Current as of 07/01/2026
PRIVACY NOTICE
Roamly UK Ltd.
Version 1.0 | June 2026
Roamly UK Ltd. (referred to in this notice as “Roamly UK”, "we", "us", or "our") is committed to protecting your personal data and respecting your privacy. This Privacy Notice explains how we collect, use, store and share your personal information when you use our services, visit our website, or interact with us.
This notice is issued in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Please read it carefully.
Roamly UK is the data controller responsible for your personal data.
Roamly UK
Data Protection Contact: Dan Severin
3rd Floor, 1 Ashley Road
Altrincham, Cheshire, WA14 2DT
Email: privacy@roamly.co.uk
Telephone: 0800 023 4567
If you have any questions about how we handle your personal data, or wish to exercise your rights, please contact us using the details above.
Depending on the services you use, we may collect and process the following categories of personal data:
In some circumstances we may need to collect special category data as defined under the UK GDPR. This may include:
We will only process such data where we have a lawful basis to do so, as described in Section 5 below.
We collect personal data from the following sources:
We process your personal data on the following legal bases under Article 6 of the UK GDPR:
Where we process special categories of personal data, we rely on the following additional conditions under Article 9 of the UK GDPR:
We use your personal data for the following purposes:
We may share your personal data with the following categories of recipients:
We will never sell your personal data to third parties for marketing purposes.
We require all third parties to whom we disclose your personal data to respect its security and to treat it in accordance with applicable law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
Your personal data is primarily processed within the United Kingdom. Where we or our service providers transfer personal data outside of the UK to a third country or international organisation, we ensure that appropriate safeguards are in place as required by UK data protection law, such as:
We retain your personal data only for as long as necessary for the purposes set out in this notice and to comply with our legal obligations. Our standard retention periods are:
Data Type Retention Period
Policy and contract records 7 years from policy expiry (FCA requirement)
Claims records 7 years from settlement of claim
Complaint records 5 years from resolution (FCA requirement)
Quotation records (policy not taken out) 1 year from quotation date
General enquiry data 3 months from date of enquiry
Website and technical data Up to 2 years
Marketing consent records Until consent is withdrawn, then 3 years
After the applicable retention period, your data will be securely deleted or anonymised.
You have the following rights in relation to your personal data:
To exercise any of these rights, please contact us using the details in Section 2. We will respond within one month of receiving your request. In some cases, we may extend this period by up to two further months where requests are complex or numerous. We may need to verify your identity before processing your request.
We take the security of your personal data seriously and have appropriate technical and organisational measures in place to protect it against unauthorised access, loss, destruction, or alteration. These include:
While we take all reasonable steps to protect your data, no transmission of data over the internet can be guaranteed to be completely secure. You provide data at your own risk, and we cannot guarantee the security of information transmitted to us electronically.
In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and inform you of the nature of the breach and the steps we are taking to address it.
Where you have given us your consent, or where we have a legitimate interest to do so, we may contact you about products and services we offer that may be of interest to you.
You can opt out of marketing communications at any time by:
Opting out of marketing will not affect the communication of important service or policy-related information.
Our website uses cookies and similar tracking technologies to improve your experience and to collect information about how you use our site. For full details of the cookies we use, the purposes for which we use them, and how to manage your cookie preferences, please refer to our Cookie Policy, available on our website.
If you are unhappy with how we have handled your personal data, we encourage you to contact us in the first instance using the details in Section 2 so that we can attempt to resolve the matter.
You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane,
Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
We review and update this Privacy Notice periodically to reflect changes in our practices, legal requirements, or regulatory guidance. When we make material changes, we will notify you by email or by posting a prominent notice on our website.
The version date at the top of this document indicates when this notice was last updated. The previous version of this notice is available on request. We encourage you to review this notice regularly.
Roamly UK is not currently required under UK GDPR to appoint a Data Protection Officer (DPO). However, we take our data protection obligations seriously and have designated a point of contact for all data protection matters.
Data Protection Contact: Dan Severin
Roamly UK
3rd Floor, 1 Ashley Road,
Altrincham, Cheshire, WA14 2DT
Email: privacy@roamly.co.uk
If you have any concerns about how your personal data is handled, please contact us at the above address in the first instance. For independent advice about data protection, privacy, and your rights, you can also contact the Information Commissioner's Office (ICO) at www.ico.org.uk.
