Privacy Policy — Vetting Hub Ltd
Legal

Privacy Policy

This Privacy Policy explains how Vetting Hub Ltd collects, uses, and protects personal information. It also explains the privacy design of Charlotte, the AI compliance advisor embedded within partner platforms.

Version 2.0 Effective May 2026 UK GDPR Compliant Company No. 17250399 ICO ZC122197 Charlotte collects no personal data
Data Controller
Vetting Hub Ltd
Company Number
17250399
Data Protection Officer
Graham Johnson — [email protected]
ICO Registration
ZC122197

Our Privacy Position in Plain English

Vetting Hub Ltd takes privacy seriously as a design principle, not just a compliance obligation. Charlotte is deliberately built to collect no personal data whatsoever. This is not a policy commitment that can be changed. It is how Charlotte is engineered.

When users access Charlotte, no names, candidate details, employment records, or any other personal information are requested, collected, stored, or shared. Conversations are not logged. Nothing passes to Vetting Hub Ltd. Nothing passes to any third party.

The only personal data Vetting Hub Ltd processes is the contact and billing information of the organisations and individuals who contract with us directly. That data is handled carefully, used only for the purposes it was provided, and never sold.

Charlotte Collects

Nothing. No names. No candidate data. No employment records. No conversation history. Zero personal data by design.

Vetting Hub Ltd Collects

Only the contact and billing information of clients who engage us directly. Used only to manage our commercial relationships.

Your Data Is Never

Sold, shared with third parties for marketing, used for profiling, or processed for any purpose beyond what is described in this policy.

Your Rights

You have full UK GDPR rights including access, correction, deletion, and the right to complain to the ICO at ico.org.uk.

1

Who We Are

Vetting Hub Ltd is a UK specialist compliance knowledge business founded by Graham Johnson, who spent 18 years at the operational centre of UK employment screening and vetting. Vetting Hub Ltd provides specialist employment screening and vetting compliance guidance through Charlotte, an AI compliance advisor embedded within partner software platforms.

Company Name
Vetting Hub Ltd
Company Number
17250399
Address
10 Lynch Green, Hethersett, Norwich, Norfolk, NR9 3JU
Website
vettinghub.co.uk
ICO Registration
ZC122197 — registered 13 April 2026, expires 12 April 2027
Data Controller
Vetting Hub Ltd
Data Protection Officer
Graham Johnson — [email protected]

For the purposes of UK data protection legislation including the UK General Data Protection Regulation and the Data Protection Act 2018, Vetting Hub Ltd is the data controller in respect of any personal data processed in connection with its activities.

2

Charlotte and Personal Data

Charlotte Collects No Personal Data. None.

This is the most important privacy fact about Vetting Hub Ltd. Charlotte is deliberately and permanently engineered to collect, process, store, and retain no personal data whatsoever.

Charlotte does not ask users for their name, job title, employer, candidate name, date of birth, address, contact details, identification document details, employment history, or any other information that could identify a living individual.

Charlotte does not log or store any conversation. When a conversation ends, no record of it is retained anywhere. Nothing from any conversation is passed to Vetting Hub Ltd, to any third party, or to any system outside the conversation itself.

This is not a policy commitment. It is how Charlotte is built. It cannot be switched on or configured differently for any client.

Names

Not collected. Not requested. Not stored.

Candidate Data

Not collected. Charlotte has no access to any candidate records.

Conversations

Not logged. Not stored. Not accessible to Vetting Hub Ltd.

User Profiles

Not created. Vetting Hub Ltd does not monitor or profile individual users.

Employment Records

Not collected. Charlotte operates solely as a knowledge guidance tool.

Identification

Not requested. No identification documents or numbers are ever sought.

Because Charlotte processes no personal data, Vetting Hub Ltd is not a data processor or joint controller in relation to Charlotte's operation as an AI compliance advisor. No data processing agreement is required between Vetting Hub Ltd and any client specifically in connection with Charlotte's function as a guidance tool.

