Data Security Policy
How we collect, store, and protect your data
(A) Alkaline Solutions Limited trading as popcorn CRM.
(B) popcorn is a provider of CRM and marketing services, in particular, the provision of sales, marketing tools, management information, storage and support.
To fulfil our contractual obligations and in the legitimate interest of the day to day running of its business, Popcorn needs to collect, store, and process data, especially personal data for our users and our employees. We take the protection of this data very seriously because we understand the importance of this information to you.
As with information online, popcorn cannot guarantee 100% safety for the information. However, as a data processor working to best practice, we have safeguards in place to ensure that any personal data, as defined by UK GDPR, that you give to us is protected.
- One of the ways we protect your data is at the point of collection — our website is hosted on a leading, secure host site. Our software and databases are also separate from our website, giving your personal data another level of protection if our website is ever compromised.
- Your account password is stored in encrypted form using the hash method.
- Before we begin processing, we carry out a Data Protection Impact Assessment to identify where risks to your data are present and implement the necessary steps to mitigate these risks.
- Information risk assessments are carried out regularly, allowing us to implement appropriate organisational and technical security measures to protect the data we hold and can access.
- All information we collect is stored in password-protected, UK-based cloud storage, so it cannot be accidentally accessed by anyone.
- All data processed by our software is kept in separate databases so that no one can see data that isn’t relevant to their work. This separation also means we have no access to our users’ contact data without their explicit authorisation.
- International transfers: where personal data is transferred outside the UK, we only do so using a lawful transfer mechanism — for example, UK adequacy regulations, an International Data Transfer Agreement (IDTA), or the UK Extension to the Data Privacy Framework. We assess each transfer to ensure it meets the UK’s current data protection standards.
- To fulfil our contractual obligation to you, your personal data and your contacts’ data may need to be shared with developers and email managers who have links to third countries. To protect data, we ensure that these companies are UK GDPR compliant, and any future company we work with will be required to meet UK GDPR standards before any information is shared.
- Although we see purchase and order information, your credit card and payment details are not visible to us — only the information necessary to process payment is held securely by Stripe.
- Data is held for as long as set out in your service agreement with us. After this period, we review the data to determine whether it remains necessary for processing and, if not, securely delete or anonymise it.
- Database security is consistently reviewed, and updates are implemented as needed to maintain the safety of your personal data.
- If there is a breach to our database that poses a likely risk to you and your fundamental rights, we will inform the Information Commissioner’s Office (ICO) without undue delay. If it is determined that the breach poses a high risk to you and your rights, we will get in touch with you directly, also without undue delay.
- If a breach occurs, we will make any relevant upgrades to the security of the database.
- We have a Data Protection Officer responsible for making sure our data protection policy is adhered to, and for assisting with staff training to help keep your data secure.
- For information on your rights over your personal data — including access, correction, deletion, and portability — please see our Privacy Policy or contact our Data Protection Officer using the details below.
- If you have any questions about how your data is kept and protected, you can contact our Data Protection Officer, Simon Washbrook, by email at data@popcornmail.co.uk
- This policy is maintained in line with current UK data protection law, including the Data (Use and Access) Act 2025.
Release Date: 25th May, 2018 Last Reviewed: 10th August, 2026