Legal
Privacy Policy
This policy explains what personal data HNDOVR™ collects when you use hndovr.app, how we use it, who we share it with, and your rights under UK GDPR. Privacy operations are aligned with ISO/IEC 27701:2025; that is not a certification.
Last updated: 19 August 2026
Who we are
HNDOVR™ is a UK software platform for trade businesses to create digital handovers for their customers. For privacy queries contact info@hndovr.app.
For account and marketing-site data we are the controller. For names, addresses, photos and documents you put in a customer HNDOVR™ we are the processor and you (the trade business) are the controller. Chimney Sweeps Near Me enquiries we collect on that directory are described in the CSNM privacy notice when you use that site.
ISO/IEC 27701
We maintain an internal privacy information management system aligned with ISO/IEC 27701:2025 (the current standalone PIMS standard). We are not ISO 27701 certified. ISO does not certify organisations. The truthful statement until a certification body issues a certificate is: privacy management aligned with ISO/IEC 27701.
What we collect
- Account and business details (name, email, phone, company name, handle, address).
- Customer, project, product, document, photo and handover records you upload.
- Booking, payment and support information where those features are used.
- Technical data such as IP address, device/browser type, and security logs.
How we use your data
- To provide the HNDOVR™ service, including customer portals, bookings and support tickets.
- To authenticate users, prevent abuse, and keep the platform secure.
- To send transactional email (handovers, bookings, password and account notices).
- To improve the product and meet legal obligations.
Legal bases
We process personal data to perform our contract with you, for legitimate interests in operating and securing the service, and where required by law. Where we rely on consent (for example optional marketing), you can withdraw it at any time.
Sharing and subprocessors
We do not sell personal data. We use trusted processors under contract. Core subprocessors currently include Clerk (authentication), Stripe (payments where enabled), and Resend (transactional email), plus our hosting provider. Optional social networks are only used if you connect them in Marketing. See Security for the live list.
Customer portal content is shared with the people you send a HNDOVR™ link to. You are responsible for what you upload and who you share it with.
International transfers
Some processors may process data outside the UK. Where that happens we use appropriate safeguards such as UK IDTA / EU SCCs offered by those providers.
Retention
We keep account and handover data for as long as the organisation remains active and as needed for legal, tax and dispute purposes. You can ask us to delete an organisation account; we will erase or anonymise personal data unless we must retain it.
Your rights
Where we are the controller, you can request access, correction, deletion, restriction or portability of your personal data, and object to certain processing. Email info@hndovr.app. We aim to acknowledge within five business days and complete within one month of a valid request. You may complain to the UK Information Commissioner’s Office (ICO).
If you are named in a handover another business created, contact that business first. We will help them export or delete what we store when they instruct us.
Cookies
Essential cookies are required for sign-in and security (including Clerk session cookies). We do not use advertising cookies on the marketing site.