Privacy Policy

Last updated: 6 October 2026

1. Who We Are

Domson Ltd ("we", "us", "our") is the data controller responsible for your personal data. We are a company registered in England and Wales under company number 06460707 with our registered office at 19 Wellington Road, London E17 6LS, United Kingdom, and our trading address at 1-10 Gordon Road, Waltham Abbey, EN9 1AF. Our VAT registration number is GB924015849.

If you have any questions about this Privacy Policy or our data practices, please contact us at:

  • Email: office@domson.co.uk
  • Phone: (+44) 02085 589 400
  • Post: Data Protection, Domson Ltd, 1-10 Gordon Road, Waltham Abbey, EN9 1AF

2. What Data We Collect

We collect and process the following categories of personal data:

CategoryExamples
IdentityFirst name, last name, job title
ContactEmail address, phone number, business address
CompanyCompany name, registration number, VAT number, billing address
AccountUsername, password (hashed), account preferences
TransactionOrder history, invoices, payment details, delivery information
TechnicalIP address, browser type, operating system, pages visited

We do not collect any special category data (such as racial or ethnic origin, political opinions, religious beliefs, trade union membership, health data, or biometric data).

3. How We Collect Your Data

We collect personal data through:

  • Direct interactions: When you register an account, place an order, request a quote, or contact us.
  • Automated technologies: When you browse our website, we collect technical data through cookies and similar technologies (see our Cookie Policy).
  • Third parties: Our sales representatives may provide your details when setting up your B2B account, or we may receive data from our SAP Business One system.

4. How We Use Your Data and Our Lawful Basis

Under the UK General Data Protection Regulation (UK GDPR), we must have a lawful basis for processing your personal data. The bases we rely on are:

PurposeLawful Basis
Processing and fulfilling your ordersPerformance of a contract (Art. 6(1)(b))
Managing your B2B account and company profilePerformance of a contract (Art. 6(1)(b))
Sending order confirmations and invoicesPerformance of a contract (Art. 6(1)(b))
Providing customer support and responding to enquiriesLegitimate interest (Art. 6(1)(f))
Website analytics and performance improvementConsent (Art. 6(1)(a))
Compliance with legal obligations (e.g. tax, accounting)Legal obligation (Art. 6(1)(c))
Fraud prevention and securityLegitimate interest (Art. 6(1)(f))

5. Who We Share Your Data With

We may share your personal data with the following categories of recipients:

  • Group companies: Domson Midlands Ltd and Domson Poland Sp. z o.o., for order fulfilment and logistics.
  • Payment processors: Stripe, to process your payments securely.
  • Delivery operations: Our own transport fleet and group companies, who carry out order delivery. Where we occasionally engage external logistics providers, your data is shared only as necessary to fulfil your order.
  • IT service providers: Hosting, analytics and software providers who support our platform.
  • Professional advisers: Accountants, lawyers and auditors where necessary.
  • HMRC and regulators: Where required by law.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes — we only permit them to process your personal data for specified purposes and in accordance with our instructions.

6. International Transfers

Some of our service providers and group companies are based outside the United Kingdom. Whenever we transfer your personal data outside the UK, we ensure a similar degree of protection is afforded to it by relying on one of the following safeguards:

  • Countries that the UK Government has deemed to provide an adequate level of protection (adequacy regulations).
  • Standard contractual clauses approved by the UK Information Commissioner's Office (ICO).

7. Data Retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting, or reporting requirements.

  • Account data: Retained for the duration of your account and up to 12 months after closure.
  • Transaction data: Retained for 7 years to comply with HMRC requirements.
  • Technical/analytics data: Retained for up to 26 months.

8. Your Rights

Under the UK GDPR, you have the following rights in relation to your personal data:

  • Right of access — You can request a copy of the personal data we hold about you.
  • Right to rectification — You can ask us to correct any inaccurate or incomplete data.
  • Right to erasure — You can ask us to delete your personal data in certain circumstances.
  • Right to restrict processing — You can ask us to suspend the processing of your personal data.
  • Right to data portability — You can request a machine-readable copy of your data.
  • Right to object — You can object to processing based on legitimate interests.
  • Right to withdraw consent — Where we rely on consent, you can withdraw it at any time.

