> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.hoxtonmix.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Privacy Policy

> ⚡ **Quick Answer:** This Privacy Policy explains how The Hoxton Mix Limited collects, uses, stores, and protects your personal data. For privacy queries, contact **dpo@hoxtonmix.com**.

---

Welcome to the Privacy Policy of **The Hoxton Mix Limited** (“Hoxton Mix”, “we”, “us”, “our”).

We are committed to protecting your privacy and handling your personal data lawfully, fairly, and transparently. This policy applies to visitors, prospective customers, customers, individuals whose data appears in processed mail, and business partners.

Please also read our [Cookie Policy](https://help.hoxtonmix.com/en/article/cookie-policy-1kp06gn/).

---

# Contents

1. [Who We Are](#1-who-we-are)
2. [How to Contact Us](#1-how-to-contact-us)
3. [The Data We Collect](#1-the-data-we-collect)
4. [How We Collect Data](#1-how-we-collect-data)
5. [Lawful Bases for Processing](#1-lawful-bases-for-processing)
6. [How We Use Personal Data](#1-how-we-use-personal-data)
7. [Google User Data (Google API Services)](#1-google-user-data-google-api-services)
8. [Automated Decision-Making](#1-automated-decision-making)
9. [Sub-Processors and Third Parties](#1-sub-processors-and-third-parties)
10. [International Data Transfers](#1-international-data-transfers)
11. [Data Retention](#1-data-retention)
12. [Your Rights](#1-your-rights)
13. [Data Security](#1-data-security)
14. [Data Breaches](#1-data-breaches)
15. [Children’s Data](#1-childrens-data)
16. [Third-Party Links](#1-third-party-links)
17. [Updates to This Policy](#1-updates-to-this-policy)
18. [Contact Us](#1-contact-us)

---

# Who We Are

**The Hoxton Mix Limited**
Company number: 07212205
Registered office: **66 Paul Street, London EC2A 4NA**

We act as **Data Controller** for customer accounts, identity verification, billing, postal metadata, digital scans, and support records. We act as **Data Processor** only where you instruct us to process or scan your mail.

---

# How to Contact Us

**Data Protection Officer:** dpo@hoxtonmix.com

---

# The Data We Collect

**Identity & Verification (KYC/AML)** — passport, driving licence, proof of address, DOB, nationality, company details, PSC/UBO information

**Account & Contact** — name, company name, postal address, email, phone, billing data (tokenised; we do not store card numbers)

**Mail Handling** — postal logs, sender/recipient details, digital scans, forwarding metadata

**Website & Technical** — IP address, cookies, device/browser details, usage patterns (see Cookie Policy)

**Support** — Crisp chat logs, email correspondence, complaint records

**Special Category Data** — not intentionally collected, but may appear in scanned mail. Handled securely and incidentally only.

---

# How We Collect Data

From you directly (sign-up, contact), postal items, KYC documents, business partners (Crunch, Tide, Ember, Osome, ANNA), public sources (Companies House), analytics, and support interactions.

---

# Lawful Bases for Processing

* **Contractual necessity** — providing your subscription, mail handling, account admin, support
* **Legal obligation** — AML Regulations, London Local Authorities Act, DUAA 2025, DPA 2018
* **Legitimate interests** — service security, fraud prevention, accurate records, IT integrity
* **Consent** — marketing communications and non-essential cookies (withdrawable at any time)

---

# How We Use Personal Data

To verify identity, manage accounts, process mail, provide scanning/forwarding, deliver support, process payments, improve services, comply with regulations, and prevent fraud. **We never sell personal data.**

---

# Google User Data (Google API Services)

Some of our products and tools connect to Google. You can sign in with your Google account, and our scheduling and leave-management features can connect to your Google Calendar — so that booking pages only offer times when you are free, and bookings or approved leave appear in your calendar automatically.

**Google scopes we request**

| Scope | Used for |
|---|---|
| `openid`, `userinfo.email`, `userinfo.profile` | Signing you in and identifying your account |
| `https://www.googleapis.com/auth/calendar.readonly` | Reading your calendar free/busy availability so booking pages only offer free time slots |
| `https://www.googleapis.com/auth/calendar.events` | Creating, updating and cancelling calendar events for bookings and approved leave |

We only request calendar scopes if you choose to connect your Google Calendar — signing in with Google on its own never grants us access to your calendar.

