Privacy policy
This policy was last updated in June 2026.
Introduction
This policy explains how Airband collects, uses, discloses, stores and protects personal data in the following circumstances:
- when you visit our websites;
- when you register for, enquire about, subscribe to or use our services;
- when you register an interest in our services;
- when we receive your data from external third-party sources, credit reference agencies, consumer reporting agencies, fraud prevention services, publicly available sources, public registers or as part of our lead generation programme; and
- when we process personal data for customer service, service delivery, billing, network operation, fraud prevention, identity verification, compliance, marketing, audit and business administration purposes.
Who We Are
In this policy, references to “Airband”, “we”, “us” or “our” are references to Airband Community Internet Limited, its partner companies and subsidiaries.
We collect, use and handle certain personal information about you. When we do so, we follow applicable data protection laws, including the UK General Data Protection Regulation and the Data Protection Act 2018. Airband Community Internet Limited is the data controller of your personal information unless we tell you otherwise.
Airband Community Internet Limited is registered in England and Wales under company number 07114545, with its registered office at:
105 Pointon Way, Hampton Lovett, Droitwich, Worcestershire, England, WR9 0LW.
Airband is registered with the Information Commissioner’s Office under reference Z3414766.
Airband has appointed a Data Protection Officer, who can be contacted by email at:
Airband Websites
Third-Party Links
Our website may include links to websites operated by third parties. We have no control over those websites and are not responsible for their privacy practices, content or policies. We recommend that you review the privacy notice of each website you visit when leaving our website.
Child Data Policy
Our website and services are not intended for use by children, and we do not knowingly collect personal data relating to individuals under the age of 15.
Personal Data We Collect and Process
We collect personal information about you when you use our website, enquire about our services, subscribe to our services, use our services, contact us, interact with us, or where your information is made available to us by third parties or from public sources.
In most cases, this information is provided directly by you. Some information is collected automatically, such as IP address, device and technical information. We may also collect information from other sources, such as the Land Registry, publicly available sources, lead generation partners, business partners, credit reference agencies, consumer reporting agencies, fraud prevention services and service providers.
The personal data we hold and process may include:
- name, address, date of birth and contact details;
- service address, installation address and property information;
- marketing preferences and communication preferences;
- communications we have had with you;
- account, service, billing and customer support records;
- transactional and financial information;
- payment information and billing history;
- identity verification information;
- credit reference, consumer report, eligibility, affordability, risk or fraud prevention information, where relevant;
- connection logs and network service information;
- Land Registry information;
- IP address, device information, browser information and other technical information;
- website usage and analytics information;
- audit logs and compliance records; and
- information received from public sources or third-party lead generation sources.
Customer network traffic data, such as browsing history, will not be stored unless required for legal, regulatory, security, fraud prevention or network protection reasons.
Sources of Personal Data
We may collect personal data from:
- you directly;
- other people authorised to act on your behalf;
- our website, systems, network and customer service platforms;
- payment and billing providers;
- installation, maintenance and network service providers;
- public registers, including the Land Registry;
- publicly available sources;
- lead generation providers and marketing partners;
- business partners;
- credit reference agencies, consumer reporting agencies and fraud prevention services, including TransUnion where applicable;
- professional advisers, regulators, law enforcement bodies or public authorities; and
- third parties involved in the provision, administration, security or improvement of our services.
How We Use Personal Data and Our Lawful Bases
We only process personal data where we have a lawful basis to do so. Depending on the circumstances, we may rely on contract, legal obligation, consent, legitimate interests, or another lawful basis permitted under data protection law.
| Purpose of Processing | Lawful basis/bases |
|---|---|
| Providing services, managing customer accounts, service administration and billing | Contract; legal obligation; legitimate interests |
| Customer service and handling enquiries, complaints and support requests | Contract; legitimate interests; legal obligation |
| Processing orders, arranging installations and delivering services | Contract; legitimate interests |
| Network maintenance, monitoring, troubleshooting and service improvement | Contract; legitimate interests |
| Website and network analytics | Legitimate interests; consent where required |
| Marketing activities and lead generation | Consent; legitimate interests |
| Managing marketing preferences and opt-outs | Legal obligation; legitimate interests |
| Identity verification, eligibility checks, affordability checks, risk assessment and fraud prevention, where relevant | Contract; legitimate interests; legal obligation where applicable |
| Obtaining or using consumer reports, credit reference information or TransUnion data, where relevant | Contract; legitimate interests; legal obligation where applicable |
| Protecting systems, data, networks and TransUnion data | Legitimate interests; legal obligation; contract |
| Audit, compliance, monitoring and record keeping | Legal obligation; legitimate interests |
| Debt recovery, account management and fraud investigation | Contract; legitimate interests; legal obligation |
| Responding to lawful requests from regulators, courts, public authorities or law enforcement agencies | Legal obligation; legitimate interests |
| Corporate transactions, restructuring, merger, acquisition or sale of all or part of our business | Legitimate interests; legal obligation where applicable |
Legitimate Interests We Pursue
Where we rely on legitimate interests, our legitimate interests include:
- operating, managing and developing our business;
- providing, administering and improving our services;
- fulfilling contractual obligations and managing customer relationships;
- ensuring system, network and data security;
- preventing, detecting and investigating fraud, misuse of services, cyber threats and unlawful activity;
- verifying identity and managing commercial or credit risk;
- protecting Airband data and data received from third parties, including TransUnion data where applicable;
- supporting audit, compliance, monitoring and governance activities;
- managing complaints, enquiries, disputes and legal claims;
- recovering debts and managing accounts;
- conducting direct marketing where permitted by law; and
- protecting our business, customers, staff, suppliers, partners and service providers.
