Privacy Policy

ICO Registration: ZB401452
Last Updated: 01/09/2026

1. Introduction

MACE Systems Limited ("MACE", "we", "us", or "our") is committed to protecting and respecting your privacy.

This Privacy Policy explains how MACE handles personal data in connection with its website, software, products, services and technical support activities.

MACE supplies software to businesses and other customers which can be installed and operated on the customer's own servers, computers, networks or other infrastructure.

The MACE software performs processing functions on the customer's own infrastructure. The data processed by the customer's installation of the MACE software normally remains on the customer's infrastructure unless the customer chooses to transmit data to a third-party service.

MACE does not normally receive, access, host, store or control such data as part of the normal operation of the software.

However, where a customer requests or authorises MACE to provide technical support, maintenance, troubleshooting, installation, configuration, development or other services, MACE personnel may be given access to the customer's servers, computers, networks, databases or other systems. As a consequence of providing such services, MACE personnel may be able to view, access or otherwise encounter data stored on those systems, including personal data.

Where MACE personnel are authorised to access customer systems, MACE will use such access only for legitimate business purposes connected with providing the requested services and will seek to limit access to information reasonably necessary for those purposes.

There is an important distinction between:

MACE Customer Data

Personal data that is provided directly to MACE and which MACE determines the purposes and means of processing.

MACE is responsible for MACE Customer Data.

Merchant Data

Personal data belonging to a MACE customer (merchant) or that customer's customers which is held and processed on the customer's own servers or other infrastructure using MACE software.

The customer (merchant) is responsible for merchant data and for determining the purposes and means of processing it, except to the extent that MACE processes personal data in connection with authorised support or other services provided to the customer.

MACE does not acquire ownership or general control of merchant data merely because MACE software is installed on the customer's infrastructure or because MACE personnel are authorised to access the customer's systems for support.

To the fullest extent permitted by law, MACE is not responsible or liable for the customer's collection, processing, storage, security, retention, disclosure or use of merchant data, except to the extent that such responsibility or liability cannot lawfully be excluded or arises from MACE's own acts or omissions.

2. Information We Collect

MACE may collect and process MACE Customer Data that is provided directly to us.

This may include:

  • Name.
  • Email address.
  • Telephone number.
  • Postal address.
  • Business details.
  • Contact information.
  • Information provided when purchasing MACE products or services.
  • Information provided when requesting technical support.
  • Records of correspondence with MACE.
  • Website usage information.
  • IP addresses and technical information where applicable.

MACE may also encounter or access information held on a merchant's systems when providing authorised technical support, maintenance, troubleshooting, installation, configuration, development or other services.

Such access may include access to databases, files, records, customer accounts, transaction information, application data or other information stored on the customer's systems.

MACE will not normally access such information unless access is reasonably necessary for the services being provided or the customer has otherwise authorised that access.

MACE is responsible for MACE Customer Data that it collects and controls.

MACE does not collect merchant data merely because a merchant installs or uses MACE software.

Where the MACE software processes personal data on the merchant's own infrastructure, that data remains primarily the responsibility of the merchant.

3. MACE Customer Data

MACE is responsible for personal data that MACE itself collects, receives and controls in connection with its own business activities.

MACE will process such data in accordance with applicable data protection legislation and this Privacy Policy.

MACE will take appropriate technical and organisational measures to protect MACE Customer Data against unauthorised access, loss, misuse or disclosure.

We will not sell your personal information to third parties. However, we may, with your express permission, share your data with trusted partners and service providers who help us deliver our services (e.g. hosting providers, payment processors) under strict confidentiality agreements.

Nothing in this Privacy Policy removes MACE's responsibility for personal data that MACE itself collects and controls.

4. Merchant Data

MACE provides software which allows its merchants to perform processing functions on their own infrastructure.

