FMIS Software
  • Home
  • Solutions
    • Fixed Asset Management Systems
      • Capital Projects
      • Enterprise Asset Management
      • Fixed Asset Management Software
    • Asset Tracking
      • Barcode Tracking
      • FMIS Mobile Asset Manager
    • Purchase to Pay
      • Purchase Order Processing
      • Sales Order Processing
    • Stock and Inventory
      • Kitting and Assembly
      • Material Requirements Planning (MRP)
      • Production Control
    • Equipment Maintenance
      • Field Service Management
    • Lease Accounting
      • Order Management
  • Market Sectors
    • Commercial and Retail
    • Education
    • Government
    • Health
    • Manufacturing
    • Non-Profit
    • Oil, Gas and Energy
  • Partners
    • Deltek
    • Find a partner
    • Become a Partner
  • Resources
    • Trust Centre
      • Certifications & Assurance
      • Data Protection & Privacy
      • Cloud Security & Infrastructure
    • News and articles
    • Case studies
    • Fixed asset management guide
  • About us
  • Contact
    • Request a demo
    • Pricing
    • Product information
    • Customer Support
    • Careers
    • Training Feedback
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

FMIS Privacy Policy

How FMIS collects, uses, protects and manages your personal information and privacy rights.

FMIS Privacy Policy

Your privacy is important. Financial and Management Information Systems Limited (FMIS) explains here how we collect, use and protect personal information and how you can exercise your rights. We comply with applicable data protection law, including the UK GDPR and Data Protection Act 2018, as amended, and the Privacy and Electronic Communications Regulations where relevant.

Last updated: September 2026. We review this notice regularly and update it when our processing changes. Where required, we will bring material changes to your attention before further processing.

Privacy at a glance

  • FMIS acts as a controller for its own business activities and normally as a processor when handling customer data through our software and services.
  • We collect and use only the personal information needed for identified, lawful purposes.
  • We do not sell or lease personal information.
  • Customer data hosted and processed by FMIS is currently resident in the UK.
  • You can object to direct marketing or unsubscribe from promotional emails at any time.
  • You can contact our Data Protection Lead at privacy@fmis.co.uk.

Further information about our security, compliance and data protection arrangements is available through the FMIS Trust Centre.

Contents

  • Our role and the scope of this notice
  • What personal information does FMIS collect?
  • How does FMIS use personal information?
  • Marketing and service communications
  • Data minimisation and purpose limitation
  • How does FMIS protect personal information?
  • How long does FMIS retain personal information?
  • What data protection rights do you have?
  • Automated decision-making and profiling
  • International data transfers
  • How does FMIS use cookies?
  • Who does FMIS share personal information with?
  • Staff and recruitment information
  • Links to other websites
  • Contacting FMIS and raising a complaint

Our role and the scope of this notice

FMIS is a controller for its own business activities, including enquiries, customer and supplier relationships, marketing, recruitment, employment and security administration. This notice covers those activities. Further information may be provided when information is collected for a particular purpose.

For customer personal data handled under our Data Processing Agreement, the customer is normally the controller and FMIS acts as processor on its documented instructions. The customer’s privacy information explains its purposes and lawful bases.

This notice does not give FMIS permission to use customer-controlled data for its own marketing or other unrelated purposes. Requests concerning that data are referred to the customer, with assistance from FMIS under the applicable agreement.

What personal information does FMIS collect?

Depending on your relationship with FMIS, we may collect:

  • Names, job titles and employer details.
  • Contact details and correspondence.
  • Enquiry and support information.
  • Account and transaction records.
  • Preferences and marketing choices.
  • IP addresses, device and browser details, usage information and access logs.

We collect information directly through forms, email, telephone, meetings and our services, and automatically through website and security technologies.

Where relevant, we may receive business contact or support information from your employer, colleagues, customers or referral partners, and recruitment information from recruiters and referees. If we obtain information from other sources, including public sources where used, we provide the source and other required privacy information within the applicable legal timeframe, unless an exemption applies.

Where information is required by law or necessary to enter into or perform a contract, we explain this and the consequences of not providing it. Without necessary details, we may be unable to respond to an enquiry, provide a service, make a payment or progress an application.

How does FMIS use personal information?

We identify and record an appropriate lawful basis for each processing purpose. Different activities or datasets may have different bases. These are determined by the circumstances and legal requirements rather than a general permission to choose any basis.

Enquiries, business relationships, support and supplier administration

We process this information for our legitimate interests in responding to requests, delivering services and managing business relationships. Contractual necessity may apply where processing is necessary for a contract with you personally or for steps you request before entering one.

Accounting, tax and statutory records

We process these records to comply with applicable legal obligations. Other business records may be retained for our legitimate interests in administration, accountability and establishing or defending legal claims.

Service improvement, security and research

We may process information for our legitimate interests in improving services, protecting systems, preventing misuse and understanding business needs. Where consent is legally required, we obtain it.

