Privacy Policy

Hive Business and the Hive Business Group is a trading name of Hive Accountancy Ltd, Hive Marketing Solutions Ltd and Hive Business Consultancy Ltd. Hive Accountancy Ltd is registered in England and Wales number 09572514 at 75 Daniell Road, Truro, TR1 2DB. Hive Marketing Solutions Ltd is registered in England and Wales number 09572612 at 75 Daniell Road, Truro, TR1 2DB. Hive Business Consultancy Ltd is registered in England and Wales number 11871755 at 4 Parkvedras Terrace, Truro, Cornwall, United Kingdom, TR1 3DF.

This notice tells you how we look after your personal data, about your privacy rights, and about our compliance with and your protections under data protection law. In this notice, “Data Protection Legislation” means any applicable law relating to the processing, privacy and use of personal data, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (as amended), and the Data (Use and Access) Act 2025. We also have regard to the guidance published by the Information Commissioner’s Office (ICO) and to our professional guidelines and requirements.

Data controller

Hive Business is, in most circumstances, the “data controller”. This means we are responsible for deciding how we hold and use personal data about you. We are required under the Data Protection Legislation to notify you of the information contained in this privacy notice.

Hive Business may request and store names, addresses and other contact details. Such information will be used by Hive Business for its own administrative and marketing purposes only. Hive Business will not release such information, in whole or in part, to any third parties unless obliged to do so by law or as otherwise set out in this notice.

We have appointed a Data Protection Point of Contact, Ross Martin, Director, who is responsible for assisting with enquiries in relation to this privacy notice or our treatment of your personal data. Should you wish to contact our Data Protection Point of Contact you can do so by emailing hello@hivebusiness.co.uk.

Data processor

In providing some of our services, including but not limited to marketing and payroll, Hive Business acts as a data processor on behalf of our clients. In these cases the client is the data controller responsible for the personal data, and Hive Business processes that data only to the extent needed to provide the service and in accordance with the client’s instructions.

If we host your email or mailing list(s), you entrust us with your list information, including list membership and message content. We do not sell, rent or trade your list information to any third parties. Only employees of Hive Business who are responsible for supporting clients are granted access to the lists we host. We may, however, need to release or transfer data in limited circumstances, for example where we are required to do so by law, where it is necessary to investigate or prevent unlawful activity or a threat to someone’s safety, or where the business is sold, merged or reorganised.

If you decide to terminate your hosted list(s), we will erase your list membership once you have settled all outstanding invoices and secured a copy for yourself. The servers we use to deliver the service are protected to help prevent unauthorised access. Hive Business will not use personal data obtained in the course of providing our email management service for any other purpose and will not release it, in whole or in part, to anyone other than our client in its capacity as data controller, unless obliged to do so by law.

The personal data we hold about you

We obtain personal data about you, for example, when:

  • you request a proposal from us in respect of the services we provide;
  • you, your employer or our clients engage us to provide our services, and also during the provision of those services;
  • you contact us by email, telephone, post or social media (for example when you have a query about our services); or
  • we receive it from third parties and/or publicly available sources (for example, from your employer or from Companies House).

The information we hold about you may include:

  • your personal details (such as your name and/or address);
  • details of contact we have had with you in relation to the provision, or the proposed provision, of our services;
  • details of any services you have received from us;
  • our correspondence and communications with you;
  • information about any complaints and enquiries you make to us;
  • information from research, surveys and marketing activities;
  • information we receive from other sources, such as publicly available information, information provided by your employer or our clients, or information from our network firms; and
  • your IP address, which pages you may have visited on our website, and when you accessed them.

How we use the personal data we hold about you

We may process your personal data:

  • for the performance of our contract with you, your employer or our clients, and to comply with our legal obligations. This may include processing your personal data where you are an employee, subcontractor, supplier or customer of our client;
  • for the purposes of our own legitimate interests, provided that those interests do not override your own interests, rights and freedoms. This includes processing for marketing, business development, statistical and management purposes; and
  • for certain additional purposes with your consent. Where your consent is required, you have the right to withdraw it at any time.

