Privacy Policy
Effective date: 21 September 2026
Key points
This summary is provided for convenience. The full terms of this Policy are set out below.
- We use Personal Data only where necessary to provide and secure the Services, respond to you, comply with our legal obligations, and for the other purposes described in this Policy.
- We don’t sell any data collected or use it for advertising.
- You can ask to see, correct or delete your information at any time.
1. Introduction and scope
-
1.1 This Privacy Policy (the “Policy”) sets out the
basis on which BMCE Networks Ltd (“BMCE”,
“we”, “us” or
“our”) collects, uses, stores, discloses and
otherwise processes Personal Data in connection with:
- the B7000 Android application (the “Application”);
- our website at b7000.net (the “Website”); and
- any correspondence or other dealings between you and us relating to B7000,
- 1.2 This Policy is issued in accordance with Articles 13 and 14 of the UK GDPR and the EU GDPR and Article 19 of the Swiss Federal Act on Data Protection. It should be read together with our B7000 Terms and Conditions and the terms under which a Customer subscribes to the Services (together, the “Licence Terms”).
-
1.3 The Application is provided by BMCE to Customers as a service for
a defined term. Customers may authorise employees or other individuals
to use the Application in the course of carrying out their duties.
BMCE operates the Services and determines the purposes and mean of
processing Personal Data in connection with them.
In this Policy, “you” means an Authorised User or any other individual whose Personal Data we process in connection with the Services, such as a visitor to the Website or a person who corresponds with us. - 1.4 By using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with it, you should not use the Services.
2. Definitions and interpretation
- 2.1 In this Policy, the following terms have these meanings:
- BMCE
- BMCE Networks Ltd, which operates and provides the Services, including the Application, Website and Web App, and determines the purposes and means of processing Personal Data in connection with the Services.
- Active Survey
- Any period during which the Application is running and has been activated to carry out a survey, including while it runs in the background.
- Authorised User
- An employee or other individual authorised by a Customer to use the Application in the course of carrying out their duties for that Customer.
- Customer
- A business or other organisation that has purchased the right to use the Services, including the Application, and is authorised to provide Device Accounts to it's Authorised Users.
- Data Protection Legislation
- All laws relating to data protection and privacy that apply to our processing of Personal Data, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, the EU GDPR, Directive 2002/58/EC and the Swiss Federal Act on Data Protection of 25 September 2020, each as amended, extended or replaced from time to time.
- Device Account
- The account and credentials that we issue to a Customer for use on a device so that it can access the Services.
- EU GDPR
- Regulation (EU) 2016/679 (the General Data Protection Regulation).
- Service Provider
- A third party that processes Personal Data on our behalf and under our instructions.
- UK GDPR
- The EU GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.
- Web App
- The B7000 web application, made available to Customers through the Website, through which Customers access the results of the Services.
- 2.2 “Personal Data”, “Controller”, “Processor”, “Processing” (and “process”), “Data Subject” and “Personal Data Breach” have the meanings given to them in the Data Protection Legislation.
- 2.3 Headings are for convenience only and do not affect the interpretation of this Policy. The words “including”, “include” and “for example” are illustrative and do not limit the words before them.
3. Data controller
- 3.1 BMCE Networks Ltd is the Controller of the Personal Data described in this Policy. BMCE determines the purposes for which and the means by which Personal Data processed in connection with the Services.
- 3.2 Customers subscribe to the Services and may authorise individuals to use the Application. BMCE operates and provides the Services and determines how Personal Data is processed in connection with the Services.
- 3.3 An Authorised User controls when the Application is activated to carry out a survey. Location data is collected only during an Active Survey and is not collected by the Application outside an Active Survey.
- 3.4 Our contact details are set out in section 15. All enquiries relating to this Policy or to our processing of Personal Data, including requests to exercise your rights under section 11, should be directed to support@bmce-networks.com.
- 3.5 The contact details in section 15 should be used for all data protection matters.
4. Personal Data we collect
- 4.1 Device Account data. To access the Services, the Application must authenticate using a Device Account. On authentication, the Application transmits to us the Device Account username and password and the device’s Android ID. The Device Account identifies a device rather than an individual. However, because data relating to a device, including its location, may relate to an identifiable individual carrying that device, we treat such data as Personal Data. Device Account passwords are transmitted only over an encrypted connection (see section 9), are not stored on the device, are stored on our servers only in a secure, non-reversible (hashed) form, and are never recorded in any log.
- 4.2 Location data. During an Active Survey, the Application records the device’s precise geographic location at the frequency selected by the Authorised User in the Application’s settings. The Application determines location using a combination of satellite positioning (GPS) and network-based positioning, which uses nearby Wi-Fi access points and mobile network cells. Network-based positioning is provided by Google Play services, which processes such information in accordance with Google’s privacy policy. Where the Application is running in the background, the device displays a persistent notification. The Application does not record location data outside an Active Survey. Location data is transmitted to and stored on our servers, associated with the relevant Device Account, and is used to display where survey results were recorded on maps in the Application and the Web App.