Partner platforms are responsible for ensuring that their customers do not input personal data, candidate information, or any sensitive personal information into Charlotte. Inputting personal data into Charlotte serves no guidance purpose and is contrary to the intended use of the service.

Charlotte's zero personal data design means organisations can embed Charlotte and give their customers access without creating any additional data processing obligations in relation to Charlotte's operation.

3

Charlotte's Knowledge Base Design

Charlotte operates exclusively from a locked knowledge base written and maintained by Graham Johnson, founder of Vetting Hub Ltd. This knowledge base contains 65 specialist topics and 2,900 sub-topics covering UK employment screening, vetting, and compliance.

Charlotte does not search the internet. She does not browse external websites or databases. She does not connect to any external system. She does not generate speculative answers from general AI training data. Every answer Charlotte gives comes from her knowledge base.

If a question falls outside the knowledge base, Charlotte states clearly that she cannot answer it and directs the user to seek further guidance. This design prevents hallucinated or fabricated responses and is a deliberate compliance and accuracy safeguard.

Because Charlotte draws only on her knowledge base and collects no data, she poses no data protection risk in her operation as a guidance tool. Her design is privacy by default and privacy by design in the fullest sense of those principles.

Charlotte's closed knowledge base design means her answers are consistent, controlled, and cannot be influenced by internet searches, external data sources, or user-provided information.

4

What Personal Data We Collect

Vetting Hub Ltd collects personal data only in the following limited circumstances. We do not collect personal data speculatively or beyond what is necessary for the specific purpose described.

CategoryData CollectedWhen and How
Client Contact DataName, job title, email address, company name, telephone numberWhen an organisation contacts us by email, makes an enquiry, or enters into a commercial relationship with Vetting Hub Ltd
Billing and Contract DataName, company name, billing address, invoice detailsWhen a partnership is entered into and for the duration of the commercial relationship for invoicing and accounting purposes
Website Technical DataIP address, browser type, pages visited, time spent on pages, referring URLAutomatically collected when visiting vettinghub.co.uk via essential and performance cookies and server logs
Correspondence DataContent of emails, enquiries, and written communicationsWhen you contact Vetting Hub Ltd directly by email or any other written channel

Vetting Hub Ltd does not collect special category personal data. We do not collect health data, biometric data, racial or ethnic origin data, political opinions, religious beliefs, criminal record data, or any other special category data as defined under UK GDPR Article 9.

We do not collect personal data from children. Our services are directed at business professionals and organisations only.

We do not purchase marketing lists. We do not acquire personal data from data brokers. We do not collect personal data from social media platforms. All personal data we hold has been provided to us directly by the individual or organisation it relates to.

5

How We Use Personal Data

Personal data collected by Vetting Hub Ltd is used only for the following purposes. We do not use personal data for any purpose not described here without first informing you and, where required, obtaining your consent.

  • Responding to enquiries — to reply to questions, requests for information, and trial requests received by email or through the website
  • Managing commercial relationships — to administer partnerships, process onboarding, manage account details, and maintain records of the commercial relationship
  • Billing and invoicing — to issue invoices, process payments, and maintain financial records in accordance with legal and accounting obligations
  • Delivering and supporting the service — to provide CSS embed codes, support deployment, and respond to technical queries from partners
  • Operating and improving the website — to ensure the website functions correctly, monitor security, understand how visitors use the site, and make improvements
  • Complying with legal obligations — to meet obligations under UK law including tax, accounting, data protection, and any applicable regulatory requirements
  • Protecting our legal position — to enforce our Terms and Conditions, manage disputes, and protect Vetting Hub Ltd's rights where necessary

Vetting Hub Ltd does not use personal data for direct marketing without consent. We do not use personal data for profiling or automated decision-making. We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.

6

Legal Basis for Processing

Vetting Hub Ltd processes personal data only where a lawful basis exists under UK GDPR. The legal bases we rely on are as follows.

