Privacy Policy
Last updated: 10 February 2026
Holisteed ("we", "us", "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, store, and share personal data when you use the Holisteed platform and website, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all applicable UK data protection legislation.
1. Data Controller
The data controller responsible for your personal data is:
Holisteed Ltd
Registered in England and Wales
Email: support@holisteed.com
2. Personal Data We Collect
We collect and process the following categories of personal data:
Account Information
- Name, email address, phone number
- Business name and address
- Billing and payment information
- Account login credentials
Platform Usage Data
- Records you create within the platform (horse records, medical data, training logs, race entries)
- Documents you upload (vet reports, invoices, prescriptions)
- Activity logs and audit trails
Technical Data
- IP address, browser type, and device information
- Usage analytics (pages visited, features used, session duration)
- Cookies and similar tracking technologies
3. Lawful Basis for Processing
We process your personal data on the following lawful bases under Article 6 of the UK GDPR:
- Performance of a contract: To provide and maintain the Holisteed platform and services you have subscribed to.
- Legitimate interests: To improve our services, ensure platform security, provide customer support, and communicate service updates.
- Consent: Where you have given explicit consent, for example to receive marketing communications. You may withdraw consent at any time.
- Legal obligation: To comply with applicable laws and regulations.
4. How We Use Your Data
We use your personal data to:
- Provide, operate, and maintain the Holisteed platform
- Process your subscription and payments
- Provide customer support and respond to enquiries
- Send service-related notifications and updates
- Improve and develop our platform and services
- Ensure the security and integrity of our systems
- Comply with legal and regulatory obligations
5. Data Sharing
We do not sell your personal data to third parties. We may share your data with:
- Service providers: Trusted third parties who assist in operating our platform (hosting, payment processing, email delivery), bound by data processing agreements.
- Owner portal users: Where you use the owner portal feature, designated horse owners will see the information you choose to share about their horses.
- Legal requirements: Where required by law, regulation, or valid legal process.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate safeguards.
6. International Transfers
Your data is primarily stored and processed within the United Kingdom and European Economic Area. Where we transfer data outside the UK, we ensure appropriate safeguards are in place, such as UK International Data Transfer Agreements or adequacy decisions, in compliance with the UK GDPR.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with our services. Upon account closure, we will retain your data for a maximum of 12 months to fulfil any legal obligations, resolve disputes, and enforce our agreements, after which it will be securely deleted.
You may request earlier deletion of your data at any time by contacting us.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption in transit and at rest, access controls, regular security audits, and staff training.
9. Your Rights
Under the UK GDPR, you have the following rights in relation to your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data in certain circumstances.
- Right to restrict processing: Request that we limit how we use your data.
- Right to data portability: Request your data in a structured, commonly used format.
- Right to object: Object to processing based on legitimate interests or for direct marketing.
- Rights related to automated decision-making: You will not be subject to decisions based solely on automated processing that produce legal effects concerning you.
To exercise any of these rights, please contact us at support@holisteed.com. We will respond to your request within one month.
10. Cookies
Our website uses essential cookies required for the platform to function correctly. We use analytics cookies to understand how visitors use our website. You can manage your cookie preferences through your browser settings. For more detail, see our cookie preferences on first visit.
11. Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our website and, where appropriate, by email. The "Last updated" date at the top of this page indicates when this policy was last revised.
13. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Helpline: 0303 123 1113
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: support@holisteed.com