Data handling
Plain answers to the questions clients ask before they hand us a database. If something you need is not covered here, ask and we will put it in writing.
Client systems run on infrastructure in the United Kingdom that we manage. Data does not leave the UK in normal operation. Where a client needs an on-premises installation, we support that instead.
Every hosted system is backed up daily to a separate off-site location, and restores are tested. If you want a copy of your own backup on a schedule, we can arrange that.
Only named SuperCrank staff working on your system have access, over authenticated, encrypted connections. We do not give third parties access to client data. Client-side access is controlled through the roles and permissions built into the system you use.
Web traffic to your system is encrypted (HTTPS). Passwords are stored hashed, never in plain text. Desktop applications that hold data locally use encrypted storage.
For client systems, the client is the data controller and SuperCrank is the data processor. We process personal data only on the client's instructions and under a written agreement. We help with subject access requests and data protection impact assessments where they affect a system we run.
Screenshots on this site use fictional test data created for the purpose. We never show real customer, patient or staff records, and we do not name a client on this site without their agreement.
Your data is yours. At the end of an engagement we provide a full export in a standard format (SQL dump or CSV, as you prefer), then delete our copies on a date agreed with you and confirm in writing.
Email hello@supercrank.tech or call 07394 848972. Data protection queries are handled by the director, Harvey Geeson.
Last reviewed 16 September 2026.