EXETON SERVICES SCALE. AUTOMATE. GROW.
Corporate Governance

Corporate Privacy & Data Protection Policy

Effective Date: August 7, 2026 | Last Updated: August 7, 2026

1. Overview & General Scope

This Privacy & Data Protection Policy outlines how EXETON SERVICES ("we," "our," or "us") collects, uses, processes, stores, shares, and disposes of Personal Identifiable Information (PII) and corporate data across our operations, websites, client management platforms, and integrated third-party systems.

We are committed to processing all data in compliance with applicable international data protection standards, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and relevant global privacy frameworks.

2. Information We Collect

We collect data from various sources to provide, maintain, and secure our commercial services:

  • Direct Website & Service Data: Name, email address, phone number, corporate details, billing information, and inquiry details submitted via contact forms or service agreements.
  • Automated Technical Data: IP addresses, browser types, device identifiers, cookies, and usage analytics collected when interacting with our online portals.
  • Client & Operational Data: Business operational assets, catalog data, transactional records, and third-party integration data provided by client enterprise accounts.

3. How We Use Information

We process personal and operational data strictly for the following legitimate business purposes:

  • Delivering client account management, technical administration, software integrations, and customer support.
  • Fulfilling statutory tax, legal accounting, and corporate compliance obligations.
  • Securing our digital assets, preventing fraud, and maintaining system integrity.

4. General Security Standards & Safeguards

We implement technical and organizational controls across our entire infrastructure to protect data from unauthorized access, loss, or disclosure:

Encryption Controls

All sensitive data in transit across public networks is encrypted using TLS 1.2 or higher. Data stored at rest in databases or backup storage is encrypted using industry-standard AES-256.

Identity & Access Management

Access to internal systems is granted strictly on the Principle of Least Privilege. Multi-Factor Authentication (MFA) is strictly enforced for all employee and administrative accounts. Hardcoded API keys, shared user accounts, and generic logins are prohibited.

Logging & Audit Protocols

System access logs are maintained and reviewed regularly to monitor security events. Logs are stored securely for a minimum of 12 months. All logs strictly prohibit the exposure or recording of unencrypted PII.

Vulnerability & Incident Management

Software dependencies and server environments are patched regularly. In the event of a suspected security incident, an internal response plan is executed to isolate, remediate, and notify relevant authorities and affected parties as required by law.

Platform Compliance

5. Amazon Information & SP-API Specific Policy

This section applies specifically to data, integrations, and services operated in connection with Amazon Selling Partner API (SP-API) and the Amazon Service Provider Network.

5.1 Scope & Purpose

We access Amazon Information (including restricted order details, inventory statistics, catalog data, and buyer Personally Identifiable Information [PII]) exclusively to provide approved functional services—such as order fulfillment, catalog management, inventory tracking, and tax/invoicing processing—for authorized Selling Partners. Amazon Information is never used for independent marketing, cross-channel buyer profiling, or commercial re-sale.

5.2 Access & PII Handling

Access to Amazon Information is restricted exclusively to authorized personnel who require access to fulfill specific client tasks.

Buyer PII (such as customer names, delivery addresses, and phone numbers) is accessed strictly when necessary to execute order fulfillment or client-requested shipping workflows.

5.3 Retention, Deletion, & Disposal Schedule

  • PII Expiration & Removal: All Amazon Personally Identifiable Information (PII) is securely deleted, permanently purged, or irreversibly anonymized no more than 30 days following successful order fulfillment, or immediately upon client contract termination/seller deauthorization.
  • Sanitization Methods: Data deletion is executed using automated scripts adhering to NIST SP 800-88 guidelines for secure media and database sanitization.
  • Statutory Records: Non-PII transactional summaries required for statutory accounting, audit, or tax compliance are archived in encrypted cold storage and disposed of according to legal retention limits.

5.4 Third-Party Sub-Processors & Data Transfer

Amazon PII is shared strictly with authorized logistics partners (e.g., Royal Mail, Evri, DHL) strictly for physical order delivery. Operational transactional data is integrated into accounting software (e.g., Zoho) without retaining customer PII. We do not sell, license, or transfer Amazon data to any unauthorized third parties or external data brokers.

6. General Third-Party Sharing & Transfers

Outside of specific platform integration constraints (such as Section 5 above), we do not share, sell, or disclose personal data except:

  • With explicit client consent or direction.
  • To trusted third-party service providers (web hosters, cloud infrastructure, banking/payment processors) bound by strict confidentiality and data protection agreements.
  • When required by applicable law, court order, or regulatory body.

7. Data Retention & General Disposal

General business data and client communications are retained only for as long as necessary to fulfill the operational purpose for which they were collected, or to meet statutory, legal, and financial obligations. Once data reaches the end of its retention schedule, it is securely destroyed or permanently anonymized.

8. User Rights & Data Protection Inquiries

Under applicable data protection laws, individuals have the right to request access to, correction of, or deletion of their personal data.

For all data protection inquiries, access requests, or questions regarding this policy, please contact our Data Protection Office:

Company Name: EXETON SERVICES

Email: info@services.exeton-int.com

Phone: 0330 133 3838