GDPR Policy

360 OM LIMITED
DATA PROTECTION & UK GDPR POLICY

Company: 360 OM Limited
Effective Date: October 2025
Version: 2.0

Current Version: The current version of this policy is published on 360 OM Limited's designated website or online legal documentation location.

1. Purpose

360 OM Limited ("360 OM", "we", "us" or the "Company") is committed to protecting personal data and respecting the privacy rights of individuals whose information we process.

This policy establishes the framework under which 360 OM processes personal data in accordance with applicable UK data protection legislation, including:

the UK General Data Protection Regulation ("UK GDPR");
the Data Protection Act 2018;
the Privacy and Electronic Communications Regulations 2003 ("PECR"), where applicable;
the Data (Use and Access) Act 2025 and subsequent amendments to UK data protection law; and
applicable guidance and requirements issued by the Information Commissioner's Office ("ICO").

This policy is intended to ensure that personal data is handled lawfully, fairly, transparently, securely and responsibly throughout its lifecycle.

2. Scope

This policy applies to:

all employees, directors, officers and workers of 360 OM;
contractors, freelancers, consultants and temporary staff;
third parties processing personal data on behalf of 360 OM;
all personal data processed by 360 OM, whether electronically, manually or through third-party platforms; and
all relevant business functions, including client services, paid media, CRM, email marketing, SMS marketing, analytics, creative production, sales, finance, HR, recruitment and administration.

Compliance with this policy is mandatory for all personnel handling personal data on behalf of 360 OM.

3. Definitions
Personal Data

Any information relating to an identified or identifiable living individual.

Examples include:

names;
email addresses;
telephone numbers;
postal addresses;
IP addresses;
customer identifiers;
cookie identifiers;
advertising identifiers;
online behaviour;
purchase history;
location information; and
employment information.
Special Category Data

Personal data requiring additional protection, including information concerning:

health;
racial or ethnic origin;
political opinions;
religious or philosophical beliefs;
trade union membership;
genetic data;
biometric information used for identification; or
a person's sex life or sexual orientation.
Data Subject

The individual to whom personal data relates.

Processing

Any operation performed on personal data, including collecting, recording, storing, organising, analysing, altering, retrieving, sharing, transmitting or deleting it.

Controller

An organisation that determines the purposes and means of processing personal data.

Processor

An organisation that processes personal data on behalf of a controller and in accordance with its documented instructions.

Sub-processor

A third party appointed by a processor to assist in processing personal data.

Personal Data Breach

A security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

4. Our Role as Controller and Processor

360 OM may act as either a data controller or data processor, depending on the relevant processing activity.

4.1 Where 360 OM is a Controller

360 OM will generally act as a controller in relation to personal data concerning:

employees and contractors;
job applicants;
suppliers;
business contacts;
prospective clients;
existing client contacts;
website visitors;
360 OM's own sales and marketing activities; and
individuals whose information is processed for the Company's internal administration.

In these circumstances, 360 OM determines the purposes and means of processing.

4.2 Where 360 OM is a Processor

360 OM will commonly act as a processor when processing personal data on behalf of clients in connection with services such as:

CRM management;
email marketing;
SMS marketing;
audience segmentation;
marketing automation;
customer journey analysis;
paid search;
paid social;
remarketing and retargeting;
customer matching;
analytics;
attribution;
conversion tracking;
conversion rate optimisation;
customer data analysis; and
marketing technology implementation.

When acting as a processor, 360 OM will process personal data only in accordance with the client's documented instructions, except where otherwise required by applicable law.

5. Data Protection Principles

360 OM will ensure that personal data is:

5.1 Lawful, Fair and Transparent

Personal data must be processed on a valid lawful basis and in a manner individuals would reasonably expect.

5.2 Collected for Specified Purposes

Personal data must only be collected for specified, explicit and legitimate purposes and must not subsequently be used incompatibly with those purposes.

5.3 Adequate, Relevant and Limited

Only personal data reasonably necessary for the intended purpose should be collected or processed.

5.4 Accurate

Reasonable steps must be taken to ensure personal data is accurate and, where necessary, kept up to date.

5.5 Retained Only as Necessary

Personal data must not be retained for longer than required for the relevant business, contractual or legal purpose.

