Data Compliance

Last updated: 24 August 2026

We take the security and lawful handling of your data seriously. This page summarises the standards we follow and the safeguards we apply.

1. UK GDPR & Data Protection Act 2018

We process personal data lawfully, fairly, and transparently, in line with UK GDPR and the Data Protection Act 2018. See our Privacy Policy for full details on the personal data we collect and your rights.

2. Payment security (PCI DSS)

Card payments are processed by PCI DSS-compliant third-party providers. We do not store or have access to your full card details on our servers.

3. Encryption

  • All traffic to and from our site is encrypted in transit using TLS 1.2+.
  • Database backups and customer files are encrypted at rest.
  • Passwords are stored using industry-standard one-way hashing.

4. Access controls

Access to customer data is restricted to authorised staff on a least-privilege basis, and protected by role-based access control and audit logging.

5. Data location and sub-processors

Customer data is hosted with trusted cloud providers within the UK/EU where possible. A list of sub-processors is available on request.

6. Data retention & deletion

We retain personal data only as long as necessary for the purposes described in our Privacy Policy, after which it is securely deleted or anonymised.

7. Incident response

In the unlikely event of a personal data breach affecting your rights, we will notify the Information Commissioner's Office (ICO) within 72 hours and affected individuals without undue delay, as required by UK GDPR.

8. Contact our Data Protection lead

For data protection requests or enquiries, email privacy@supremeprinters.co.uk.