
HqO and GDPR
CertReports found no public GDPR evidence for HqO as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 5 Nov 2019
- Expires or valid through
- 26 Feb 2027
- Scope
- The purpose of this project is HqO’s business purpose: to provide the platform that facilitates access management, workspace analytics, and tenant engagement for businesses and their employees. HqO purpose is to help workplace operations, improve user experiences, and provide insights for optimising the workplace. For individuals, this includes features like mobile-based access to buildings, personalised notifications, and tools that allow them to control their preference. The platform also provides transparency, enabling individuals to understand how their data is being used and to manage their information. The benefits of processing include improving convenience for users by reducing reliance on physical access tools, such as keycards, and providing tailored information relevant to their needs. For businesses, the processing helps manage operations such as visitor tracking, access permissions, and compliance with legal requirements. It also provides insights into workspace usage, through aggregated and anonymised data. It gives the ability to monitor and analyse workspace trends and support better decision-making, such as optmising office layouts or managing energy consumption. Categories of data subjects whose personal data is transferred Registered Authorized Users (shall mean Customer, Company, Tenants and Tenant Users as defined in the Agreement) means users that have a User License. Categories of personal data transferred Customer or Tenants may submit Personal Data and or Customer Data to the Vendor, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to the following categories of Personal Data: ● First and last name ● Work Email Address ● Title ● Position ● Employer ● Temporary Access badge information ● Tenant status ● Location 15 ● User ID ● Building ID ● Time stamp of activities using the HqO Mobile App and other HqO Service ● Usage data for the HqO Mobile App and other HqO Services (each as defined in the Agreement) ● Text, images, sound and other data entered by Registered Authorized Users into the HqO Mobile App ● Technical support and other requests by Registered Authorized Users ● Transactional data resulting from Registered Authorized Users performing actions using features and functions of the HqO Mobile App and other HqO Services. ● Other Personal Data collected via the HqO Mobile App and other HqO Services as agreed to by the Customer from time to time. Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures. Data may be disclosed to third-party service providers that support platform hosting such as AWS, customer support such as Zendesk, analytics, communications such as Gmail, or security infrastructure such as Snowflake. These include cloud providers, IT service firms, analytics vendors, and customer success platforms. All such third parties are bound by contractual obligations to meet or exceed the level of protection required under the DPF Principles.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | HqO: Active: UK Extension Certification, EU-US Certification, SW-US Certification | Live pagesha256 2a95c31731 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is HqO GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Real estate and property category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Real estate and property vendor has GDPR evidence in the index yet.