Privacy Policy

    LynixSIM is a trading name of Lynix Group Ltd.

    Last updated: 23 April 2026

    Contents

    1. Who We Are and How to Contact Us
    2. The Personal Data We Collect and Why
    3. Legal Bases for Processing
    4. How We Use Your Data
    5. Who We Share Your Data With
    6. International Data Transfers
    7. Cookies and Local Storage
    8. Data Retention
    9. How We Protect Your Data
    10. Your Rights Under UK GDPR
    11. Children
    12. Changes to This Policy
    13. Contact Us

    1. Who We Are and How to Contact Us

    Lynix Group Ltd ("we", "us", "our") operates the LynixSIM platform, accessible at lynixsim.co.uk and via the LynixSIM mobile application. We provide SIM card management software and services for electric gate and intercom engineers and their end customers in the United Kingdom.

    For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Lynix Group Ltd is the Data Controller in respect of personal data collected through the LynixSIM platform.

    Contact details for data protection enquiries:

    • Email: support@lynixsim.co.uk
    • Website: lynixsim.co.uk

    If you wish to exercise any of your data rights, make a complaint, or ask any questions about how we handle your personal data, please contact us using the details above. We will respond within 30 days.


    2. The Personal Data We Collect and Why

    We collect personal data from several categories of individuals who interact with the LynixSIM platform. We only collect data that is necessary for the purposes described below.

    2.1 Retail Customers

    Retail customers are end users who subscribe to a SIM plan through the LynixSIM platform, typically introduced by a trade engineer.

    Data collected: Full name, email address, and phone number. Billing and delivery address. Subscription details including plan type, pricing, billing cycle start date, and next billing date. Payment method reference (provided by Stripe — we do not store card details). Stripe customer ID and subscription ID. SIM card identifiers linked to the subscription. Contract acceptance records including date and time of signing. Order status and shipping tracking information.

    Why we collect this: To process and fulfil SIM subscriptions, manage billing, deliver SIM cards, provide customer support, and comply with our contractual and legal obligations.

    2.2 Trade Customers (Engineers and Managers)

    Trade customers are professional gate and intercom engineers who apply for a trade account to purchase, manage, and assign SIM cards through our platform.

    Data collected during application: Full name, email address, and phone number. Company name, company website, and business address. Delivery address for SIM card shipments. Intended use case and estimated SIM volumes per week. Employment or company verification documents uploaded during onboarding, stored in a private access-controlled storage environment accessible only to authorised Lynix Group Ltd personnel.

    Data collected during platform use: SIM inventory records including SIM numbers, nicknames assigned to customer installations, pricing, network, status, and assignment history. Activity logs recording actions taken within the platform such as SIM setup, link sharing, resets, and installation completions. Order history including quantities, shipping information, and Royal Mail tracking references. Revenue share records including monthly earnings calculations and payout history. Team management data including team member names, roles, and invitation records. Profile photographs if voluntarily uploaded. Platform preferences and account settings.

    Why we collect this: To verify trade account eligibility, process SIM orders, manage SIM inventory, calculate and process monthly revenue share payments, facilitate team management, provide customer support, and comply with our contractual and financial record-keeping obligations.

    2.3 Team Members (Engineers invited by a Manager)

    Where a trade account manager invites a team member to join their account, we collect the invited person's email address at the point of invitation. Upon registration we collect full name, email address, phone number, company name, and address. We also collect employment or identity verification documents uploaded during onboarding, and SIM management activity and inventory data associated with their account.

    Why we collect this: To verify the team member's identity and employment, grant appropriate platform access, and enable the manager to oversee team SIM activity.

    2.4 Install Guide Leads

    Where an engineer or installer completes the install guide form on our website, we collect first name, company name, SIM card number, email address (optional, only collected if the individual indicates they are an existing customer), and whether they are an existing LynixSIM customer.

    Why we collect this: To follow up on the enquiry, assist with SIM activation, and identify potential trade account applicants.

    2.5 All Platform Users

    For all users of the LynixSIM web platform and mobile application we collect email address and encrypted password managed by Supabase Auth, login timestamps and session information, device information and authentication tokens stored locally on your device, and failed login attempt records stored locally and used to protect your account against unauthorised access.


