- Effective
- 2 August 2026
- Version
- 2.0.0
- Scope
- Clients, contacts, prospects, suppliers, website users and support users
On this page
Corporate Privacy Notice
This notice explains how DM Digital UK Services Ltd uses personal information as a controller in connection with its customers, prospects, suppliers, websites, customer portal, billing, support and business operations.
1. Who we are
DM Digital UK Services Ltd is a company registered in England and Wales under company number 17166861. Our registered office is Hoults Yard, Mailing Exchange, Walker Road, Newcastle upon Tyne, NE5 2HL, United Kingdom. We trade as DM Digital UK and HostedTable.
Data protection enquiries and complaints can be submitted through the authenticated customer or support portal, through HostedTable support where relevant, or by post to the registered office marked “Data Protection”.
2. Scope and roles
This notice applies where we decide why and how personal information is used. Where we process information solely on a business customer’s documented instructions, that customer is normally the controller and our Data Processing Addendum applies.
3. Information we collect
- names, job titles, organisation, contact details and account identifiers;
- contracts, quotations, invoices, payment status, bank mandate references and tax records;
- support tickets, calls, correspondence, complaints, service notes and audit records;
- user accounts, permissions, login, MFA, IP, device, session and security information;
- website, portal, product and communication usage and preferences;
- supplier, contractor and professional-adviser information;
- sales, onboarding, service, asset, project and installation records;
- CCTV or visitor information if someone attends premises or appears in evidence supplied to us;
- publicly available business information and due-diligence information; and
- any other information a person chooses to provide.
4. How we obtain information
We collect information directly from individuals and organisations, through our websites and platforms, from authorised users, payment and identity providers, suppliers, public registers, referrals, professional advisers and security tools.
5. Purposes and lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Quotations, onboarding, contracts and service delivery | Contract, steps requested before contract, and legitimate interests in managing business relationships |
| Billing, credit control, tax and accounting | Contract, legal obligation and legitimate interests in recovering sums due |
| Support, service management and customer communications | Contract and legitimate interests in operating and improving services |
| Security, access control, fraud prevention, abuse investigation and audit | Legitimate interests, legal obligation and recognised legitimate interest where applicable |
| Business-to-business marketing and relationship management | Legitimate interests, consent or soft opt-in as required by PECR |
| Corporate transactions, insurance, legal claims and professional advice | Legitimate interests and legal obligation |
| Compliance with law, regulators, courts and law enforcement | Legal obligation, public task of the recipient or legitimate interests |
Where consent is used, it may be withdrawn at any time without affecting prior processing. Where we rely on legitimate interests, we consider necessity, impact and reasonable expectations.
6. Direct marketing
We may send relevant business-to-business communications to corporate contacts where permitted. Marketing to individuals, sole traders and ordinary partnerships by email or text requires consent or a valid soft opt-in. Every electronic marketing message will identify the sender and provide a valid opt-out route.
Service, security, billing and regulatory messages are not marketing where they are neutral and necessary, but promotional content added to such messages may be treated as marketing.
7. Sharing information
We may share information with:
- employees, contractors and group or successor entities on a need-to-know basis;
- hosting, communications, security, payment, accounting, support and software providers;
- customer organisations and their authorised users;
- banks, payment processors, credit reference, debt recovery and fraud-prevention services;
- professional advisers, auditors, insurers and prospective business purchasers;
- regulators, courts, law enforcement and public authorities where lawful; and
- other parties with consent or where disclosure is reasonably necessary to protect rights, safety or systems.
We do not sell personal information to advertisers.
8. International transfers
Some suppliers may store or access information outside the UK. We use UK adequacy regulations or appropriate safeguards such as the International Data Transfer Agreement or UK Addendum to EU Standard Contractual Clauses where required. We may carry out transfer risk assessments and apply supplementary technical, contractual or organisational controls.
9. Retention
We retain information only for as long as reasonably necessary for the purpose collected, legal and tax obligations, security, disputes, insurance and legitimate business records. The Data Retention Schedule provides our default categories. A legal hold, complaint, fraud investigation or regulatory requirement may extend retention.
10. Security
We use proportionate access control, authentication, logging, segmentation, encryption in transit where appropriate, backup, patching, supplier management and incident-response measures. Security is shared: customers and users must protect devices, accounts and credentials.
11. Individual rights
Subject to conditions and exemptions, individuals may have rights to:
- be informed and obtain access;
- correct inaccurate or incomplete information;
- request erasure or restriction;
- receive portable data in certain circumstances;
- object to direct marketing and certain legitimate-interest processing;
- withdraw consent;
- complain about data protection handling; and
- obtain safeguards relating to significant solely automated decisions.
We may need to verify identity and authority. Rights are not absolute and we may retain information where a legal basis or exemption applies.
12. Data protection complaints
We provide a clear route to raise a data protection complaint. We will acknowledge receipt within 30 days, take appropriate steps to investigate without undue delay, keep the complainant informed and communicate the outcome.
An individual may also complain to the Information Commissioner’s Office. We encourage concerns to be raised with us first so we can investigate.
13. Automated processing
We may use automation to route tickets, identify security anomalies, match customer records, assess service usage or assist fraud prevention. We do not ordinarily make decisions producing legal or similarly significant effects solely by automated means without an appropriate lawful basis and safeguards.
14. Children
Our business services are not directed to children. HostedTable may process children’s booking-party information supplied by an adult, but children should not independently create accounts or submit personal information unless the service expressly supports it and appropriate protections are in place.
15. Changes
We may update this notice to reflect law, guidance, services and processing. Material changes will be highlighted through the Legal Hub or relevant service.
Legal notices
Formal notices must be sent using the notice method stated in the applicable Order or through the authenticated customer portal. Where no method is stated, notices may be delivered to the registered office above. Operational support messages are not formal legal notices unless expressly identified as such.
Contracting entity: DM Digital UK Services Ltd, company number 17166861, registered office Hoults Yard, Mailing Exchange, Walker Road, Newcastle upon Tyne, NE5 2HL, United Kingdom.
