Legal and Compliance
Privacy Policy
Last updated 25 June 2026
This Privacy Policy explains how HeroPerks collects, uses, and protects your personal data when you use our website and services. We are committed to handling your data transparently and in accordance with UK data protection laws, including the UK GDPR and the Data Protection Act 2018.
1. Who We Are
HeroPerks is a platform that connects employees within Partner Organisations with exclusive offers, services, and trusted local businesses. For the purposes of data protection law, we act as a Data Controller when determining how and why your personal data is used.
2. What Information We Collect
Personal Information — Name, email address, and contact details
Account Information — Login details, preferences, and usage activity
Business / Partner Information — Business contact details and service information (where applicable)
Technical Data — IP address, browser type, device information, and cookies
Communication Data — Messages, enquiries, and support requests
We do not intentionally collect sensitive (special category) data unless required and lawful.
3. How We Collect Your Data
We collect data when you register or create an account, subscribe to emails or updates, contact us directly, use our website (via cookies and analytics tools), or interact with partner listings or services.
4. How We Use Your Data
We use your data to provide and manage your account, deliver relevant offers and services, communicate with you, improve our platform and user experience, manage partnerships and listings, and comply with legal obligations.
5. Lawful Basis for Processing
Consent — for marketing communications
Contract — to provide our services
Legal obligation — to meet regulatory requirements
Legitimate interests — to improve our platform and prevent misuse
6. How We Share Your Data
We may share your data with trusted third parties where necessary, including technology and hosting providers, email and communication platforms, payment processors, professional advisers, and regulatory authorities (where required). All third parties are required to process your data securely and only for agreed purposes. We do not sell your personal data.
7. Data Security
We take appropriate steps to protect your data, including secure systems and infrastructure, access controls and permissions, encryption where appropriate, and regular monitoring and updates. Only authorised individuals have access to your data.
8. International Transfers
Where data is transferred outside the UK, we ensure appropriate safeguards are in place, such as UK adequacy decisions, standard contractual clauses, or approved legal mechanisms.
9. How Long We Keep Your Data
We only retain your data for as long as necessary. For more information, please see our Data Retention Policy.
10. Your Rights
You have the right to access your personal data, correct inaccurate information, request deletion (where applicable), restrict or object to processing, request transfer of your data, and withdraw consent at any time. To exercise your rights, please see Data Rights & Requests.
11. Cookies
We use cookies and similar technologies to improve your experience and understand how our website is used. For more details, please see our Cookie Policy.
12. Data Breaches
We have procedures in place to detect and respond to data breaches. Where required, we will notify the Information Commissioner’s Office (ICO) and affected individuals.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services or legal obligations. This Privacy Policy should be read alongside our Data Handling Policy, Data Retention Policy, and Cookie Policy.
14. Contact Us
If you have any questions about this Privacy Policy or your data, please contact: [email protected]
Legal responsibility for the content on this page sits with Employees Global Ltd.