Privacy & data protection
Privacy Policy
This Privacy Policy explains how Habitus Systems Ltd collects, uses and protects personal data when you visit our website or contact us.
Who we are
Habitus Systems Ltd is a specialist consultancy supporting public-sector organisations to improve housing and homelessness systems. For the purposes of UK data protection law, we are the data controller for personal data collected through this website.
Contact: info@habitussystems.co.uk
How we use personal data
What we collect and why
We only collect personal data that is necessary to respond to enquiries, deliver our services, and operate our website securely.
Enquiries and contact
If you email us or submit a form, we may process your name, organisation, email address, phone number (if provided) and the content of your message to respond and keep a record of our correspondence.
Website usage data
We may collect limited technical information (such as IP address, browser type, device information and pages visited) to maintain website security, understand performance and improve content.
Service delivery
Where you engage us professionally, we process contact and business information needed to deliver consultancy services, manage projects and meet contractual obligations.
Legal and compliance
We may process personal data where necessary to comply with legal obligations, protect our rights, and prevent fraud or misuse of our website.
Lawful bases
Our legal basis for processing
We process personal data under one or more of the following lawful bases (UK GDPR):
Legitimate interests โ to respond to enquiries, run our business and improve our website.
Contract โ where processing is necessary to deliver agreed services.
Legal obligation โ where we must comply with applicable law.
Consent โ where you have provided consent (for example, where required for certain cookies or marketing).
Sharing and international transfers
We do not sell personal data. We may share personal data with trusted service providers who support our website and business operations (for example, hosting, email and security services). These providers act as processors and are required to protect your data and use it only on our instructions.
Where any data is transferred outside the UK, we will ensure appropriate safeguards are in place (such as adequacy regulations or standard contractual clauses), as required.
Retention
We keep personal data only for as long as necessary for the purposes set out in this policy. Typical retention periods depend on the nature of the interaction (for example, enquiry correspondence, contractual records, and legal or regulatory requirements).
Your rights
Under UK GDPR, you may have the following rights in relation to your personal data (subject to legal limitations):
Access
Request a copy of the personal data we hold about you.
Rectification
Ask us to correct inaccurate or incomplete data.
Erasure
Request deletion of your data in certain circumstances.
Restriction
Ask us to limit how we use your data in certain circumstances.
Objection
Object to processing based on legitimate interests.
Data portability
Receive certain data in a structured, commonly used format.
Withdraw consent
Where we rely on consent, you can withdraw it at any time.
Complain
Raise a concern with the Information Commissionerโs Office (ICO).
Cookies
We use cookies and similar technologies to help the website function and to understand how it is used. Where required, we will ask for your consent before setting non-essential cookies. You can control cookies through your browser settings and, where available, our cookie controls.