Version 3.0 β last updated 15 July 2026
This privacy policy is issued by KTM Online Limited on behalf of itself and its wholly owned subsidiaries, Fonehouse Services Limited and KTM Device Protection Services Limited (together referred to as "the KTM Online group", "we", "us", or "our" in this policy). Where those subsidiaries process personal data, they do so as independent data controllers registered separately with the Information Commissioner's Office. This policy covers the processing activities of all three entities. Please refer to Section 2 to identify which entity is the data controller for your specific relationship with us.
We are committed to protecting your personal data and handling it in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
It is important that you read this privacy policy together with any other terms & conditions, privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them.
This policy explains how we use your personal data. Where we rely on consent (for example for marketing or non-essential cookies), you may withdraw it at any time.
KTM Online Limited, and its group of companies including Fonehouse Services Limited, KTM Device Protection Service Limited, Go Mobile Limited and Go Mobile Retail Limited, is a UK company providing network connectivity, mobile phones, SIM-only contracts, accessories, and related products and services to UK consumers.
The KTM Online group is made up of the following legal entities, each of which may act as your data controller depending on which brand or service you are using:
| Legal Entity | ICO Registration | Brands / Services covered |
|---|---|---|
| KTM Online Limited | ZA299181 | Fonehouse, Metrofone, Buytechdirect, Network Portals. |
| Fonehouse Services Limited | ZB592855 | Fonehouse Services (fonehouseservices.co.uk) |
| KTM Device Protection Services Limited | ZC046200 | KTM Device Protection, Insurance services |
All entities are registered in England and Wales. KTM Online Limited is the parent company and policy owner. Fonehouse Services Limited and KTM Device Protection Services Limited are wholly owned subsidiaries of KTM Online Limited.
When we refer to "we", "us", or "our" in this policy, we are referring to the relevant KTM Online group entity that is the data controller for your relationship with us. If you are unsure which entity that is, please contact us at [email protected].
The KTM Online group operates within the LURI Group, a privately owned group of companies. Where other LURI Group companies process personal data in connection with our services, this will be disclosed in the relevant section of this policy.
Our nominated privacy contact for all group entities is [email protected].
In addition to our direct retail activities, KTM Online Limited operates a white-label network portal platform which is used by third-party commercial partners to facilitate mobile SIM connections for their customers. Where we provide this platform service, we act as an independent data controller in respect of the personal data processed through it. Section 10A of this policy sets out further details of this arrangement.
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). Our services are not intended for children under 18 and we do not knowingly collect childrenβs data. If you believe we hold personal data relating to a child, please contact us at [email protected].
Depending on the products and services you subscribe, we may collect and process the following categories of personal data:
We also collect, use, and share Aggregated Data such as statistical or demographic data for business and analytical purposes. Where aggregated data is combined with personal data so that it can identify you, it will be treated as personal data under this policy.
We collect personal data through:
We are not responsible for the privacy practices of third-party websites linked from our sites.
Under UK GDPR we must have a lawful basis for every processing activity. The table below sets out the main types of processing we carry out and the basis on which we carry out each one.
| Processing Activity | Lawful Basis | Notes |
|---|---|---|
| Processing your order and delivering products or services | Contract performance | Necessary to fulfil your purchase |
| Credit checking at point of sale | Contract performance | Cannot assess suitability without it β see Section 6 |
| Account management and customer service | Contract performance | Necessary to manage your relationship with us |
| Fraud prevention, debt recovery, and security | Legitimate interests | LIA completed; our interest in preventing harm to business and customers |
| Call recording for training, quality, and compliance | Legitimate interests / Legal obligation | Regulatory compliance and quality assurance |
| CCTV in stores | Legitimate interests | Crime prevention, staff and customer safety, property protection |
| Marketing to existing customers (email/SMS) | Legitimate interests (soft opt-in) / Consent | PECR applies; see Section 7 |
| Marketing to new customers | Consent | Explicit opt-in required |
| Analytics and website improvement | Legitimate interests / Consent | Consent required for non-essential cookies |
| Complying with legal and regulatory obligations | Legal obligation | Tax, consumer protection, FCA, HMRC, Ofcom |
| Handling data protection complaints | Legal obligation | Section 164A Data Protection Act 2018 (as amended by the DUAA 2025) |
| Upgrade and renewal contact with existing customers | Legitimate interests | Legitimate Interests Assessment completed |
| Demographic profiling and TV advertising attribution (sharing house number and postcode with third-party analytics partners) | Legitimate interests | Data minimised to house number and postcode only; customers can object at any time |
| Device protection product administration and claims handling | Contract performance | Necessary to administer your device protection product and process any claims, including to our insurance underwriter. |
| Device blacklist verification during claims process | Contract performance | As part of processing a claim we may submit your device's IMEI number to Recipero to check whether it has been reported as stolen or blacklisted. If it has not, we will ask you to do so as a condition of your claim. |
| Fonehouse Services order processing and fulfilment | Contract performance | Processing necessary to fulfil orders placed through fonehouseservices.co.uk including passing your address to our distributors (e.g. Royal Mail) for collection of your device. |
| Fonehouse Services SMS/mobile messaging service | Consent / PECR | Marketing messages sent only with your explicit opt-in consent |
You can object to processing carried out on the basis of legitimate interests at any time. See Section 15 (Your Rights) for details.
