Privacy Notice
1. About This Notice
Simunix Limited operates five online services: the corporate website simunix.com, the consumer and business directory ukphonebook.com, the data intelligence platform ORBIS, the data API t2a.io, and the age verification API ageverifyuk.com. This single notice explains how Simunix collects, uses, and protects personal data across all of these services.
This notice is published on the Simunix Trust Centre at simunix.com/trust-centre and is linked from every Simunix product. Each product also has its own cookie notice covering the cookies specific to that site.
Which sections apply to you?
| If you are… | Read these sections |
|---|---|
| A visitor to simunix.com or someone who has contacted us | 1. About This Notice · 2. About Simunix Ltd · 3.1 simunix.com · 4. Data Security · 5. Data Retention · 6. Your Rights · 7. Cookies |
| A ukphonebook.com registered user or subscriber | 1. About This Notice · 2. About Simunix Ltd · 3.2 ukphonebook.com · 4. Data Security · 5. Data Retention · 6. Your Rights · 7. Cookies |
| A person whose data appears on ukphonebook.com | 1. About This Notice · 2. About Simunix Ltd · 3.2.1 Published data · 6. Your Rights · 7. Cookies |
| An ORBIS registered user | 1. About This Notice · 2. About Simunix Ltd · 3.3 ORBIS · 4. Data Security · 5. Data Retention · 6. Your Rights · 7. Cookies |
| A person whose data is held within ORBIS | 1. About This Notice · 2. About Simunix Ltd · 3.3.1 Data in ORBIS · 6. Your Rights · 7. Cookies |
| A t2a.io registered user | 1. About This Notice · 2. About Simunix Ltd · 3.4 t2a.io · 4. Data Security · 5. Data Retention · 6. Your Rights · 7. Cookies |
| An ageverifyuk.com registered user | 1. About This Notice · 2. About Simunix Ltd · 3.5 ageverifyuk.com · 4. Data Security · 5. Data Retention · 6. Your Rights · 7. Cookies |
2. About Simunix Ltd
Simunix Limited is the data controller for all personal data processed across its services. Our details are:
| Full legal name | Simunix Limited |
|---|---|
| Registered address | Middleham House 2-3, St. Marys Court, York, YO24 1AH |
| Company number | 03684982 |
| Telephone | +44 (0)1904 217765 |
| Data Protection Officer | John L Lewis |
| Privacy contact | dpo@simunix.com |
| ICO registration | Z4703855 (ico.org.uk) |
If you have any questions about this notice or wish to exercise your rights (see Section 6), please contact our Data Protection Officer at dpo@simunix.com.
You also have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at www.ico.org.uk or by calling 0303 123 1113. We would always appreciate the chance to address your concern first.
3. Data We Process
This section describes what personal data each Simunix service collects or holds, why, and on what lawful basis.
3.1 simunix.com — Corporate Website
simunix.com is the Simunix company website. It does not provide a search or directory service. The personal data we collect here is limited to:
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Responding to contact form enquiries | Name, email address, telephone number, message content | Legitimate interests — responding to business enquiries |
| Direct marketing (with your consent) | Name, email address | Consent — you may withdraw at any time by emailing dpo@simunix.com or using the unsubscribe link in any email we send |
| Website analytics | IP address, pages visited, referral source, browser/device type (anonymised) | Legitimate interests — improving our website and understanding visitor behaviour |
We do not sell or share personal data collected via simunix.com with third parties for their own purposes.
For cookies used on simunix.com, please see the simunix.com cookie notice.
3.2 ukphonebook.com — Consumer and Business Directory
ukphonebook.com is a directory search service available to consumers and businesses. It involves two distinct categories of data subject: (a) individuals whose data is published on the site, and (b) registered users who use the service.
3.2.1 Personal data published on ukphonebook.com
To provide its directory search service, ukphonebook.com publishes personal data drawn from the sources listed below. All of these sources are publicly available or permissioned datasets. We have assessed the lawful basis for each:
| Data source | Lawful basis |
|---|---|
| BT / Directory Enquiries | Legitimate interests |
| Open Electoral Register | Legitimate interests |
| Companies House | Legitimate interests |
| Sagacity Solutions Ltd — permissioned consumer data | Legitimate interests |
| Sagacity Solutions Ltd — Bereavement Register | Legitimate interests |
| Credit Safe — company credit reports and director/shareholder data | Legitimate interests |
| Land Registry | Legitimate interests |
| Royal Mail — address and postcode data | Legitimate interests |
| Ordnance Survey — mapping and geolocation data | Legitimate interests |
We have carried out Legitimate Interests Assessments (LIAs) for each data source and believe we have taken the steps necessary to protect data subjects' interests while providing information to subscribers. We aggregate data from multiple sources and have carried out a Data Protection Impact Assessment (DPIA) to assess the effect of this aggregation on individual privacy.
