Security & Data Retention

Zuletzt aktualisiert 2026-07-24

A plain-language summary of how we protect data and how long we keep it. It complements the Privacy Notice and the DPA.

Security measures

• encryption of data in transit (HTTPS/TLS); • per-tenant isolation of customer data enforced at the database level (row-level security); • role-based access controls and least-privilege access for staff; • hardened cloud infrastructure and restricted database credentials; • monitoring and logging for security and troubleshooting.

Backups and recovery

Customer data is backed up on a regular schedule to allow recovery from failure. The backup frequency, retention window and recovery objectives applicable to your plan are set out in your subscription; we do not rely on a blanket "no liability for data loss" position.

Retention periods

• Enquiry / access-request data — kept while we follow up and for a reasonable period afterwards, then deleted. • Customer account and content — kept for the subscription term; on termination, deleted or returned per the DPA. • Accounting and tax records — kept for the statutory periods required by UK law (HMRC), then deleted or anonymised. • Server/security logs — kept for a limited period for security and troubleshooting.

Export and deletion

Customers can export their data during the subscription and request deletion or return on termination. For requests, contact info@samjake.uk.