Privacy Policy
Last Updated: September 2026 · BIZZLOOP LTD (Company No: 17319641)
Data Controller: BIZZLOOP LTD (Company No: 17319641) is the Data Controller responsible for personal data processed through this website (bizzloop.co.uk) and our commercial customer relationships under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.
1. Categories of Personal Data We Collect
We only collect personal information that is necessary to deliver our services, answer enquiries, and fulfill statutory obligations:
- Contact & Identity Data: Name, professional email address, telephone/WhatsApp number, job title, and company name.
- Commercial & Operational Data: Business sector, operational workflows, enquiry requirements, and communication logs.
- Billing & Transaction Data: Invoicing details, payment verification records, and transaction history (payment card numbers are processed directly by certified UK payment processors and are never stored on our servers).
- Technical & Browsing Data: IP address, browser type and version, operating system, page response timings, and referral URLs collected via privacy-first aggregated logs.
2. Lawful Bases for Processing (UK GDPR Article 6)
We process your personal data under the following recognized legal grounds:
- Performance of a Contract: Necessary to provide our managed platform, set up client instances, deliver customer support, and execute billing.
- Legitimate Interests: Necessary for the proper administration of our business, responding to client enquiries, maintaining platform security, and preventing fraudulent misuse.
- Consent: Where you have provided explicit opt-in consent, such as subscribing to our growth newsletter or accepting non-essential analytics cookies.
- Legal Obligation: Necessary to comply with UK statutory obligations, including HMRC financial records retention and anti-fraud regulations.
3. How We Store & Protect Your Data
We employ robust technical and organizational security measures to protect your information:
- UK Data Residency: All client databases and platform infrastructure are hosted in certified, high-security UK cloud data centres.
- End-to-End Encryption: All data transmitted between your browser and our servers is encrypted using modern TLS 1.3 encryption protocols. Databases are encrypted at rest using AES-256 standards.
- Access Controls: System access is strictly restricted to authorised personnel via multi-factor authentication and role-based access protocols.
4. Third-Party Disclosures & Sub-processors
We never sell, rent, or trade your personal data to third parties for marketing purposes. Data is shared strictly with essential service partners under binding UK GDPR data processing agreements:
- Secure UK cloud infrastructure and server hosting providers.
- PCI-DSS compliant payment processing gateways.
- Business communication infrastructure (transactional email and WhatsApp APIs).
- Professional advisors, accountants, and law enforcement agencies where strictly required by UK law.
5. Data Retention Periods
We retain personal data only as long as necessary to fulfill the purposes for which it was collected:
- Active Account Data: Retained for the duration of your active subscription contract.
- Enquiry Data: Unconverted prospect enquiries are reviewed and purged after 24 months of inactivity.
- Statutory Financial Records: Invoices, payment records, and tax filings are retained for 6 full financial years in compliance with HMRC statutory rules.
6. Your Statutory Rights Under UK GDPR
As an individual in the United Kingdom, you hold comprehensive rights regarding your personal data:
- Right of Access (SAR): You can request a copy of the personal data we hold about you, free of charge, answered within 30 days.
- Right to Rectification: You can request the correction of any inaccurate or incomplete personal information.
- Right to Erasure: You can ask us to delete your personal data where there is no overriding legal ground for retention.
- Right to Restrict Processing: You can request that we suspend processing your data under certain conditions.
- Right to Data Portability: You can receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object: You can object at any time to the processing of your data for direct marketing purposes.
7. Exercising Rights & Regulatory Supervision
To exercise any of your statutory rights, email our Data Protection team at [email protected]. We respond to all verified requests within 30 calendar days.
If you are not satisfied with our response or believe your data is not being handled lawfully, you have the statutory right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 · Website: ico.org.uk