Last updated: 11 October 2026
HX | Hive eXperience ("HX", "we", "us", "the Platform") is operated by Elevated Experience Ltd, a company registered in Jersey, Channel Islands. This Privacy Policy explains, in full, how we collect, use, share, store, and protect personal information for everyone who uses the Platform, wherever in the world they use it from, at hive.elevatedexperience.vip and any associated apps or services.
HX is used by members and communities in many countries. This policy is written to meet our obligations under the Data Protection (Jersey) Law 2018, and, for members based in the United Kingdom or European Economic Area, the UK GDPR and EU GDPR. Rather than offering a different, lesser standard of protection to people outside those regions, we apply the same core protections and rights described in this policy to every HX member globally.
Elevated Experience Ltd is the Data Controller for all personal information processed through HX, wherever our members are based. That means we, not any individual Hive owner or Hive administrator, are legally responsible for deciding how and why personal data is processed on the Platform (see Section 6 for what this means in practice for community-level administrators).
Business Registration: Elevated Experience Ltd is registered with the Jersey Financial Services Commission (JFSC) under the Registration of Business Names (Jersey) Law 1956, registration number 36688.
Data Protection Registration: Separately, Elevated Experience Ltd is registered with the Jersey Office of the Information Commissioner (JOIC) under registration number 19141. You can verify this registration at jerseyoic.org.
Lead supervisory authority: Because we are established in Jersey, the Jersey Office of the Information Commissioner (JOIC) is our lead data protection supervisory authority. If you are based in the UK or EEA, you may also have the right to raise a complaint with your own local data protection authority, in addition to or instead of JOIC, see Section 14.
Wherever GDPR or an equivalent standard applies to you, we only process your personal data where we have a valid legal basis to do so. Depending on what we're doing with your data, that basis is one of the following:
| Basis | When we rely on it |
|---|---|
| Contract | Creating and running your account, hive membership, messaging, event registration, and marketplace or course purchases, this is the core basis for most of what HX does. |
| Consent | Optional profile fields you choose to add, marketing communications you opt into (including the optional "keep me posted" tick on a form), the organiser using your answers to a form for the purpose the form states, and, where required locally, non-essential cookies or similar technology. |
| Legitimate interests | Keeping the Platform secure, preventing fraud and abuse (including unfair voting on forms), maintaining essential technical logs, improving reliability, counting visits to public pages anonymously so their hosts can see how they are doing, and holding the details of someone who has been nominated on a form so the organiser can invite them, always balanced against your right to privacy. |
| Legal obligation | Retaining certain financial and transaction records, and responding to lawful requests from regulators or law enforcement. |
We collect the following categories of information:
Your name, email address, password (securely hashed, never stored in plain text), date of birth (used only to confirm you meet our minimum age requirement, see Section 12), country, optional phone number, profile photo, headline, biography, skills, experience, and, if you list one, verified business details and handle/URL.
You can create your account and sign in with Sign in with Apple or Sign in with Google instead of a password. Either way, the only information we receive from Apple or Google is your name and email address, plus a technical identifier that lets us recognise you next time. With Sign in with Apple you can choose Hide My Email: we then receive a private relay address from Apple that forwards to your real inbox, and we never learn your real address. Apple and Google don't tell us your date of birth, so the first time you sign in this way we ask for it, only to confirm you are 16 or over (see Section 12); if you're under 16 the account is deleted straight away. For Sign in with Apple we also keep a token Apple issues, used for one thing only: telling Apple to end HX's access when you delete your account, as Apple requires. Neither sign-in option is used for advertising or tracking of any kind.
Posts, comments, reactions, messages, group chat and Circle (sub-thread) content, event registrations and attendance, course enrolments and progress, testimonials and requests for them (a request, and its note, can only be seen by you and the person asked), reviews, and any other content you create within a specific Hive or across the Platform. If you post the same thing to several of your Hives at once, each Hive gets its own post, with its own reactions and comments that only that Hive's members see; the photos or video are stored once and shared by those posts. You can only post to Hives you belong to.
Documents, photos, voice notes and video messages you send in chats and Circles; course materials, lesson videos and assignment submissions; digital products you sell; and files shared with event attendees. See Section 8 for who can access them and Section 9 for how long voice notes and video messages are kept.
Transaction history for anything you buy or sell (events, marketplace listings, courses), and payout details needed to pay you if you sell something. We do not directly process or store full payment card details ourselves, all payments are handled by our payment providers (currently PayPal, and card processing partners they use); we store only what's needed to reconcile a transaction, such as a PayPal email address, order status, and amount.
