Skip to main content
Super Save Protocol SSP Registry
Home About Us Services How It Works Leadership
Request access
SSP Registry
Home 01 About Us 02 Services 03 How It Works 04 Leadership 05
Request registry access
hello@supersaveprotocol.com
Mon–Fri, 09:00–18:00 GMT
All legal documents

Privacy Policy

Last updated · 11 August 2026 Effective · 11 August 2026 Version 1.0
On this page

On this page

  1. Who is responsible for your data
  2. What we collect
  3. Why we process it, and our lawful basis
  4. Who we share it with
  5. International transfers
  6. How long we keep it
  7. Your rights
  8. Security
  9. Children
  10. Cookies
  11. Complaints
  12. Changes to this policy

This policy explains how Super Save Protocol Ltd ("Super Save Protocol", "we", "us") handles personal data when you use our website, when your institution uses the SSP registry, and when you contact us. It applies to everyone whose personal data we hold, wherever they are located.

Super Save Protocol operates an inter-institutional registry. Most of what the registry holds is transaction data about shipments, invoices, collateral and cheques rather than personal data — but some of it identifies people, and that is what this policy covers.

01 Who is responsible for your data

Super Save Protocol Ltd, registered at 207 Regent Street, London, W1B 3HH, United Kingdom, is the controller of personal data described in this policy, except where we act as a processor on behalf of a member institution.

The distinction matters:

  • We are the controller for website visitor data, enquiry and marketing data, and the account data of individual users we provision.
  • We are a processor for the registry records a member institution submits — including any personal data inside them, such as the name of an exporter's authorised signatory. The member institution is the controller of that data and decides why it is processed.

Questions about either role go to privacy@supersaveprotocol.com. Our Data Protection Officer can be reached at dpo@supersaveprotocol.com.

02 What we collect

Information you give us

  • Enquiry data — name, work email, telephone number, institution, institution type, enquiry type and the content of your message.
  • Account data — for users of the registry: name, work email, role, organisation, telephone number, and authentication credentials stored as a one-way hash.
  • Correspondence — emails, support tickets and call notes.

Information created by your use of the service

  • Authentication events — sign-in attempts, two-factor verification, password changes, session start and end.
  • Audit records — the actions you take in the registry, with your user identifier, organisation, timestamp and IP address. These are retained as an integrity control and cannot be edited.
  • Technical data — IP address, browser and operating system, referring page, and pages viewed.

Registry content submitted by members

Records about shipments, invoices, collateral and cheques. These are primarily commercial rather than personal, but may include the names of individuals acting for a business — for example a sole trader named as an exporter, or the drawer of a cheque.

What we do not collect

We do not ask for or want special category data (health, biometrics, race, religion, political opinion, trade union membership, sexual orientation), and we do not build behavioural profiles of individuals for advertising.

03 Why we process it, and our lawful basis

PurposeData usedLawful basis
Responding to your enquiryEnquiry data, correspondenceLegitimate interests — replying to someone who contacted us; consent where you ticked the box
Providing the registry to your institutionAccount data, registry contentPerformance of the contract with your institution; legitimate interests
Detecting duplicate and fraudulent financingRegistry content, audit recordsLegitimate interests of members and the wider financial system in preventing fraud; substantial public interest where applicable
Securing accounts and the platformAuthentication events, technical dataLegitimate interests; legal obligation
Maintaining an audit trailAudit recordsLegal obligation; legitimate interests in accountability
Meeting AML, sanctions and regulatory dutiesAccount data, institutional due diligenceLegal obligation
Improving the serviceAggregated and technical dataLegitimate interests
Optional analytics cookiesTechnical dataConsent

Where we rely on legitimate interests we have assessed that our interest does not override your rights. You may ask for a summary of that assessment at privacy@supersaveprotocol.com.

04 Who we share it with

We do not sell personal data. We never have and the business model does not depend on it.

  • Member institutions. A registry search returns the identifiers needed to establish a collision and the identity of the member holding the earlier record. It does not return that member's pricing, credit assessment or customer relationship data.
  • Service providers. Hosting, email delivery, error monitoring and similar suppliers, each bound by a written contract that limits them to acting on our instructions. The current list is published at Sub-processors.
  • Professional advisers. Auditors, lawyers and insurers, under confidentiality.
  • Authorities. Regulators, law enforcement and courts where we are legally required to disclose, or where disclosure is necessary to establish or defend legal claims. We review every request and challenge those that are overbroad.
  • A successor entity. If the business is sold or reorganised, subject to the same protections.

05 International transfers

Super Save Protocol serves institutions in several jurisdictions, so data may be processed outside the country where it was collected. Where personal data leaves the UK or European Economic Area, we rely on one of:

  • an adequacy decision covering the destination country;
  • the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies; or
  • another lawful transfer mechanism recognised at the time of transfer.

