B2B mobile wholesaleBelfast, Northern IrelandUK & Europe served

CLEAR INFORMATION ABOUT YOUR DATA

Privacy
Policy.

How BMW collects, uses, shares, protects and retains personal data across its website, trade relationships and B2B services.

CURRENT PUBLISHED VERSION
LAST UPDATED5 August 2026

Applies to personal data handled through the website and BMW's business operations from this publication date.

DATA CONTROLLERUL Mobiles LtdUK FRAMEWORKUK GDPR & DPA 2018EU FRAMEWORKWhere applicableCOMPANY NUMBERNI721693
01

Introduction and scope

This Privacy Policy explains how UL Mobiles Ltd trading as Bulk Mobile Wholesalers, referred to in this policy as BMW, we, us or our, collects and uses personal data through bulkmobilewholesalers.com and during our business operations. It applies to website visitors, buyer and supplier contacts, trade applicants, service customers, professional advisers and other individuals who communicate or trade with us.

Please read this policy so that you understand what information we hold, why we use it, who may receive it, how long we keep it and the rights available to you. Using the website does not remove any of those rights. When you provide personal data, you acknowledge that it will be handled as described here and under applicable law.

This is the current published version, last updated on 5 August 2026. It should be read with our Cookie Policy and, where relevant, our Terms and Conditions.

02

Who we are and our role as Data Controller

UL Mobiles Ltd is the Data Controller for the personal data described in this policy. This means we decide why and how that personal data is processed and are responsible for handling it lawfully, fairly, securely and transparently.

  1. 02.1

    Legal entity. UL Mobiles Ltd trading as Bulk Mobile Wholesalers.

  2. 02.2

    Company number. NI721693, registered in Northern Ireland.

  3. 02.3

    VAT number. XI 478420863.

  4. 02.4

    Registered address. 37a Upper Dunmurry Lane, Dunmurry, Belfast, Northern Ireland, BT17 0AA.

  5. 02.5

    Website. bulkmobilewholesalers.com.

  6. 02.6

    Data protection contact. [email protected]. Please use the subject line Privacy Request or Data Protection Complaint so the matter can be routed correctly.

  7. 02.7

    WhatsApp. +44 7425 299682. Email is the preferred route for formal rights requests because it creates a clear written record.

03

Data protection framework

Our principal data protection framework is the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, in each case as amended. This includes relevant amendments made by the Data (Use and Access) Act 2025.

The EU General Data Protection Regulation may also apply to particular processing where its territorial-scope requirements are met, including certain activities directed to individuals in the European Economic Area. EU trading activity or an XI VAT number does not by itself decide territorial scope, so we assess the applicable framework by reference to the actual processing activity.

Where both UK and EU rules apply, we aim to meet the requirements of each. References in this policy to data protection law mean the framework that applies to the relevant processing.

04

Personal data we collect

Personal data means information relating to an identified or identifiable individual. Company information is not personal data by itself, but information about a director, employee, beneficial owner, sole trader or business contact may be personal data.

  1. 04.1

    Identity and business contact data. Name, job title, company name, business address, business email address, telephone number, WhatsApp number, preferred contact method and professional role.

  2. 04.2

    Trade-account and verification data. Company registration, VAT or tax details, ownership and beneficial-owner information, identification documents where reasonably required, proof of address, trade references, source and destination information, due-diligence results and account status.

  3. 04.3

    Transaction and commercial data. Enquiries, requested stock, quotations, orders, invoices, payment references, payment status, currency, VAT route, delivery information, returns, warranty claims, supplier offers, purchase records and trading history.

  4. 04.4

    Correspondence data. Emails, contact-form submissions, WhatsApp messages, telephone notes, meeting records, complaints, rights requests and other communications with BMW.

  5. 04.5

    Device and service data. Device identifiers, model, grade, diagnostic results, CheckMend or blacklist status, repair and erasure records, ownership or provenance evidence and information needed to perform an agreed service or assess offered stock.

  6. 04.6

    Technical and usage data. IP address, browser and device type, operating system, approximate location derived from IP, referring page or source, pages viewed, time and interaction data, cookie identifiers, security logs and similar website information.

