Privacy notice
Last updated: 9 August 2026
This notice explains how Haccora handles personal data under the UK GDPR, the Data Protection Act 2018 and, where electronic communications or device storage are involved, the Privacy and Electronic Communications Regulations. It covers our public website, account administration, support, web app and native apps.
1. Who is responsible for your data
For website visitors, account contacts, billing contacts and direct support requests, the controller is iTechLounge Ltd · hello@haccora.co.uk.
A subscribing food business is normally the controller for staff records, fitness-to-work reports, training records and operational food-safety evidence entered in its workspace. Haccora normally processes that data on the customer's documented instructions.
2. Personal data we handle
- Identity and account data, including name, work email, role and site membership.
- Subscription, invoice and transaction references.
- Checks, temperatures, cleaning, delivery, allergen, equipment, corrective-action and audit evidence.
- Induction, training, certificate-expiry and limited fitness-to-work information.
- Documents, photographs and files that authorised users choose to upload.
- Optional foreground GPS coordinates, accuracy, device time and server time when an authorised user scans an equipment QR label and permits location access.
- Device, sign-in, security, diagnostic, notification-token and audit-log data.
3. Sensitive information
Fitness-to-work information may reveal health data, which is special-category personal data. The customer must document a valid UK GDPR Article 6 basis and Article 9 condition, restrict access and avoid collecting unnecessary medical detail.
4. Why we use data
- Provide, secure and administer the service and authorised user accounts.
- Process subscriptions, invoices, support, service notices and customer requests.
- Detect misuse, investigate incidents and maintain audit evidence.
- Meet tax, accounting, legal and regulatory duties that apply to Haccora.
- Send marketing only where permitted and always provide an opt-out.
Depending on the activity, our controller bases are contract performance, legitimate interests, legal obligation or consent. When acting as processor, the customer determines the relevant legal bases.
5. Equipment scans and worker transparency
Haccora does not perform continuous or background location tracking. A location reading is requested only during an equipment QR workflow, is optional at device level and is stored with the scan accuracy so reviewers can understand its limits. The scan remains attributable when location is denied or unavailable.
Customers using scan location as worker-monitoring evidence must document why it is necessary and proportionate, identify an appropriate lawful basis, give workers clear privacy information, set a suitable retention period and complete a data-protection impact assessment where required. Employment consent should not be treated as valid merely because an app permission was accepted.
6. Recipients and international transfers
Access is limited to authorised customer users and suppliers needed for hosting, authentication, storage, payments, email, push notifications, malware scanning, support and monitoring. Where data leaves the UK, a lawful transfer mechanism and supplementary safeguards are used where required.
7. Retention and security
Data is retained only as long as needed for its purpose, legal claims, security, accounting or the customer's documented retention schedule. Haccora uses tenant-scoped controls, role and location permissions, private storage, encryption in transit, attributable timestamps and audit logging.
8. Your rights
- Access, rectification and, where applicable, erasure.
- Restriction, objection and portability where the legal conditions apply.
- Withdrawal of consent without affecting earlier lawful processing.
- A complaint to the Information Commissioner's Office.
Contact hello@haccora.co.uk. If the request concerns your employer's workspace, contact that organisation first. You can also read the ICO complaints guidance.