Legal
Privacy Policy
Last updated:
1. Who we are
Go Unbounded Ltd (“Go Unbounded”, “we”, “us”) provides mobile connectivity services, including SIMs, eSIMs and mobile routers, primarily to UK businesses.
We are the data controller for the personal data described in this policy.
- Company
- Go Unbounded Ltd
- Company number
- 16542452
- Registered office
- Ra01 Suite 195 Wood Street, London, England, E17 3NU
- ICO registration
- ZB995991
- Contact
- support@go-unbounded.co.uk
This policy explains what personal data we collect, why, how long we keep it, and the rights you have under UK data protection law. Where we act as a provider of electronic communications services, we are also subject to the Privacy and Electronic Communications Regulations (PECR).
2. Who this policy covers
This policy applies to:
- People who buy or use our services, including named users on a business account
- People invited to join an existing account
- People who visit our website or contact us
Where a business buys our services, that business is our customer, but the individuals named on the account are still covered by this policy in their own right.
3. What we collect
Account and order information. Name, business name, email address, phone number, billing address, and shipping address where hardware is being sent.
Service information. SIM card ID (ICCID), eSIM details, router identifiers, service nicknames and other labels you apply, plan and add-on selections including EU roaming, and the current status of each service.
Portal information. Your login credentials (passwords are stored in hashed form and we cannot see them), authentication and session records, login events, the other users on your account, and the permissions assigned to them.
Invitations. If you invite someone to your account, we collect their email address in order to send the invitation, along with the permissions you have assigned them. We hold this from the point of invitation, whether or not it is accepted.
Connectivity and network data. See section 4, which describes this in full.
Support communications. The content of emails you send us and our replies, together with any information you provide in the course of resolving an issue.
Payment information. Order value, payment status, and a partial card reference. Full card details are handled by Stripe and never reach our systems.
Website information. Pages viewed, referral source, approximate location derived from IP address, device and browser type, and interaction with our checkout. Analytics data is only collected where you have consented. See section 7.
4. Connectivity and network data
We think you should know exactly what our network can and cannot see, so this section is more detailed than the rest.
Traffic routing. Data from our SIMs is carried over a private APN: network infrastructure we operate ourselves rather than a shared public gateway. This gives you a more controlled and secure route to the internet, and it means your traffic passes through servers under our management.
Usage records. Our carrier partner provides us with connection start and end times and total data volumes for each SIM. We use these to bill you accurately, apply plan allowances, monitor for faults, and detect misuse. We do not receive location or cell site data, and we do not track the physical whereabouts of your devices.
DNS queries. Our own DNS resolvers translate domain names into addresses when your devices connect to the internet. This is a necessary part of providing connectivity, and it means our systems process a record of the domains your devices request. Those records are held for 7 days and then automatically deleted. We use them only for network security, fault diagnosis, abuse detection, and DNS-level content filtering where it applies to your plan.
Within that 7-day window it is technically possible for us to see which domains a particular SIM has requested. Access is limited to staff who need it to operate the network, and we do not use this data for marketing, profiling, or building any picture of your business activity.
What we do not do. We do not inspect the contents of your traffic. We cannot read your messages, see the content of pages you load, or access data sent over encrypted connections. We do not sell, share, or otherwise make network or usage data available to advertisers, data brokers, or any other third party, except where we are legally required to disclose it.
Lawful disclosure. Like any communications provider, we may be required to disclose information in response to a valid legal request from law enforcement, a court, or a regulator. We will only do so where we are satisfied the request is lawful and properly made.
5. Why we use your data, and our lawful basis
| What we do | Lawful basis |
|---|---|
| Set up, deliver and manage your connectivity service | Contract |
| Ship, replace and process returns of hardware | Contract |
| Take payment and manage billing | Contract |
| Provide and secure the customer portal | Contract |
| Respond to support requests | Contract |
| Send invitations to join an account | Legitimate interests: enabling account holders to manage their team |
| Operate and secure the network, diagnose faults | Legitimate interests: keeping the service reliable and safe |
| Detect fraud and misuse | Legitimate interests: protecting our business and other customers |
| Analyse usage patterns to improve the service | Legitimate interests: improving what we offer |
| Send marketing email | Legitimate interests for business subscribers, or consent |
| Website analytics and advertising measurement | Consent |
| Keep accounting and tax records | Legal obligation |
| Respond to lawful requests from authorities | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights, and concluded it is not. You can ask us for the reasoning behind any of these assessments, and you can object at any time. See section 12.
6. Who we share your data with
We do not sell your personal data, and we do not share it with third parties for their own marketing.
We use a small number of service providers who process data on our behalf, under contracts requiring them to protect it and act only on our instructions:
- Stripe: payment processing and fraud screening. Stripe handles card details directly; we never receive them.
