Privacy Policy

Onecom Group Privacy Notice

Our Privacy Notice explains how Onecom uses your personal data, what we do to ensure the safety and security of it, and who we share it with. It also informs you of your rights and how the law protects you.

In short

Here are the things we think you’d really want to know about how we manage your personal data.

  • Your personal information is, where appropriate, shared within the Onecom Group
  • We do use a number of third parties to process your personal information on our behalf and some of them are based outside of the UK and European Economic Area
  • You have a number of rights over your personal information. How you can exercise these rights is set out in this notice
  • We do send direct marketing, if we’re allowed to. If you want us to stop then please email hello@onecom.co.uk

Who we are

When we use the expressions “Onecom”, “we”, “us” and “our” we are referring to the companies that make up the Onecom Group. This includes: Onecom Limited, Onecom Partners Limited, IMS Technology Services Limited, Daly Systems Limited, Onecom Technology (India) Private Limited, Onecom Group Limited, Solo Bidco Limited, Solo Topco Limited, Gradwell Communications Limited.

For more information about Onecom: https://www.onecom.co.uk/about

Your rights

You have a number of rights under data protection legislation which, in certain circumstances, you may be able to exercise in relation to the personal information we process about you.

These include:

  • The right to access a copy of the personal information we hold about you
  • The right to correction of inaccurate personal information we hold about you
  • The right to restrict our use of your personal information
  • The right to be forgotten
  • The right of data portability
  • The right to object to our use of your personal information

If you are seeking to exercise any of these rights, please contact us using the contact form.

How the law protects you

Data protection law states that we are allowed to use personal data only if we have a proper reason to do so. The law says we must have one or more of the following reasons:

  • To fulfil a contract we have with you
  • You have given us your consent
  • We have a legitimate interest and it is necessary for us to conduct our business, but not where our interests are overridden by your interests or rights
  • Where we have a legal obligation to do so
  • When it is necessary to protect you or someone else’s life, this is called Vital Interest

Types of personal data we collect

  • Contact Data includes billing address, delivery address, email address and telephone numbers
  • Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us
  • Technical Data includes internet protocol (IP) addresses
  • Usage Data includes information about how you interact with and use our website, products and services
  • Marketing, Market Research and Communications Data includes your preferences in receiving marketing from us

Credit referencing agencies

The three main Credit Reference Agencies are TransUnion, Equifax and Experian. Each of the Agencies have signed up to a joint policy (“CRAIN”) which explains how they use and share personal data they receive about you and/or your business that is part of or derived from or used in credit activity. To find out more please follow the links below.

  • TransUnion International UK Limited
  • Equifax Limited
  • Experian Limited

Where we collect personal data from

We may collect personal data about you from these sources:

  • Personal data you give us directly
  • When you use our websites or interact with us through social media
  • Credit reference agencies
  • Reputable data suppliers
  • Personal data from companies/businesses which have been acquired by Onecom
  • From publicly available sources such as information held in Companies House, and information about you that is openly available on the internet

How do we use your data

  • To provide our products and services
  • For safety and security
  • Analytics and profiling
  • Marketing and advertising

Who and why we may share your personal data

  • If we are required to by law, under any code of practice by which we are bound or where we are asked to do so by a public or regulatory authority.
  • Companies within the Onecom Group so that we can provide you with a high-quality service.
  • Our service providers so that they can help us provide the products and services you require from us, or we think you might be interested in. This may include a third party
    • if you wish to apply or enter into a financial agreement with them when purchasing a product. These third parties include:
    • Advertising companies, who help us place adverts online and on other media
    • Social media providers, such as Facebook, Instagram and Twitter
    • Market research partners, who help us analyse customer behaviour
    • Companies that deploy our email campaigns because they need to know your email address to carry out these services
    • Credit reference agencies
    • Third party vendors who help us manage and maintain our IT infrastructure
    • Security and fraud prevention companies to ensure the safety and security of our customers, colleagues and business
    • Companies that enable us to collect your reviews and comments, both online and offline
    • Professional advisors including lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, and accounting services

International transfers of personal information

From time to time we transfer your personal information to Onecom Group companies, suppliers or service providers based outside of the UK and EEA for the purposes described in this privacy policy. When we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law, including the use of model contracts in a form approved by regulators.

Keeping you informed about our products and services

We would like to tell you about our products and services that we think you might be interested in. We will only ever do this with your consent or where there is a legitimate interest.

We won’t send you marketing messages, if you tell us not to, but if you receive a service from us, we will still need to send you occasional service-related messages and may still send you surveys (you can always opt out of these via the survey email itself).

Please note that it can take a little while for all marketing to stop once you either withdraw your consent or tell us you’d like to opt out of marketing.

You may opt out of these calls or emails at any time, either verbally whilst on the phone or by using the contact form.

Automated decision making and AI

We sometimes use automated decision-making. For instance, we use automated decision-making for credit assessments when you apply for a contract with us. The outcome can determine your eligibility for a contract or the payment terms we can offer you. You have the right to request human intervention or contest a decision by contacting us via the ‘Your Rights’ section.

We use AI within a few of our operational processes. Before using AI we will always complete an assessment to ensure that your rights will always be maintained and ICO guidance is considered.

How long we hold your personal data for

We will only keep your personal data for as long as necessary for our business or legal requirements. To determine the appropriate retention period we always consider the amount and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure and the applicable legal and/or regulatory requirements.

We also have processes in place to securely dispose of personal data we no longer require.

Security

We take protecting your personal information seriously and are continuously developing our security systems and processes. Some of the controls we have in place are:

  • We use technology controls for our information systems, such as firewalls, user verification, strong data encryption and multiple verification access protocols
  • Systems are proactively monitored through a “detect and respond” information security function
  • We utilise industry “good practice” standards to support the maintenance of a robust information security management system
  • We enforce a “need to know” policy, for access to any data or systems

If things go wrong and you wish to make a complaint

You have the right to make a complaint at any time to the Information Commissioner’s Office, the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact our Data Protection Officer in the first instance using the below details, or via this contact form.

Cookies

Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site. For detailed information on the cookies we use and the purposes for which we use them, please see our Cookies Policy.

Data Protection Officer Contact Details

Address: Onecom House, 4400 Parkway, Solent Business Park, Fareham, Hampshire, PO15 7FJ

Email: dpo@onecom.co.uk
Supervisory Authority Contact Details
Name: Information Commissioner’s Office

Website: https://ico.org.uk/
Email: casework@ico.org.uk
or the contact form at: https://ico.org.uk/global/contact-us
Telephone: 0303 123 1113

 

Join thousands of businesses

We’ve helped organisations from across the UK take advantage of cloud-based communications tools. Can we help you?
Gradwell office meeting