Privacy Policy
Last updated: 7 April 2026 · OTS Broker Ltd · UK GDPR compliant
UK GDPR CompliantAzure West EuropeNo Third-Party Ads4-Year Retention
1. Data Controller
OTS Broker Ltd
Suite A Surrey House, 189 London Road, Staines, TW18 4HR
EORI: GB464362093000
Contact: support@otsbroker.com
Suite A Surrey House, 189 London Road, Staines, TW18 4HR
EORI: GB464362093000
Contact: support@otsbroker.com
2. What We Collect
When you use NEXT, we collect and process the following categories of personal data:
Account data
Name, email address, and authentication credentials used to access NEXT.
Declaration data
Customs declaration information including commodity codes, values, weights, EORI numbers, trader details, and document references.
HMRC responses
Status messages, conversation IDs, MRNs, acceptance/rejection notifications, and data returned by HMRC CDS and NCTS5.
System logs
IP addresses, timestamps, API request metadata, error logs, and audit trail entries generated during use.
3. Legal Basis for Processing
We process your data under the following legal bases (UK GDPR Article 6):
Legitimate interest
Art. 6(1)(f)
To operate a customs declaration platform that helps you prepare, submit, and manage declarations efficiently.
Legal obligation
Art. 6(1)(c)
Customs brokers must maintain declaration records and submit accurate information to HMRC under the Customs Act 2018.
Contract performance
Art. 6(1)(b)
To provide the NEXT platform services you have requested.
5. Where Data Is Stored
All data is stored on Microsoft Azure, West Europe region (Netherlands). Data does not leave the EEA except when transmitted to HMRC in the UK, covered by the UK adequacy decision.
6. How Long We Keep Data
Declaration records
4 yearsFrom date of submission — HMRC customs record-keeping requirement.
System & audit logs
12 monthsThen automatically purged.
Account data
Account + 12 monthsAfter account closure, to handle outstanding queries.
7. Your Rights
Under UK GDPR, you have the following rights:
Access
Request a copy of the personal data we hold about you.
Rectification
Request correction of inaccurate data.
Erasure
Request deletion of your data, subject to legal retention obligations.
Restriction
Request that we limit processing of your data.
Portability
Receive your data in a structured, machine-readable format.
Objection
Object to processing based on legitimate interest.
Submit a formal request
Use the form below to exercise any of these rights. We will respond within one calendar month.
9. Security
HTTPS encryption in transit for all connections.
Encrypted storage at rest via Azure platform encryption.
API key authentication with SHA-256 hashed storage.
HMAC-SHA256 webhook signature verification (fail-closed).
Role-based access controls and full audit logging.
10. Complaints
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk · Helpline: 0303 123 1113
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk · Helpline: 0303 123 1113
11. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the platform. The "last updated" date at the top of this page reflects the most recent revision.
Current version: v1.0 — 7 April 2026