Company: Roaming Intelligence Limited
Company Number: 139261C
Policy Owner: Roaming Intelligence Limited
Effective Date: 26 August 2026
Review Frequency: At least annually
Version: 1.0
Roaming Intelligence Limited is committed to protecting personal data and maintaining appropriate standards of privacy, security and information governance.
This Data Protection Policy establishes the principles and procedures Roaming Intelligence will follow when collecting, accessing, storing, using, analysing, sharing, transferring and deleting personal data.
This policy applies to personal data processed by Roaming Intelligence in connection with its activities, including information relating to:
It applies to personal data held electronically or in physical form.
Roaming Intelligence LimitedCompany Number: 139261C
Registered Office:Fairhaven118 Woodbourne RoadDouglasIM2 3BAIsle of Man
Website: www.roamingintelligence.com
Data Protection Contact:info@roamingintelligence.com
Roaming Intelligence will process personal data in accordance with applicable Isle of Man data protection legislation, including:
The GDPR as applied in Isle of Man law is referred to in this policy as the Applied GDPR.
Roaming Intelligence will seek to ensure that personal data is processed in accordance with the following principles.
Personal data must be processed lawfully, fairly and transparently.
Individuals should be provided with appropriate information about how and why their information is used.
Personal data must be collected for specified, explicit and legitimate purposes and not subsequently processed in a manner incompatible with those purposes.
Personal data must be adequate, relevant and limited to what is reasonably necessary for the relevant purpose.
Reasonable steps must be taken to ensure personal information is accurate and, where necessary, kept current.
Personal data must not be retained for longer than reasonably necessary.
Appropriate security must be maintained to protect personal data against unauthorised or unlawful processing and accidental loss, destruction or damage.
Roaming Intelligence must be able to demonstrate appropriate compliance with applicable data-protection requirements.
Roaming Intelligence may act as either a data controller or data processor depending upon the service and processing activity concerned.
Where Roaming Intelligence determines the purposes and means of processing personal data, it acts as controller.
Where Roaming Intelligence processes personal data on documented instructions from an enterprise customer or other organisation, it may act as processor.
Where acting as processor, appropriate contractual arrangements must be maintained with the relevant controller.
Where appropriate, relationships with subprocessors must also be appropriately documented and managed.
Personal data must only be processed where an appropriate lawful basis has been identified.
Depending upon the activity, this may include:
Where consent is relied upon, consent must be capable of being demonstrated and withdrawn where required.
Roaming Intelligence will seek to minimise the personal data it processes.
Only personal data reasonably necessary to deliver the relevant service or fulfil another legitimate purpose should be collected or accessed.
Where aggregate, anonymised or pseudonymised information can reasonably fulfil the business requirement, its use should be considered.
This is particularly relevant when analysing:
Roaming Intelligence services may involve information associated with enterprise connectivity and eSIM services.
Depending upon the particular service, this could include:
Such information must only be accessed and processed where reasonably necessary to provide or administer the relevant service.
Enterprise customers should be encouraged not to provide unnecessary personal information.
Access to personal data must be restricted to authorised individuals who reasonably require access for legitimate business purposes.
Where appropriate, Roaming Intelligence will use measures including:
Administrative or privileged access should be limited wherever reasonably practicable.
Before appointing material service providers that process personal data, Roaming Intelligence will consider the provider's ability to maintain appropriate privacy and security standards.
Where required, contractual provisions should address matters including:
Personal data must not be transferred internationally in a manner inconsistent with applicable Isle of Man data protection legislation.
Before relevant international transfers occur, Roaming Intelligence will determine whether an appropriate legal mechanism or safeguard is required.
Particular attention should be given to international transfers associated with:
Roaming Intelligence will maintain processes for identifying and responding to individuals exercising applicable data protection rights.
Requests may relate to:
Requests should be handled promptly and in accordance with applicable statutory requirements.
Identity verification may be required where appropriate.
Requests received at info@roamingintelligence.com that relate to data protection must be identified and handled appropriately.
Privacy and data-protection considerations should be incorporated into new products, services, systems and business processes from the outset.
When developing or introducing new services, Roaming Intelligence should consider:
Before introducing processing that may create an elevated risk to individuals, Roaming Intelligence will consider whether a Data Protection Impact Assessment ("DPIA") is required.
Particular consideration should be given to services involving:
Any actual or suspected personal data breach must be investigated promptly.
The response should include, where appropriate:
Where required by applicable legislation, Roaming Intelligence will notify the Isle of Man Information Commissioner and/or affected individuals within the applicable statutory requirements.
Personal data must only be retained for as long as reasonably required for the relevant:
Roaming Intelligence should maintain appropriate retention practices covering categories including:
Information reaching the end of its applicable retention period should be securely deleted, destroyed or anonymised where appropriate.
Roaming Intelligence will maintain technical and organisational security measures proportionate to:
Security controls should be periodically reviewed.
Anyone authorised to process personal data on behalf of Roaming Intelligence must:
Personal data used for direct marketing must be processed in accordance with applicable data protection and electronic communications requirements.
Marketing preferences, unsubscribe requests and objections must be respected.
Roaming Intelligence will maintain records proportionate to its processing activities and legal obligations.
Where appropriate, these may include:
Roaming Intelligence should periodically review its processing activities, suppliers, technology platforms and security arrangements to ensure this policy continues to reflect its operations.
Material changes to products or data flows should trigger an additional privacy review where appropriate.
This policy will be reviewed at least annually and following significant changes to:
Overall responsibility for data-protection compliance rests with:
Roaming Intelligence Limited
Registered Office:Fairhaven118 Woodbourne RoadDouglasIM2 3BAIsle of Man
Company Number: 139261C
Data Protection Contact:info@roamingintelligence.com
Website:www.roamingintelligence.com
Questions, concerns, data-protection requests or suspected personal-data breaches should be reported to the above contact without undue delay.