Privacy Policy

RAIZHUB

Privacy Notice

How RaizHub collects, uses, shares and protects personal information

Effective date: 20 August 2026 | Version 1.0

Data controller: XAATAA CLEANING LTD, trading as RaizHub

Company number: 17090645

Registered office: 20 Wenlock Road, London, England, N1 7GU

Director / app owner: Diabanda Veloso

Privacy contact: info@raizhub.co.uk

Website: www.raizhub.co.uk

This document is a comprehensive launch draft. It should be checked against RaizHub's final technical implementation, vendor list, age-access model and data-retention configuration before publication, and reviewed by a UK privacy/technology solicitor.

This Privacy Notice explains how RaizHub handles personal information when you use the RaizHub mobile application, website and related services, including profiles, Home Feed, Connect, messaging, communities, events, ticketing, business/promoter features, advertising, customer support and safety systems (together, the “Services”).

RaizHub is the trading name of XAATAA CLEANING LTD. For the processing described in this Notice, XAATAA CLEANING LTD is generally the data controller, meaning it decides why and how personal information is processed.

1. Who This Notice Applies To

This Notice applies to RaizHub users, prospective users, event attendees, organisers, promoters, business users, website visitors, people who contact support, and other individuals whose information is processed through the Services.

This version assumes RaizHub is an 18+ service. If RaizHub permits children to access any part of the Services, we will update our age-assurance, privacy-by-design, transparency and safety arrangements before enabling that access.

2. Personal Information We Collect

2.1 Information you provide directly

Account information, such as name, username, email address, password credentials or authentication identifiers, and account settings.

Profile information, such as profile photo, cover image, bio, country of origin or roots, current city, languages, interests, hobbies, profession, goals, social interests and other profile fields you choose to complete.

User Content, including posts, photos, videos, comments, reactions, Moments, community content, event content, business listings and other material you publish.

Connection information, including Connect requests, accepted connections, declined or cancelled requests, blocks, mutes and shared community context.

Messages and communications sent through direct messages or community conversations, including attachments, delivery/read information and related metadata.

Event information, including events created, attendance/Going status, saves, ticket selections, event interactions, organiser details and related communications.

Commercial information, including business profiles, promoter information, advertising campaign settings, targeting selections, budgets and campaign analytics.

Support, complaint, report and appeal information, including messages to us, evidence you submit, moderation reports and account-safety communications.

Payment and transaction information, such as purchase amount, ticket type, transaction status, billing/contact information and payment-provider identifiers. We do not need to store full payment-card details where payments are handled by a payment processor.

2.2 Information collected automatically

Device and app information, such as device type, operating system, app version, language, time zone, device identifiers, browser type and technical configuration.

Usage and interaction information, such as screens viewed, searches, taps, saves, reactions, comments, Connect activity, event interactions, navigation patterns, session times and feature usage.

Log and security information, such as IP address, timestamps, authentication events, error logs, crash information, abuse signals and security events.

Approximate location inferred from information such as IP address or your selected city.

Precise device location only where the feature requires it, the device permits it and you have enabled the relevant permission or consent.

Storage/access technology data, including cookies, SDK identifiers, local storage, pixels or similar technologies used by the website or app, subject to applicable consent and exemption rules.

2.3 Information from other sources

Other users, for example when they tag you, invite you, report content, share content with you or provide information about a community or event.

Authentication, payment, hosting, analytics, communications, fraud-prevention, map/location and app-store providers where they provide information needed to operate a feature.

Event organisers, businesses or ticket providers where needed to administer an event, booking, refund, check-in or customer-support issue.

Publicly available sources where reasonably necessary for verification, fraud prevention, safety, intellectual-property complaints or legal compliance.

Law enforcement, regulators, courts, professional advisers or other authorised sources where information is lawfully provided to us.

3. Special Category and Criminal-Offence Information

Some information you choose to provide or publish may reveal matters that receive additional protection under data-protection law, for example racial or ethnic origin, religious or philosophical beliefs, political opinions, health information, sexual orientation, biometric information used for unique identification, or other special-category information.

RaizHub does not require users to disclose sensitive characteristics merely to participate in ordinary community activity. Where we intentionally process special-category information, we will identify both an Article 6 lawful basis and an applicable additional condition under Article 9 of the UK GDPR. Depending on the context, this may include your explicit consent, information you have deliberately made public, substantial-public-interest conditions permitted by law, vital interests, or the establishment, exercise or defence of legal claims.

Moderation, reporting and safety systems may also encounter allegations or information relating to suspected criminal offences. Where criminal-offence data is processed, we will rely on an applicable legal condition under the Data Protection Act 2018 and maintain appropriate safeguards where required.

4. How We Use Personal Information

Purpose

What we do

Main lawful basis

Provide and administer your account

Create and authenticate accounts, maintain sessions, manage settings, provide profile functionality and respond to account requests.