  7. 04.7

    Marketing and preference data. Newsletter or stock-alert choices, consent records, unsubscribe status, areas of commercial interest and communication preferences.

  8. 04.8

    Fraud, security and compliance data. Information used to identify suspicious activity, sanctions or legal risk, validate payment and delivery instructions, protect accounts, investigate incidents and maintain an audit trail.

05

Sensitive data, device content and children

We do not ordinarily ask for special category data, such as health, biometric, religious or political information, and we do not intentionally collect it through general website forms. Please do not include sensitive personal information in a free-text field unless it is genuinely necessary. If we receive it, we will limit its use and apply an additional legal condition where the law requires one.

Devices supplied to BMW should be cleared of personal accounts, content and access locks before transfer unless secure data erasure is an agreed part of the service. Any residual device content encountered during diagnostic, repair, refurbishment, buy-back or recycling work is handled under restricted operational controls and is not used for unrelated purposes.

Our website and services are intended for professional business users and are not directed to children. We do not knowingly collect personal data from anyone under 18 through a trade application. If you believe a child has supplied information to us, contact us so we can investigate and remove it where appropriate.

06

How we collect personal data

  1. 06.1

    Directly from you. When you complete a trade application, request a quote, apply to become a supplier, offer devices for sale, submit a contact form, subscribe to stock updates, place an order, raise a claim or make a privacy request.

  2. 06.2

    Through correspondence. When you communicate with us by email, WhatsApp, telephone, video call, in person or through another agreed business channel.

  3. 06.3

    Through our commercial relationship. When we create quotations, invoices, delivery records, payment records, service files, testing records, returns, warranty or supplier records during trading.

  4. 06.4

    Automatically. When cookies, logs, analytics and similar technologies collect technical and usage data as you visit or interact with the website.

  5. 06.5

    From your organisation. When a colleague, director, buyer, supplier or authorised representative gives us your professional contact details for a legitimate business purpose.

  6. 06.6

    From public and third-party sources. From Companies House, VAT and business registers, sanctions and fraud-prevention sources, professional websites, trade references, CheckMend, payment providers, couriers and other sources used for proportionate due diligence or transaction administration.

Where we obtain personal data indirectly, we provide privacy information within the period required by law unless an exemption applies, the person already has the information or doing so would be impossible or involve disproportionate effort under an applicable legal provision.

07

Our lawful bases for processing

We use personal data only where we have a lawful basis. More than one basis may apply to the same activity. Contract is relevant where the individual is personally party to, or taking steps toward, a contract. Where a contact acts for a limited company or other organisation, our legitimate interests in managing that business relationship will often be the more appropriate basis.

  1. 07.1

    Contract and pre-contract steps. To respond to a request made by an individual who will be party to a contract, manage a sole-trader account, process an order, arrange delivery, provide an agreed service, handle payment or manage a claim connected with that contract.

  2. 07.2

    Legitimate interests. To develop and manage B2B relationships, respond to corporate contacts, administer trade accounts, improve our website and services, maintain records, secure systems, prevent fraud, conduct proportionate due diligence, recover debts and protect BMW, its buyers, suppliers and partners. We assess necessity and balance these interests against individual rights where required.

  3. 07.3

    Legal obligation. To maintain tax, VAT, accounting and company records, meet data protection duties, comply with court orders or lawful authority requests, support customs obligations and satisfy other legal or regulatory requirements.

  4. 07.4

    Consent. For non-essential cookies and analytics where consent is required, and for email stock offers or newsletters where an individual has specifically opted in or applicable electronic-marketing law requires consent. Consent can be withdrawn at any time.

  5. 07.5

    Recognised legitimate interests. Where UK law expressly recognises a legitimate interest, such as certain disclosures needed to assist a public authority with its lawful task or to protect public security. We rely on this only where the statutory conditions are met.

  6. 07.6

    Legal claims. Where necessary to establish, exercise or defend legal claims, including the limited handling of relevant special category or criminal-offence data where a separate legal condition is satisfied.

