For businessSign upLog in
Log in
2026 © Huzzeno Ltd. All rights reserved.Huzzeno Ltd is registered in England and Wales. Company No. 17310433. Registered Office: 71-75 Shelton Street, London WC2H 9JQ, United Kingdom. VAT No. GB123456789.
ContactTerms & ConditionsPrivacy policyCookie policy

Privacy Policy

Last Updated: 01 September 2026
Platform Operator: Huzzeno Ltd ("we", "us", "our")
Company Number: 17310433
Registered Address: 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
Contact Email: privacy@huzzeno.com
Terms and Conditions: https://huzzeno.com/terms-and-conditions
Cookie Policy: https://huzzeno.com/cookie-policy
DMCA Designated Agent: DMCA Agent Department, Huzzeno Ltd, privacy@huzzeno.com

Welcome to Huzzeno! We provide an online software-as-a-service (SaaS) application designed to help homeowners and businesses efficiently manage their day-to-day tasks, data, workflows, and administrative information (the "Platform"). Whether you are tracking household projects, organising company assets, or storing critical operational notes and files, our platform is built to simplify your management processes and keep your information in one place.

This Privacy Policy explains how we collect, use, store, and protect personal data belonging to website visitors, registered users, workspace administrators, and business customers using our Platform.

1. Our Legal Roles: Controller vs. Processor

Data Controller

We act as the Data Controller for personal data relating to account registration, billing, security monitoring, platform administration, and promotional communications. This includes information such as your name, email address, hashed password credentials, billing records, and security logs.

Data Processor

We act as the Data Processor regarding the records, files, and Workspace Content you upload to the Platform. You (or your organisation) remain the Data Controller of that content. We process Workspace Content only as necessary to provide, secure, maintain, and support the Platform in accordance with your instructions, our contractual obligations, and applicable law.


2. Personal Data We Collect

We process personal data under the lawful bases provided by the UK GDPR and EU GDPR.


Account & Profile Data

Data Collected: Name, email address, and hashed password credentials.
Purpose: To create and manage your account and provide access to the Platform.
Lawful Basis: Performance of a Contract.


System Telemetry

Data Collected: IP addresses, browser configurations, device identifiers, and session metadata.
Purpose: To maintain platform security, reliability, and service integrity.
Lawful Basis: Legitimate Interest.


Transactional Data

Data Collected: Billing names, invoice information, subscription history, and payment records.
Purpose: To manage subscriptions, process payments, and comply with financial obligations.
Lawful Basis: Performance of a Contract and Legal Obligation.


Usage Diagnostics

Data Collected: Engagement metrics, feature usage statistics, and performance diagnostics.
Purpose: To optimise and improve the Platform.
Lawful Basis: Legitimate Interest.


Security & Fraud Monitoring

Data Collected: Security logs, authentication events, and activity records.
Purpose: To detect, prevent, investigate, or respond to security incidents, fraud, abuse, or unlawful activity.
Lawful Basis: Legitimate Interest.


3. Processing Workspace Content

We process Workspace Content only as necessary to provide, secure, maintain, and support the Platform in accordance with your instructions, our contractual obligations, and applicable law.

Access to Workspace Content by authorised personnel is limited to situations where it is reasonably necessary for technical support, security, maintenance, or compliance purposes.

We do not access or use Workspace Content for advertising, profiling, or cross-service behavioural tracking.

Processing activities may include:

  • Storing and encrypting data within our database and object-storage systems.
  • Rendering files, records, and data layouts within the Platform.
  • Indexing text and records to enable in-app search functionality.
  • Applying automated calculations or workflows triggered by user actions, such as reminders and scheduled tasks.


4. AI and Machine Learning Policy

We do not use Workspace Content or customer-uploaded files to train general-purpose artificial intelligence or machine learning models.

If we introduce AI-assisted features in the future, we will clearly disclose:

  • what data is processed,
  • the providers involved,
  • the purpose of the processing, and
  • any available customer controls or opt-out mechanisms.


5. Security Measures

We implement commercially reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, misuse, loss, disclosure, or alteration.

These safeguards include:

  • encryption in transit and at rest,
  • secure authentication controls,
  • access restrictions,
  • system monitoring,
  • backup procedures, and
  • secure cloud infrastructure practices.


6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy or as required by applicable law.

Account Data

Retained for the duration of your active account and any legally required retention period thereafter.

Workspace Content

Deleted content is removed from active production systems within 30 days of deletion.

Financial Records

Billing and financial records may be retained for up to 7 years to comply with tax, accounting, and audit obligations.

Backups

Residual data contained in encrypted backup systems may persist temporarily and is overwritten according to our standard backup rotation schedule, generally within 60 days.


7. Sharing Data and Legal Disclosure

We do not sell personal data or use Workspace Content for advertising purposes.

We use trusted third-party service providers (“Subprocessors”) to support infrastructure hosting, payment processing, diagnostics, analytics, and operational communications. All vendors are assessed through reasonable due diligence processes and are subject to contractual data protection obligations.

A current list of our Subprocessors is available in our Subprocessor Registry.

Business customers acting as data controllers may request our standard Data Processing Agreement (DPA) by contacting us at Contact Email.

We may also disclose personal data where necessary to:

  • comply with applicable law or regulation,
  • respond to lawful requests from public authorities,
  • enforce our legal rights,
  • prevent fraud or security threats, or
  • protect the safety and integrity of the Platform and its users.


8. Cross-Border Transfers

Where personal data is transferred outside the United Kingdom or European Economic Area (EEA), we implement appropriate safeguards in accordance with applicable data protection laws.

These safeguards may include:

  • the European Commission’s Standard Contractual Clauses (SCCs), and
  • the UK International Data Transfer Addendum (IDTA).


9. Your Statutory Rights (UK GDPR / GDPR)

Subject to applicable law, you may have the right to:

  • access a copy of your personal data,
  • correct inaccurate or incomplete data,
  • request deletion of your personal data,
  • receive your data in a portable machine-readable format,
  • restrict certain processing activities, and
  • object to processing carried out under legitimate interests.

To exercise your rights, please contact us at Contact Email.

We will respond to valid requests without undue delay and generally within one month unless a lawful extension applies.


10. Complaints

If you have concerns about how we handle personal data, please contact us at Contact Email and we will investigate the matter and provide a response.

You also have the right to lodge a complaint with your local supervisory authority.

In the United Kingdom, this is the Information Commissioner’s Office (ICO):
https://www.ico.org.uk


11. Cookies and Tracking

We use essential cookies and similar technologies necessary for authentication, security, and core platform functionality.

Non-essential analytics or tracking technologies are used only where you provide consent through our cookie banner or preference controls.

Further information is available in our Cookie Policy.


12. Children’s Data

The Platform is not intended for individuals under 18 years of age, and we do not knowingly collect personal data from children.

If you believe that a child has provided us with personal data, please contact us so we can take appropriate steps to remove the information.


13. Updates to This Policy

We may update this Privacy Policy periodically to reflect changes to our services, operational practices, or legal obligations.

Where changes are material, we will provide notice through the Platform, by email, or through other appropriate communication channels.

Your continued use of the Platform following the effective date of an updated Privacy Policy constitutes acknowledgment of the revised Policy.