Privacy & data Policy

Onnec Group has been at the vanguard of IT infrastructure and support for more than 30 years. Our company is made up of several limited company subsidiaries, supported by a central services function. As a provider of information technology and associated services we operate across largely regulated markets in the private and public sectors, primarily our employees work across our operations in the UK & Europe, with service provision across other continents such as Asia, Africa, North America, South America and Australia.

Maintaining data privacy and data protection is a priority for Onnec Group. This policy sets out the legal basis on which any personal data is processed by Onnec Group or its subsidiaries. Please read this policy carefully to understand our views and practices regarding your personal data and how we will treat it.

This policy applies to Onnec Group and its subsidiaries, those company’s employees, contractors, subcontractors, vendors and clients where Onnec Group has access to, or holds information of an individual’s personal data. This policy sets out how we capture, store and treat the personal information we use in our daily activities.

Personal Data

According to The General Data Protection Regulations (GDPR), all personal data we hold must be:

  • Processed lawfully, fairly and in a transparent manner
  • Collected for specified, explicit and legitimate purposes
  • Adequate, relevant and limited to what is necessary
  • Accurate and, where necessary, kept up-to-date
  • Retained only for as long as necessary
  • Processed in an appropriate manner to maintain security

Onnec Group has assessed the six grounds for lawful processing of personal data under GDPR and has selected ‘Legitimate Interests’ as the most suitable lawful ground for the processing of data. We believe that the individuals whose data we process are likely to have an interest in Onnec Group services. This is typically based upon specific criteria including the business industry sector, size of organisation as well as the individual’s job function within the organisation. Our typical segmentation includes those within IT, operations, facilities and real estate roles, although this list is not exhaustive and other variables may apply.

  • Information you consent to provide Onnec Group that is required to carry out our obligations arising from any contracts entered between you and us, or potential contracts that may be in liaison between you and us.
  • Information that you consent to provide by filling in forms on our website, or as part of any direct marketing or sales activities. This includes and is not limited to personal information about you such as your name, telephone contact number, geographical address/location, email address and interests.
  • If you contact us by telephone or in writing, we may keep a copy of your correspondence or communication.
  • Details of your visits to our website and the resources that you access (link to cookie policy).

We will only ever collect, process and store the essential information required for contacting individuals within a business environment. The personal data we collect is limited to first name, last name, email address, social profiles, business IP address, business name, job function and address.

We will not process or hold any data irrelevant to the purposes of doing business with you, nor any special category data, including: race; ethnic origin; political opinions; religion; philosophical beliefs; trade union membership; health data; concerning a natural person’s sex life; or sexual orientation.

The data we collect will be used to communicate messages relating to the services of Onnec via email, social media, telephone or any other business to business (B2B) marketing methods that may be relevant. You have the right to object from any method of correspondence at any time via the methods detailed below.

We use information held about you to carry out our obligations arising from any contracts entered between you and us; and to notify you about changes to our services. At Onnec Group we procure data in a variety of ways, collected in line with the lawful basis of ‘Legitimate Interests’.  If you have received correspondence from us, we will have procured your data in one of the following ways:

  • You have requested information from Onnec Group on a previous occasion
  • Someone has sent us your e-mail address requesting information about our articles and/or services be sent to you
  • There is a contract in place between you and Onnec Group
  • You or someone else has expressly shared your contact details with us for the purpose of receiving information now and/or in the future
  • We have previously met at an event and your business card or contact details were handed to us willingly
  • You or a business colleague has visited our website and we believe that there is a genuine legitimate interest in our services
  • You have previously connected with a member of our team and discussed our services
  • A member of our team has found your business and your contact details online, believing that your business would genuinely be interested in the services of Onnec, based on your job function aligning with our typical customer profiles they have made contact to introduce you to our product
  • Your data has been purchased from a registered third-party data supplier, and will have been segmented by industry, organisation size and job function based upon our typical customer profiles (due diligence checks around GDPR compliance will have been conducted accordingly)

Per the ICO guidance, Onnec Group UK Ltd can confirm:

  • We have checked that legitimate interests are the most appropriate basis
  • We understand our responsibility to protect the individual’s interests
  • We have conducted a legitimate interest’s assessment (LIA) and kept a record of it, to ensure that we can justify our decision
  • We have identified the relevant legitimate interests
  • We have checked that the processing is necessary and there is no less intrusive way to achieve the same result
  • We have done a balancing test, and are confident that the individual’s interests do not override those legitimate interests
  • We only use individuals’ data in ways they would reasonably expect
  • We are not using people’s data in ways they would find intrusive or which could cause them harm
  • We do not process the data of children
  • We have considered safeguards to reduce the impact where possible
  • We will always ensure there is an opt-out / ability to object
  • Our LIA did not identify a significant privacy impact, and therefore we do not require a DPIA
  • We keep our LIA under review every six months, and will repeat it if circumstances change
  • We include information about our legitimate interests in our privacy notice

Using your personal information

Data submitted to us via our website will be used for the purposes specified in this privacy policy or in relevant parts of our website.

