This Privacy Policy explains how Bhope Business Group LTD ("Bhope Business Group", "we", "us" or "our") collects, uses, shares and protects personal information through this website. Personal information means any information about a person who can be identified, such as your name or email address.
We have written this policy in plain language. It is designed to meet the privacy laws that apply to us and to you, including the EU General Data Protection Regulation (GDPR) and the UK GDPR where they apply. Wherever you live, we handle your information with the care this policy describes.
Privacy at a glance
We collect only what you choose to send us. We use it to reply to you and, if you ask, to send you our newsletter. We never sell it. Optional cookies and analytics stay off unless you say yes. Our chat assistant, Amana, runs in your browser and does not send your conversation to us.
Who we are and who is responsible
Bhope Business Group LTD is responsible for the personal information described in this policy. Under the GDPR, we are the "controller" of that information.
- Legal name: Bhope Business Group LTD
- Company number: [Company number to be added]
- Registered office: [Address coming soon]
- Privacy contact: [Privacy email coming soon]
Our Privacy Officer
Our Privacy Officer is accountable for how we handle personal information and for making sure we follow this policy. They are your contact point for every privacy question, including questions under the GDPR.
- Name: [Name to be designated]
- Title: Privacy Officer
- Email: [Privacy email coming soon]
Our Privacy Officer is the person in charge of the protection of personal information. Some privacy laws require us to publish their title and contact details, so we publish them here for everyone.
Representative in the European Union and United Kingdom
If the law requires us to appoint a representative in the European Union or the United Kingdom (under Article 27 of the GDPR and UK GDPR), we will name them here: [EU/UK representative to be confirmed, if required]. Until then, please contact our Privacy Officer directly.
Our privacy principles
We follow ten widely recognised fair information principles. They shape everything in this policy. Here is how we apply each one.
| Principle | What we do |
|---|---|
| 1. Accountability | Our Privacy Officer is responsible for our compliance. We require our service providers, by contract, to protect your information. |
| 2. Identifying purposes | We tell you why we collect information, at or before the time we collect it, on each form and in this policy. |
| 3. Consent | We ask for your consent before we collect personal information. Our forms and newsletter sign-up use a box that is never ticked in advance. |
| 4. Limiting collection | We collect only what we need. Our forms ask only for what we need to reply, and some fields are optional. |
| 5. Limiting use, disclosure and retention | We use information only for the purpose you gave it for, unless you agree otherwise or the law requires or allows it. We keep it only as long as we need it. |
| 6. Accuracy | We rely on the details you send us. You can ask us to correct them at any time. |
| 7. Safeguards | We protect information with security measures suited to how sensitive it is. See How we protect it. |
| 8. Openness | This policy explains our practices in plain language. We will answer any question about it. |
| 9. Individual access | You can ask to see the personal information we hold about you. See Your rights. |
| 10. Challenging compliance | You can raise a concern with our Privacy Officer and complain to the data protection authority where you live. See Contact us and complaints. |
Privacy laws in different countries
Privacy laws differ from country to country, and some regions within a country have their own. Where one of these laws applies to how we handle your information, we aim to follow it.
We also aim to follow the GDPR and UK GDPR when they apply to information about people in Europe or the United Kingdom. If you live somewhere else, your local law may give you other rights. We will consider every privacy request, wherever you live.
Information we collect
We collect as little personal information as we can. This website has no user accounts, no online shop and no payments.
Information you choose to give us
You can contact us through four forms. Each form asks only for the details below.
| Form | Required | Optional |
|---|---|---|
| Contact form | Name, email address, topic and message | None |
| Support request | Name, email address, topic and message | Order or reference number |
| Investor enquiry | Name, email address, the type of investor you are enquiring as, and message | Organisation and country |
| Partner enquiry | Name, company name, work email, country, partnership type, sector and message | Company website |
Each form also has a consent box, which is never ticked in advance. You must tick it before you send the form. This confirms that you agree to us using your details to reply, as described in this policy. The investor form has one more box, which confirms you understand that our website is not an offer of securities or financial advice.
If you sign up for our newsletter, we collect your email address and a record of your consent. If you email us directly, we receive your email address, your name if you include it, and whatever you write.
Please do not send us sensitive information, such as health details, religious beliefs, passwords, or bank or card details, unless it is truly needed for your enquiry. Our website talks about halal principles, but we never need to know your religion to help you.
