Skip to main content
Super Save Protocol SSP Registry
Home About Us Services How It Works Leadership
Request access
SSP Registry
Home 01 About Us 02 Services 03 How It Works 04 Leadership 05
Request registry access
hello@supersaveprotocol.com
Mon–Fri, 09:00–18:00 GMT
All legal documents

GDPR Compliance Statement

Last updated · 11 August 2026 Effective · 11 August 2026 Version 1.0
On this page

On this page

  1. Our position in the data chain
  2. The principles, and how we apply them
  3. Data subject rights
  4. Automated decision-making and profiling
  5. International transfers
  6. Personal data breaches
  7. Governance and accountability
  8. Representatives and supervisory authorities

This statement sets out how Super Save Protocol Ltd meets its obligations under Regulation (EU) 2016/679 (EU GDPR), the UK GDPR and the Data Protection Act 2018, and how it applies those standards alongside India's Digital Personal Data Protection Act, 2023.

It supplements the Privacy Policy, which contains the detail of what we collect and why.

01 Our position in the data chain

Super Save Protocol acts in two capacities, and the difference determines who you contact:

CapacityApplies toWho is accountable
ControllerWebsite visitors, enquiries, marketing, individual user accounts, our own security and audit logsSuper Save Protocol Ltd
ProcessorRegistry records submitted by a Member, including any personal data within themThe Member institution as controller; we process on its documented instructions

Where we act as processor, the Data Processing Agreement forms part of the membership agreement and sets out Article 28 terms in full.

02 The principles, and how we apply them

Article 5 principleHow we meet it
Lawfulness, fairness, transparencyEvery purpose has a documented lawful basis, published in the Privacy Policy in a table rather than buried in prose.
Purpose limitationRegistry data is used for duplicate and fraud detection, compliance and audit. It is not repurposed for marketing, credit scoring or profiling.
Data minimisationWe collect the identifiers needed to detect a collision and nothing more. We deliberately do not collect pricing, margin or credit assessments.
AccuracyMembers warrant the accuracy of what they submit. Correction requests are routed to the registering Member and tracked to closure.
Storage limitationRetention periods are published per category in the Data Retention Policy, with a documented justification for the long periods on audit and registry records.
Integrity and confidentialityEncryption in transit and at rest, role-based access with organisation scoping, two-factor authentication, append-only audit logging.
AccountabilityRecords of processing, data protection impact assessments, vendor due diligence, breach procedures and staff training, all reviewed at least annually.

03 Data subject rights

You may request access, rectification, erasure, restriction, portability, or object to processing, and you may withdraw consent where consent is the basis. The full description is in the Privacy Policy.

How to make a request

  1. Email privacy@supersaveprotocol.com with the right you wish to exercise and enough detail to identify your data.
  2. We acknowledge within 5 business days and may ask for proof of identity.
  3. We respond within one month, extendable by two further months for complex requests, and we tell you if we extend and why.
  4. If we cannot act, we explain why and how to complain.

Where a Member is the controller

If your data reached the registry through a bank, factor, customs authority or cheque casher, that institution is the controller. We will forward your request to it within 5 business days, tell you we have done so, and assist it in responding as Article 28(3)(e) requires.

Limits we will assert

We will normally refuse erasure of audit log entries and of registry records within their retention period, relying on Article 17(3)(b) and 17(3)(e) — compliance with a legal obligation, and the establishment, exercise or defence of legal claims. A registry that can be edited by the parties it records is not an anti-fraud control. We tell you when we rely on this and how to challenge it.

04 Automated decision-making and profiling

The registry generates match and fraud scores automatically. We take the position that these are not decisions within Article 22, because:

  • a score is returned to a human officer at a Member institution, who decides;
  • every score is accompanied by the specific signals that produced it, so it can be examined and contested;
  • Members are contractually required to apply human judgement and not to auto-decline on score alone.

Members are responsible for ensuring their own use of Output does not become solely automated decision-making without an Article 22 basis and appropriate safeguards. If you believe a decision affecting you was made solely by automated means, contact dpo@supersaveprotocol.com and we will investigate with the Member concerned.

05 International transfers

Transfers outside the UK or EEA rely on an adequacy decision, the EU Standard Contractual Clauses with the UK International Data Transfer Addendum where applicable, or another lawful mechanism. We complete a transfer risk assessment before relying on contractual safeguards, and apply supplementary measures where it identifies a need. Copies are available on request.

06 Personal data breaches

  • We maintain a documented incident response procedure with defined severity levels and named owners.
  • Where we are controller and a breach is likely to result in a risk to rights and freedoms, we notify the lead supervisory authority within 72 hours of becoming aware.
  • Where the risk is high, we notify affected individuals without undue delay.
  • Where we are processor, we notify the Member controller without undue delay so it can meet its own deadline.
  • All breaches, notifiable or not, are recorded in our internal breach register.

07 Governance and accountability

  • A Data Protection Officer is appointed and reachable at dpo@supersaveprotocol.com.
  • Records of processing activities are maintained under Article 30 for both controller and processor roles.
  • Data protection impact assessments are completed before launching processing likely to result in high risk, including each new registry module.
  • Sub-processors are subject to due diligence and written Article 28 terms, and are listed publicly at Sub-processors.
  • Staff receive data protection training on joining and annually thereafter.
  • Privacy by design and by default is applied at the point of feature design, not retrofitted.

08 Representatives and supervisory authorities

Our EU representative under Article 27 is not yet appointed; in the meantime enquiries are handled by our Data Protection Officer, contactable through dpo@supersaveprotocol.com.

You may complain to the supervisory authority in your country of residence or work, to the Information Commissioner's Office in the United Kingdom, or to the Data Protection Board of India. We would rather you came to us first at privacy@supersaveprotocol.com, but the right is yours either way.

Questions about this document?

Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.

Super Save Protocol SSP Registry

A shared registry for customs authorities, banks, factoring companies and cheque cashers — so the same document can never be financed twice.

Super Save Protocol Ltd
207 Regent Street
London
W1B 3HH
United Kingdom
hello@supersaveprotocol.com

Company

  • Home
  • About Us
  • Services
  • How It Works
  • Leadership
  • Contact Us
  • Sitemap

Registry

  • Customs Registry
  • Bank Finance
  • Collateral Registry
  • Invoice Factoring
  • Cheque Verification

Legal

  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • GDPR Statement
  • Data Processing Agreement
  • Sub-processors
  • Data Retention

Policies

  • Acceptable Use
  • AML / KYC & Sanctions
  • Information Security
  • Responsible Disclosure
  • Service Level Agreement
  • Refund & Cancellation
  • Accessibility
  • All legal documents
© 2026 Super Save Protocol Ltd. All rights reserved. Privacy Terms Cookies Accessibility Registered in England & Wales · 17377995

Cookies on this site

We use strictly necessary cookies to keep the site working and secure. Analytics cookies are only set if you accept them. Read the Cookie Policy.