Where we collect personal data directly from you, we will make clear at the point of collection whether providing that data is a statutory requirement, a contractual requirement, or a requirement necessary to enter into a contract with us.
In the context of obtaining an insurance quotation or arranging a policy, much of the personal data we request is necessary for us to assess risk and provide you with a quote. If you do not provide the required information, we may be unable to provide you with a quotation or arrange cover on your behalf.
Where providing personal data is optional — for example, for marketing communications — we will make this clear and there will be no consequence for declining to provide it.
Where we rely on legitimate interests as the legal basis for processing, we will always carry out a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You may request details of our legitimate interests assessment by contacting us.
In order to prevent and detect insurance fraud, we and the insurers we work with may search and share information with the following fraud prevention and industry databases:
If false or inaccurate information is provided and fraud is identified, details will be passed to fraud prevention agencies and may be accessed by law enforcement agencies. This information may be used by us and other organisations to prevent fraud and money laundering, and to verify your identity. Your data may also be used for other purposes permitted by law.
A record of any fraud or attempted fraud will be retained for a period of up to six years. If you would like further details on how information held by these agencies may be used, please contact us.
As an Appointed Representative, certain processing activities — particularly those relating to regulatory compliance, oversight, and supervision — are carried out jointly between Roamly UK and Richdale Brokers and Financial Services Ltd. Where this is the case, both parties act as joint controllers under Article 26 of the UK GDPR.
An arrangement is in place between Roamly UK and Richdale Brokers and Financial Services Ltd that sets out the respective responsibilities of each party in relation to joint processing activities, including how data subject rights requests are handled and how individuals are informed about the processing.
You may exercise your UK GDPR rights against either party. Regardless of any internal arrangement, you retain all rights set out in Section 10 of this notice. If you have a question about joint processing, please contact us at privacy@roamly.co.uk.
Some of the insurers and underwriters we work with use automated processes to assess risk and determine insurance premiums. This may involve profiling — the automated analysis of your personal data (such as your age, location, claims history, and the item being insured) to evaluate certain aspects of your risk profile.
Where a decision is made solely by automated means and produces a legal or similarly significant effect on you (for example, a refusal of cover or a significant change in premium), you have the right under Article 22 of the UK GDPR to:
If you believe an automated decision has been made about you and you wish to challenge it, please contact us at privacy@roamly.co.uk. We will liaise with the relevant insurer on your behalf.
Some of the insurance products we offer may include or be linked to telematics technology — devices or applications that collect data about how a vehicle is used. This section explains how such data is collected and processed where telematics is a feature of your policy.
Where a telematics device or mobile application is used in connection with your policy, the following types of data may be collected:
Telematics data is used for the following purposes:
We process telematics data on the basis of contract performance (to administer your policy), legitimate interests (fraud prevention and risk assessment), and where required, your consent. Location data is only collected where it is necessary for the insurance product you have purchased and you have been clearly informed of this at the point of sale.
Telematics data may be shared with the insurer underwriting your policy, claims handlers, and fraud prevention bodies as described in Sections 7 and 18. Where your policy is arranged as an embedded product integrated with a third-party fleet management platform (such as Wheelbase Pro), relevant telematics and usage data may also be shared with that platform to enable the seamless administration of your cover within your fleet management system. It will not be sold to or shared with third parties for marketing purposes. Where a telematics device or fleet management platform is provided by a third-party hardware or software provider, that provider will process data on our behalf, or as an independent controller in respect of its own platform, under an appropriate data processing or data sharing agreement.
Telematics data will be retained for the duration of your policy and for a period of up to 7 years thereafter, in line with our standard policy record retention period. Raw journey data may be retained in anonymised or aggregated form for longer periods for statistical analysis.
Roamly UK | Appointed Representative of Richdale Brokers and Financial Services Ltd (FRN: 769876)
Roamly UK Ltd (FRN: 979796) is an appointed representative of Richdale Brokers and Financial Services Ltd which is authorised and regulated by the Financial Conduct Authority. Roamly UK Ltd is a company registered in England and Wales (Company Number 15613204) with its registered office at 3rd Floor 1 Ashley Road, Altrincham, Cheshire, WA14 2DT.
Product
© 2026 Roamly UK Ltd. All rights reserved.
