ADM Indicia Mobile App Privacy Policy
Privacy Policy

HIVE IN-STORE

Mobile Application — Published by ADM (Group) Limited

Effective date: 1 July 2026 Closed business-to-business platform ICO registration: Z2348775

Contents

1 Introduction

This Privacy Policy explains how ADM (Group) Limited ("ADM Indicia", "we", "us", or "our") collects, uses, stores, and shares personal data in connection with the HIVE IN-STORE mobile application ("the App").

ADM (Group) Limited is incorporated in England and Wales and is committed to protecting the personal data of all individuals who use the App in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy applies exclusively to users of the HIVE IN-STORE App. It does not apply to end customers of ADM Indicia's clients, who have no access to the App and are subject to separate data handling arrangements.

2 Data Controller

ADM (Group) Limited is the Data Controller for all personal data processed through the HIVE IN-STORE App.

ADM (Group) Limited

26-28 Bedford Row, 4th & 5th Floor, London, England, WC1R 4HE

ICO Registration Number: Z2348775

Privacy Contact: Global.Legal@adm-indicia.com

3 Who This Policy Applies To

HIVE IN-STORE is a closed, business-to-business platform. Access is restricted to two categories of authorised users:

End customers (the clients of ADM Indicia who commission field services) do not have access to the App. Customers may receive operational completion reports — containing photographic evidence, signatures, and work records generated within the App — delivered via a separate web-based management platform. This sharing is described in Section 7.

4 Information We Collect

4.1 Personal Information

4.2 Location Data

4.3 Camera, Photography, and Device Storage

4.4 Audio Recordings

4.5 Operational and Work Records

4.6 Device and Technical Data

4.7 In-App Communications

4.8 Notifications

5 How We Use Your Information

We use personal data collected through the App for the following purposes:

6 Legal Basis for Processing

We rely on the following legal bases under UK GDPR Article 6:

For subcontracted field operatives, the legal basis for processing is Article 6(1)(b) (performance of the subcontract) and Article 6(1)(f) (legitimate interests in managing and evidencing the delivery of contracted services).

7 Data Sharing and Disclosure

7.1 Partner Organisations

Partner Organisations are engaged by ADM Indicia as subcontractors to deliver field services using the App. They act as Data Processors under UK GDPR, processing personal data only on ADM Indicia's instructions and subject to formal Data Processing Agreements (DPAs). Partner Organisations do not control the data they access via the App.

7.2 End Customers

ADM Indicia's end customers do not access the App. However, they may receive operational completion reports — which may include photographs, signatures, location records, and task completion evidence generated via the App — delivered through the separate HIVE IN-STORE web management platform. This disclosure is made on the basis of our legitimate interests and contractual obligations to evidence the delivery of commissioned services.

7.3 Technology Sub-Processors

Microsoft Azure is engaged as a Data Processor under a formal Data Processing Addendum (DPA). The North Europe region (Ireland) is covered by the UK Government's adequacy decision for EEA countries, meaning no International Data Transfer Agreement (IDTA) is required for UK-to-Ireland data transfers.

Sub-ProcessorService / RoleLocationSafeguard
Microsoft Azure (Microsoft Ireland Operations Limited) Cloud infrastructure provider — hosting, database, file storage, identity management, messaging, and email delivery services used to operate the HIVE IN-STORE platform North Europe region (Ireland) Microsoft Products and Services Data Processing Addendum (DPA). North Europe (Ireland) is covered by the UK adequacy decision for EEA countries — no IDTA required.

A full breakdown of Azure services used within the platform, together with the categories of personal data processed by each, is maintained in ADM Indicia's internal Records of Processing Activities (Article 30 UK GDPR). This record is available to the ICO on request.

7.4 Legal Disclosure

We may disclose personal data to law enforcement, regulatory authorities, or courts where required to do so by law or in response to a valid legal request.

8 Data Storage and Security

All personal data is stored and processed within Microsoft Azure infrastructure hosted in the North Europe region (Ireland).

We implement appropriate technical and organisational security measures to protect personal data against unauthorised access, loss, or disclosure. These measures include:

9 Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law or contract. The table below sets out our retention periods by data category.

Data CategoryDescriptionRetention PeriodBasis for Retention
User account and identity dataName, email address, login credentials, role and organisational affiliationDuration of employment / subcontract + 7 years as part of operational work recordsContractual obligation; legitimate interests
Operational work recordsWork orders, task completion records, asset inspection records, attendance records7 years from date of recordLegal obligation; contractual obligation to end customers
Photographic and documentary evidencePhotographs, PDFs, and completion evidence captured during field operations7 years from date of capture as part of operational work recordsContractual obligation to evidence delivery of commissioned services
Electronic signaturesSignatures captured via the App to confirm task completion or acceptance7 years from date of capture as part of operational work recordsContractual obligation; legal obligation
Audio recordingsVoice and sound recordings made via the in-app chat feature7 years from date of capture as part of operational work recordsLegitimate interests — internal communications
In-app chat messagesText messages exchanged between authorised users within the App7 years from date of capture as part of operational work recordsLegitimate interests — internal communications
Location dataGPS and network location records associated with field activity7 years from date of capture as part of operational work recordsContractual obligation; legitimate interests
Application logs and diagnosticsCrash logs, error reports, performance metrics, and structured event logs stored locally on Azure infrastructure via Seq90 days for system maintenance and operational troubleshootingLegitimate interests — system reliability and security monitoring
Device-cached dataData stored locally on the user's device via WatermelonDB for offline useCleared on account deactivation or App uninstallN/A — device-local storage only
Authentication tokens and session dataJWT tokens and Redis-cached session data used for App authenticationSession duration; tokens expire per identity provider configurationLegitimate interests — security and access control
Retention periods shown above require confirmation and sign-off by ADM Indicia prior to publication of this policy. Retention periods shown in the table are standard, however they should be reviewed against applicable contractual obligations with end customers and any relevant regulatory or legal requirements.

Locally cached data on user devices is cleared upon account deactivation or when the App is uninstalled.

10 Your Rights Under UK GDPR

As a data subject under UK GDPR, you have the following rights:

To exercise any of these rights, please contact us at Global.Legal@adm-indicia.com.

10.1 Data Protection Officer

ADM Indicia has assessed its obligations under UK GDPR and has determined that appointment of a Data Protection Officer is not currently required. Privacy matters are managed by the Global Legal team.

11 International Data Transfers

The HIVE IN-STORE platform is deployed to support operations in the Asia-Pacific (APAC) region. This may involve the transfer of personal data to countries outside the United Kingdom.

Transfer jurisdictions: India

Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place in accordance with UK GDPR Chapter V, including:

The primary Azure infrastructure is hosted in the North Europe region (Ireland), which is covered by the UK's adequacy decision for EEA countries and does not require an IDTA for UK-to-Ireland transfers.

12 Children's Privacy

The HIVE IN-STORE App is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. Access to the App requires a valid employment or subcontract relationship with ADM Indicia or a Partner Organisation.

13 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. Where changes are material, we will notify authorised users through appropriate channels.

14 Contact Us

If you have any questions, concerns, or complaints about how we handle your personal data, please contact us:

ADM (Group) Limited

26-28 Bedford Row, 4th & 5th Floor, London, England, WC1R 4HE

Email: Global.Legal@adm-indicia.com

You also have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner's Office (ICO)

Website: www.ico.org.uk

Telephone: 0303 123 1113

Post: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF