Snapshot 35434
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Convergence Group’s Privacy Policy
This is the Privacy Policy of Convergence (Group Networks) Limited (Company
Registration Number: 3815417) and Convergence Group (Wireless) Networks Limited
(Company Registration Number: 04975343), whose registered office is:
Rhodium
Central Boulevard
Blythe Valley Park
Solihull
B90 8AS
(collectively referred to as “we”, “our”, “us” or “Convergence Group”)
This Privacy Policy explains how we collect, use, store and share personal information
obtained through our interactions with you. It also explains what information we may hold
about you, why we collect it, who we may share it with, how long we keep it, and how you
can access or exercise your rights in relation to that information.
Convergence Group takes your privacy seriously and is committed to being open and
transparent about how we use your personal information. If you have any questions about
this Privacy Policy, how we process your personal data, or whether this policy has been
followed, please contact us.
Contacting Us about Data Protection
If you have any questions about this Privacy Policy or how your personal data is handled,
please contact
Email: [email protected].
Alternatively:
You may also contact our Data Protection Officer directly on:
Email: [email protected]
Cookie Statement
For information on how we deal with cookies and your use of our website please refer to our
website terms of use.
This statement covers the following points:
1. What information we may hold about you
2. Where we obtain your information from
3. How we use information about you and the legal reason for doing so
4. The type of third parties we might share your personal information with
5. Use of Artificial Intelligence (AI)
6. How long we will keep your information for
7. Data Protection Impact Assessments
8. Your Data Rights
9. How you can access the information we hold about you
10. What to do if you have a complaint
1. What information we may hold about you
We may collect, store and use the following personal data:
Ref: Priv 01
Version: 4.9 Public
Date of revision: 16/06/2026 © 2026 Convergence (Group Networks) Limited
• Personal contact details which may include name, title, job title, workplace addresses,
department, telephone numbers and workplace email addresses, signature (whether
provided directly or via a partner legitimately contracting with us on your behalf).
• Other personal information you provide to us by telephone, via our portal, website or
social media channels.
• Information gathered if you are involved in an environmental, health & safety,
information security or business continuity incident connected to us or the service we
provide.
• Visitor sign-in information when attending our offices, including name, email address,
phone number, photograph and signature.
• Any personal information provided during interactions with you or your employer (or via
a partner or service provider contracting with us on your behalf).
• Video and voice recordings from Microsoft Teams and telephony systems where a
meeting or call is intentionally recorded for a defined business purpose, such as quality
assurance, training, dispute resolution or regulatory compliance. Recording will not
take place on a continuous basis and, where applicable, participants will be notified.
• Technical information collected when you interact with our digital services, such as IP
address, browser type, device information and access timestamps.
• Information you provide when creating or accessing an online account or customer
portal, including usernames, passwords and associated profile information.
We do not knowingly collect information on children without parental consent. If
Convergence Group has collected personal information on a child, please contact
[email protected] so we can remove this information
without any undue delay.
Additional Information We May Hold about Partners and Customers
• Information relevant to the service we provide, whether supplied by you (or via a partner)
or gathered during our work.
• Personal information provided by vendors or third-party service providers.
• Network information you or our partner (the third party who is legitimately contracting
with us on your behalf), provided to us or that is gathered by our monitoring systems
(if part of the service) including machine identifiers such as IP addresses.
Additional Information We May Hold about Vendors and Suppliers
• If you are attending a customer site on our behalf, then we may request a copy of your
real time location details
• Network information you or our partner provide, including machine identifiers.
Additional Information We May Hold about Job Applicants
• Personal contact details may include home addresses, personal telephone numbers
and personal email addresses.
• Recruitment information (right to work documentation, references, CVs, cover letters).
• Information provided during the application process, including qualifications,
employment history, training records and professional certifications or memberships.
• Psychometric and personality test data, and background checks required for the role.
Ref: Priv 01
Version: 4.9 Public
Date of revision: 16/06/2026 © 2026 Convergence (Group Networks) Limited
2. Where we obtain your information from
We may collect personal data directly from you, from your employer, or from organisations
that we work with to deliver our services, including partners, vendors and service
providers. We may also receive information from publicly available sources or from
systems used to monitor and manage our services.
Where we receive personal data indirectly, we will process it in accordance with this
Privacy Policy and applicable data protection law.
3. How we use information about you and the legal reason for doing so
We process personal information in order to manage our contractual relationships, provide
services and measure performance. We will only process your personal data where we have
a lawful basis to do so. The lawful basis relied upon will depend on the purpose for which
your personal data is used. This may include processing using approved artificial
intelligence tools as further described below.
Lawful basis we rely on:
• Contract – where processing is necessary to perform or enter into a contract with you.
This includes processing carried out using AI-assisted tools where applicable where
processing forms part of delivering services to customers or managing business
relationships.
• Legitimate Interests – where processing is necessary to pursue our legitimate
business interests provided these are not overridden by your rights or freedoms. Our
legitimate interests include delivering and improving our services, maintaining
network and information security, preventing fraud, ensuring operational resilience,
and managing our commercial relationships. We carry out an assessment where
required. This includes processing carried out using AI-assisted tools where applicable
to improve efficiency, quality and consistency of our services.