Information collected automatically
- Server logs. When your browser asks for a page, our hosting provider may automatically record technical details, such as your IP address, browser type and the date and time of the request. This helps keep the website secure and working. [Hosting provider, log contents and log retention to be confirmed]
- Cookies and similar storage. We use one strictly necessary cookie,
bhope_consent, to remember your cookie choices. It lasts 12 months. If your browser blocks cookies, the same information is kept in your browser's local storage instead. We do not use marketing or advertising cookies. Our Cookie Policy has full details. - Analytics. We may use Plausible Analytics to count visits. It loads only if we have switched analytics on for this website and you have accepted Analytics. Plausible is designed to work without cookies and without storing IP addresses. It gives us totals, such as page views, referring websites, and broad browser, device and country information. It does not give us a profile of you.
- Anti-spam field. Our forms include a hidden field that people cannot see but spam programs often fill in. If it is filled in, we treat the message as spam. It does not collect any information about you.
Our fonts and images are stored on our own website. Loading a page does not send requests to outside font, image or advertising services.
How we use your information, and why
We use personal information only for the purposes below. We will not use it for a new purpose without telling you and, where the law requires, asking for your consent again.
| Purpose | Information used | Legal basis under the GDPR |
|---|---|---|
| Replying to contact messages and support requests | Name, email address, topic, message and any reference number | Your consent. If your message is about an order or agreement, also taking steps you have asked for before entering into a contract. |
| Handling investor enquiries | Name, email address, investor type, message, and any organisation and country you give | Your consent, and taking steps you have asked for before entering into a contract. Also our legitimate interest in managing relationships with potential investors. |
| Handling partner and supplier enquiries | Name, company, work email, country, partnership type, sector, message, and any website you give | Your consent, and taking steps you have asked for before entering into a contract. Also our legitimate interest in finding and assessing business partners. |
| Sending our newsletter | Email address and your consent record | Your consent |
| Remembering your cookie choices | Your choices, stored in bhope_consent | Legal obligation (to record and respect your choices) |
| Understanding how the website is used | Aggregate statistics from Plausible Analytics | Your consent |
| Keeping the website secure and free of spam | Server log data and the anti-spam field | Our legitimate interest in protecting the website and its visitors |
| Meeting our legal duties | Records needed for the duty, such as consent records and privacy requests | Legal obligation |
| Setting up, using or defending legal claims | Records relevant to the claim | Our legitimate interest in protecting our legal rights |
Where the privacy law that applies to you is based on consent rather than the legal bases above, we rely on your consent. For our forms and newsletter, you give it expressly by ticking a box. For basic technical information that any website needs in order to work securely, such as server logs, we rely on implied consent where the law allows it. This use is limited, not sensitive and reasonably expected.
When we rely on legitimate interests, we have weighed our interests against your rights and what you would reasonably expect. You can object at any time (see Your rights).
You do not have to give us any personal information. If you choose not to, we may not be able to reply to your enquiry.
No automated decisions or profiling
We do not make decisions about you by automated means alone, and we do not profile you. Our chat assistant, Amana, gives automated answers to questions, but it makes no decisions about you and does not send us anything.
Consent and your choices
Forms
Ticking the consent box on a form means you agree that we may use the details you give to respond to your enquiry. You can withdraw your consent at any time by emailing [Privacy email coming soon]. We will then stop using your information for that purpose, unless the law or a contract requires us to keep it. We may need reasonable notice. If you withdraw consent before we reply, we may not be able to help you.
Newsletter
Our newsletter is optional. We send it only if you give your express consent by ticking an unticked box. Every newsletter will:
- identify Bhope Business Group LTD as the sender;
- include our mailing address and a way to contact us; and
- include an unsubscribe link that keeps working for at least 60 days after we send it.
You can unsubscribe at any time, free of charge, using the link in any newsletter or by emailing [Email coming soon]. We will act on your request promptly, and always within 10 business days. We keep a record of when and how you gave your consent, so we can show that we had your permission.
Cookies and analytics
Optional cookies and analytics are switched off by default. They are switched on only if you choose "Accept all", or turn them on under "Customise". You can change your mind at any time using Cookie settings, which is also linked at the bottom of every page.
If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to keep optional cookies and analytics switched off.
