Effective from 28 July 2026
Purpose, status and scope
Revante is the UK online device buyback service operated by WE BUY BACK LTD. This public policy summarises the data protection standards that apply when we handle personal information through revante.co.uk, quotations, sell orders, postage, device inspection, customer support, payments, returns and complaints.
It applies to customer and prospective-customer information, business contacts, authorised representatives, website users, order records, device identifiers, inspection evidence and personal information that may remain on a device sent to us. Separate notices may apply to workers, job applicants and particular business relationships.
This policy supports our Privacy Policy, Cookie Policy and Terms & Conditions. If those documents describe a particular customer interaction in more detail, they should be read together.
Personal information must have a defined purpose, lawful basis, responsible owner, controlled access, appropriate retention period and secure end-of-life process.
The legal framework we follow
Revante's processing is governed principally by the UK General Data Protection Regulation, the Data Protection Act 2018 and amendments introduced by the Data (Use and Access) Act 2025. Cookies and electronic marketing are also governed by the Privacy and Electronic Communications Regulations where they apply.
We identify an appropriate lawful basis before using personal information. Depending on the purpose, this is usually necessary steps before entering a contract, performance of a contract, compliance with a legal obligation, our legitimate interests or consent. Consent is used only where a genuine, informed and withdrawable choice is appropriate.
The law may permit or require limited processing for preventing or detecting crime, responding to a lawful authority, protecting legal claims or meeting tax and accounting duties. We document the justification and limit the information used.
Seven principles guide every decision
The UK GDPR principles are the foundation of our data protection approach. They apply from the first design decision through collection, daily use, storage and deletion.
Lawful, fair & clear
We use information lawfully, consider the effect on people and explain our practices in understandable language.
Purpose limitation
We collect information for specified purposes and assess any new use before it begins.
Data minimisation
We seek information that is adequate and relevant without collecting more than the task requires.
Accuracy
We provide routes to correct records and take reasonable steps to keep operational information accurate.
Storage limitation
We assign retention periods and delete, anonymise or securely destroy information when it is no longer needed.
Security
We use technical, organisational and physical safeguards appropriate to the information and risk.
Accountability
We maintain evidence of decisions, responsibilities, supplier controls, training, reviews and incident handling.
Roles, responsibility and accountability
WE BUY BACK LTD is the controller for the Revante processing described here. Senior management is responsible for providing suitable resources and ensuring data protection is considered in operational and technology decisions.
A designated Data Protection Lead coordinates privacy notices, data-rights requests, complaints, records, supplier reviews, risk assessments, incidents and policy updates. This operational title does not claim that Revante is legally required to appoint a statutory Data Protection Officer.
Everyone with access to personal information must follow authorised processes, maintain confidentiality, use only the access needed for their role and report mistakes or suspected incidents promptly. Deliberate misuse may lead to disciplinary, contractual or legal action.
We keep records of relevant processing activities, purposes, lawful bases, information categories, recipients, transfers, retention and safeguards at a level proportionate to our operations and legal duties.
Control across the complete data lifecycle
Protection is applied to the whole journey rather than only the moment information enters our website.
Collect
Clear fields, relevant choices and privacy information at quotation, order, contact and payment stages.
Use
Defined purposes, lawful bases, trained users and access appropriate to the authorised task.
Keep
Controlled systems, traceable records, supplier safeguards and reviewed retention periods.
Close
Secure deletion, anonymisation or destruction when the purpose and applicable retention duties end.
Where information is corrected, restricted, erased or no longer needed, we take reasonable steps to apply that change across relevant active systems and tell recipients where the law requires it. Backup copies may remain protected until they are overwritten through the normal secure cycle.
Aevum Recycling System governance
Revante uses the Aevum Recycling System to create an accountable record of each device journey. Aevum was developed by World Business Software Solutions. Records may include customer and order details, product specification, network, condition, IMEI or serial number, photographs, video, test results, grade, price, communications, return and payment status.
