Misdirected mail and your data: how we handle processing errors
⚡ Quick Answer: Every envelope is scanned on arrival and matched to an account on several signals at once — company name, individual name, post history, timing and correspondence type. Confident matches are barcoded and routed automatically; anything below the threshold goes to a person for manual review. Misdirected mail is therefore rare, and when it happens it is almost always a mechanical fault. We log it, assess the risk, recover or securely destroy the item, and fix the cause.
Mistakes are rare — and we are open about them
We handle a very large volume of post every day, and the overwhelming majority of it reaches exactly the right person. But no physical mail operation is perfect, and we would rather explain honestly how the occasional error happens than pretend it never does. Here is how we route your post, what causes a misdirected item, what we do about it, and what the data protection rules genuinely require.
None of what follows is new. It is how we have matched and handled post for years — what is new is that we have set it out in one place so you can see it.
How we make sure post reaches the right person
Matching an item to the right account is the part of this business we have invested in most heavily, and it runs on software we built ourselves rather than anything bought off the shelf.
Step one: we scan the envelope
Nothing is sorted by eye. Every item is scanned on arrival and the addressee details are read off the outside of the envelope. That scan is what the rest of the process works from — no item is allocated, processed or released until it has been matched to an account.
Step two: the item is matched on several signals at once
The addressee details are then tested against your account records from a number of different angles, not just one:
- Company name — checked against the registered and trading names on the account
- Individual name — where the item is addressed to a person, a likeness-matching algorithm compares it to the individuals associated with that business, so near-misses and misspellings are still recognised
- Directors — including any director we hold a Directors Service Address for
- Beneficial owners — the UBOs recorded against the account through our verification checks
- Post history — what that business and that named individual have received here before
- Timing — whether an item of this kind is due, or fits the pattern of what usually arrives
- Type of correspondence — an account that regularly receives HMRC or Companies House post is a stronger match for another item of the same kind
Each of these produces a likelihood score rather than a yes or no, and the scores are weighed together. Only when the combined confidence clears our threshold is the item allocated automatically. If there is a legitimate signal on an envelope that can help identify its owner, we would rather feed it into the match than discard it.
Step three: the item is barcoded and routed
Once matched, the item is barcoded. From that point the barcode is the item's identity: a lookup against it determines exactly what should happen next — scanned, forwarded, held for collection, or handled under whatever preferences that account has set. Every stage after matching reads the barcode rather than the envelope, which removes a whole category of human error from the rest of the journey.
Step four: anything below the threshold goes to a person
Items that do not clear the confidence threshold are never guessed at. They are pulled out and queued for manual review, and a member of our team makes the decision.
That queue exists because real post is messy. A sender misspells the company name or uses a trading name we do not hold. Print is faint or the ink has failed. A label has torn or lifted in transit. Sometimes the name simply does not belong to any account here — which may be an innocent error by a sender, or may be someone using the address who has no right to (see our Falsification Policy and Client Conduct Standards). Either way it is flagged for a human rather than resolved automatically.
Uncertainty, in other words, produces a human judgement — never an automated one.
Where two businesses look alike
Companies House permits names that sit very close together, and post often arrives carrying a shortened or informal version of a company name. "Acme Studio" and "Acme Studios Ltd" can be two entirely different customers of ours.
The most useful thing you can do is give your correspondents your full registered company name, including the "Limited" or "Ltd" — exactly as it appears on your Companies House record. A shortened trading name on the envelope is the single most common reason an item becomes ambiguous in the first place.
Where two accounts still cannot be separated on the name alone, we look for a second identifier on the item — a director's name, a director whose service address we hold, or a registered beneficial owner. If that does not settle it, we contact you directly.
Only where an item cannot be identified any other way will an authorised member of staff open it, and then solely to find something that identifies the correct recipient — nothing further is read, and the step is recorded. Customers on a mail scanning plan instruct us to open and scan their post as part of the service in any case. We would always rather ask than assume.
How misdirected mail happens
Against that process, the errors that do get through come down to mechanics rather than judgement.
Post is sorted and enclosed at speed using automated equipment. The most common fault is a double-feed: two items pass through the machine together — stuck by static, a slight curl in the paper, or an adhesive edge — and are treated as one. The result is that a letter belonging to one customer travels inside an envelope addressed to another.
Less commonly, an item is misread at the sorting stage: a smudged or obscured address, an unusual layout, or a label that has lifted in transit. Occasionally a sender addresses an item incorrectly before it ever reaches us.
None of these are dramatic failures. They are the ordinary error rate of physical handling, which is why the process around them matters more than the error itself.
What we do when it happens
We identify and log the incident. Every reported or detected misdirection is recorded in our internal breach register with the date, what was sent, who was affected, and how it came to light. That record is the evidence base for everything that follows, and it lets us spot patterns rather than treat each case as a one-off.
We assess the risk. We look at what the item contained and the realistic consequence for the person whose data it held. A routine notice reaching another business address sits in a very different category from something carrying financial or identity information, and the response scales accordingly.
We recover or destroy the item. We ask the unintended recipient to return it to us or to destroy it securely, and we confirm that this has been done. Where an item cannot be recovered, we work with the sender on a replacement wherever that is possible.
We review the process. Recurring faults are traced back to the equipment or step that caused them — feed rollers, separation settings, batch sizes, or the checks applied at a particular stage. Preventing the next occurrence is the part of the response that actually protects customers.
What the data protection rules actually say
A misdirected letter is a personal data breach in the technical sense, because personal data has reached someone who should not have received it. That does not mean every instance is reportable.
Under UK GDPR, a breach must be reported to the Information Commissioner's Office within 72 hours unless it is unlikely to result in a risk to people's rights and freedoms. The individuals concerned only need to be told directly where the breach is likely to result in a high risk to them. The threshold is set deliberately, so that regulators and customers hear about genuinely damaging incidents rather than being buried in notifications about trivial ones.
What is always required is that the organisation records the breach, documents its reasoning, and can produce that record if the ICO asks. That is exactly what our breach register exists to do, and it is the commitment set out in the Data Breaches section of our Privacy Policy.
The ICO publishes worked examples of this judgement in its Personal data breach examples guidance, including cases involving post. Some are notifiable and some are not — the deciding factor is the sensitivity of what was disclosed and the likely consequence for the person involved. We make that assessment case by case, and escalate to the ICO where it calls for it.
If you receive an item that isn't yours
Please tell us straight away through the chat widget or at help@hoxtonmix.com, and let us know what you have received. We will ask you either to return the item to us or to destroy it securely — shredding is ideal — and to confirm once done.
Please do not open it further, forward it on, photograph it, or contact the intended recipient yourself. Telling us is what lets us close the loop properly with the person affected.
Our commitment
Your post is handled in a secure, access-controlled facility by vetted staff, and the data around it is encrypted and hosted in the UK — the detail is in How secure is my data? and our GDPR & Security Compliance overview.
We take the handling of your post extremely seriously, and the matching technology behind it is our own — built in-house, refined against our live mail volume rather than bought off the shelf, and now going through patent protection with specialist patent attorneys. We would still rather tell you plainly that occasional errors occur, and show you the process that catches and corrects them, than claim a perfection no mail operation can honestly promise.
ℹ️ Note: This article is general information about how we handle mail processing errors. It is not legal advice. If you need advice on your own data protection obligations, please consult a qualified adviser or the ICO directly.
Contact our Data Protection Officer →
Updated on: 04/08/2026