Processing ActivityLegal Basis
Responding to enquiries and managing pre-contract communicationsLegitimate interests (Article 6(1)(f)) — necessary to respond to genuine business enquiries
Administering partnerships, billing, and delivering the servicePerformance of a contract (Article 6(1)(b)) — necessary to fulfil our obligations under the partnership agreement
Maintaining financial and accounting recordsLegal obligation (Article 6(1)(c)) — required under UK tax and accounting law
Operating and securing the websiteLegitimate interests (Article 6(1)(f)) — necessary to operate a secure and functional website
Complying with legal and regulatory obligationsLegal obligation (Article 6(1)(c)) — required to comply with applicable UK law
Protecting and enforcing our legal rightsLegitimate interests (Article 6(1)(f)) — necessary to protect Vetting Hub Ltd's legitimate business interests

Where we rely on legitimate interests as our legal basis, we have carried out a balancing test and are satisfied that our interests do not override the rights and freedoms of the individuals concerned.

7

Who We Share Data With

Vetting Hub Ltd does not sell, rent, or trade personal data. Personal data is shared only in the following limited circumstances.

  • Payment processors — billing and payment information is processed by our third-party payment provider. Payment card details are processed securely by that provider and are never stored by Vetting Hub Ltd.
  • Platform providers — we use GoHighLevel as our technology platform. Personal data related to partner account management may be stored within GoHighLevel's systems. GoHighLevel processes data in accordance with its own privacy policy and data processing terms.
  • Professional advisors — where necessary we may share data with legal advisors, accountants, or other professional advisors in connection with the operation of our business. All such advisors are bound by appropriate confidentiality obligations.
  • Legal and regulatory requirements — we may disclose personal data to law enforcement, regulatory authorities, or courts where required to do so by law or by a valid legal process.

All third parties with whom Vetting Hub Ltd shares personal data are required to handle that data in accordance with applicable data protection law. We do not share personal data with third parties for their own marketing or commercial purposes.

Vetting Hub Ltd does not share personal data with advertisers, data brokers, analytics companies for profiling purposes, or any party whose primary purpose is to use that data commercially.

8

International Transfers

Where personal data is transferred outside the United Kingdom, Vetting Hub Ltd ensures that appropriate safeguards are in place in accordance with UK GDPR requirements. This may include transfers to countries recognised by the UK government as providing adequate data protection, or transfers subject to appropriate contractual safeguards such as the UK International Data Transfer Agreement.

Our primary platform provider GoHighLevel is a US-based company. Where personal data is transferred to GoHighLevel's systems, this is subject to appropriate data transfer safeguards. Details of GoHighLevel's data transfer mechanisms are available in their privacy documentation.

We will not transfer personal data internationally in a manner that would undermine the protections afforded by UK data protection law.

9

Cookies and Website Tracking

The Vetting Hub Ltd website uses cookies to ensure the website functions correctly and to understand how visitors use it. We use only the following categories of cookies.

Cookie TypePurposeRequired
Essential CookiesNecessary for the website to function. Enable core functions such as page navigation, security, and access to secure areas.Yes — cannot be disabled
Performance CookiesHelp us understand how visitors interact with the website by collecting anonymous information about pages visited and time spent. Used to improve the website.No — can be managed through browser settings
Analytics CookiesUsed to understand traffic patterns and visitor behaviour in aggregate. No individual user profiling takes place.No — can be managed through browser settings

Vetting Hub Ltd does not use cookies for behavioural advertising, retargeting, or user profiling for commercial purposes. We do not place third-party advertising cookies on the website.

Cookie preferences can be managed through your browser settings. Please note that disabling certain cookies may affect the functionality of the website.

10

Data Retention

Vetting Hub Ltd retains personal data only for as long as necessary for the purpose for which it was collected and in line with our legal and regulatory obligations. The following retention periods apply.

