Factory Direct Pricing Free Visual Proofs 10 Year Warranty Account Managers Worldwide Delivery
Speak to an Account Manager
0800 130 3366
Request a Quote

Privacy and Data Protection

Privacy Policy

This policy is our privacy notice. It explains how Disc Makers Limited, trading as USB Makers Intl, collects, uses, stores and shares personal information when you visit our website, request a quotation, place an order, contact our team or use our services.

The complete policy is numbered 1 to 27 and can be browsed from the contents list below, printed, or saved for procurement and compliance records. The summary on the right covers the points most customers and data-protection teams ask about first.

  • Effective date: [CONFIRM DATE]
  • Last reviewed: 11 July 2026
  • Version: v3.0 (review draft)
Contact Us About Your Data
  • Controller: Disc Makers Limited
  • Your Data Rights Explained
  • Printable for Procurement Records

At a Glance: The Short Version

A brief summary of how USB Makers handles personal information.

  • Disc Makers Limited, trading as USB Makers Intl, is responsible for the personal information covered by this policy.
  • We collect the information needed to answer enquiries, prepare quotations, process orders, provide customer support and meet legal obligations.
  • We do not automatically use every sales enquiry for email marketing; marketing messages follow the applicable consent or legitimate-interest rules and always include an opt-out.
  • We share information only where necessary, with service providers such as hosting, email, payment, production and delivery partners.
  • Files supplied for artwork or USB data preloading are handled separately and kept only for a confirmed operational or legal period.
  • You may have rights to access, correct, delete, restrict or object to the use of your personal information.
  • You can raise concerns with our privacy contact or complain to the Information Commissioner's Office at any time.

This summary is provided for convenience. The complete policy below contains the full information.

Review draft. This policy is not yet in force. The highlighted placeholders below must be confirmed against USB Makers' actual data-processing activities, the cookie-consent remediation must be completed, and the wording must be approved by a qualified UK data-protection professional or solicitor before publication.

Key privacy information. Data controller: Disc Makers Limited. Trading name: USB Makers Intl. Company number: 05350646. Privacy email: privacy@usbmakers.com. Telephone: 0800 130 3366. ICO registration: [CONFIRM ICO REGISTRATION NUMBER].

1. Who we are

Disc Makers Limited, trading as USB Makers Intl, is the data controller for the personal information described in this policy — that is, the company that decides why and how the information is used. Company number: 05350646. VAT number: GB 880 6582 93. Registered office: Market House, 10 Market Walk, Saffron Walden, Essex, CB10 1JZ. Trading address: G6, Allen House, The Maltings, Sawbridgeworth, Hertfordshire CM21 9JX.

We have not appointed a formal Data Protection Officer; privacy matters are handled by our data protection contact, reachable at privacy@usbmakers.com or 0800 130 3366. Our ICO registration number is [CONFIRM ICO REGISTRATION NUMBER].

Some organisations we work with process information on our instructions as processors, such as our website host. Others, such as banks, payment providers and couriers, are separate controllers of the information they need for their own services, and their own privacy notices apply to that processing.

2. Who this policy applies to

This policy covers website visitors; prospective and current customers and their employees and representatives; delivery recipients; newsletter subscribers; users of our quote and contact forms; suppliers and their representatives; and individuals whose personal information appears in artwork or files supplied to us for branding or USB data preloading. It does not cover our own employees or job applicants, who receive separate information.

3. Personal information we collect

Identity and contact information — name, job title, company, department, business email and telephone, billing and delivery addresses.

Enquiry and quotation information — the products you are interested in, quantities, capacities, branding and packaging requirements, delivery country, required dates and your quotation history.

Order and account information — products ordered, order values, invoices, purchase orders, payment status, credit terms, returns and claims, and customer-support history.

Artwork and uploaded files — logos, artwork and design instructions, together with any personal information they contain, such as names, contact details, photographs or signatures. Visual proofs we create from them are also retained.

Data-preloading files — files supplied for copying onto USB products, including folder structures, filenames and any personal information within the files. Please supply only information you are authorised to provide, and avoid unnecessary personal or sensitive content.

Technical information — IP address, browser and device type, pages viewed, referring pages and cookie identifiers, as described in section 12.

Communications — emails, form messages, telephone notes, complaints, feedback and marketing preferences. Telephone calls are not recorded.

Payment information — payment references and status. Card payments are processed by our payment provider; see section 9.

Credit information — where a credit account is requested: company details, trade references and payment history.