We may use this data to:

  • administer the website;
  • improve your browsing experience by personalising the website;
  • enable your use of the services available on the website;
  • send you general (non-marketing) commercial communications;
  • send to you marketing communications relating to our business which we think may be of interest to you by post, email or similar technology;
  • send you email notifications which you have specifically requested;
  • provide third parties with statistical information about our users – but this information will not be used to identify any individual user;
  • deal with enquiries and complaints made by or about you relating to the website; and
  • keep our website secure and prevent fraud.

third party processors

Our carefully selected partners and service providers may process personal information about you on our behalf as described below:

Digital Marketing Service Providers
We periodically appoint digital marketing agents to conduct marketing activity on our behalf, such activity may result in the compliant processing of personal information. Our appointed data processors include:
(i) Prospect Global Ltd (trading as Sopro) Reg. UK Co. 09648733. You can contact Sopro and view their privacy policy here: Sopro are registered with the ICO Reg: ZA346877 their Data Protection Officer can be emailed at:”


We may disclose information about you to any of our employees, officers, agents, suppliers or subcontractors insofar as reasonably necessary for the purposes as set out in this privacy policy. In addition, we may disclose your personal information:

  • to the extent that we are required to do so by law;
  • in connection with any legal proceedings or prospective legal proceedings;
  • in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk);
  • to the purchaser (or prospective purchaser) of any business or asset that we are (or are contemplating) selling; and
  • to any person who we reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in our reasonable opinion, such court or authority would be reasonably likely to order disclosure of that personal information.

Except as provided in this privacy policy, we will never provide your information to third parties.

Storage, security and retention of your personal information

We will take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your data.

The personal data we hold in accordance with the policies above will be stored on secure servers our CRM platform, email or marketing software.

We will retain the personal data we hold for as long as we consider it necessary for working with you, selling and marketing our services, or to comply with any legal obligations, and then we will securely delete your data. We will delete your data at an earlier date if you request it.

You have the right to rectification, erasure, restriction and objection.

You may instruct us to provide you with any data we hold about you via a subject access request. Provision of such information will be subject to the supply of appropriate evidence of your identity (for this purpose, we will usually accept a photocopy of your passport certified by a solicitor or bank plus an original copy of a utility bill showing your current address). We may withhold such personal information to the extent permitted by law. We may also refuse nuisance requests, where a person requests their data excessively on multiple occasions without legitimate reason.

You can at any time request that the information we hold about you is updated or corrected.

In all correspondence with you we will give you the right to object from receiving further correspondence from Onnec Group.  On any emails you receive from Onnec Group there will be the option to ‘unsubscribe’ from receiving any further email correspondence.  If you receive a telephone call from us, you have the right to request not to receive any further calls.

You can also make any request for rectification, erasure, restriction and objection by emailing or by writing to: Onnec Group, 2nd Floor Farringdon Point, 33 Farrington Street, London EC1M 3JF.

All requests will be processed within 30 days. Your details will be added to a suppression file to ensure that your details cannot be processed by Onnec Group systems in the future.

It is important to understand the difference between a right to object and a request for deletion.  If you make a request for deletion, we will remove any data we hold about you from our systems.  This will also mean that we will remove you from our suppression files.  If you are removed from our suppression files, there is a risk that your data may be processed again in the future if your details are re-added to our system by a member of our team who genuinely believes that you would benefit from the Onnec Group services.  If you do not wish for us to contact you again about Onnec Group, we would recommend you request to object rather than a request for deletion, as this will ensure that your details are always suppressed from processing.

Onnec Group website

Our website uses cookies. We will notify you of this when you first visit our website and provide a link to our complete Cookie Policy, which includes details of which cookies are used and how to prevent their use. Click here for the Cookie Policy.

The website also contains links to other websites. We are not responsible for the privacy policies or practices of third-party websites.

A privacy event: A privacy event is the unauthorised or inappropriate access, use, destruction or disclosure of personal information, that is collected, processed or maintained by Onnec Group or by a third party on behalf of Onnec Group.

Procedures for the escalation of a privacy event: Any such events must be reported within twenty-four hours to Our compliance team will, following the receipt of the email, action the event in accordance with the current policies, procedures, agreed contracts, and legislation.

Security threats, incidents and suspicions must be reported immediately to the IT Helpdesk

Procedures for monitoring and resolution of an event: It is Onnec Group’s policy to log, monitor and resolve where practicable all events reported to the compliance team. Each ticket will be monitored by the Compliance Director and escalated to key stakeholders, the ticket will also remain active on the database until a satisfactory resolution has been found and agreed by all parties.

Changes to our Privacy Policy

Any changes we may make to our Privacy Policy in the future will be posted on our website. Any queries relating to data privacy with Onnec or this policy should be sent by email to, or by writing to the Data Protection Officer, Onnec Group UK Limited, 2nd Floor Farringdon Point, 33 Farringdon Street, London EC1M 3JF. Alternatively, you can call our Data Protection Officer on 0203 929 9915

For and on behalf of:

Onnec Group