Trust & Compliance
Security, privacy, and responsible operations at AAA I Services (UK) Limited.
Overview
Last updated:This hub consolidates our policies, certifications, and operational commitments. For uptime and incident history, see our Service Status & SLA.
Compliance scope
- GDPR & UK GDPR readiness
- Data Processing Addendum (DPA) available
- Standard Contractual Clauses (where applicable)
Security scope
- Vulnerability management & patch cadence
- Encryption in transit & at rest (where supported)
- Incident response & breach notification
Security Overview
Last updated:Read the full policy: /security
- Authentication: 2FA for staff & admin panels; optional 2FA for retailers (recommended).
- Data in transit: TLS 1.2+; HSTS on primary domains.
- Data at rest: Provider-level encryption for databases and storage where supported.
- Vulnerability mgmt: Routine patching; emergency out-of-cycle patches for critical CVEs.
- Incident response: 24/7 monitoring; notify impacted customers per legal obligations.
- Backups & DR: Daily snapshots; integrity tests; documented RTO/RPO in SLA.
Sub-processor List
Last updated:See: /subprocessors
You can subscribe to change notifications from this page.
- Provider name, role, data categories, region, and purpose
- Notification policy and minimum notice period for changes
Acceptable Use Policy
Last updated:- Prohibited activities (abuse, malware, fraud, IP infringement, unlawful content)
- Rate limits, fair usage, and API access
- Enforcement actions and suspension criteria
Governance & Ethics
Last updated:Data Retention & Deletion
Last updated:- Default retention periods per data category
- Deletion timelines and verification
- Customer-initiated deletion process
Accessibility Statement
Last updated:Read: /accessibility
- WCAG 2.1 AA targets and current conformance
- Known limitations and planned fixes
- Accessible contact methods for support
Frequently asked questions
Yes. Review our DPA and contact us if you require countersignature or custom clauses.
We post updates on /subprocessors and provide an email opt-in for change notifications.
Visit Service Status & SLA for historical uptime, scheduled maintenance, and incident reports.
Contact our team
For security disclosures, privacy requests, or compliance queries.