08

How we use personal data

  1. 08.1

    Enquiries and quotations. To understand a request, confirm requirements, prepare a quotation and continue a relevant business conversation.

  2. 08.2

    Trade accounts. To assess, open, manage, secure, suspend or close buyer and supplier accounts and keep their details accurate.

  3. 08.3

    Orders, services and payments. To confirm stock, manage contracts, issue invoices, reconcile funds, provide services, arrange dispatch and delivery, handle returns, warranty claims and refunds, and maintain a transaction record.

  4. 08.4

    Due diligence. To verify the legitimacy, identity, ownership, trading status, payment route, stock provenance, destination and risk profile of potential or existing buyers and suppliers.

  5. 08.5

    Commercial updates. To send stock offers, new-arrival notices, service updates and other relevant B2B communications to people who have opted in or where another lawful route is available.

  6. 08.6

    Legal and regulatory compliance. To meet tax, VAT, accounting, customs, company, sanctions, fraud-prevention, data protection and other applicable duties, and to respond to lawful requests.

  7. 08.7

    Website operation and improvement. To deliver pages, maintain functionality, understand aggregate use, diagnose faults, improve content and services and measure performance.

  8. 08.8

    Security and protection. To protect accounts, systems, funds, stock, intellectual property and business partners, investigate suspected fraud or illegal activity and preserve evidence.

  9. 08.9

    Business administration. To manage advisers, insurance, audits, disputes, debt recovery, business continuity, corporate transactions and internal reporting.

09

Data about other people

If you give us personal data about a colleague, director, beneficial owner, delivery contact, customer, supplier, trade reference or other person, you must have authority or another lawful basis to do so and should make this policy available to them where appropriate.

We use information about those individuals only for the relevant business, verification, transaction, service, security or legal purpose. We may contact them directly where necessary to verify details, administer the relationship or provide privacy information.

10

Stock alerts and direct marketing

We may send stock offers, new-arrival alerts, service news and related commercial information. Where consent is required by the Privacy and Electronic Communications Regulations, we ask for it before sending electronic marketing. For relevant contacts at corporate bodies, we may rely on legitimate interests where the law permits and the communication is proportionate to the recipient's professional role.

Every electronic marketing message will provide a practical way to opt out. You may also unsubscribe at any time by emailing [email protected]. Stopping marketing does not stop essential messages about an active enquiry, account, order, service, payment, delivery or legal matter.

We do not sell personal data and do not share personal data with another organisation for that organisation's independent marketing.

11

Data sharing and third parties

We share only the personal data reasonably needed for a defined purpose. Service providers acting for us must handle data under appropriate confidentiality, security and data-processing terms. Some recipients act as independent controllers where they determine their own legal purposes and duties.

  1. 11.1

    Courier and logistics partners. Including DHL, FedEx, UPS, Royal Mail and GLS, for collection, delivery, tracking, customs and investigation of transit issues.

  2. 11.2

    Banks and payment providers. To receive, validate, reconcile, return or investigate payments and protect against payment fraud.

  3. 11.3

    IT and business-system providers. Website hosting, cloud storage, email, communications, CRM, accounting, support, cybersecurity, analytics, data erasure and system-maintenance providers.

  4. 11.4

    Verification and compliance providers. Company, VAT, identity, sanctions, fraud, device-status, CheckMend and trade-reference services used for proportionate due diligence.

  5. 11.5

    Professional advisers. Lawyers, accountants, auditors, insurers, consultants, debt-recovery providers and other advisers where their work requires access.

  6. 11.6

    Authorities and law enforcement. HMRC, customs bodies, courts, regulators, police and other competent authorities where disclosure is required or permitted by law.

  7. 11.7

    Corporate transactions. A genuine prospective buyer, investor, lender or successor in connection with a merger, financing, restructuring or sale, subject to appropriate confidentiality and lawful safeguards.

12

Controller and processor roles in device services

For website, contact, account, supplier, transaction, compliance and relationship data described in this policy, UL Mobiles Ltd acts as Data Controller.