4. How we collect information

Most information comes directly from you: through our website forms and quote cart, by email or telephone, in uploaded artwork and data files, and on purchase orders. Some is generated while we work together, such as order and payment records. Some comes from third parties: publicly available business sources such as Companies House, and couriers confirming delivery; we do not search credit reference agencies. Technical information is collected automatically when you use the website, subject to the cookie controls described in section 12.

5. Why we use personal information and our lawful bases

UK data protection law requires a lawful basis for each use of personal information. The table below summarises our purposes and bases. Where we rely on legitimate interests, we have considered whether the processing is necessary and whether it is outweighed by your interests and rights, and you may object as described in section 20. [CONFIRM LEGITIMATE INTERESTS ASSESSMENTS]

Purposes, information used and lawful bases
PurposeInformation usedLawful basisShared with
Answering enquiries and preparing quotations and visual proofsIdentity, contact, enquiry, artworkSteps taken at your request before a contractEmail and IT providers
Processing orders, production and brandingOrder, artwork, specificationContractProduction partners and suppliers
Data preloadingSupplied filesContract (see section 8 for our processor role)Duplication team only
Taking payment and providing refundsPayment, billingContractPayment providers, banks
Providing credit accountsCredit informationLegitimate interests (responsible credit decisions)Assessed internally; no external agency
Delivering productsDelivery detailsContractCouriers, customs agents
Handling returns, claims and supportOrder, communicationsContract; legitimate interests (resolving issues)Couriers, suppliers where relevant
Keeping accounting and tax recordsInvoices, payment recordsLegal obligationAccountants, HMRC where required
Sending marketing communicationsContact, preferencesConsent, or legitimate interests / soft opt-in where permitted (section 11)Mailchimp
Operating and securing the websiteTechnical informationLegitimate interests (a safe, working website)Hosting and security providers
Measuring website use and advertisingCookie and usage dataConsent (section 12)Google and Meta (once activated, subject to consent)
Establishing or defending legal claimsRelevant recordsLegitimate interests (protecting our legal position)Legal advisers, insurers

Scroll sideways to see the full table.

6. Quotations and orders

When you request a quotation through the website quote cart, by email or by telephone, we use your details to prepare the quotation, create any visual proof and follow up on that enquiry. An account manager may contact you about the quotation you requested; that is service follow-up, not marketing. Requesting a quotation does not by itself opt you in to newsletters or unrelated promotional email — marketing is handled separately, as described in section 11. Order information is then used to manage production, invoicing, delivery, repeat orders and support.

7. Artwork and logo uploads

Logos and artwork you upload or send to us are used to check formats, create visual proofs and brand your products. Artwork sometimes contains personal information — names, contact details printed in designs, photographs or signatures — and by supplying it you confirm you are authorised to provide that content. Artwork may be shared with the production partners who manufacture your goods, including manufacturing partners outside the UK where your order requires it. Artwork and proofs are stored securely and retained for up to five years after your last order so we can reproduce repeat orders accurately, after which they are deleted.

8. Data-preloading services

Where you ask us to preload files onto USB products, you decide what the files contain, and we copy them according to your instructions. For any personal information inside those files, we act as a processor on your documented instructions; you (or your organisation) remain the controller. [LEGAL REVIEW: CONTROLLER AND PROCESSOR STATUS FOR PRELOADED DATA] Data-processing terms form part of our Terms and Conditions for these orders.

Please transfer files using the method we agree with you (normally a WeTransfer or Dropbox link, or email for files under 10MB), keep your own backup copies, tell us in advance if files contain personal data, and avoid supplying special-category or otherwise sensitive information unless it has been agreed and safeguarded. Access to supplied files is limited to the staff who need it.

Working copies of preload files are deleted 30 days after despatch. Copies can persist in our routine backups for up to a further 90 days before they cycle out; backup copies are not accessed except for restoration. We cannot promise immediate deletion from every backup, and we will tell you honestly what deletion involves if you ask.

9. Payments

Card payments are processed by our payment provider, Opayo (formerly SagePay); the provider collects your card details under its own terms and privacy notice, and full card numbers do not enter our systems: card details taken by telephone are keyed directly into the payment system during the call and are never written down, emailed or stored. Bank-transfer payments give us the payment reference and account name shown on our statement. We keep payment references, invoices and refund records for accounting purposes, and we may use payment information for fraud-prevention checks.

10. Delivery and fulfilment

To deliver your order we share the recipient's name, company, address, telephone number, email and any delivery instructions with our couriers, and customs information with customs agents for international shipments. Where you ask us to deliver to someone else — colleagues, event venues or your own customers — you confirm you are entitled to give us their details, and we use them only for that delivery.

