FMIS Privacy Policy
How FMIS collects, uses, protects and manages your personal information and privacy rights.
How FMIS collects, uses, protects and manages your personal information and privacy rights.
Your privacy is important. Financial and Management Information Systems Limited (FMIS) explains here how we collect, use and protect personal information and how you can exercise your rights. We comply with applicable data protection law, including the UK GDPR and Data Protection Act 2018, as amended, and the Privacy and Electronic Communications Regulations where relevant.
Last updated: September 2026. We review this notice regularly and update it when our processing changes. Where required, we will bring material changes to your attention before further processing.
Further information about our security, compliance and data protection arrangements is available through the FMIS Trust Centre.
FMIS is a controller for its own business activities, including enquiries, customer and supplier relationships, marketing, recruitment, employment and security administration. This notice covers those activities. Further information may be provided when information is collected for a particular purpose.
For customer personal data handled under our Data Processing Agreement, the customer is normally the controller and FMIS acts as processor on its documented instructions. The customer’s privacy information explains its purposes and lawful bases.
This notice does not give FMIS permission to use customer-controlled data for its own marketing or other unrelated purposes. Requests concerning that data are referred to the customer, with assistance from FMIS under the applicable agreement.
Depending on your relationship with FMIS, we may collect:
We collect information directly through forms, email, telephone, meetings and our services, and automatically through website and security technologies.
Where relevant, we may receive business contact or support information from your employer, colleagues, customers or referral partners, and recruitment information from recruiters and referees. If we obtain information from other sources, including public sources where used, we provide the source and other required privacy information within the applicable legal timeframe, unless an exemption applies.
Where information is required by law or necessary to enter into or perform a contract, we explain this and the consequences of not providing it. Without necessary details, we may be unable to respond to an enquiry, provide a service, make a payment or progress an application.
We identify and record an appropriate lawful basis for each processing purpose. Different activities or datasets may have different bases. These are determined by the circumstances and legal requirements rather than a general permission to choose any basis.
We process this information for our legitimate interests in responding to requests, delivering services and managing business relationships. Contractual necessity may apply where processing is necessary for a contract with you personally or for steps you request before entering one.
We process these records to comply with applicable legal obligations. Other business records may be retained for our legitimate interests in administration, accountability and establishing or defending legal claims.
We may process information for our legitimate interests in improving services, protecting systems, preventing misuse and understanding business needs. Where consent is legally required, we obtain it.
Where we rely on legitimate interests, we assess necessity and balance our interests against your rights and reasonable expectations. We document other lawful bases where a particular activity requires them and provide relevant information to affected individuals. We do not retrospectively change a lawful basis merely to avoid a consent withdrawal or an individual’s rights.
We send administrative and service communications, such as support responses, account information and service notices, on the basis appropriate to delivering and administering the service. These communications are separate from promotional messages.
For marketing, we use consent where required. Where electronic marketing to corporate subscribers is permitted without consent, we may rely on legitimate interests following an appropriate assessment.
Marketing to sole traders and other individual subscribers requires consent unless the applicable existing-customer soft opt-in conditions are met. We comply with channel-specific marketing rules and preferences.
You can unsubscribe from promotional emails or contact us to stop marketing at any time. Necessary service communications may continue. Information promoting third parties is sent only with your explicit consent.
We collect and use only the personal information needed for identified, lawful purposes. We do not use information for an incompatible new purpose unless permitted by law, including where valid fresh consent is appropriate. Where required, we provide updated privacy information before using information for a new purpose.
We use appropriate physical, technical and organisational measures to protect personal information against unauthorised access, loss, misuse or disclosure. Access is limited according to role and business need.
Security concerns and suspected breaches should be reported using the contact details below and are handled under our incident procedures.
Further information about our approach is available through the FMIS Trust Centre, including our information on data protection and privacy.
We retain personal information only for as long as necessary for its purpose or to meet applicable legal and contractual requirements. Our retention schedules provide reviewable guidelines; they do not override the requirement to justify retention or comply with binding obligations.
Relevant personal and client business records are normally retained for seven years under our working retention guidance. This is not a universal minimum or fixed period for every dataset. The relevant trigger and period depend on the record, relationship or transaction and the applicable legal, contractual and claims requirements.
We review and adjust retention periods where justified, recording the reasons and updating privacy information where required. Records that are no longer needed are securely deleted or anonymised.
Depending on the processing and applicable conditions, you may have the following rights:
You have an absolute right to object to the use of your personal information for direct marketing, including related profiling. We will stop that use when you object.
To exercise your rights, email privacy@fmis.co.uk or use one of the other contact routes below.