We carry out a transfer risk assessment before relying on contractual safeguards and apply supplementary technical measures — encryption in transit and at rest, and access controls scoped to organisation — where the assessment calls for them. A copy of the safeguards for a specific transfer is available on request.

06 How long we keep it

CategoryRetention
Enquiry and correspondence data24 months from last contact
Account data for active usersDuration of the account, then 12 months
Authentication and session logs12 months
Registry records7 years from registration, or as the member's instructions and law require
Audit log entries7 years, append-only
Fraud alerts and dispositions7 years
AML, KYB and sanctions records5 years from the end of the member relationship, or longer where required
Billing and tax records8 years
Cookie consent records12 months

Registry and audit records are deliberately long-lived: duplicate financing is often only discovered years after the fact, and a registry that forgets is not a registry. Full detail is in the Data Retention Policy.

07 Your rights

Depending on where you live, you may have the right to:

  • Access a copy of the personal data we hold about you.
  • Rectify data that is inaccurate or incomplete.
  • Erase data, where we no longer have a lawful reason to keep it.
  • Restrict processing while a dispute about accuracy or legitimate interests is resolved.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Portability — receive data you gave us in a structured, machine-readable format.
  • Withdraw consent where consent is the basis, without affecting processing before withdrawal.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

An important limit

Erasure and objection rights are not absolute. We will normally decline to erase audit log entries or registry records within their retention period, because keeping them is necessary for compliance with a legal obligation and for the establishment, exercise or defence of legal claims. Where we decline, we tell you why and how to challenge it.

Automated processing

The registry produces match and fraud scores automatically. Those scores are decision support, not decisions: a human officer at the member institution decides whether to lend, factor or pay. Every score is returned with the reasons behind it so it can be examined and contested. If you believe a score has been applied to you as an automated decision, contact us and we will investigate.

How to exercise a right

Write to privacy@supersaveprotocol.com. We respond within one month and may extend by two further months for complex requests, telling you if we do. We may ask for proof of identity. There is no fee unless a request is manifestly unfounded or excessive.

If your data reached the registry through a member institution, that institution is the controller and we will pass your request to it and support its response.

08 Security

We apply controls proportionate to the sensitivity of what the registry holds:

  • Encryption of data in transit (TLS) and at rest.
  • Passwords stored using a modern one-way hashing algorithm, never in plain text.
  • Two-factor authentication, enforced password rotation and lockout after repeated failed sign-in attempts.
  • Role-based access control with organisation scoping and least-privilege defaults.
  • Append-only audit logging of every registry action.
  • Session idle timeouts and cross-site request forgery protection.
  • Regular patching, backups and restore testing.

No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights, we notify the relevant supervisory authority within 72 hours and tell affected people without undue delay where the risk is high. Details are in the Information Security Policy.

09 Children

The SSP registry is an institutional service. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to privacy@supersaveprotocol.com and we will delete it.

10 Cookies

We use strictly necessary cookies to keep the site and the registry working and secure. Analytics cookies are only set if you accept them. You can change your choice at any time — see the Cookie Policy.

11 Complaints

Please raise a concern with us first at privacy@supersaveprotocol.com — most issues are resolved quickly.

You also have the right to complain to a supervisory authority:

  • India — the Data Protection Board of India, under the Digital Personal Data Protection Act, 2023.
  • European Economic Area — the data protection authority in your country of residence or work. Our EU representative is not yet appointed; in the meantime enquiries are handled by our Data Protection Officer.
  • United Kingdom — the Information Commissioner's Office.

12 Changes to this policy

We update this policy when our practices or the law change. The version date is shown at the top of the page. Where a change materially affects your rights we tell members directly and give at least 30 days' notice before it takes effect. Continuing to use the service after that date means the updated policy applies.

Questions about this document?

Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.

Super Save Protocol SSP Registry

A shared registry for customs authorities, banks, factoring companies and cheque cashers — so the same document can never be financed twice.

Super Save Protocol Ltd
207 Regent Street
London
W1B 3HH
United Kingdom
hello@supersaveprotocol.com

Company

  • Home
  • About Us
  • Services
  • How It Works
  • Leadership
  • Contact Us
  • Sitemap

Registry

  • Customs Registry
  • Bank Finance
  • Collateral Registry
  • Invoice Factoring
  • Cheque Verification

Legal

  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • GDPR Statement
  • Data Processing Agreement
  • Sub-processors
  • Data Retention

Policies

  • Acceptable Use
  • AML / KYC & Sanctions
  • Information Security
  • Responsible Disclosure
  • Service Level Agreement
  • Refund & Cancellation
  • Accessibility
  • All legal documents
© 2026 Super Save Protocol Ltd. All rights reserved. Privacy Terms Cookies Accessibility Registered in England & Wales · 17377995

Cookies on this site

We use strictly necessary cookies to keep the site working and secure. Analytics cookies are only set if you accept them. Read the Cookie Policy.