Privacy Policy

Version 1.0 | Effective date: 11 September 2026 | Last reviewed: 11 September 2026

1. Introduction

Global Image Management Limited ("GLIMMA", "we", "our" or "us") is committed to protecting and respecting your privacy.

This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit our website, contact us, engage with our services or otherwise interact with us.

GLIMMA is headquartered in the United Kingdom and operates globally through offices and affiliates across EMEA, India, APAC and the Americas.

This Privacy Policy has been prepared in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the EU General Data Protection Regulation (EU GDPR).

2. Who We Are

Global Image Management Limited is the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Registered Address:

Global Image Management LimitedFreemantle RoadLowestoftSuffolkNR33 0EAUnited Kingdom

Registered Company Number: 04126932

Email: dataprotection@glimma.com

Telephone: +44 (0)20 7043 1322

UK ICO Registration number: ZA522159

3. Personal Data We Collect

Depending on how you interact with us, we may collect the following categories of personal data:

3.1 Contact and business information

  • Name
  • Company name
  • Job title
  • Business email address
  • Telephone number
  • Postal address

3.2 Enquiry and communication data

  • Information contained in enquiries submitted to us
  • Records of correspondence by email, telephone or post
  • Marketing preferences

3.3 Technical and usage data

  • IP address
  • Browser type and version
  • Device information
  • Website usage information collected via cookies and similar technologies

3.4 Service delivery data

Where you engage GLIMMA to deliver brand implementation, fleet branding, signage, or related services, we may also process personal data in connection with those services, including contact details of your personnel and project stakeholders. This data is processed under the terms of our client engagement and any applicable data processing agreement.

3.5 BrandEye™ platform data

GLIMMA operates BrandEye™, a proprietary digital platform used to track, manage and optimise brand assets on behalf of clients. Where personal data is processed within BrandEye™ — for example, contact data of client personnel — this is processed in accordance with this policy and any applicable data processing agreement in place with the relevant client.

3.6 General

We only collect personal data that is relevant and necessary for the purposes described in this Privacy Policy. We do not intentionally collect special category personal data through our website or general business operations.

Our website and services are directed at business professionals. We do not knowingly collect personal data from individuals under the age of 18.

4. How We Collect Personal Data

We collect personal data when:

  • You submit an enquiry through our website.
  • You contact us by email, telephone or post.
  • You request information about our services.
  • You subscribe to marketing communications.
  • You engage with our services, including through the BrandEye™ platform.
  • You interact with our website.

Website enquiries submitted through our contact forms are directed to authorised GLIMMA personnel for the purpose of responding to your enquiry and providing information about our services.

We may also collect certain technical information automatically through cookies and similar technologies. Please refer to Section 13 (Cookies) for further information.

5. How We Use Personal Data

We use personal data to:

  • Respond to enquiries.
  • Provide, manage and deliver our services.
  • Manage customer and supplier relationships.
  • Communicate with you regarding our services.
  • Send marketing communications where permitted by law.
  • Improve and secure our website and digital platforms.
  • Monitor website performance and analytics.
  • Operate and develop the BrandEye™ platform on behalf of clients.
  • Comply with legal and regulatory obligations.

6. Lawful Basis for Processing

We process personal data under one or more of the following lawful bases under UK GDPR. The table below sets out the primary purposes for which we process data and the corresponding lawful basis:

PurposeData TypesLawful Basis
Responding to website enquiriesContact, enquiry dataLegitimate interests
Delivering contracted servicesContact, service dataPerformance of a contract
Managing client and supplier relationshipsContact, business dataLegitimate interests
Sending marketing communicationsContact, preferencesConsent / Legitimate interests (PECR)
Operating and improving our websiteTechnical, usage dataLegitimate interests
Complying with legal obligationsAs required by lawLegal obligation
BrandEye™ platform operationClient personnel dataPerformance of a contract

Where we rely on legitimate interests as our lawful basis, we have carried out a balancing test to confirm that our legitimate business interests are not overridden by your rights and freedoms. You have the right to object to processing carried out on this basis — see Section 12 (Your Rights).

Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

7. Marketing Communications

Where permitted by law, we may contact you with information regarding our services, events, news and updates.

Our email marketing activities are conducted in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) as well as UK GDPR. For business-to-business communications, we may rely on the ‘soft opt-in’ exemption where you have previously expressed interest in or engaged with our services. In all other cases, we will obtain your prior consent before sending marketing emails.

You may opt out of receiving marketing communications at any time by using the unsubscribe link provided in any marketing email, or by contacting us directly at dataprotection@glimma.com.