11. Marketing communications

We send marketing — such as newsletters, product updates and reorder reminders — only in accordance with the rules that apply to each audience. Where consent is required, we ask for it when you sign up, and signing up to the newsletter is always separate from making an enquiry. For existing customers we may rely on the "soft opt-in", which allows email about similar products where you were given the chance to opt out when we collected your details and in every message. For corporate contacts we may also rely on legitimate interests where the law permits business-to-business marketing; sole traders and some partnerships have the same protection as individuals, and we treat them accordingly. Newsletters are sent through Mailchimp. We do not make unsolicited marketing calls, and account managers may send reorder reminders to existing customers. Marketing contacts come from our own customer and enquiry records; we do not buy marketing lists.

Every marketing email contains an unsubscribe link, and you can opt out at any time by contacting us. We do not sell or rent mailing lists. Service messages — order confirmations, proofs, delivery updates and similar — are not marketing and are sent as part of your order.

12. Cookies, analytics and advertising

The website uses cookies and similar technologies (including local storage) in four groups: strictly necessary technologies that make the site work, such as the quote cart; preference and functional cookies; analytics cookies that help us understand how the site is used; and advertising cookies. Analytics and advertising technologies are used only with your consent, requested through the cookie banner, and you can change or withdraw your choices at any time through the cookie settings — withdrawing consent is as easy as giving it, and rejecting non-essential cookies does not stop the site working. Google Analytics (measurement) and Google Ads and Meta (advertising) are planned and will operate only after the required consent, using Google Consent Mode v2 in its basic configuration. [CONFIRM ANALYTICS RETENTION SETTINGS]

Full details of each cookie, its purpose and its duration are in our Cookie Policy. The website includes an AI-powered chat assistant that answers product questions: conversations are processed by our AI provider (Anthropic) to generate replies, are not stored on your device, and should not include sensitive personal data.

13. Credit accounts and fraud prevention

If you apply for a credit account, we use the information you provide, together with publicly available company information, to make a credit decision and set a credit limit; credit accounts are offered to education and public-sector buyers. We do not search credit reference agencies, and credit decisions are made by people, not solely by automated means. Unpaid accounts may be referred to debt-recovery providers.

14. Suppliers and business contacts

We hold business contact details for our suppliers, manufacturing partners and professional advisers, and use them to manage those relationships, place orders and meet our legal obligations. The lawful bases are the contract with the supplier and our legitimate interest in running the business.

15. Who we share information with

We share personal information only where needed, with: website hosting and IT providers; email and office systems; our own order and accounting systems; email-marketing platforms; payment providers and banks; manufacturers and production partners; couriers, freight companies and customs agents; accountants, auditors, insurers and legal advisers; security and backup providers; analytics and advertising providers, subject to your cookie choices; debt-recovery providers where accounts are unpaid; and regulators, government bodies or law enforcement where the law requires. If the business were ever sold or restructured, information could be shared with prospective purchasers under confidentiality obligations.

Providers acting on our instructions do so under contracts restricting their use of the information. Organisations such as banks, couriers, credit-reference agencies and advertising platforms are separate controllers for parts of their processing and have their own privacy notices. We do not sell personal information.

16. International transfers

Some of the organisations we work with process information outside the United Kingdom. This can include manufacturing partners in China who receive order and artwork information, and technology providers whose services are hosted in the United States or elsewhere, such as Google, Meta, Mailchimp and our AI chat provider (Anthropic). Our United States office operates separately and does not access UK customer data.

Where information leaves the UK, we use a lawful transfer route: the UK adequacy regulations where the destination is covered; the UK Extension to the EU-US Data Privacy Framework for participating US providers; or the International Data Transfer Agreement or UK Addendum with additional safeguards where needed. [CONFIRM TRANSFER SAFEGUARDS PER PROVIDER] You can ask our privacy contact for more information about the safeguards used for a particular transfer.

17. How long we keep information

We keep personal information only as long as needed for the purpose it was collected, and retention depends on contract requirements, tax obligations, possible legal claims, fraud prevention, warranty periods and operational need. Typical periods are below; do not read this table as a promise to delete information we are legally required to keep.

