Legal

Privacy Policy

Last updated: 14 September 2026

HiveCFO Limited is committed to protecting your personal data. This policy explains what we collect, why we collect it, and your rights under UK GDPR and the Data Protection Act 2018. Two things are worth reading before you upload anything: our infrastructure is hosted in the United States (section 6), and documents you submit for verification are analysed by a third-party AI service (section 7).

1. Who we are

HiveCFO Limited ("HiveCFO", "we", "us", "our") is a company registered in England and Wales. Our registered office is 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. We operate the platform available at hivecfo.io ("Platform").

We are the data controller for personal data collected through the Platform. If you have questions about this policy, contact us at privacy@hivecfo.io.

2. What data we collect

We collect the following categories of personal data:

Account data — your name, email address, company name, and password (hashed) when you register.

Financial profile data — revenue figures, valuation inputs, industry classification, and company stage information you provide to generate valuations and readiness scores.

Uploaded documents — files you choose to upload for verification, which may include bank statements, management accounts, filed accounts, certificates of incorporation, and pitch decks. These may contain personal data about you, your directors, and your employees, including names, account holder details, and payroll figures. Section 7 explains how they are analysed.

Usage data — pages visited, features used, timestamps, and device and browser information collected automatically via logs.

Technical and security data — your IP address, which we process to apply rate limits, detect abuse, and protect the Platform. We do not store your IP address in your account record; it is held transiently for rate limiting and appears in our hosting provider's request logs.

Communications — messages you send us via the contact form or email, and questions you ask Hive AI.

Verification pack requests: when you request a HiveCert verification pack from a certificate's page, your work email address, your organisation, the reason you give, whether you agreed to be contacted, and the country your request came from. We do not store your IP address with the request.

Payment data — billing information processed by Stripe. We do not receive or store full card numbers on our servers.

3. How we use your data

We use your personal data to:

— Provide and maintain your HiveCFO account and Platform services — Generate HiveIndex valuations, readiness scores, and HiveCerts — Verify documents you upload, and check that the identity they evidence matches your account (see section 7) — Surface relevant leads via Growth Radar, matched to your offer profile — Send transactional emails (cert issuance, document verification, digest notifications) — Respond to your enquiries submitted via the contact form or Hive AI — Apply rate limits and detect abuse, to keep the Platform available and prevent fraudulent certification — Improve the Platform through aggregated, anonymised usage analytics — Comply with our legal obligations under UK law

If you request a HiveCert verification pack, we use your email address to send it to you, and we keep a record of the request (your organisation, the reason you gave and your country) so we know which certificates are being checked and by whom. We contact you about HiveCFO only if you tick the box on the request form asking us to.

We do not sell your personal data to third parties. We do not use your data for unsolicited marketing without your consent.

4. Legal bases for processing

Under UK GDPR, we rely on the following legal bases:

Contract — processing necessary to deliver the services you have signed up for.

Legitimate interests — usage analytics, fraud prevention, platform security, and sending and keeping a record of verification pack requests, where our interests do not override your rights.

Legal obligation — where we are required to retain or disclose data under applicable UK law.

Consent — for any optional marketing communications, including contacting you after a verification pack request if you ticked the box asking us to. You may withdraw consent at any time.

5. Processors we share data with

We do not sell personal data. We share it only with the processors below, each under a data processing agreement that binds them to process data solely on our instructions:

Firebase (Google) — database, authentication, and file storage. Holds your account record, financial profile, and every document you upload.

Vercel — Platform hosting and edge infrastructure. Its request logs contain IP addresses.

Stripe — payment processing and subscription billing. Stripe is a separate controller for its own fraud-prevention purposes; see stripe.com/privacy.

Resend — transactional email delivery. Receives your email address and the contents of emails we send you.

Anthropic — the Claude API, which powers document verification, Hive AI assistance, Growth Radar matching, and investor intelligence reports. Documents you upload for verification are transmitted to Anthropic in full, including any personal data they contain. Anthropic does not train its models on data submitted through its API.