Please note that we may process your personal data on more than one lawful basis depending on the specific purpose for which we are using it.

In particular, we may use your personal data in order to:

  • carry out our obligations arising from any agreement entered into between you, your employer or our clients and us (which will most usually be for the provision of our services);
  • carry out our obligations arising from any agreement entered into between our clients and us, where you may be a subcontractor, supplier or customer of our client;
  • prevent and detect crime, fraud or corruption;
  • provide you with information related to our services, events and activities that you request from us or that we feel may interest you, provided you have consented to be contacted for such purposes;
  • seek your thoughts and opinions on the services we provide; and
  • notify you about any changes to our services.

If you refuse to provide us with certain information when requested, we may not be able to perform the contract we have entered into with you, or we may be unable to comply with our legal or regulatory obligations. We may also process your personal data without your knowledge or consent, in accordance with this notice, where we are legally required or permitted to do so.

In some circumstances we may anonymise or pseudonymise the personal data so that it can no longer be associated with you, in which case we may use it without further notice to you.

Data retention

We will only retain your personal data for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, accounting, tax or reporting requirements, and to allow us to deal with any potential claims.

We are required by legislation, other regulatory requirements and our insurers to retain certain data after we have ceased to act for you. In most cases we will retain your personal data for seven years after the end of our engagement with you. We may retain data for a longer period where a specific legal, regulatory or insurance requirement applies, or where it is necessary in connection with an actual or potential claim. After the applicable period, we will securely delete or anonymise your personal data.

Change of purpose

Where we need to use your personal data for a reason other than the purpose for which we originally collected it, we will only do so where that reason is compatible with the original purpose. If we need to use your data for a new purpose, we will notify you and tell you the legal basis for that new processing.

Data sharing

We will share your personal data with third parties where we are required by law, where it is necessary to administer the relationship between us, or where we have another legitimate interest in doing so.

“Third parties” includes third-party service providers and other entities within our group. The following activities are carried out by third-party service providers: IT and cloud services, professional advisory services, administration services, marketing services, accountancy outsourcing service providers, CRM services and banking services. We only permit our third-party service providers to process your personal data for specified purposes and in accordance with our instructions, and we require them to take appropriate security measures to protect it.

We may also share your personal data with other third parties, for example in the context of a possible sale or restructuring of the business, with a regulator, or to otherwise comply with the law.

Transferring personal data outside the United Kingdom

Because we use a range of IT systems and service providers, your personal data may be stored or processed in countries outside the United Kingdom, including the United States,  Bangladesh, India, the Philippines and Zimbabwe. Whenever we transfer your personal data outside the UK, we make sure an appropriate level of protection applies by relying on one of the safeguards described below.

Adequacy regulations. Some countries are covered by UK “adequacy regulations”, meaning the UK government has decided they provide a level of data protection essentially equivalent to that required under the Data Protection Legislation. This includes transfers to organisations in the United States that are certified under the UK Extension to the EU-US Data Privacy Framework (the “UK-US Data Bridge”). Many of the major cloud, email and storage providers we rely on are certified in this way.

Appropriate safeguards. For transfers to countries that are not covered by UK adequacy regulations — including Bangladesh, India, the Philippines and Zimbabwe, and any US organisation that is not certified under the Data Privacy Framework — we put in place appropriate safeguards to ensure your personal data is treated in a way that is consistent with, and which respects, the Data Protection Legislation. These safeguards take the form of the UK International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses as appropriate.

Should you require further information about these safeguards, or a copy of them, please contact us using the details below. Further information on international transfers is available from the ICO at ico.org.uk.

Data security

We have put in place commercially reasonable and appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We also limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected data security breach, and will notify you and any applicable regulator of a breach where we are legally required to do so.

