Communications Policy

Last updated: 23 August 2026

Purpose

OMSUK uses approved communication channels to protect confidential and personal information, maintain reliable business records and ensure that client instructions can be verified and acted upon correctly.

This policy applies to communications between OMSUK, its clients, users, suppliers and other business contacts.

Approved communication channels

Business communications should normally take place using one or more of the following:

  • Email using an approved business account.

  • Microsoft Teams or another collaboration platform approved by OMSUK.

  • Telephone or video call.

  • The OMSUK client portal.

  • ConnectWise ticket communications.

  • Approved remote-support tools.

  • Face-to-face meetings.

  • Company SMS services where there is a legitimate business need.

The availability of a particular channel may depend on the client, service and sensitivity of the information involved.

Recording important communications

Instructions, approvals, decisions and other communications that are relevant to the delivery of a service should be recorded in the appropriate support ticket, project record, client record or other approved business system.

Where an important instruction is received verbally, by SMS or through another channel that does not automatically create a permanent business record, OMSUK may confirm or summarise it through email or the relevant ticket.

Telephone and video calls are not routinely recorded. Relevant decisions or instructions may instead be documented in written notes.

Messaging and social-media services

Personal messaging accounts and social-media direct messages should not normally be used for substantive business communications.

Receiving a message through an unapproved channel does not automatically constitute a personal-data breach. However, staff should move any substantive conversation to an approved channel and record relevant information in the appropriate business system.

Where there is evidence that personal or confidential information may have been exposed, lost, misdirected or accessed without authorisation, the matter will be handled under OMSUK’s incident-management and personal-data-breach procedures.

Sensitive requests and identity verification

OMSUK may require additional verification before acting on requests involving:

  • Password or multi-factor authentication resets.

  • Changes to user or administrator access.

  • Financial transactions or changes to payment details.

  • Disclosure of confidential or personal information.

  • Domain, cloud-service or security changes.

  • The transfer or deletion of significant quantities of information.

  • Any request that appears unusual or inconsistent with previous instructions.

Verification may take place through a known telephone number, Microsoft Teams video call, an existing authorised contact or another previously agreed method.

For security reasons, OMSUK may decline to act on a sensitive request until appropriate verification has been completed.

Sharing confidential information

Confidential information should only be shared with authorised recipients and only to the extent necessary for the intended purpose.

Passwords, recovery codes and other authentication information must not be sent through ordinary email or messaging services unless an approved secure method has been agreed. OMSUK uses approved password-management and secure-sharing systems for this purpose.

Before sending sensitive information, the sender should check the recipient, attachment and permissions carefully.

Electronic transfers and attachments

Where possible, large or sensitive files should be transferred using an approved secure file-sharing service rather than as ordinary email attachments.

Links should be restricted to the intended recipients where the platform supports this. Access should be removed when it is no longer required.

Files and links received from external parties may be scanned, blocked, quarantined or otherwise restricted by OMSUK’s security systems. Alternative transfer arrangements may be required where an attachment cannot be accepted safely.

International communications

Electronic communications and supporting services may be processed through infrastructure located outside the United Kingdom.

Where this involves a restricted transfer of personal information, OMSUK uses an appropriate transfer mechanism or safeguard as required by UK data-protection law.

Use of artificial intelligence

Where OMSUK personnel use an approved artificial-intelligence service to assist with drafting, analysis or administration:

  • Only approved business accounts and services may be used.

  • Client passwords, authentication secrets and unnecessary confidential information must not be entered.

  • The minimum information necessary should be used.

  • Outputs must be reviewed by an appropriate person before they are relied upon or sent externally.

  • Responsibility for the accuracy and suitability of the final communication remains with OMSUK.

Monitoring and security

OMSUK may retain logs and business communications where necessary to operate its services, maintain security, resolve disputes, meet legal obligations and preserve appropriate business records.

Communications may be filtered or monitored using automated security tools to detect spam, phishing, malware, impersonation and other threats.

Questions or concerns

Questions about secure communications can be sent to hello@omsuk.com.

Suspected security incidents, misdirected communications or accidental disclosures should be reported to OMSUK immediately using a known contact method.