Privacy Policy

    UK Biz Network

    How we protect and handle your personal information

    info@ukbiznetwork.comhttps://ukbiznetwork.com/
    UK GDPR CompliantCCPA CompliantGoogle Play Compliant

    Last updated: June 27, 2026

    1. Introduction & Identity of Controller

    UK Biz Network(“we”, “us”, “our”) is the data controller responsible for your personal information. We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable international privacy laws including the California Consumer Privacy Act (CCPA).

    This policy applies to all users of our website, mobile application (including our Progressive Web App and any Google Play Store release), and related services.

    Contact: info@ukbiznetwork.com — Website: https://ukbiznetwork.com/

    2. Personal Data We Collect

    We collect the following categories of personal data:

    Data CategoryExamplesCollected?Shared?
    IdentityName, usernameYesNo
    ContactEmail addressYesNo
    Contact (optional)Phone, addressOptionalNo
    AuthenticationHashed password, session tokenYesNo
    ProfileProfile image, language preferenceOptionalNo
    Usage / AnalyticsPages visited, click events, time on siteYesYes — anonymised
    Device / TechnicalIP address, browser type, OSYesNo
    CookiesSession cookies, preference cookiesYesNo
    User ContentBusiness listings, blog commentsIf submittedPublic
    PaymentWe do not collect payment data directlyNoNo

    3. Legal Basis for Processing (UK GDPR)

    • Contract: Processing your account data to deliver our services (Art. 6(1)(b)).
    • Legitimate Interests: Security, fraud prevention, analytics (Art. 6(1)(f)).
    • Consent: Marketing emails, non-essential cookies — you may withdraw at any time (Art. 6(1)(a)).
    • Legal Obligation: Compliance with UK law where required (Art. 6(1)(c)).

    4. How We Use Your Information

    • Provide and improve our platform and services
    • Authenticate you securely and maintain your session
    • Send transactional emails (password reset, email verification)
    • Send marketing communications only with your explicit consent
    • Analyse traffic and usage patterns (anonymised where possible)
    • Detect and prevent fraud, abuse, and security incidents
    • Comply with legal obligations and respond to lawful requests

    5. Data Retention Periods

    We retain personal data only for as long as necessary:

    Data TypeRetention Period
    Account / Profile dataUntil account deletion + 30 days
    Session tokens30 days or logout
    Activity / Audit logs12 months
    Email verification tokens24 hours
    Password reset tokens1 hour
    Analytics data (anonymised)26 months
    Legal / Compliance records7 years (legal obligation)

    6. Third-Party Services & SDKs

    We use the following third-party services. Each has its own privacy policy:

    • Google Analytics — Usage analytics. Data may be transferred to the US. Privacy Policy
    • Cloudinary / ImageKit — Media hosting and image optimisation
    • SMTP Provider (Nodemailer) — Transactional email delivery
    • Prabisha SDK — Platform analytics and chatbot functionality
    • Google OAuth — Optional sign-in via Google account
    • reCAPTCHA v3 — Bot and fraud prevention

    We do not sell your personal data to any third party.

    7. Cookies

    We use cookies to operate the platform and improve your experience. You can manage your cookie preferences via the banner shown on your first visit, or at any time through your browser settings.

    • Strictly necessary: Authentication session, CSRF token — cannot be disabled
    • Analytics: Google Analytics — disabled by default, requires your consent
    • Marketing: Ad tracking — disabled by default, requires your consent

    See our full Cookie Policy for details.

    8. Your Rights

    Access (Art. 15)

    Request a copy of all personal data we hold about you.

    Rectification (Art. 16)

    Correct inaccurate or incomplete data via your profile settings.

    Erasure (Art. 17)

    Request permanent deletion of your account and data.

    Portability (Art. 20)

    Download your data in machine-readable JSON format.

    Objection (Art. 21)

    Object to processing based on legitimate interests.

    Restriction (Art. 18)

    Request we restrict processing while a dispute is resolved.

    Exercise any right by visiting your Profile Settings → Privacy & Data or emailing info@ukbiznetwork.com. We respond within 30 days.

    9. California Residents — CCPA Rights

    If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

    • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
    • Right to Delete: Request deletion of personal information we have collected, subject to certain exceptions.
    • Right to Opt-Out: We do not sell your personal information. No opt-out is required.
    • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

    To submit a CCPA request, email us at info@ukbiznetwork.comwith the subject “CCPA Request”.

    10. International Data Transfers

    Some of our third-party service providers (e.g. Google Analytics) may process data outside the UK and EEA. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO).

    11. Children's Privacy

    Our services are not directed at children under 13 years of age (or 16 in the EU/UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us immediately and we will delete it.

    12. Security

    We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction, including:

    • HTTPS/TLS encryption for all data in transit
    • Bcrypt password hashing — plaintext passwords are never stored
    • Secure, httpOnly, sameSite session cookies
    • Rate limiting and CSRF protection on all API routes
    • Role-based access control with audit logging
    • Two-factor authentication (2FA) available for all accounts

    13. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via a prominent notice on our website. The “Last Updated” date at the top of this page reflects the most recent revision. Continued use of our services after changes constitutes acceptance of the updated policy.

    14. Contact & Complaints

    For any privacy questions or to exercise your rights, contact our Data Protection contact:

    info@ukbiznetwork.com

    If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk | 0303 123 1113.