Hewett Payments UK Ltd

PLATFORM SAFEGUARDS

Security & compliance

We would rather describe exactly what we do than make claims we cannot evidence. This page sets out our access controls, data handling and the boundaries of our role.

Our role, stated plainly

Hewett Payments UK Ltd supplies software. We are not a payment provider, and we do not process payments, hold funds, settle funds or carry out money transmission. Payment processing, identity verification and settlement are performed by the relevant third-party payment providers you have accounts with. Our obligations apply to the data we hold as part of operating the platform.

our mission

How the platform protects your data

Practical controls, described without jargon.

Access control

Named user accounts, role-based permissions and separate access per connected account. Access is removed promptly when someone leaves.

Encryption

Data is encrypted in transit, and at rest on the infrastructure that hosts the platform.

Infrastructure

The platform runs on UK/EU infrastructure with access limited to those who need it to operate and support the service.

Data retention

Records are retained for as long as your agreement requires, and deleted or returned at the end of it.

UK GDPR duties

Where we act as a controller for account data, we follow UK GDPR obligations: lawful basis, minimisation, and handling subject requests.

Change history

Status changes and administrative actions are logged so that activity can be reviewed after the fact.

Hewett Payments settlement reconciliation view

What we do not claim

You will not find statements on this site about certifications we do not hold or regulatory status we do not have. If a procurement team needs specific information about our controls, ask us and we will answer in writing — including saying plainly where a control does not exist.

Ask our team a compliance question

Send your question and we will answer in writing, including the boundaries of our role.