5.6 Kept Secure

Appropriate technical and organisational measures must be used to protect personal data against unauthorised access, accidental loss, alteration, destruction or disclosure.

5.7 Accountability

360 OM must be able to demonstrate compliance with its data protection responsibilities.

6. Lawful Bases for Processing

When acting as a controller, 360 OM must identify an appropriate lawful basis before processing personal data.

Depending on the circumstances, this may include:

Contract

Where processing is necessary to enter into or perform a contract with an individual.

Legal Obligation

Where processing is necessary to comply with a legal obligation.

Legitimate Interests

Where processing is necessary for the legitimate interests of 360 OM or a third party and those interests are not overridden by an individual's rights and freedoms.

Examples may include:

B2B business development;
fraud prevention;
IT and information security;
internal administration; and
improving services.

Where appropriate, a Legitimate Interests Assessment should be undertaken.

Consent

Where an individual has freely given specific, informed and unambiguous consent.

Where consent is relied upon, 360 OM must maintain appropriate evidence of that consent and make withdrawal of consent straightforward.

Vital Interests or Public Task

These are unlikely to be regularly relied upon by 360 OM but may apply in exceptional circumstances.

7. Client Marketing Data

As a performance marketing agency, 360 OM may have access to personal data relating to clients' customers, users, leads and prospective customers.

This can include:

email addresses;
telephone numbers;
customer IDs;
purchase histories;
order values;
browsing behaviour;
CRM profiles;
marketing preferences;
advertising audiences;
lead information; and
conversion information.

Client personal data must only be:

accessed by personnel who require it to perform their duties;
used for the agreed client purpose;
processed through approved systems;
shared with authorised service providers;
retained for as long as required to perform the services or satisfy applicable obligations; and
returned, deleted or securely disposed of following termination where required by the applicable agreement.

Client personal data must not be used for 360 OM's own marketing or other independent purposes unless there is an appropriate lawful basis and any required client authorisation has been obtained.

8. Email and SMS Marketing

Where 360 OM manages email, SMS or other electronic marketing activity, appropriate consideration must be given to UK GDPR and PECR.

Before campaigns are launched, the relevant controller should establish:

the lawful basis for processing;
whether PECR consent is required;
the source of the marketing data;
how and when consent was obtained where relied upon;
whether applicable soft opt-in requirements are satisfied;
how marketing preferences are maintained; and
how individuals can opt out.

Applicable marketing communications must include an appropriate and effective mechanism for opting out.

Opt-out requests must be respected promptly.

Suppression records may be retained where necessary to ensure that individuals who have opted out are not inadvertently contacted again.

9. Advertising Platforms and Customer Audiences

360 OM may process personal data through advertising and marketing platforms, including platforms operated by Google, Meta, TikTok and other providers.

This may include:

customer match lists;
hashed email addresses;
hashed telephone numbers;
website audience information;
conversion data;
CRM audiences; and
customer segmentation information.

Before customer information is uploaded or transmitted to an advertising platform, 360 OM personnel must ensure that:

the relevant client has authorised the processing where required;
there is an appropriate lawful basis;
the processing complies with applicable platform terms;
only information necessary for the intended purpose is used; and
appropriate transparency has been provided to affected individuals by the relevant controller.

Where available and suitable, personal identifiers should be hashed, pseudonymised or otherwise protected before transmission.

10. Cookies, Tracking and Analytics

Where 360 OM implements or advises upon technologies including:

cookies;
tracking pixels;
Google Analytics;
Google Tag Manager;
Meta Pixel;
TikTok Pixel;
server-side tracking;
Conversion APIs;
enhanced conversions; or
other advertising and analytics technologies,

appropriate consideration must be given to applicable UK GDPR and PECR requirements.

Where consent is required, non-essential tracking technologies should not be activated before appropriate consent has been obtained.

Consent signals should be implemented and transmitted correctly to relevant platforms where required.

360 OM personnel must not intentionally bypass client cookie consent management systems or deploy unauthorised tracking technology.

