Security & Data Retention
Last updated 2026-07-24
A plain-language summary of how we protect data and how long we keep it. It complements the Privacy Notice and the DPA.
Security measures
• encryption of data in transit (HTTPS/TLS); • per-tenant isolation of customer data enforced at the database level (row-level security); • role-based access controls and least-privilege access for staff; • hardened cloud infrastructure and restricted database credentials; • monitoring and logging for security and troubleshooting.
Backups and recovery
Customer data is backed up on a regular schedule to allow recovery from failure. The backup frequency, retention window and recovery objectives applicable to your plan are set out in your subscription; we do not rely on a blanket "no liability for data loss" position.
Retention periods
• Enquiry / access-request data — kept while we follow up and for a reasonable period afterwards, then deleted. • Customer account and content — kept for the subscription term; on termination, deleted or returned per the DPA. • Accounting and tax records — kept for the statutory periods required by UK law (HMRC), then deleted or anonymised. • Server/security logs — kept for a limited period for security and troubleshooting.
Export and deletion
Customers can export their data during the subscription and request deletion or return on termination. For requests, contact info@samjake.uk.