The Amana chat assistant
Amana is an automated assistant that answers common questions about us. It is rule-based: it matches your question to answers we have written in advance. It is not a person.
- Amana runs entirely in your browser.
- Your conversation is not sent to us or to anyone else, and we do not store it. We cannot see what you type.
- Because we never receive your conversation, anything you tell Amana does not reach our team. To make a request or complaint, please use our contact form.
- Amana cannot give financial, legal or religious advice.
Who we share it with
We share personal information only when we need to, and only with the people and organisations described below.
Service providers
We use a small number of service providers to run this website. They act on our behalf (under the GDPR, as "processors"). We require them, by contract, to protect your information, to use it only to provide their service to us, and to delete or return it when the service ends.
| Service | Provider | What they do | Where information is stored |
|---|---|---|---|
| Form processing | [Form service provider to be named] | Receives messages sent through our forms and delivers them to us | [Location to be confirmed] |
| Business email | [Email provider to be named] | Hosts our email inbox, where enquiries arrive | [Location to be confirmed] |
| Newsletter | [Email service provider to be named] | Stores subscriber email addresses and consent records, and sends the newsletter | [Location to be confirmed] |
| Website hosting | [Hosting provider to be named] | Serves the website and may keep server logs | [Location to be confirmed] |
| Analytics (only with your consent) | Plausible Analytics | Counts visits in aggregate, without cookies | European Union |
Other times we may share information
- Professional advisers, such as lawyers, accountants and auditors, who must keep it confidential.
- Companies in our group. If one of our ventures is run by a separate company in our group, we may pass your enquiry to it so it can reply. It must handle your information in line with this policy. [Group companies to be listed, if any]
- When the law requires or allows it, for example to comply with a court order, to respond to a lawful request from a government authority, or to protect the rights, property or safety of our visitors, our business or others.
- If our business changes hands. If we sell, merge or reorganise all or part of our business, we may share information with the other party, as the law allows. They must protect it and use it only for the purposes in this policy.
- With your consent. In any other case, we will ask you first.
We never sell your information
We do not sell, rent or trade personal information. We do not share it with advertisers, and we do not use it for targeted advertising.
Where your information is stored
Some of our service providers may store or process information in countries other than the one where you live, such as the United States or countries in the European Union. While information is in another country, it is subject to the laws of that country. Courts, law-enforcement or national-security authorities there may be able to access it.
When we transfer information across borders, we use safeguards such as:
- contracts that require the recipient to protect it to the standard set out in this policy;
- for information about people in Europe, a European Commission decision recognising that the destination country offers adequate protection, or, where no such decision applies, the European Commission's Standard Contractual Clauses (SCCs);
- for information about people in the United Kingdom, UK adequacy regulations where they apply, or the UK International Data Transfer Addendum to the SCCs; and
- where the law requires it, an assessment of the privacy risks before the information is transferred.
You can ask our Privacy Officer for more information about these safeguards, including a copy of the relevant clauses.
How long we keep it
We keep personal information only as long as we need it for the purpose we collected it for, or as long as the law requires.
Proposed retention periods
The periods below are proposed defaults. They will be confirmed after legal review, before the website launches.
| Information | How long we keep it (proposed) |
|---|---|
| Contact messages and support requests | 24 months after our last contact with you |
| Investor and partner enquiries | 24 months after our last contact with you. If a business relationship follows, we keep the relevant records for as long as the relationship lasts and for as long as the law then requires. |
| Newsletter subscription | Until you unsubscribe |
| Newsletter consent record | While you are subscribed, and for 3 years after you unsubscribe, so we can show that we had your permission |
| Unsubscribe list | Your email address only, for as long as needed to make sure we do not email you again |
Cookie choices (bhope_consent) | 12 months, in your browser. After that, we ask again. |
| Server logs | [Period to be confirmed with our hosting provider] |
| Analytics | Plausible keeps only aggregate statistics, which do not identify you |
You can delete the cookies and storage in your own browser at any time, using your browser settings.
If we use your information to make a decision about you, we keep it long enough for you to ask to see it. If you have asked for access to your information, we keep it until you have had the chance to use your rights. When a retention period ends, we securely delete the information, or anonymise it so that it can no longer identify you.