Where MACE software is installed and operated on a merchant’s own server, computer, network or other infrastructure:

  • The merchant controls the data entered into the software.
  • The merchant determines what personal data is collected.
  • The merchant determines the purposes for which the data is processed.
  • The merchant determines how the data is used.
  • The merchant determines how long the data is retained.
  • The merchant determines which third parties receive the data.
  • The merchant is responsible for establishing the lawful basis for processing.
  • The merchant is responsible for the security of its infrastructure.
  • The merchant is responsible for backups and data retention.
  • The merchant is responsible for compliance with applicable data protection legislation.

The MACE software performs processing functions locally on the merchant's infrastructure.

MACE does not receive, access, host, store or control merchant data during normal operation of the MACE software.

However, where the merchant authorises MACE personnel to access the merchant's systems for technical support, maintenance, troubleshooting, installation, configuration, development or other services, MACE personnel may be able to access or view merchant data stored on those systems.

MACE will seek to limit such access to what is reasonably necessary to provide the relevant services.

MACE personnel and contractors who are authorised to access merchant systems are required to maintain the confidentiality of information encountered during the provision of services and to use such information only for legitimate purposes connected with those services.

The fact that MACE personnel may have authorised access to a merchant's systems for support does not mean that MACE assumes general responsibility for the merchant's data or becomes responsible for the merchant's underlying processing activities.

To the fullest extent permitted by law, MACE accepts no responsibility or liability for the merchant's collection, processing, storage, security, retention, disclosure, alteration, loss or use of merchant data, except where such responsibility or liability arises from MACE's own acts or omissions and cannot lawfully be excluded.

5. Merchant Infrastructure and Security

The merchant is responsible for the infrastructure on which the MACE software is installed.

This includes:

  • Servers.
  • Computers.
  • Networks.
  • Firewalls.
  • Operating systems.
  • Security software.
  • Anti-virus and anti-malware protection.
  • Security updates.
  • User accounts.
  • Passwords.
  • API keys.
  • Authentication credentials.
  • Security certificates.
  • Backups.
  • Physical security.
  • Access controls.

MACE does not operate or control the merchant's infrastructure merely because MACE software is installed on that infrastructure.

The merchant may, however, provide MACE with temporary or ongoing access to its infrastructure for the purpose of providing support or other services.

Such access may be provided through remote access software, VPN connections, remote desktop services, administrative accounts, database access, screen sharing, on-site access or other technical means.

Where MACE personnel are granted such access:

  • The merchant authorises MACE to access its systems for the agreed support or service purposes.
  • MACE personnel may be able to view information stored on those systems.
  • MACE personnel may incidentally encounter personal data, confidential business information or other merchant information while carrying out technical work.
  • MACE will seek to access only information reasonably necessary for the relevant support or service.
  • MACE personnel must treat information encountered during support as confidential.
  • The merchant remains responsible for deciding what information is stored on its systems and for maintaining appropriate access controls and security.
  • The merchant remains responsible for providing MACE with appropriate access and for removing or restricting such access when it is no longer required.

MACE will take reasonable technical and organisational measures appropriate to the circumstances to protect information accessed by MACE personnel during the provision of services.

MACE does not guarantee that its personnel will never be able to view merchant information where the merchant has authorised access to its systems.

To the fullest extent permitted by law, MACE is not responsible or liable for any loss, corruption, disclosure, unauthorised access or alteration of merchant data resulting from the merchant's infrastructure, security arrangements, personnel, configuration, backups or third-party services.

Nothing in this section limits any responsibility that MACE may have under applicable data protection legislation for personal data that MACE actually processes as part of providing its services.

6. Third-Party Services and Data Transfers

The MACE software may provide functionality allowing the merchant's installation to transmit information to third-party services.

These may include:

  • Payment service providers.
  • Payment processors.
  • Banking services.
  • Hosting providers.
  • Telecommunications providers.
  • Cloud services.
  • Other third-party technology providers.

MACE may also recommend, introduce or provide information about third-party service providers where MACE considers that such services may be suitable for the merchant's requirements.

