Privacy Policy
This Privacy Policy explains how we collect, use, store and protect personal data in connection with our website, our commercial relationships and our email and SMS marketing campaign services.
1. Who we are
For the purposes of applicable data protection laws, including the UK GDPR, the EU GDPR where applicable, and the Data Protection Act 2018, the controller of the personal data described in this Privacy Policy is DMS Europe Ltd.
We have not appointed a formal Data Protection Officer. However, any question relating to privacy or data protection can be sent to our privacy contact address.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed in connection with our website, our contact and quotation forms, our commercial exchanges, our customer relationships, our newsletters, our campaign services and our opt-in audiences.
It also explains how we process personal data when we send email or SMS marketing campaigns to our own opt-in audiences on behalf of business customers, without transferring contact files to those customers.
Separate cookie information may be provided in our Cookie Policy, where applicable.
3. Who this policy applies to
This Privacy Policy applies to website visitors, people who contact us, newsletter subscribers, prospects, customers, representatives of customers or agencies, users of our services and people included in our opt-in audiences.
It may also apply to recipients of marketing campaigns routed by us on our own audiences, including individuals who receive an email or SMS campaign, click on a link, unsubscribe, send a STOP SMS request or submit a complaint.
4. Personal data we collect
The personal data we collect depends on the relationship we have with the individual and the context in which the data is processed.
For website visitors, prospects and people who contact us, we may process identification and contact details, such as first name, last name, business email address, phone number, company name, job title, country, language, message content, requested service, campaign requirements and any information voluntarily submitted through our forms.
For customers, agencies and business contacts, we may process business identity data, billing details, order details, campaign parameters, selected countries, target volumes, selected products, targeting criteria, budget information, website URLs, landing page URLs, creative assets, commercial content, communication history, support requests, contractual documents, invoices, payment status, account information and service usage information.
For people included in our opt-in audiences, we may process, depending on the data available and the relevant consent, contact details, demographic information, country, geographical area, age range, gender, socio-professional category, housing-related information, interests, commercial preferences, property-related interests, automotive interests, interaction history, campaign exposure history, email engagement data, SMS delivery status, unsubscribe status, SMS STOP status, complaint information, consent records, source of registration, timestamp, IP address, form or registration context and proof of consent.
We may also process technical data such as IP address, browser type, device information, operating system, language, pages viewed, logs, timestamps, security events and cookie-related identifiers where applicable.
5. How we collect personal data
We may collect personal data directly from individuals when they fill in a form, contact us, request an estimate, subscribe to a newsletter, interact with our website, communicate with us or use our services.
We may also collect personal data through our own opt-in audience acquisition processes, registration forms, preference forms, consent mechanisms, campaign interactions, unsubscribe links, SMS STOP messages, complaints and technical systems.
In the context of customer campaigns, customers may provide us with campaign content, commercial information, landing page links, targeting instructions and other materials necessary for campaign preparation and routing. However, our standard service does not require customers to provide us with their own contact databases.
6. Why we use personal data and lawful bases
We use personal data to respond to enquiries, prepare quotations, manage commercial discussions, create and execute campaigns, provide customer support, manage billing, maintain business records and operate our services.
We also use personal data to manage opt-in audiences, route email and SMS campaigns, apply targeting criteria, manage unsubscribes, process SMS STOP requests, handle complaints, maintain suppression lists, keep proof of consent and demonstrate compliance where necessary.
The lawful bases we rely on may include consent, where a person subscribes to a newsletter or agrees to receive marketing communications; contract or steps prior to entering into a contract, where we respond to a commercial request or provide services to a customer; legitimate interests, where we manage our business, secure our services, respond to professional enquiries or maintain compliance records; and legal obligation, where we must keep records, manage objections or respond to lawful requests.
For email and SMS marketing campaigns sent to individuals in our B2C audiences, we rely on consent where required by applicable electronic communications and data protection laws.
7. Marketing campaigns sent to our opt-in audiences
For campaigns sent to our own opt-in audiences, we act as controller for the audience data and for the routing of the campaign. We do not sell, rent or deliver contact files to our customers.
Customers select targeting criteria, campaign parameters, channels and volumes, but the technical routing is carried out by us or by technical providers acting under our instructions.
