Hapstar Limited (“Hapstar”, “we”, “us”, or “our”) is committed to protecting and respecting your privacy. This Privacy & Cookie Policy explains how we collect, use, store and protect personal data when:

  • you use the Hapstar platform through your organisation or institution; or
  • you visit our public website or communicate with us directly.

We comply with:

  • the UK General Data Protection Regulation (UK GDPR)
  • the Data Protection Act 2018
  • other applicable data protection and privacy laws.

Where required, we also comply with the EU General Data Protection Regulation (EU GDPR).

Our aim is to ensure that personal data is handled lawfully, transparently, securely and with respect at all times.

1. SCOPE OF THIS POLICY

This Privacy Policy applies to two categories of individuals:

Platform Users

Individuals who access Hapstar through their employer, organisation, NHS Trust, or education provider (“Institution”).

In this case:

  • the Institution acts as the Data Controller
  • Hapstar acts as the Data Processor

Hapstar processes personal data only on the instructions of the Institution in order to provide the platform and associated services.

Website Visitors

Individuals who visit the Hapstar public website or contact us directly.

In this case:

  • Hapstar acts as the Data Controller.

2. WHO WE ARE

Hapstar Limited is a UK technology company providing digital wellbeing and mental health support platforms.

Registered Company: Hapstar Ltd

Company Number: 12488063

Registered Address:

19 Park Road

London

E12 5HG

Hapstar is registered with the Information Commissioner’s Office (ICO).

ICO Registration Number: ZB495969

For privacy enquiries you may contact us at:

hello@hapstar.app

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at:

www.ico.org.uk

3. PERSONAL DATA WE COLLECT

3.1 Platform Users

When you use the Hapstar platform through an Institution, we may process the following information:

Account information

  • email address and/or mobile number provided by your Institution.

Organisation-related information (where provided by the Institution)

  • gender
  • location
  • job function or role
  • job type or department
  • salary band (if relevant to the Institution).

Platform usage data

Automatically collected information such as:

  • IP address and general location
  • device information
  • browser type and operating system
  • login activity
  • navigation through the platform
  • assessments completed and related scores.

User-generated content

Content voluntarily submitted through platform features such as:

  • Speak Up
  • Community
  • Share Thoughts.

Users may choose to submit comments anonymously or with their identity.

All such data is encrypted in transit and at rest.

3.2 Website Visitors

When you visit our public website or contact us directly we may collect:

Contact information

If you submit a form, request a demo or contact us:

  • name
  • email address
  • organisation
  • phone number (if provided).

Technical and usage data

Including:

  • IP address
  • device and browser information
  • pages visited
  • time spent on the website
  • navigation behaviour.

Cookie and analytics data

Collected through cookies or similar technologies used to improve website performance and user experience.

4. HOW WE COLLECT PERSONAL DATA

We collect personal data in several ways:

From your Institution

When your organisation provides account access to the Hapstar platform.

Directly from you

When you:

  • register or log into the platform
  • complete wellbeing assessments
  • submit feedback or comments
  • contact us through our website.

Automatically

Through cookies, analytics tools and system logs when you use the platform or browse our website.

5. HOW WE USE PERSONAL DATA

5.1 Platform Users

Hapstar processes personal data on behalf of the Institution in order to:

  • provide and operate the Hapstar platform
  • deliver wellbeing assessments and support tools
  • manage user accounts
  • provide technical support
  • maintain security of the platform
  • generate aggregated and anonymised insights for organisations.

Organisations are not able to identify individual users from wellbeing data under normal circumstances.

The legal basis for this processing is determined by the Institution acting as Data Controller.

5.2 Website Visitors

When Hapstar acts as the Data Controller, we may process personal data to:

  • respond to enquiries and demo requests
  • communicate about our platform and services
  • improve our website functionality and performance
  • understand how visitors use our website
  • maintain security and prevent misuse of our systems.

The legal bases for processing may include:

  • Legitimate interests (operating and improving our services)
  • Consent (for cookies or marketing communications)
  • Pre-contractual steps where you request information about our services.

