How Lamix SMS meets the UK GDPR and Regulation (EU) 2016/679, and what your reviewer needs to sign us off.
The privacy policy covers data about you as an account holder. This page is about data that moves through the platform when you send traffic.
The roles
- You are the controller for your recipients. You hold the relationship, the consent and the message.
- We are your processor for delivery. We route on your instructions and do nothing else with it - no analysis, no mining.
- We are an independent controller for the delivery records we keep to reconcile with carriers, spot fraud, and meet our own tax and regulatory duties.
- Carriers downstream control the network data they generate. That is inherent to the network and applies to every provider in this market.
What we process for you
- Data subjects - the recipients of your messages.
- Personal data - destination number, sender identifier, content in transit, delivery status, timestamp, route.
- Special category data - not requested, not required. If your use case involves it, talk to us first.
- Purpose and duration - delivery and the checks it requires, for the term of the account plus the retention periods in the privacy policy.
Our commitments as processor
- We act on your documented instructions, and tell you if one looks like it would breach the law rather than quietly carrying it out.
- Staff and contractors are bound by confidentiality that survives the engagement.
- We apply the measures below and help you meet your own security, breach-notification and DPIA duties.
- We help with data subject requests that reach us instead of you.
- On termination we delete or return what we hold as processor.
- We provide what you need to demonstrate compliance, and accept audits on reasonable notice at no charge.
Sub-processors
Engaged under terms no less protective than these, and we stay responsible to you for them - you deal with us, not with them.
The current list comes from info@lamix.org. We give 30 days' notice before adding one, so nothing appears in your supply chain unannounced.
International transfers
Adequacy decision where one exists, otherwise the UK Addendum or the EU Standard Contractual Clauses with a transfer risk assessment.
The paperwork is already done for every destination we serve, so adding a country is not a new legal exercise on your side.
Technical and organisational measures
- Encryption in transit, and of credentials and settlement data at rest.
- Role-based access with mandatory MFA on production, reviewed quarterly.
- Segregation of customer data and per-account isolation of delivery records.
- Admin access to raw records logged for 12 months and available to you on request.
- Change management, vulnerability scanning and periodic penetration testing.
- Tested backup and restoration procedures.
- Vetting and data protection training for anyone with access.
Breaches
You hear from us within 72 hours, with what we actually know at the time. We would rather tell you early with an incomplete picture than late with a tidy one.
Report anything you are unsure about to info@lamix.org marked urgent.
Data subject requests
Requests about your recipients are yours to answer. If one reaches us we pass it to you promptly and help you respond, including finding the records. That help is part of the service, not a billable extra.
Getting a signed DPA
Email info@lamix.org with your entity name and destinations. A countersigned DPA with the sub-processor list and the SCCs comes back, usually same day, at no cost.
Have your own template? Send it. We will review yours rather than insist on ours, which is normally faster through procurement.
Contact
Everything data protection related: info@lamix.org. Registered office details available on request.
You can always complain to your supervisory authority. We would ask you to come to us first, only because we can usually fix it faster.