Who we are
HoloHub is a client portal operated by Holo Digital Ltd ("we", "us"), a company registered in England and Wales. Registered office: 15 The Pippins, Meopham, Gravesend, England, DA13 0HB, United Kingdom. ICO registration number: ZB399236.
This policy covers the HoloHub web portal at hub.holodigital.co.uk and the HoloHub apps for iPhone and Android. They are the same service with the same data handling.
For anything in this policy, contact laurence@holodigital.co.uk.
Two different kinds of data
This matters, because our responsibilities differ:
- Your account data. The details of the person logging in. We are the data controller for this.
- Your business data. The performance figures and customer enquiries belonging to the business you work for. We are a data processor acting on that business's instructions, under our services agreement with them.
What we collect
Account data
| Data | Why |
|---|---|
| Email address | Identifies your account and is how you sign in. |
| Password | Stored only as a salted scrypt hash. We cannot read or recover it. |
| Your name | Shown in the app so it addresses you properly. |
| Session cookie (web) or session token (app) | Keeps you signed in for up to 30 days. Strictly necessary, so no consent banner is required for it. In the app the token is held in your device's secure keychain. |
| Last sign-in time | Security, so unexpected access can be spotted. |
| Device push token | Only if you switch on new enquiry alerts in the app. Notifications are optional and off by default. The token is used solely to deliver those alerts and is deleted when you switch them off or sign out. |
Business data shown in the app
HoloHub displays data about the business you work for, drawn from services that business already uses:
- Website analytics from Google Analytics: visits, pages viewed, traffic sources, countries.
- Search performance from Google Search Console: search terms, clicks, ranking positions.
- Enquiries submitted through the business's own website forms. These contain the personal data of the person enquiring, typically their name, phone number, email address, the service they asked about and their town or postcode.
- Advertising performance from Google Ads and Meta: spend, clicks and results.
- Google Business Profile activity: calls, direction requests and how often the listing appeared.
- On-site behaviour from PostHog: aggregate counts such as how many people tapped a phone number, and where visitors leave a form. Used in aggregate, not to profile named individuals.
What we do not do
- No advertising or tracking SDKs inside the app itself.
- No selling or sharing of personal data for marketing.
- No automated decision-making with legal or similarly significant effects.
- No location tracking, no contacts access, no camera or microphone access.
- Face ID unlock, if you turn it on, is handled entirely by your device. Biometric data never leaves your phone and never reaches us.
Our legal bases
- Contract. Providing you an account and the portal you have been given access to.
- Legitimate interests. Keeping the service secure and working, such as limiting repeated failed sign-in attempts.
- Processor instructions. Business data is processed on behalf of the business we provide services to, under our agreement with them.
Where your data is held
HoloHub's database runs on a private virtual server operated solely by Holo Digital Ltd. The server is located in Singapore, and we tell you that plainly because it is outside the UK. The data there remains under our exclusive control: access is restricted to Holo Digital, traffic to and from the server is encrypted, and the database is backed up nightly to encrypted off-site storage. The datacentre operator supplies the infrastructure only, under its own data processing terms, and does not access the data we store. We apply the same UK GDPR standards to data on this server as we would to data held in the UK.
Google Analytics, Google Search Console, Google Ads, Google Business Profile, Meta and PostHog process data on their own infrastructure under their own terms.
How long we keep it
- Account data: for as long as the account is active, then deleted within 90 days of the account being closed.
- Session cookies: 30 days, or until you sign out.
- Business data, including enquiries: retained for as long as we provide services to that business, then deleted or returned in line with our agreement with them.
Security
- All traffic is encrypted in transit over HTTPS.
- Passwords are stored only as salted scrypt hashes, never in readable form.
- Session cookies are HttpOnly, Secure and SameSite, so they cannot be read by scripts.
- Each account can only ever see its own business's data. This is enforced on the server from the signed-in session, not from anything the app sends, so it cannot be bypassed from the browser.
- Repeated failed sign-in attempts are rate limited.
- The database is backed up nightly to encrypted off-site storage.
Your rights
Under UK GDPR you can ask for access to your data, correction of it, deletion of it, restriction of how it is used, a portable copy, or object to processing based on legitimate interests. Email laurence@holodigital.co.uk and we will respond within one month.
If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint.
Where we act as processor for a business, we will pass your request to that business, as they decide how the data is used.
Children
HoloHub is a business tool and is not intended for anyone under 18. We do not knowingly collect children's data.
Changes
If we change this policy we will update the date at the top, and tell account holders directly if the change materially affects them.