In a limited service engagement, such as handling a device or dataset strictly under a trade client's documented instructions, BMW may instead act as a Data Processor for particular personal data. In that case, the client remains the controller and the service agreement or data-processing terms govern that processing. This policy still applies to BMW's own account, billing, security, compliance and relationship records.

13

International data transfers

BMW trades across the UK, the European Economic Area and other international markets. Personal data may therefore be accessed, stored or processed outside the country where it was collected, including through couriers, cloud systems, communications providers and professional partners.

Where a transfer is restricted by UK data protection law, we use an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses or another lawful safeguard. Where EU GDPR transfer rules apply, we use an applicable European Commission adequacy decision, approved EU Standard Contractual Clauses or another permitted safeguard.

Where required, we assess the destination, recipient, contractual protection and practical risks and apply supplementary measures. A limited legal exception is used only where the relevant conditions are genuinely met. You may contact us for information about the safeguard used for a particular transfer.

14

How long we keep personal data

We keep personal data only for as long as it is reasonably needed for the purpose collected, including legal, tax, accounting, security, warranty, dispute and evidence requirements. We consider the amount, sensitivity, risk, purpose and applicable limitation periods when setting retention periods.

  1. 14.1

    Financial and transaction records. Normally retained for seven years from the end of the relevant accounting period or transaction record so that BMW can meet HMRC, VAT, accounting, audit and reasonable legal-claims requirements.

  2. 14.2

    Active trade accounts. Retained throughout the relationship and normally for up to seven years after the last material transaction or account closure, subject to any continuing dispute, legal or compliance need.

  3. 14.3

    Unsuccessful applications and due diligence. Normally retained for up to two years after the decision, unless a longer period is justified by fraud prevention, a legal duty, a complaint or a prospective relationship.

  4. 14.4

    Enquiries and correspondence. Normally retained for up to two years after the enquiry closes. If the enquiry leads to a transaction, claim, complaint or dispute, the relevant longer record period applies.

  5. 14.5

    Supplier and service records. Retained for the relationship and a reasonable period afterward, normally aligned with the related transaction, warranty, accounting and legal requirements.

  6. 14.6

    Marketing records. Active subscription data is retained until unsubscribe or withdrawal. We may keep a minimal suppression record afterward so that the opt-out continues to be respected.

  7. 14.7

    Website analytics and cookies. Retained according to the settings and periods stated in our Cookie Policy and the relevant platform controls. Aggregated or effectively anonymised statistics may be kept longer because they no longer identify an individual.

  8. 14.8

    Security and incident records. Kept for a period proportionate to the risk and, where an incident, claim or investigation occurs, until the matter and any related limitation period are complete.

A record may be deleted earlier where no longer needed or kept longer where required by law, litigation hold, regulatory enquiry, fraud prevention or another documented lawful reason.

15

Data security

We use proportionate technical and organisational safeguards designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. No internet or storage system can be guaranteed completely secure, but we review risk and improve controls as our systems and operations develop.

  1. 15.1

    Access controls. Role-based access, account controls and confidentiality expectations limit information to people who need it for their work.

  2. 15.2

    Secure systems and communications. Appropriate hosting, backups, system maintenance, malware protection, secure transfer methods and verified communication routes are used according to the risk.

  3. 15.3

    Payment and instruction checks. We verify unusual bank-detail, delivery and account instructions and retain audit records to reduce impersonation and fraud risk.

  4. 15.4

    Device data erasure. Where erasure is part of our operational process, BMW uses controlled procedures and Blancco-certified data-erasure technology where applicable, with records maintained for the relevant service.

  5. 15.5

    Provider controls. Relevant processors and service providers are selected and managed using contractual, confidentiality and security requirements appropriate to their role.

  6. 15.6

    Review and incident response. We review security arrangements, investigate suspected incidents and notify affected people and regulators where data protection law requires it.

16

Your data protection rights

Depending on the circumstances and applicable law, you may exercise the rights below. These rights are not absolute. An exemption may apply, and some rights depend on the lawful basis, the type of processing and whether the information can identify you.

  1. 16.1

    Access. Ask whether we process your personal data and request a copy together with relevant information about its use.