When you apply for a mobile phone contract or any product involving credit or a minimum-term commitment, we are required to carry out a credit check before we can enter into an agreement with you.
We share certain personal data with credit reference agencies to conduct a credit assessment. We always carry out a soft search in the first instance.
We use TransUnion (formerly Callcredit) as our credit reference agency. TransUnion acts as an independent data controller for the purposes of maintaining credit files and providing services to other lenders. For information about how TransUnion uses your data, visit: www.transunion.co.uk/legal-information/bureau-privacy-notice.
The lawful basis for this processing is contract performance β we cannot assess whether to enter into a contract with you without it. We do not rely on your consent for this processing, and you should not be asked to consent to a credit check as a condition of proceeding.
We retain credit check outcomes for the duration of your application plus 12 months. If you enter into a contract, credit assessment data is retained for the duration of the contract plus 6 years.
You have the right to request access to the data we hold about you in connection with a credit check, and to raise a dispute directly with TransUnion about information held on your credit file.
We use your personal data only when the law allows us to. Our main uses are:
We would love to keep you informed about our latest products, services, offers, and promotions that we think may be of interest to you. We are constantly updating our range and negotiating exclusive deals, and we believe keeping you in the loop helps you get the most value from your relationship with us.
We may contact you by email, SMS, post, or telephone with marketing communications about our products, services, offers, and promotions. We will only do so where:
We will never sell your personal data to third parties for their own marketing purposes. Where we work with trusted partners to deliver offers, those partners must meet our data protection standards and any sharing of your data with them is done lawfully and transparently.
You may be contacted by other LURI Group companies for marketing purposes only where you have separately consented to this, or where it is otherwise permitted by law.
You can opt out of marketing communications at any time by:
Please allow a couple of days for all our systems to update following your opt-out request.
Certain communications are necessary to deliver our services and are not marketing β these include order confirmations, account updates, contract notifications, tariff changes, and regulatory notices. You cannot opt out of these essential service communications. Where an upgrade or renewal notification includes a promotional offer, it will be treated as a marketing communication and will only be sent where permitted.
Where you have contacted us by telephone to enquire about our products or services but did not proceed to purchase, we may contact you to follow up on that enquiry. We rely on our legitimate interests as the lawful basis for this contact rather than your consent.
We consider this processing to be proportionate because:
This type of follow-up contact is distinct from our general marketing activity. It is time-limited and tied to your specific enquiry rather than being a general promotional communication.
You have the right to object to this processing at any time. If you do not wish to be contacted following an inbound enquiry, please tell us during your call or contact us at [email protected]. We will record your objection and ensure no further follow-up contact is made.
Our websites use cookies and similar technologies. Some cookies are essential for the operation of our websites. Others require your consent.
Under changes introduced by the Data (Use and Access) Act 2025, certain analytics cookies that are used solely to collect statistical data and improve website functionality may be set without consent, provided we offer you a clear opt-out. Our Cookie Policy sets out which categories of cookie we use, the basis on which each is set, and how to manage your preferences.
You can manage your cookie preferences at any time through our . You can also set your browser to refuse cookies, though some parts of our website may not function correctly if you do so.
We do not sell your personal data. We may share your personal data with the following categories of recipients:
As a group of companies under common ownership, KTM Online Limited, Fonehouse Services Limited, and KTM Device Protection Services Limited may share personal data with each other where necessary for the following purposes:
Where personal data is shared between group entities, each entity remains independently responsible for its own data protection compliance. Personal data shared within the group is not used by any group entity for purposes beyond those described above without a separate lawful basis.
When you take out a mobile contract through us, we share your personal data with the relevant Mobile Network Provider (such as Vodafone, Three, Talkmobile, VOXI, Sky Mobile, EE, or BT) to enable them to activate and manage your connection. These network providers act as independent data controllers for the purposes of managing your network account and their own services. Their use of your data is governed by their own privacy policies, not this one. Links to the relevant network privacy notices are available on our website.
Our franchise stores operate under licence from Fonehouse. When you purchase in a franchise store, the store processes your personal data on our behalf. KTM Online Limited remains the data controller. Franchise stores do not use your data for their own purposes and are contractually required to handle your data in accordance with our data protection standards.
