Data Protection
Data Handling Policy
Last updated 25 June 2026
HeroPerks is committed to handling personal data responsibly, transparently, and securely. This policy explains how we collect, use, store, and protect personal data in line with UK data protection laws, including the UK GDPR and the Data Protection Act 2018.
1. Purpose of This Policy
This policy ensures that all personal data handled by HeroPerks is:
- Processed lawfully, fairly, and transparently
- Collected for specific and legitimate purposes
- Limited to what is necessary
- Accurate and kept up to date
- Stored securely
- Handled in line with individuals’ rights
2. Types of Data We Handle
We may collect and process the following types of data:
Personal Identification Data — Name, email address, contact details
Account Data — Login details, preferences, usage activity
Business / Partner Data — Company names, contact details, service information
Financial Data — Invoices, payment records (where applicable)
Technical Data — IP address, browser type, device data, cookies
Communication Data — Emails, enquiries, support messages
We do not intentionally collect sensitive (special category) data unless required and lawful.
3. How We Collect Data
We collect data through:
- Website registrations and account creation
- Email subscriptions and marketing sign-ups
- Direct contact (email, phone, forms)
- Partner onboarding processes
- Cookies and analytics tools
4. How We Use Data
We use personal data to:
- Provide and manage our services
- Manage user accounts
- Communicate with users and partners
- Deliver relevant offers and updates
- Improve our website and user experience
- Process payments
- Comply with legal obligations
5. Lawful Basis for Processing
We rely on the following lawful bases:
Consent — for marketing and optional communications
Contract — to deliver our services
Legal obligation — where required by law
Legitimate interests — for business operations and improvements
6. Data Sharing
We may share data with trusted third parties where necessary, including:
- Technology and hosting providers
- Email and communication platforms
- Payment processors
- Professional advisers (legal/accounting)
- Regulatory authorities where required
All third parties are required to handle data securely and only for agreed purposes.
We do not sell personal data.
7. Data Storage and Security
We use appropriate measures to protect data, including:
- Secure cloud-based systems
- Access controls and permissions
- Encryption where appropriate
- Regular security monitoring
- Staff awareness and training
Only authorised individuals can access personal data.
8. International Data Transfers
If data is transferred outside the UK, we ensure appropriate safeguards are in place, such as:
- UK-approved adequacy decisions
- Standard contractual clauses
- Approved certification frameworks
9. Data Retention
We only retain personal data for as long as necessary. For full details, please see our Data Retention Policy.
10. Your Rights
Under UK data protection law, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion (where applicable)
- Restrict or object to processing
- Request transfer of your data
- Withdraw consent at any time
11. Data Breaches
We have procedures in place to detect, investigate, and report data breaches. Where required, we will notify the Information Commissioner’s Office (ICO) and affected individuals.
12. Responsibility and Governance
Responsibility for data protection sits with:
- Company Directors
- Appointed Data Protection Lead
All staff and partners must follow this policy, handle data securely, and report any concerns immediately.
13. Policy Review
This policy is reviewed at least once per year, or when legal or operational changes require updates.
14. Contact Us
If you have any questions about this policy or your data, please contact: [email protected]
Legal responsibility for the content on this page sits with Employees Global Ltd.