We may use personal data in our audiences to select relevant recipients, send the campaign, record delivery and interaction events, manage unsubscribes, process SMS STOP requests, suppress contacts from future campaigns and respond to complaints or regulatory requests.
We may keep evidence of consent and related compliance records for the duration of the processing concerned and for up to five years after the end of the relevant processing, where this is necessary to demonstrate compliance, manage complaints, defend legal claims or respond to competent authorities.
8. Customers’ landing pages and lead collection
Campaigns routed by us may direct recipients to a landing page, website, form or digital environment operated by the customer or by a third party selected by the customer.
The customer is responsible for the content of the campaign, the promoted offer, the landing page, any form displayed after a click, and any personal data collected from individuals after they leave our campaign environment.
When a recipient clicks on a campaign and submits information on a customer’s page or form, the customer is responsible for providing the required privacy information, identifying the appropriate lawful basis, collecting any required consent and respecting the rights of the individuals concerned.
11. International transfers
Personal data may be processed in the United Kingdom, the European Economic Area and other countries where we or our service providers operate.
Where personal data is transferred outside the United Kingdom, the European Economic Area or the country of residence of the relevant individual, we ensure that an appropriate transfer mechanism is in place where required.
Such mechanisms may include adequacy regulations or adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard recognised by applicable data protection laws.
12. How long we keep personal data
We keep personal data only for as long as necessary for the purposes for which it was collected, including to provide our services, manage our business, comply with legal obligations, resolve disputes and demonstrate compliance.
Contact requests and prospect data may generally be kept for up to three years after the last meaningful interaction, unless a longer period is justified by an ongoing relationship, legal requirement or dispute.
Customer, contractual, billing and accounting records may be kept for the duration of the business relationship and for up to six years afterwards, or for any longer period required by applicable law.
Technical logs are generally kept for a limited period, usually between six and twelve months, unless longer retention is necessary for security, fraud prevention, investigation or legal purposes.
Unsubscribe, objection and SMS STOP records may be kept for as long as necessary to ensure that the person is not contacted again in breach of their request.
Consent evidence and related compliance records may be kept for the duration of the relevant processing and for up to five years after the end of that processing, where necessary to demonstrate compliance, manage complaints or defend legal claims.
13. Your rights
Depending on the applicable law and the circumstances, individuals may have the right to request access to their personal data, ask for inaccurate data to be corrected, request erasure, request restriction of processing, object to processing, request data portability or withdraw consent where processing is based on consent.
These rights are not absolute and may be subject to conditions, limitations or exemptions under applicable data protection laws. For example, we may need to retain certain information to comply with legal obligations, maintain suppression lists, demonstrate consent or defend legal claims.
To exercise a privacy right, individuals can contact us at privacy@dmseurope.com. We may need to verify the identity of the person making the request before responding.
14. Unsubscribes and SMS STOP requests
Individuals who receive an email campaign routed by us can use the unsubscribe link included in the message, where available, or contact us to request removal from future marketing campaigns.
Individuals who receive an SMS campaign can follow the STOP instructions provided in the message, where available. We process SMS STOP requests and apply suppression measures to prevent future marketing messages where required.
Suppression records are maintained to ensure that unsubscribe, objection and STOP requests are respected over time.
15. Security
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, unlawful processing, accidental loss, destruction or damage.
These measures may include access controls, confidentiality obligations, secure hosting, encryption or pseudonymisation where appropriate, monitoring, backups, provider due diligence and internal procedures designed to reduce privacy and security risks.
No system can be guaranteed to be completely secure. However, we work to maintain a level of security appropriate to the nature of the personal data processed and the risks involved.
16. Complaints
Individuals can contact us at privacy@dmseurope.com if they have any question or concern about how we process personal data.
Individuals also have the right to lodge a complaint with the UK Information Commissioner’s Office, or with their local data protection authority where applicable.
We encourage individuals to contact us first so that we can review and address the concern where possible.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, our processing activities, legal requirements or operational practices.
The updated version will be published on this page. Where changes are material, we may take additional steps to inform affected individuals where required by applicable law.
18. Contact
For any question about this Privacy Policy, our processing of personal data, unsubscribe requests, SMS STOP requests, complaints or the exercise of privacy rights, individuals can contact us by email.
Contact us about privacy