Essential device and session information, such as IP address, browser/device type, timestamps, and error logs, collected strictly to keep the Platform secure, functioning, and able to diagnose problems. We do not use this data to build behavioural advertising profiles, see Section 4.
When anyone opens a public event, course, product, business or Hive invite page, or an event embedded on another website, we count the visit: which page, the kind of device (phone, tablet or desktop), and where the visit came from (for example LinkedIn, a QR code, or the website an event is embedded on). We don't use cookies or store anything on your device for this, and we don't keep your IP address: your IP address and browser are turned into an anonymous code that changes every day, so a visitor can be counted once a day but can't be followed from one day to the next. If you sign in, create an account or register within a day of visiting, we note which public page brought you, so its host can see how many visitors went on to register, enrol, buy, join or sign up. Hosts, Hive admins and platform admins only ever see totals, never who you are.
Event hosts can add forms to their free events: votes, nominations, feedback, registration and applications (such as a call for speakers). When you answer one we keep your answers, the exact wording of the consent box you ticked and when you ticked it, whether you ticked the optional "keep me posted" box, and when you answered or changed your answers. If you don't have an account, answering creates one with the same details as any sign up (name, email, password, date of birth and country); your answers are saved straight away but only count once you confirm your email address. To keep votes fair we also keep a one way code made from your network address for that form only (never the address itself), so the organiser can see when many answers come from one place, and we note when an answer was set aside and why.
A person answering a nomination form may give us details about you: a description, and optionally your name, email address, organisation, phone number and website or social media handle, with their reasons. We keep only what they give, show it only to the form's organisers (judges see your name, organisation, website and the reasons, never your contact details), and use it for one purpose: letting the organiser invite you. Nominees are never listed publicly; anything published about you uses a name the organiser has confirmed. If you are invited, the invitation explains that you were nominated through the organiser's form, and you can decline with one click, which removes your name, contact details and the reasons from the nomination straight away.
Invitations to nominees contain a small image that tells us the first time the email is displayed, so the organiser can see it was opened. This is a hint rather than a certainty: some email apps load images automatically (so an email can show as opened when it wasn't read) and others block them (so an opened email can show as unopened). We record only the time it was first displayed, nothing about your device, and we don't use this kind of tracking in any other email.
This is a deliberate, structural commitment, not just a policy statement:
We do not sell your personal information to third parties. HX is a multi-tenant platform, meaning many independent communities ("Hives") run on the same underlying service, each with its own membership and its own administrators. We share information in the following, limited circumstances:
When you join a Hive, that Hive's owner and administrators can see the same profile and activity information any other member of that Hive can see (your profile, posts, and participation within that Hive), plus membership-management information needed to run the community, such as your join date, role, and any reports filed about you within that Hive. A Hive administrator cannot see your activity in other Hives you belong to, your private messages with people outside a shared group chat, or your account-level data such as your password or full payment details. Hive administrators run their own community day to day using our tools, under our Terms of Service and our instructions; Elevated Experience Ltd remains the Data Controller, and responsible for your data, throughout.
Your public profile (name, photo, headline, biography, skills, experience, location and similar details you add) can be seen by other members, and parts of it appear on public pages such as events you host. Your phone number, date of birth, shipping address, PayPal email address and tax ID are private: other members cannot see them. When you sell something, buyers only see whether you accept PayPal, not your PayPal email address.
There are a few deliberate exceptions, each limited to what that person needs:
A form's organisers (the event's hosts and co-hosts, and the Hive's administrators) see what the form asked and your answers, with your name and email address, so they can use them for the purpose the form states; they never see your date of birth, country or password through a form. If a form is set to "totals only" (it tells you so), organisers see who answered but never what they chose, and their download has counts only. Judges an organiser adds see the entries they are judging but not contact details, and can only download answers if the organiser allows it. Organisers and platform administrators can download a form's answers as a spreadsheet; every download is logged with who made it and when. Other people answering a form never see your individual answers; if the organiser publishes results, they show the winners, finalists or totals the organiser chose, never who voted for whom. Answering a form also adds you to the event's Hive and to our home Hive, and registers you for the event, as registering from the event page does.
Event hosts can place a registration form for their event on their own website. If you sign in or register through one, your details go directly to HX, not to the website showing the form, and that website cannot access your HX account.
We use a small number of infrastructure and service providers to operate the Platform, each of whom processes data on our behalf, under a Data Processing Agreement (DPA) or equivalent contractual safeguard, and only to the extent necessary to provide their service to us:
We may disclose information where required by law, regulation, court order, or other valid legal process, or where necessary to protect the rights, property, or safety of HX, our members, or the public.
