HumanWox Legal and Governance Policies

Source, deploy, and manage workers seamlessly— with automated compliance, intelligent scheduling, and workforce optimisation.

 


1. Privacy Policy (UK GDPR-Compliant)

Last Updated: April 2025

HumanWox (“we”, “our”, or “us”) is committed to protecting your personal data. This Privacy Policy outlines how we collect, use, store, and share information in compliance with the Data Protection Act 2018 and UK GDPR.

This policy applies to both:

  • Visitors to the HumanWox website (e.g., browsing, submitting demo forms)

  • Users of the HumanWox platform/app (e.g., account holders, organisations, workers)

 

 

1.1 Website Usage and Tracking

When you visit our website, we may collect:

  • IP address, device type, browser information

  • Referrer source and general location (anonymised)

  • Pages visited, time spent, clicks, and scrolls (via analytics)

We use this information to:

  • Understand website traffic and improve user experience

  • Monitor performance and usage trends

 

Analytics Tools: We may use Google Analytics, Microsoft Clarity, or similar tools. No behavioural targeting is performed.

Form Submissions: When you submit your email (e.g., demo request, newsletter), we store your information to respond or follow up. You may unsubscribe anytime.

We do not use advertising cookies or third-party marketing trackers.


 

1.2 Platform Data Handling (App Users)

What We Collect

  • Name, email, contact details

  • Role, company information

  • Uploaded compliance documents (e.g., ID, certifications)

  • Metadata (e.g., time of upload, document expiry)

Why We Collect It

  • To assign and track compliance requirements

  • To send notifications and reminders

  • To generate audit-ready evidence packs

  • To fulfil legal obligations (e.g., Right to Work checks via certified IDSPs)

Lawful Basis for Processing

  • Contractual necessity

  • Legal obligation

  • Legitimate interest (e.g., for platform improvement)

Your Rights

  • Access, correction, deletion

  • Restriction and objection

  • Data portability

Retention

  • Documents and user data are retained for no longer than necessary for compliance or legal obligations.

Data Security

  • Encrypted storage

  • Access control policies

  • Regular reviews and audits

Contact for data/privacy matters: privacy@humanwox.com


2. Terms of Use

These Terms govern your use of the HumanWox platform.

1. Use of Platform

  • You agree to use HumanWox for lawful compliance management purposes only.

  • You must not impersonate others or misuse access credentials.

2. Data Ownership

  • You retain ownership of your documents and data.

  • You grant HumanWox a limited license to process, store, and transmit this data on your behalf.

3. Third-Party Integrations

  • Some checks (e.g., Right to Work, DBS) are facilitated via third-party IDSPs.

  • HumanWox does not act as an IDSP but orchestrates integration.

4. Termination

  • We reserve the right to suspend access if misuse or security risks are detected.

5. Liability

  • We are not responsible for the outcome of third-party checks.

  • Platform uptime and availability are best-effort.

Contact

For platform-related support: support@humanwox.com


3. Responsible AI Use Policy

HumanWox uses artificial intelligence (HX Copilot) to assist users in managing compliance workflows.

What Our AI Does

  • Surfaces expiring or missing documents

  • Suggests compliance actions

  • Summarises activity logs and alerts

What Our AI Does Not Do

  • Make final hiring decisions

  • Replace human review for legal obligations

  • Access biometric data

Principles

  • Transparency: Users are informed when AI is used.

  • Oversight: Human-in-the-loop is always available.

  • Fairness: AI insights are free from discriminatory logic.

  • Safety: No biometric processing. No profiling for punitive actions.


4. Data Protection Impact Assessment (DPIA Summary)

Scope

HumanWox processes identity documents, compliance-related records, and workforce metadata.

Risks

  • Loss of personal data

  • Inference or misuse of uploaded documents

  • Unauthorised third-party access

Mitigations

  • Encryption at rest and in transit

  • Granular access control and audit logging

  • Use of certified IDSPs only

  • Automated expiry/removal workflows

Review

This DPIA is reviewed annually or after any material change to data flows.


Version 1.1 – Updated April 2025.
For legal, data, or compliance queries, contact: legal@humanwox.com