Policies

Website & Service Privacy Policy

Huq Industries Limited ("Huq", "we", "us", or "our") respects your privacy and is committed to protecting personal data. This privacy policy informs you as to how we handle personal data when you visit our website, register for or use our B2B SaaS analytics platform, communicate with us, or receive our business services. It also outlines your privacy rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Contents

1. Important Information and Who We Are

Purpose of This Privacy Policy

This privacy policy applies to personal data processed by Huq in its capacity as a Data Controller (for example, business contact details, account credential data, platform telemetry, and website visitor analytics).

Where Huq processes customer application data or analytics queries on behalf of corporate clients using our B2B SaaS platform, Huq acts as a Data Processor. Such processing is governed strictly by the Data Processing Agreement (DPA) executed between Huq and the relevant corporate client.

Our website and SaaS platform are strictly intended for business and commercial users and are not directed at children.

Data Controller & Contact Details

Huq Industries Limited is the data controller responsible for your personal data. We have appointed a Data Protection Officer (DPO) to oversee data privacy compliance.

  • Full Legal Entity: Huq Industries Limited (Co. Reg. 09202565)
  • Data Protection Officer: Azita O'Shaughnessy
  • Email Address: azita.oshaughnessy@huq.io
  • Postal Address: 9 Dallington Street, London, EC1V 0LN, United Kingdom

You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the opportunity to address your concerns directly before you approach the ICO.

2. The Data We Collect About You

Personal data means any information about an individual from which that person can be identified. It does not include data where identity has been permanently removed (anonymous data).

As a B2B SaaS provider, we collect, use, store, and transfer the following categories of personal data:

  • Identity Data: First name, last name, job title, company name, user role, and account credentials.
  • Contact Data: Work email address, telephone numbers, and corporate billing address.
  • Financial & Transaction Data: Invoicing records, corporate payment details, payment history, and subscription plan information.
  • Technical & Telemetry Data: IP addresses, user login identifiers, browser type and version, time zone settings, device metadata, operating system, and session security logs generated during platform usage.
  • Usage Data: Aggregated information on how users interact with our web application, API endpoints, feature usage, performance metrics, and platform navigation.
  • Marketing & Communications Data: Marketing preferences, newsletter subscriptions, demonstration requests, and communication logs.

We do not collect any Special Categories of Personal Data (e.g., race, health, religious beliefs, sexual orientation) or information regarding criminal convictions.

3. How Is Your Personal Data Collected?

We collect data through the following interactions:

  • Direct Interactions: You provide Identity, Contact, and Financial Data when registering for a platform account, requesting a demonstration, signing a contract, submitting support tickets, or communicating with us.
  • Automated Technologies & Platform Telemetry: As authorized users interact with our B2B SaaS platform and website, we automatically collect Technical and Usage Data via server logs, secure cookies, and analytics tools (e.g., PostHog) to maintain security and optimize service performance.
  • Third Parties & Enterprise Integrations: Technical or authentication data received from our cloud infrastructure partners (e.g., Google Workspace, Firebase Authentication, Vercel).

4. How We Use Your Personal Data

We only process personal data where the law permits. The primary legal bases relied upon for our B2B operations are:

Purpose / Operational Activity Categories of Personal Data Lawful Basis for Processing
Account Registration & Service Provisioning: To onboard business clients, create user accounts, authenticate platform access, and manage subscription billing. Identity, Contact, Financial, Transaction Performance of a Contract with your organization.
Platform Operations & Technical Support: To provide client support, troubleshoot application errors, perform infrastructure maintenance, and issue system alerts. Identity, Contact, Technical, Usage Legitimate Interests (to operate, maintain, and support our enterprise SaaS platform).
Platform Security & Fraud Prevention: To enforce role-based access controls (RBAC), monitor authentication logs, prevent unauthorized access, and protect system integrity. Technical, Usage, Identity Legitimate Interests & Legal Obligations (ensuring information security and network resilience).
Business Communications & Client Relationship Management: To notify corporate clients of service updates, platform releases, privacy notice changes, or contract renewals. Identity, Contact, Marketing & Communications Legitimate Interests (maintaining commercial client relationships) & Legal Obligations.

