Privacy Policy
How Habix collects, uses, and protects your personal data.
Last updated: March 2026
1. Introduction
Habix (habix.co.uk) is operated by Habix Ltd ("we", "us", "our"). We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy explains what data we collect, how we use it, and what rights you have. By using the Habix platform, you agree to the practices described in this policy.
2. What data we collect
We collect the following categories of personal data:
- Account information — your name, email address, password (hashed), and account type (landlord or contractor).
- Property data — property addresses, tenancy details, and compliance records you add to the platform.
- Compliance documents — certificates, inspection reports, and other files you upload (e.g. Gas Safety Certificates, EICRs, EPCs).
- Contractor profile data — business name, qualifications, service areas, and contact details.
- Usage data — pages visited, features used, browser type, IP address, and device information, collected automatically via server logs and analytics.
- Payment data — billing details are processed by our payment provider and are not stored on our servers.
3. How we use your data
We use the data we collect to:
- Provide and maintain the Habix platform and your account.
- Track compliance status for your properties and send expiry reminders.
- Facilitate communication between landlords and contractors.
- Process subscriptions and payments.
- Improve our services, fix bugs, and develop new features.
- Send service-related emails (e.g. compliance alerts, account updates).
- Comply with legal obligations.
4. Legal basis for processing
Under the UK GDPR, we rely on the following lawful bases:
- Contract performance — processing necessary to deliver the service you signed up for.
- Legitimate interests — improving our platform, preventing fraud, and ensuring security.
- Consent — where you have given explicit consent, such as opting in to marketing communications.
- Legal obligation — where processing is required by law.
5. Data sharing
We do not sell your personal data to third parties.
We may share limited data in the following circumstances:
- Contractors you book — when you request work from a contractor through Habix, we share relevant property and contact details to enable the job.
- Compliance sharing — if you use the compliance sharing feature, selected compliance data is shared via a secure link with people you choose (e.g. tenants, agents).
- Service providers — we use trusted third-party services for hosting, payment processing, and email delivery. These providers process data on our behalf under strict data processing agreements.
- Legal requirements — we may disclose data if required by law, regulation, or court order.
6. Data retention
We retain your personal data for as long as your account is active or as needed to provide you with our services. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal, accounting, or regulatory purposes.
Uploaded compliance documents are deleted when you remove them or when your account is closed.
7. Your rights
Under the UK GDPR, you have the following rights:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data ("right to be forgotten").
- Right to data portability — request a machine-readable copy of your data.
- Right to restrict processing — request that we limit how we use your data.
- Right to object — object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at support@habix.co.uk. We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
We use essential cookies to keep you signed in and to remember your preferences. We may also use analytics cookies to understand how our platform is used. You can manage cookie preferences through your browser settings.
We do not use third-party advertising cookies.
9. Security
We take the security of your data seriously. We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS), hashed passwords, regular security reviews, and access controls.
No system is 100% secure. If you believe your account has been compromised, please contact us immediately.
10. Changes to this policy
We may update this privacy policy from time to time. If we make significant changes, we will notify you via email or through the platform. The "Last updated" date at the top of this page indicates when the policy was last revised.
11. Contact
If you have any questions about this privacy policy or how we handle your data, please contact us:
Habix Ltd
Email: support@habix.co.uk
Website: habix.co.uk