- 4.3 Crash and error data. If the Application crashes or encounters an error, it transmits a crash and error report to Sentry, our error-monitoring Service Provider. Such reports contain technical information including the device model, operating system version, Application version and the sequence of events immediately preceding the error.
- 4.4 Technical data. When the Application or the Website connects to our servers, we automatically receive technical information including the IP address, device type and operating system and, in the case of the Website, the browser type.
- 4.5 Correspondence data. If you contact us, we receive the information you choose to provide, including your email address and the content of your correspondence.
-
4.6 Data we do not collect. We do not:
- process special categories of Personal Data within the meaning of Article 9 of the UK GDPR and EU GDPR (including data revealing racial or ethnic origin, religious beliefs, health or sexual orientation), sensitive personal data within the meaning of the Swiss Federal Act on Data Protection, or Personal Data relating to criminal convictions and offences;
- obtain Personal Data about you from third parties;
- use advertising identifiers, advertising networks or tracking pixels in the Application;
- use artificial intelligence technologies to process your Personal Data;
- make decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 of the UK GDPR and EU GDPR; or
- send direct marketing communications.
- 4.7 Cookies. Where the Website uses cookies or similar technologies that are not strictly necessary for its operation, we will obtain your consent before doing so, in accordance with the Data Protection Legislation.
5. Purposes and lawful bases of processing
- 5.1 We process Personal Data only where we have a lawful basis to do so under Article 6(1) of the UK GDPR and EU GDPR. The purposes for which we process Personal Data, and the lawful bases on which we rely, are as follows:
| Purpose | Categories of Personal Data | Lawful basis |
|---|---|---|
| Providing the Application, authenticating devices and displaying survey results on maps | Device Account data, location data, technical data | Legitimate interests (Article 6(1)(f)) in providing the Services to the Customer under the Licence Terms, so that its Authorised Users can carry out their duties |
| Identifying, diagnosing and rectifying faults | Crash and error data, technical data | Legitimate interests (Article 6(1)(f)) in maintaining the reliability of the Application |
| Maintaining security and preventing misuse or fraud | Device Account data, technical data | Legitimate interests (Article 6(1)(f)) in protecting the Services and their users |
| Responding to correspondence and requests | Correspondence data | Legitimate interests (Article 6(1)(f)) in responding to enquiries; compliance with a legal obligation (Article 6(1)(c)) where you exercise your rights under the Data Protection Legislation |
| Complying with legal and regulatory obligations and establishing, exercising or defending legal claims | Any of the above, as necessary | Compliance with a legal obligation (Article 6(1)(c)); legitimate interests (Article 6(1)(f)) |
| Protecting the life or physical safety of any person | Any of the above, as necessary | Vital interests (Article 6(1)(d)) |
- 5.2 Where we rely on legitimate interests, we have carried out a balancing test and concluded that those interests are not overridden by your interests or fundamental rights and freedoms. You may object to such processing in accordance with section 11.
- 5.3 Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- 5.4 The provision of Device Account data and location data is necessary for the Application to function. If this data is not provided, the Application, or certain of its features, will not operate.
6. Disclosure of Personal Data
-
6.1 We do not sell Personal Data or disclose it for advertising
purposes. We disclose Personal Data only as follows:
- Customers. We make available to each Customer, through the Web App, the Personal Data collected by the Application on devices using that Customer’s Device Accounts, including location data, so that the Customer can use the results of the Services. Each Customer is deployed as a separate, single-tenant instance of the Services, and its data is not stored with, or accessible to, any other Customer. Access to the Web App requires authentication and is encrypted in transit using TLS over HTTPS.
- Service Providers. We engage Service Providers, including hosting and infrastructure providers and Sentry. Service Providers act as our Processors under written agreements that comply with Article 28 of the UK GDPR and EU GDPR, and may process Personal Data only on our documented instructions.
- Legal requirements. We may disclose Personal Data where required to do so by law, regulation, court order or other legal process, or in response to a lawful request from a public authority.
- Protection of rights and safety. We may disclose Personal Data where we believe in good faith that disclosure is necessary to protect our rights or property, your safety or the safety of others, or to investigate or prevent fraud.
- Business transfers. We may disclose or transfer Personal Data in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or part of our business. Any recipient will be required to protect Personal Data to a standard no less protective than this Policy.
7. International transfers
- 7.1 Certain Service Providers, including Sentry, may process Personal Data outside the United Kingdom, the European Economic Area (“EEA”) and Switzerland, in countries that may not offer an equivalent level of data protection.
-
7.2 Where we make such a transfer, we ensure that it is subject to an
appropriate safeguard under Chapter V of the UK GDPR and EU GDPR and
Articles 16 and 17 of the Swiss Federal Act on Data Protection,
including:
- adequacy regulations or decisions confirming that the destination country provides an adequate level of protection;
- the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, together with the International Data Transfer Addendum issued by the UK Information Commissioner and any amendments required for transfers from Switzerland; or
- any other safeguard or derogation permitted by the Data Protection Legislation.
