Privacy Policy
This policy is version 3.0, last updated 15th July 2026. It replaces version 2.0 dated 25th February 2026.
1. Purpose
This privacy policy is issued by KTM Online Limited on behalf of itself and its wholly owned subsidiaries, Fonehouse Services Limited and KTM Device Protection Services Limited (together referred to as “the KTM Online group”, “we”, “us”, or “our” in this policy). Where those subsidiaries process personal data, they do so as independent data controllers registered separately with the Information Commissioner’s Office. This policy covers the processing activities of all three entities. Please refer to Section 2 to identify which entity is the data controller for your specific relationship with us.
We are committed to protecting your personal data and handling it in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
It is important that you read this privacy policy together with any other terms & conditions, privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them.
This policy explains how we use your personal data. Where we rely on consent (for example for marketing or non-essential cookies), you may withdraw it at any time.
2. Who We Are
KTM Online Limited, and its group of companies including Fonehouse Services Limited, KTM Device Protection Service Limited, Go Mobile Limited and Go Mobile Retail Limited, is a UK company providing network connectivity, mobile phones, SIM-only contracts, accessories, and related products and services to UK consumers.
The KTM Online group is made up of the following legal entities, each of which may act as your data controller depending on which brand or service you are using:
| Legal Entity | ICO Registration | Brands / Services covered |
|---|---|---|
| KTM Online Limited | ZA299181 | Fonehouse, Metrofone, Buytechdirect, Network Portals. |
| Fonehouse Services Limited | ZB592855 | Fonehouse Services (fonehouseservices.co.uk) |
| KTM Device Protection Services Limited | ZC046200 | KTM Device Protection, Insurance services |
All entities are registered in England and Wales. KTM Online Limited is the parent company and policy owner. Fonehouse Services Limited and KTM Device Protection Services Limited are wholly owned subsidiaries of KTM Online Limited.
When we refer to “we”, “us”, or “our” in this policy, we are referring to the relevant KTM Online group entity that is the data controller for your relationship with us. If you are unsure which entity that is, please contact us at [email protected].
The KTM Online group operates within the LURI Group, a privately owned group of companies. Where other LURI Group companies process personal data in connection with our services, this will be disclosed in the relevant section of this policy.
Our nominated privacy contact for all group entities is [email protected].
Company details:
KTM Online Limited
Company Number: 10781202
Registered Address: 7 Treadaway Tech Centre Treadaway Hill, Loudwater, High Wycombe, Bucks, United Kingdom, HP10 9RS
Email: [email protected]
In addition to our direct retail activities, KTM Online Limited operates a white-label network portal platform which is used by third-party commercial partners to facilitate mobile SIM connections for their customers. Where we provide this platform service, we act as an independent data controller in respect of the personal data processed through it. Section 10A of this policy sets out further details of this arrangement.
3. The Personal Data We Collect
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). Our services are not intended for children under 18 and we do not knowingly collect children’s data. If you believe we hold personal data relating to a child, please contact us at [email protected].
Depending on the products and services you subscribe, we may collect and process the following categories of personal data:
- Identity & Contact Data – your name (first name, last name), title, billing address, delivery address, telephone number, date of birth, email address and in some circumstances proof of identity.
- Call and Voice Data – recordings of telephone calls, metadate (such as date, time, and duration), and any information disclosed during recorded calls.
- CCTV and Image Data – images captured by CCTV systems operating in our retail stores and premises for security, crime prevention, and safety purposes.
- Financial Data – your debit or credit card information, information about your bank account number, sort code, and other banking information, and in some circumstances other information required to validate your identity. We do not store full payment card details and use PCI-DSS compliant payment processing providers.
- Profile Data – your account information, including your username and password (not visible to Us), your preferences and interests both when you tell us what they are or when we deduce them from what we know about you, your demographic information (which we may acquire from third parties). We may process limited information where required for accessibility needs or where you provide it voluntarily.
- Transaction Data – such as how you purchased or signed up to our products and services, the products, and services you use, order history, refunds, contract details, and anything else relating your transaction with Us.
