Data Protection Policy
How we handle personal data, and what we expect of everyone who handles it on our behalf. Last updated 6 September 2026.
| Legal entity | Switch&Save Business Services Ltd (company number 15051352) |
|---|---|
| Trading style | Zivaro |
| Registered office | 3A Perry Common Road, Erdington, Birmingham, B23 7AB |
| Privacy contact | hello@zivaro.co.uk |
| Applies from | 6 September 2026 |
| Review cycle | At least annually |
Policy statement. Switch&Save Business Services Ltd will process personal data lawfully, fairly, transparently and securely, and will be able to demonstrate compliance with the UK GDPR and the Data Protection Act 2018.
1. Purpose and scope
This policy sets the minimum rules for every director, employee, worker, contractor and supplier who handles personal data on our behalf. It covers personal data in any format, and every system, device, paper record, call, email, website and supplier platform used to run Zivaro and the wider business.
2. Governance and responsibilities
The directors have ultimate responsibility for data protection. The policy owner coordinates day-to-day compliance, records, rights requests, incidents, supplier checks and training. Managers must embed this policy in their teams. Everyone covered by it must protect personal data, follow authorised processes, and report concerns immediately rather than waiting to be asked.
Privacy contact: hello@zivaro.co.uk.
3. Data protection principles
- Lawfulness, fairness and transparency — identify and record a lawful basis, and explain processing plainly.
- Purpose limitation — collect data for specified purposes and assess compatibility before any new use.
- Data minimisation — collect only what is adequate, relevant and necessary.
- Accuracy — take reasonable steps to keep data correct and current.
- Storage limitation — keep identifiable data no longer than necessary.
- Integrity and confidentiality — apply security proportionate to the risk.
- Accountability — keep evidence that these principles are being followed.
4. What we process, and why
Our principal activities involving personal data are: receiving and responding to business enquiries; arranging and running EPOS and card machine demonstrations; quoting, supplying, installing and supporting EPOS systems, card machines and hardware; reviewing merchant statements where a business asks us to; taking and fulfilling orders; managing supplier and partner relationships; handling complaints; and ordinary corporate functions such as accounts and employment.
The detail of what we collect from customers and website visitors, and the lawful bases we rely on, is set out in our Privacy Policy.
5. Lawful bases and records
The owner of each processing activity must record its purpose, the categories of data and people involved, recipients, retention period, security measures and lawful basis in our Record of Processing Activities. The bases we typically rely on are: steps taken at your request before entering a contract, performance of a contract, compliance with a legal obligation, and legitimate interests.
6. Special category and criminal offence data
Our services are not designed to collect special category or criminal offence data. Staff must not request or record it unless it is genuinely necessary, authorised by the policy owner, and supported by an appropriate condition in law.
7. Commercially sensitive business documents
Where a business sends us a merchant statement or similar document so that we can review what they are paying, we treat it as confidential and use it only to produce that comparison and quote. We ask you to redact bank account numbers, sort codes and card numbers before sending, because we do not need them. We do not pass such documents outside the company without asking you first, and we delete them once the review is complete and the retention period has passed.
8. Direct marketing
All outbound email, text and telephone marketing must comply with the UK GDPR and the Privacy and Electronic Communications Regulations. Consent, where it is the basis we rely on, must be freely given, specific and recorded, and every marketing message must offer a straightforward way to opt out. Opt-outs are actioned promptly and permanently.
9. Security
We apply technical and organisational measures proportionate to the risk, including access control on a need-to-know basis, encryption of data in transit, secure storage of documents away from publicly accessible locations, supplier due diligence, and staff training. Access to customer records is limited to those who need it to do their job.
10. Suppliers and processors
Where a supplier processes personal data on our behalf, we carry out proportionate due diligence and put a written contract in place containing the terms required by Article 28 of the UK GDPR. Suppliers must not engage a sub-processor without our authorisation.
11. International transfers
Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place, such as UK adequacy regulations or the International Data Transfer Agreement or Addendum.
12. Your rights
You have the right to be informed, and to request access, rectification, erasure, restriction, portability, and to object to processing, including to direct marketing. You also have rights in relation to automated decision-making. To exercise any of these, email hello@zivaro.co.uk. We will respond within one month, and will tell you if we need to extend that period or ask you for identification first.
13. Personal data breaches
Anyone who becomes aware of an actual or suspected personal data breach must report it internally immediately. We assess every report, and where a breach is likely to result in a risk to people's rights and freedoms we notify the Information Commissioner's Office without undue delay and within 72 hours of becoming aware. Where the risk is high, we also tell the people affected.
14. Retention
We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires. Enquiry and quotation records, order and accounting records, and support records each have their own retention period, and data is securely deleted or anonymised at the end of it.
15. Training and compliance
Everyone covered by this policy receives data protection training appropriate to their role. Failure to follow this policy may be dealt with under our disciplinary procedures, and, for contractors and suppliers, under the terms of their contract.
16. Complaints and the regulator
If you are unhappy with how we have handled your personal data, please tell us first using our Complaints Policy so that we can put it right. You also have the right to complain to the Information Commissioner's Office at any time, at ico.org.uk or on 0303 123 1113.
17. Review
This policy is reviewed at least annually, and sooner if our processing, our suppliers or the law changes materially.