Security & Trust
Our commitment
At Salespuzzle, we take the security, privacy, and integrity of your data seriously. Our platform is designed to protect your information using industry-standard safeguards and best practices aligned with the UK General Data Protection Regulation.
Data Security
We implement technical and organisational measures to protect your data, including:
-
Access Controls
Role-based access ensures users only see what they are authorised to access. -
Authentication & Account Protection
Secure login systems and account-level controls help prevent unauthorised access. -
Encryption
Data is encrypted in transit using HTTPS/TLS. Sensitive data is protected where appropriate. -
Infrastructure Security
Our systems are hosted on secure, industry-standard infrastructure providers. -
Monitoring & Logging
We monitor system activity and maintain logs to detect and respond to suspicious behaviour.
Data Privacy
We are committed to protecting personal data in line with the Data Protection Act 2018.
-
We act as a data processor for Customer Data
-
Customers remain the data controller
-
We only process data based on customer instructions
We do not sell personal data.
GDPR & Data Rights
Salespuzzle includes features to support compliance with data protection laws:
-
Data export and portability tools
-
Data deletion and retention controls
-
Audit visibility for account activity
-
Support for handling data subject requests (DSARs)
Customers are responsible for determining the lawful basis for processing their data.
Access & Permissions
Customers have full control over:
-
User roles and permissions
-
Account access management
-
Third-party integrations
Company Administrators can:
-
Add or remove users
-
Restrict access
-
Manage data visibility
Sub-processors & Third Parties
We may use trusted third-party providers for:
-
Hosting and infrastructure
-
Payment processing
-
Analytics and performance monitoring
All providers are:
-
Carefully selected
-
Contractually bound to data protection obligations
A current list of sub-processors is available upon request.
Data Transfers
Where data is transferred outside the UK, we ensure appropriate safeguards are in place, such as:
-
UK International Data Transfer Agreements (IDTAs)
-
Transfers to jurisdictions with adequacy decisions
Incident Response
We maintain procedures to detect and respond to security incidents.
In the event of a personal data breach, we will:
-
Notify affected customers without undue delay
-
Provide relevant information to support regulatory compliance
Data Retention
-
Customer Data is retained for the duration of the account
-
After termination, data is deleted in accordance with our Terms
-
Backup data may be retained securely for a limited period
Transparency & Accountability
We are committed to transparency in how we handle data:
-
Privacy Policy available publicly
-
Data Processing Agreement available to customers
-
Support provided for compliance-related enquiries
Contact
If you have questions about security or data protection, contact:
​
You also have the right to contact the Information Commissioner's Office (ICO) if you have concerns about how data is handled.
