Based on the 4 September 2026 documents, with the brand spelling corrected to Printi. Launch domains, contact details and the publication checks remain to be finalised.
Branded Solutions Ltd (company number 17305191), trading as Printi is the controller for the personal data described in this notice. Registered office: Valley View, Clayhidon, Cullompton, England, EX15 3TH. This notice explains what we use, why, who receives it, how long it is retained and your rights. Where a Printi customer enters its own customers’ or staff data into Printi, that customer is normally controller and we act as its processor; requests about that data should usually be directed to that customer.
1. Scope and data sources
This notice covers the Printi website, sales and marketing, account administration, platform users, support, events, security and direct business relationships. We obtain data from you; your employer/account administrator; our customers when they create users; devices and Service activity; integrations you activate; public business sources; suppliers and event/referral partners; and payment providers. We do not receive full payment-card numbers where payment is handled by a compliant payment provider.
2. Data, purposes and lawful bases
| Data / activity | Purpose | UK GDPR lawful basis |
|---|---|---|
| Identity, business contact, role, company and enquiry data | Respond, demonstrate, contract, onboard and manage the relationship | Steps at your/business request; contract; legitimate interests in B2B sales and service |
| Account, authentication, permissions and audit data | Provide accounts, access control and traceability | Contract; legitimate interests in secure service delivery |
| Billing, transaction and subscription data | Charge, account, prevent fraud and meet tax duties | Contract; legal obligation; legitimate interests |
| Support content, calls, remote-session records and feedback | Resolve issues, train support, quality and product improvement | Contract; legitimate interests; consent where specifically required for recording |
| Device, IP, log, diagnostic and security data | Operate, troubleshoot, secure, prevent abuse and investigate incidents | Legitimate interests; legal obligation where applicable |
| Usage and feature analytics | Understand adoption and improve Printi | Legitimate interests for in-product service analytics; consent for non-essential device cookies/technologies where required |
| Marketing preferences and communications | Send relevant B2B updates, events and offers; suppress opt-outs | Consent where PECR requires; otherwise legitimate interests; legal obligation to honour objections |
| Recruitment/vendor/professional contact data | Recruit, procure and manage business relationships | Steps toward contract; contract; legitimate interests; legal obligations |
| Customer Data processed for subscribers | Host and operate workflows on the customer’s instructions | Customer determines lawful basis; we process under Article 28 terms |
3. AI-enabled features
Printi may offer AI-assisted functions such as Bobbin, drafting, classification, search or recommendations. We process prompts, selected context, outputs, account identifiers and safety/diagnostic data to provide and secure the feature. We identify when a feature uses AI and provide controls appropriate to its use. Outputs may be inaccurate and should be reviewed by a person. We do not use identifiable Customer Data to train a general-purpose AI model unless the relevant customer separately and expressly opts in. We do not intend to make solely automated decisions about individuals that produce legal or similarly significant effects; if that changes, we will provide specific information and safeguards before use.
4. Sharing
We disclose personal data only as reasonably necessary to: hosting, infrastructure, security, communications, support, analytics, payment and professional-service providers; integrations activated by the customer/user; affiliated entities supporting Printi; regulators, courts, law enforcement and advisers where required or necessary to establish or defend rights; and a genuine buyer, investor or successor under confidentiality during a corporate transaction. Processors act under contract and may use data only for instructed services. A current material-subprocessor list should be published before launch.
5. International transfers
Where personal data is transferred outside the UK, we use a lawful safeguard: UK adequacy regulations; the ICO International Data Transfer Agreement or UK Addendum to approved standard contractual clauses; or another lawful mechanism. We assess transfer risk and apply supplementary technical/organisational measures where appropriate. Contact us for information about the relevant safeguard.