• Legal obligation – where processing is necessary to comply with a legal or regulatory
obligation.
• Consent – where you have explicitly provided clear and specific consent (which you may
withdraw at any time).
Examples of how we use your information
• Contractual obligation – using your contact details to fulfil our contractual obligations.
• Legitimate interests – ensuring office security for visitors; ensuring network use aligns
with our Acceptable Use Policy; maintaining certifications; monitoring telephone/video
conversations for quality and audit purposes; assessing creditworthiness for
prospective or existing customers, suppliers or partners where necessary to prevent
fraud and manage financial risk.
• Legal obligation – health & safety requirements; insurance notifications; informing
regulators or law enforcement where required.
• Consent - providing you with information about our products and services (where you
have opted in).
Further details on the lawful basis relied upon for specific processing activities are
available on request.
Ref: Priv 01
Version: 4.9 Public
Date of revision: 16/06/2026 © 2026 Convergence (Group Networks) Limited
Additional basis for Partners and Customers
• Contractual obligation – using your contact details, site locations and machine
identifiers (if required for the services provided) to fulfil service obligations (or
legitimate interests where information is provided via a partner).
• Consent - sending marketing information where you have opted in, or creating
marketing materials such as case studies or testimonials where you have explicitly
agreed for us to use your personal information in this way.
Additional basis for Job Applicants
• Consent – evaluating suitability for employment.
• Legal obligation – to comply with our obligation to carry out right to work checks.
• Legitimate interests – to conduct security clearance and behavioral/cognitive
assessments
4. The type of third parties we might share your personal information with
In order to provide our services or to manage our responsibilities we use third parties for
completing certain tasks, some of whom require authorisation from us to share your
personal information with them in order to complete their responsibilities.
We shall ensure that any third party we use respects the security of your information, in
particular that:
• They have provided appropriate safeguards in relation to the processing and
transfer (particularly if the transfer of data is outside of the UK);
• You have the enforceable rights available to you; and
• There is an adequate level of protection to any Personal Data that is processed and
transferred.
Personal data may be transferred to, and processed in, countries outside the UK where our
service providers operate globally.
Where personal data is transferred outside of the UK, we ensure that appropriate
safeguards are in place in accordance with UK data protection legislation. These
safeguards may include:
• the UK International Data Transfer Agreement (IDTA);
• the UK Addendum to the EU Standard Contractual Clauses;
• transfers to countries subject to an adequacy decision; or
• other legally recognised transfer mechanisms.
We will take reasonable steps to ensure that your personal data is treated securely and in
accordance with this Privacy Notice.
Below are the categories or functions provided by the third parties which we use:
• Hardware vendors providing enhanced services and software support
• Engineering support providers
• Circuit providers for telecommunications
• Data centres and data storage companies
• Software suppliers used to host our services (such as our visitor sign in and supplier
payment process)
• Technology providers supporting AI functionality acting as data processors on our
behalf (Microsoft)
• Tiviti (our partner company which provides a self-service platform)
• Regulators and law enforcement agencies
Ref: Priv 01
Version: 4.9 Public
Date of revision: 16/06/2026 © 2026 Convergence (Group Networks) Limited
• Security clearance providers
• Recruitment agencies
• Delivery companies
• Professional advisers (lawyers, auditors and insurers)
• Marketing agencies
• Credit reference agencies (where relevant to individuals such as sole traders).
We may also share personal data in connection with corporate transactions, such as
mergers, acquisitions or business transfers,
Specific third-party details are available on request.
5. Use of Artificial Intelligence (AI)
We may use artificial intelligence (“AI”) tools, including Microsoft 365 Copilot, to support
our business operations. These tools assist with the creation, review and improvement of
business content.
• AI tools may be used to generate drafts, summarise information, analyse existing
content and support internal decision-making processes.
• AI tools will only process information already held within our systems, such as
emails, documents and business communications.
• Our use of AI does not involve collecting new personal data directly from
individuals.
Nature of processing
AI tools may:
• retrieve and analyse information that users already have permission to access;
• generate summaries, draft communications, or provide insights based on existing
data;
• log user prompts and AI-generated responses within our systems in accordance
with internal retention policies.
Lawful basis
We rely primarily on:
• Legitimate Interests (to improve efficiency, quality and consistency of our services);
and
• Contractual Necessity (where processing forms part of delivering services to
customers or managing business relationships).
Safeguards and limitations
We implement technical and organisational controls to ensure that:
• AI tools only access data in accordance with existing user permissions;
• sensitive or restricted data is protected using access controls, data loss prevention
measures, and classification tools;
• AI outputs are reviewed by trained employees before use and are not relied upon
without appropriate human validation to ensure accuracy, fairness and
appropriateness;
• AI tools are not used to make automated decisions that produce legal or similarly
significant effects on individuals.
