1. Who we are

Iconic Management Solutions UK Limited is a private company limited by shares incorporated in England and Wales under company number 17320780. Its registered office is at 6 Baker Street, Middlesbrough, England, TS1 2LH.

In this Privacy Notice, “IMS UK”, “we”, “us” and “our” refer to Iconic Management Solutions UK Limited.

For personal data covered by this Privacy Notice, IMS UK generally acts as the controller. This means that we determine why and how the personal data is processed. In certain service engagements, we may instead act as a processor on behalf of a business client, as explained below.

CompanyIconic Management Solutions UK Limited
Emailprivacy@iconicms.co.uk
PostData Protection Enquiries, Iconic Management Solutions UK Limited, 6 Baker Street, Middlesbrough, England, TS1 2LH
Company Number17320780

2. Purpose and scope of this Privacy Notice

This Privacy Notice explains how IMS UK collects, uses, discloses, retains and protects personal data relating to:

  • visitors to our UK website and online services;
  • individuals who contact or communicate with us;
  • prospective clients and their representatives;
  • clients, suppliers, carriers, consultants, referral sources and business partners;
  • personnel and representatives of organisations with which we conduct, or consider conducting, business;
  • individuals whose personal data is provided to us in connection with an enquiry, proposal or service engagement;
  • persons who receive business communications, publications, invitations or marketing from us.

This Notice applies to our website, business-development activities, client and supplier administration, and related corporate operations. It does not replace a more specific privacy notice, contractual data protection clause or data processing agreement that applies to a particular service, platform or engagement.

3. When IMS UK acts as a processor

In providing Managed Mobility Services, Wireless Expense Management, Telecom Expense Management, device lifecycle services, carrier account support or related services, IMS UK may process personal data on behalf of a business client. That data may include employee names, business mobile numbers, user identifiers, device identifiers, carrier account information, usage information and billing records.

  • In those circumstances:
  • The client will ordinarily be the controller, and IMS UK will ordinarily be the processor.
  • IMS UK will process the personal data only on the client's documented instructions and in accordance with the applicable services agreement and data processing agreement.
  • individuals should ordinarily direct requests relating to that client-controlled data to the client that supplied it.
  • IMS UK may still act as an independent controller for its own corporate purposes, including:
    • Client relationship management
    • Invoicing
    • Legal compliance
    • Information security
    • The establishment, exercise or defence of legal claims

4. Personal data we collect

4.1 Identity and business contact data

  • Name
  • job title and role
  • Employer or organisation
  • Business address
  • email address
  • Telephone number
  • Professional profile information
  • Business relationship information

4.2 Enquiry and communication data

  • Information submitted through contact, consultation, bill-review, or demonstration forms.
  • Service interests and business requirements.
  • The approximate number of mobile lines, devices or telecom accounts managed by an organisation.
  • Current carrier or telecom vendor information.
  • Emails, correspondence, meeting notes and telephone records where lawfully recorded.
  • customer service and support communications.
  • Other information voluntarily provided to us.

4.3 Client, supplier and contractual data

  • Proposal, tender and contracting information
  • Authorised client and supplier contacts
  • Signatures, approvals and audit records
  • Service requirements and project information
  • Billing contacts, purchase orders, invoices and payment records
  • Account administration and service performance records
  • Records needed to manage a commercial relationship

4.4 Mobility, device and telecom data

Where relevant to an enquiry or contracted service, we may process:

  • business mobile telephone numbers and assigned user information;
  • employee or user identifiers;
  • device make, model, serial number and International Mobile Equipment Identity (IMEI);
  • SIM, eSIM and related service identifiers;
  • carrier account numbers, tariffs, plans and service features;
  • billing, usage and cost allocation data;
  • department, cost centre, business unit or location data;
  • device assignment and inventory records;
  • procurement, activation, upgrade, suspension, cancellation and trade-in records; and
  • related support, technical and audit information.

Where this data is processed on behalf of a client, the client is generally responsible for establishing the lawful basis on which it collects and provides the data to IMS UK.

4.5 Website and technical data

  • Internet Protocol (IP) address;
  • browser type and version;
  • device type and operating system;
  • referring website or campaign source;
  • pages viewed and actions taken;
  • date and time of access;
  • website navigation and performance information;
  • security, authentication and diagnostic logs;
  • cookie or similar technology identifiers; and
  • consent and preference records.

Further information is provided in our Cookie Policy.

4.6 Marketing and preference data

  • communication and marketing preferences;
  • consent and withdrawal records;
  • publications, invitations or campaigns sent;
  • responses and engagement information; and
  • opt-out and suppression information.

4.7 Security and legal compliance data

We may process data needed to authenticate users, prevent fraud, detect and investigate cybersecurity threats, respond to suspected misuse, comply with legal or regulatory requirements, or establish, exercise or defend legal rights.

5. Data we do not intend to collect through general website forms

Our website and ordinary business-development activities are not intended to collect:

  • special category data, such as health information, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic or biometric identification data, or information concerning sex life or sexual orientation;
  • criminal conviction or offence data;
  • passwords or personal banking credentials;
  • complete payment-card data; or
  • personal data concerning children.