Requests are normally free of charge and answered without undue delay and within one month, subject to lawful identity checks, extensions, pauses and exemptions. Where relevant, we will explain any extension or refusal and your complaint rights. Requests and complaints do not need to use a special form or legal terminology.
FMIS does not engage in automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
If this changes, we will assess the applicable requirements, implement necessary safeguards and provide appropriate privacy information before the new processing begins.
Customer data hosted and processed by FMIS for its customers is currently resident in the UK and is not processed internationally by FMIS. For customer-hosted installations, the customer determines its own infrastructure and locations.
Changes to FMIS customer processing locations require assessment and compliance with the relevant agreement, including any prior consent, notification or UK-only restrictions.
Some internal business systems and their providers may process personal information outside the UK. The actual location depends on the service and configuration; use of a cloud provider does not itself determine the country of processing.
Where a restricted international transfer occurs, we use a lawful transfer mechanism, such as applicable UK adequacy regulations or an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses. We carry out the required assessment and apply supplementary measures where necessary.
Contact privacy@fmis.co.uk for information about relevant destinations and safeguards, including how to obtain a copy. This notice does not override customer-specific transfer restrictions.
Our website uses cookies and similar technologies for functions such as operation, security, preferences and measurement, and for marketing where enabled and permitted. Current details of the technologies in use, their purposes, providers and durations are provided through our Cookie Policy and the website’s cookie preference controls.
We obtain consent before using technologies that require it, including advertising tracking. Technologies may operate without consent only where a relevant legal exception applies and its conditions are met. Where an exception requires a simple and free means to object, we provide it.
You can accept or reject optional technologies and review or withdraw consent through the website’s cookie controls. Browser controls offer additional options but do not replace our consent obligations.
The consent-management provider, cookie inventory and configuration may change. The same legal standards and transparent choice requirements will continue to apply.
We share personal information where necessary with relevant providers of hosting, IT, communications, business administration and support services, and with professional advisers, payment or payroll providers and authorities where applicable to the activity.
Sharing is limited to an appropriate purpose and lawful basis. We do not sell or lease personal information.
Providers processing information on our behalf are subject to appropriate assessment, confidentiality, security and data-processing terms. Some recipients act as independent controllers for their own legal or professional responsibilities.
Sota Solutions is treated as a limited subprocessor supporting FMIS Cloud hosting and infrastructure. FMIS administers the hosted servers and controls the operational encryption keys. Customer data at rest and backups are encrypted, and Sota is not expected to have plaintext access under the recorded arrangement.
Additional subprocessors may be appointed where needed, subject to assessment, appropriate contractual safeguards and the authorisation, notification and objection provisions of the applicable customer agreement.
Current information about relevant recipients or subprocessors is available from privacy@fmis.co.uk. This notice does not itself authorise a change to a customer’s agreed subprocessor arrangements.
FMIS also acts as controller for personal information used in recruitment, employment and internal administration. Depending on the activity, this may include:
We use this information to assess applications, manage employment and payments, meet employment and tax duties, support staff welfare, administer access and protect the business.
The lawful basis depends on the purpose and may include steps towards or performance of an employment contract, legal obligations or assessed legitimate interests. Consent is used only where appropriate and a genuine choice is available.
Health and other special-category information is processed only where an Article 6 lawful basis and an applicable Article 9 condition are established, such as employment-law obligations where applicable.
Criminal-offence information, including relevant screening, requires lawful authority under Article 10 and the Data Protection Act 2018. We maintain an appropriate policy document where required by the relevant condition.
Access is limited to authorised people with a need to know, including relevant managers and HR, payroll or professional support providers. Additional information about specific purposes, sources, recipients, retention and monitoring is provided to applicants and staff as appropriate. Staff may use the same privacy contact and complaint routes as other individuals.
Our website may link to third-party websites. Those organisations are responsible for their own privacy practices. Please review their privacy information when you use their services.
For privacy questions, data protection rights requests or complaints, contact the FMIS Data Protection Lead:
You may raise a complaint through any of these routes, including by telephone. We acknowledge data protection complaints within 30 days of receipt, make appropriate enquiries without undue delay, keep you informed and communicate the outcome without undue delay.
Complaints are coordinated by the Data Protection Lead and escalated internally to senior management as appropriate, including where you remain dissatisfied.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority. Information about doing so is available through the ICO complaints service.
We welcome the opportunity to resolve concerns directly, but our internal escalation process does not restrict your right to contact the ICO or seek other legal remedies.
FMIS Ltd
167b John Wilson Business Park
Whitstable
Kent
CT5 3RA
United Kingdom
Phone:+44 (0) 1227 773003
Fax:+44 (0) 1227 773005
Sales:sales@fmis.co.uk
Support:support@fmis.co.uk
