Arctic Air · Legal
Privacy Policy
Last updated: 17 September 2026
1. Who we are
1.1 This policy explains how James Wiles, trading as Roost Labs ("Roost Labs", "we", "us", "our"), handles personal data in connection with Arctic Air ("Software"). Arctic Air is business management software for heating, ventilation, air conditioning and refrigeration firms.
1.2 Contact details: 46 Compton Way, Farnham, Surrey, GU10 1QU, United Kingdom. Email: jwiles@roostlabs.co.uk.
1.3 This policy covers the Software only. Our website has its own privacy policy.
2. Our role
2.1 When we act as a processor. The businesses that use Arctic Air ("Customers") decide what data about their own customers, suppliers and staff goes into the Software. For that data, the Customer is the controller and we process it only on the Customer's instructions. If you are a customer of one of those businesses, please contact that business first about your data. We will help them respond.
2.2 When we act as a controller. We are the controller for the data we need to run our own relationship with Customers: the names, contact details and account information of the people who sign up for and use the Software, and our billing and support records.
3. The data we process
3.1 Account and user data: names, business email addresses, phone numbers, job titles, login and access records.
3.2 Customer business data: the information a Customer enters or receives in the Software. This may include the names, addresses, phone numbers and email addresses of the Customer's own customers and suppliers, site and job details, equipment records, appointments, quotes, orders, invoices, payment status, and messages exchanged through the Software.
3.3 Connected accounting data: if a Customer connects QuickBooks Online or Xero, we access the records needed to provide the Software's accounting features. These are customer contacts, invoices, payments, credit notes where the connected service supports them, and the organisation's account, product and tax settings. We also store the access credentials the accounting service issues for that connection.
3.4 Technical data: log records such as IP addresses, browser type, and the dates and times of requests, used to operate and secure the Software.
3.5 We do not intentionally collect special category data. We ask Customers not to enter it into the Software.
4. How we use data
We use personal data to:
- (a) provide, operate and maintain the Software;
- (b) create and update records in a Customer's connected accounting software, and read back the status of those records, at the Customer's request;
- (c) send messages and documents the Customer asks the Software to send;
- (d) provide support and respond to enquiries;
- (e) keep the Software secure, prevent misuse, and fix faults;
- (f) bill Customers and keep business records; and
- (g) comply with our legal obligations.
5. Our lawful bases
Where we are the controller, we rely on:
- contract, to provide the Software to the Customer we have an agreement with;
- legitimate interests, to support users, secure and improve the Software, and run our business; and
- legal obligation, to keep records the law requires.
Where we are a processor, the Customer is responsible for having a lawful basis for the data it puts into the Software.
6. Data from QuickBooks and Xero
6.1 We access a Customer's QuickBooks Online or Xero data only after an authorised person at that Customer has approved the connection. We access only the data needed for the Software's features.
6.2 We use that data only to provide the Software to that Customer. We do not sell it, share it with advertisers, use it for marketing, or combine it with other Customers' data.
6.3 A Customer can disconnect at any time: in QuickBooks Online, from the Apps section of their company; in Xero, from Connected Apps in their organisation settings; or by contacting us. Once a connection is withdrawn we can no longer access that service, and we delete the access credentials we hold for it on request.
6.4 Intuit Inc. and Xero Limited are independent controllers of the data held in their own products, and their own privacy policies apply to it.
7. Artificial intelligence
Some features of the Software use an artificial intelligence service to help read, sort or draft content. Data sent to that service is used only to produce the result the feature needs. Our agreement with the provider does not allow it to use that data to train its models.
8. Who we share data with
8.1 We never sell personal data.
8.2 We share personal data only with service providers that help us run the Software, under written terms that require them to protect it and use it only on our instructions:
- Netlify, Inc. — hosting the Software
- Supabase, Inc. — database and data storage
- Anthropic, PBC — artificial intelligence features
- Meta Platforms, Inc. (WhatsApp Business) — messaging, where a Customer enables it
- Postmark (ActiveCampaign, LLC) — sending and receiving email
8.3 We also send data to the accounting services a Customer chooses to connect, as described in section 6.
8.4 We may disclose data if the law requires it, to protect our rights or the safety of others, or to a successor if our business is transferred. In each case we will do so only as permitted by law.
9. International transfers
Some of our service providers store or process data outside the United Kingdom, including in the European Economic Area and the United States. Where data is transferred outside the UK, we make sure it is protected by an adequacy decision (including the UK Extension to the EU-US Data Privacy Framework, where the provider participates) or by the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
10. How we protect data
10.1 We use appropriate technical and organisational measures to protect personal data, including:
- encryption of data in transit using HTTPS;
- encryption of stored data by our hosting and database providers;
- access limited to the people who need it, with account sign-up disabled so accounts are created only by us, and sign-in rate-limited to resist guessing;
- keeping access credentials for connected services on our servers, never in a user's browser; and
- logging and monitoring to detect and investigate errors and misuse.
10.2 If a personal data breach affects a Customer's data, we will tell that Customer without undue delay. Where the law requires it, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach.
11. How long we keep data
11.1 We keep Customer business data for as long as the Customer uses the Software. When a Customer's agreement ends, we keep it for 30 days so the Customer can request an export, and then delete it, unless the law requires us to keep it.
11.2 We delete the access credentials for a connected accounting service on request once the connection has ended.
11.3 We keep billing and business records for six years after the end of the financial year they relate to, as UK law requires.
11.4 We keep technical logs for no longer than 90 days, unless we need them to investigate a security incident.
12. Your rights
12.1 Under UK data protection law you have the right to: access your personal data; have it corrected; have it erased; restrict or object to its processing; receive it in a portable format; and withdraw consent where we rely on consent.
12.2 To use these rights, email jwiles@roostlabs.co.uk. We will respond within one month. If we hold your data as a processor for one of our Customers, we will pass your request to that Customer and help them respond.
12.3 If you are unhappy with how we have handled your data, please contact us first. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
13. Children
The Software is for businesses and is not directed at anyone under 18. We do not knowingly collect children's personal data.
14. Changes to this policy
We may update this policy from time to time. We will tell Customers about any material change by email or within the Software, and we will always show the date of the latest version at the top of this page.
15. Contact
James Wiles, trading as Roost Labs
46 Compton Way, Farnham, Surrey, GU10 1QU, United Kingdom
jwiles@roostlabs.co.uk
Arctic Air · Privacy Policy · Last updated 17 September 2026 · Licence agreement