Privacy Policy
Halo Connected Health is a product of DXN Design Ltd, registered in Northern Ireland (company number NI684155). This policy explains what personal data we collect through haloconnectedhealth.com, why we collect it, how we protect it, and the rights you have over it. It applies to the marketing website only — the Halo platform itself has separate, tailored data-protection documentation available under NDA.
Effective date: 6 July 2026 · Last updated: 6 July 2026
Who we are
We are the data controller for personal data collected on this website:
- DXN Design Ltd, trading as Halo Connected Health
- Registered office: 3 Avondale Drive, Ballyclare, County Antrim, BT39 9AU, United Kingdom
- Companies House registration: NI684155
- ICO registration: pending (published here on receipt)
- Contact for privacy queries: privacy@haloconnectedhealth.com
What personal data we collect
We only collect what we need. Categories:
- Form submissions — when you use the Contact form, the Request a Demo form, or any other form on the site. Fields collected are visible on the form itself (typically: name, work email, organisation, role, setting-type, message, consent). We do not use hidden fields.
- Server logs — standard web-server logs including IP address, user-agent string, requested URL, timestamp. Retained for 30 days for security and diagnostic purposes.
- Cookies — see the Cookie Policy. We use Complianz to manage consent. Analytics is Plausible, which is cookieless and IP-anonymised.
We do not collect: special-category data on this website; children’s data (this website is not directed at anyone under 18); financial or payment data (form submissions do not accept card details).
Why we process it (lawful basis)
Under UK GDPR Article 6, our lawful bases are:
- Consent — Article 6(1)(a). Applies to marketing communications, if you opt in separately. You can withdraw consent at any time.
- Contract or steps toward contract — Article 6(1)(b). Applies when you request a demo, procurement pack, or otherwise ask us to prepare a commercial engagement.
- Legitimate interests — Article 6(1)(f). Applies to responding to general enquiries, partnership requests, press enquiries, and security-disclosure reports. Our legitimate interest is running the business and protecting our platform; we balance this against your rights and reasonable expectations.
- Legal obligation — Article 6(1)(c). Applies where we must retain records for accounting, tax, or regulatory reasons.
How long we keep it
- Form submissions: 12 months from the date of your last interaction with us, unless you have entered into a commercial relationship with DXN Design Ltd (in which case retention is governed by that contract).
- Server logs: 30 days.
- Cookie consent record: 12 months.
- Records required by law (accounting, tax): 7 years, per HMRC.
We delete or anonymise personal data when the retention period ends.
Who we share it with
We do not sell your data. We do not share it with third-party marketers. We use these processors to run the site and respond to enquiries:
- Amazon Web Services (AWS) — hosting infrastructure (EC2, RDS, S3, SES). UK region (eu-west-2). AWS acts as a UK GDPR processor.
- Amazon SES — outbound email delivery for form notifications.
- Cloudflare — CDN and DDoS protection.
- Plausible Analytics — cookieless, IP-anonymised website analytics. EU-hosted.
If we ever add other processors, we will update this list. For a full processor register, contact privacy@haloconnectedhealth.com.
International transfers
Our infrastructure is UK-hosted (AWS eu-west-2, Cloudflare’s UK presence). Under normal operations your personal data does not leave the UK. Where a processor may transfer data outside the UK (rare — typically only for support), we rely on the UK’s IDTA or approved SCCs and only for necessary purposes.
Your rights
Under UK GDPR you have the right to:
- Access — a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — ask us to delete your data (subject to legal retention obligations)
- Restriction — ask us to stop processing while you contest accuracy or use
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests or for direct marketing
- Withdraw consent — where processing is based on consent
To exercise any right, email privacy@haloconnectedhealth.com. We aim to respond within one month. We do not charge for exercising rights except where a request is manifestly unfounded or excessive.
If you are unhappy with our response you can complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint, or by post: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
Security
We take appropriate technical and organisational measures to protect your data, including: TLS 1.2+ on all endpoints, at-rest encryption for databases and backups, role-based access control, least-privilege IAM, audit logging, mandatory MFA on all administrative accounts, and a documented incident-response plan.
We do not guarantee absolute security, but we design against known threats and disclose material breaches to affected individuals and the ICO within statutory timeframes.
Automated decision-making
We do not make automated decisions with legal or similarly significant effects about you on this website.
Changes to this policy
If we materially change how we handle your data, we will update this page and note the change in the “Last updated” date. For significant changes affecting existing subjects we will contact you where practicable.
Contact
Data controller: DXN Design Ltd
Privacy contact: privacy@haloconnectedhealth.com
Post: DXN Design Ltd, 3 Avondale Drive, Ballyclare, County Antrim, BT39 9AU, United Kingdom