  2. 16.2

    Rectification. Ask us to correct inaccurate personal data or complete information that is materially incomplete.

  3. 16.3

    Erasure. Ask us to delete personal data in circumstances where there is no continuing lawful reason to keep it.

  4. 16.4

    Restriction. Ask us to limit use of personal data in certain circumstances, including while accuracy or an objection is being assessed.

  5. 16.5

    Data portability. Receive qualifying data you provided in a structured, commonly used and machine-readable format, or ask for it to be sent to another controller where technically feasible.

  6. 16.6

    Object. Object to processing based on legitimate interests. We will stop unless we demonstrate compelling legitimate grounds or need the data for legal claims.

  7. 16.7

    Object to direct marketing. Object at any time to use of your personal data for direct marketing. We will stop that marketing without requiring you to explain why.

  8. 16.8

    Withdraw consent. Withdraw consent at any time where processing relies on it. Withdrawal does not affect processing already carried out lawfully before withdrawal.

  9. 16.9

    Automated decisions. Request safeguards and human involvement where a solely automated significant decision is made and the right applies.

  10. 16.10

    Complain. Raise a complaint with BMW and lodge a complaint with the ICO or, where EU GDPR applies, the relevant EEA supervisory authority.

To exercise a right, email [email protected] with the subject Privacy Request. Tell us the right you wish to exercise and provide enough information to locate the record. We may ask for proportionate proof of identity or authority. We normally respond within one month, subject to any lawful extension, and do not charge a fee unless the law permits one.

17

Automated decision-making and profiling

BMW does not currently make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. Automated tools may help organise enquiries, identify website patterns, flag security concerns or support due diligence, but material trade-account and relationship decisions involve appropriate human review.

If this changes, we will provide the information and safeguards required by applicable law, including meaningful information about the logic and likely consequences where required.

18

Cookies and similar technologies

The website uses cookies and similar storage or access technologies for functions such as security, essential operation, preferences, analytics and performance. Some technologies are necessary, while others are used only with consent where the law requires it.

Our separate Cookie Policy explains the technologies used, their purposes, providers and duration, and how to accept, reject or change optional settings. Browser controls may also allow you to block or delete cookies, although disabling essential technologies can affect website operation.

Read the Cookie Policy
19

Data protection complaints

If you are unhappy with how BMW has handled personal data, email [email protected] with the subject Data Protection Complaint. Explain what happened, whose data is involved, the outcome you are seeking and include relevant correspondence or references. We may request proportionate evidence of identity or authority where needed.

We will acknowledge a data protection complaint within 30 days of receipt, investigate and keep you informed without undue delay, and explain the outcome. You do not have to complete our internal process before contacting a regulator, although giving us the opportunity to resolve the matter may lead to a faster practical answer.

In the UK, you may complain to the Information Commissioner's Office at ico.org.uk. If EU GDPR applies to the processing, you may also complain to the competent supervisory authority in the EEA country connected with the matter.

Visit the ICO website
20

Changes to this Privacy Policy

We may update this policy to reflect changes in law, guidance, technology, providers, services or business operations. The last-updated date at the top of this page identifies the current published version.

A material change will be highlighted on the website or communicated directly where appropriate. Earlier processing remains governed by the law and privacy information applicable at the relevant time.

21

Privacy contact details

For a privacy enquiry, rights request or data protection complaint, contact UL Mobiles Ltd trading as Bulk Mobile Wholesalers using the details below. Please include your name, company, contact details and enough information for us to understand and locate the relevant record. Do not send unnecessary identity documents until we ask for them securely.

PRIVACY EMAIL[email protected]WHATSAPP+44 7425 299682
REGISTERED ADDRESS37a Upper Dunmurry Lane, Dunmurry, Belfast, Northern Ireland, BT17 0AA
REQUEST SUBJECTPrivacy Request or Data Protection Complaint
PRIVACY ENQUIRY OR REQUEST

Want to understand
your data?

Tell us who you are, the company or transaction involved and what you would like us to explain, correct, provide or review.

WRITE TO THE PRIVACY CONTACT[email protected]INDEPENDENT UK REGULATORInformation Commissioner's Office