- Technical Data – includes internet protocol (IP) address, access times, any websites you linked from, pages you visit, the links you use, the ad banners and other content you view, your login data, browser type and version, information about your device, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
- Usage Data – includes information about how you use our website, products, and services.
- Marketing and Communications Data – includes your preferences in receiving marketing from us, consent records, customer service interactions, information you provide to us when entering prize draws or competitions or participate in surveys or consumer panels.
We also collect, use, and share Aggregated Data such as statistical or demographic data for business and analytical purposes. Where aggregated data is combined with personal data so that it can identify you, it will be treated as personal data under this policy.
4. How We Collect Personal Data
We collect personal data through:
- Direct interactions — when you place an order online or in store, create an account, agree to receive marketing, enter a competition, contact customer services, or give us feedback.
- Automated technologies — as you interact with our websites, we automatically collect technical data using cookies, server logs, and similar technologies. Please see our Cookie Policy for details.
- Third parties and public sources — we receive data from analytics providers, advertising networks, search information providers, payment and delivery services, and identity and credit reference agencies including CreditSafe and TransUnion.
We are not responsible for the privacy practices of third-party websites linked from our sites.
5. Lawful Basis for Processing
Under UK GDPR we must have a lawful basis for every processing activity. The table below sets out the main types of processing we carry out and the basis on which we carry out each one.
| Processing Activity | Lawful Basis | Notes |
|---|---|---|
| Processing your order and delivering products or services | Contract performance | Necessary to fulfil your purchase |
| Credit checking at point of sale | Contract performance | Cannot assess suitability without it — see Section 6 |
| Account management and customer service | Contract performance | Necessary to manage your relationship with us |
| Fraud prevention, debt recovery, and security | Legitimate interests | LIA completed; our interest in preventing harm to business and customers |
| Call recording for training, quality, and compliance | Legitimate interests / Legal obligation | Regulatory compliance and quality assurance |
| CCTV in stores | Legitimate interests | Crime prevention, staff and customer safety, property protection |
| Marketing to existing customers (email/SMS) | Legitimate interests (soft opt-in) / Consent | PECR applies; see Section 7 |
| Marketing to new customers | Consent | Explicit opt-in required |
| Analytics and website improvement | Legitimate interests / Consent | Consent required for non-essential cookies |
| Complying with legal and regulatory obligations | Legal obligation | Tax, consumer protection, FCA, HMRC, Ofcom |
| Handling data protection complaints | Legal obligation | Section 164A Data Protection Act 2018 (as amended by the DUAA 2025) |
| Upgrade and renewal contact with existing customers | Legitimate interests | Legitimate Interests Assessment completed |
| Demographic profiling and TV advertising attribution (sharing house number and postcode with third-party analytics partners) | Legitimate interests | Data minimised to house number and postcode only; customers can object at any time |
| Device protection product administration and claims handling | Contract performance | Necessary to administer your device protection product and process any claims, including to our insurance underwriter. |
| Device blacklist verification during claims process | Contract performance | As part of processing a claim we may submit your device’s IMEI number to Recipero to check whether it has been reported as stolen or blacklisted. If it has not, we will ask you to do so as a condition of your claim. |
| Fonehouse Services order processing and fulfilment | Contract performance | Processing necessary to fulfil orders placed through fonehouseservices.co.uk including passing your address to our distributors (e.g. Royal Mail) for collection of your device. |
| Fonehouse Services SMS/mobile messaging service | Consent / PECR | Marketing messages sent only with your explicit opt-in consent |
You can object to processing carried out on the basis of legitimate interests at any time. See Section 15 (Your Rights) for details.
6. Credit Checking
When you apply for a mobile phone contract or any product involving credit or a minimum-term commitment, we are required to carry out a credit check before we can enter into an agreement with you.
How credit checking works
We share certain personal data with credit reference agencies to conduct a credit assessment. We always carry out a soft search in the first instance.
- Soft search — this is carried out to assess your eligibility before you commit. A soft search does not affect your credit score and is not visible to other lenders.
