Privacy Policy
How we collect, use, and protect your personal information
Last updated: 28 August 2026
This policy explains, in plain English, what personal information HomeHub Smart Solutions collects, why we collect it, where it is kept and what your rights are. We have tried to describe what we actually do, not what a template says we should do. If anything here is unclear, ring us on 01403 626006 and we will explain it.
1. Who we are and how to contact us
HomeHub Smart Solutions is the trading name of Home Hub Smart Solutions Limited, a company registered in England and Wales under company number 15412644. Our registered office is 88 Cook Way, Broadbridge Heath, Horsham, West Sussex, RH12 3US. In this policy, "we", "us" and "our" mean Home Hub Smart Solutions Limited.
We are the data controller for the personal information described in this policy. That means we decide how and why it is used, and we are responsible for looking after it. We are registered with the Information Commissioner's Office as a data controller under registration reference ZC233660.
You can contact us about anything in this policy by phone on 01403 626006, by email at [email protected], or by post to the registered office address above.
2. What we collect and where it comes from
We collect information when you enquire through the form on our website, call or text us, email us, book a free site survey, or become a customer. While we work with you, we build up a record of the job. Depending on how far things go, that record can include:
- Your name and contact details (phone number, email address, postal address)
- The address of the property where the work is to be done
- Details of your enquiry, such as the rooms involved, the equipment you have or want, and what you are trying to achieve
- Site survey notes and photos of the installation, before, during and after the work
- Quotes, job records, invoices and payment records (never full card numbers, see section 5)
- Correspondence with you, including emails to and from our info@ address, SMS conversations and notes of calls and visits
- WiFi network names and passwords, and device sign-in details, where we need them to set up and hand over your system (see section 6)
Two things about our phone system that you should know. First, calls to and from our business number may be recorded, and voicemail messages may be transcribed into text. We do this so we have an accurate note of what was discussed and agreed, and to keep an eye on the quality of our service. Second, if you call us and we cannot answer, our system may automatically send you a text message to let you know we have seen your call and will ring you back.
3. Why we use your information and our lawful bases
Data protection law says we need a proper reason (a "lawful basis") for everything we do with your information. In plain terms, ours are:
- To do the job you have asked for (contract). Preparing your quote, booking the survey and installation, doing the work, invoicing you, and looking after you under our 12-month workmanship guarantee.
- To run the business properly (legitimate interests). Keeping notes and records of enquiries and jobs, recording calls and transcribing voicemails so we have an accurate account of what was agreed, texting you back when we miss your call, and holding records in case a question or dispute comes up later.
- Marketing (consent). We only send marketing emails or texts if you have agreed to receive them, and you can stop them at any time (see section 7).
- Because the law says so (legal obligation). Keeping business and tax records for HMRC, and responding to lawful requests from authorities.
We do not make any decisions about you by purely automated means that have legal or similarly significant effects on you. Some first replies to new enquiries may be drafted and sent automatically to acknowledge you quickly, but a person reads every enquiry, and every quote, price and piece of advice comes from a person.
4. The systems and companies we use
We keep your data in as few places as we sensibly can. Our customer records (enquiries, quotes, jobs, invoices, notes) are held in our own CRM system, which runs on a server we own, located in the UK, and is backed up every night. Beyond that, these companies process data on our behalf:
- Microsoft 365 handles our email and calendar
- Twilio runs our phone lines and SMS
- Stripe processes card payments (see section 5)
- Cloudflare delivers our website and provides secure access to our customer portal at app.hhssuk.co.uk
- Hostinger hosts our website
- Google Analytics and Microsoft Clarity give us website statistics, and only run if you accept analytics cookies (see our Cookie Policy)
One thing we want to be clear about, because a lot of firms are vague on it. We use AI tools to help draft messages and to transcribe calls and voicemails, and those tools run on our own computers, on our own premises. Your information is not sent to third-party AI cloud services.
Setting up your smart devices often involves creating or configuring accounts with the device manufacturers (for example your camera, doorbell or speaker brand). Those accounts are yours, not ours: the manufacturer handles your data under its own privacy policy, and we walk you through what has been set up at handover.
Some of the companies listed above process data outside the UK. Where they do, the transfer is protected by safeguards approved under UK law, such as the UK Extension to the EU-US Data Privacy Framework or the UK International Data Transfer Agreement and Addendum built into their contracts. Ask us and we will tell you which safeguard applies to a provider and how to see it. We never sell your information to anyone.
5. Payments
Card payments (Visa, Mastercard, American Express, Apple Pay and Google Pay) are taken through secure Stripe payment links. Your card details go directly to Stripe, and we never see or store your full card number. Receipts come from Stripe. Stripe's handling of your card details is covered by its own privacy policy at stripe.com/privacy.
