Privacy policy
Version 1.0 · 10 September 2026
Privacy policy
Last updated: 10 September 2026
Who we are
Infinitel Communications Limited ("Infinitel", "we", "us") is a business communications provider registered in England and Wales, company number 10653020. Our registered office is C/O Williamson & Croft LLP, York House, 20 York Street, Manchester, M2 3BB, and our trading address is 2 Beecham Court, Wigan, WN3 6PR.
We are the controller of the personal data described in this policy. We are registered with the Information Commissioner's Office (ICO) under registration number ZA771640.
If you have any question about this policy or about how we handle personal data, contact us at hello@infinitel.co, call 0333 048 0000, or write to us at the trading address above.
What this policy covers
This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights you have. It applies to visitors to our website, people who contact us, our customers and their staff, our channel partners and their staff, our suppliers, and people who apply to work with us.
Where we provide services to a business customer, the customer decides how its own staff and end users' data is used within those services, and we act on the customer's instructions for that data. This policy covers what we do as a controller in our own right.
The personal data we collect
When you visit our website. Technical information such as your IP address, browser type, device type, pages visited and the time of your visit. See our cookie policy for details of the cookies we use.
When you contact us or make an enquiry. Your name, business name, job title, email address, telephone number, and whatever you tell us in your message. Our website enquiry form collects name and email as required fields; telephone number, company and message are optional.
When you become a customer or partner. Contact details for the people we deal with at your organisation, account and billing details, the services you take from us, the numbers and sites we provision, and records of our communications with you, including support tickets and service requests. For telephony services, we also process call detail records (numbers called, time, duration and routing) because that is how the service is delivered and billed.
When you call us. We record calls to and from our main and support numbers for training, quality and dispute resolution. We tell you at the start of the call. Recordings are kept for 12 months and then deleted.
When you use our portals. Login details and the activity needed to run your support and billing accounts.
When you apply to work with us. Your CV, covering message and contact details, and anything else you choose to send to careers@infinitelcomms.co.uk.
We do not knowingly collect special category data (such as health or religious information) and we ask you not to send it to us.
Where we get personal data from
Most of it comes directly from you or your organisation. We also receive data from our channel partners when they introduce a customer, from carriers and network suppliers when we provision or support a service (for example, number porting information from a losing provider), and from publicly available sources such as Companies House and business directories when we check who we are dealing with.
Why we use personal data, and our lawful basis
| What we do | Why | Lawful basis |
|---|---|---|
| Respond to enquiries and provide quotes | To answer you and prepare a proposal | Legitimate interests (running our business and responding to people who contact us) |
| Provide, provision, support and bill our services | To deliver what you have ordered | Performance of a contract |
| Keep call detail records and service records | Billing, fault handling, and legal and regulatory requirements | Contract; legal obligation |
| Manage partner relationships | To operate our partner programme | Contract; legitimate interests |
| Send service messages (outages, maintenance, renewals, billing) | To run the service properly | Contract; legitimate interests |
| Send business-to-business marketing about our services | To tell business contacts about relevant products | Legitimate interests, with an easy opt-out in every message |
| Record calls | Training, quality and dispute resolution | Legitimate interests |
| Keep our website and systems secure, and prevent fraud | Protecting our business and customers | Legitimate interests; legal obligation |
| Comply with law and regulation (including Ofcom rules and tax law) | Because we are required to | Legal obligation |
| Consider job applications | Recruitment | Legitimate interests; steps before entering a contract |
Where we rely on legitimate interests, we have considered the effect on you and concluded that the processing is what you would reasonably expect from a business communications provider and does not override your rights. You can object at any time; see "Your rights".
Marketing
We send marketing by email to business contacts at prospective and existing customers about our products and services. We deal only with limited companies and other corporate bodies, and we rely on legitimate interests to contact business email addresses, as the Privacy and Electronic Communications Regulations allow. Every message includes a way to opt out, and we stop as soon as you ask. We use Mailchimp to send these messages. We do not sell or rent personal data to anyone, and we do not send marketing on behalf of other companies.
Who we share personal data with
We share personal data only where necessary to run our business and provide our services:
- Carriers, network operators and wholesale suppliers that we use to provision and deliver voice, connectivity and mobile services, including number porting, where the data is needed to set up or support your service.
- Software and platform providers that host our systems and data: our website hosting and content platform; Microsoft 365 and our customer relationship management systems (Microsoft Dynamics 365 and Zoho CRM); Freshdesk, which runs our support desk and support portal; Intelligent Billing, which runs our billing platform and billing portal; Mailchimp for marketing email; and the 3CX platform where you take a managed 3CX service.
- Our digital marketing agency, Embryo Digital, which manages our website analytics and online advertising, and the analytics and advertising platforms it uses on our behalf, principally Google. These operate only with your consent to the relevant cookies; see our cookie policy.
- Professional advisers such as our accountants, auditors, insurers and, where needed, lawyers.
- Regulators, law enforcement and courts where we are required to, including Ofcom and the ICO.
- A buyer or successor if we sell or reorganise the business, in which case the same protections continue to apply.
Our suppliers act on our instructions under written contracts and may not use the data for their own purposes.
International transfers
Some of our suppliers store or process data outside the UK, most commonly in the European Economic Area or the United States. Where that happens, we rely on the UK's adequacy regulations (for the EEA and, for certified organisations, the UK–US data bridge) or on the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, together with supplier security commitments. You can ask us for details of the safeguards used for any specific transfer.
How long we keep personal data
We keep personal data only as long as we need it for the purposes above, and then delete or anonymise it.
| Data | Retention |
|---|---|
| Enquiries that do not lead to a customer or partner relationship | 12 months from the last contact |
| Customer and partner account records, contracts and billing records | 6 years after the relationship ends, to meet tax and legal requirements |
| Call detail records | For the life of the account and as long afterwards as billing, dispute and regulatory requirements demand, then deleted |
| Call recordings | 12 months |
| Support tickets | For the life of the account and 6 years after, as part of the service record |
| Job applications | 6 months after the position closes, unless you ask us to keep your details for future roles |
| Website analytics | See the cookie policy |
How we protect personal data
We use appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, secure hosted platforms, and staff who are trained to handle data properly. No system is completely secure, and if we ever discover a breach that puts your rights at risk we will tell you and the ICO as the law requires.
Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you;
- correct data that is inaccurate or incomplete;
- erase data in certain circumstances;
- restrict how we use it in certain circumstances;
- receive the data you gave us in a portable format;
- object to processing based on legitimate interests, including marketing, which we will always stop;
- withdraw consent where we rely on it, without affecting anything done before you withdrew it.
We do not make decisions about you using automated processing that has a legal or similarly significant effect.
To exercise any of these rights, email hello@infinitel.co or write to us at the trading address above. We may ask you to confirm your identity. We will respond within one month, or tell you if we need longer and why. There is normally no charge.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, by phone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
If your complaint is about the service rather than your data, our complaints process is described in our Service Terms and our complaints code of practice, including how to escalate to the Communications Ombudsman, the independent dispute resolution scheme we belong to, if we cannot resolve it.
Changes to this policy
We review this policy at least annually and whenever our practices change. The date at the top shows when it was last updated. If we make a significant change to how we use personal data we already hold, we will tell affected people directly.