6. Retention
| Record | Typical retention rule |
|---|---|
| Prospect enquiries and non-customer sales records | Up to 24 months after last meaningful contact, unless you object or a longer period is justified. |
| Account and contract records | Contract term plus 6 years for legal, tax and dispute purposes. |
| Invoices, payment and tax records | Normally 6 years after the relevant financial period, or longer if law requires. |
| Routine support records | Up to 3 years after ticket closure; security, complaint or dispute records may be retained up to 6 years. |
| Security and access logs | Normally 12 months, adjusted where needed for risk, investigation or legal hold. |
| Marketing contact and preference data | While relevant and permitted; suppression records retained as necessary to honour opt-outs. |
| Customer Data as processor | During subscription and the contractual export period, then deleted through the production and backup cycle unless law/legal hold requires retention. |
| Cookie/device identifiers | As stated in the live cookie controls/table; optional identifiers no longer than justified for their purpose. |
Actual periods may be shortened or extended based on volume, sensitivity, security, legal limitation periods, regulator requirements, disputes and backup cycles. We minimise or anonymise data when identifiable retention is no longer needed.
7. Security
We use measures appropriate to risk, including role-based access, authentication controls, encryption in transit, appropriate protection at rest, tenant separation, secure development and change practices, vulnerability management, logging/monitoring, backups, incident response, supplier controls and personnel confidentiality/training. No system can be guaranteed completely secure. Customers control their users, permissions, endpoints and the information they choose to enter.
8. Your rights
- Ask for access to your personal data and specified supplementary information.
- Ask us to correct inaccurate or incomplete data.
- Ask for erasure where the legal conditions apply.
- Ask us to restrict processing in specified circumstances.
- Object to processing based on legitimate interests, and object at any time to direct marketing.
- Receive data you provided in a structured, commonly used, machine-readable format where portability applies.
- Withdraw consent at any time without affecting earlier lawful processing.
- Request safeguards concerning qualifying solely automated decisions, where applicable.
To exercise rights, use the privacy contact published on printii.co.uk or write to the registered office. We may verify identity and authority. We normally respond within one month, subject to lawful extensions or exemptions. There is usually no fee, but manifestly unfounded or excessive requests may be charged or refused as law allows.
9. Complaints
Please contact us first so we can investigate. You may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk or by using its published contact channels. If you live elsewhere, you may have a right to contact your local data-protection authority.
10. Cookies and electronic marketing
Strictly necessary storage/access technologies are used where needed for security, login, load balancing and requested functions. Optional analytics, advertising and similar technologies require a valid choice where PECR applies and are described in the live cookie table. Rejecting optional cookies must be as easy as accepting them and you may change your choice later. Marketing emails to individuals are sent only where consent or the statutory customer “soft opt-in” applies; every message provides an opt-out. Corporate contacts may receive relevant B2B communications where lawful, subject to objection and suppression.
11. Children
Printi is a business service and is not directed to children. Customer-facing stores are operated by Printi customers, who are responsible for age-appropriate notices and lawful handling. Tell us if you believe a child has supplied personal data directly to Printi contrary to this notice.
12. Changes and contact
We may update this notice to reflect legal, technical or operational changes and will show the effective date. We will give prominent notice of material changes where appropriate. Privacy questions and requests may be submitted through the privacy contact published on printii.co.uk or by post to the registered office above.
Publication and verification schedule+
| Confirm before publication | Why required |
|---|---|
| Monitored privacy email and, if appointed, DPO/representative details | Transparent and usable rights channel. |
| Complete production subprocessor/integration list, countries and transfer mechanisms | Articles 13/14 and processor transparency. |
| Actual hosting regions, backup cycle and security-control wording | Avoid making inaccurate promises. |
| Final retention settings for logs, support, deleted tenants, backups and AI records | Retention statements must match engineering reality. |
| Production cookie scan, consent configuration and live cookie table | PECR compliance depends on actual technologies. |
| ICO registration/fee position and record of processing activities | Operational compliance beyond publication. |
| AI vendors, prompt retention, training defaults and human-review design | Required for accurate AI transparency and customer contracting. |