To exercise any of these rights, please email us at office@domson.co.uk. We will respond within one month. You will not have to pay a fee unless your request is clearly unfounded, repetitive or excessive.

9. Cookies

Our website uses cookies and similar technologies. For full details about the cookies we use, the purposes for which we use them, and how you can manage your preferences, please see our Cookie Policy.

10. Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. These include:

  • Encryption of data in transit (HTTPS/TLS).
  • Secure, hashed password storage — we never store passwords in plain text.
  • HTTP-only, secure cookies with strict same-site policies.
  • Access controls limiting who within our organisation can view your data.

We have procedures to deal with any suspected personal data breach and will notify you and the ICO where we are legally required to do so.

11. Complaints

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us first.

12. Domson Customs (HMRC Customs Declarations Software)

Domson Ltd also develops and operates "Domson Customs", an internal software application used only by authorised employees and contractors of Domson Ltd and of its Polish group company, Domson Poland Sp. z o.o., to prepare and lodge customs declarations for goods moving between Poland and Great Britain. It is not offered to customers of this Platform or to any other business. This section is published because HM Revenue & Customs (HMRC) requires software that connects to its APIs to have a published privacy policy. It does not change how we handle your data as a Platform customer (sections 1 to 11).

Domson Ltd (company number 06460707, registered office 19 Wellington Road, London E17 6LS, United Kingdom) is the controller of the personal data processed in the application in connection with UK customs formalities. Domson Poland Sp. z o.o. (ul. kpt. Tadeusza Doranta 37, 05-170 Zakroczym, Poland) is the controller for the Polish export formalities handled in the application under an intra-group arrangement.

12.1 Who uses the application

Only authorised employees and contractors of Domson Ltd and Domson Poland Sp. z o.o. can use the application. Access requires a client certificate issued by Domson Ltd, a login to the Domson staff portal and an explicit permission for the application on the user's account. There are no external users and no customer accounts.

12.2 What data the application processes

CategoryExamplesWhose data
Customs declaration dataNames, addresses and EORI numbers of consignors, consignees, declarants and carriers; invoice and transport document numbers; description, classification, quantity, weight, origin and value of goods; vehicle and trailer registration numbers; declaration references (LRN, MRN, GMR); references of veterinary and sanitary certificates (CHED, EHC)Mostly companies. Personal data only where a party is a sole trader or where a document names a contact person. Driver names are not stored.
HMRC authorisation tokensOAuth 2.0 access and refresh tokens issued by HMRC after Domson Ltd's Government Gateway office user grants the application access. The application never sees or stores Government Gateway user IDs or passwords.Domson Ltd's organisation account
Staff account and audit dataPortal user identifier, role (administrator or user), assigned desk; an audit log of settings changes and of every declaration released, with the user identifier and timeEmployees of Domson Ltd and Domson Poland Sp. z o.o.
Messages exchanged with authoritiesDeclarations sent to and notifications received from HMRC (Customs Declaration Service, Safety and Security GB, Goods Vehicle Movement Service), the Polish customs system (PUESC/AES), the French customs envelope system (ELO) and the UK import notification system (IPAFFS), with their technical identifiers (conversation IDs, timestamps)As in the first row
Technical logsServer and application logs: time, request path, internal IP address, outcome, error codes. Logs do not contain tokens, secrets or declaration contents.Staff using the application
Data sent to HMRC in request headersHMRC's fraud-prevention header set: connection method, time zone, the portal user identifier of the person who triggered the request, the public IP address of the application server and, where known, of the user's browser, and the software versionStaff using the application

12.3 Why we process it and on what legal basis

  • Lodging customs, safety-and-security and goods-movement declarations with HMRC and with the Polish and French customs authorities, and keeping the records the law requires: compliance with a legal obligation (UK GDPR and GDPR, Art. 6(1)(c)).
  • Operating, securing and auditing the application, including access control, the audit log, technical logs and HMRC's fraud-prevention headers: our legitimate interests in running a reliable and secure system and in meeting HMRC's terms of use (Art. 6(1)(f)).
  • Managing staff access: performance of the employment or service contract and our legitimate interests (Art. 6(1)(b) and (f)).

