Legal

Privacy Policy

How we collect, use and protect personal information

This policy applies when you visit our website, contact us, request a quote, become a client, or use our services.

Version: 1.0 Last updated: 12 August 2026 Bristol, UK admin@resource4uweb.com resource4uhub.com

This notice explains how Resource4uHub Ltd uses personal information when you visit our website, contact us, request a review or quote, become a customer, use our services, or receive business communications from us. It also explains when we process information on behalf of our customers.

01 Who We Are

Resource4uHub Ltd (also referred to as “Resource4uHub”, “we”, “us” or “our”) is a digital services, hosting, software and automation business. For personal information covered by this notice, Resource4uHub Ltd is normally the data controller.

RESOURCE4UHUB LTD
Company number: 17284723
Registered office: 6 Bakers Ground, Bristol, United Kingdom, BS34 8GF
Email: admin@resource4uhub.com
Telephone: +44 (0)7988 681 925

02 When We Are A Controller And When We Are A Processor

We act as a controller for our website, enquiries, sales, customer administration, billing, our own marketing, security and business operations.When a customer uses our hosting, CRM, communication, AI-agent or automation services to handle the personal information of its own customers, staff, members, donors or users, that customer will usually be the controller and we will act as its processor. In that situation, the customer decides why and how the information is used, its privacy notice applies, and we process the information under the customer’s documented instructions and our data processing agreement.

03 The Personal Information We Collect

Information you give us

  • Identity and contact information, including your name, job title, organisation, email address, telephone number and postal address.
  • Enquiry and project information, including the service you need, business type, goals, challenges, budget, timescale and any information included in a message or free-review request.
  • Customer and contract information, including quotations, orders, project decisions, approvals, support requests and correspondence.
  • Account and access information, including usernames, permissions and authentication records. Please do not send passwords through an ordinary contact form or email unless we have provided an approved secure method.
  • Financial and transaction information, including invoices, payment status and limited payment references. Card or bank details are normally handled by the relevant payment provider rather than stored by us in full.
  • Marketing preferences and records of consent, objections, opt-outs and communications.

Information collected through the website and services

  • Technical information such as IP address, browser and device type, operating system, referring page, pages viewed, timestamps and security logs.
  • Cookie, consent and embedded-content information, including choices made through our cookie controls and interactions with video or other third-party content.
  • Service-usage and support information, such as system events, configuration, error logs, message delivery status and actions taken in an account.
  • Customer-provided data processed within hosted websites, forms, CRM systems, inboxes, calendars, AI agents and automated workflows where we act as a processor.

Information obtained from other sources

We may receive information from an authorised colleague or representative, a referring partner, a customer-selected integration, a payment or communications provider, or publicly available business sources such as company websites, professional profiles and public registers. If we use publicly available business contact information for relevant business-to-business outreach, we record the source and respect objections and opt-outs.

Our public enquiry forms are not designed for special category information (for example health information) or criminal-offence information. Please do not include such information unless it is necessary and we have agreed an appropriate secure process. Where a customer’s service legitimately requires sensitive information, the customer is responsible for identifying the relevant legal condition and safeguards, and we process it only under an appropriate agreement and instructions.

04 How We Use Personal Information And Our Lawful Bases

UK data protection law requires us to have a lawful basis for each use. The basis depends on the circumstances.

Purpose Typical information Lawful basis
Respond to enquiries, arrange a free review and prepare a quote Identity, contact, organisation and project information Steps at your request before a contract; and our legitimate interest in responding to genuine enquiries
Enter into and deliver a contract Customer, account, project, service-usage and transaction information Performance of a contract; or legitimate interests where the customer is an organisation and we deal with its representatives
Provide hosting, support, security, maintenance and service administration Account, technical, usage, support and security information Contract and legitimate interests in operating reliable and secure services
Invoice, collect payment and keep business and tax records Contact, contract, invoice and payment information Contract and legal obligations
Improve services, manage quality, train staff and develop our business Feedback, correspondence, service and usage information Legitimate interests, balanced against your rights
Prevent fraud, abuse and security incidents and establish or defend legal claims Identity, account, technical, security and correspondence information Legitimate interests and legal obligations
Send service messages and relevant direct marketing Contact details, customer relationship and preferences Contract for essential service messages; consent or legitimate interests for marketing, subject to PECR
Comply with law, regulators and lawful requests Information relevant to the request Legal obligation; or legitimate interests where appropriate

05 Direct Marketing And Your Right To Object

We may send relevant information about our services where you have asked for it, consented, or where the law allows us to rely on legitimate interests. The Privacy and Electronic Communications Regulations apply to email, text and similar marketing. We seek consent where required and provide a clear way to opt out.

You have an absolute right to object to the use of your personal information for direct marketing. Use the unsubscribe option in a message or email admin@resource4uhub.com. We may keep a minimal suppression record so that we continue to respect your choice.

06 Cookies, Similar Technologies And Embedded Content

Our website uses technologies needed to operate securely and remember choices. Optional technologies are used only where permitted, and consent is requested before non-essential storage or access technologies are enabled. You can accept, reject or change optional choices through the cookie settings available on the website.

Technology/category Why it is used Control and duration
Strictly necessary website, form and security functionality Operate WordPress pages, protect forms, prevent abuse and maintain essential service functions Used because it is necessary. Session-based or retained only for the short period needed for security and functionality.
Cookie/consent preference Remember whether you accepted or rejected optional technologies Strictly necessary to remember your request. Normally retained for up to six months before we ask again.
Embedded YouTube video Display video content on the website Optional media. YouTube/Google may receive IP address, browser/device information and interaction data, and may use cookies or similar storage. Enabled only after the required choice; provider retention may vary.
Externally delivered fonts Display the website consistently Google may receive technical request data such as IP address and browser information when font files are requested. This technology should not be used for advertising profiling.
Analytics or marketing technologies, if introduced Understand use of the site or measure campaigns Not enabled without the required consent. Exact providers, names and durations will be shown in the live cookie settings.