6. COOKIES

Cookies are small text files placed on your device when you visit a website.

They help websites function properly and provide information about how visitors use the site.

We may use:

Essential cookies

Required for basic website functionality and security.

Functional cookies

Used to remember preferences and improve user experience.

Analytical cookies

Used to understand how users interact with our website so we can improve it.

Where required by law, we will request your consent before placing non-essential cookies on your device.

You may manage cookie preferences through the cookie banner or through your browser settings.

7. SHARING PERSONAL DATA

We do not sell personal data.

Personal data may be shared only in limited circumstances.

Platform Users

Your Institution may receive aggregated and anonymised insights, but will not be able to identify individual users unless a safeguarding situation requires it (see Section 8).

Service Providers

We may use trusted third-party providers to support our services, including:

  • cloud hosting providers
  • data storage providers
  • security services
  • technical infrastructure providers.

These providers process data only on our instructions and are bound by strict confidentiality and security obligations.

Legal Requirements

We may disclose personal data where required by law or where requested by:

  • regulators
  • courts
  • law enforcement agencies.

8. SAFEGUARDING AND WELFARE ESCALATION

Your safety is a priority.

The Hapstar platform includes features designed to identify when someone may require urgent support.

Under normal circumstances, organisations cannot identify individual users from platform data.

However, anonymity may be overridden in exceptional safeguarding situations, including where:

  • there is an imminent risk to life or safety
  • there is a risk of serious harm to the user
  • there is a risk of serious harm to another person
  • disclosure is legally required.

In such cases, Hapstar may provide limited identifying information to the Institution’s safeguarding team where necessary to protect vital interests.

The legal basis for this processing is UK GDPR Article 6(1)(d) – protection of vital interests.

Only the minimum necessary information will be disclosed.

9. DATA RETENTION

Personal data is retained only for as long as necessary for the purposes for which it was collected.

Retention periods depend on the type of data and context:

  • Platform user data is retained according to the agreement between Hapstar and the relevant Institution.
  • Website enquiry data is typically retained for up to 24 months unless a longer period is required for legal or operational reasons.
  • Technical and analytics data may be retained for shorter periods depending on analytics provider settings.

When personal data is no longer required it will be securely deleted or anonymised.

10. INTERNATIONAL DATA TRANSFERS

Where personal data is transferred outside the UK or the European Economic Area, appropriate safeguards will be implemented.

These may include:

  • adequacy decisions
  • standard contractual clauses
  • equivalent legally recognised protection mechanisms.

11. SECURITY

We implement appropriate technical and organisational security measures to protect personal data against:

  • unauthorised access
  • accidental loss
  • destruction or damage.

Security measures include:

  • encrypted data transmission (SSL)
  • secure hosting environments
  • access controls and authentication systems
  • ongoing security monitoring and improvement.

While we take reasonable steps to protect data, communications over the internet cannot be guaranteed to be completely secure.

12. YOUR DATA PROTECTION RIGHTS

Individuals have the right to:

  • access their personal data
  • correct inaccurate data
  • request deletion of personal data
  • restrict processing in certain circumstances
  • object to processing
  • request portability of certain data
  • lodge a complaint with a supervisory authority.

Platform users should normally submit requests through their Institution, which acts as the Data Controller.

Hapstar will support the Institution in responding to such requests where required.

Website visitors may contact Hapstar directly at:

hello@hapstar.app

13. USERS AGED 16-17

Hapstar is not intended for use by individuals under the age of 16.

If we become aware that someone under 16 has created an account, we will suspend the account and delete associated personal data.

For users aged 16-17, access is permitted only through an approved educational institution that acts as the Data Controller.

These institutions are responsible for:

  • obtaining any necessary consents
  • supervising use of the platform
  • appointing a Designated Safeguarding Lead.

14. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time.

The latest version will always be available on our website.

Where significant changes are made, we may notify users via:

  • a notice within the platform, or
  • email notification where appropriate.

Continued use of the platform or website indicates acceptance of the updated policy.

Last updated: 21 August 2026