Retention periods by data category
Data categoryTypical retentionReasonDeletion trigger
Enquiries and quotations2 years after last contactFollow-up; repeat quotesPeriod after last contact
Orders, invoices and payment records7 yearsTax and accounting law; claimsEnd of statutory period
Artwork and visual proofsUp to 5 years after your last orderRepeat ordersPeriod after last order
Data-preloading filesDeleted 30 days after despatch; backups cycle out within a further 90 daysProduction; restore capabilityDespatch + period; backup cycle
Returns, claims and warranty recordsWarranty period plus 1 yearClaims handling; warranty periodsClaim closure + period
Marketing consents and preferencesWhile marketing continues, plus 2 years after withdrawalEvidence of consentWithdrawal + record period
Suppression listKept minimally for as long as needed to honour opt-outsPreventing unwanted marketingNot deleted while marketing continues
Cookie-consent records180 days on your device (no server copy)Evidence of consentPeriod after choice
Security and server logs90-day rolling deletionSecurity investigationRolling deletion
Credit applications[CONFIRM CREDIT APPLICATION RETENTION]Credit decisions; disputesAccount closure + period

Scroll sideways to see the full table.

18. Security

We take proportionate technical and organisational measures to protect personal information, including serving the website over HTTPS, restricting access to the staff who need it, using agreed transfer methods for customer files, and holding our providers to contractual security obligations. No online system is entirely risk-free, so we do not claim that security incidents are impossible; we work to prevent them and to respond properly if one occurs.

19. Personal data breaches

We maintain a process for assessing suspected personal data breaches. Where a breach is notifiable, we report it to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to individuals, we inform those affected without undue delay. Not every incident meets these thresholds, and we document incidents and the decisions made about them.

20. Your rights

Depending on the circumstances, you have the right to: be informed about how your information is used; access a copy of your information; correct inaccurate information; have information erased; restrict processing; object to processing based on legitimate interests, and to direct marketing at any time; receive certain information in a portable format; not be subject to solely automated decisions with legal or similarly significant effects; and withdraw consent where consent is the basis, without affecting earlier processing.

These rights are not absolute. For example, we cannot erase records we must keep for tax, contract, claims or fraud-prevention purposes, and suppression-list entries are retained so that opt-outs keep working. We may need to verify your identity before acting, and we may ask you to clarify a request. We normally respond within one month; the law allows an extension of up to two further months for complex or numerous requests, and we will tell you within the first month if that applies. To exercise any right, contact privacy@usbmakers.com or write to our registered office (Market House, 10 Market Walk, Saffron Walden, Essex, CB10 1JZ).

21. Marketing objections and suppression lists

You can object to direct marketing at any time, using the unsubscribe link in any marketing email or by contacting us, and we will stop. To make the opt-out stick, we keep a minimal suppression record (typically just your email address and the date) rather than deleting every trace of you — deleting the suppression entry would risk marketing resuming. Service messages needed for your order are unaffected by marketing opt-outs.

22. Automated decisions and profiling

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Ordinary website analytics and audience measurement are used to improve the site and, with consent, for advertising; this is not significant automated decision-making.

23. Children's information

Our website and services are intended for businesses and organisations, and we do not knowingly invite children to submit personal information. Schools, colleges and universities order through adult representatives. If you believe a child has submitted personal information to us without appropriate authority, please contact us and we will address it.

24. Third-party websites and embedded content

Our website links to external websites, and includes some embedded third-party content such as customer-review widgets. Those services have their own privacy practices, which we do not control and are not responsible for; embedded content may collect information about your visit, subject to your cookie choices. Please review the relevant third-party notices.

25. Changes to this policy

We review and update this policy from time to time, and change the last-reviewed date whenever we do. If we make a material change to how we use personal information, we will highlight it on this page and, where appropriate, tell affected customers directly or seek consent where the law requires it. Earlier versions are retained where practical.

26. Complaints

If you have a concern about how we handle your information, we would welcome the chance to resolve it: contact our privacy contact at privacy@usbmakers.com and we will investigate and respond. If you remain unhappy, you can ask for the matter to be escalated within the company. You also have the right to complain to the Information Commissioner's Office at any time — you do not have to contact us first. The ICO can be reached at ico.org.uk or on 0303 123 1113.

27. Contact information

Disc Makers Limited trading as USB Makers Intl
Company number: 05350646
Privacy email: privacy@usbmakers.com
Telephone: 0800 130 3366
Registered office: Market House, 10 Market Walk, Saffron Walden, Essex, CB10 1JZ
Privacy correspondence address: Market House, 10 Market Walk, Saffron Walden, Essex, CB10 1JZ
ICO registration number: [CONFIRM ICO REGISTRATION NUMBER]

Related pages: Cookie Policy · Terms and Conditions · Returns, Faults and Claims · Contact Us · Data Preloading · Artwork Guidelines