5. Disclosures & Sub-processors

To deliver our B2B SaaS platform, we engage vetted third-party service providers (sub-processors) bound by strict written Data Processing Agreements (DPAs) enforcing confidentiality, UK GDPR compliance, and technical security standards:

  • Cloud Infrastructure & Database Services: Google Cloud Platform (GCP) and Supabase (managed database hosting).
  • Authentication & Identity Management: Firebase Authentication.
  • Web Hosting & Edge Infrastructure: Vercel.
  • Performance Tracing & Error Monitoring: Sentry.
  • Product Analytics & Usage Telemetry: PostHog.
  • Professional Advisers: Legal, financial, auditing, and insurance providers.
  • Regulatory Authorities: Public sector bodies or regulators (e.g., ICO, HMRC) where required by applicable law.

We prohibit sub-processors from using personal data for their own independent purposes.

6. International Data Transfers

Where personal data or technical logs are processed outside the United Kingdom (e.g., via cloud infrastructure providers operating in the EEA or US), Huq ensures an equivalent level of protection is maintained by implementing verified UK GDPR transfer mechanisms:

  • Hosting data within countries subject to UK Government Adequacy Decisions.
  • Executing the UK International Data Transfer Addendum (IDTA) or Standard Contractual Clauses (SCCs) with sub-processors.
  • Ensuring US sub-processors maintain certification under the UK Extension to the EU-U.S. Data Privacy Framework.

7. Data Security

Huq implements defense-in-depth technical and organizational measures to safeguard data against unauthorized access, loss, or alteration:

  • Encryption: Mandatory encryption in transit (TLS 1.2/1.3) and at rest (AES-256) across all systems and databases.
  • Access Control: Centralized Identity & Access Management (IAM) enforcing the Principle of Least Privilege, Role-Based Access Control (RBAC), and mandatory Multi-Factor Authentication (MFA / 2SV) for all personnel.
  • Monitoring: Automated security posture evaluation, audit logging, and continuous threat monitoring.
  • Incident Response: Documented incident management and breach reporting procedures to notify affected clients and regulators within statutory deadlines.

8. Data Retention

We retain personal data only for as long as necessary to fulfill the operational purposes for which it was collected, or to satisfy legal, statutory, tax, or accounting requirements:

  • Commercial Account & Transaction Data: Retained for the duration of the commercial contract plus 6 years following contract termination for legal and tax compliance.
  • Platform User Telemetry & Audit Logs: Security logs, authentication records, and session data are retained in accordance with our documented log retention schedule, after which they are securely purged or anonymized.
  • Anonymized Aggregated Data: Data that has been irreversibly anonymized so that it can no longer identify an individual may be retained indefinitely for statistical and analytical evaluation.

9. Your Legal Rights

Under UK data protection law, individuals have statutory rights regarding their personal data:

  • Right of Access: Request a copy of personal data held about you (Data Subject Access Request).
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of personal data where no legal ground exists for continued processing.
  • Right to Object / Restrict: Object to or request restriction of processing based on legitimate interests.
  • Right to Data Portability: Request transfer of automated data to another service provider.

To exercise any legal rights, please submit a written request to our DPO at azita.oshaughnessy@huq.io. DSAR requests are processed free of charge within one calendar month.

10. Glossary

  • Data Controller: The entity that determines the purposes and means of processing personal data.
  • Data Processor: An entity that processes personal data solely on behalf of and in accordance with the documented instructions of a Data Controller.
  • B2B SaaS: Business-to-Business Software-as-a-Service delivered via web applications and APIs.

Huq Industries Limited | Website & Service Privacy Policy | Last Updated: February 2026

PRIVACY SUPPORT

Questions About Your Privacy?

Whether you have questions about this Privacy Policy, your personal data, or wish to exercise your privacy rights, our team is here to help.