How we protect it
We protect personal information with safeguards suited to how sensitive it is. They include:
- encrypted connections (HTTPS) for the website and for sending forms;
- access limited to the people on our team who need it for their work;
- contracts that require our service providers to keep information secure;
- collecting as little information as possible, so there is less to protect;
- storing fonts and images on our own website, so loading a page does not share your details with other companies; and
- a simple anti-spam field, instead of tools that track you.
No website or email system is completely secure. Please do not send passwords, bank or card details, or other sensitive information through our forms.
If something goes wrong
If a breach of security safeguards affects your personal information, we will act quickly to contain it and reduce the risk of harm. Where the law requires it, we will:
- report it to the relevant data protection authority, and notify you as soon as possible, if it creates a real risk of significant harm to you;
- for people in Europe or the United Kingdom, notify the relevant supervisory authority within 72 hours, and tell you without undue delay if there is a high risk to your rights and freedoms; and
- tell other organisations that could help reduce the harm, when that would help.
We keep a record of every breach or incident, whether or not it had to be reported, for at least 24 months.
Your rights
You have rights over your personal information. Which rights apply depends on where you live, but we will consider every request, wherever you are.
Everyone, wherever you live
- Access: ask whether we hold personal information about you, see it, and find out how we have used it and who we have shared it with.
- Correction: ask us to correct information that is inaccurate or incomplete.
- Withdraw consent: withdraw your consent at any time, subject to legal or contractual limits and reasonable notice. We will explain what this means for you.
- Challenge our compliance: raise a concern about how we handle your information (see Contact us and complaints).
Where local law gives you more rights
Depending on where you live, you may also have the right to:
- receive computerised personal information that you gave us in a structured, commonly used technological format, or have it sent to another organisation; and
- ask us to stop sharing your information, or to de-index any hyperlink attached to your name, where the law allows.
In the European Union and United Kingdom
- Access: get a copy of your personal information and details of how we use it.
- Rectification: have inaccurate or incomplete information corrected.
- Erasure: ask us to delete your information in certain cases.
- Restriction: ask us to pause using your information, for example while we check that it is accurate.
- Portability: receive the information you gave us in a machine-readable format, or have it sent to another organisation, where we rely on your consent or a contract.
- Objection: object to our use of your information where we rely on legitimate interests. You can always object to direct marketing, and we will stop.
- Withdraw consent: at any time. This does not affect anything we did before you withdrew it.
- Complain: to a data protection supervisory authority, in particular where you live or work, or where you think a breach of the law happened (see Contact us and complaints).
How to make a request
- Email our Privacy Officer at [Privacy email coming soon], or write to us at [Address coming soon]. Tell us what you would like us to do.
- We may ask for information to confirm who you are. We will ask only for what we need, and use it only for that purpose.
- We aim to respond within 30 days. If we need more time, where the law allows it, we will tell you why and when to expect our reply.
Someone else can make a request for you, such as a lawyer or family member, if they show us your written permission.
Requests are free of charge. If a request is clearly unfounded or excessive, or where the law allows a small fee, we will tell you before we go further. If we cannot meet a request in full, we will explain why, unless the law prevents us, and tell you how to challenge our decision.
Children
Our website is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal information from anyone under 16.
If you believe a child has sent us personal information, please contact us at [Privacy email coming soon]. We will delete it.
Changes to this policy
We may update this policy when our website, our services or the law changes. The "Last updated" date on this page shows when we last changed it.
If we make a significant change, we will make it clear on our website before the change takes effect. If you subscribe to our newsletter, we may also tell you by email. Where the law requires it, we will ask for your consent before using your information in a significantly different way.
Contact us and complaints
If you have a question or concern about privacy, please contact our Privacy Officer first. We take every concern seriously. We aim to acknowledge your message within 2 business days, and to resolve it within 30 days.
- Privacy Officer: [Name to be designated]
- Email: [Privacy email coming soon]
- Post: Privacy Officer, Bhope Business Group LTD, [Address coming soon]
- Online: our contact form
We will look into your concern and tell you what we found. If we have not handled your information properly, we will put it right and, where needed, change how we work.
Complaining to a regulator
If you are not satisfied with our response, you can complain to a privacy regulator. You do not have to contact us first, but we would welcome the chance to put things right.
- Where you live: the data protection authority in your country or region. If you are not sure which one that is, ask us and we will help you find it.
- European Union: the data protection authority in your country. The European Data Protection Board lists them all at edpb.europa.eu
- United Kingdom: the Information Commissioner's Office, at ico.org.uk