    3. Legal Bases for Processing

    We process personal data only where we have a valid legal basis to do so under UK GDPR. The legal bases we rely on are as follows:

    • Fulfilling SIM subscription orders and managing accounts: performance of contract.
    • Processing trade account applications and onboarding: performance of contract.
    • Verifying identity and employment of trade applicants: legitimate interests and legal obligation.
    • Processing SIM orders and arranging delivery: performance of contract.
    • Calculating and processing monthly revenue share payments: performance of contract and legal obligation.
    • Sending transactional emails including account approvals, order confirmations, and team invitations: performance of contract and legitimate interests.
    • Maintaining activity logs for audit and support purposes: legitimate interests.
    • Protecting against fraudulent login attempts: legitimate interests.
    • Retaining financial records: legal obligation under HMRC requirements.
    • Responding to data subject rights requests: legal obligation.

    Where we rely on legitimate interests we have carried out a balancing test and are satisfied that our interests do not override your rights and freedoms. You have the right to object to processing based on legitimate interests — see Section 10.


    4. How We Use Your Data

    We use your personal data for the following purposes.

    • Account management: Creating and managing your account, verifying your identity, and providing access to the platform.
    • Service delivery: Processing SIM orders, managing SIM inventory, facilitating engineer-to-customer SIM assignment, and tracking subscription status.
    • Communications: Sending you transactional emails including account approval notifications, order confirmations, shipping updates, team invitations, and revenue share notifications. We do not send marketing emails unless you have separately opted in.
    • Revenue share calculation: Calculating monthly earnings based on active SIM subscriptions assigned through your trade account and processing payouts accordingly.
    • Platform security: Monitoring for fraudulent activity, protecting accounts against unauthorised access, and maintaining the security and integrity of the platform.
    • Customer support: Using activity logs and account data to diagnose and resolve issues you report to us.
    • Legal compliance: Retaining records as required by HMRC and other applicable legal obligations.
    • Platform improvement: Using anonymised aggregated activity data to improve the performance and features of the LynixSIM platform.

    We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects. We do not use your personal data for advertising purposes. We do not sell your personal data to any third party.


    5. Who We Share Your Data With

    We share personal data only with the following trusted third-party service providers, and only to the extent necessary to provide our services. All third parties are contractually required to handle your data securely and in accordance with applicable data protection law.

    Stripe is used for payment processing and subscription management. We share your email address, subscription plan, and metadata required to create and manage your subscription. Card payment details are collected directly by Stripe via their secure checkout and never pass through our servers. Stripe is located in the United States and transfers are subject to Standard Contractual Clauses and the UK-US Data Bridge. Privacy policy: stripe.com/gb/privacy

    Resend is used for transactional email delivery. We share your recipient email address, name, and relevant account information included in the email body such as order details, approval status, team invitation links, and revenue share notifications. Resend is located in the United States and transfers are subject to appropriate safeguards. Privacy policy: resend.com/legal/privacy-policy

    Royal Mail is used for physical SIM card order fulfilment and delivery. We share your name, company name, and delivery address. Phone number and email address are not included on shipping labels. Royal Mail is located in the United Kingdom. Privacy policy: royalmail.com/privacy-policy

    Supabase provides our database hosting, user authentication, and secure file storage infrastructure. All personal data described in Section 2 is stored within Supabase-managed PostgreSQL databases and storage infrastructure located in the European Union (eu-west-2 region). Data does not leave the EU except where standard contractual clauses are in place. Privacy policy: supabase.com/privacy

    Google reCAPTCHA is used for bot detection and protection on login and activation pages. Google processes a reCAPTCHA token and device and browser fingerprint data to determine whether a login attempt is human or automated. Google is located in the United States and transfers are subject to appropriate safeguards. Privacy policy: policies.google.com/privacy

    We do not share your personal data with any other third parties except where required by law, such as in response to a court order, regulatory request, or to comply with a legal obligation.


    6. International Data Transfers

    Some of our third-party service providers are located outside the United Kingdom. Where personal data is transferred outside the UK we ensure appropriate safeguards are in place including Standard Contractual Clauses approved by the UK Information Commissioner's Office and the UK-US Data Bridge where applicable for transfers to US-based providers, together with contractual requirements on data processors to maintain appropriate security standards. If you would like further information about the safeguards in place for international transfers please contact us at support@lynixsim.co.uk.


    7. Cookies and Local Storage

    First-party cookies: We set one first-party cookie called sidebar:state which remembers whether the admin sidebar is collapsed or expanded and lasts for 7 days.

    Local storage: We store the following in your browser's local storage. The Supabase auth token maintains your login session and is cleared when you sign out. Login attempt counters record failed login attempts to protect your account and reset after 30 minutes. The cookie consent preference records your consent decision and persists until you clear your browser storage.

    Third-party cookies: Google sets a _GRECAPTCHA cookie on login and activation pages for bot detection. Stripe sets session cookies when you visit their checkout page during payment.