Jersey is recognised by both the UK and the European Commission as providing an adequate level of data protection, which permits the free flow of personal data between Jersey, the UK, and the EEA without additional safeguards being required.
Some of our infrastructure and service providers (Section 6) may process or store data in countries outside Jersey, the UK, or the EEA, including the United States. Where a transfer is made to a country that does not benefit from an adequacy decision, we ensure an appropriate safeguard is in place before the transfer occurs, such as Standard Contractual Clauses (SCCs) approved by the European Commission (and the corresponding UK Addendum to those clauses), or an equivalent mechanism recognised under the Data Protection (Jersey) Law 2018. You can request further detail on the safeguards applying to a specific transfer by contacting us, see Section 14.
Where we store data: Your data is stored securely using Supabase, a cloud database platform built on PostgreSQL, hosted on Amazon Web Services (AWS) infrastructure, in secure, SOC 2 compliant data centres.
Authentication: We use Supabase Authentication, which provides industry-standard security including bcrypt password hashing, JWT token-based sessions, and Row Level Security (RLS) policies enforced at the database level.
Row Level Security: Database-level security policies ensure members can only read, create, update, or delete data that belongs to them, or that they've been granted access to through genuine community membership.
Encryption: All data transmitted between your device and our servers is encrypted using TLS/SSL (HTTPS). Data at rest is encrypted using AES-256 encryption.
Private files: Documents, photos and voice notes sent in chats and Circles, course materials and lesson videos, digital products, event files and assignment submissions are stored in private storage. Only the people entitled to them can open them: the participants of that chat (and of any chat a file is forwarded to, which gets its own copy), enrolled students, buyers of the product, eligible event attendees, or the course owner for an assignment. Each file opens through a link that expires after a short time, so a copied link stops working.
Public images and files: Content you publish, such as your profile and cover photos, post images and audio, and business, event and product images, is served from public storage so it can appear on public pages and in link previews. Anyone with the link to one of these files can view it. Only images, audio, PDF and Word documents can be uploaded there.
Videos you upload or record, including video messages in chats, are hosted and streamed by Mux (see Section 6). Video messages in chats and event recordings are private: they can only be played by people in the conversation they were sent in (or forwarded to) or, for a recording, by the event's hosts, speakers and registered attendees. Each viewer is checked and given a short-lived access link, so a copied video link stops working on its own. Other videos, such as Stories, videos in posts and hive welcome videos, can be played by anyone who is given their video link. When a video stops being used, because you delete it, a moderator removes it, it expires, or the hive or event it belongs to is deleted, it is deleted from Mux too, within the hour (a video shared to several places is kept until the last of them goes). A daily check also deletes any video uploaded through the Platform that ends up not being used at all, for example an upload whose post was never saved.
Access control: Only a small number of authorised personnel and platform administrators can access personal data directly, and only where necessary to operate, secure, or support the Platform.
We retain your personal data for as long as your account is active, or as needed to provide you with our services. Certain financial and transaction records may be retained for longer where we are required to do so for tax, accounting, or other legal or regulatory purposes, even after an account is deleted.
Voice notes and video messages sent in chats are kept for 30 days. After that, the audio or video is permanently deleted, including from our video provider, and the message is replaced with a notice that it has been removed. A forwarded voice note is a separate copy, kept for 30 days from when it was forwarded; a forwarded video message is removed when the original is. Stories are removed after 48 hours, with their titles, captions and tags.
Message requests. If you write to someone you don't share a hive with (everyone is in the platform's main hive, so that one doesn't count) and aren't connected to, your first message arrives as a request. They see who it's from and what you wrote, and can accept, decline or block you; you can't send anything more until they accept, and you aren't told if they decline. The notification they get says who wants to message them, not what you wrote. Group chats you start can only include people you could message directly.
Forwarded messages. Anyone in a chat with you can forward a message you sent there, including photos, files, voice notes and video messages, to their other chats on the Platform or to people they're connected with. A forwarded message is sent by the person forwarding it and is marked "Forwarded"; it doesn't name who wrote it originally. Forwarding only ever happens within the Platform, to other members. Photos, files and voice notes are copied to the chat they're forwarded to, so deleting your original doesn't remove copies already forwarded; ask the person to delete theirs, or contact us if you need help. You can block someone to stop them messaging you.
Reports and blocks. When you report a post, comment, Story or message, we keep a record of the report, including a copy of the words reported (so our moderators can review a message in a private chat they can't otherwise read), who wrote it, and your reason if you give one. The person you report isn't told it was you. When you block a member, we record the block and tell our moderators; the person you block isn't told. A block stays until you lift it or one of you deletes your account. Reports, including the copy of the words reported, are kept while our moderators deal with them and for 2 years after, so repeated abuse can be spotted, then deleted automatically. Logs of member and attendee list downloads are also kept for 2 years.