We do not use this data for marketing, profiling or automated decisions about individuals, and we do not sell or share it for marketing. The data comes from Domson Ltd's and Domson Poland's own business systems (the ERP system and the transport system), from the documents issued for the shipment (invoices, transport documents, veterinary certificates), from the authorities' responses to our declarations, and from the staff who prepare and release declarations.

12.4 Who receives the data

  • HM Revenue & Customs (Customs Declaration Service, Safety and Security GB, Goods Vehicle Movement Service, Pull Notifications) and, through the existing import notification process, the Animal and Plant Health Agency (IPAFFS): as required by law to import the goods.
  • The Polish customs administration (PUESC, AES) and the French customs administration (DGDDI, ELO envelopes) for the export and transit side of the same movements.
  • Our hosting provider, OVH SAS (European Union), which stores the server and the encrypted backups on our behalf and has no access to the data in clear text.
  • Where a customs agent or a freight carrier is involved in a movement, the documents needed for that movement.

No other processors are used. The application runs on a single server operated by Domson Ltd and hosted by OVH SAS in the European Union; encrypted backups are kept in OVH object storage in Warsaw, Poland. HMRC's systems are in the United Kingdom. We do not transfer this data outside the United Kingdom and the European Union; data flows between the two are covered by the UK adequacy regulations for the EEA and the EU adequacy decision for the United Kingdom.

12.5 How we protect it

  • Every connection to the application uses HTTPS with mutual TLS: the user's browser must present a client certificate issued by Domson Ltd before any page is served. Connections to HMRC use TLS.
  • HMRC authorisation tokens are stored only in encrypted form; the encryption key is kept outside the database in a configuration file readable only by the service account. Client secrets live in that file only.
  • Role-based access: only administrators can change settings or connect and disconnect the HMRC authorisation; desk users see only their own desk. Every setting change and every released declaration is written to an audit log.
  • Secrets never appear in logs, tickets or the source code repository; automated checks enforce this. The deferment account number is masked in the user interface.
  • Backups are encrypted on the server before they leave it.
  • A written security-incident procedure applies: containment, notification to HMRC through the Developer Hub within 72 hours, notification to the Information Commissioner's Office within 72 hours where personal data is affected, an incident register and a post-incident review.

12.6 How long we keep it

DataRetention
Declarations, messages exchanged with the authorities, evidence of export and import10 years from the end of the year of the declaration (covers the UK customs record-keeping period of 4 years, the UK VAT period of 6 years and the Polish tax period of 5 years)
HMRC authorisation tokensUntil the authorisation is withdrawn or the refresh token expires (18 months from the Government Gateway sign-in); deleted immediately on disconnection
Audit log10 years, with the records it relates to
Technical logsService journal: 2 weeks; web server access logs: 14 days
Staff account dataFor as long as the person is authorised to use the application

12.7 Your rights and reporting a security concern

If you are an individual whose data is processed in the application (for example an employee, a sole trader trading with Domson, or a named contact person), you have the rights described in section 8. Data that the law obliges us to keep cannot be erased before the retention period ends. You may complain to the Information Commissioner's Office (section 11) or, for the processing carried out by Domson Poland Sp. z o.o., to the President of the Personal Data Protection Office in Poland (uodo.gov.pl).

Anyone, including people outside Domson, can report a security risk or incident concerning the application by e-mail to office@domson.co.uk with the subject "Security", or by telephone to (+44) 02085 589 400. Reports reach the person responsible for the software at Domson Ltd, who runs the incident procedure described above.

Domson Customs is software developed and operated by Domson Ltd for its own use. It is not provided, endorsed, approved or recognised by HM Revenue & Customs. Its terms of use are in section 13 of our Terms & Conditions.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.