Privacy Policy — Totem Systems
Totem Systems

Privacy Policy

Effective date: May 2026  ·  Registered entity: Chaahk Limited

Totem Systems is committed to protecting your personal information. This policy explains what data we collect, why we collect it, and how we handle it — in plain English.

1. Who We Are

Totem Systems is a trading name of Chaahk Limited, a company registered in England and Wales. We provide smart energy management software and hardware for Purpose-Built Student Accommodation (PBSA) operators in the United Kingdom.

Our software connects to our Xero accounting integration ("Totem Operations") and other services to manage quotes, proposals, and billing on behalf of operators we work with.

2. What Data We Collect

We collect personal data in the following contexts:

  • Operators and building managers — name, email address, job title, company name, and phone number, collected when you contact us, use our ROI calculator, or enter our sales process.
  • Residents — email address and display name, collected when you register to use the Totem resident app to control your room's heating.
  • Website visitors — anonymised usage data via analytics (no personally identifiable information is stored from browsing totem.systems).
  • Accounting and billing — company name, billing address, and contact details necessary to create quotes and invoices through Xero.

3. How We Use Your Data

We use the data we collect to:

  • Provide and operate the Totem energy management platform
  • Create and send quotes and proposals to prospective operator clients
  • Process invoices and manage our accounting obligations
  • Send relevant product updates and communications to operators (you can unsubscribe at any time)
  • Respond to enquiries submitted via our website or sales inbox
  • Comply with our legal and regulatory obligations

We do not sell your personal data to third parties. We do not use your data to train AI models.

4. Legal Basis for Processing

We process personal data under the following lawful bases under UK GDPR:

  • Contract — processing necessary to provide our services to operators and residents
  • Legitimate interests — responding to sales enquiries and communicating with prospective clients
  • Legal obligation — maintaining accounting records and complying with UK law
  • Consent — where we ask for your explicit permission (e.g. marketing communications)

5. Data Storage and Security

Your data is stored securely on servers located within the United Kingdom and European Economic Area. We use industry-standard encryption in transit (TLS/SSL) and at rest. Access to personal data is strictly limited to Totem staff who need it to perform their role.

We integrate with the following third-party services, each of which has its own privacy and security standards:

  • Xero — for accounting, quoting, and invoicing (xero.com)
  • HubSpot — for customer relationship management (hubspot.com)
  • Microsoft 365 — for email and document management (microsoft.com)
  • Amazon Web Services — for IoT device management (aws.amazon.com)

In the event of any breach of security or suspected breach involving personal data or system credentials, we will notify affected parties and relevant authorities in accordance with our legal obligations, and where required notify Xero at api@xero.com.

6. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law. Accounting records are retained for a minimum of 6 years in accordance with UK tax law. Resident account data is deleted within 30 days of account closure.

7. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (where no legal obligation to retain it exists)
  • Object to or restrict processing of your data
  • Data portability — receive your data in a structured, machine-readable format
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us using the details below. We will respond within 30 days.

8. Cookies

Our website (totem.systems) uses only essential cookies necessary for the site to function. We do not use tracking or advertising cookies. No cookie consent banner is shown because no non-essential cookies are set.

9. Changes to This Policy

We may update this privacy policy from time to time. When we do, we will update the effective date at the top of this page. We encourage you to review this policy periodically.

Contact us about privacy

Email: trevor@totem.systems

Website: www.totem.systems

Post: Totem Systems (Chaahk Limited), 4 Glasshouse Studios, Fordingbridge, Hampshire, SP6 1QX

Chaahk Limited is registered in England and Wales. Totem Systems is a trading name of Chaahk Limited. This policy applies to all services provided under the Totem Systems brand.