Our control standard requires named and authorised access, permissions appropriate to job duties, traceability for important order activity, protection during transmission and storage, controlled support access, backups, retention controls and prompt removal or adjustment of access when responsibilities change.
Where World Business Software Solutions or another provider can access live personal information to host, maintain or support Aevum, that access is governed by written instructions, confidentiality, security and data protection requirements. Providers may not use Revante information for their own unrelated purposes.
Inspection images and records support consistent grading, device traceability, fraud prevention and fair resolution of disputes. They are not created for public display or unrelated profiling.
Personal information left on devices
A device can contain highly personal information that is separate from the order record. Before posting, customers must back up anything they wish to keep, sign out, remove SIM and memory cards, remove passcodes and activation locks, and perform an appropriate factory reset. Revante never needs a customer's password or authentication code.
Every received device is treated as if residual personal information may remain. Staff must not browse content out of curiosity or use it for marketing, profiling or any unrelated purpose. Access is limited to what is reasonably necessary to identify, secure, inspect or erase the device, resolve a lock, investigate suspected unlawful material or comply with law.
Where the device is accessible and the transaction can proceed, Revante may perform a controlled wipe before reuse. If a device cannot be lawfully accessed or wiped, the order may be paused while we request remote lock removal or arrange a return.
SIM and memory cards should not be included. If received, they may be securely destroyed rather than returned. Data wiping is an additional operational safeguard and does not replace the customer's responsibility to erase the device before dispatch.
Security, access and confidentiality
We select safeguards according to the sensitivity, volume, context and risk of the information. The measures may include role-based access, strong account controls, multi-factor authentication where supported, encryption in transit, secure systems and backups, event logging, physical access controls, confidentiality duties, supplier checks, patching, malware protection and secure disposal.
Access follows the principles of least privilege and need to know. Shared credentials are not an acceptable normal working method. Access is reviewed and changed when a person joins, moves role or leaves, and privileged or support access receives additional control.
Payment credentials are handled only through approved processes. Staff must not copy personal information into unapproved personal email, messaging, storage or portable media. Sensitive discussions and records must be protected from unauthorised viewing.
No system can be guaranteed completely secure. Our duty is to apply appropriate safeguards, review risk, respond promptly and improve controls when technology, threats or operations change.
Processors, sharing and international transfers
Before a supplier processes personal information for Revante, we consider the service, information involved, access required, security, location, sub-processors, deletion and incident arrangements. Appropriate written terms require processing on documented instructions and protection of people's rights.
Necessary recipient categories may include hosting and IT support, Aevum support, email and communications, couriers, banks and payment providers, CheckMEND and device-status services, professional advisers, insurers, auditors and public authorities where disclosure is lawfully justified.
We share the minimum information reasonably needed for the purpose and do not sell customer contact, order or device data to data brokers.
Where information is transferred outside the United Kingdom, we use a permitted mechanism such as UK adequacy regulations or appropriate contractual safeguards. Where required, we complete the applicable data protection or transfer-risk assessment and consider supplementary protections.
Retention, deletion and secure disposal
Retention is determined by purpose, legal requirements, risk, complaints, fraud concerns and the time in which a claim may be brought. We review records and securely delete, anonymise or destroy them when continued identification is no longer justified.
- incomplete quotations and abandoned enquiries are normally held for up to 12 months;
- completed order, payment, accounting and tax records are normally held for up to six years;
- linked IMEI, serial, inspection, image, video, status and return evidence may be held for up to six years;
- standalone support or complaint records are normally held for up to three years after closure, unless another justified period applies; and
- technical logs, consent records and security information use shorter periods set according to their purpose and risk.
Paper is destroyed securely, storage media is securely erased or destroyed, and equipment is checked before reuse or disposal. Data may be retained longer where required by law or reasonably necessary for an open investigation, dispute or legal claim.