OpenAI — text embedding of your Hive AI questions and manual searches, so we can retrieve the relevant help content. OpenAI does not train its models on data submitted through its API.

Upstash — three services: QStash schedules background jobs such as digest emails and lead syncs; Vector stores embeddings of our help content and of search queries submitted to it; Redis holds short-lived rate-limiting counters keyed on IP address, which expire automatically within minutes.

We may also disclose personal data where required by law, or to professional advisers under a duty of confidence.

6. Where your data is held, and international transfers

Our infrastructure is hosted in the United States. Specifically, our Firebase database and file storage are located in Google's US-EAST1 region, which means your account record, your financial profile, and the documents you upload are stored in the United States rather than in the United Kingdom or the EEA. Our other processors are likewise US-based.

This is a restricted transfer under UK GDPR. We rely on the International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, as incorporated into each processor's data processing terms, together with the technical measures described in section 11. You may request a copy of the relevant transfer mechanism by emailing privacy@hivecfo.io.

We state this plainly because an earlier version of this policy implied that transfers outside the UK and EEA were exceptional. They are not: they are how the Platform ordinarily operates.

7. Automated processing and AI

Two Platform features rely on automated analysis, and you should understand both before uploading anything.

Document verification. When you upload a document, its full contents are sent to the Claude API operated by Anthropic, which extracts identifying details such as the registered company name on a certificate of incorporation or the account holder name on a bank statement. Those extracted values are then compared against your HiveCFO company name by deterministic rules, not by the model, to decide whether the document supports a HiveCert. We also examine the file's own technical metadata for signs that it was edited after issue.

Effect on you. A verification outcome can prevent a HiveCert from being issued. That is a commercial consequence, so it is not left solely to automated processing: you may ask a person at HiveCFO to review any verification outcome by emailing privacy@hivecfo.io, and we will do so.

Hive AI. Questions you ask Hive AI are embedded by OpenAI and matched against our help content, then answered by the Claude API. Do not include personal data about other people in these questions; you do not need to, and we would rather you did not.

Neither Anthropic nor OpenAI trains models on data we submit through their APIs. Valuations and readiness scores are produced by our own deterministic calculations, not by a language model.

8. Data retention

We retain your personal data for as long as your account is active or as necessary to provide our services. If you request account closure, we will anonymise or delete your personal data within 30 days, except where retention is required by law (for example, financial records which may be retained for up to 7 years under UK tax law).

Verification pack requests are kept for 24 months and then deleted. You can ask us to delete yours sooner, or withdraw your consent to be contacted, by emailing privacy@hivecfo.io.

Aggregated, anonymised data derived from your usage may be retained indefinitely for analytics purposes.

9. Your rights

Under UK GDPR, you have the following rights:

Right of access — request a copy of the personal data we hold about you. Right to rectification — request correction of inaccurate data. Right to erasure — request deletion of your data where no legal basis for retention exists. Right to restriction — request we limit processing of your data in certain circumstances. Right to data portability — receive your data in a structured, machine-readable format. Right to object — object to processing based on legitimate interests. Right to withdraw consent — where processing is based on consent, withdraw it at any time.

To exercise any of these rights, email privacy@hivecfo.io. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Cookies

We use strictly necessary cookies to maintain your authenticated session. We do not use advertising or tracking cookies. We do not use third-party analytics cookies (e.g. Google Analytics).

You can control cookies through your browser settings. Disabling session cookies will prevent you from remaining logged in to the Platform.

11. Security

We implement appropriate technical and organisational measures to protect your personal data, including 256-bit AES encryption at rest, TLS encryption in transit, Firebase Authentication for session management, and role-based access controls. We conduct regular security reviews and restrict access to personal data to authorised personnel only.

No method of transmission over the internet is 100% secure. If you believe your account has been compromised, contact us immediately at security@hivecfo.io.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Platform. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Platform after changes constitutes acceptance of the updated policy.

13. Contact

For privacy-related enquiries:

HiveCFO Limited 71-75 Shelton Street Covent Garden London WC2H 9JQ United Kingdom

Email: privacy@hivecfo.io