Please do not submit such information through a general website form. Where sensitive data is genuinely necessary for a specific service, it will be handled through an appropriate contractual, technical and legal process.

6. How we obtain personal data

We may obtain personal data:

  • directly from the individual;
  • from the individual’s employer or another organisation the individual represents;
  • from an IMS client;
  • from telecom carriers, suppliers and service providers;
  • from Iconic Management Solutions, LLC or another IMS group entity;
  • from professional advisers, referral partners and event organisers;
  • from publicly available corporate websites, Companies House records, professional directories or business networking platforms;
  • from lawful and appropriately sourced business-development databases; and
  • automatically through the operation, security and measurement of our website.

Where we obtain personal data from another source, we will provide the privacy information required by applicable law within the required period, unless a lawful exception applies.

7. How and why we use personal data

PurposeTypical lawful basis
Responding to enquiries and arranging consultationsTaking steps requested before entering a contract; legitimate interests in responding to business enquiries
Assessing prospective engagements and preparing proposalsTaking steps requested before entering a contract; legitimate interests in business development
Managing client, carrier, supplier and partner relationshipsContract; legitimate interests in managing professional and commercial relationships
Delivering contracted servicesContract where the individual is a party; legitimate interests; processing on behalf of a client
Managing user, device, billing and carrier data for clientsClient instructions under a data processing agreement; legitimate interests where IMS UK acts as controller
Processing invoices and paymentsContract; legal obligations; legitimate interests in obtaining and recording payment
Maintaining accounting, tax and corporate recordsLegal obligation
Operating, maintaining and securing websites and systemsLegitimate interests in secure and reliable systems; legal obligations
Preventing fraud, misuse and cybersecurity incidentsLegitimate interests; legal obligations; recognised legitimate interests where applicable
Conducting non-exempt website analyticsConsent
Sending service-related communicationsContract; legitimate interests
Sending business-to-business marketingLegitimate interests or consent, depending on the recipient, method and applicable law
Maintaining suppression recordsLegitimate interests and legal compliance
Handling complaints and rights requestsLegal obligation
Establishing, exercising or defending legal claimsLegitimate interests; legal obligation
Complying with lawful requests from authoritiesLegal obligation; recognised legitimate interests where applicable
Evaluating or completing a corporate transactionLegitimate interests, subject to confidentiality and data protection safeguards

Where we rely on legitimate interests, those interests may include operating and developing our business, responding to business enquiries, maintaining business relationships, protecting personnel, clients, systems and property, improving services, maintaining appropriate records, preventing fraud and communicating relevant B2B service information. We consider whether the processing is necessary and proportionate and whether the individual’s rights and interests override those interests.

8. Direct marketing

We may use business contact data to communicate about IMS UK services, events, publications and developments where permitted by law. The rules may differ depending on whether the recipient is a limited company or other corporate subscriber, a sole trader, an unincorporated partnership or an individual acting in a personal capacity. Where consent is required, we will seek valid consent before sending the communication. Where we rely on legitimate interests for B2B marketing, we will use the data proportionately, identify IMS UK, provide a valid and simple opt-out and maintain an appropriate suppression record.

RIGHT TO OBJECT TO DIRECT MARKETING. You have an absolute right to object at any time to the use of your personal data for direct marketing, including related profiling.

You may opt out by using an unsubscribe link, replying to the communication or emailing privacy@iconicms.co.uk. Service, security, contractual and regulatory communications are not marketing and may continue where necessary.

9. Cookies and similar technologies

We use cookies and similar storage or access technologies in accordance with our Cookie Policy. Strictly necessary technologies may operate without consent where legally permitted. Non-exempt analytics, functional, advertising and tracking technologies will not operate until an appropriate choice has been made. Users may change their choices through the Cookie Settings link on the website.

10. Sharing personal data

10.1 IMS group companies

We may share personal data with our parent company, Iconic Management Solutions, LLC, in the United States. It may provide operational, administrative, technical, security, management, reporting, customer-support or business-development assistance. Depending on the activity, the parent may act as a processor, separate controller or joint controller under an appropriate arrangement.

10.2 Service providers

We may engage service providers supporting website hosting and development, cloud infrastructure, email and collaboration, cybersecurity, customer relationship management, analytics, payment administration, accounting, document management, electronic signature, telecommunications, support, data storage and backup. Providers must be subject to appropriate confidentiality, security and data protection obligations.

10.3 Clients, carriers and suppliers

Where necessary to respond to an enquiry or perform services, personal data may be shared with the relevant client, telecom carrier, mobile network operator, device or accessories supplier, fulfilment provider, trade-in vendor, professional adviser or other party involved in the applicable service or transaction.

10.4 Legal and regulatory recipients

We may disclose personal data to courts, law enforcement bodies, regulators, tax authorities, government departments, auditors, insurers and professional advisers where authorised or required by law or reasonably necessary to protect legal rights.

10.5 Corporate transactions

Personal data may be disclosed under appropriate safeguards in connection with a proposed or completed merger, acquisition, financing, restructuring, transfer of business, sale of assets or insolvency process.

