HUDU Limited
Privacy Policy
Version 0.2 | Effective from the date you first access the Platform | Last updated: March 2026
BETA PLATFORM — This Privacy Policy applies to HUDU.vu during its Beta testing phase. The Platform is experimental and under active development. Data practices and technical arrangements described here reflect our current Beta operation and may evolve as the Platform develops, with appropriate notice to users.
Legal Framework — Three Separate Instruments
Your use of the Platform is governed by three separate legal documents, each of which requires independent acceptance:
The End User Licence Agreement ("EULA"), which governs your licence to use the Platform, your permitted and prohibited conduct, usage allowances, payment terms, liability, and intellectual property.
This Privacy Policy ("Privacy Policy"), which explains how HUDU Limited collects, uses, stores, and shares your personal data as data controller in connection with your account and use of the Platform. It describes your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The Data Processing Agreement ("DPA"), which governs the processing of personal data relating to third parties that may be contained in documents you upload to the Platform, and under which HUDU Limited acts as data processor on your behalf as data controller.
Each document must be accepted independently during registration or first login. Acceptance of this Privacy Policy does not constitute acceptance of the EULA or the DPA. Acceptance of any one document does not constitute acceptance of either of the others. All three documents are published in full at www.hudu.vu.
In the event of conflict between these documents: the DPA takes precedence on all matters relating to the processing of third-party personal data contained in uploaded documents; this Privacy Policy takes precedence on all matters relating to the processing of your own personal data as a user of the Platform; and the EULA governs on all other matters.
IMPORTANT: Please read all three documents carefully before using HUDU.vu. By creating an account or accessing the Platform, you confirm that you have read and accepted each document independently. If you do not agree to any of them, do not use the Platform.
1. Who We Are
HUDU Limited is the data controller for personal data processed in connection with your use of the Platform. We are registered in England and Wales (Company No. 15583356).
Data protection contact:
Email: privacy@hudu.uk
Website: www.hudu.vu
Post: HUDU Limited, Parkhill Studio, Walton Road, Wetherby, United Kingdom, LS22 5DZ
We are not currently required to appoint a Data Protection Officer. All data protection enquiries should be directed to the contact above.
2. What Personal Data We Collect
2.1 Account and registration data
When you register we collect: full name, email address, job title, organisation name, country of residence, and a hashed password. If you register with a work email address, your email domain is used to identify your organisation and enable organisation visibility features.
2.2 Usage and interaction data
When you use the Platform we automatically collect: log data (IP address, browser type, device, pages visited, timestamps), chat and query interactions, feature usage patterns, session duration, usage against your monthly allowances including top-up purchases, and error and diagnostic data.
2.3 Uploaded documents and AI processing
HUDU.vu uses AI at several points when you upload and work with documents. Here is what happens at each stage:
Document OCR and conversion: Uploaded documents are processed to extract readable text. Where documents are scanned or image-based, AI-assisted optical character recognition (OCR) is used to convert them to text.
Chunk embeddings: Extracted text is divided into fragments (chunks) and converted into vector embeddings — mathematical representations stored on our servers that allow the Platform to retrieve relevant content in response to your queries.
Summary provision: AI generates document summaries to support your review workflow.
Insight provision: AI analyses document content to identify issues, risks, comments, and queries in an engineering and construction context. These are the primary outputs of HUDU Insight.
Continuation chats: You can continue a conversation about a document or review within the Platform. These interactions are processed by AI in the context of your uploaded content.
Project chat: Within a Project Licence, team members can interact via project-level chat. These interactions are processed by AI and are visible to the project administrator.
Know How processing: Content you add to your Know How workspace is processed by AI to generate embeddings and enable intelligent retrieval and responses. Know How content may also inform agent-based analysis where you have configured this.
Connecting People: HUDU.vu analyses the embeddings generated from documents uploaded by users within the same organisational domain to detect whether they appear to be working on the same project — for example, by identifying common project names or references across documents. Where such a connection is identified, affected users may be notified and suggested that a Project Licence could enable more effective collaboration. This analysis uses embeddings only — no document content is shared between users. The detection is probabilistic and users are not obligated to act on any suggestion made. The legal basis for this processing is our legitimate interests in facilitating collaboration between users on the same organisational domain, where those interests are not overridden by your rights. Given that this feature involves profiling across users, we have conducted a data protection impact assessment (DPIA) in accordance with Article 35 UK GDPR before activating it.
Important: By uploading a document, you confirm that you have full authority to share it with a third-party AI-powered service, and that doing so does not breach any confidentiality obligation, intellectual property right, or data protection obligation.
