HENOC Limited · Company registration 11414478
Security & Data Protection
Last updated: 15 August 2026
HENOC Limited handles commercial energy data on behalf of UK businesses — enquiry details, energy bills, meter numbers, consumption data and Letters of Authority. We treat that information as confidential business data and protect it with enterprise-grade controls.
This page sets out, in plain English, how our systems are built and how your data is kept safe.
Infrastructure and hosting
Our website and client tools run on managed cloud infrastructure operated by our platform provider, rather than on self-managed office servers. That means patching, network hardening, physical data-centre security and infrastructure monitoring are handled continuously by a specialist provider whose platform is used by enterprise and regulated organisations.
- Data centres located within established, security-audited cloud regions.
- Infrastructure and dependency updates applied on an ongoing basis.
- Automated database backups with point-in-time recovery.
- Independent verification of the platform's security posture is published by our provider at our platform Trust Centre.
Encryption
- In transit: every page, form and file upload on henoc.co.uk is served over HTTPS using TLS. Plain HTTP requests are redirected to the secure endpoint.
- At rest: databases and uploaded documents are stored encrypted on managed cloud storage.
Access control
- Access to client data is limited to HENOC personnel who need it to broker your energy contracts.
- Database access is governed by row-level security policies — records are not readable by unauthenticated visitors.
- Administrative accounts are individually named, password-protected and protected by multi-factor authentication.
- Access is revoked immediately when someone leaves the business or changes role.
What we do not hold
- We do not take card payments and we do not store card or bank details on this website.
- We do not sell, rent or trade your data with third parties.
- We do not run offshore call centres — your data stays with the senior broker handling your account.
Data protection and UK GDPR
HENOC Limited (company registration 11414478) is the data controller for the information you provide. We process it lawfully under UK GDPR and the Data Protection Act 2018, retain it only for as long as needed to provide brokerage services and meet our legal obligations, and support your rights of access, correction, erasure and objection. Full detail is in our Privacy Policy.
Documents you upload
Bills and contracts submitted through our audit tools are used solely to prepare your analysis and to approach suppliers on your instruction. They are stored encrypted, are not shared beyond the suppliers you authorise us to approach, and can be deleted on request.
Business continuity
Because our systems are cloud-hosted and backed up automatically, a single office, device or location failure does not interrupt service or put client data at risk. Contract and renewal records are recoverable from backup.
Reporting a security concern
If you believe you have found a vulnerability, or you have a question about how your data is handled, email info@henoc.co.uk or call 020 8050 0158. We aim to acknowledge security reports within one working day. Please do not publicly disclose an issue before we have had a chance to respond.
Certifications
The security certifications and independent audit reports covering the platform our systems run on are published by our provider at the platform Trust Centre. Those certifications belong to the platform provider and cover the hosting environment; they are not certifications held by HENOC Limited. Any certification held by HENOC in its own name will be listed here once awarded.
