Privacy
How we handle personal data, including yours.
We ask other organisations to account for the personal data they hold. It would be poor form not to account for ours. This notice says what we collect, why, how long we keep it and what you can ask us to do about it.
Who we are
Data Safe Solutions Ltd, 2nd Floor, Port of Liverpool Building, Mann Island, Liverpool L3 1BY, United Kingdom. Registered in England and Wales, company number 12245066. We are the controller for the personal data described in this notice.
For anything in this notice, write to [email protected] or use our contact form.
Last updated 8 September 2026.
What we collect and why
| What | Why | Lawful basis | Kept for |
|---|---|---|---|
| Name, organisation, email, phone and anything you write, when you use the contact form or email us | To answer you and, if it goes further, to run the commercial relationship | Legitimate interests, and performance of a contract once there is one | Two years from our last exchange, unless you become a customer |
| Contact and account details of customer staff who operate the Platform | To provide the service, issue certificates and support the account | Legitimate interests: delivery, administration and security of the customer account. Performance of a contract only where the individual is personally the contracting party. | Seven years after the account ends, for audit and limitation periods |
| Server logs, including IP address, browser and pages requested | Security, fault diagnosis and keeping the site up | Legitimate interests | Twelve months |
| Aggregate, non-identifying page statistics if analytics are enabled | To see which pages are useful | Consent, through the cookie banner | Fourteen months |
We do not buy contact lists, we do not sell or rent personal data to anybody, and we do not use your data to train machine learning models.
Data on the devices we erase
This is the part most people actually want to know. When the Smart Wipe Engine processes a storage device, it does not read, copy, extract, index or transmit the content of that device to us. The engine writes a known pattern to selected sectors, executes the destruction command, reads those sectors back and records the result.
What leaves the device is a record: the device identifiers, the method selected, the verification result, timings and a checksum. Not the contents of the device. Where we act as a processor on a customer’s behalf, we do so under that customer’s written instructions and the terms of the licence.
Who we share it with
Only where it is needed to run the business, and never for anybody else’s marketing:
- Our hosting and email providers, which process data on our instructions under written terms
- Our professional advisers, insurers and auditors where they need it
- A regulator, court or law enforcement body where we are legally required to
Where a provider processes data outside the UK, we rely on UK adequacy regulations or the International Data Transfer Addendum. We will tell you which if you ask.
Your rights
Under the UK GDPR you can ask us for a copy of the personal data we hold about you, ask us to correct it or delete it, ask us to restrict or stop a particular use, object to processing based on legitimate interests, and ask for your data in a portable format. Where we rely on consent you can withdraw it at any time, and withdrawing it does not affect anything done before you did.
Ask at [email protected]. We answer within one month. There is no charge unless a request is manifestly unfounded or excessive, and we will say so before doing anything.
If you are not satisfied with how we have handled it, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first so we can put it right.
Changes
If we change this notice we will change the date at the top. Where a change materially affects how we use data we already hold, we will tell affected people directly rather than relying on you noticing.