We may share your personal data with other companies within the LURI Group where they are acting as processors on our behalf or as joint controllers. We will identify when this is the case.
We share personal data with service providers who assist with the delivery, distribution, and marketing of our products and services, payment processing, and other business functions. These providers act on our instructions, are contractually bound to process your data only as we direct and must maintain appropriate security measures.
We share data with credit reference agencies (including TransUnion) and fraud prevention agencies. These agencies may act as independent controllers for their own credit file and fraud prevention purposes.
Where you hold a device protection product with KTM Device Protection Services Limited, your personal data may be shared with:
We may disclose personal data to law enforcement agencies, regulators, courts, and public authorities where we are legally required or permitted to do so.
If we sell, buy, merge, or reorganise our business, personal data may be shared with prospective or actual purchasers or partners and their advisers as part of that process.
We may share your house number and postcode with trusted third-party marketing analytics partners for two purposes:
We rely on our legitimate interests as the lawful basis for this processing. We have assessed that this activity does not override your rights and interests, and we share only the minimum data necessary β your house number and postcode. Your details are not used by these partners to contact you directly, and we do not share your name, email address, telephone number, or any other identifying information for this purpose.
You have the right to object to this processing at any time. To do so, please contact us at [email protected]. We will apply your objection before any further data is shared.
KTM Online Limited operates a white-label portal platform through which authorised third-party commercial partners (such as Core Communication Retail Limited) to enable their retail network to sell mobile SIM connections to end customers.
Where personal data is submitted through the portal in connection with a SIM connection, KTM Online Limited acts as an independent data controller. We determine our own purposes and means of processing in respect of that data, which are:
We are not acting as a processor on behalf of the third-party partner in this context. Each party is independently responsible for its own data protection compliance.
Through the portal we receive personal data entered by retail store staff on behalf of end customers at the point of sale. This typically includes name, date of birth, address history, email address, and bank details. We receive this data solely for the purposes described above and do not use it for any other purpose, including our own direct marketing.
The end customer's personal data is shared with the relevant Mobile Network Operator to enable credit checking and network activation. The network operator acts as an independent data controller for those purposes. Their privacy policies govern their use of the data.
The third-party commercial partner (for example Core Communication Retail Limited) is the data controller in respect of the end customer relationship. They are responsible for ensuring end customers are informed about how their data is used, including its transmission to KTM Online Limited and to the relevant Mobile Network Operator. End customers should refer to the third-party partner's privacy policy for information about how their data is handled in the context of their purchase.
If you are an end customer whose data has been processed through this portal arrangement and you wish to exercise your data subject rights in respect of KTM Online Limited's processing, please contact us at [email protected]. Where a request relates to data held by the third-party partner or the Mobile Network Operator, we will direct you to the appropriate party.
Personal data received through the portal is retained for the duration of the connection arrangement plus six years, in line with our standard retention periods set out in Section 12.
Some third parties we work with β including technology providers, payment processors, and analytics services β may process your personal data outside the United Kingdom.
Under the Data (Use and Access) Act 2025, we assess whether the level of protection for your personal data in any destination country is not materially lower than UK standards (the "Data Protection Test"). We only transfer personal data internationally where:
For information about the specific safeguards in place for any international transfer, or to request a copy of the relevant transfer mechanism, please contact us at [email protected].
We retain personal data only for as long as necessary for the purpose for which it was collected, including to satisfy legal, regulatory, tax, accounting, and reporting requirements. We may retain data for longer where there is an ongoing legal dispute, complaint, or regulatory investigation, retaining only what is necessary for as long as required.
The table below sets out how long we typically retain different categories of data:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account and purchase history | 6 years from last transaction | Legal obligation / Limitation Act 1980 |
| Contract and identity data | Duration of contract + 6 years | Limitation Act 1980 |
| Credit check results | Application duration + 12 months; if contract entered, contract duration + 6 years | Proportionality / Limitation Act |
| Customer service records and correspondence | 3 years from interaction | Dispute resolution / quality assurance |
| Call recordings | 3 years (standard); longer where required for regulatory compliance | Quality / compliance |
| Marketing preferences and consent records | Duration of opt-in + 3 years; suppression records kept indefinitely | ICO guidance / PECR |
| Insurance-related records | 7 years from policy end | FCA requirements |
| CCTV footage | 31 days ordinarily; up to 90 days where an incident has occurred | Crime prevention proportionality |
| Prospective customer data (no contract) | 90 days from initial enquiry | Legitimate interests (time-limited) |
| Data protection complaint records | 6 years from resolution | Accountability / Limitation Act 1980 |
| Fraud prevention records | 6 years | Legitimate interests / legal obligation |
In some circumstances we will anonymise your personal data for research or statistical purposes, in which case it is no longer personal data and may be used without further notice.
