Data & security
Last updated September 2026
A summary for you and your IT, procurement or legal colleagues of how the portal handles your information. Questions are welcome: scott@spitfirecreative.co.uk.
What the portal is
A private website where your team briefs Spitfire Creative Ltd on design work, reviews and approves proofs, and downloads final artwork. It's used only by Spitfire and the clients we invite. There's no public sign-up, no advertising and no selling or sharing of data for marketing.
Who's responsible
Spitfire Creative Ltd (company no. 09069069, registered in England and Wales) runs the portal and is the controller of the account information in it. For any personal data within the material you send us, we act on your instructions, as set out in section 13 of our terms of business. The privacy notice covers your rights in full.
Signing in
- Invite only. Accounts are created by Spitfire for named people at your organisation. Nobody can register themselves.
- No passwords to leak. You sign in with a single-use link emailed to your work address.
- Two-step verification for everyone, including Spitfire staff, using an authenticator app. This is enforced by the database itself, so a session without it can't see or change any jobs, files or messages, whatever the website does.
- Removing access. Tell us when someone leaves and we'll remove their account, which ends their access.
Keeping clients apart
Every request is checked by rules in the database that limit each person to their own organisation's jobs, comments and files. Another client can't see your work, even by guessing a web address. Only Spitfire's studio accounts can see across clients.
Files and encryption
- All traffic uses HTTPS, and browsers are told never to connect without it.
- Data and files are encrypted at rest by our hosting provider.
- Files are stored privately, never at a public address. Each download uses a link made for you that expires after an hour.
- The database is backed up daily, and backups are kept for seven days.
Where your data is held
All data and files are stored in London. We use three service providers, each under a data processing agreement:
| Provider | What it does | Where | What it handles |
|---|---|---|---|
| Supabase | Database, file storage and sign-in | London, UK (Amazon Web Services, eu-west-2) | Accounts, job details, comments, approvals and all uploaded files |
| Netlify | Hosts the portal website | Pages served from a global network; server functions run in the US | Passes requests between your browser and the database; keeps only standard request logs |
| Resend | Sends the portal's emails | Ireland (eu-west-1) | Your name and email address, and the text of each notification |
All three are US-headquartered companies. Where information is processed outside the UK, their agreements include the safeguards UK data protection law requires for international transfers.
What we don't do
- No advertising, analytics or tracking. The only cookies are the ones that keep you signed in, and your light or dark mode choice is saved in your own browser.
- No AI tools read your briefs or files through the portal. Our wider approach to AI is in section 12 of our terms.
- No marketing emails. The portal only emails you about your own jobs.
How long we keep things
- Proofs, final files and uploaded files stay in the portal for six months after a job is completed. We email you a week before they're removed, and we keep an archive copy.
- The job itself, its history and its approval record stay, as the record of what was agreed, for as long as we need them for legal and accounting purposes.
- Accounts are removed on request, or when someone leaves your organisation.
If something goes wrong
If we become aware of a security incident affecting your information, we'll tell you without undue delay, explain what happened and what we're doing about it, and meet our obligations to report to the Information Commissioner's Office where required.
What we ask of you
- Please don't upload personal data we don't need for the work, and particularly patient or other health information, unless we've agreed it in advance.
- Keep the phone with your authenticator app secure, and tell us if it's lost.
- Let us know when colleagues join or leave, so the right people have access.
- Notification emails include job titles and short extracts of messages, so avoid putting anything highly sensitive in a job title.
Questions and documents
If your IT, procurement or legal team needs anything further, such as a completed security questionnaire, our providers' data processing agreements or separate processor terms, email scott@spitfirecreative.co.uk.