How we look after data in the systems we run
Every J-Mach customer's system holds personal data about that customer's own customers, staff and contacts. This page sets out how J-Mach handles it as the customer's processor. The binding version is the data processing terms in each customer's licence.
Last updated 14 September 2026.
Roles
For data in a customer's system, the customer is the controller and J-Mach is the processor, in the sense of Article 4 of the UK GDPR. J-Mach processes that data only to build, host, support and maintain the system, and only on the customer's documented instructions, as Article 28 requires. J-Mach does not use customer data for its own purposes, does not combine data from different customers, and does not sell or share it.
Where data is held
- Database and API: Render, in the region agreed in the customer's licence.
- Web applications and websites: Vercel.
- Documents the system generates or receives: the customer's own Microsoft 365 (OneDrive or SharePoint), under the customer's control.
- Email the system sends: through the customer's own mail service where configured, otherwise through J-Mach's.
Where a provider processes data outside the UK, the transfer relies on the safeguards in Chapter V of the UK GDPR, applying the data protection test set by the Data (Use and Access) Act 2025.
Sub-processors
J-Mach uses these providers to run customer systems. Each is bound by its own data protection terms. Customers are told before a new sub-processor of J-Mach's own is added, and may object.
- Render (hosting of API and PostgreSQL databases)
- Vercel (hosting of web applications and websites)
- Neon (PostgreSQL for serverless deployments, where used)
- Microsoft (Microsoft 365, where the customer's own tenancy is used for filing and email)
- GoDaddy (J-Mach's own email)
Integrations a customer connects to their own accounts, such as Xero, courier services or Mailchimp, are the customer's own processors and are governed by the customer's agreements with them.
Security
The measures below are what Article 32 of the UK GDPR calls "appropriate technical and organisational measures", applied to every system J-Mach runs.
- Every connection is encrypted in transit; databases are encrypted at rest by the hosting provider.
- Per-user logins with hashed passwords and role-based access. Customer portals can only ever see the records of the customer they belong to.
- Secrets and credentials are held in the hosting providers' environment settings, never in source code.
- Access to production systems is limited to J-Mach's founder, who is bound to confidentiality. There are no offshore teams and no shared accounts.
- Dependencies and platforms are kept up to date as part of the monthly service.
Backups and recovery
Databases are backed up daily with point-in-time recovery, and backups are held for the period stated in the customer's licence. Documents filed to the customer's Microsoft 365 are covered by the customer's own retention.
If something goes wrong
If J-Mach becomes aware of a personal data breach affecting a customer's data it tells that customer without undue delay, as Article 33(2) requires of a processor: what is known, what has been done and what the customer may need to do, with updates as the picture becomes clearer. That gives the customer what it needs to decide, as controller, whether the breach must be reported to the regulator within 72 hours and whether individuals must be told.
Requests and complaints from individuals
Requests to see, correct or delete personal data held in a customer's system, and complaints about it, go to that customer as the controller. J-Mach helps the customer answer them within the time the law allows, and does not act on such requests directly unless the customer asks it to.
When the arrangement ends
The customer's data is returned as CSV files plus the original documents, within the period stated in the licence, and then deleted from J-Mach's systems, including backups once they expire. The customer's domain is transferred back to the customer.
Questions
Customers with questions about any of this, or who need the detail for their own records or a supplier questionnaire, can email info@jmach.co.uk.
The law this page follows
Checked 14 September 2026. Each link goes to the official text on legislation.gov.uk.
- UK GDPR — Regulation (EU) 2016/679 as it forms part of UK law, amended by the Data (Use and Access) Act 2025.
- Data Protection Act 2018 — As amended by the Data (Use and Access) Act 2025.
- Data (Use and Access) Act 2025 — Royal Assent 19 June 2025; data protection provisions in force from 5 February 2026 and 19 June 2026; Information Commissioner replaced by the Information Commission from 30 September 2026.
See also: Privacy notice · Cookies · Modern slavery · Website terms