    What we do not use: We do not use Google Analytics, any web analytics service, advertising or retargeting cookies, social media tracking pixels from Meta, LinkedIn, TikTok, or any similar service, or session recording and heatmap tools. Our cookie consent banner is presented to users on first visit. Declining cookies does not affect your ability to use the platform as we do not gate any core functionality behind cookie consent.


    8. Data Retention

    We retain personal data for as long as necessary to fulfil the purposes for which it was collected or as required by law.

    Trade and retail customer account data is retained for the duration of your account and deleted upon account deletion subject to the exceptions below. Order history for retail customers is retained with personal identifiers removed following account deletion to maintain financial records. Revenue share and payout records are retained for a minimum of 6 years from the date of the relevant financial transaction in line with HMRC financial record-keeping requirements. Employment and identity verification documents are retained for as long as required for verification purposes and deleted thereafter upon request. Activity logs are retained for the duration of the account and deleted upon account deletion. Team invitation records expire after 7 days and are marked as expired but are not physically deleted. Authentication session tokens are governed by Supabase Auth defaults and cleared when you sign out. Failed login attempt counters reset automatically after 30 minutes of inactivity or upon successful login. Install guide leads are retained until deleted by Lynix Group Ltd personnel and you may contact us to request deletion.

    Account deletion: When an account is deleted we delete your user record, profile data, and trade account information from our systems. Your order history is retained with personal identifiers removed. Your authentication account is deleted from Supabase Auth. Any outstanding team invitations associated with your email address are marked as expired. Audit columns referencing your user ID in other records are set to null. To request account deletion, use the in-app deletion request in Account > Legal & Privacy or contact support@lynixsim.co.uk.


    9. How We Protect Your Data

    We have implemented appropriate technical and organisational measures to protect your personal data. All data in transit is encrypted using TLS. Data at rest is encrypted within Supabase-managed infrastructure. Access to personal data is restricted using row-level security policies within our database and only authorised Lynix Group Ltd personnel can access sensitive data such as employment verification documents. Administrator accounts are protected by two-factor authentication. Card payment data is collected directly by Stripe via PCI-DSS compliant infrastructure and never stored on our servers. Failed login attempts are tracked and accounts are temporarily locked after repeated failures to protect against brute-force attacks. Employment verification documents are stored in a private access-controlled storage bucket and are not publicly accessible.

    Despite these measures no system is completely secure. If you believe your account has been compromised please contact us immediately at support@lynixsim.co.uk.


    10. Your Rights Under UK GDPR

    As a data subject under UK GDPR you have the following rights in relation to your personal data.

    • Right of access: You have the right to request a copy of the personal data we hold about you. We will provide this within 30 days of your request.
    • Right to rectification: You have the right to ask us to correct personal data that is inaccurate or incomplete.
    • Right to erasure: You have the right to request that we delete your personal data subject to any overriding legal obligations such as the requirement to retain financial records.
    • Right to restriction of processing: You have the right to ask us to restrict our processing of your personal data in certain circumstances for example while a dispute about accuracy is being resolved.
    • Right to data portability: You have the right to receive the personal data you have provided to us in a structured commonly used machine-readable format and to request that we transmit it to another controller where technically feasible.
    • Right to object: You have the right to object to our processing of your personal data where we rely on legitimate interests as our legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
    • Rights related to automated decision-making: You have the right not to be subject to decisions made solely on the basis of automated processing where those decisions produce legal or similarly significant effects. We do not currently carry out such automated decision-making.

    To exercise any of the above rights please contact us at support@lynixsim.co.uk. We will respond within 30 days. We may ask you to verify your identity before processing your request.

    If you are unhappy with how we have handled your personal data you have the right to lodge a complaint with the Information Commissioner's Office, the UK's independent data protection authority, at ico.org.uk or by calling 0303 123 1113.


    11. Children

    The LynixSIM platform is intended exclusively for business use by adults aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected data from a minor please contact us immediately at support@lynixsim.co.uk and we will take prompt steps to delete it.


    12. Changes to This Policy

    We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes we will update the last updated date at the top of this page. We encourage you to review this policy periodically. Continued use of the LynixSIM platform following the posting of changes constitutes your acceptance of the updated policy. If you do not agree with any changes you should discontinue use of the platform and contact us to request deletion of your account.


    13. Contact Us

    Lynix Group Ltd trading as LynixSIM. Email: support@lynixsim.co.uk. Website: lynixsim.co.uk. For all data protection enquiries, rights requests, or complaints please use the email address above.