Contract

Build your profile and Social Passport

Display information you choose to share about roots, city, language, interests, profession, hobbies, communities and content.

Contract; consent where required for optional sensitive data

Home Feed and discovery

Deliver posts, communities, people, businesses and other content and personalise ranking.

Contract; legitimate interests

Connect

Recommend relevant people, process Connect requests, accepted connections, blocks and related relationship states.

Contract; legitimate interests

Messaging

Deliver direct and community messages, attachments, read/delivery states, drafts and abuse-prevention controls.

Contract; legitimate interests for security/safety

Communities

Provide community discovery, membership, content, moderation, roles and community communications.

Contract; legitimate interests

Events and ticketing

Display events, process Going/interest states, administer tickets, purchases, event communications, capacity and check-in where supported.

Contract; legal obligation; legitimate interests

Payments and financial administration

Process purchases, detect payment fraud, reconcile transactions, issue refunds and maintain accounting/tax records.

Contract; legal obligation; legitimate interests

Promotions and advertising

Provide promoter tools, campaign delivery, targeting, measurement, frequency control and billing.

Contract; legitimate interests; consent where required

Recommendations and personalisation

Use city, roots, language, interests, communities, connections, freshness and interaction signals to improve relevance and diversity.

Legitimate interests; contract where integral to the service

Safety, moderation and integrity

Detect, investigate and act on spam, scams, harassment, illegal content, child-safety concerns, fraud, security threats, account compromise and violations of our rules.

Legitimate interests; legal obligation; other lawful conditions where sensitive/criminal-offence data is involved

Support, complaints and appeals

Respond to support requests, data-protection complaints, moderation appeals and service complaints.

Contract; legal obligation; legitimate interests

Service improvement and analytics

Measure reliability, diagnose crashes, understand feature performance, improve accessibility and product quality.

Legitimate interests; consent where required for storage/access technologies

Marketing communications

Send product, event or commercial communications where permitted and honour opt-outs.

Consent where PECR requires it; legitimate interests only where lawful

Legal compliance and claims

Comply with court orders, statutory duties, regulatory requests, record-keeping requirements and establish, exercise or defend legal claims.

Legal obligation; legitimate interests

5. Lawful Bases in More Detail

Contract: processing that is necessary to provide the Services you request or to take steps at your request before entering a contract.

Legal obligation: processing necessary to comply with UK legal or regulatory duties.

Legitimate interests: processing necessary for RaizHub's or a third party's legitimate interests where those interests are not overridden by your rights and interests. Examples include platform security, fraud prevention, service improvement, relevant recommendations and enforcing community standards.

Consent: used where you have a genuine choice and the law requires or makes consent appropriate, for example certain precise-location uses, optional sensitive profile information, particular marketing, or non-essential storage/access technologies. You can withdraw consent, but withdrawal does not make earlier processing unlawful.

Vital interests: may be used in exceptional circumstances to protect someone's life where the legal requirements are met.

6. How Recommendations and Personalisation Work

RaizHub may personalise the Home Feed, Connect suggestions, communities, events, businesses and other recommendations. Signals may include your selected current city, roots/country context, languages, interests, communities, connections, content freshness, saves, comments, profile opens, Connect actions, event activity, hides, reports and repeated skips.

We aim to balance relevance with freshness, diversity and exploration. Paid promotion may influence placement where clearly identified, but it should not automatically override safety, eligibility or core relevance controls.

Where a decision would produce legal or similarly significant effects solely through automated processing, we will provide the protections required by applicable data-protection law. Ordinary feed ranking and content recommendations are generally intended to personalise content rather than make legally significant decisions about you.

7. Location Information

RaizHub is built around community and city relevance. You may provide your current city manually. We may also infer approximate location from IP address or similar technical information.

If a feature requests precise device location, we will ask through the device permission mechanism and, where required, obtain consent. You can normally disable precise location through your device settings. Some location-based features may then become less accurate or unavailable.

We do not intend to publish your precise live location merely because you enable location services. Public-facing location should normally use city-level or other deliberately chosen profile information unless a feature clearly tells you otherwise.

8. Who Can See Information on RaizHub

Public or broadly visible profile/content information may be visible to other RaizHub users according to the audience and privacy settings shown in the product.

Connection-only content is intended to be visible only to eligible connected users, subject to feature design and moderation requirements.

Community content may be public, member-only, role-restricted or otherwise limited according to community settings.

Direct messages are intended for the relevant participants, subject to lawful safety review, user reports, security investigations and legal obligations.

Event organisers may receive information reasonably necessary to administer tickets, attendance, check-in, refunds or event communications.

Your 'View as Others' or similar preview feature is intended to help you understand what other users can see, but you should still review your privacy settings carefully.

