This policy explains how Super Save Protocol Ltd ("Super Save Protocol", "we", "us") handles personal data when you use our website, when your institution uses the SSP registry, and when you contact us. It applies to everyone whose personal data we hold, wherever they are located.
Super Save Protocol operates an inter-institutional registry. Most of what the registry holds is transaction data about shipments, invoices, collateral and cheques rather than personal data — but some of it identifies people, and that is what this policy covers.
01 Who is responsible for your data
Super Save Protocol Ltd, registered at 207 Regent Street, London, W1B 3HH, United Kingdom, is the controller of personal data described in this policy, except where we act as a processor on behalf of a member institution.
The distinction matters:
- We are the controller for website visitor data, enquiry and marketing data, and the account data of individual users we provision.
- We are a processor for the registry records a member institution submits — including any personal data inside them, such as the name of an exporter's authorised signatory. The member institution is the controller of that data and decides why it is processed.
Questions about either role go to privacy@supersaveprotocol.com. Our Data Protection Officer can be reached at dpo@supersaveprotocol.com.
02 What we collect
Information you give us
- Enquiry data — name, work email, telephone number, institution, institution type, enquiry type and the content of your message.
- Account data — for users of the registry: name, work email, role, organisation, telephone number, and authentication credentials stored as a one-way hash.
- Correspondence — emails, support tickets and call notes.
Information created by your use of the service
- Authentication events — sign-in attempts, two-factor verification, password changes, session start and end.
- Audit records — the actions you take in the registry, with your user identifier, organisation, timestamp and IP address. These are retained as an integrity control and cannot be edited.
- Technical data — IP address, browser and operating system, referring page, and pages viewed.
Registry content submitted by members
Records about shipments, invoices, collateral and cheques. These are primarily commercial rather than personal, but may include the names of individuals acting for a business — for example a sole trader named as an exporter, or the drawer of a cheque.
What we do not collect
We do not ask for or want special category data (health, biometrics, race, religion, political opinion, trade union membership, sexual orientation), and we do not build behavioural profiles of individuals for advertising.
03 Why we process it, and our lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Responding to your enquiry | Enquiry data, correspondence | Legitimate interests — replying to someone who contacted us; consent where you ticked the box |
| Providing the registry to your institution | Account data, registry content | Performance of the contract with your institution; legitimate interests |
| Detecting duplicate and fraudulent financing | Registry content, audit records | Legitimate interests of members and the wider financial system in preventing fraud; substantial public interest where applicable |
| Securing accounts and the platform | Authentication events, technical data | Legitimate interests; legal obligation |
| Maintaining an audit trail | Audit records | Legal obligation; legitimate interests in accountability |
| Meeting AML, sanctions and regulatory duties | Account data, institutional due diligence | Legal obligation |
| Improving the service | Aggregated and technical data | Legitimate interests |
| Optional analytics cookies | Technical data | Consent |
Where we rely on legitimate interests we have assessed that our interest does not override your rights. You may ask for a summary of that assessment at privacy@supersaveprotocol.com.
05 International transfers
Super Save Protocol serves institutions in several jurisdictions, so data may be processed outside the country where it was collected. Where personal data leaves the UK or European Economic Area, we rely on one of:
- an adequacy decision covering the destination country;
- the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies; or
- another lawful transfer mechanism recognised at the time of transfer.
We carry out a transfer risk assessment before relying on contractual safeguards and apply supplementary technical measures — encryption in transit and at rest, and access controls scoped to organisation — where the assessment calls for them. A copy of the safeguards for a specific transfer is available on request.
06 How long we keep it
| Category | Retention |
|---|---|
| Enquiry and correspondence data | 24 months from last contact |
| Account data for active users | Duration of the account, then 12 months |
| Authentication and session logs | 12 months |
| Registry records | 7 years from registration, or as the member's instructions and law require |
| Audit log entries | 7 years, append-only |
| Fraud alerts and dispositions | 7 years |
| AML, KYB and sanctions records | 5 years from the end of the member relationship, or longer where required |
| Billing and tax records | 8 years |
| Cookie consent records | 12 months |
Registry and audit records are deliberately long-lived: duplicate financing is often only discovered years after the fact, and a registry that forgets is not a registry. Full detail is in the Data Retention Policy.
07 Your rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase data, where we no longer have a lawful reason to keep it.
- Restrict processing while a dispute about accuracy or legitimate interests is resolved.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Portability — receive data you gave us in a structured, machine-readable format.
- Withdraw consent where consent is the basis, without affecting processing before withdrawal.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
An important limit
Erasure and objection rights are not absolute. We will normally decline to erase audit log entries or registry records within their retention period, because keeping them is necessary for compliance with a legal obligation and for the establishment, exercise or defence of legal claims. Where we decline, we tell you why and how to challenge it.
Automated processing
The registry produces match and fraud scores automatically. Those scores are decision support, not decisions: a human officer at the member institution decides whether to lend, factor or pay. Every score is returned with the reasons behind it so it can be examined and contested. If you believe a score has been applied to you as an automated decision, contact us and we will investigate.
How to exercise a right
Write to privacy@supersaveprotocol.com. We respond within one month and may extend by two further months for complex requests, telling you if we do. We may ask for proof of identity. There is no fee unless a request is manifestly unfounded or excessive.
If your data reached the registry through a member institution, that institution is the controller and we will pass your request to it and support its response.
08 Security
We apply controls proportionate to the sensitivity of what the registry holds:
- Encryption of data in transit (TLS) and at rest.
- Passwords stored using a modern one-way hashing algorithm, never in plain text.
- Two-factor authentication, enforced password rotation and lockout after repeated failed sign-in attempts.
- Role-based access control with organisation scoping and least-privilege defaults.
- Append-only audit logging of every registry action.
- Session idle timeouts and cross-site request forgery protection.
- Regular patching, backups and restore testing.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights, we notify the relevant supervisory authority within 72 hours and tell affected people without undue delay where the risk is high. Details are in the Information Security Policy.
09 Children
The SSP registry is an institutional service. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to privacy@supersaveprotocol.com and we will delete it.
11 Complaints
Please raise a concern with us first at privacy@supersaveprotocol.com — most issues are resolved quickly.
You also have the right to complain to a supervisory authority:
- India — the Data Protection Board of India, under the Digital Personal Data Protection Act, 2023.
- European Economic Area — the data protection authority in your country of residence or work. Our EU representative is not yet appointed; in the meantime enquiries are handled by our Data Protection Officer.
- United Kingdom — the Information Commissioner's Office.
12 Changes to this policy
We update this policy when our practices or the law change. The version date is shown at the top of the page. Where a change materially affects your rights we tell members directly and give at least 30 days' notice before it takes effect. Continuing to use the service after that date means the updated policy applies.
Questions about this document?
Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.