11. International transfers

Personal data may be accessed, processed or stored outside the United Kingdom, including in the United States, because IMS UK works with its U.S. parent and may use international service providers.

Where a restricted international transfer is made, we will use a legally recognised transfer mechanism. Depending on the recipient and circumstances, this may include:

  • UK adequacy decisions
  • the UK Extension to the EU-U.S. Data Privacy Framework where the U.S. recipient has an applicable active certification
  • the UK International Data Transfer Agreement
  • the UK Addendum to approved EU Standard Contractual Clauses
  • another approved safeguard or a limited statutory exception where legally available

Where required, we conduct an appropriate transfer risk or data protection assessment and implement supplementary safeguards. Further information about the safeguards used may be requested at privacy@iconicms.co.uk.

12. Retention of personal data

We retain personal data only for as long as reasonably necessary for the applicable purpose, including legal, accounting, security and evidentiary requirements. Our general retention approach is as follows:

Record categoryGeneral retention period
General website enquiries not resulting in an engagementUp to 24 months after the last substantive interaction
Prospect and business-development recordsUp to 24 months after the last meaningful interaction, unless a longer relationship or lawful reason applies
Marketing consent and preference recordsFor as long as the marketing activity continues and as needed to demonstrate compliance
Marketing suppression recordsA minimal record for as long as necessary to honour the objection
Client contracts and principal engagement recordsGenerally 7 years after the engagement ends
Accounting, invoice and tax recordsFor the period required by applicable tax and accounting law
Client service data processed as processorAs directed by the client and specified in the applicable contract or data processing agreement
Website security and access logsNormally up to 12 months, unless required for an investigation or legal matter
Cookie and consent recordsAs stated in the Cookie Policy or consent-management platform
Data protection complaints and rights-request recordsGenerally 6 years after closure, subject to necessity and proportionality
Legal claim and dispute recordsUntil the relevant limitation period expires and any claim is finally resolved

Data may be retained longer where necessary for litigation, a regulatory inquiry, fraud prevention, legal compliance or enforcement of an agreement. Backup copies may remain for a limited period under controlled deletion and disaster-recovery procedures.

13. Your data protection rights

Subject to applicable conditions and exemptions, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request erasure of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object to direct marketing at any time;
  • request portability of certain data in a structured, commonly used and machine-readable format;
  • withdraw consent where processing is based on consent; and
  • request safeguards relating to certain solely automated decisions.

These rights are not absolute and may depend on the purpose, lawful basis and circumstances of the processing. We do not ordinarily charge a fee. A reasonable fee may be charged, or a request refused, where permitted by law because it is manifestly unfounded or excessive. We may request proportionate information to confirm identity and authority before acting on a request.

Requests may be submitted through our Privacy Rights and Data Protection Complaints page or by emailing privacy@iconicms.co.uk.

14. Automated decision-making

IMS UK does not presently use website visitor or business contact data to make decisions based solely on automated processing that produce legal or similarly significant effects. If this changes, we will provide the information and safeguards required by law.

15. Information security

We use proportionate technical and organisational measures designed to protect personal data against unauthorised access, unlawful processing, accidental loss, alteration, disclosure and destruction. Measures may include access controls, authentication, encryption where appropriate, logging and monitoring, vulnerability and patch management, supplier due diligence, confidentiality obligations, security awareness, incident response and backup and recovery controls.

No internet transmission or information system can be guaranteed to be completely secure. Users should not send passwords, payment credentials or unnecessary sensitive information through an ordinary website contact form.

16. Personal data breaches

We maintain procedures for assessing and responding to suspected personal data breaches. Where required by law, we will notify the Information Commissioner’s Office and affected individuals within the applicable statutory periods.

17. Children

Our website and services are directed to organisations and professional users. They are not intended for children under 18. We do not knowingly collect personal data from children through the website. If we become aware that such data has been submitted without an appropriate lawful basis, we will take reasonable steps to delete it.

18. Third-party websites

Our website may contain links to websites operated by third parties. IMS UK is not responsible for the privacy or security practices of third-party websites. Users should review the applicable third-party privacy notice before providing personal data.

19. Data protection complaints

A complaint concerning our use of personal data may be submitted through our Privacy Rights and Data Protection Complaints page, by email to privacy@iconicms.co.uk, or by post to the address stated in section 1.

We will:
  • 1. provide a clear means of making a data protection complaint;
  • 2. acknowledge receipt within 30 days;
  • 3. take appropriate steps to investigate and respond without undue delay;
  • 4. keep the complainant appropriately informed; and
  • 5. communicate the outcome without undue delay.

We encourage individuals to contact us first so that we can investigate and attempt to resolve the matter. You also have the right to complain to the Information Commissioner’s Office (ICO).

  • ICO website: ICO online complaint form
  • ICO helpline: 0303 123 1113
  • ICO postal address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

20. Changes to this Privacy Notice

We may amend this Privacy Notice to reflect changes in law, regulation, our services, technology, suppliers or information-handling practices. The revised notice will be posted on the website with an updated date. Where appropriate, we may provide additional notice of a material change.

View RTLView LTR