- Hard search — if your application proceeds and a contract is entered into, a hard search may be recorded on your credit file. A hard search is visible to other lenders and may have a short-term effect on your credit score.
Our credit reference agency
We use TransUnion (formerly Callcredit) as our credit reference agency. TransUnion acts as an independent data controller for the purposes of maintaining credit files and providing services to other lenders. For information about how TransUnion uses your data, visit: www.transunion.co.uk/legal-information/bureau-privacy-notice.
The lawful basis for this processing is contract performance — we cannot assess whether to enter into a contract with you without it. We do not rely on your consent for this processing, and you should not be asked to consent to a credit check as a condition of proceeding.
Retention
We retain credit check outcomes for the duration of your application plus 12 months. If you enter into a contract, credit assessment data is retained for the duration of the contract plus 6 years.
Your rights
You have the right to request access to the data we hold about you in connection with a credit check, and to raise a dispute directly with TransUnion about information held on your credit file.
7. Using Your Personal Data
We use your personal data only when the law allows us to. Our main uses are:
- to verify your identity and make credit decisions, including carrying out a network credit check where you take out a network agreement with us;
- to confirm and process your orders, validate you as a registered customer, and provide customer services;
- to provide the relevant products and services and administer your account;
- to send service announcements, administrative messages, contract end notifications, upgrade eligibility communications, tariff change notices, and other non-marketing communications necessary to deliver our services. You cannot opt out of these essential communications;
- to operate CCTV in our physical stores for crime prevention, staff and customer safety, and property protection. CCTV footage may be disclosed to law enforcement where required;
- to monitor and record telephone calls for training, quality assurance, fraud prevention, dispute resolution, and regulatory compliance;
- to prevent and detect criminal activity, fraud, and misuse of our services;
- to comply with applicable laws, regulations, court orders, and requests from law enforcement and regulatory authorities;
- for internal management, research, analytics, and corporate reporting to improve our business;
- to market our products and services to you where permitted under this policy and applicable law — see Section 8 (Marketing Communications) for full details;
- to provide personalised services and targeted advertising. Please see our Cookie Policy for further information; and
- to handle data protection complaints in accordance with our legal obligations under the Data (Use and Access) Act 2025.
8. Marketing Communications
We would love to keep you informed about our latest products, services, offers, and promotions that we think may be of interest to you. We are constantly updating our range and negotiating exclusive deals, and we believe keeping you in the loop helps you get the most value from your relationship with us.
We may contact you by email, SMS, post, or telephone with marketing communications about our products, services, offers, and promotions. We will only do so where:
- you have explicitly opted in to receive marketing from us; or
- you are an existing customer, the communication relates to similar products or services to those you have purchased from us, we have provided you with a clear opportunity to opt out, and you have not done so (soft opt-in under PECR).
We will never sell your personal data to third parties for their own marketing purposes. Where we work with trusted partners to deliver offers, those partners must meet our data protection standards and any sharing of your data with them is done lawfully and transparently.
You may be contacted by other LURI Group companies for marketing purposes only where you have separately consented to this, or where it is otherwise permitted by law.
How to opt out
You can opt out of marketing communications at any time by:
- clicking “unsubscribe” in any marketing email;
- replying STOP to any marketing SMS;
- updating your account preferences on our website; or
- contacting us at [email protected] or calling 0333 900 1133.
Please allow a couple of days for all our systems to update following your opt-out request.
Service communications
Certain communications are necessary to deliver our services and are not marketing — these include order confirmations, account updates, contract notifications, tariff changes, and regulatory notices. You cannot opt out of these essential service communications. Where an upgrade or renewal notification includes a promotional offer, it will be treated as a marketing communication and will only be sent where permitted.
Follow-up contact with inbound enquirers
Where you have contacted us by telephone to enquire about our products or services but did not proceed to purchase, we may contact you to follow up on that enquiry. We rely on our legitimate interests as the lawful basis for this contact rather than your consent.
We consider this processing to be proportionate because:
- you initiated contact with us and expressed an active interest in our products or services;
- any follow-up contact is directly related to the subject of your original enquiry;
- follow-up contact is limited to a window of no more than 60 days from the date of your original inbound call; and
- we do not use your details for any broader marketing purpose on this basis.
