HaloGet Started

Privacy Policy

Last updated: 8 April 2026

1. Who we are

Halo Benefits Ltd ("Halo", "we", "us") is the data controller for personal data collected through halobenefits.co.uk and the Halo platform (app.halobenefits.co.uk). Our registered office is in England. You can contact us at hello@halobenefits.co.uk.

2. What data we collect

We collect the following categories of personal data:

  • Account information — name, email address, phone number, job title.
  • Employment information — employer name, salary details (for Halo Pay calculations).
  • Child information — child's name, date of birth, sex (required for nursery arrangements).
  • Nursery information — nursery name, Ofsted/Care Inspectorate number, contact details.
  • Company information — company name, company number, registered address, contact details.
  • Financial information — bank details for Direct Debit mandates (processed via GoCardless).
  • Usage data — pages visited, features used, device and browser type (via analytics). On our nursery fee savings calculator at /calculator we additionally record an anonymous, video-like replay of your interaction with the page (mouse movement, clicks, scrolling, and the values you enter into calculator fields). These recordings help us understand where visitors get stuck and improve the calculator. Recordings are stored by our analytics provider Amplitude (see Section 7) and are not used to identify you personally.
  • Business contact data — work email address, job title, employer name, company number, and business phone number. Where this data has been sourced from third-party B2B data providers rather than directly from you, see Section 3.

3. Business contact data sourced from third parties

For our B2B outreach programme we obtain business contact data from specialist B2B data providers, currently:

  • Apollo.io — lead database and contact enrichment.
  • Instantly.ai — lead database and contact enrichment.

These providers supply work email addresses, job titles, employer names, company numbers, and business phone numbers compiled from publicly available and licensed business sources. We do not obtain personal email addresses, home addresses, or private contact details through these providers. If we contact you using data sourced this way, every message identifies Halo, explains why you are being contacted, and contains a clear opt-out. On request we will tell you which provider supplied your details.

4. How we use your data

We process personal data for the following purposes:

  • Setting up and managing childcare arrangements under the workplace nursery exemption.
  • Calculating Halo Pay amounts and tax/NI savings.
  • Processing payments between employers and nurseries.
  • Verifying nursery registrations (Ofsted/Care Inspectorate).
  • Communicating with you about your account and arrangements.
  • Improving our platform and services.
  • Complying with legal and regulatory obligations.
  • Conducting B2B awareness outreach to employers, senior decision-makers, and employees at UK businesses about the workplace nursery exemption (Section 318 ITEPA 2003) and how Halo helps them make use of it. This includes sending cold outreach emails to corporate work addresses, running follow-up sequences, and using engagement signals (opens, clicks, replies) and statistical modelling to refine targeting and suppression.

5. Legal basis for processing

We rely on the following legal bases under UK GDPR:

  • Contract — processing necessary to provide our services to you.
  • Legitimate interests — improving our services, fraud prevention, business analytics, and conducting B2B direct marketing to corporate subscribers (see Section 6).
  • Legal obligation — compliance with tax, employment, and financial regulations.
  • Consent — where required, for marketing communications and optional cookies.

6. Legitimate interest assessment for B2B outreach

When we send cold outreach emails to corporate work addresses, we rely on legitimate interests under Article 6(1)(f) UK GDPR, together with the corporate subscriber exemption under Regulation 22 of the Privacy and Electronic Communications Regulations 2003 (PECR).

  • Purpose — to introduce the workplace nursery exemption (Section 318 ITEPA 2003) and the Halo platform to UK employers whose staff could benefit from tax and NI savings on childcare. This is a lawful commercial purpose.
  • Necessity — direct contact with decision-makers and affected employees at relevant employers is the most proportionate way to reach businesses whose workforce could benefit. Broad advertising alone would not reach the intended audience effectively.
  • Balancing — we only contact people at their corporate work email address, in their professional capacity, about a statutory tax benefit (the workplace nursery exemption under Section 318 ITEPA 2003) that could deliver meaningful tax and National Insurance savings to their workforce or, where contacted as employees, to them personally. The outreach is informational in nature: we are raising awareness of an underused HMRC-recognised benefit, not promoting a paid consumer product. We do not use this basis to contact individual subscribers, sole traders, or non-corporate partnerships (outside Scotland). Every message identifies Halo, explains why the recipient is being contacted, and contains a clear opt-out. Opt-out requests are actioned immediately and the address is added to a permanent suppression list. Because the communication offers a potential financial benefit to the recipient rather than imposing a cost, we consider the impact on recipients to be minimal to positive, and not to override our legitimate interests.

7. Who we share your data with

We may share your personal data with:

  • Your employer — arrangement details and Halo Pay amounts.
  • Nursery providers — child details and payment information for arrangements you set up.
  • GoCardless — payment processing (as a data processor).
  • Clerk — authentication services (as a data processor).
  • Vercel — hosting and infrastructure (as a data processor).
  • Apollo.io — B2B lead sourcing and email sequence delivery (as a data processor).
  • Instantly.ai — B2B lead sourcing and cold email sending platform (as a data processor).
  • SendGrid (Twilio) — transactional and outreach email delivery infrastructure (as a data processor).
  • Customer.io — customer communications and lifecycle messaging (as a data processor).
  • PostHog — product analytics and usage measurement (as a data processor).
  • Amplitude — product analytics and session replay on the nursery fee savings calculator (as a data processor).
  • Microsoft Clarity — session replay and behavioural analytics on the Halo platform (as a data processor).

We do not sell your personal data. We only share data as necessary to provide our services or as required by law.

8. Data retention

We retain your personal data for as long as your account is active and for a reasonable period afterwards to comply with legal obligations (including tax record-keeping requirements). Arrangement records are retained for at least 6 years after the arrangement ends, in line with HMRC requirements. Business contact records used for B2B outreach are retained while the outreach programme is active; opted-out addresses are kept on a suppression list indefinitely so that we do not contact you again in error.

9. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Request erasure of your data (subject to legal retention requirements).
  • Object to or restrict certain processing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time (where processing is based on consent).

To exercise any of these rights, contact us at hello@halobenefits.co.uk.

10. Rights relating to direct marketing

If you have received a B2B outreach email from us, you have additional rights in relation to that processing:

  • Right to object — you have an absolute right to object to direct marketing at any time under Article 21(2) UK GDPR. We will stop processing your personal data for marketing purposes immediately on request.
  • Opt out — every outreach email contains a one-click unsubscribe link. You can also reply "unsubscribe" to any message, or email hello@halobenefits.co.uk, and we will suppress your address from all future outreach within one working day.
  • Source of data — if we contacted you using data obtained from a third-party B2B data provider, you can ask us which provider supplied your details and we will tell you.
  • Erasure — you can request deletion of your business contact details from our systems. We will retain a minimal suppression record (email address and opt-out flag) on the basis of legitimate interest in honouring your objection, so that we do not contact you again in error.

11. Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, and regular security reviews.

12. International transfers

Several of our service providers (including Vercel, Clerk, Apollo.io, Instantly.ai, SendGrid, Customer.io, PostHog, Amplitude, and Microsoft Clarity) are based in the United States and may process personal data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or reliance on adequacy decisions (including the UK–US Data Bridge where applicable).

13. Complaints

If you have concerns about how we handle your data, please contact us first at hello@halobenefits.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

14. Changes to this policy

We may update this privacy policy from time to time. We will notify you of significant changes via email or through the platform. The "last updated" date at the top of this page indicates when the policy was last revised.