2.4 Organisation visibility data (work email licences)
If you hold a Work Email Trial, Work Email Paid, Project Licence, or Guest licence, your name and organisational domain will be visible to other users within your organisation on the Platform’s organisation view. This is a core feature of work email licence types and cannot be opted out of while you hold such a licence. If you do not want this visibility, you should use a Personal Email licence instead.
2.5 Project data
If you are part of a project team, the Platform records your participation, activity, and document review history within that project. This information is accessible to the project administrator (the Project Licence holder).
3. Legal Basis for Processing
We process your personal data on the following legal bases under UK GDPR Article 6:
Contract performance (Article 6(1)(b)): Processing necessary to provide the Platform under your licence, including account creation, document processing, and AI-generated outputs.
Legitimate interests (Article 6(1)(f)): Processing necessary to improve and secure the Platform, develop our AI agents, understand usage patterns, review chat interactions to improve our agents and prompt frameworks, and carry out the Connecting People analysis described in Section 2.3 — where these interests are not overridden by your rights.
Legal obligation (Article 6(1)(c)): Where required by applicable law.
Consent (Article 6(1)(a)): Where we specifically ask for it, such as for certain communications or inclusion in internal development datasets. You may withdraw consent at any time.
4. How We Use Your Personal Data
We use your personal data to:
Create and manage your account and apply the correct licence type and allowances.
Provide, operate, and improve the Platform and its AI features.
Carry out the AI processing activities described in Section 2.3 above.
Enable organisation visibility for work email licence holders.
Enable project collaboration for Project Licence holders, team members, and Guests.
Process top-up purchases and apply additional usage allowances.
Carry out the Connecting People step — using embedding analysis to detect whether users on the same domain are working on the same project, and to notify them where a Project Licence may better serve the team (see Section 2.3).
Review chat interactions to improve our AI agents and prompt frameworks on the basis of our legitimate interests, as described in Section 5 below.
Communicate with you about your account, trial, subscription, allowances, and updates to these terms.
Detect, investigate, and prevent fraudulent or unlawful use of the Platform.
Comply with legal and regulatory obligations and exercise or defend legal claims.
5. AI Improvement and Model Training
5.1 Chat interactions
Your chat interactions (queries, prompts, and AI responses) may be reviewed by HUDU Limited personnel to improve our AI agents and prompt frameworks. We do this on the basis of our legitimate interests in developing and improving the Platform. You have the right to object to this processing at any time by contacting privacy@hudu.uk. We will cease this processing in respect of your data unless we have compelling legitimate grounds to continue. Objecting will not affect your access to the Platform.
5.2 Aggregated and anonymised data
We may use aggregated and pseudonymised interaction data solely for internal platform improvement. We apply appropriate technical measures to reduce the risk of re-identification before doing so. To the extent this data may still constitute personal data under UK GDPR, the legal basis is our legitimate interests in improving the Platform. You may object to inclusion in these datasets at any time by contacting privacy@hudu.uk and we will honour your objection.
5.3 No training on your documents
We will not use your uploaded documents, or the embeddings derived from them, to train any AI or machine learning model — whether our own or any third-party provider’s.
5.4 No sharing for training
We do not share your interaction data — anonymised or otherwise — with any AI provider or third party for training, fine-tuning, or model development. This data is used exclusively by HUDU Limited internally.
6. AI Providers, Data Sharing, and Data Location
6.1 How we use AI providers
To deliver the AI processing activities described in Section 2.3, relevant text fragments from your documents and interactions are transmitted to AI model providers. We do not transmit full copies of your original documents externally.
During the Beta phase, we are actively developing and refining the Platform. The specific AI providers and infrastructure we use may change as we do so. We will always seek to work with providers who operate under appropriate data processing agreements and with appropriate regard to data protection law.
6.2 Data location
We aim to store your data on servers located within the UK, EU, or EEA, and to use AI providers whose infrastructure is also UK, EU, or EEA based where this is practicable. Where personal data is transferred to a country outside the UK that does not benefit from an adequacy decision, we will ensure that appropriate safeguards are in place in accordance with UK GDPR Chapter V, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses. During the Beta phase, specific infrastructure arrangements may evolve, but the requirement to maintain appropriate safeguards applies throughout.
We will be transparent about the providers we use in our Privacy Policy. If data location is important to you, please review the current provider information at www.hudu.vu before uploading sensitive content.
6.3 Default AI provider
Our current default AI provider for Know How responses and AI-assisted analysis is Mistral AI, a European AI provider. We have chosen Mistral with data location in mind. We reserve the right to change the default provider at any time and will notify users when we do so.
6.4 User-configured AI providers
Where the Platform permits, users creating their own Know How agents may configure an alternative AI provider. If you do so, you accept full responsibility for that choice. HUDU Limited makes no warranty about any alternative provider’s performance, data handling, or compliance, and accepts no liability for any consequence of your choice. Data transmitted to a user-configured provider may be processed outside the UK, EU, or EEA. In those circumstances, you are responsible for ensuring that your use of that provider is consistent with your own data protection obligations, including the requirement to have appropriate safeguards in place for any international transfer.