11. Data Minimisation

360 OM must only request, access or retain personal data that is reasonably required to perform the relevant task.

For example:

exports should contain only required fields;
full customer databases should not be downloaded when a limited segment is sufficient;
data should not be duplicated unnecessarily;
local copies should be avoided where secure platform access is available; and
personal data should not be transferred through insecure channels.
12. Access Control

Access to personal data must be granted on a least-privilege and need-to-know basis.

360 OM will implement appropriate access controls, including where appropriate:

unique user accounts;
role-based permissions;
multi-factor authentication;
strong passwords;
restrictions on administrative accounts;
removal of access when personnel leave the business or change roles; and
periodic reviews of user permissions.

Employees and contractors must not share passwords or individual login credentials.

13. Information Security

360 OM will implement technical and organisational safeguards proportionate to the risks associated with the personal data being processed.

These may include:

encryption in transit and at rest where appropriate;
multi-factor authentication;
endpoint security;
access controls;
password management;
secure cloud storage;
regular software updates;
device encryption;
secure backups;
monitoring and logging;
malware protection;
staff awareness training; and
appropriate incident response procedures.

Personal data should not ordinarily be stored on personal devices unless specifically authorised and appropriately secured.

14. Remote Working

Employees and contractors working remotely must ensure that:

screens cannot reasonably be viewed by unauthorised persons;
devices are password protected;
devices are locked when unattended;
confidential information is not left unsecured;
public or unsecured Wi-Fi is avoided when handling sensitive information unless adequate security protections are used; and
confidential information is not discussed where conversations can reasonably be overheard.
15. International Data Transfers

360 OM may use employees, contractors, technology providers or other service providers located outside the United Kingdom.

Personal data must not be transferred outside the UK unless the transfer complies with applicable UK data protection requirements.

Depending on the destination and circumstances, safeguards may include:

UK adequacy regulations;
the UK International Data Transfer Agreement;
the UK Addendum to the EU Standard Contractual Clauses;
another legally recognised transfer mechanism; and
additional technical or organisational safeguards where appropriate.

Before appointing overseas processors or sub-processors, 360 OM must consider the data protection risks associated with the proposed processing and transfer.

16. Suppliers and Sub-processors

Before engaging a supplier that will process personal data, appropriate due diligence must be carried out.

Relevant considerations may include:

the nature of the data being processed;
security measures;
hosting locations;
international transfers;
breach procedures;
access controls;
deletion arrangements;
certifications;
use of further sub-processors; and
contractual data protection obligations.

Where required, an appropriate Data Processing Agreement must be in place.

360 OM must not appoint a sub-processor in relation to client personal data where doing so would breach the terms of the applicable client agreement or the client's documented instructions.

Where contractually required, 360 OM will provide appropriate notification of proposed additions or replacements to sub-processors.

17. Artificial Intelligence Tools

Personal data must not be uploaded to generative AI or other AI systems unless:

the tool has been approved for business use;
the intended processing is lawful;
applicable client instructions permit the processing;
appropriate contractual and security safeguards are in place;
any international transfer requirements have been considered; and
the information supplied is limited to what is necessary.

Employees and contractors should anonymise or pseudonymise information before using AI tools wherever reasonably possible.

Client customer lists, medical information, payment data, passwords, authentication credentials, API credentials or other sensitive datasets must not be uploaded into unapproved AI systems.

Confidential client information must be handled in accordance with both this policy and applicable contractual confidentiality obligations.

18. Special Category and Sensitive Data

360 OM should avoid processing special category personal data unless it is necessary to provide contracted services or otherwise conduct lawful business activities.

Where special category data is processed, an appropriate Article 6 lawful basis and Article 9 condition must be identified where required.

Access must be appropriately restricted and enhanced security measures considered.

Particular care must be exercised where 360 OM provides services to clients operating in healthcare, pharmacy, medical or similarly sensitive sectors.

360 OM personnel must avoid accessing or processing identifiable patient, treatment or medical information unless such access is specifically necessary, lawful and authorised.

19. Data Protection by Design and Default

Privacy and data protection considerations should be incorporated into projects at an early stage rather than addressed only after implementation.

This may include considering privacy when:

implementing new advertising technology;
adopting new AI systems;
introducing new CRM platforms;
building customer data integrations;
establishing server-side tracking;
creating customer segmentation models;
onboarding new suppliers; or
designing new marketing programmes.