Third-party websites and embedded services have their own privacy information. Blocking optional cookies may affect embedded media but should not prevent access to core information or contact options. Browser controls can also delete or block cookies, although they may not replace consent controls for all technologies.

07 Who We Share Personal Information With

We share information only where necessary and subject to appropriate safeguards. Recipients may include:

  • hosting, cloud infrastructure, backup, security and technical-support providers;
  • CRM, communications, email, SMS, telephony, scheduling, automation and AI-service providers used to deliver an agreed service;
  • payment, accounting, banking and fraud-prevention providers;
  • customer-selected services and integrations, such as calendars, social channels, booking systems, CRMs or payment platforms;
  • professional advisers, insurers, auditors and contractors who need access for a defined business purpose;
  • regulators, law-enforcement bodies, courts or other parties where disclosure is required by law or needed to protect rights; and
  • a purchaser, investor or successor in connection with a genuine business sale, reorganisation or due-diligence process, subject to confidentiality and data protection requirements.

We do not sell personal information. Customer conversations and business data are used to provide the agreed service and are not used by us to train a general-purpose AI model unless the relevant controller has given separate, explicit written instructions and a lawful basis has been confirmed.

08 International Transfers

We aim to use UK or EEA hosting and processing for systems we control. Some providers, embedded content and customer-selected integrations may process or make information accessible outside the UK. Where a restricted transfer occurs, we use an available lawful mechanism, such as UK adequacy regulations or approved contractual safeguards (including the UK International Data Transfer Agreement or UK Addendum), and carry out any required risk assessment. Contact us if you want information about the safeguard relevant to a particular service.

09 How Long We Keep Personal Information

We keep information only for as long as needed for the purpose collected, legal and tax obligations, security, support and the establishment or defence of claims. Our normal starting points are below; a legal hold, dispute, contract or controller instruction may require a different period.

Record Normal retention approach
Enquiries and free-review requests that do not become customers Up to 24 months after the last meaningful contact, unless an earlier deletion request applies
Customer contracts, project approvals, delivery and key correspondence Contract duration and normally six years after it ends
Invoices, payments and statutory accounting records Normally six years, or longer where law requires
Support tickets, service and operational records For the contract and a proportionate period afterwards, normally up to 24 months unless needed for a claim or security investigation
Security and access logs Normally up to 12 months, unless an incident requires longer retention
Marketing contacts Until consent is withdrawn or you object, with periodic review of continued relevance
Consent and suppression records For as long as reasonably needed to demonstrate and respect the choice
Customer-controlled data where we are a processor As set out in the order or data processing agreement; on termination it is returned or deleted subject to agreed export arrangements, backup cycles and legal holds

10 Security

We use proportionate technical and organisational measures designed to protect personal information, including access controls, least-privilege permissions, secure hosting, encryption where appropriate, monitoring, updates, backups according to the relevant plan, supplier checks and removal of access when it is no longer needed. No internet service is completely secure, so please use the secure route we specify for credentials or sensitive data.

11 AI And Automated Processing

Our services may use AI to draft responses, classify enquiries, route messages, support booking, summarise communications or trigger approved workflows. We design these systems to work within agreed information, rules and human-handover points. We do not intend to make solely automated decisions about individuals that produce legal or similarly significant effects when acting as controller. If a customer instructs us to support processing that could have such effects, the customer must identify the lawful basis, provide required information and put appropriate human review and challenge arrangements in place.

12 Your Data Protection Rights

Depending on the circumstances and lawful basis, you may have the right to:

  • ask for access to your personal information and a copy of it;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information in certain circumstances;
  • ask us to restrict how information is used in certain circumstances;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • receive certain information in a portable format or ask for it to be transferred;
  • withdraw consent at any time where we rely on consent, without affecting earlier lawful processing; and
  • ask for human intervention and challenge certain solely automated decisions, where applicable.

Rights are not absolute and may depend on the legal basis and circumstances. We may ask for information needed to verify identity and authority. We normally respond within one month and do not charge a fee unless the law allows it.

If your request concerns information controlled by one of our customers, contact that customer first. We will support the customer in responding where we act as its processor.

13 Children

Our website and commercial services are not directed to children, and we do not knowingly invite children to submit enquiries. A customer may use an agreed service in a context involving children, but the customer remains responsible for the relevant lawful basis, transparency, age-appropriate design and safeguarding requirements.

14 Complaints

Please contact us first so we can try to resolve a concern. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority.ICO website: ico.org.uk/make-a-complaint  |  Telephone: 0303 123 1113

15 Changes To This Notice

We may update this notice when our services, suppliers or legal obligations change. The current version will be published on the website with its last-updated date. If a change materially affects how we use information, we will take reasonable steps to bring it to the attention of affected people before the new use begins.

16 Contact Us

For questions, rights requests, objections or complaints about personal information, contact the Privacy Lead at:

RESOURCE4UHUB LTD
Company number: 17284723
Registered office: 6 Bakers Ground, Bristol, United Kingdom, BS34 8GF
Email: admin@resource4uhub.com
Telephone: +44 (0)7988 681 925
Questions?

Not sure how this applies to you?

Ask us directly and we will give you a straight answer in plain English - no legal jargon.