Calendar subscriptions. When you use Add all to calendar on an event with several sessions and pick a calendar, your calendar service (for example Microsoft, Google or Apple) fetches that event's sessions from us through a link made just for you, and keeps checking it for changes. It holds the sessions' titles, times and places and, while you hold a ticket, their join links. Remove the calendar in your calendar app to stop it.
Being tagged in a Story. Members can tag other members of the same hive in a Story, or mention them in its caption. If you're tagged, you're told in the app (and on your phone if you allow notifications), the Story shows your name and appears on your profile while it's up, and you can remove yourself from it at any time from the Story. Only members of that hive can see who is tagged.
Visit counts for public pages are kept for 13 months. The note of which public page brought you is kept for 30 days; the totals it added to stay, but are no longer linked to you once your account is deleted.
Answers to a form, its nominees' details, judges' scores and the consent records are kept for six months after the form closes, then deleted automatically, keeping only anonymous totals (such as how many votes each finalist received). An organiser can archive a form to keep its answers for longer, for example for an awards history; nominees who were never invited and have no contact details are still deleted at six months. You can see everything you have answered under My forms in your account menu, change your answers while a form is open, delete your answers at any time, and stop results emails with one tap. A nominee who declines has their details removed straight away. Deleting your account deletes your answers too.
You can permanently delete your own account at any time from Account Settings, this removes your profile from every Hive directory and community you belong to. Deletion is immediate and automated, your personal data is erased at the moment you confirm, including your posts and Stories in every Hive, and the videos and photos you uploaded (which are also deleted from our video provider); if you used Sign in with Apple, we also tell Apple to end HX's access to your Apple ID. This applies to everything except the limited records described above that we are required to keep for longer. See how to delete your account for step-by-step instructions, including what to do if you can't sign in.
You can get a copy of the personal data we hold about you yourself, at any time: in Account Settings, choose Download my data. We email a link to your account's email address; it downloads a file with a readable summary, your data in a commonly used, machine-readable format you can take to another service, links to your photos and files, and what we do with your data. The link works for 7 days, after which the copy is deleted; you can ask once a day. To protect other people, the copy leaves out who reported you, whether someone blocked you, other members' own lists, the seller's side of your purchases, and security codes. You can also ask by writing to us at the address in Section 14; we reply within four weeks, as required under Section 10. Each request is recorded, with how and when we answered it.
As a Jersey-registered Data Controller, we process your personal data in accordance with the Data Protection (Jersey) Law 2018 and, where applicable, the UK GDPR and EU GDPR. We extend the same rights described here to every HX member globally, regardless of where you live. You have the right to:
To exercise any of these rights, contact us at hx@hx.elevatedexperience.vip. We will respond within four weeks of receiving your request, as Jersey law requires. If a request is complex, or you make several, we may extend this by up to eight more weeks; if so, we will tell you why within the first four weeks. Responding is free. We may ask you to confirm your identity before we act, so that nobody else can obtain your data, and we keep a record of each request and how we handled it.
The Platform uses browser local storage to remember your preferences, such as dark/light mode, your active Hive, view state and your recent searches (kept only on your device, and you can clear them from the search screen), and essential session cookies/tokens for authentication only. We do not use third-party advertising or tracking cookies of any kind. Counting visits to public pages uses no cookies and stores nothing on your device (see Section 3).
The Platform is not intended for use by anyone under the age of 16, and we do not knowingly collect personal information from children under 16. Age is confirmed at sign-up, and if we become aware that we've collected personal information from a child under 16, we will delete it.
Some Hives on HX are run by charities, non-profits, or organisations working with younger people. Where a Hive is intended for members below our platform-wide minimum age of 16, or has its own stricter age or safeguarding requirements, it is the responsibility of that Hive's owner and administrators to implement and enforce those additional protections at the community level, on top of, never instead of, this platform-wide minimum.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date above; for significant changes, we will also notify you in-app or by email before they take effect.
If you have any questions about this Privacy Policy or our data practices, or wish to exercise any of the rights in Section 10, please contact us:
Elevated Experience Ltd
Registered in Jersey, Channel Islands · JFSC Business Registration No. 36688 · JOIC Data Protection Registration No. 19141
Email: hx@hx.elevatedexperience.vip
If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the Jersey Office of the Information Commissioner (JOIC), our lead supervisory authority, at jerseyoic.org. If you are based in the UK or EEA, you may also have the right to complain to your own local data protection authority.