Where we rely on legitimate interests, we balance those interests against your rights, freedoms and interests. We use appropriate safeguards, which may include data minimisation, access controls, contractual protections, audit logs, retention controls, encryption, multifactor authentication, opt-out mechanisms and internal governance processes.
Credit Reference and Affordability Checks
To help us assess applications, prevent fraud, and meet our legal and regulatory obligations, we may obtain information about you from credit reference agencies (CRAs).
We obtain this information via Creditsafe, which uses its data partner TransUnion to supply consumer credit and identity data.
- Creditsafe Business Solutions Limited is authorised and regulated by the Financial Conduct Authority
FCA Firm Reference Number: 742313 - TransUnion International UK Limited is authorised and regulated by the Financial Conduct Authority
FCA Firm Reference Number: 737740
The information we receive may include data relating to your identity, credit commitments, payment history, and public record information. This data is used solely for legitimate business purposes, including creditworthiness assessment, identity verification, and fraud prevention, in accordance with applicable data protection laws.
Further information about how Creditsafe and TransUnion process your personal data can be found in their respective privacy notices:
- Creditsafe Privacy / Transparency Notice
- TransUnion CRAIN (Credit Reference Agency Information Notice)
- TransUnion Bureau Privacy Notice
Retention
We only retain your personal data for as long as necessary for the purposes for which it was collected.
When determining retention periods for different categories of personal data, we consider factors including:
- applicable legal, regulatory, accounting and tax requirements;
- the nature and sensitivity of the information;
- the purposes for which the information is processed;
- whether we need the information to provide services or manage your account;
- whether the information is needed for audit, compliance, fraud prevention, dispute resolution, legal claims or security purposes; and
- the potential impact in the event of a breach.
If you would like information about a particular retention policy, please contact our Data Protection Officer at [email protected].
At the end of the applicable retention period, personal information will be securely deleted or anonymised so that it can no longer be linked to you.
Special Category Data and Criminal Offence Data
Special category data is personal data revealing or relating to:
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade union membership;
- genetic data;
- biometric data used for identification;
- health;
- sex life; or
- sexual orientation.
Criminal offence data is subject to separate legal protections.
We understand that special category data and criminal offence data require additional safeguards and a specific legal basis for processing.
We do not intend to collect or process special category data or criminal offence data relating to our customers or suppliers unless it is necessary, lawful and subject to appropriate safeguards.
Sharing of Data
We may share your personal data where permitted by law and where it is necessary and proportionate to do so.
We may share personal data with:
- colleagues within Airband where access is necessary for them to perform their duties;
- Airband partner companies, subsidiaries and group companies;
- business customers or business partners where relevant, for example where you are an employee, contractor or representative of one of our customers or partners;
- billing, payment and account management service providers;
- credit reference agencies, consumer reporting agencies and fraud prevention services, including TransUnion where applicable;
- network, installation, maintenance, infrastructure and technical support providers;
- IT, cloud, hosting, software, communications and cybersecurity service providers;
- customer relationship management, customer support and contact centre providers;
- analytics, website, cookie and digital service providers;
- marketing platforms, lead generation providers and digital marketing agents acting on our behalf;
- auditors, insurers, lawyers, accountants, consultants and other professional advisers;
- regulators, public authorities, courts, law enforcement agencies and government bodies;
- stakeholders, investors, purchasers, sellers and advisers in connection with any merger, acquisition, restructuring, financing or sale of all or part of our business; and
- other third parties where disclosure is required by law or necessary to protect our rights, customers, systems, services or business.
Where we use third-party service providers, we require them to protect personal data and only use it in accordance with our instructions, applicable law and appropriate contractual obligations.
Where personal data is shared outside the UK or European Economic Area, appropriate safeguards will apply as described in the International Transfers section below.
International Transfers
Personal data collected by us may be stored, accessed or processed in countries outside the UK and/or the European Economic Area by Airband, our affiliates, suppliers, partners, group companies, service providers or agents.