This type of follow-up contact is distinct from our general marketing activity. It is time-limited and tied to your specific enquiry rather than being a general promotional communication.
You have the right to object to this processing at any time. If you do not wish to be contacted following an inbound enquiry, please tell us during your call or contact us at [email protected]. We will record your objection and ensure no further follow-up contact is made.
9. Cookies and Tracking Technologies
Our websites use cookies and similar technologies. Some cookies are essential for the operation of our websites. Others require your consent.
Under changes introduced by the Data (Use and Access) Act 2025, certain analytics cookies that are used solely to collect statistical data and improve website functionality may be set without consent, provided we offer you a clear opt-out. Our Cookie Policy sets out which categories of cookie we use, the basis on which each is set, and how to manage your preferences.
You can manage your cookie preferences at any time through our Cookie Settings on the website. You can also set your browser to refuse cookies, though some parts of our website may not function correctly if you do so.
10. Who We Share Your Data With
We do not sell your personal data. We may share your personal data with the following categories of recipients:
KTM Online group companies
As a group of companies under common ownership, KTM Online Limited, Fonehouse Services Limited, and KTM Device Protection Services Limited may share personal data with each other where necessary for the following purposes:
- group-wide fraud prevention and security monitoring
- shared technology infrastructure and platform services
- group compliance and regulatory reporting obligations
- internal administration and group financial reporting
Where personal data is shared between group entities, each entity remains independently responsible for its own data protection compliance. Personal data shared within the group is not used by any group entity for purposes beyond those described above without a separate lawful basis.
Mobile Network Providers — independent controllers
When you take out a mobile contract through us, we share your personal data with the relevant Mobile Network Provider (such as Vodafone, Three, Talkmobile, VOXI, Sky Mobile, EE, or BT) to enable them to activate and manage your connection. These network providers act as independent data controllers for the purposes of managing your network account and their own services. Their use of your data is governed by their own privacy policies, not this one. Links to the relevant network privacy notices are available on our website.
Franchise stores
Our franchise stores operate under licence from Fonehouse. When you purchase in a franchise store, the store processes your personal data on our behalf. KTM Online Limited remains the data controller. Franchise stores do not use your data for their own purposes and are contractually required to handle your data in accordance with our data protection standards.
Group companies
We may share your personal data with other companies within the LURI Group where they are acting as processors on our behalf or as joint controllers. We will identify when this is the case.
Service providers
We share personal data with service providers who assist with the delivery, distribution, and marketing of our products and services, payment processing, and other business functions. These providers act on our instructions, are contractually bound to process your data only as we direct and must maintain appropriate security measures.
Credit and identity agencies
We share data with credit reference agencies (including TransUnion) and fraud prevention agencies. These agencies may act as independent controllers for their own credit file and fraud prevention purposes.
Device protection partners
Where you hold a device protection product with KTM Device Protection Services Limited, your personal data may be shared with:
- underwriters who provide the underlying insurance product.
- internally with KTM Online or its partners/franchisees who are authorised to carry out repairs under your protection plan.
- Recipero, an independent device verification service, to whom your device’s IMEI number is submitted during the claims process to check whether the device has already been reported as stolen or blacklisted. This check is a procedural step only – no decision on your claim is made from its outcome. Recipero acts as an independent data controller in respect of this check. Their privacy policy is available at recipero.com.
- the FCA and other regulatory bodies where required by law.
Law enforcement and regulators
We may disclose personal data to law enforcement agencies, regulators, courts, and public authorities where we are legally required or permitted to do so.
Business transfers
If we sell, buy, merge, or reorganise our business, personal data may be shared with prospective or actual purchasers or partners and their advisers as part of that process.
Marketing analytics and advertising attribution partners
We may share your house number and postcode with trusted third-party marketing analytics partners for two purposes:
- to help us understand the demographic profile of our customer base; and
- to measure the effectiveness of our advertising, including identifying whether households have been exposed to our television advertisements.
