4.1 Where we store your personal data
The data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Area ("EEA"). It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers. Such staff may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support services.
4.2 Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
Security Measures
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication
- Staff training on data protection
- Incident response procedures
4.3 Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for. Indicative retention periods:
- Account data: Until account closure + 5 years for legal/accounting obligations
- Transaction/payment records: 10 years (legal requirement)
- Support tickets & communications: 3 years from resolution
- Technical logs (IP, sessions): Up to 12 months
After these periods, data is securely deleted or anonymised.
4.4 Withdrawal of Consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. To withdraw consent, contact us or use the relevant opt-out options in your account settings.