Skip to main content
Super Save Protocol SSP Registry
Home About Us Services How It Works Leadership
Request access
SSP Registry
Home 01 About Us 02 Services 03 How It Works 04 Leadership 05
Request registry access
hello@supersaveprotocol.com
Mon–Fri, 09:00–18:00 GMT
All legal documents

Data Processing Agreement

Last updated · 11 August 2026 Effective · 11 August 2026 Version 1.0
On this page

On this page

  1. Subject matter, duration, nature and purpose
  2. Processor obligations
  3. Controller obligations
  4. The registry carve-out
  5. Sub-processors
  6. International transfers
  7. Security measures (Annex A)
  8. Breach notification
  9. Audit
  10. Liability and term

This Data Processing Agreement ("DPA") forms part of the membership agreement between Super Save Protocol Ltd ("Processor") and the Member institution ("Controller"). It applies where the Processor processes personal data on the Controller's behalf and is intended to satisfy Article 28 of the UK and EU GDPR.

A countersigned copy is available on request from legal@supersaveprotocol.com.

01 Subject matter, duration, nature and purpose

ItemDetail
Subject matterProvision of the SSP anti-duplicate finance registry
DurationThe term of the membership agreement, plus the retention periods that survive it
Nature and purposeCollection, storage, normalisation, hashing, matching, scoring, disclosure to other Members, alerting, audit logging, reporting and deletion
Types of personal dataBusiness contact details of authorised users; names and identifiers of individuals appearing in commercial documents (for example a sole trader exporter, a cheque drawer, an authorised signatory); technical and audit data
Categories of data subjectController's employees and authorised users; the Controller's customers and their counterparties, where they are individuals or sole traders
Special category dataNone. The Controller must not submit special category or criminal offence data

02 Processor obligations

The Processor will:

  1. process personal data only on the Controller's documented instructions, including on transfers, unless required by law — in which case it informs the Controller first unless the law forbids it;
  2. ensure personnel authorised to process are bound by confidentiality;
  3. implement the technical and organisational measures set out in Annex A;
  4. respect the conditions on sub-processors set out below;
  5. assist the Controller, by appropriate technical and organisational measures and insofar as possible, in responding to data subject rights requests;
  6. assist the Controller with security, breach notification, impact assessments and prior consultation under Articles 32 to 36;
  7. at the Controller's election, delete or return personal data at the end of the service, subject to the retention carve-out below;
  8. make available information necessary to demonstrate compliance and allow for audits as described below;
  9. immediately inform the Controller if, in its opinion, an instruction infringes data protection law.

03 Controller obligations

The Controller warrants that:

  • it has a lawful basis for the processing it instructs, including for the disclosure of registry records to other Members;
  • it has given the required transparency information to its data subjects, including that records may be checked against and disclosed to a shared industry registry;
  • the personal data it submits is accurate and lawfully obtained;
  • it will not submit special category data, criminal offence data, or data of children;
  • its instructions comply with applicable data protection law.

04 The registry carve-out

The Controller acknowledges and instructs that, notwithstanding any deletion request:

  • registry records already submitted and the fingerprints derived from them are retained for their stated retention period, because other Members have relied and will rely on them to detect duplicate financing;
  • audit log entries are append-only and are retained for their stated retention period as an integrity and compliance control.

This is a condition of membership and is disclosed before any record is submitted. It reflects Article 17(3)(b) and (e), and the legitimate interests of the Member community in the integrity of a shared fraud-prevention record.

05 Sub-processors

The Controller gives general written authorisation for the Processor to engage sub-processors. The current list is published at Sub-processors.

The Processor will give at least 30 days' notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the affected service without penalty for the unused portion of any prepaid fees.

The Processor imposes on each sub-processor obligations no less protective than this DPA, and remains fully liable for its sub-processors' performance.

06 International transfers

Where processing involves a transfer of personal data outside the UK or EEA, the parties rely on an adequacy decision or enter into the European Commission's Standard Contractual Clauses (Module Two, controller to processor), together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this DPA by reference and prevail in the event of conflict.

07 Security measures (Annex A)

  • Encryption — TLS 1.2 or above in transit; encryption at rest for databases and backups.
  • Access control — role-based access with twelve defined institutional roles, organisation scoping, least-privilege defaults, quarterly access reviews.
  • Authentication — two-factor authentication, password hashing with a modern algorithm, enforced rotation, lockout after repeated failures, idle session timeout.
  • Logging — append-only audit log capturing actor, organisation, action, timestamp and IP for every registry action.
  • Application security — CSRF protection, parameterised queries, output encoding, security headers, dependency patching.
  • Resilience — regular backups with tested restores, documented recovery objectives.
  • Personnel — background checks proportionate to role, confidentiality undertakings, annual security and data protection training.
  • Vendor management — due diligence and written terms before any sub-processor handles personal data.

08 Breach notification

The Processor notifies the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Controller's data. The notification includes, so far as known: the nature of the breach, categories and approximate numbers affected, likely consequences, measures taken or proposed, and a contact point. The Processor provides further information as the investigation progresses.

09 Audit

The Processor makes available to the Controller its current security documentation and, where available, third-party assurance reports. Where those do not reasonably satisfy the Controller, the Controller may audit once in any 12-month period on 30 days' written notice, during business hours, subject to confidentiality, at its own cost, and without accessing other Members' data. A regulator with jurisdiction may audit at any time as the law requires.

10 Liability and term

Liability under this DPA is subject to the limitations in the membership agreement and the Terms and Conditions, except to the extent those limitations are prohibited by data protection law.

This DPA takes effect on the effective date of the membership agreement and continues until the Processor has ceased all processing, including at the end of the surviving retention periods.

Questions about this document?

Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.

Super Save Protocol SSP Registry

A shared registry for customs authorities, banks, factoring companies and cheque cashers — so the same document can never be financed twice.

Super Save Protocol Ltd
207 Regent Street
London
W1B 3HH
United Kingdom
hello@supersaveprotocol.com

Company

  • Home
  • About Us
  • Services
  • How It Works
  • Leadership
  • Contact Us
  • Sitemap

Registry

  • Customs Registry
  • Bank Finance
  • Collateral Registry
  • Invoice Factoring
  • Cheque Verification

Legal

  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • GDPR Statement
  • Data Processing Agreement
  • Sub-processors
  • Data Retention

Policies

  • Acceptable Use
  • AML / KYC & Sanctions
  • Information Security
  • Responsible Disclosure
  • Service Level Agreement
  • Refund & Cancellation
  • Accessibility
  • All legal documents
© 2026 Super Save Protocol Ltd. All rights reserved. Privacy Terms Cookies Accessibility Registered in England & Wales · 17377995

Cookies on this site

We use strictly necessary cookies to keep the site working and secure. Analytics cookies are only set if you accept them. Read the Cookie Policy.