top of page
Logo elements-04.png

Client Data Storage and Security Overview

Document prepared on 26 July 2026

For visitors in the European Union, cookies and similar technologies are governed by the ePrivacy rules and GDPR. Non-essential cookies normally require clear, specific, informed and freely given consent before they are stored or read.

What Data Is Stored

  • Clients Company name, client name, email, phone, billing and

  • shipping addresses.

  • Wix Data collections, primarily

  • WorkflowJobs client-directory records.

Quotes and invoices

  • Quote/invoice numbers, tokens, project details, line items,

  • quantities, turnaround, totals, VAT, payment status and

  • correspondence status.

  • Quotes collection and WorkflowJobs

  • invoice/workflow records.


Artwork approval

  • Artwork links, version links, approval status, proof response,

  • amendment notes, signature/name fields and proof tokens.

  • WorkflowJobs proof/artwork records.

  • Artwork files may be stored in Google

  • Drive where upload links are used.


Suppliers/products

  • Supplier contact details, product names, description variants,

  • turnaround values and supplier mappings.

  • WorkflowJobs supplier-directory and

  • product-directory records.

Timesheets

  • Month, client, invoice, note/job reference, time category,

  • start/end times and duration.

  • WorkflowJobs timesheet records.


Backups

  • Exported page or directory backup data, including chunked

  • backup records.

  • WorkflowJobs data-backup and

  • data-backup-chunk records; optional

  • emailed/downloaded backup files.

Security Controls Visible in the Current System

  • Admin functions require an admin access key or a valid staff portal session before private pages are shown.

  • Workflow pages require workflow-level access or an admin session.

  • Staff sessions use a signed portal session cookie called dp_portal_session with a one-hour expiry.

  • Customer-facing quote, invoice, upload and artwork proof pages use tokenised URLs rather than public index pages.

  • API keys and integration credentials are requested through Wix Secrets, including SendGrid, Stripe and QuickBooks secrets.

  • The backend sanitises many text fields before rendering them into HTML and normalises artwork/Drive URLs.

  • Client upload files are routed through a Google Apps Script/Drive workflow rather than being attached directly to emails.

  • Backup and restore pages require admin access.

Third-Party Services

Wix
Provider Purpose: Website hosting, HTTP functions, Wix Data storage, media handling, member authentication, triggered emails and secrets storage.

SendGrid
Provider Purpose: Transactional email delivery for quotes, invoices, artwork proof notifications and workflow

messages.

Stripe
Provider Purpose: Payment links and payment webhook processing.


QuickBooks / Intuit
Provider Purpose: Accounting and payment/accounting integration.

Google Drive / Apps Script
Provider Purpose: Artwork/client upload storage and transfer where Drive upload links are used.


Recommended Operational Controls

  • Keep the admin and workflow access keys private and rotate them when staff access changes.

  • Review Wix roles, member permissions and collection permissions regularly.

  • Keep Google Drive artwork folders restricted to staff who need access.

  • Use unique staff logins where possible rather than sharing passwords.

  • Keep a dated restore backup after each major site publish.

  • Confirm retention periods for client data, invoice data, artwork proofs and backups, then document those retention periods in the live privacy notice.


Official References

ICO, Guide to the UK GDPR - transparency and the right to be informed: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-to-be-informed/


ICO, Security principle and data security guidance:

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/

ICO, Cookies and similar technologies under PECR: https://ico.org.uk/for-organisations/direct-marketing-and-privac

y-and-electronic-communications/guide-to-pecr/cookies-and-similar-technologies/

European Commission, Cookies and EU/ePrivacy information: https://commission.europa.eu/cookies_en


European Data Protection Board, Guidelines 05/2020 on consent under GDPR: https://www.edpb.europa.eu/our-wo

rk-tools/our-documents/guidelines/guidelines-052020-consent-under-regulation-2016679_en

2026 A4 lookbook12.jpg
2026 A4 lookbook12.jpg
2026 A4 lookbook11.jpg
2026 A4 lookbook11.jpg

Follow us on Instagram

2026 A4 lookbook12.jpg
2026 A4 lookbook2.jpg
2026 A4 lookbook11.jpg
2026 A4 lookbook6.jpg
bottom of page