Where we rely on legitimate interests, we assess necessity and balance our interests against your rights and reasonable expectations. We document other lawful bases where a particular activity requires them and provide relevant information to affected individuals. We do not retrospectively change a lawful basis merely to avoid a consent withdrawal or an individual’s rights.

Marketing and service communications

We send administrative and service communications, such as support responses, account information and service notices, on the basis appropriate to delivering and administering the service. These communications are separate from promotional messages.

For marketing, we use consent where required. Where electronic marketing to corporate subscribers is permitted without consent, we may rely on legitimate interests following an appropriate assessment.

Marketing to sole traders and other individual subscribers requires consent unless the applicable existing-customer soft opt-in conditions are met. We comply with channel-specific marketing rules and preferences.

You can unsubscribe from promotional emails or contact us to stop marketing at any time. Necessary service communications may continue. Information promoting third parties is sent only with your explicit consent.

Data minimisation and purpose limitation

We collect and use only the personal information needed for identified, lawful purposes. We do not use information for an incompatible new purpose unless permitted by law, including where valid fresh consent is appropriate. Where required, we provide updated privacy information before using information for a new purpose.

How does FMIS protect personal information?

We use appropriate physical, technical and organisational measures to protect personal information against unauthorised access, loss, misuse or disclosure. Access is limited according to role and business need.

Security concerns and suspected breaches should be reported using the contact details below and are handled under our incident procedures.

Further information about our approach is available through the FMIS Trust Centre, including our information on data protection and privacy.

How long does FMIS retain personal information?

We retain personal information only for as long as necessary for its purpose or to meet applicable legal and contractual requirements. Our retention schedules provide reviewable guidelines; they do not override the requirement to justify retention or comply with binding obligations.

Relevant personal and client business records are normally retained for seven years under our working retention guidance. This is not a universal minimum or fixed period for every dataset. The relevant trigger and period depend on the record, relationship or transaction and the applicable legal, contractual and claims requirements.

  • Enquiry and marketing records: reviewed for continuing relevance and your preferences. Limited suppression information may be retained to honour an opt-out.
  • Recruitment and employment records: reviewed according to the recruitment outcome, employment relationship, statutory duties and any relevant claims period.
  • Technical logs and cookies: retained according to their operational purpose and applicable schedule or stated duration.
  • Customer-controlled data: returned or deleted under the applicable agreement and instructions. Backup copies are handled through their applicable retention cycle and may not be removed immediately.

We review and adjust retention periods where justified, recording the reasons and updating privacy information where required. Records that are no longer needed are securely deleted or anonymised.

What data protection rights do you have?

Depending on the processing and applicable conditions, you may have the following rights:

  • Access: request a copy of your personal information.
  • Rectification: ask us to correct inaccurate or incomplete information.
  • Erasure: ask us to delete personal information in applicable circumstances.
  • Restriction: ask us to restrict processing in applicable circumstances.
  • Data portability: receive information you provided in a suitable format where processing is automated and based on consent or a contract with you.
  • Objection: object to processing based on legitimate interests. We will consider your objection and stop unless the law permits us to continue, for example because of compelling overriding grounds or legal claims.
  • Withdrawal of consent: withdraw consent at any time, as easily as it was given. Withdrawal does not affect the lawfulness of processing before it was withdrawn.

You have an absolute right to object to the use of your personal information for direct marketing, including related profiling. We will stop that use when you object.

To exercise your rights, email privacy@fmis.co.uk or use one of the other contact routes below.

Requests are normally free of charge and answered without undue delay and within one month, subject to lawful identity checks, extensions, pauses and exemptions. Where relevant, we will explain any extension or refusal and your complaint rights. Requests and complaints do not need to use a special form or legal terminology.

Automated decision-making and profiling

FMIS does not engage in automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.

If this changes, we will assess the applicable requirements, implement necessary safeguards and provide appropriate privacy information before the new processing begins.

Does FMIS transfer personal information outside the UK?

Customer data hosted and processed by FMIS for its customers is currently resident in the UK and is not processed internationally by FMIS. For customer-hosted installations, the customer determines its own infrastructure and locations.

Changes to FMIS customer processing locations require assessment and compliance with the relevant agreement, including any prior consent, notification or UK-only restrictions.

Some internal business systems and their providers may process personal information outside the UK. The actual location depends on the service and configuration; use of a cloud provider does not itself determine the country of processing.

Where a restricted international transfer occurs, we use a lawful transfer mechanism, such as applicable UK adequacy regulations or an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses. We carry out the required assessment and apply supplementary measures where necessary.

Contact privacy@fmis.co.uk for information about relevant destinations and safeguards, including how to obtain a copy. This notice does not override customer-specific transfer restrictions.

How does FMIS use cookies?

Our website uses cookies and similar technologies for functions such as operation, security, preferences and measurement, and for marketing where enabled and permitted. Current details of the technologies in use, their purposes, providers and durations are provided through our Cookie Policy and the website’s cookie preference controls.

We obtain consent before using technologies that require it, including advertising tracking. Technologies may operate without consent only where a relevant legal exception applies and its conditions are met. Where an exception requires a simple and free means to object, we provide it.