**Limited Use disclosure**

Our use of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the **Limited Use** requirements. Specifically:

* We only use Google user data to provide and improve the user-facing features described above.
* We do **not** transfer Google user data to third parties, except as necessary to provide these features, with your explicit consent, for security purposes, or to comply with applicable law.
* We do **not** use Google user data for advertising.
* We do **not** allow humans to read Google user data, unless we have your explicit consent, it is necessary for security purposes (such as investigating abuse), it is required to comply with applicable law, or the data has been aggregated and anonymised for internal operations.
* We do **not** use Google user data to develop, improve, or train generalised artificial intelligence or machine-learning models.

**Storage, retention and revoking access**

OAuth tokens are stored encrypted. We store only the minimum calendar data needed to operate these features — identifiers and times for events we create or check for availability — and we do not store the wider contents of your calendar. You can disconnect Google at any time from your account settings or via your [Google Account permissions page](https://myaccount.google.com/permissions). On disconnection we delete stored tokens, and associated Google user data is removed within 30 days.

---

# Automated Decision-Making

We do **not** make automated decisions that produce legal or significant effects.

---

# Sub-Processors and Third Parties

> ⚠️ **Note:** Postal carriers (Royal Mail, DHL, FedEx) act as independent Data Controllers once mail enters their network.

| Sub-Processor | Purpose | Region |
|---|---|---|
| **AWS** | Hosting, storage, OCR | UK (London) |
| **Twilio** | VOIP/SMS | US (SCCs/Data Bridge) |
| **OpenAI** | Internal OCR/classification (zero data retention) | US (Data Bridge) |
| **Crisp IM** | Support chat/helpdesk | EU (France) |
| **Chargebee** | Subscription billing | EU/US |
| **Stripe / PayPal / GoCardless** | Payment processing | UK/EU/US |
| **Mailgun / Amazon SES** | Email delivery | EU/US |
| **Google Workspace** | Internal email/collaboration | EU/US |
| **Slack** | Internal communications | EU/US |
| **Vercel** | Website hosting | EU/US |
| **Microsoft (Bing)** | Advertising/analytics | US (Data Bridge) |
| **Meta (Facebook)** | Advertising/analytics | US (Data Bridge) |

---

# International Data Transfers

Where data is transferred outside the UK/EEA, we use UK IDTA, Standard Contractual Clauses, or DUAA-compliant mechanisms.

---

# Data Retention

| Data Type | Retention |
|---|---|
| AML/KYC documents | 5 years after account closure |
| Billing records | 6 years |
| Mail scans | 30 days |
| Postal logs | 24 months |
| Support logs/tickets | 24 months |
| Analytics | Per Cookie Policy |

> ⚠️ **Important:** AML/KYC retention (5 years) overrides the Right to Erasure under UK GDPR. We cannot delete identity records before this period expires.

---

# Your Rights

Under UK GDPR: access, rectification, erasure, restrict processing, data portability, object, and protection from automated decision-making.

To exercise any right: **dpo@hoxtonmix.com** (we may request proof of identity).

---

# Data Security

* Encryption at rest and in transit
* AWS-certified hosting
* Two-factor authentication
* Role-based access controls
* Regular penetration testing
* Annual Cyber Essentials Plus compliance

---

# Data Breaches

We assess risk, notify the ICO within **72 hours** where required, and notify affected individuals if high risk. We maintain an internal breach register.

---

# Children’s Data

Our services are for individuals aged **16 or over** (minimum age to be a UK company director or sole trader). Data collected in error for under-16s will be deleted.

---

# Third-Party Links

Our site may link to third-party sites. We are not responsible for their privacy practices.

---

# Updates to This Policy

We may update this policy from time to time. Material changes will be notified by email.

---

# Contact Us

**The Hoxton Mix Limited**
66 Paul Street, London EC2A 4NA
**Email:** dpo@hoxtonmix.com

---

**[Contact DPO →](mailto:dpo@hoxtonmix.com)**