Roaming Intelligence Limited –
Data Protection Policy

Company: Roaming Intelligence Limited
Company Number: 139261C
Policy Owner: Roaming Intelligence Limited
Effective Date: 26 August 2026
Review Frequency: At least annually
Version: 1.0

1. Purpose

Roaming Intelligence Limited is committed to protecting personal data and maintaining appropriate standards of privacy, security and information governance.

This Data Protection Policy establishes the principles and procedures Roaming Intelligence will follow when collecting, accessing, storing, using, analysing, sharing, transferring and deleting personal data.

2. Scope

This policy applies to personal data processed by Roaming Intelligence in connection with its activities, including information relating to:

  • customers;
  • prospective customers;
  • customer employees and authorised users;
  • suppliers;
  • partners;
  • contractors;
  • website users;
  • business contacts; and
  • other individuals whose personal data we process.

It applies to personal data held electronically or in physical form.

3. Company Details

Roaming Intelligence LimitedCompany Number: 139261C

Registered Office:Fairhaven118 Woodbourne RoadDouglasIM2 3BAIsle of Man

Website: www.roamingintelligence.com

Data Protection Contact:info@roamingintelligence.com

4. Applicable Legislation

Roaming Intelligence will process personal data in accordance with applicable Isle of Man data protection legislation, including:

  • the Data Protection Act 2018;
  • the Data Protection (Application of GDPR) Order 2018;
  • the GDPR and LED Implementing Regulations 2018; and
  • applicable amendments, regulations and successor legislation.

The GDPR as applied in Isle of Man law is referred to in this policy as the Applied GDPR.

5. Data Protection Principles

Roaming Intelligence will seek to ensure that personal data is processed in accordance with the following principles.

Lawfulness, Fairness and Transparency

Personal data must be processed lawfully, fairly and transparently.

Individuals should be provided with appropriate information about how and why their information is used.

Purpose Limitation

Personal data must be collected for specified, explicit and legitimate purposes and not subsequently processed in a manner incompatible with those purposes.

Data Minimisation

Personal data must be adequate, relevant and limited to what is reasonably necessary for the relevant purpose.

Accuracy

Reasonable steps must be taken to ensure personal information is accurate and, where necessary, kept current.

Storage Limitation

Personal data must not be retained for longer than reasonably necessary.

Integrity and Confidentiality

Appropriate security must be maintained to protect personal data against unauthorised or unlawful processing and accidental loss, destruction or damage.

Accountability

Roaming Intelligence must be able to demonstrate appropriate compliance with applicable data-protection requirements.

6. Controller and Processor Responsibilities

Roaming Intelligence may act as either a data controller or data processor depending upon the service and processing activity concerned.

Where Roaming Intelligence determines the purposes and means of processing personal data, it acts as controller.

Where Roaming Intelligence processes personal data on documented instructions from an enterprise customer or other organisation, it may act as processor.

Where acting as processor, appropriate contractual arrangements must be maintained with the relevant controller.

Where appropriate, relationships with subprocessors must also be appropriately documented and managed.

7. Lawful Processing

Personal data must only be processed where an appropriate lawful basis has been identified.

Depending upon the activity, this may include:

  • performance of a contract;
  • taking steps prior to entering into a contract;
  • legitimate interests;
  • compliance with a legal obligation;
  • consent; or
  • another lawful basis permitted by applicable legislation.

Where consent is relied upon, consent must be capable of being demonstrated and withdrawn where required.

8. Data Minimisation

Roaming Intelligence will seek to minimise the personal data it processes.

Only personal data reasonably necessary to deliver the relevant service or fulfil another legitimate purpose should be collected or accessed.

Where aggregate, anonymised or pseudonymised information can reasonably fulfil the business requirement, its use should be considered.

This is particularly relevant when analysing:

  • enterprise roaming expenditure;
  • connectivity usage;
  • eSIM allocation;
  • destination information; and
  • workforce travel or connectivity patterns.

9. Enterprise Connectivity and eSIM Data

Roaming Intelligence services may involve information associated with enterprise connectivity and eSIM services.

Depending upon the particular service, this could include:

  • employee names;
  • employee identifiers;
  • business email addresses;
  • business mobile numbers;
  • eSIM identifiers;
  • connectivity allocations;
  • usage information;
  • destination or country information;
  • activation information;
  • service status information; and
  • service and support records.

Such information must only be accessed and processed where reasonably necessary to provide or administer the relevant service.

Enterprise customers should be encouraged not to provide unnecessary personal information.

10. Access Controls

Access to personal data must be restricted to authorised individuals who reasonably require access for legitimate business purposes.

Where appropriate, Roaming Intelligence will use measures including:

  • individual user accounts;
  • strong passwords;
  • multi-factor authentication;
  • role-based access controls;
  • controlled administrator permissions;
  • secure password management;
  • endpoint and device security;
  • encryption;
  • secure cloud services; and
  • prompt revocation of access when no longer required.

Administrative or privileged access should be limited wherever reasonably practicable.

11. Suppliers, Processors and Subprocessors

Before appointing material service providers that process personal data, Roaming Intelligence will consider the provider's ability to maintain appropriate privacy and security standards.

Where required, contractual provisions should address matters including:

  • subject matter and duration of processing;
  • nature and purpose of processing;
  • categories of personal data;
  • categories of data subjects;
  • documented processing instructions;
  • confidentiality;
  • information security;
  • subprocessors;
  • international transfers;
  • data-subject rights;
  • personal-data breaches;
  • deletion or return of information; and
  • appropriate compliance or audit information.