We do not issue individual privacy notices to data subjects whose data we publish because of the disproportionate effort this would require. We provide the required information in this notice instead, in accordance with Article 14(5)(b) UK GDPR.
Removal: If you would like your personal data removed from ukphonebook.com, please complete the record removal form at www.ukphonebook.com/remove-me. We are not able to process requests made through third parties. You may also wish to contact the organisations that originally hold your data (e.g. British Telecom, your local council, Companies House, Sagacity Solutions Ltd) to request removal from their records.
3.2.2 Data collected from registered users
When you register and use ukphonebook.com as a subscriber, we collect and process the following:
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Account registration and management | Identity (name, job title), contact (email, billing address), login credentials | Performance of contract |
| Processing payments and managing credits | Identity, contact, transaction data (payment details processed via Braintree) | Performance of contract; legitimate interests (debt recovery) |
| Providing search results | Identity, technical (IP address), usage (search queries and results) | Performance of contract |
| Notifying you of service changes | Identity, contact, communications preferences | Performance of contract; legal obligation |
| Website security and fraud prevention | Identity, technical (IP address, browser data) | Legitimate interests — protecting our service and users |
| Analytics and service improvement | Technical, usage data (anonymised where possible) | Legitimate interests — improving our service |
| Marketing (existing subscribers) | Identity, contact, communications preferences | Legitimate interests — informing you of service updates and related Simunix services |
You can opt out of marketing at any time by using the unsubscribe link in any email we send, or via the Privacy Settings page in your account.
3.2.3 Search logs
We retain logs of all searches conducted on ukphonebook.com, including the IP address from which the session was conducted. These logs are used to improve the service, prevent fraudulent or unlawful use, and develop new features. You can opt out of your data being retained in search logs (except for mandatory disclosure to law enforcement) via the privacy dashboard in your account.
We may disclose search log data to:
- A data subject who makes a Subject Access Request, where we reasonably believe it is appropriate to provide those logs; and
- The police and other law enforcement agencies where they issue a request under the Data Protection Act 2018, Schedule 2, Part 1(2).
3.3 ORBIS — Data Intelligence Platform
ORBIS is a professional data intelligence platform providing access to a comprehensive, aggregated dataset for use by authorised Closed User Groups (CUGs). CUGs are organisations that have signed a Data Sharing Agreement with Simunix and hold appropriate permissions. Typical use cases include identity verification, person tracing, anti-money laundering (AML), and know-your-customer (KYC) checks.
Unlike ukphonebook.com, ORBIS data is not publicly accessible. Access is strictly controlled and limited to authorised CUG personnel.
Note on the controller relationship: ORBIS CUGs are independent data controllers. They determine their own purposes for accessing and using data retrieved from ORBIS (for example, to meet their own regulatory obligations under the Money Laundering Regulations 2017). Simunix is the controller in respect of the data held within ORBIS. Each CUG is the controller in respect of how they use that data within their own systems and processes. Simunix and each CUG enter into a Data Sharing Agreement that reflects this relationship.
3.3.1 Personal data held within ORBIS
ORBIS draws from the same data sources as ukphonebook.com, with the addition of further datasets suited to professional verification and tracing use cases:
| Data source | Lawful basis |
|---|---|
| BT / Directory Enquiries | Legitimate interests |
| Open Electoral Register | Legitimate interests |
| Companies House | Legitimate interests |
| Sagacity Solutions Ltd — permissioned consumer data | Legitimate interests |
| Sagacity Solutions Ltd — Bereavement Register | Legitimate interests |
| Credit Safe — company credit reports and director/shareholder data | Legitimate interests |
| Land Registry | Legitimate interests |
| Royal Mail — address and postcode data | Legitimate interests |
| Ordnance Survey — mapping and geolocation data | Legitimate interests |
We have carried out Legitimate Interests Assessments and a DPIA covering the aggregation of data within ORBIS, the restriction of access to authorised CUGs only, and the professional use cases for which ORBIS is licensed.
Data subjects whose data is held in ORBIS are not notified individually due to the disproportionate effort this would require (Article 14(5)(b) UK GDPR). This notice fulfils our transparency obligation.
Removal: To request removal of your personal data from ORBIS, please contact us at dpo@simunix.com. You may also wish to contact the organisations that originally hold your data (listed as data sources above) to request removal at source.