You can accept or reject optional technologies and review or withdraw consent through the website’s cookie controls. Browser controls offer additional options but do not replace our consent obligations.

The consent-management provider, cookie inventory and configuration may change. The same legal standards and transparent choice requirements will continue to apply.

Who does FMIS share personal information with?

We share personal information where necessary with relevant providers of hosting, IT, communications, business administration and support services, and with professional advisers, payment or payroll providers and authorities where applicable to the activity.

Sharing is limited to an appropriate purpose and lawful basis. We do not sell or lease personal information.

Providers processing information on our behalf are subject to appropriate assessment, confidentiality, security and data-processing terms. Some recipients act as independent controllers for their own legal or professional responsibilities.

FMIS Cloud infrastructure

Sota Solutions is treated as a limited subprocessor supporting FMIS Cloud hosting and infrastructure. FMIS administers the hosted servers and controls the operational encryption keys. Customer data at rest and backups are encrypted, and Sota is not expected to have plaintext access under the recorded arrangement.

Additional subprocessors may be appointed where needed, subject to assessment, appropriate contractual safeguards and the authorisation, notification and objection provisions of the applicable customer agreement.

Current information about relevant recipients or subprocessors is available from privacy@fmis.co.uk. This notice does not itself authorise a change to a customer’s agreed subprocessor arrangements.

Staff, recruitment and internal personal information

FMIS also acts as controller for personal information used in recruitment, employment and internal administration. Depending on the activity, this may include:

  • Application and reference information.
  • Identity and right-to-work evidence.
  • Employment terms.
  • Payroll and bank details.
  • Emergency contacts.
  • Training, performance and absence records.
  • Proportionate access and security records.

We use this information to assess applications, manage employment and payments, meet employment and tax duties, support staff welfare, administer access and protect the business.

The lawful basis depends on the purpose and may include steps towards or performance of an employment contract, legal obligations or assessed legitimate interests. Consent is used only where appropriate and a genuine choice is available.

Health and other special-category information is processed only where an Article 6 lawful basis and an applicable Article 9 condition are established, such as employment-law obligations where applicable.

Criminal-offence information, including relevant screening, requires lawful authority under Article 10 and the Data Protection Act 2018. We maintain an appropriate policy document where required by the relevant condition.

Access is limited to authorised people with a need to know, including relevant managers and HR, payroll or professional support providers. Additional information about specific purposes, sources, recipients, retention and monitoring is provided to applicants and staff as appropriate. Staff may use the same privacy contact and complaint routes as other individuals.

Links to other websites

Our website may link to third-party websites. Those organisations are responsible for their own privacy practices. Please review their privacy information when you use their services.

How can you contact FMIS or raise a privacy complaint?

For privacy questions, data protection rights requests or complaints, contact the FMIS Data Protection Lead:

  • Email: privacy@fmis.co.uk
  • Telephone: 01227 773 003
  • Website: Contact FMIS
  • Post: FMIS Ltd, 167b John Wilson Business Park, Whitstable, Kent, CT5 3RA, United Kingdom

You may raise a complaint through any of these routes, including by telephone. We acknowledge data protection complaints within 30 days of receipt, make appropriate enquiries without undue delay, keep you informed and communicate the outcome without undue delay.

Complaints are coordinated by the Data Protection Lead and escalated internally to senior management as appropriate, including where you remain dissatisfied.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority. Information about doing so is available through the ICO complaints service.

We welcome the opportunity to resolve concerns directly, but our internal escalation process does not restrict your right to contact the ICO or seek other legal remedies.

Support Icon
Can we help?
Book a demo View products Contact support
Or call: +44 (0) 1227 773003
Mon–Fri, 9:00–17:00 (BST/GMT)

Explore More

  • What is new in FMIS Fixed Assets version 12.47
  • What is new in FMIS Lease Accounting version 12.47
  • AccountMate Fixed Asset Integration with FMIS
  • Asset Depreciation Methods Explained for UK Businesses
  • How to Conduct a Fixed Asset Audit: Step by Step

SOLUTIONS

  • Fixed Asset Management Systems
  • Asset Tracking
  • Purchase to Pay
  • Order Management
  • Equipment Maintenance
  • Lease Accounting
  • Stock and Inventory
  • View all solutions

Home › Privacy policy

Market Sectors

  • Commercial and Retail
  • Education
  • Local and Central Government
  • NHS and Health
  • Manufacturing
  • Non-profit
  • Oil, Gas and Energy

FOLLOW US

FMIS Twitter FMIS Linkedin

CONTACT US

FMIS Ltd
167b John Wilson Business Park
Whitstable
Kent
CT5 3RA
United Kingdom

Phone:+44 (0) 1227 773003
Fax:+44 (0) 1227 773005
Sales:sales@fmis.co.uk
Support:support@fmis.co.uk

Copyright © 2024 - All rights reserved www.fmis.co.uk
  • Privacy Policy
  • Cookie Policy
Scroll to top