6. WiFi and device passwords
To set up your network and smart devices, and to hand everything over to you working and demonstrated, we sometimes need to keep hold of WiFi network names and passwords or device sign-in details. These are stored encrypted on our own systems and used only to support your installation. We keep them while your system is under our 12-month guarantee or an ongoing support arrangement with us, delete them when that ends, and delete them sooner if you ask.
7. Marketing and how to opt out
We only send marketing emails or texts to people who have agreed to receive them, and we keep a record of that consent. Every marketing message we send includes an unsubscribe link, and clicking it stops them. You can also opt out at any time by emailing [email protected] or calling us. Opting out of marketing does not affect the messages we need to send you about your own enquiry or job, such as quotes, appointment confirmations and invoices.
8. How long we keep your information
- Business records (quotes, invoices, job records and the correspondence that goes with them) are kept for at least 6 years, because tax law requires it. Site photos are kept as part of the job record.
- Call recordings and voicemail transcripts are kept for up to 12 months and then deleted, unless they form part of a job record or relate to an open question or dispute, in which case they are kept with that record.
- Enquiries that do not become jobs are deleted 12 months after our last contact with you.
- Marketing consent records are kept for as long as you are on our marketing list, so we can show your consent and honour your opt-out.
9. How we keep your information safe
Our customer records live on our own server in the UK, not scattered across third-party clouds, and are backed up nightly. WiFi and device passwords are stored encrypted. Access to customer data is limited to the people who need it to do their work, and our customer portal sits behind secure access provided by Cloudflare.
No system connected to the internet is ever completely secure, and we will not pretend otherwise. If a breach ever put your data at risk, we would report it to the ICO within 72 hours as the law requires, and tell you directly and promptly if it posed a real risk to you.
10. Your rights under UK GDPR
You have the right to:
- Ask for a copy of the personal information we hold about you
- Have anything inaccurate corrected
- Ask us to delete your information
- Ask us to restrict what we do with it
- Receive the information you gave us in a portable, machine-readable format (this applies to data we process electronically under the contract or consent bases)
- Object to how we are using it
- Withdraw any consent you have given, at any time
To use any of these rights, contact us using the details in section 1. There is normally no charge, we may need to check your identity first, and we will respond within one month. For a particularly complex request the law allows up to a further two months, and we would tell you within the first month if we needed that. Some records we are required to keep by law (such as invoices, for tax) cannot be deleted before their retention period ends, but we will always tell you what we can and cannot do.
11. CCTV systems we install
When we install a CCTV system at your home or business, the recorded footage is yours. You own and control it, and in day-to-day use we have no access to it. If you ask us to connect to your system remotely for support or maintenance, or take out a monitoring plan with us, we act only on your instructions and access footage only so far as that work needs.
If your cameras only capture your own private property, data protection law generally does not apply to your home use. Where they can see beyond your boundary, such as a street, a shared path or a neighbour's property, you have responsibilities of your own under data protection law, and we give you plain-English guidance on them at handover.
12. Guardian monitoring and children
Our Guardian service monitors the wellbeing of an adult being cared for, and the activity and alert data it produces is about that adult. Where the person being monitored is not our customer, we rely on our and their family's legitimate interests in safeguarding their wellbeing, and, because activity and alert data can reveal information about a person's health, we ask for the monitored person's explicit consent before the service goes live wherever they have capacity to give it. Where they do not, we ask the person arranging care to confirm they are authorised to act for them (for example under a Lasting Power of Attorney) and that monitoring is in the person's best interests. We explain the system to the monitored person in plain terms at installation, and they can use all the rights in section 10.
Our services are designed for adults and we do not market to children or ask them for information. Children may appear incidentally in things like site photos or camera test footage during an installation; we keep such material to the minimum needed for the job, treat it with the same care as everything else, and will remove it on request.
13. Cookies
Our website uses a small number of cookies, and analytics only runs if you agree to it when you first visit. Full details, including how to change your choice, are in our separate Cookie Policy.
14. Changes to this policy
If we change how we handle your information, we will update this page and change the date at the top. If a change is significant and you are an existing customer, we will make a point of telling you.
15. Questions and complaints
If you have a question or a complaint about how we have handled your information, please come to us first, and we will do our best to put it right. Contact Home Hub Smart Solutions Limited on 01403 626006, at [email protected], or by post to 88 Cook Way, Broadbridge Heath, Horsham, West Sussex, RH12 3US.
If you are not happy with our answer, you have the right to complain to the Information Commissioner's Office (ICO), the UK regulator for data protection, at ico.org.uk.