Skip to main content
SEGHU

Legal

Privacy Policy

Last updated: 15 June 2026

1. Who we are

Seghu is a product of hibretOne CIC, a Community Interest Company registered in England and Wales (Company No. 13622819), whose registered office is in Birmingham, West Midlands. hibretOne CIC is the data controller for personal data collected through this platform.

Contact us at: info@hibretone.org

2. What data we collect

We collect the following categories of personal data:

  • Account data — name, email address, and password (hashed) when you create an account.
  • Project data — your responses to the Structure Assessment, Funding assessment, and any documents you generate. This data is linked to your account.
  • Usage data — pages visited, features used, and session duration, collected via server logs.
  • Contact data — any information you send us when you contact us by email (for example, hello@seghu.org).

We do not collect payment card details directly. Payment processing (where applicable) is handled by third-party providers.

3. Why we process your data

PurposeLegal basis
Providing the platform and your accountContract performance (Article 6(1)(b) UK GDPR)
Improving the platformLegitimate interests (Article 6(1)(f) UK GDPR)
Responding to enquiriesLegitimate interests
Complying with legal obligationsLegal obligation (Article 6(1)(c) UK GDPR)

4. Who we share your data with

We share data only with processors acting on our behalf:

  • Supabase (database and authentication) — EU-hosted infrastructure.
  • Vercel (frontend hosting) — processes request logs.
  • Railway (backend hosting) — processes API requests.
  • OpenAI — receives text you submit for AI-assisted improvements. We do not send identifying information to OpenAI. OpenAI is not used to make decisions about you.

We do not sell your personal data to any third party.

5. How long we keep your data

Account and project data is retained for as long as your account is active. If you delete your account, your data will be removed within 30 days. Document exports are retained until you delete them. Emails you send us are retained for up to 2 years.

6. Your rights

Under UK GDPR you have the right to:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data we hold about you.
  • Erasure — request deletion of your data ("right to be forgotten").
  • Restriction — ask us to limit how we use your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.

To exercise any of these rights, email us at info@hibretone.org. We will respond within one month.

You can also download a machine-readable copy of your account data at any time from Settings → Privacy & Data within the platform. To delete your account, email us and we will erase your data within 30 days.

7. Cookies and local storage

We keep you signed in using an authentication token stored in your browser's local storage (not a cookie), which is sent with each request to identify you. We do not use advertising or cross-site tracking cookies. If we run product analytics or A/B testing, these rely on privacy-preserving, first-party measurement only — and where the law requires consent for any non-essential cookie or similar technology, we will ask for it before it is set.

8. Security

Passwords are hashed before storage. All data is transmitted over HTTPS. Access to production systems is restricted to authorised personnel only.

9. Complaints

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Changes to this policy

We will update this policy as the platform evolves. Material changes will be communicated by email or by a notice on the platform. The date at the top of this page reflects the most recent revision.