Use of AI-assisted tools

In delivering our services we may use artificial-intelligence tools to help us prepare documents, summarise information and carry out analysis. Where these tools process personal data, they do so on our instructions and under appropriate contractual safeguards. Some of these tools are provided by organisations based outside the UK, in which case the transfer is protected as described in the section “Transferring personal data outside the United Kingdom” above.

We do not use these tools to make decisions about you by automated means alone. A member of our team reviews the output and remains responsible for any decisions we make and any advice we provide.

Google Analytics and cookies

This website uses Google Analytics to help analyse how visitors use the site. The tool uses cookies — small text files placed on your device — to collect standard internet log information and visitor behaviour information. The information generated about your use of the website is used to evaluate how visitors use the site and to compile statistical reports on website activity.

We will not use the analytics tool to identify individual visitors, and we will not associate any data gathered from this site with information that identifies you personally, unless you explicitly submit that information via a form on our website. You can manage or refuse cookies through your browser settings and through the cookie controls on this website. For more information, please see the Google Analytics privacy policy.

Links to other websites

Where there are links from the Hive Business website to other websites, please note that we have no control over those sites, their content, or the way in which they collect or use personal data. We therefore strongly advise you to check the privacy policy of any site you visit.

Mailing list

When you provide personal data to Hive Business, we may use it to provide you with ongoing information about our products and services. We will not rent, sell or lease this personal data to other companies or individuals. If you join our mailing list, we will use the information you provide to contact you from time to time with news and information about Hive Business and the services we offer.

You can unsubscribe from our mailing list at any time. We will not provide your details to any other organisation, or use our mailing list to promote products and services on behalf of anybody else.

Your rights: access, correction, erasure and restriction

It is important that the personal data we hold about you is accurate and current. If your personal information changes, please notify us using the contact details below.

Under certain circumstances, by law you have the right to:

  • request access to your personal data, so you can receive details of the personal data we hold about you and check that we are processing it lawfully;
  • request correction of the personal data we hold about you;
  • request erasure of your personal data, where there is no good reason for us to continue processing it, or where you have successfully objected to processing;
  • object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and something about your particular situation makes you want to object. You also have the right to object where we are processing your personal data for direct marketing purposes;
  • request the restriction of processing of your personal data, for example so we can establish its accuracy or the reason for processing it; and
  • request the transfer of your personal data to you or another data controller, where the processing is based on consent or contract, is carried out by automated means, and this is technically feasible.

If you want to exercise any of the above rights, please email our Data Protection Point of Contact, Ross Martin, Director, at hello@hivebusiness.co.uk.

You will not have to pay a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee for the administrative costs of complying, or refuse to comply with the request, if your request is clearly unfounded or excessive. We may also need to request specific information from you to confirm your identity and ensure your right to access the information. This is an appropriate security measure to ensure that personal data is not disclosed to anyone who has no right to receive it.

Right to withdraw consent

In the limited circumstances where you have provided your consent to the collection, processing and transfer of your personal data for a specific purpose (for example, in relation to direct marketing that you have indicated you would like to receive from us), you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please email our Data Protection Point of Contact, Ross Martin, Director, at hello@hivebusiness.co.uk.

Once we have received notification that you have withdrawn your consent, we will no longer process your personal data for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.

Changes to this notice

Any changes we make to this privacy notice in the future will be updated on our website at hivebusiness.co.uk/privacy-policy. This privacy notice was last updated June 2026.

Contact us

If you have any questions regarding this notice, or if you would like to speak to us about the way in which we process your personal data, please email our Data Protection Point of Contact, Ross Martin, Director, at hello@hivebusiness.co.uk.

You also have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues, at any time. You can call the ICO on 0303 123 1113 (normal opening hours are Monday to Friday, 9am to 5pm, excluding bank holidays), or make a complaint via their website at ico.org.uk. We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please do contact us in the first instance.

Call Now Button