9. Who We Share Personal Information With

Cloud hosting, database, authentication, storage and infrastructure providers.

Payment processors and fraud-prevention providers.

Email, push-notification, SMS or customer-communications providers.

Analytics, crash-reporting, performance and product-measurement providers, subject to applicable consent requirements.

Map, location and geocoding providers where a location feature uses them.

Content-safety, moderation, security and abuse-prevention service providers.

Customer-support and help-desk providers.

App stores and platform operators where necessary to distribute the app, manage subscriptions or support purchases.

Event organisers, ticket sellers or business partners where necessary to provide a transaction or feature you choose.

Professional advisers such as lawyers, accountants, auditors and insurers.

Law enforcement, regulators, courts, government bodies or other parties where disclosure is legally required or reasonably necessary to protect rights, safety or security.

A buyer, investor, group company or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and data-protection safeguards.

We do not sell private conversations to advertisers. Advertising or recommendation systems should not provide advertisers with access to the contents of your private messages.

10. International Transfers

Some service providers or recipients may process personal information outside the United Kingdom. Where UK data-protection law treats a transfer as restricted, we will use an approved legal mechanism, such as an adequacy regulation or appropriate contractual safeguards (for example, the UK International Data Transfer Agreement or an approved UK Addendum), together with any transfer assessment or supplementary measures required by law.

You may contact us for further information about the safeguards used for relevant international transfers.

11. How Long We Keep Personal Information

We keep personal information only for as long as reasonably necessary for the purposes described in this Notice, including legal, accounting, safety, fraud-prevention, dispute-resolution and enforcement needs. Retention may vary by data type and feature.

Data category

Indicative retention

Account and core profile data

While your account is active; normally deleted or anonymised after account closure, subject to a short operational deletion period and legal/safety exceptions.

Deleted content and routine operational backups

Removed from active systems as soon as reasonably practicable; backup copies may persist for up to 90 days unless a longer period is required for security, legal or technical reasons.

Posts, comments, media and community content

While published or until deleted/removed, then according to backup, moderation, legal and dispute requirements.

Direct/community message data

While needed to provide messaging and according to applicable product deletion controls; reported or safety-relevant messages may be retained longer where necessary for safety, enforcement or legal obligations.

Connection and membership records

While the relationship or membership exists and for a limited period afterwards where needed for integrity, safety, abuse prevention or dispute handling.

Event RSVP / Going data

While relevant to the event and for a limited period afterwards for event history, fraud prevention, support and disputes.

Payment, invoice and accounting records

Normally retained for the period required by tax, accounting and company-record obligations; this may be six years or longer in some circumstances.

Security and access logs

Typically up to 12 months, unless needed longer for an active investigation, legal requirement or serious security incident.

Moderation, abuse, report and appeal records

Typically up to 24 months after closure of the matter, and longer where reasonably necessary for serious safety matters, repeat abuse, legal claims or regulatory obligations.

Customer support records

Typically up to 24 months after the issue is closed, unless a longer period is required for an ongoing dispute or legal obligation.

Marketing preferences and suppression records

For as long as needed to honour your preference, demonstrate compliance and avoid contacting you contrary to an opt-out.

Consent records

For as long as the relevant processing continues and afterwards for a period reasonably necessary to demonstrate compliance.

12. Security

We use technical and organisational measures designed to protect personal information against unauthorised access, loss, alteration, misuse or disclosure. Measures may include access controls, authentication safeguards, encryption in transit, secure development practices, monitoring, backups, supplier controls and incident response.

No online service can guarantee absolute security. You are responsible for keeping your account credentials confidential and should contact us promptly if you believe your account has been compromised.

13. Cookies, SDKs and Similar Technologies

Our website and app may use cookies, local storage, SDKs, pixels, device identifiers and similar storage/access technologies. Some are necessary for login, security, fraud prevention, preferences or core service operation. Others may support analytics, measurement, personalisation, social features or advertising.

Where PECR or other applicable law requires consent, we will ask before using non-essential storage/access technologies. Where a statutory exception applies, we may use the relevant technology without consent while still providing appropriate information.

A separate Cookie / Storage and Access Technologies Notice should identify the technologies actually deployed, their purposes, providers and durations.

14. Marketing

We may send service messages that are necessary for your account or transactions, such as security notices, ticket confirmations or important product communications.

Marketing by email, SMS, push notification or similar electronic means will be sent only where permitted by applicable law. Where consent is required, you can withdraw it at any time. Where an unsubscribe or preference control is provided, we will honour it.

Opting out of marketing does not stop essential service or transactional communications.

15. Your Data Protection Rights

Depending on the circumstances and applicable law, you may have rights including:

The right to be informed about how your personal information is used.

The right of access to personal information we hold about you.

