We keep your data safe and secure
Data security is a big issue and we take it seriously. When you choose Hoge 100, you're trusting us with your information. It's a big responsibility and we work hard to protect it and put you in control. For example, all our staff are DBS checked. That just makes sense.
You can read our privacy policy to understand what information we collect from you, whether you're a client or not, and how we use it. The policy also explains why we collect this data in the first place.
If you have any questions, please do get in touch.
Privacy, Data Protection & Information Security Policy
1. Introduction
Hoge 100 Business Systems Ltd ("Hoge 100", "we", "us", "our") is committed to protecting the privacy, confidentiality, and integrity of personal data.
This document explains how we collect, use, protect, and manage personal data in accordance with:
- UK GDPR
- Data Protection Act 2018
- ISO/IEC 27001:2022 principles
This policy is designed for clients, partners, and external stakeholders.
2. Our Commitment
We commit to:
- Processing data lawfully, fairly, and transparently
- Collecting only data necessary for defined purposes
- Maintaining data accuracy and integrity
- Protecting data with appropriate security controls
- Retaining data only as long as necessary
3. How We Collect Personal Data
We may collect personal data through:
- Delivery of our services
- Client engagements and contracts
- Events, webinars, and communications
- Website forms and enquiries
- Surveys and research
- Public sources and third parties (where lawful)
4. Categories of Personal Data
We may process:
- Contact details (name, email, phone, address)
- Professional information (role, organisation)
- Communication records
- Website usage data (IP, analytics)
- CCTV footage (for security purposes)
Where legally permitted, we may process special category data.
5. Lawful Basis for Processing
We rely on the following legal bases:
- Contractual necessity - to deliver agreed services
- Legitimate interests - business operations, improvement, and security
- Legal obligations - regulatory compliance
- Consent - marketing communications and optional data
6. How We Use Personal Data
We use personal data to:
- Deliver and support our services
- Manage client relationships
- Respond to enquiries
- Provide updates and relevant communications
- Improve our services and systems
- Ensure compliance and security
7. Marketing and Communications
We only send marketing where lawful to do so.
You can opt out at any time via:
- Email unsubscribe links
- Contacting us directly
We may personalise communications based on your interactions with us.
8. Data Sharing
We may share data with:
- Trusted service providers
- IT and security partners
- Professional advisers
- Regulators or authorities where required
All third parties are subject to strict confidentiality and data protection obligations.
9. International Data Transfers
We primarily store and process data within the UK.
Where transfers outside the UK/EEA occur, we implement safeguards such as:
- Adequacy regulations
- Standard Contractual Clauses (SCCs)
10. Data Security (ISO 27001 Alignment)
We operate an Information Security Management System aligned with ISO 27001.
Key controls include:
- Access control and least privilege
- Cryptography and secure data handling
- Physical security
- Incident management
- Supplier security controls
We implement:
- Technical controls (encryption, firewalls, monitoring)
- Organisational controls (policies, training, audits)
11. Data Retention
We retain personal data only for as long as necessary to:
- Fulfil contractual obligations
- Meet legal and regulatory requirements
- Support legitimate business purposes
Retention periods are defined in internal schedules and reviewed regularly.
12. Your Rights
You have the right to:
- Access your data
- Correct inaccurate data
- Request deletion
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
Requests are handled within statutory timeframes.
13. Cookies Policy (Summary)
We use cookies to:
- Ensure website functionality
- Analyse performance
- Improve user experience
You can manage cookies via browser settings.
Cookie Types:
- Essential cookies - required for operation
- Analytics cookies - help us understand usage
- Preference cookies - remember user choices
A full Cookie Policy is available on request.
14. Contact Details
Data Protection Officer
Hoge 100 Business Systems Ltd
IMS House, Prescott Drive
Worcester, WR4 9NE, UK
Email: privacy@hoge100.co.uk
Tel: +44 (0)1905 947257
15. Continuous Improvement
We regularly review and update this policy to:
- Reflect legal and regulatory changes
- Improve clarity and transparency
- Maintain ISO 27001 compliance
Approved by:
Stuart Wild
Director
