Gifting your security team can sign off
We're ISO 27001 and Cyber Essentials Plus certified, built so you never have to collect a home address, and we process data in the UK and EU.
Certified, and independently reviewed
- ISO 27001 certified by NQA
- Cyber Essentials Certified Plus
- Trustpilot
Certified, not just careful
What we hold, and who issued it
ISO/IEC 27001:2022
Certified by NQA, certificate 193981, covering all operations including our web, API and mobile platforms. Valid to April 2027.
Cyber Essentials Plus
Certified across the whole organisation, with recertification due March 2027.
Registered with the ICO
Registration ZA218199. Our Record of Processing Activities is reviewed quarterly.
The safest personal data is the data you never collect
Most gifting asks you to hand over employees' home addresses. We don't need, and that changes the conversation with your DPO before it starts.
Less data collected means less to protect or explain, and no awkward email asking 300 people where they live.
Three ways to send
None of them need a home address
Share a gifting link
Export the gift links and drop them into Slack, Teams, or wherever your team already talks. No recipient data reaches us at all.
Send by email or SMS
The only field we need is a single contact point: a work email or a mobile number. Nothing else.
Send a physical gift
The recipient adds their own delivery address when they redeem, so neither you nor we ever hold it.
Your security questions, answered
The detail your security, legal and procurement teams will ask for. If yours asks something that isn't here, send it over.
Which security certifications does Huggg hold?
Huggg is certified to ISO/IEC 27001:2022 by NQA, certificate 193981, valid to April 2027. The scope covers all operations, including our web, API and mobile platforms.
We also hold Cyber Essentials Plus across the whole organisation, with recertification due March 2027, and we're registered with the ICO under ZA218199.
Where is our data processed, and how is it encrypted?
Processing happens in the UK and the EU, on AWS. There's one stated exception: an SMS sent to a phone in another country is inevitably processed in that country, so our SMS provider's processing follows the recipient's location.
Data is encrypted in transit with TLS 1.2 or above, and at rest with AES-256.
Who at Huggg can access our data?
Access runs on least privilege. Role-based access controls keep customer data segregated, and only senior people who need access to a system or its data are granted it. Access is protected by MFA, logged, and monitored.
Staff cannot download customer data onto their own machines. Admin access and activity logs are retained for at least 30 days and can be shared with you on request.
What personal data do you actually need about our employees?
Very little, and often none at all.
You can export gift links and share them however your team already communicates, in which case no recipient data reaches us. If you send through the platform, the only mandatory field is a single contact point: a work email or a mobile number.
Gift card recipients enter no personal data. For physical gifts, the recipient adds their own delivery address when they redeem, so neither you nor we need to hold it.
How do you monitor and patch the platform?
We run continuous automated monitoring and alerting across our infrastructure and applications. Anomalous behaviour raises automated alerts that escalate to senior engineers.
Critical security patches are applied within 14 days of us being alerted to the vulnerability. Automated vulnerability scanning runs continuously across the cloud environment and our application dependencies, risk-prioritised and tracked through our ISMS.
The platform sits behind firewalls and isolated internal networks with no public exposure, with a web application firewall, rate limiting on API endpoints, DDoS protection at the load balancer, and strict content security policies.
What happens if there is a security incident?
We have a documented incident response process. We investigate, and we notify affected clients within 48 hours of becoming aware of an incident.
How is the platform backed up?
Automated daily backups with versioning, and multi-zone data replication. We maintain a documented business continuity and disaster recovery plan, reviewed annually, and we test disaster recovery.
How are card payments handled?
Huggg is PCI DSS compliant as a Level 4 merchant, validated by self-assessment questionnaire (SAQ A).
Card details are entered directly into hosted fields provided by Checkout.com, our PCI DSS Level 1 certified payment provider, so cardholder data is never stored or processed on Huggg systems. We hold only a token, the last four digits, the card expiry and the card scheme. Our Attestation of Compliance can be provided on request.
Can we see your sub-processor list and a data processing agreement?
Yes. We share our sub-processor list and data processing agreement on request as part of your due diligence, along with our ISO 27001 and Cyber Essentials Plus certificates.
Where transfers outside the UK are unavoidable, the UK Addendum to the EU Standard Contractual Clauses applies.
How long do you keep our data?
Only as long as it's needed. We have a documented process for handling specific deletion requests, and we maintain a Record of Processing Activities that is reviewed quarterly.
Trusted by 2,000+ companies
- WPP Media
- Just Eat
- Octopus Energy
- Starbucks
- Allica Bank
- Hargreaves Lansdown
Got a security questionnaire?
Send it over. We answer these every week, and we can share our ISO 27001 certificate, Cyber Essentials Plus certificate, and data processing agreement.