Where processing is likely to result in a high risk to individuals, a Data Protection Impact Assessment ("DPIA") should be undertaken where required before processing begins.

20. Retention and Deletion

Personal data must only be retained for as long as reasonably necessary.

Retention periods should take into account:

the purpose for which the data was collected;
client contractual requirements;
legal obligations;
limitation periods;
regulatory obligations; and
legitimate business requirements.

Unless otherwise agreed with the client, client personal data should be securely deleted or returned following termination once it is no longer required to perform contractual or legal obligations.

Personal data contained in backups may remain until normal backup rotation or deletion cycles have completed, provided it remains appropriately protected and is not restored for ordinary business use.

360 OM should maintain an appropriate data retention schedule.

21. Data Subject Rights

Depending on the circumstances and applicable law, individuals may have rights including:

the right to be informed;
the right of access;
the right to rectification;
the right to erasure;
the right to restrict processing;
the right to data portability;
the right to object; and
rights relating to automated decision-making and profiling.

Any employee or contractor receiving a request that appears to exercise a data protection right must promptly forward it to the person responsible for data protection within 360 OM.

Personnel should not attempt to respond independently unless authorised to do so.

Where 360 OM acts as a processor, the relevant client controller should generally be informed promptly and provided with reasonable assistance in accordance with the applicable agreement.

22. Subject Access Requests

A Subject Access Request ("SAR") may be made verbally or in writing and does not necessarily need to use the phrase "subject access request".

All potential SARs must therefore be escalated promptly.

360 OM will maintain appropriate procedures to:

verify the identity of the requester where reasonable and necessary;
locate relevant personal data;
consider whether exemptions apply;
protect the personal information and rights of third parties; and
respond within applicable statutory deadlines.
23. Right to Object to Direct Marketing

Individuals have the right to object to the use of their personal data for direct marketing.

Where such an objection is received and applies, the personal data must no longer be processed for direct marketing purposes.

Suppression information may be retained where necessary to ensure that the individual's marketing preference continues to be respected.

24. Personal Data Breaches

All actual or suspected personal data breaches must be reported internally without undue delay.

Examples include:

sending customer information to the wrong recipient;
losing a laptop or mobile device containing personal data;
unauthorised access to a client platform;
compromised passwords;
accidentally publishing customer information;
malicious system access;
downloading or exporting data without authority;
loss of customer data;
ransomware;
compromised email accounts; or
an unauthorised third party obtaining access to personal data.

Employees and contractors must not attempt to conceal a suspected breach.

25. Breach Response Procedure

Upon becoming aware of a suspected personal data breach, 360 OM will, as appropriate:

contain the incident where possible;
preserve relevant evidence;
identify the systems and information affected;
establish the categories and approximate volumes of personal data involved;
determine which individuals may be affected;
assess the likely risks to individuals;
notify the relevant client without undue delay where 360 OM acts as processor;
determine whether notification to the ICO or another supervisory authority is required;
determine whether affected individuals must be informed;
document the incident and decisions taken; and
undertake remediation and preventative measures.

Where notification to the ICO is legally required, it must be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

26. Client Instructions Following an Incident

Where 360 OM acts as a processor, it will cooperate reasonably with the relevant client controller in investigating personal data incidents.

360 OM will provide information reasonably available to it concerning:

the nature of the breach;
affected systems;
categories of information;
estimated numbers of individuals affected;
security measures taken;
likely consequences; and
remediation measures.

360 OM will not notify affected individuals or regulators on behalf of a client unless legally required or expressly authorised to do so.

27. Staff Responsibilities

Everyone working for or on behalf of 360 OM is responsible for protecting personal data.

Personnel must:

comply with this policy;
follow applicable security procedures;
use only approved systems;
respect access restrictions;
report security incidents promptly;
complete required data protection training;
avoid unnecessary downloads or copies of personal data;
keep credentials secure;
challenge inappropriate data requests; and
seek guidance where uncertain.

Serious or deliberate breaches of this policy may constitute a disciplinary or contractual matter.

28. Data Protection Training

Appropriate data protection and security awareness training will be provided to personnel based on their roles.