Such recommendations or introductions are provided for the merchant's consideration only.

The merchant remains responsible for deciding whether to use any third-party provider and for entering into any agreement with that provider.

MACE does not guarantee the suitability, availability, security, performance, pricing, regulatory status or continued operation of any third-party provider unless expressly agreed otherwise in writing.

A recommendation or introduction by MACE does not make MACE responsible for the third party's services or processing activities.

Where the merchant's installation of MACE software transmits data to a third party, the transmission occurs from the merchant's infrastructure unless otherwise expressly agreed.

The merchant is responsible for:

  • Selecting the third-party provider.
  • Determining what data is transmitted.
  • Determining the purpose of the transfer.
  • Establishing the lawful basis for the transfer.
  • Configuring the integration.
  • Maintaining its credentials.
  • Ensuring the transfer is lawful.
  • Complying with the third party's terms and privacy requirements.

MACE does not receive or control data merely because its software transmits the data from the merchant's infrastructure to a third party.

To the fullest extent permitted by law, MACE is not responsible or liable for the third party's processing, storage, security, availability, disclosure, loss or use of data transmitted from the merchant's infrastructure.

Where MACE personnel assist with configuring or integrating a third-party service, such assistance does not make MACE responsible for the third party's systems or processing activities.

7. Payment Processing

MACE provides software functionality which enables its merchants' systems to communicate with third-party payment service providers.

MACE may recommend or introduce merchants to payment service providers or other payment-related technology providers.

MACE is not a payment processor, acquiring bank, card issuer, financial institution or payment service provider.

MACE does not operate the payment processing services provided by third-party payment providers.

MACE does not collect or store full payment card data as part of its normal software operation.

Payment processing is performed by the relevant payment provider using the payment provider's own systems and infrastructure.

MACE does not receive, store or process:

  • Full payment card numbers.
  • CVV/CVC security codes.
  • PINs.
  • Card authentication credentials.

Where payment information is entered into a payment terminal, hosted payment page, payment application or other payment-provider-controlled environment, that information is processed by the relevant payment provider.

MACE personnel may, when providing authorised technical support, be able to view non-card payment or transaction information displayed or stored on a merchant's systems. Such access will be limited to what is reasonably necessary for the support being provided.

The merchant is responsible for its relationship with the payment provider and for complying with the payment provider's terms and applicable laws.

A recommendation or introduction to a payment provider does not constitute a guarantee or endorsement of that provider's services.

To the fullest extent permitted by law, MACE is not responsible or liable for:

  • Payment processing.
  • Payment card data held or processed by the payment provider.
  • Payment provider security.
  • Payment provider system failures.
  • Payment interruptions.
  • Declined transactions.
  • Rejected transactions.
  • Reversed transactions.
  • Chargebacks.
  • Payment disputes.
  • Payment provider security incidents.
  • Loss or disclosure of payment data held by the payment provider.
  • Fees, charges or other costs imposed by the payment provider.
  • The acts or omissions of the payment provider.

8. Children's and Minors' Data

MACE does not knowingly collect personal data directly from children or minors.

MACE's software is supplied primarily to businesses and other organisations.

Where a merchant uses MACE software to process information relating to its own customers, the merchant is responsible for determining whether any individual is a minor and for ensuring that the collection and processing of that information complies with applicable law.

The merchant is responsible for:

  • Identifying minors where required.
  • Obtaining parental or guardian consent where required.
  • Providing appropriate privacy information.
  • Establishing the lawful basis for processing.
  • Complying with applicable legislation relating to children and minors.

Where information relating to a minor is entered into the merchant's own infrastructure and processed using MACE software, that information constitutes merchant data.

To the fullest extent permitted by law, MACE is not responsible or liable for the merchant's processing of data relating to minors, except to the extent that MACE itself processes such data as part of providing authorised services.

9. Legal Basis for Processing

Where MACE processes MACE Customer Data, the lawful basis may include:

Contract

Where processing is necessary to enter into or perform a contract.