3.3.2 Data collected from CUG account holders
When an organisation establishes a CUG account and its staff access ORBIS, we collect:
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Account setup and user administration | Organisation name, authorised user names, email addresses, roles | Performance of contract |
| Access control and audit logging | User identity, IP address, queries made, timestamps | Legitimate interests — security, fraud prevention, and contractual audit obligations |
| Billing and invoicing | Organisation details, transaction data | Performance of contract; legal obligation (tax records) |
| Service notifications and support | Contact details, communications history | Performance of contract; legitimate interests |
3.3.3 Law enforcement access
We may disclose ORBIS access logs and search data to police and other law enforcement agencies where they issue a request under the Data Protection Act 2018, Schedule 2, Part 1(2), or where we are otherwise required to do so by law.
3.4 t2a.io — Data API
t2a.io is an API service that provides programmatic access to Simunix data for business customers. It offers the same underlying dataset as ukphonebook.com via a developer API, including people search, address and postcode lookup, phone number lookup, company data, and verification endpoints.
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Account registration | Name, email address, login credentials | Performance of contract |
| Processing API credit purchases | Identity, contact, transaction data (Braintree) | Performance of contract |
| Providing API responses | IP address, API key, query content, response data | Performance of contract |
| Usage monitoring and fraud prevention | IP address, API usage logs, timestamps | Legitimate interests — protecting our service and preventing misuse |
| Account communications and service updates | Name, email address | Performance of contract; legitimate interests |
| Marketing (registered users) | Name, email address | Legitimate interests — informing you of service updates and related Simunix services |
We retain API usage logs for the purposes of security, fraud prevention, billing dispute resolution, and service improvement. Logs are retained for a maximum of three years unless required for longer by law or a specific dispute.
You can opt out of marketing at any time by emailing dpo@simunix.com or by using the unsubscribe link in any marketing email we send.
Simunix does not share t2a.io customer data with third parties for their own purposes.
3.5 ageverifyuk.com — Age Verification API
ageverifyuk.com provides an API service enabling businesses to verify the age of their customers using Simunix data. It is used by clients in retail, e-commerce, gaming, and other sectors where age verification is required.
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Account registration | Name, email address, login credentials | Performance of contract |
| Processing credit purchases | Identity, contact, transaction data | Performance of contract |
| Providing age verification responses | IP address, API key, query content (name and address of the individual being checked) | Performance of contract; legitimate interests of our API customers in meeting their own age verification obligations |
| Usage monitoring and fraud prevention | IP address, API usage logs, timestamps | Legitimate interests |
| Account communications and service updates | Name, email address | Performance of contract; legitimate interests |
Important: age verification queries submitted via the API include personal data relating to the end consumer being checked (name and address). Simunix processes this data only to return a verification result. The API customer is the data controller for the end consumer's data and is responsible for ensuring they have a lawful basis for submitting it to the API.
You can opt out of marketing at any time by emailing dpo@simunix.com or by using the unsubscribe link in any marketing email we send.
4. Data Security
We apply the same security standards across all Simunix services. Our security measures include:
- Dedicated servers: All Simunix services run on dedicated servers in a secure, UK-based data centre operated by ANS (see ans.co.uk/data-centres), with a secondary presence in London. Data is not held in public cloud infrastructure.
- Physical security: No physical access to our servers is permitted, including by Simunix staff.
- Network security: Servers sit behind a firewall that restricts web traffic to ports 80 and 443; all other IP access is limited to our office IP. Servers use RAID-ed SSDs.
- Encryption in transit: All connections to Simunix services use HTTPS with TLS 1.2 or TLS 1.3. Legacy protocols (TLS 1.0 and 1.1) are not permitted. We are rated A on the SSL Labs test. Email traffic is protected using TLS where supported by the recipient's mail server.
- Encryption at rest: Personal data is held in a secure and encrypted format using current protocols and procedures.
- Access controls: Access to personal data is limited to staff and systems that have a business need. All personnel are subject to a duty of confidentiality.
- Patch management: Servers are kept fully up to date with security patches and protected against malware and viruses.
- Breach response: We have procedures to detect, investigate, and report personal data breaches. We will notify affected individuals and the ICO where we are legally required to do so.
- Certifications: Simunix holds relevant security certifications including ISO/IEC 27001, PCI DSS compliance, and Crown Commercial Service (CCS) registration. Current certificates are available on the Trust Centre.
5. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including any legal, accounting, or reporting requirements.
| Data type | Retention period |
|---|---|
| Customer financial and transaction records | 6 years from end of business relationship (legal obligation — tax and accounting) |
| Registered account data (inactive accounts) | 3 years from date of last account activity, after which all personal data is deleted |
| Contact form and enquiry data | 3 years from last contact, unless the enquiry leads to a customer relationship |
| API usage and search logs | 3 years, unless required longer for a specific legal or contractual purpose |
| ORBIS audit and access logs | 6 years from the access event, to support audit obligations and dispute resolution |
| Published directory data (ukphonebook / ORBIS) | Retained and refreshed in line with source database updates. Removed on valid removal request. |
| Website analytics data | 26 months (Google Analytics default retention setting) |
In some circumstances we may anonymise personal data for research or statistical purposes, in which case we may use it indefinitely without further notice.