Training may include:

UK GDPR principles;
identifying personal data;
phishing and cybersecurity;
secure handling of data;
subject access requests;
personal data breaches;
marketing compliance;
use of AI systems;
client confidentiality; and
secure remote working.

Training should be refreshed periodically.

29. Record Keeping and Accountability

360 OM will maintain records appropriate to the nature and scale of its processing.

These may include:

records of processing activities;
Data Processing Agreements;
supplier assessments;
sub-processor records;
international transfer documentation and assessments;
DPIAs;
Legitimate Interests Assessments;
training records;
personal data breach records;
data subject rights request records; and
retention schedules.
30. Privacy Notices

Where 360 OM acts as controller, appropriate privacy information must be provided to individuals where required.

Privacy notices should clearly explain, where applicable:

who 360 OM is;
what personal information is collected;
why it is processed;
the applicable lawful basis;
who it may be shared with;
international transfers;
how long information is retained;
individuals' rights;
how to exercise those rights; and
how to raise a complaint.
31. Complaints

Individuals who are concerned about the manner in which their personal data has been handled should be able to contact 360 OM.

Complaints should be investigated promptly and fairly.

Individuals may also have the right to lodge a complaint with the Information Commissioner's Office or another competent supervisory authority.

32. Governance and Responsibility

Overall accountability for compliance with this policy rests with the Directors of 360 OM Limited.

A nominated person should have operational responsibility for overseeing data protection compliance, including:

maintaining this policy;
coordinating data subject requests;
overseeing personal data breach management;
supporting DPIAs;
maintaining data protection documentation;
overseeing appropriate training;
reviewing suppliers and sub-processors; and
monitoring relevant regulatory developments.

Where 360 OM is not legally required to appoint a formal Data Protection Officer, references internally to a person responsible for data protection should not imply statutory DPO status unless such an appointment has formally been made.

33. Client Responsibility

Where a client acts as controller, the client remains responsible for determining matters including:

the purposes of processing;
the lawful basis;
appropriate privacy notices;
marketing permissions and consents;
applicable retention periods; and
lawful instructions issued to 360 OM.

360 OM may provide operational, marketing or technical recommendations, but clients remain responsible for their own controller obligations unless expressly agreed otherwise.

Nothing in this policy transfers a client's statutory responsibilities as controller to 360 OM.

34. Policy Updates and Online Publication

The current version of this policy will be made available through 360 OM Limited's website or another designated online location.

360 OM may amend this policy from time to time to reflect:

changes in applicable law or regulation;
ICO or other regulatory guidance;
changes in technology;
changes to security practices;
changes to suppliers or sub-processors;
changes to the services provided by 360 OM; or
changes to the Company's operations.

The effective date and version number of this policy will be updated whenever material amendments are made.

Previous versions should be retained by 360 OM for appropriate record-keeping and audit purposes.

Where reasonably appropriate, 360 OM may notify affected clients or other relevant parties of material changes.

Where a change materially affects the contractual rights or obligations of a client, that change will be dealt with in accordance with the amendment provisions of the applicable client agreement or Data Processing Agreement and will not take effect solely by publication of an updated version of this policy online.

For the avoidance of doubt, publication of an updated policy does not permit 360 OM to unilaterally vary separately agreed contractual data protection obligations where the relevant agreement requires the parties' agreement to such a variation.

35. Failure to Comply

Failure to comply with data protection legislation may expose 360 OM and, where applicable, its clients to:

regulatory investigation;
enforcement action;
contractual claims;
reputational damage;
loss of client or customer trust; and
financial penalties.

Employees or contractors who deliberately or negligently breach this policy may be subject to disciplinary or contractual action.

36. Policy Review

This policy will be reviewed:

at least annually;
following material amendments to applicable data protection legislation;
following significant ICO guidance updates;
following a significant personal data breach;
following significant changes to 360 OM's services or technology;
following significant changes to suppliers or processing arrangements; or
following material changes to the categories of personal data processed by the business.

Any material amendments must be approved by an appropriate Company director.

37. Policy Information

Organisation: 360 OM Limited
Policy: Data Protection & UK GDPR Policy
Version: 2.0
Effective: October 2025

Approved By: 360 OM Limited

© 360 OM Limited. All rights reserved.