• You have the right not to be subject to a decision based solely on automated
processing, including profiling, where that decision produces legal or similarly
significant effects on you. We do not use AI tools for such automated decision-
making.
Ref: Priv 01
Version: 4.9 Public
Date of revision: 16/06/2026 © 2026 Convergence (Group Networks) Limited
Third-party processing
AI functionality is provided through Microsoft acting as a data processor under contractual
data protection obligations. Personal data is not used to train third-party AI models unless
explicitly agreed.
Transparency and expectations
We recognise that the use of AI may not be expected by all individuals whose personal data
we hold. We therefore ensure transparency through this Privacy Notice and apply
appropriate safeguards to minimise any impact on individuals.
6. How long we will keep your information for
We retain personal information only for as long as is necessary to fulfil the purposes for
which it was collected, including to satisfy legal, financial or reporting requirements.
Where applicable, we apply defined retention periods and periodic review to ensure that
personal data is not retained for longer than necessary. Retention periods are determined
based on applicable legal requirements, contractual obligations, regulatory expectations,
and legitimate business needs.
In particular:
• Contract information - retained for at least 7 years after contract termination.
• Financial records - retained for at least 7 years.
• Marketing information - retained while consent remains valid;
• Visitor sign-in data – retained as stated on the notice at point of collection.
• Prospective customer/partner information – retained for the duration in which we have
contractual arrangements in place and up to 7 years thereafter.
• Vendor/supplier information – retained while we do business or have a legitimate
interest.
• Job Applicants:
o Successful applicants – retained under employee privacy basis
o Unsuccessful applicants – retained for up to 12 months.
o Psychometric data – processed by a third party. Please refer to their
privacy policy - https://www.predictiveindex.com/privacy/privacy-
respondent/
7. Data Protection Impact Assessments
We carry out Data Protection Impact Assessments (DPIAs) where our processing is likely to
result in a high risk to individuals’ rights and freedoms. This helps us identify and minimize
risks before undertaking such activities and ensures that appropriate safeguards are in
place. We review DPIAs periodically and whenever there is a significant change to the
nature, scope or context of the processing.
8. Your Data Rights
You have the following rights under UK General Data Protection Regulation:
• Right to Object
• Right of Access
• Right to be Informed
• Right to Rectification
• Right to Erasure
Ref: Priv 01
Version: 4.9 Public
Date of revision: 16/06/2026 © 2026 Convergence (Group Networks) Limited
• Right to Restrict Processing
• Right to Data Portability
• Right to Withdraw Consent
Right to Object
You can object to our processing where we rely on legitimate interests as the legal basis.
We will stop processing unless we can demonstrate compelling legitimate grounds that
override your interests, rights and freedoms, or the processing is required for legal claims.
Right of Access
You can request a copy of the personal information we hold about you. We will provide
this unless an exemption applies. We may ask for information to confirm your identity
before responding.
Right to be Informed
You have the right to be informed about how we collect and use your personal information.
This Privacy Notice forms part of that obligation.
Right to Rectification
If any of your personal information is inaccurate or incomplete, you can ask us to correct or
update it.
Right to Erasure
You can ask us to delete your personal information where there is no lawful reason for us
to continue processing it. This right does not apply where we must retain information for
legal or regulatory purposes.
Right to Restrict Processing
You can ask us to restrict the use of your information in certain circumstances, such as
where you contest its accuracy or where you have objected to processing.
Right to Data Portability
Where we process your information based on consent or contract and the processing is
carried out by automated means, you can request your information in a structured,
commonly used and machine-readable format, or ask us to transfer it to another controller.
Right to Withdraw Consent
Where we rely on consent, you can withdraw it at any time. This will not affect the
lawfulness of processing carried out before consent was withdrawn.
For more information on your rights and how to exercise them please contact us on:
[email protected]. You may also contact the Information
Commissioner’s Office (ICO) via their website, helpline or live chat.
9. How you can access the information we hold about you
If you would like to access some or all of your personal information, please email
[email protected] or write to us at the above address.
If you send us your request electronically, we will provide the information to you
electronically where possible.
Ref: Priv 01
Version: 4.9 Public
Date of revision: 16/06/2026 © 2026 Convergence (Group Networks) Limited
10. What to do if you have a complaint
If you have any complaints relating to your personal information that is held or processed
by Convergence Group, please email [email protected] in
the first instance. If you wish to contact our DPO directly, please email
[email protected]. We will acknowledge receipt of your complaint
within 30 days and will investigate it without undue delay, keeping you informed
throughout.
You also have the right to lodge a complaint with the Information Commissioner Office
(www.ico.org.uk) if you think that we have denied or infringed any of your rights. You can
contact them any of the following ways:
Via their website https://ico.org.uk/make-a-complaint/; or
call their helpline on 0303 123 1113; or
contact them via live chat service ico.org.uk/livechat
Changes to Our Privacy Notice
We will keep our Privacy Notice under review and will place any updates here.
Ref: Priv 01
Version: 4.9 Public
Date of revision: 16/06/2026 © 2026 Convergence (Group Networks) Limited