What's included
Encryption
All data encrypted at rest and in transit with bank-level security.
Row-Level Security
Your data is completely isolated. No business can see another's data.
Authentication
Secure email/password authentication with password strength requirements.
Audit Trail
Key actions logged for accountability and compliance.
GDPR Friendly
Designed with UK data protection regulations in mind.
Regular Updates
Security patches and updates applied automatically.
Security & Privacy — your questions
Where is my data stored?
Data is stored in UK/EU data centres with enterprise-grade security.
Can other businesses see my data?
No. Row-level security means your data is completely isolated from every other business.
Is ServicePay GDPR compliant?
Yes. ServicePay is designed with UK data protection regulations in mind.
Who can see my business's data?
Only people you have added, and then only what their role allows. Access is enforced in the database rather than by hiding menus, so a screen someone should not see returns nothing rather than relying on the page to hide it.
How long do customer portal links last?
Portal links now expire — eighteen months for invoices and jobs, twelve for quotes and proposals, six for review requests — with a nightly sweep. Enforcement is not yet applied on every path and that work is open and tracked, which we would rather state than imply.
What happens to a customer's data if they ask you to delete it?
Deletion is handled on request today rather than by a self-service button, and erasure does not yet propagate everywhere it should. That is a known gap on our launch register, not a solved problem.