Skip to content
Legal

Data Protection

Placeholder draft, last updated July 2026. To be reviewed by a qualified UK data protection professional before publication, particularly given the handling of patient and client data across healthcare, property and accountancy verticals.

1. Our commitment

Hivedesk processes personal data, including any client, patient or tenant data handled on your behalf, in line with UK GDPR and the Data Protection Act 2018.

2. Data processing role

Where Hivedesk handles data on your behalf (for example, patient booking records or applicant details), we act as a data processor and you remain the data controller. A Data Processing Agreement (DPA) is put in place alongside your SLA before any such data is handled.

3. Access controls

  • Company-owned email and password management, so assistants never hold your credentials directly in personal accounts
  • Role-based access limited to what's needed for the assigned scope
  • Screen-recording, time-tracking and call monitoring available on request for full transparency
  • Financial details are never shared directly with assistants

4. International transfers

Our delivery team operates outside the UK. Where personal data is transferred internationally as part of service delivery, we put appropriate safeguards in place, such as UK International Data Transfer Agreements (IDTA), in line with ICO guidance.

5. Data breach response

In the event of a data breach affecting your data, we will notify you without undue delay so you can meet your own regulatory obligations, including any requirement to notify the ICO within 72 hours where applicable.

6. Sub-processors

We maintain a list of any third-party tools or sub-processors used in service delivery (e.g. CRM, scheduling or communication platforms) and will disclose these on request.

7. Contact

Data protection queries can be sent to hello@hivedesk.co.uk.