12. International Transfers

Personal data must not be transferred internationally in a manner inconsistent with applicable Isle of Man data protection legislation.

Before relevant international transfers occur, Roaming Intelligence will determine whether an appropriate legal mechanism or safeguard is required.

Particular attention should be given to international transfers associated with:

  • mobile network operators;
  • global connectivity providers;
  • eSIM platforms;
  • cloud infrastructure;
  • CRM systems;
  • artificial-intelligence services;
  • messaging platforms; and
  • enterprise integrations.

13. Individual Rights

Roaming Intelligence will maintain processes for identifying and responding to individuals exercising applicable data protection rights.

Requests may relate to:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability;
  • withdrawal of consent; or
  • automated decision-making.

Requests should be handled promptly and in accordance with applicable statutory requirements.

Identity verification may be required where appropriate.

Requests received at info@roamingintelligence.com that relate to data protection must be identified and handled appropriately.

14. Data Protection by Design and Default

Privacy and data-protection considerations should be incorporated into new products, services, systems and business processes from the outset.

When developing or introducing new services, Roaming Intelligence should consider:

  • what information is required;
  • why it is required;
  • the lawful basis for processing;
  • who can access it;
  • where it will be stored;
  • how long it will be retained;
  • which third parties will receive it;
  • whether it will be transferred internationally; and
  • how it will be secured.

15. Data Protection Impact Assessments

Before introducing processing that may create an elevated risk to individuals, Roaming Intelligence will consider whether a Data Protection Impact Assessment ("DPIA") is required.

Particular consideration should be given to services involving:

  • systematic employee monitoring;
  • detailed location information;
  • travel-pattern information;
  • large-scale connectivity usage information;
  • automated decision-making;
  • profiling;
  • significant enterprise integrations;
  • artificial-intelligence processing; or
  • new categories or combinations of personal data.

16. Personal Data Breaches

Any actual or suspected personal data breach must be investigated promptly.

The response should include, where appropriate:

  1. containing the incident;
  2. identifying affected systems and information;
  3. determining the categories and number of individuals potentially affected;
  4. assessing likely consequences;
  5. documenting the incident;
  6. correcting or mitigating the vulnerability;
  7. determining whether regulatory notification is required;
  8. determining whether affected individuals must be notified; and
  9. implementing measures intended to prevent recurrence.

Where required by applicable legislation, Roaming Intelligence will notify the Isle of Man Information Commissioner and/or affected individuals within the applicable statutory requirements.

17. Retention and Disposal

Personal data must only be retained for as long as reasonably required for the relevant:

  • business;
  • contractual;
  • legal;
  • regulatory;
  • accounting; or
  • dispute-resolution purpose.

Roaming Intelligence should maintain appropriate retention practices covering categories including:

  • customer records;
  • contracts;
  • invoices and financial records;
  • consultancy documentation;
  • eSIM records;
  • connectivity records;
  • support records;
  • enquiries;
  • marketing information;
  • supplier information; and
  • website information.

Information reaching the end of its applicable retention period should be securely deleted, destroyed or anonymised where appropriate.

18. Information Security

Roaming Intelligence will maintain technical and organisational security measures proportionate to:

  • the sensitivity of the information;
  • the volume of information processed;
  • the nature and purpose of processing;
  • the potential consequences of a security incident; and
  • recognised and appropriate security practices.

Security controls should be periodically reviewed.

19. Staff and Contractors

Anyone authorised to process personal data on behalf of Roaming Intelligence must:

  • maintain appropriate confidentiality;
  • comply with this policy;
  • use personal data only for authorised purposes;
  • comply with applicable security requirements;
  • protect account credentials;
  • avoid unauthorised sharing of information; and
  • report suspected security or data-protection incidents promptly.

20. Direct Marketing

Personal data used for direct marketing must be processed in accordance with applicable data protection and electronic communications requirements.

Marketing preferences, unsubscribe requests and objections must be respected.

21. Record Keeping and Accountability

Roaming Intelligence will maintain records proportionate to its processing activities and legal obligations.

Where appropriate, these may include:

  • records of processing activities;
  • data-processing agreements;
  • subprocessor records;
  • privacy notices;
  • consent records;
  • legitimate-interest assessments;
  • Data Protection Impact Assessments;
  • personal-data breach records;
  • data-subject request records;
  • retention schedules;
  • supplier assessments; and
  • international transfer assessments.

22. Compliance Reviews

Roaming Intelligence should periodically review its processing activities, suppliers, technology platforms and security arrangements to ensure this policy continues to reflect its operations.

Material changes to products or data flows should trigger an additional privacy review where appropriate.

23. Policy Review

This policy will be reviewed at least annually and following significant changes to:

  • applicable legislation;
  • Roaming Intelligence services;
  • processing activities;
  • technology platforms;
  • suppliers;
  • business operations; or
  • material privacy or security risks.

24. Responsibility

Overall responsibility for data-protection compliance rests with:

Roaming Intelligence Limited

Registered Office:Fairhaven118 Woodbourne RoadDouglasIM2 3BAIsle of Man

Company Number: 139261C

Data Protection Contact:info@roamingintelligence.com

Website:www.roamingintelligence.com

Questions, concerns, data-protection requests or suspected personal-data breaches should be reported to the above contact without undue delay.