We rely on our legitimate interests as the lawful basis for this processing. We have assessed that this activity does not override your rights and interests, and we share only the minimum data necessary — your house number and postcode. Your details are not used by these partners to contact you directly, and we do not share your name, email address, telephone number, or any other identifying information for this purpose.
You have the right to object to this processing at any time. To do so, please contact us at [email protected]. We will apply your objection before any further data is shared.
10A. White-Label Network Portal — Third-Party Partner Arrangements
KTM Online Limited operates a white-label portal platform through which authorised third-party commercial partners (such as Core Communication Retail Limited) to enable their retail network to sell mobile SIM connections to end customers.
Our role in this arrangement
Where personal data is submitted through the portal in connection with a SIM connection, KTM Online Limited acts as an independent data controller. We determine our own purposes and means of processing in respect of that data, which are:
- facilitating the connection of end customers to the relevant Mobile Network Operator;
- managing our relationship with the Mobile Network Operator in connection with that connection; and
- calculating and administering commissions due under our commercial arrangements with the third-party partner.
We are not acting as a processor on behalf of the third-party partner in this context. Each party is independently responsible for its own data protection compliance.
What data we receive and why
Through the portal we receive personal data entered by retail store staff on behalf of end customers at the point of sale. This typically includes name, date of birth, address history, email address, and bank details. We receive this data solely for the purposes described above and do not use it for any other purpose, including our own direct marketing.
Who else receives this data
The end customer’s personal data is shared with the relevant Mobile Network Operator to enable credit checking and network activation. The network operator acts as an independent data controller for those purposes. Their privacy policies govern their use of the data.
The third-party partner’s role
The third-party commercial partner (for example Core Communication Retail Limited) is the data controller in respect of the end customer relationship. They are responsible for ensuring end customers are informed about how their data is used, including its transmission to KTM Online Limited and to the relevant Mobile Network Operator. End customers should refer to the third-party partner’s privacy policy for information about how their data is handled in the context of their purchase.
Your rights
If you are an end customer whose data has been processed through this portal arrangement and you wish to exercise your data subject rights in respect of KTM Online Limited’s processing, please contact us at [email protected]. Where a request relates to data held by the third-party partner or the Mobile Network Operator, we will direct you to the appropriate party.
Data retention
Personal data received through the portal is retained for the duration of the connection arrangement plus six years, in line with our standard retention periods set out in Section 12.
11. International Transfers
Some third parties we work with — including technology providers, payment processors, and analytics services — may process your personal data outside the United Kingdom.
Under the Data (Use and Access) Act 2025, we assess whether the level of protection for your personal data in any destination country is not materially lower than UK standards (the “Data Protection Test”). We only transfer personal data internationally where:
- the destination country has been confirmed by the UK Government as providing an adequate level of protection through an adequacy regulation;
- we have put in place appropriate safeguards — such as a UK International Data Transfer Agreement (IDTA) or UK Addendum to EU Standard Contractual Clauses — and have completed a transfer risk assessment confirming the Data Protection Test is satisfied; or
- one of the limited derogations under Article 49 UK GDPR applies.
For information about the specific safeguards in place for any international transfer, or to request a copy of the relevant transfer mechanism, please contact us at [email protected].
12. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected, including to satisfy legal, regulatory, tax, accounting, and reporting requirements. We may retain data for longer where there is an ongoing legal dispute, complaint, or regulatory investigation, retaining only what is necessary for as long as required.
The table below sets out how long we typically retain different categories of data:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account and purchase history | 6 years from last transaction | Legal obligation / Limitation Act 1980 |
| Contract and identity data | Duration of contract + 6 years | Limitation Act 1980 |
| Credit check results | Application duration + 12 months; if contract entered, contract duration + 6 years | Proportionality / Limitation Act |
| Customer service records and correspondence | 3 years from interaction | Dispute resolution / quality assurance |
| Call recordings | 3 years (standard); longer where required for regulatory compliance | Quality / compliance |
| Marketing preferences and consent records | Duration of opt-in + 3 years; suppression records kept indefinitely | ICO guidance / PECR |
| Insurance-related records | 7 years from policy end | FCA requirements |
| CCTV footage | 31 days ordinarily; up to 90 days where an incident has occurred | Crime prevention proportionality |
| Prospective customer data (no contract) | 90 days from initial enquiry | Legitimate interests (time-limited) |
| Data protection complaint records | 6 years from resolution | Accountability / Limitation Act 1980 |
| Fraud prevention records | 6 years | Legitimate interests / legal obligation |
In some circumstances we will anonymise your personal data for research or statistical purposes, in which case it is no longer personal data and may be used without further notice.