Data CategoryRetention PeriodReason
Client Contact and Contract DataDuration of the partnership plus 6 yearsLimitation Act 1980 — contract claims may be brought within 6 years
Billing and Financial Records7 years from the end of the relevant financial yearHMRC accounting and tax record requirements
Correspondence and Enquiry Data2 years from the date of last contactSufficient to manage follow-up and resolve any disputes
Website Technical DataUp to 26 monthsStandard analytics retention period

At the end of the applicable retention period, personal data is securely deleted or anonymised. We do not retain personal data beyond the periods described above unless required to do so by law or by an ongoing legal dispute.

11

Data Security

Vetting Hub Ltd implements appropriate technical and organisational security measures to protect personal data against unauthorised access, accidental loss, destruction, or misuse. These measures include the following.

  • Access to personal data is restricted to Graham Johnson, founder of Vetting Hub Ltd, and is not shared with employees or contractors except where strictly necessary
  • Partner account data is held within GoHighLevel's platform which implements industry-standard security controls
  • Email communications containing personal data are handled through secure email infrastructure
  • Payment information is processed exclusively by our third-party payment provider using industry-standard encryption. Vetting Hub Ltd does not store payment card details
  • Website security measures include SSL encryption for all pages

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, Vetting Hub Ltd will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach, and will notify affected individuals where required by law.

No method of transmission over the internet or electronic storage is completely secure. While Vetting Hub Ltd applies appropriate security measures, we cannot guarantee absolute security. We will however take all reasonable steps to protect personal data in our care.

12

Your Rights Under UK GDPR

Under UK data protection law you have the following rights in relation to your personal data. You can exercise these rights by contacting us at [email protected]. We will respond within one calendar month of receiving your request.

Right of Access

You have the right to request a copy of the personal data we hold about you and information about how we use it.

Right to Rectification

You have the right to request that inaccurate or incomplete personal data we hold about you is corrected.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, for example where it is no longer necessary for the purpose for which it was collected.

Right to Restriction

You have the right to request that we restrict our processing of your personal data in certain circumstances.

Right to Portability

Where processing is based on consent or contract, you have the right to receive your personal data in a structured, commonly used, machine-readable format.

Right to Object

You have the right to object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.

Automated Decisions

You have the right not to be subject to decisions based solely on automated processing. Vetting Hub Ltd does not carry out such processing.

Right to Complain

You have the right to lodge a complaint with the ICO at ico.org.uk or by calling 0303 123 1113.

To exercise any of these rights please contact us at [email protected]. We may need to verify your identity before processing your request.

13

Children

Vetting Hub Ltd's services are directed exclusively at business professionals and organisations. We do not knowingly collect personal data from children under the age of 18. If we become aware that personal data has been submitted by or about a child, we will delete it promptly.

If you believe a child has provided personal data to Vetting Hub Ltd, please contact us at [email protected] and we will take immediate action.

14

Third Party Links

The Vetting Hub Ltd website may contain links to third-party websites, platforms, or resources. This Privacy Policy applies only to Vetting Hub Ltd's own processing activities. We are not responsible for the privacy practices of third-party websites and we encourage you to review the privacy policies of any website you visit.

The presence of a link on the Vetting Hub Ltd website does not constitute an endorsement of that website or its privacy practices.

15

Changes to This Policy

Vetting Hub Ltd may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Where changes are material, we will notify clients by email before the revised policy takes effect.

The most current version of this Privacy Policy is always available at vettinghub.co.uk. Continued use of our services following notification of a revised policy constitutes acceptance of the updated policy.

16

Contact and Complaints

If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have a concern about how your personal data is being handled, please contact us.

Company
Vetting Hub Ltd
Company Number
17250399
Address
10 Lynch Green, Hethersett, Norwich, Norfolk, NR9 3JU
ICO Registration
ZC122197
Response Time
We aim to respond to all data protection queries within one calendar month

If you are not satisfied with our response to your query or complaint, you have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

Vetting Hub Ltd processes no personal data through Charlotte. Charlotte is built to collect nothing, store nothing, and share nothing. Privacy is a design principle at Vetting Hub Ltd, not an afterthought.

Copyright 2026 Vetting Hub. All rights reserved.