Where we transfer personal data outside the UK and/or EEA, we will ensure that appropriate safeguards are in place to protect personal data in accordance with applicable data protection laws.
These safeguards may include:
- transferring data to countries that have been recognised as providing an adequate level of data protection;
- using the UK International Data Transfer Agreement;
- using the UK Addendum to the European Commission Standard Contractual Clauses;
- using European Commission Standard Contractual Clauses where relevant to EEA data transfers;
- completing appropriate transfer risk assessments; and
- applying technical, organisational and contractual controls to protect the data.
We do not rely on a general statement of consent to legitimise international transfers. Transfers will be made only where they are lawful and subject to appropriate safeguards or another permitted transfer mechanism.
Protecting Data
To ensure your data is suitably protected, we use a multilayered security approach, including technical and organisational controls.
Customer data is stored in secure systems and protected by controls such as multifactor authentication, encryption, access management, monitoring and other security measures.
We also apply controls to protect data received from third parties, including TransUnion data where applicable.
Airband is Cyber Essentials Plus accredited.
Automated Decision-Making and Profiling
In some circumstances, we may conduct automated decision-making or profiling using personal data. This involves using automated systems to evaluate certain information about an individual, such as risk factors, affordability indicators, eligibility criteria, identity verification results or fraud signals, based on predefined rules or algorithms.
Where automated decision-making is used, it may result in decisions such as the approval, restriction or rejection of an application, account, service or request.
Further information about automated decision-making and how to exercise these rights can be obtained by contacting our Data Protection Officer at [email protected].
Your Rights in Relation to Personal Data
Data protection law gives you certain rights in relation to your personal data.
These rights include:
Right to be informed
You have the right to be informed about how we collect and use your personal data. This privacy policy is intended to provide that information.
Right of access
You have the right to request a copy of the personal data we hold about you and information about how it is used.
Right to rectification
You have the right to ask us to correct inaccurate personal data or complete incomplete personal data.
Right to erasure
You have the right to ask us to delete your personal data where there is no lawful reason for us to continue processing it.
Right to restrict processing
You have the right to ask us to limit how we use your personal data in certain circumstances.
Right to data portability
You have the right to receive personal data you have provided to us in a structured, commonly used and machine-readable format, and to ask us to transfer it to another organisation where technically feasible.
Right to object
You have the right to object to the processing of your personal data where we rely on legitimate interests. You also have the right to object to direct marketing at any time.
Rights relating to automated decision-making
You have rights in relation to decisions based solely on automated processing where those decisions produce legal or similarly significant effects. As explained above, we do not make such decisions without meaningful human involvement.
Right to withdraw consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before consent was withdrawn.
These rights are not absolute and may only apply in certain circumstances. We may need to verify your identity before responding to a request.
To exercise your rights, please contact our Data Protection Officer at [email protected].
Provision of Personal Data
The provision of certain personal data is primarily contractual and, in some circumstances, required to meet legal or regulatory obligations.
Personal data is required to:
- enter into and perform contracts with customers, suppliers or business partners;
- process orders, manage accounts and deliver goods and services;
- arrange installation, maintenance and customer support;
- verify identity and prevent fraud;
- conduct eligibility, risk, affordability or credit-related checks where relevant;
- manage billing, payments and debt recovery;
- comply with applicable legal, regulatory, accounting and tax obligations; and
- comply with obligations owed to service providers, credit reference agencies, consumer reporting agencies or fraud prevention services where applicable.
If you choose not to provide personal data that we request:
- we may be unable to enter into a contract with you;
- we may be unable to process orders, fulfil requests, supply goods or provide services;
- we may be unable to manage your account or provide support;
- we may be unable to conduct necessary verification, compliance, fraud prevention, credit, eligibility or risk checks; and
- as a result, our services may be delayed, restricted or declined.
Where personal data is requested for optional purposes, such as marketing communications, providing that data is not mandatory. You may withdraw consent or opt out of marketing at any time without affecting your ability to receive goods or services from us.
Making a Complaint
If you have a complaint or query about how we use your personal data, please contact our Data Protection Officer in the first instance at:
We will do our best to resolve your complaint.
You also have the right to complain to the UK Information Commissioner’s Office or another relevant data protection authority if you are dissatisfied with how we manage your personal data.
The supervisory authority in the UK for data protection matters is the Information Commissioner’s Office. Current contact details and information about making a complaint are available on the ICO website. GOV.UK also states that the ICO can investigate complaints about misuse of personal data.
Cookies and Google Analytics
We use cookies and similar technologies on our website, including analytics tools such as Google Analytics, to help us understand how our website is used and to improve our website, services and user experience.
Where required by law, we will only use non-essential cookies with your consent.
You can manage cookie preferences through our cookie banner, your browser settings or other tools made available on our website.
Please see our Cookie Policy for more information about the cookies we use, why we use them, and how you can manage your preferences.
This policy was last updated in June 2026.