- Cloud hosting and database provider: storing account, service and order data
- Application hosting provider: running our website, checkout and customer portal
- Network and DNS infrastructure providers: the servers and connectivity underpinning our private APN
- Transactional email provider: order confirmations, eSIM delivery, account notifications
- Marketing email provider: newsletters and product updates
- Carrier partner: the underlying mobile network carrying your traffic
- Delivery and logistics providers: shipping hardware to you, which requires sharing your name and delivery address
- Analytics and advertising providers: where you have consented, as described in section 7
- Professional advisers: accountants and legal advisers, where needed
A current list of our named sub-processors is available on request from support@go-unbounded.co.uk.
We may also disclose data where required by law, or in connection with a sale or restructuring of our business, in which case you would be notified.
7. Cookies, analytics and advertising
Our website uses cookies and similar technologies. Strictly necessary cookies, meaning those needed for the site, checkout and portal to function, are set automatically. Everything else, including analytics and advertising cookies, is only set once you have given consent through our cookie banner.
Where you consent, we use Google Analytics and Google Ads conversion tracking to understand how people find and use our site and to measure the effectiveness of our advertising. You can change or withdraw your consent at any time through the cookie settings on our website.
8. Marketing
We may send you marketing email about our products and services. Every marketing email includes an unsubscribe link, and you can opt out at any time without affecting your service.
If you are a sole trader or an individual, we will only send marketing where you have consented or where you have bought from us and not opted out. If you represent a limited company, LLP or other corporate subscriber, we may send marketing on the basis of our legitimate interests, and you can opt out at any time.
Service and account emails, such as order confirmations, delivery notifications, billing, outage and security notices, are not marketing, and you cannot opt out of these while you hold an active service.
9. International transfers
We are based in the UK and our network infrastructure is located in the UK and the Netherlands. Data transferred within the UK and EEA is covered by UK adequacy regulations.
Some of our providers, including Stripe, process data in the United States or elsewhere outside the UK. Where this happens, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an applicable adequacy decision.
If you use EU roaming, your traffic will be carried by network operators in the country you are visiting, as is inherent to how mobile roaming works.
You can ask us for details of the safeguards applying to any particular transfer.
10. How long we keep it
| Data | Retention period |
|---|---|
| DNS query records | 7 days |
| Detailed usage records | 12 months |
| Account and service data | 12 months after your account closes |
| Billing and accounting records | 6 years from the end of the relevant financial year |
| Support correspondence | 2 years from the last message |
| Unaccepted invitations | 12 months from the invitation |
| Marketing suppression list | Indefinitely, so we can honour your opt-out |
| Website analytics | 14 months |
Where we need to keep something longer, for example an unresolved dispute or an ongoing legal matter, we will keep only what is necessary for that purpose, and delete it once resolved.
11. How we protect your data
We encrypt data in transit and at rest. Access to customer data is restricted to staff who need it, protected by individual accounts and multi-factor authentication. Passwords are stored hashed and are not visible to us. We keep our systems patched, review access periodically, and log administrative activity.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within the applicable deadline and, where the risk is high, notify you directly without undue delay.
12. Your rights
You have the right to:
- Access the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete your data, where we have no continuing need or legal obligation to keep it
- Restrict how we process your data in certain circumstances
- Object to processing based on legitimate interests, and to direct marketing at any time. An objection to marketing is always honoured
- Portability: receive data you gave us in a machine-readable format, or have it sent to another provider
- Withdraw consent at any time, where consent is the basis for processing
To exercise any of these, email support@go-unbounded.co.uk. We will respond within one month, and will tell you if we need longer because a request is complex.
If you are unhappy with how we have handled your data, please raise it with us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113.
13. Automated decision-making
We use Stripe’s fraud screening tools, which assess transactions automatically and may decline a payment. If a payment is declined and you believe it was in error, contact us and a member of our team will review it.
We may suspend or restrict a service where we have reason to believe it is being used to deliberately circumvent plan data limits, or otherwise in breach of our terms. Suspension decisions are reviewed by a member of our team rather than made automatically, and we will tell you why and how to challenge it.
We do not carry out credit checks, and we do not make solely automated decisions producing legal or similarly significant effects on you.
14. Age
Our services are sold to businesses and to adults. You must be 18 or over to open an account or buy from us. We do not knowingly collect data from children, and if we learn we have, we will delete it.
15. Changes to this policy
We may update this policy as our services develop. The current version is always available on our website, and the date at the top shows when it last changed. Where a change materially affects how we handle your data, we will notify account holders by email at least 30 days before it takes effect.
16. Contact
Questions about this policy or how we handle your data:
- Company
- Go Unbounded Ltd
- Address
- Ra01 Suite 195 Wood Street, London, England, E17 3NU
- support@go-unbounded.co.uk
- Company number
- 16542452
- ICO registration
- ZB995991