Recognising and handling individual rights
Depending on the circumstances, people may ask to be informed, access their information, correct it, erase it, restrict its use, object to processing, receive portable information, withdraw consent or obtain safeguards relating to a solely automated significant decision.
A request does not need to quote the UK GDPR or use a particular form. Staff must recognise possible requests made by telephone, email, letter or another contact channel and pass them promptly to the Data Protection Lead.
We may request proportionate information to confirm identity, authority and the records concerned. For access requests, we make reasonable and proportionate searches. We normally respond without undue delay and within one month from the point the applicable time limit begins, unless the law permits an extension, fee, clarification or refusal.
Rights are not absolute. If information must be retained for legal duties, another person's rights, fraud prevention or a legal claim, we explain the relevant limitation and available complaint route.
A clear data protection complaints process
Anyone who believes Revante has handled personal information incorrectly can raise a data protection complaint by email, telephone or post. The word “complaint” is not required; we look at the substance of the concern.
In line with the complaint-handling requirements effective from 19 June 2026, we will acknowledge a data protection complaint within 30 days of receiving it. We will make appropriate enquiries without undue delay, keep the complainant informed where needed and communicate the outcome without undue delay.
The investigation may review relevant Aevum records, correspondence, consent choices, access logs, supplier information and staff accounts. The outcome will explain what we considered, what we found and any correction, deletion, control improvement or other action taken.
Email [email protected] with the subject “Data Protection Complaint”, call 0114 698 4201 or write to our registered office. You may also complain to the ICO; contacting us first does not remove that right.
Personal data breach response
A personal data breach can involve accidental or unlawful loss, destruction, alteration, disclosure of, or access to personal information. It may result from cyberattack, misdirected communication, lost equipment, inappropriate access, supplier failure or a physical-security event.
Staff and providers must report suspected incidents immediately. We then contain the issue, preserve evidence, assess the information and people affected, reduce harm, investigate the cause, record the decision and apply corrective action.
Where a breach is likely to risk people's rights and freedoms, we notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware. Information may be provided in phases if the investigation is still developing.
Where the likely risk is high, we also inform affected people without undue delay, using clear language about what happened, likely consequences, action taken and practical steps they can take. We document all breaches, including those not reported, and the reasoning behind notification decisions.
Data protection by design and default
New forms, features, integrations, suppliers, analytics tools and material changes to Aevum are reviewed before launch. We consider the purpose, necessity, lawful basis, data fields, access, transparency, retention, security, rights, suppliers, transfers and possible effect on people.
Default settings should limit collection, visibility, sharing and retention to what is necessary for the stated purpose. Where practical, we separate identifiers, reduce free-text collection, use structured choices, restrict permissions and test deletion and recovery processes.
We screen changes for privacy risk and complete a Data Protection Impact Assessment before processing that is likely to result in a high risk to people. A DPIA describes the processing, assesses necessity and risk, records consultation where appropriate and identifies measures to reduce that risk.
High residual risk is escalated and, where the law requires, referred to the ICO before processing begins. Launch approval does not end the review: controls are reconsidered when the use, risk, supplier or technology materially changes.
Training, assurance, review and contact
People who handle personal information receive data protection and security guidance appropriate to their responsibilities, including recognising rights requests, preventing disclosure, handling device data, secure communications and reporting incidents. Training is refreshed when risk, role or law changes.
Revante reviews policies, access, retention, suppliers, incidents, complaints and selected operational records. Findings are assigned to an owner and tracked to completion. Material weaknesses are escalated to management.
This policy is reviewed at least annually and sooner when law, guidance, technology, suppliers or our service change. The latest published version shows its effective date.
11 The Crofts
Rotherham, England, S60 2DJ
You may complain to the Information Commissioner's Office, the UK regulator for data protection. We would appreciate the opportunity to investigate first, but your right to approach the ICO is not affected.