6.5 Infrastructure and hosting
We use third-party infrastructure providers to operate the Platform. These act as data processors on our behalf under appropriate data processing agreements.
6.6 Payment processing
Payments are processed by a third-party payment processor. We do not store your full payment card details. Our payment processor is bound by applicable financial regulation and data protection law.
6.7 Within your organisation
If you hold a Work Email licence, your name and domain are visible to other users on your domain within the organisation view. If you are part of a project, your participation and activity are visible to the project administrator.
6.8 Business transfers
If HUDU Limited is involved in a merger, acquisition, or sale of assets, your personal data may transfer as part of that transaction. We will notify you of any such transfer and any change to data controller arrangements.
6.9 No sale of personal data
We do not sell, rent, or trade your personal data to any third party for commercial purposes.
7. Ownership of Content and Outputs
7.1 Your documents
Your uploaded documents remain your property (or that of the party who authorised you to upload them). HUDU Limited claims no ownership over content you upload.
7.2 AI-generated outputs
You own the outputs generated by the Platform in response to your inputs — including review reports, insights, summaries, and comments. To the extent protectable rights exist in such outputs under applicable law, HUDU Limited assigns or licences them to you as described in the EULA clause 10.3.
Outputs are AI-generated and for decision-support purposes only. Ownership does not imply accuracy, completeness, or fitness for any professional purpose. You remain responsible for verifying and applying outputs in accordance with your professional obligations.
7.3 HUDU Platform
Nothing here affects HUDU Limited’s ownership of the Platform itself, including its AI models, agents, prompt frameworks, architecture, embeddings infrastructure, and all associated technology.
8. Data Storage, Security, and Retention
8.1 Data location
We aim to store personal data, document embeddings, Know How content, and associated Platform data on servers located within the UK, EU, or EEA. During the Beta phase, specific infrastructure arrangements may evolve. We take data location seriously and will update our Privacy Policy to reflect the providers and infrastructure we are using at any given time.
8.2 Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, and secure deletion processes. No system is completely secure. If you become aware of a security incident involving your account, please notify us at privacy@hudu.uk immediately.
8.3 Retention periods
Document embeddings: deleted within 30 days of your written request (extendable to a maximum of 90 days for technically complex erasure, with notice to you within 30 days of your request). Separately, embeddings will be deleted within 100 days of 3 consecutive months of account inactivity.
Account data: retained for the duration of your licence plus a reasonable period thereafter as required by law (typically up to 6 years under the Limitation Act 1980).
Interaction and usage data: retained for up to 24 months from collection.
Project data: retained for the duration of the Project Licence and a reasonable period thereafter.
You may request deletion of your embeddings at any time by contacting privacy@hudu.uk.
Where a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, HUDU Limited will notify you without undue delay in accordance with Article 34 UK GDPR. We will provide you with: (a) a description of the nature of the breach; (b) the name and contact details of our data protection contact; (c) a description of the likely consequences of the breach; and (d) a description of the measures taken or proposed to address the breach. Where direct notification is not reasonably practicable (for example, because we do not hold current contact details), we will make a public communication or similar measure so that you are informed in an equally effective manner.
9. Your Rights Under UK GDPR
Subject to conditions and exceptions, you have the right to: access your personal data; have inaccuracies corrected; request erasure; restrict processing; receive data in a portable format; object to processing based on legitimate interests; and withdraw consent where processing is consent-based.
To exercise any of these rights, contact privacy@hudu.uk. We will respond within one calendar month (or three months for complex requests, with notice). We may need to verify your identity first.
10. Complaints
If you have concerns about how we handle your data, please contact us first at privacy@hudu.uk. You also have the right to complain to the Information Commissioner’s Office (ICO):
Website: ico.org.uk
Telephone: 0303 123 1113
Post: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
11. Cookies
The Platform may use cookies and similar technologies to operate its functionality, maintain your session, and understand usage. A full Cookie Policy is at www.hudu.vu. Where cookies require consent under PECR, we will ask for it before placing them.
12. Children
The Platform is for construction and engineering professionals and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe we have done so inadvertently, contact privacy@hudu.uk and we will delete it promptly.
13. Changes to This Policy
We may update this Policy from time to time. We will notify you of material changes by email or via the Platform. Continued use following notification constitutes acceptance.
14. Contact Us
HUDU Limited (Company No. 15583356)
Email: privacy@hudu.uk
Website: www.hudu.vu
Legal and Compliance: www.hudu.vu
HUDU Limited — Privacy Policy v0.2 | March 2026