Legal Obligation

Where processing is necessary to comply with a legal or regulatory obligation.

Legitimate Interests

Where processing is necessary for MACE's legitimate business interests and those interests are not overridden by the individual's rights.

Consent

Where MACE has obtained consent for a specific processing activity.

Where MACE personnel access personal data held on a merchant's systems as part of authorised technical support or other services, the legal basis for such processing will depend on the circumstances and the contractual and data protection arrangements between MACE and the merchant.

The merchant remains responsible for establishing the appropriate lawful basis for its own processing of merchant data.

10. International Data Transfers

Where MACE itself transfers MACE Customer Data outside the United Kingdom or European Economic Area, MACE will ensure that an appropriate lawful transfer mechanism is used where required.

This may include:

  • An adequacy decision.
  • UK International Data Transfer Agreement (IDTA).
  • UK International Data Transfer Addendum.
  • European Commission Standard Contractual Clauses.
  • Another legally recognised transfer mechanism.

Where a merchant uses MACE software to transfer merchant data to a third-party provider outside the United Kingdom or European Economic Area, the merchant is responsible for ensuring that the transfer complies with applicable legislation.

Where MACE personnel access merchant systems remotely from outside the United Kingdom, MACE will consider any applicable data protection requirements and appropriate safeguards.

11. Your Rights

In relation to MACE Customer Data, you may have the right to:

  • Access personal data held by MACE.
  • Request correction of inaccurate data.
  • Request deletion of data, subject to legal obligations.
  • Request restriction of processing.
  • Object to certain processing.
  • Request data portability where applicable.
  • Withdraw consent where processing is based on consent.

Where the data concerned is merchant data held and processed on the merchant's own infrastructure, requests should normally be directed to the relevant merchant because that merchant is responsible for the data.

Where MACE has processed or accessed personal data on behalf of a merchant as part of authorised support or other services, MACE will cooperate with the merchant as reasonably required to address applicable data protection requests, subject to applicable law and the terms of the relevant agreement.

12. Data Retention

MACE is responsible for determining appropriate retention periods for MACE Customer Data.

MACE will retain MACE Customer Data only for as long as reasonably necessary for the purposes for which it was collected, to comply with legal obligations, or to establish, exercise or defend legal claims.

MACE does not determine the retention period for merchant data held on the merchant's infrastructure.

The merchant is responsible for determining and managing retention periods for merchant data processed by its installation of MACE software.

Where MACE temporarily obtains copies of merchant data as reasonably necessary for technical support, troubleshooting or other services, MACE will retain such copies only for as long as reasonably necessary for the relevant purpose, unless a longer retention period is required by law or reasonably necessary to establish, exercise or defend legal claims.

13. Complaints and Supervisory Authority

If you have concerns regarding MACE Customer Data, please contact MACE in the first instance.

You also have the right to lodge a complaint with the relevant Data Protection Authority or Supervisory Authority.

For the United Kingdom:

Information Commissioner's Office (ICO)

Complaints can be made through:

https://ico.org.uk/make-a-complaint/

Telephone: 0303 123 1113

MACE Systems Limited ICO Registration: ZB401452

Where a complaint relates to merchant data held and processed by a merchant on its own infrastructure, the complaint should normally be directed to that merchant in its capacity as the organisation responsible for that data.

14. Contact Us

For matters relating to MACE Customer Data or this Privacy Policy, please contact:

MACE Systems Limited
3 Fairfield Close
Marshfield
Chippenham
SN14 8NH
United Kingdom

Email: accounts@mace.systems

ICO Registration: ZB401452

15. Changes to this Privacy Policy

MACE may update this Privacy Policy from time to time to reflect changes in our services, legal requirements or data processing activities.

The "Last Updated" date will be amended whenever this Privacy Policy is reviewed or materially updated.

MACE Systems Limited

ICO Registration: ZB401452

Privacy Policy Last Reviewed: 1st September 2026