The right to correct inaccurate or incomplete information.

The right to request erasure in certain circumstances.

The right to restrict processing in certain circumstances.

The right to data portability for certain information processed by automated means on the basis of consent or contract.

The right to object to processing based on legitimate interests and, in particular, to object to direct marketing.

Rights relating to certain solely automated decisions that have legal or similarly significant effects.

The right to withdraw consent where processing is based on consent.

The right to complain to us and to the UK data-protection regulator.

To exercise a right, contact info@raizhub.co.uk. We may need reasonable information to verify your identity and locate the relevant data. We will respond without undue delay and normally within the period required by data-protection law.

16. Data Protection Complaints

You can raise a data-protection complaint directly with RaizHub at info@raizhub.co.uk or by writing to our registered office. We will provide a clear route for complaints, acknowledge a qualifying data-protection complaint within the legally required period, investigate it without undue delay, keep you appropriately informed and communicate the outcome.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. You can find current complaint information through the ICO's official website.

17. Account Deletion

You may request account deletion through available in-app settings or by contacting info@raizhub.co.uk. Deletion removes or de-identifies account information from active systems subject to legal, safety, fraud-prevention, financial-record, backup and dispute-resolution exceptions.

Some content may remain where another user has lawfully reshared or incorporated it, where an event or transaction record must be preserved, or where immediate removal from backups is not technically practical. Where retained, access will be limited to the purpose justifying retention.

18. Children

This version of RaizHub's privacy framework assumes the Services are intended for adults aged 18 and over. We do not intend knowingly to operate an under-18 service under this version of the Notice.

If we learn that an account belongs to a person who does not meet the applicable minimum age, we may restrict or close the account and take appropriate steps regarding the data, subject to legal and safety obligations.

If RaizHub later allows children, we will carry out the necessary child-access assessment, implement age-appropriate privacy protections and update this Notice before enabling such access.

19. Safety, Moderation and Online Safety

RaizHub is a user-to-user community service. We may process account, content, message metadata, reports, device/security information and other relevant information to prevent, detect, investigate and respond to illegal content, fraud, harassment, child-safety concerns, threats, account compromise and breaches of our rules.

Where required by applicable online-safety law, we may maintain risk assessments, reporting and complaints systems, moderation controls, records and legally required reports to competent authorities.

Safety processing does not mean that RaizHub routinely reads every private message. Review may occur where content is reported, lawfully detected by safety/security systems, necessary to investigate abuse, or required by law.

20. Business Users, Organisers and Promoters

If you use RaizHub as a business, event organiser or promoter, we may process business contact details, campaign settings, event information, transaction data, audience targeting choices, performance metrics and support communications.

Where you independently collect personal information from attendees, customers or other individuals outside the data RaizHub processes for its own platform purposes, you may have your own obligations as a controller. RaizHub and the business user may each be responsible for different processing activities.

21. Changes to This Privacy Notice

We may update this Notice to reflect changes to the Services, technology, vendors, legal requirements or our privacy practices.

If a change is material, we will provide reasonable notice through the app, website, email or another appropriate method where required. The effective date at the top identifies the current version.

22. Contact Us

Privacy email: info@raizhub.co.uk

Website: www.raizhub.co.uk

Postal address: RaizHub / XAATAA CLEANING LTD, 20 Wenlock Road, London, England, N1 7GU

Company number: 17090645

Pre-Publication Privacy Checklist (Internal - remove before publication if desired)

Confirm that RaizHub is strictly 18+. If any under-18 access is possible, obtain specialist advice and complete the required child-access/age-assurance and children's privacy work before launch.

Map every production SDK/provider and confirm the recipient categories above match reality.

Create a separate Cookie / Storage and Access Technologies Notice listing actual cookies, SDKs, identifiers, providers, purposes and durations.

Confirm whether precise location is used and ensure permission/consent and city-level public-display rules match the app.

Confirm actual message deletion/retention behaviour and update the retention table if needed.

Confirm moderation report retention and security log retention against production configuration.

Complete a Record of Processing Activities (ROPA) where required/appropriate and document lawful-basis decisions.

Complete Legitimate Interests Assessments for processing that materially relies on legitimate interests.

Complete DPIAs for high-risk processing, including any sensitive profiling, precise location, large-scale moderation/safety tooling, facial/biometric processing or significant automated decision-making.

Document Article 9 conditions for any special-category data intentionally processed and DPA 2018 conditions for criminal-offence data.

Put processor agreements in place with vendors and document international-transfer safeguards.

Implement a data-protection complaint process that meets the post-DUAA complaint-handling requirements.

Confirm subject-rights workflow, identity verification, export, correction, deletion and objection tooling.

Confirm ICO registration/data-protection fee position and current registration details if applicable.

Review this Notice with a UK privacy/technology solicitor before public launch.