For more information about how long we keep a specific type of data, or to request deletion, please contact us at [email protected].
Automated decision-making is where a decision is made about you using only automated processes, without meaningful human involvement, and that decision has a legal or similarly significant effect on you. UK GDPR gives you specific rights in these situations.
When you apply for a product or service directly with us that involves a minimum-term commitment or credit, we use automated tools to carry out an initial eligibility assessment. This may include an automated soft credit check via TransUnion and an automated fraud screening check.
Where an automated assessment produces a result that affects whether we can offer you a product or service, this constitutes automated decision-making with a legal or similarly significant effect. In these cases, you have the right to:
To exercise any of these rights, please contact us at [email protected].
Where you take out a contract that connects you to a mobile network, the network provider (such as Vodafone, Three, EE, or others) will carry out their own credit assessment as an independent data controller. That credit decision is made by the network, not by us, and the network's own automated decision-making processes and rights apply. If you wish to contest a network credit decision or request human review of it, you should contact the relevant network provider directly. Links to network privacy notices are available on our website.
We use automated tools to personalise the content, offers, and advertising you see on our websites and in our marketing communications. This involves profiling based on your browsing behaviour, purchase history, and preferences.
This type of profiling does not produce decisions with a legal or similarly significant effect on you. However, you have the right to object to it at any time. To do so, please contact us at [email protected] or manage your preferences through our . See also Section 15 (Your Rights) for further details.
We maintain the highest standards of data privacy and security to protect your personal details and other information about your account because we want you to feel completely confident about using our services. We regularly review our processes and procedures to protect your personal information from unauthorised access and use, accidental loss, and/or destruction.
We maintain appropriate technical and organisational measures to protect your personal data from unauthorised access, accidental loss, destruction, or disclosure. These include:
Where required by data protection law, we will notify affected individuals and the ICO of a personal data breach without undue delay.
If you believe you have identified a security vulnerability in our website or systems, please contact us at [email protected].
Under UK data protection law you have the following rights in relation to your personal data:
To exercise any of these rights, please contact us at [email protected]. We will respond to legitimate requests within one month. Where requests are complex or numerous we may extend this by a further two months and will notify you accordingly. We will not charge a fee unless a request is manifestly unfounded, repetitive, or excessive.
We may need to verify your identity before responding to a rights request.
Under section 164A of the Data Protection Act 2018, as introduced by the Data (Use and Access) Act 2025, you have a statutory right to raise a data protection complaint directly with us. This right came into force on 19 June 2026.
A data protection complaint is any expression of concern or dissatisfaction about how we have handled your personal data. You do not need to use formal legal language β if you are unhappy with anything related to how your personal data has been used, we want to hear from you.
If your complaint relates specifically to the processing of your personal data by Fonehouse Services Limited or KTM Device Protection Services Limited, please contact us at [email protected] identifying the relevant brand or service in your correspondence. We will ensure your complaint is handled by the appropriate entity. The statutory right to raise a complaint directly with the controller and receive a response within 30 days applies equally to all three KTM Online group entities.
You can submit a data protection complaint by any of the following methods:
We will also accept complaints received through any other channel β including in store, by social media, or through a general customer service contact β and route them into our data protection complaints process. You do not need to use a specific form or channel.
The Information Commissioner's Office (ICO) is the UK's independent regulator for data protection. You have the right to lodge a complaint with the ICO at any time β you do not have to come to us first, though we would appreciate the opportunity to resolve your concern directly.
We are always looking for new ways to improve your shopping experience with us, that is why we love hearing from you. If you have any questions about how we use your personal data or if you would like to amend or stop us from processing your data (for marketing purposes), please contact us.
If you have any questions about this privacy policy or how we use your personal data, or for all data protection enquiries, subject access requests, rights requests, and complaints relating to any KTM Online group entity, please contact us using the following details:
We have appointed a Data Protection Lead (DPL) to oversee our compliance with data protection law. The DPL is an internal role responsible for data protection governance and can be contacted at the details above. Please identify in your correspondence which brand or service your enquiry relates to so we can ensure it is directed to the correct entity and data controller within the group.
If you fail to provide personal data that we are required by law or contract to collect, we may not be able to perform the contract we have with you. We will notify you if this is the case.
We may update this privacy policy from time to time to reflect changes in our practices, applicable law, or regulatory guidance. We will update the version number and date at the top of this policy when we do so. Where changes are material, we will take reasonable steps to notify you directly.
This policy is version 3.0, last updated 15 July 2026. It replaces version 2.0 dated 25 February 2026.
We use essential cookies to make this site work. We would also like to use non-essential cookies if we add them in future. You can accept or reject non-essential cookies. Essential cookies are always used. See our Cookie Policy for details.