Data policy

How we handle the personal data in your store or website when we work on it. This policy forms part of our terms and conditions. Last updated 29 September 2026.

This policy forms part of our terms and conditions. If you’re a client, it’s the data processing agreement between us.

Our role

Your store holds your customers’ personal data: names, addresses, email addresses, order histories and similar. When we work on your store, you are the controller of that data and SKU Digital Ltd is your processor. We only handle it to carry out the work you’ve asked for, and never for our own purposes.

For the personal data we collect about you as our client, such as your contact and billing details, we are the controller. Our privacy policy covers that.

What we may have access to

To do the work we usually need access to your store’s admin, hosting, database, logs and code. Some of these contain customer personal data. Having access doesn’t mean we look at it: we use only what a task needs.

How we work with your data

  • Our development environment has no customer data. We build every change with your code and configuration, but we don’t import your customer database into it.
  • AI tools see code, not customers. Your code may be processed by our AI provider under business terms that don’t allow it to be used for training. We don’t put your customers’ personal data into AI tools.

Our commitments as your processor

In line with Article 28 of the UK GDPR, we:

  • process personal data only on your documented instructions, which are the work you ask us to do, unless the law requires otherwise (and we’ll tell you if it does)
  • make sure everyone who can access it is bound by confidentiality
  • keep it secure with appropriate technical and organisational measures (see below)
  • use sub-processors only as described below, under written terms that give the same protection
  • help you respond to people exercising their data rights, and with security, breach notification and impact assessments where our work is involved
  • delete or return the data when our work ends, as described below
  • give you the information you need to show that these commitments are met, and allow reasonable audits

Security

We take appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, and against accidental loss, damage or disclosure. Access is limited to the people working on your store, and to what the work needs.

Sub-processors

We use a small number of providers to do the work, such as code hosting, our AI provider and hosting for the development and staging environments we run, and senior developers we work with regularly when they cover leave or larger projects. They work under written terms that give the same protection as this policy.

We’ll tell you before adding or replacing a sub-processor that handles your customers’ personal data, so you can object.

Transfers outside the UK

Some providers, such as GitHub and our AI provider, may process data outside the UK. Where they do, the transfer is protected by the safeguards UK law requires, such as the UK’s adequacy regulations or the International Data Transfer Agreement.

If there’s a breach

If we become aware of a breach affecting personal data in your store, we’ll tell you without undue delay, with what we know. We’ll help you decide whether it needs reporting to the ICO or to your customers, which, as controller, you do within 72 hours where required.

When our work ends

When a plan or project ends, we remove our access to your systems. We don’t keep copies of your store longer than we need them: development and staging environments we run are deleted, unless you ask us to hand them over first or the law requires us to keep something. Your code stays in your repository.

Questions

For anything about how we handle your data, email [email protected].