data Protection Law, the applicable contractual arrangements between the parties and this Privacy Policy.
MCP tooling may allow you or your own AI agent to interact with the Platform. Any such AI agent is controlled by you and acts on your behalf, not ours.
AI assists users but does not make legally significant decisions.
Our port and supplier scoring, ranking, lead-matching tools and AI-generated outputs are intended solely to assist users in making commercial decisions. They rank commercial options, analyse information and generate decision-support outputs, but they do not make decisions that produce legal or similarly significant effects on any individual solely by automated means. Commercial decisions remain the responsibility of the relevant user, and AI-generated outputs should always be independently reviewed (see our Terms of Use). We do not carry out profiling of individuals for the purposes of Article 22 UK GDPR or EU GDPR.
Third-party links and platforms
The website and Services may link to or integrate with third-party websites, messaging platforms, payment providers, analytics tools or other services. Those third parties have their own privacy practices. We are not responsible for their privacy policies or handling of personal data.
International transfers
Personal data may be transferred to, stored in or processed in the United Kingdom, the European Economic Area, the United States and other countries where Revert, its users or service providers operate. Where required, we use appropriate safeguards such as adequacy regulations (including UK-approved transfer mechanisms where applicable), standard contractual clauses, transfer risk assessments or other lawful transfer mechanisms.
Business-to-business Marketing
We may send service messages and, where permitted, marketing communications about our services, insights and updates. You can opt out of marketing at any time by using unsubscribe links or contacting us. Even if you opt out of marketing, we may still send service, security, legal or transactional messages. We will not send electronic marketing communications where prohibited by applicable law.
Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this document, then delete or anonymise it, unless a longer period is required by law.
Indicative retention periods are:
-
account and business contact data: for the life of the account or relationship, plus up to 2 years;
-
user content, lead / contacts data, quote request and transaction-related records: up to 7 years where needed for legal, tax, audit or dispute reasons;
-
chat and support communications: up to 2 years, unless a longer period is needed for legal, security or dispute reasons;
-
technical, usage and security logs: typically up to 12 months, unless needed for investigation or compliance;
-
marketing data: until you opt out or the data is no longer needed.
-
Billing & tax records: 6 years (UK tax law)
Security
We use reasonable technical and organisational measures, including encryption in transit (TLS); passwords stored only as salted hashes; role-based access controls; session based authentication with short-lived tokens; login-location (country) security checks; and restricted, access-controlled document storage. No internet transmission or system can be guaranteed completely secure. You are responsible for keeping account credentials, API keys, MCP credentials and devices secure and for notifying us promptly of any suspected unauthorised access.
Your rights
Depending on applicable law, you may have rights to access your personal data, correct inaccurate data, request deletion, restrict or object to processing, receive data in a portable format, withdraw consent where processing is based on consent, object to direct marketing, and complain to a supervisory authority. In the UK, the supervisory authority is the Information Commissioner's Office (ICO).
Complaints. You can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, or, if you are in the EEA, to your local data-protection supervisory authority - though we'd welcome the chance to resolve your concern first.
To exercise your rights, contact us using the details below. We may need to verify your identity before responding.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page. Where appropriate, we may notify you by email or other reasonable means.
Contact
Questions, comments and rights requests should be sent to:
Lite Blue Services Ltd., trading as Revert
85 Great Portland Street, London, England W1W 7LT
Email: sm@reverting.io
