Privacy Policy
Version 1.0 | Effective date: September 11, 2026 | Last reviewed: September 11, 2026
1. Introduction
Global Image Management Limited ("GLIMMA", "we", "our" or "us") is committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit our website, contact us, engage with our services or otherwise interact with us.
GLIMMA is headquartered in the United Kingdom and operates globally through offices and affiliates across EMEA, India, APAC and the Americas.
This Privacy Policy has been prepared in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the EU General Data Protection Regulation (EU GDPR).
2. Who We Are
Global Image Management Limited is the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Registered Address:
Global Image Management LimitedFreemantle RoadLowestoftSuffolkNR33 0EAUnited KingdomRegistered Company Number: 04126932
Email: dataprotection@glimma.com
Telephone: +44 (0)20 7043 1322
UK ICO Registration number: ZA522159
3. Personal Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data:
3.1 Contact and business information
- Name
- Company name
- Job title
- Business email address
- Telephone number
- Postal address
3.2 Inquiry and communication data
- Information contained in inquiries submitted to us
- Records of correspondence by email, telephone or mail
- Marketing preferences
3.3 Technical and usage data
- IP address
- Browser type and version
- Device information
- Website usage information collected via cookies and similar technologies
3.4 Service delivery data
Where you engage GLIMMA to deliver brand implementation, fleet branding, signage, or related services, we may also process personal data in connection with those services, including contact details of your personnel and project stakeholders. This data is processed under the terms of our client engagement and any applicable data processing agreement.
3.5 BrandEye™ platform data
GLIMMA operates BrandEye™, a proprietary digital platform used to track, manage and optimize brand assets on behalf of clients. Where personal data is processed within BrandEye™ — for example, contact data of client personnel — this is processed in accordance with this policy and any applicable data processing agreement in place with the relevant client.
3.6 General
We only collect personal data that is relevant and necessary for the purposes described in this Privacy Policy. We do not intentionally collect special category personal data through our website or general business operations.
Our website and services are directed at business professionals. We do not knowingly collect personal data from individuals under the age of 18.
4. How We Collect Personal Data
We collect personal data when:
- You submit an inquiry through our website.
- You contact us by email, telephone or mail.
- You request information about our services.
- You subscribe to marketing communications.
- You engage with our services, including through the BrandEye™ platform.
- You interact with our website.
Website inquiries submitted through our contact forms are directed to authorized GLIMMA personnel for the purpose of responding to your inquiry and providing information about our services.
We may also collect certain technical information automatically through cookies and similar technologies. Please refer to Section 13 (Cookies) for further information.
5. How We Use Personal Data
We use personal data to:
- Respond to inquiries.
- Provide, manage and deliver our services.
- Manage customer and supplier relationships.
- Communicate with you regarding our services.
- Send marketing communications where permitted by law.
- Improve and secure our website and digital platforms.
- Monitor website performance and analytics.
- Operate and develop the BrandEye™ platform on behalf of clients.
- Comply with legal and regulatory obligations.
6. Lawful Basis for Processing
We process personal data under one or more of the following lawful bases under UK GDPR. The table below sets out the primary purposes for which we process data and the corresponding lawful basis:
| Purpose | Data Types | Lawful Basis |
|---|---|---|
| Responding to website inquiries | Contact, inquiry data | Legitimate interests |
| Delivering contracted services | Contact, service data | Performance of a contract |
| Managing client and supplier relationships | Contact, business data | Legitimate interests |
| Sending marketing communications | Contact, preferences | Consent / Legitimate interests (PECR) |
| Operating and improving our website | Technical, usage data | Legitimate interests |
| Complying with legal obligations | As required by law | Legal obligation |
| BrandEye™ platform operation | Client personnel data | Performance of a contract |
Where we rely on legitimate interests as our lawful basis, we have carried out a balancing test to confirm that our legitimate business interests are not overridden by your rights and freedoms. You have the right to object to processing carried out on this basis — see Section 12 (Your Rights).
Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
7. Marketing Communications
Where permitted by law, we may contact you with information regarding our services, events, news and updates.
