CentralHub

Privacy information · public notice

How personal information is handled

Version 1.1 · Updated 25 September 2026

This notice describes the existing website and private administration service. Proposed integrations are labelled separately. Our business-facing contractual data-processing schedule and detailed retention inventory remain subject to review before independent customer onboarding.

Who operates the service and how to contact us

CentralHub is operated by INDIVORA LTD (company number 17459277), registered office: Weald Bridge Nursery, Kents Lane, Epping, England, CM16 6AX. For privacy requests, write to the registered office and mark your correspondence “CentralHub privacy request”. This notice concerns the CentralHub website and the existing private administrative platform. The separate CentralHub Shop showcase has its own privacy notice.

Our role and the information we handle

For our own website, account administration and correspondence, INDIVORA LTD determines the purposes of that processing. The role for information held on behalf of each business depends on who determines the purposes and means; the business may be the controller and INDIVORA LTD a processor. This distinction and any required processing contract must be confirmed for the relevant service. Depending on use, the platform may hold authorised staff and business contact details, login and security records, customer and supplier details, sales and orders, invoices, inventory, banking and reconciliation records, staff operational records and support communications. Business records may include information about identifiable people. Please do not submit sensitive personal information or payment-card details unless specifically required by an authorised and protected workflow.

Purposes and legal grounds

We use information to provide and secure the requested software, administer authorised users, maintain operational records, handle support requests and investigate errors or misuse. Depending on the particular activity, the applicable UK GDPR basis may be performing a contract, a legal obligation or a legitimate interest in running and protecting the service. Where we process information solely on a business customer’s documented instructions, that customer determines the relevant purpose and legal basis. Optional marketing or tracking, if introduced, needs its own applicable information and consent controls; an account or support request does not automatically opt you in.

Information received from other sources

A business administrator may import authorised staff, customer, supplier or transaction details. Connected stores, couriers, messaging, email or banking services may send records through their configured integration. For individual data held on behalf of a business customer, ask that business how it originally collected the information. We do not represent a planned government connection as an active source of taxpayer records.

Recipients, hosting and transfers

The application uses hosting and database infrastructure, including Netlify and Supabase, and may exchange relevant records with existing connected business services selected by the authorised organisation. Access and disclosure depend on the feature and configured account. Provider processing and support locations can differ from the database region. We do not promise that all data remains in the UK; any relevant international transfers and safeguards must be documented for each service before wider commercial onboarding. No planned tax integration is automatically connected merely by visiting this site.

Current processing locations and limits of verification

At the most recently checked project configuration, the private CentralHub Supabase database is in AWS eu-west-2 (London). Netlify deployment functions may use a configured region, global delivery and support infrastructure; a database location alone does not establish that all providers or support staff process data in the UK. Exact provider contracts, backup/support access locations and any applicable international transfer safeguards need validation before wider paid customer onboarding. Do not interpret this notice as a UK-only processing guarantee.

Retention, security and account closure

We retain business records for as long as needed to operate the service, support authorised users, handle disputes and meet applicable accounting, tax or other record-keeping obligations. Log and backup lifecycles may differ. A reviewed category-by-category retention schedule and customer export/deletion process must be finalised before independent paid onboarding; we cannot promise instant removal of records subject to a lawful retention obligation. Access is restricted through applicable sign-in and permissions, but no online service can be guaranteed risk-free.

Records, retention criteria and deletion requests

Account credentials, security events and support correspondence are retained only as long as needed for access, incident response and resolving enquiries. Transactional and accounting records may need longer retention where relevant accounting, tax or dispute duties apply; backups and audit records can have distinct, controlled lifecycles. The exact per-category duration, legal basis and documented deletion/export workflow have not yet been approved for a commercial multi-tenant offering, so we do not make a fixed-period or automatic-deletion promise.

Your rights

Depending on the processing and applicable exemptions, you may request access, correction, erasure, restriction, portability or object to processing. Where consent applies you may withdraw it. Contact us by writing to the registered office above. If a business customer controls the record, we may need to direct the request to that business or help it respond. You may complain to the UK Information Commissioner’s Office at ico.org.uk. We do not use the public website to make solely automated decisions about people with legal or similarly significant effects.

Cookies and browser information

Essential sign-in/session mechanisms and security-related technical information may be used to operate the website and protected application. Optional analytics, cookies and marketing technologies require a feature-by-feature audit and any applicable consent controls. We will not claim all optional technologies are blocked before consent until the implementation has been tested.

Future tax and government connections — not active filing services

We plan separate VAT Making Tax Digital, Corporation Tax, PAYE/payroll, Business Rates, Customs Duty/import VAT and Companies House integrations. If activated, a customer may choose to supply relevant tax identifiers, authorised account references, financial transactions, payroll, property or customs records, and consent to service-specific account authorisation where applicable. A privacy-notice update and appropriate security, processor/recipient, location, retention and user-authorisation reviews must happen before any new processing starts. Accepting this notice is not permission to connect an HMRC or council account, file returns or make payments. The current sandbox application diagnostic is not production VAT filing.

Commercial customers should also review the proposed data-processing terms and outstanding approval conditions. This public notice does not by itself create a processor contract.

See ICO guidance on your information rights, our website terms and tax integration roadmap.

Return to homepage