For more information about how long we keep a specific type of data, or to request deletion, please contact us at [email protected].
13. Automated Decision-Making
What is automated decision-making?
Automated decision-making is where a decision is made about you using only automated processes, without meaningful human involvement, and that decision has a legal or similarly significant effect on you. UK GDPR gives you specific rights in these situations.
Credit and fraud assessments
When you apply for a product or service directly with us that involves a minimum-term commitment or credit, we use automated tools to carry out an initial eligibility assessment. This may include an automated soft credit check via TransUnion and an automated fraud screening check.
Where an automated assessment produces a result that affects whether we can offer you a product or service, this constitutes automated decision-making with a legal or similarly significant effect. In these cases, you have the right to:
- request that the decision is reviewed by a member of our team rather than determined solely by automated means;
- express your point of view in relation to the decision; and
- contest the decision where you believe it is wrong.
To exercise any of these rights, please contact us at [email protected].
Credit assessments carried out by Mobile Network Operators
Where you take out a contract that connects you to a mobile network, the network provider (such as Vodafone, Three, EE, or others) will carry out their own credit assessment as an independent data controller. That credit decision is made by the network, not by us, and the network’s own automated decision-making processes and rights apply. If you wish to contest a network credit decision or request human review of it, you should contact the relevant network provider directly. Links to network privacy notices are available on our website.
Profiling for personalisation and advertising
We use automated tools to personalise the content, offers, and advertising you see on our websites and in our marketing communications. This involves profiling based on your browsing behaviour, purchase history, and preferences.
This type of profiling does not produce decisions with a legal or similarly significant effect on you. However, you have the right to object to it at any time. To do so, please contact us at [email protected] or manage your preferences through our Cookie Settings on the website. See also Section 15 (Your Rights) for further details.
14. Data Security
We maintain the highest standards of data privacy and security to protect your personal details and other information about your account because we want you to feel completely confident about using our services. We regularly review our processes and procedures to protect your personal information from unauthorised access and use, accidental loss, and/or destruction.
We maintain appropriate technical and organisational measures to protect your personal data from unauthorised access, accidental loss, destruction, or disclosure. These include:
- encrypted transmission links and secure server storage;
- role-based access controls, authentication requirements, and regular access reviews;
- PCI-DSS compliant payment processing — we do not store full payment card numbers;
- regular testing and monitoring of our IT systems to identify vulnerabilities;
- staff data protection and security training appropriate to each role;
- documented incident response procedures for suspected personal data breaches.
Where required by data protection law, we will notify affected individuals and the ICO of a personal data breach without undue delay.
If you believe you have identified a security vulnerability in our website or systems, please contact us at [email protected].
15. Your Rights
Under UK data protection law you have the following rights in relation to your personal data:
- Right to make a data protection complaint to us — from 19 June 2026, under section 164A of the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), you have a statutory right to raise a data protection complaint directly with us if you believe we have infringed your rights. See Section 16 (Data Protection Complaints) for how to do this.
- Right of access — you may request a copy of the personal data we hold about you (a subject access request). We will carry out a reasonable and proportionate search of our records.
- Right to rectification — you may ask us to correct inaccurate or incomplete personal data. We may need to verify the accuracy of the replacement data.
- Right to erasure — you may ask us to delete your personal data where there is no good reason for us to continue processing it, where you have successfully objected to processing, where processing was unlawful, or where erasure is required by law. We may not always be able to comply where we have a legal or legitimate reason to retain data.