Our email marketing activities are conducted in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) as well as UK GDPR. For business-to-business communications, we may rely on the ‘soft opt-in’ exemption where you have previously expressed interest in or engaged with our services. In all other cases, we will obtain your prior consent before sending marketing emails.
You may opt out of receiving marketing communications at any time by using the unsubscribe link provided in any marketing email, or by contacting us directly at dataprotection@glimma.com.
9. International Data Transfers
As a global organization, personal data may be transferred to and accessed by authorized personnel located outside the UK, including in the European Economic Area, India, the Middle East and the Americas, where necessary to provide our services and operate our business.
Where personal data is transferred internationally, we ensure that appropriate safeguards are in place in accordance with UK GDPR. These safeguards may include:
- Transfers to countries that have received an adequacy decision from the UK Secretary of State (including EEA member states and countries listed under the UK adequacy regulations).
- Use of the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (SCCs) as approved by the European Commission, as applicable.
- Other appropriate safeguards as permitted under UK GDPR Article 46.
For transfers of EU personal data subject to EU GDPR (for example, data relating to individuals in EEA member states), we rely on the applicable EU transfer mechanisms including EU SCCs.
You may request further information about the specific safeguards applied to international transfers by contacting us at dataprotection@glimma.com.
10. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal, regulatory and contractual obligations.
| Data Category | Typical Retention Period | Basis |
|---|---|---|
| Website inquiries | 24 months | Legitimate interests |
| Marketing contacts | Until consent withdrawn or 24 months of inactivity | Consent / Legitimate interests |
| Customer records | 6 years following end of relationship | Legal obligation / Limitation Act 1980 |
| Supplier records | 6 years following end of relationship | Legal obligation |
| Service delivery data | Duration of contract + 6 years | Legal obligation / contract |
| BrandEye™ platform data | As specified in client agreement | Contract |
Where data is no longer required, it will be securely deleted or anonymized in accordance with our data retention and disposal procedures.
11. Data Security
We maintain appropriate technical and organizational measures to protect personal data against accidental or unlawful loss, misuse, alteration, unauthorized disclosure or access. These measures include, but are not limited to:
- Access controls restricting personal data to authorized personnel on a need-to-know basis.
- Encryption of data in transit and, where appropriate, at rest.
- Regular review of our information security practices.
- Staff training on data protection obligations.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) in accordance with our legal obligations and, where required, inform affected individuals without undue delay.
12. Your Rights
Subject to applicable data protection law, you have the following rights in relation to your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Rectification | Request correction of inaccurate or incomplete personal data. |
| Erasure | Request deletion of your personal data in certain circumstances. |
| Restriction | Request that we restrict processing of your personal data. |
| Objection | Object to processing based on legitimate interests or for direct marketing purposes. |
| Portability | Receive your personal data in a structured, machine-readable format where processing is based on consent or contract and is carried out by automated means. Note: this right is limited in scope for most B2B interactions. |
| Withdraw consent | Where processing is based on consent, withdraw it at any time without affecting prior lawful processing. |
| Complaint | Lodge a complaint with the ICO or another supervisory authority. |
To exercise any of these rights, please contact us using the details provided in Section 14. We will respond to your request within one month in accordance with UK GDPR Article 12. In some circumstances, we may extend this period by a further two months, in which case we will notify you.
14. Contact Us
If you have any questions regarding this Privacy Policy or how we process personal data, please contact:
Email: dataprotection@glimma.com
Telephone: +44 (0)20 7043 1322
Mail:
Global Image Management LimitedFreemantle RoadLowestoftSuffolkNR33 0EAUnited Kingdom15. Complaints
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection:
Website: www.ico.org.uk
If you are located in the European Economic Area, you may also have the right to lodge a complaint with the data protection supervisory authority in your country of residence.
We would, however, welcome the opportunity to address any concerns you may have directly before you contact the ICO. Please reach out to us at dataprotection@glimma.com in the first instance.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, legal requirements or privacy practices. The version number and effective date shown at the top of this document will be updated accordingly.
Where changes are material, we will take reasonable steps to bring them to your attention. Any updates will be published on this page and will take effect from the date of publication.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.