6. Your Legal Rights
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights in relation to personal data we hold about you:
- Right of access (Subject Access Request): You may request a copy of the personal data we hold about you, along with information about why we hold it, who it may be shared with, and how long we retain it.
- Right to rectification: You may ask us to correct personal data that is inaccurate or incomplete.
- Right to erasure ('right to be forgotten'): You may ask us to delete your personal data where there is no lawful reason to continue processing it, where you have withdrawn consent, or where we have processed it unlawfully.
- Right to object: You may object to processing based on legitimate interests where your particular circumstances mean the processing impacts your fundamental rights and freedoms. You may also object to direct marketing at any time.
- Right to restriction of processing: You may ask us to suspend processing in certain circumstances — for example, while we verify the accuracy of your data, or while an objection is considered.
- Right to data portability: Where processing is based on your consent or on a contract with you, you may request your personal data in a structured, commonly used, machine-readable format.
- Right to withdraw consent: Where we rely on consent as the lawful basis for processing, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
How to exercise your rights
To exercise any of these rights, please contact our Data Protection Officer at dpo@simunix.com or write to us at Simunix Limited, Middleham House 2-3, St. Marys Court, York, YO24 1AH.
We will respond within one calendar month. Where a request is particularly complex or we have received multiple requests from you, we may extend this by a further two months — we will notify you within the first month if this is the case.
We will not charge a fee to handle your request unless it is manifestly unfounded, repetitive, or excessive, in which case we may charge a reasonable fee or refuse to comply, giving our reasons.
We may need to verify your identity before processing your request. We may ask you for information to confirm who you are.
Complaints
If you are unhappy with how we have handled your personal data, we encourage you to contact us first at dpo@simunix.com so we can try to resolve the matter. You also have the right to lodge a complaint with the ICO at any time:
| ICO website | www.ico.org.uk |
|---|---|
| ICO helpline | 0303 123 1113 |
| ICO live chat | Available via ico.org.uk |
| ICO address | Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF |
7. Cookies
All Simunix websites use cookies. For full details of the cookies used on each site, see our Cookies page.
8. International Transfers
8.1 Our servers and processors
All Simunix services are hosted on dedicated servers located in the United Kingdom. Personal data collected through our services is processed in the UK and governed by UK GDPR. However, some of our third-party service providers operate internationally:
- Google (Analytics and reCAPTCHA) — based in the US. Google operates under the EU-US Data Privacy Framework and UK adequacy arrangements. See policies.google.com/privacy.
- Microsoft / Bing — based in the US. Microsoft participates in the EU-US Data Privacy Framework and UK adequacy arrangements.
- Braintree (payment processing) — a PayPal service, based in the US, processing under Standard Contractual Clauses. See braintreepayments.com/legal.
Where any of our processors transfer data internationally, we ensure appropriate safeguards are in place (adequacy decision, Standard Contractual Clauses, or equivalent) as required by UK GDPR.
8.2 Access to ukphonebook.com — permitted jurisdictions
Access to ukphonebook.com is restricted to users in the United Kingdom, the European Economic Area, and other countries that maintain data protection standards recognised as adequate by the UK ICO or the European Commission. Access from countries that do not meet these standards is blocked at the network level. All data processed through the site is hosted on UK servers and governed by UK GDPR.
- Visitors from the UK: Processing is governed by UK GDPR. Simunix Limited is the UK-based controller responsible for that processing.
- Visitors from the EEA: The UK has been assessed by the European Commission as providing an adequate level of data protection, meaning your data transferred to our UK servers benefits from protection recognised as equivalent to EU GDPR. We recommend verifying the current status of the UK adequacy decision at commission.europa.eu.
- Visitors from other permitted countries: Access is also permitted from countries covered by recognised data protection frameworks, including the EU-US Data Privacy Framework, the UK-US Data Bridge, and other arrangements recognised by the ICO or European Commission as providing adequate protection.
- Directory data: Personal data published on ukphonebook.com (UK directory information drawn from the sources listed in Section 3.2.1) is accessible to users in permitted jurisdictions only. To request removal of your data, please see Section 3.2.1.
9. Changes to This Notice
We review and update this notice periodically — when we launch new features, when our processing activities change, or when required by changes in the law. The 'Last updated' date at the top of this notice will always reflect the most recent revision.
Where changes are material, we will notify registered users by email and display a prominent notice on the Trust Centre for 30 days following the update.
We encourage you to check this page periodically. Continued use of any Simunix service following an update constitutes acceptance of the revised notice.