- 7.3 You may request further information about, or a copy of, the relevant safeguards by contacting us using the details in section 15.
8. Data retention
-
8.1 We retain Personal Data only for as long as is necessary for the
purposes for which it was collected, as follows:
- Device Account data and location data: for the duration of the Device Account and for 12 months after it is closed;
- crash and error data and technical data: for up to 24 months from collection;
- correspondence data: for as long as necessary to deal with the relevant enquiry or request and to maintain a record of it; and
- anonymised or aggregated data that no longer identifies any individual: indefinitely.
- 8.2 We may retain Personal Data for longer where required to do so by law or for the establishment, exercise or defence of legal claims.
- 8.3 At the end of the applicable retention period, we delete or anonymise Personal Data. Where this is not immediately possible (for example, because the data is held in backup archives), we store it securely and isolate it from further processing until deletion is possible.
9. Security
- 9.1 We implement appropriate technical and organisational measures, in accordance with Article 32 of the UK GDPR and EU GDPR, to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage. Access to Personal Data is restricted to authorised personnel and contractors who require it for the performance of their duties.
- 9.2 All data transmitted between the Application or the Website and our servers, and between the Application and our Service Providers, is encrypted in transit using Transport Layer Security (TLS) over HTTPS. The Application does not permit unencrypted connections.
- 9.3 No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee the absolute security of Personal Data.
- 9.4 In the event of a Personal Data Breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.
10. Age restriction
- 10.1 The Services are intended solely for persons aged 18 years or over. We do not knowingly collect Personal Data from, or market the Services to, persons under the age of 18.
- 10.2 If we become aware that we have collected Personal Data from a person under the age of 18, we will deactivate the relevant Device Account and promptly delete that data. If you believe that we hold such data, please contact us at support@bmce-networks.com.
11. Your rights
-
11.1 If you are located in the United Kingdom, the EEA or Switzerland,
you have the following rights under the Data Protection Legislation,
subject to the conditions and exemptions set out in it:
- the right of access to your Personal Data (Article 15);
- the right to rectification of inaccurate or incomplete Personal Data (Article 16);
- the right to erasure (Article 17);
- the right to restriction of processing (Article 18);
- the right to data portability (Article 20);
- the right to object to processing based on legitimate interests (Article 21);
- the right to withdraw consent, where processing is based on consent (Article 7(3)); and
- the right not to be subject to a decision based solely on automated processing (Article 22).
- 11.2 To exercise any of these rights, please contact us at support@bmce-networks.com. We may request information to verify your identity before responding. You may authorise another person to make a request on your behalf.
- 11.3 We will respond without undue delay and in any event within one month of receipt of your request. Where necessary, taking into account the complexity and number of requests, we may extend this period by up to two further months, in which case we will inform you of the extension and the reasons for it within the initial one-month period.
- 11.4 We will not charge a fee for responding to a request, except where the request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on it, as permitted by the Data Protection Legislation.
Complaints
- 11.5 If you are dissatisfied with how we have handled your Personal Data, we ask that you contact us in the first instance. We will acknowledge your complaint within 30 days of receipt, investigate it without undue delay, keep you informed of its progress and notify you of the outcome.
-
11.6 You also have the right to lodge a complaint with a supervisory
authority, in particular in the country where you live or work or
where the alleged infringement took place:
- United Kingdom: the Information Commissioner’s Office (ICO), ico.org.uk/make-a-complaint, telephone 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF;
- EEA: the supervisory authority in your member state, as listed at edpb.europa.eu/about-edpb/members_en; and
- Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch.
12. Ceasing collection
- 12.1 You may cease the collection of location data at any time by ending the Active Survey or by revoking the Application’s location permission in your device settings. Certain features of the Application will not function without location data.
- 12.2 You may cease all further collection by the Application by uninstalling it, and all further collection by the Website by ceasing to use it.
- 12.3 Ceasing collection does not result in the deletion of Personal Data already held by us. To request deletion, please contact us in accordance with section 11.
- 12.4 There is currently no uniform technical standard for recognising and implementing “Do Not Track” browser signals, and we do not currently respond to them. The Application does not track you across third-party applications or websites.
13. Third-party websites
- 13.1 The Website and this Policy may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites, and we encourage you to read their privacy policies.
14. Changes to this Policy
- 14.1 We may amend this Policy from time to time. The amended Policy will be published with a revised effective date.
- 14.2 Where we make material changes, we will draw them to your attention prominently or notify you directly and, where required by the Data Protection Legislation, obtain your consent before the changes take effect.
- 14.3 Previous versions of this Policy are available on request.
15. Contact
- 15.1 Questions, comments and requests regarding this Policy should be addressed to:
Email: support@bmce-networks.com
Post:
BMCE Networks7-1-7 Cameron House
White Cross Business Park
Lancaster
LA1 4XF
United Kingdom