- Right to object — you may object to processing carried out on the basis of our legitimate interests, or to direct marketing. In some cases we may have compelling grounds to continue processing despite your objection.
- Right to restrict processing — you may ask us to suspend processing in certain circumstances, for example while we verify the accuracy of data or consider your objection.
- Right to data portability — you may request that we provide your personal data to you or a third party in a structured, machine-readable format. This applies to data you provided to us and which we process on the basis of contract or consent.
- Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at [email protected]. We will respond to legitimate requests within one month. Where requests are complex or numerous we may extend this by a further two months and will notify you accordingly. We will not charge a fee unless a request is manifestly unfounded, repetitive, or excessive.
We may need to verify your identity before responding to a rights request.
16. Data Protection Complaints
Under section 164A of the Data Protection Act 2018, as introduced by the Data (Use and Access) Act 2025, you have a statutory right to raise a data protection complaint directly with us. This right came into force on 19 June 2026.
A data protection complaint is any expression of concern or dissatisfaction about how we have handled your personal data. You do not need to use formal legal language — if you are unhappy with anything related to how your personal data has been used, we want to hear from you.
Complaints relating to subsidiary entities
If your complaint relates specifically to the processing of your personal data by Fonehouse Services Limited or KTM Device Protection Services Limited, please contact us at [email protected] identifying the relevant brand or service in your correspondence. We will ensure your complaint is handled by the appropriate entity. The statutory right to raise a complaint directly with the controller and receive a response within 30 days applies equally to all three KTM Online group entities.
How to make a data protection complaint to us
You can submit a data protection complaint by any of the following methods:
- Email — [email protected] (please include “Data Protection Complaint” in the subject line)
- Post — Data Protection Lead, KTM Online Limited, Unit 5 E-Centre, Easthampstead Road, Bracknell, RG12 1NF
- Telephone — 0333 900 1133 (ask to speak to the Data Protection team)
We will also accept complaints received through any other channel — including in store, by social media, or through a general customer service contact — and route them into our data protection complaints process. You do not need to use a specific form or channel.
What happens next
- We will acknowledge your complaint within 30 calendar days of receiving it.
- We will investigate your complaint without undue delay and keep you informed of progress.
- We will tell you the outcome of our investigation, what steps we have taken, and any action we are taking as a result.
- If you are unhappy with our response, or if we fail to respond, you have the right to escalate your complaint to the ICO at any time.
Escalation to the ICO
The Information Commissioner’s Office (ICO) is the UK’s independent regulator for data protection. You have the right to lodge a complaint with the ICO at any time — you do not have to come to us first, though we would appreciate the opportunity to resolve your concern directly.
- ICO website: ico.org.uk
- ICO helpline: 0303 123 1113
- ICO address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
17. Contact Us
We are always looking for new ways to improve your shopping experience with us, that is why we love hearing from you. If you have any questions about how we use your personal data or if you would like to amend or stop us from processing your data (for marketing purposes), please contact us.
If you have any questions about this privacy policy or how we use your personal data, or for all data protection enquiries, subject access requests, rights requests, and complaints relating to any KTM Online group entity, please contact us using the following details:
- Email: [email protected]
- Telephone: 0333 900 1133 (Mon–Thurs 09:00–18:00, Fri 10:00–18:00, Sat 09:00–17:00)
- Post: Data Protection Lead, KTM Online Limited, Unit 5 E-Centre, Easthampstead Road, Bracknell, RG12 1NF
We have appointed a Data Protection Lead (DPL) to oversee our compliance with data protection law. The DPL is an internal role responsible for data protection governance and can be contacted at the details above. Please identify in your correspondence which brand or service your enquiry relates to so we can ensure it is directed to the correct entity and data controller within the group.
If you fail to provide personal data that we are required by law or contract to collect, we may not be able to perform the contract we have with you. We will notify you if this is the case.
18. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, applicable law, or regulatory guidance. We will update the version number and date at the top of this policy when we do so. Where changes are material, we will take reasonable steps to notify you directly.
This policy is version 3.0, last updated 15 July 2026. It replaces version 2.0 dated 25 February 2026.