8. Sharing Personal Data

We may share personal data with the following categories of recipient:

Recipient CategoryPurpose
GLIMMA group companiesProviding services across our global network
Professional advisersLegal, financial and compliance support
CRM and marketing platformsManaging client and prospect communications
Cloud infrastructure and hosting providersStoring and processing data securely
Project management and collaboration toolsDelivering client projects
IT support providersMaintaining and securing our systems
Legal and regulatory authoritiesWhere required by law or court order

We do not sell personal data to third parties. All third-party processors are required to process personal data only on our instructions and in accordance with applicable data protection law. Where required, we enter into data processing agreements with our processors.

9. International Data Transfers

As a global organisation, personal data may be transferred to and accessed by authorised personnel located outside the UK, including in the European Economic Area, India, the Middle East and the Americas, where necessary to provide our services and operate our business.

Where personal data is transferred internationally, we ensure that appropriate safeguards are in place in accordance with UK GDPR. These safeguards may include:

  • Transfers to countries that have received an adequacy decision from the UK Secretary of State (including EEA member states and countries listed under the UK adequacy regulations).
  • Use of the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (SCCs) as approved by the European Commission, as applicable.
  • Other appropriate safeguards as permitted under UK GDPR Article 46.

For transfers of EU personal data subject to EU GDPR (for example, data relating to individuals in EEA member states), we rely on the applicable EU transfer mechanisms including EU SCCs.

You may request further information about the specific safeguards applied to international transfers by contacting us at dataprotection@glimma.com.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with legal, regulatory and contractual obligations.

Data CategoryTypical Retention PeriodBasis
Website enquiries24 monthsLegitimate interests
Marketing contactsUntil consent withdrawn or 24 months of inactivityConsent / Legitimate interests
Customer records6 years following end of relationshipLegal obligation / Limitation Act 1980
Supplier records6 years following end of relationshipLegal obligation
Service delivery dataDuration of contract + 6 yearsLegal obligation / contract
BrandEye™ platform dataAs specified in client agreementContract

Where data is no longer required, it will be securely deleted or anonymised in accordance with our data retention and disposal procedures.

11. Data Security

We maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful loss, misuse, alteration, unauthorised disclosure or access. These measures include, but are not limited to:

  • Access controls restricting personal data to authorised personnel on a need-to-know basis.
  • Encryption of data in transit and, where appropriate, at rest.
  • Regular review of our information security practices.
  • Staff training on data protection obligations.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) in accordance with our legal obligations and, where required, inform affected individuals without undue delay.

12. Your Rights

Subject to applicable data protection law, you have the following rights in relation to your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you.
RectificationRequest correction of inaccurate or incomplete personal data.
ErasureRequest deletion of your personal data in certain circumstances.
RestrictionRequest that we restrict processing of your personal data.
ObjectionObject to processing based on legitimate interests or for direct marketing purposes.
PortabilityReceive your personal data in a structured, machine-readable format where processing is based on consent or contract and is carried out by automated means. Note: this right is limited in scope for most B2B interactions.
Withdraw consentWhere processing is based on consent, withdraw it at any time without affecting prior lawful processing.
ComplaintLodge a complaint with the ICO or another supervisory authority.

To exercise any of these rights, please contact us using the details provided in Section 14. We will respond to your request within one month in accordance with UK GDPR Article 12. In some circumstances, we may extend this period by a further two months, in which case we will notify you.

13. Cookies

Our website uses cookies and similar technologies to improve functionality, analyse website performance and support website administration.

For a full inventory of cookies, tracking technologies, analytics and performance tools deployed and further information on cookies generally, please visit www.glimma.com/cookie-policy/

14. Contact Us

If you have any questions regarding this Privacy Policy or how we process personal data, please contact:

Email: dataprotection@glimma.com

Telephone: +44 (0)20 7043 1322

Post:

Global Image Management LimitedFreemantle RoadLowestoftSuffolkNR33 0EAUnited Kingdom

15. Complaints

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection:

Website: www.ico.org.uk

If you are located in the European Economic Area, you may also have the right to lodge a complaint with the data protection supervisory authority in your country of residence.

We would, however, welcome the opportunity to address any concerns you may have directly before you contact the ICO. Please reach out to us at dataprotection@glimma.com in the first instance.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business, legal requirements or privacy practices. The version number and effective date shown at the top of this document will be updated accordingly.

Where changes are material, we will take reasonable steps to bring them to your attention. Any updates will be published on this page and will take effect from the date of publication.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.