Privacy Notice
How FleetVerified handles personal data in FleetVerified, the roles the platform provider and the operator each play under UK data protection law, and the rights available to individuals.
1. Who this notice is from
FleetVerified is provided by FleetVerified ("we", "us"), registered in England and Wales with company number [to be completed before launch], registered office [to be completed before launch]. Our registration with the Information Commissioner's Office is [to be completed before launch].
Privacy enquiries: privacy@fleetverified.co.uk. Written correspondence: [to be completed before launch], marked for the attention of The Data Protection Lead.
2. Our role and your operator's role
This is the most important part of this notice, because two different organisations decide how your data is used, and which one is answerable depends on the data.
Your employer or the transport operator whose workspace you use (the "operator") is the controller for the fleet and compliance data held in the platform. The operator decides who is invited, which vehicles are recorded, which inspection regime applies and how long optional records are kept, and it is the operator that carries the statutory duties attached to an operator's licence. For that data we act as a processor, handling it on the operator's documented instructions under the data processing agreement.
We are the controller for a narrower set of data that we decide about ourselves: creating and securing the underlying account, protecting the service from abuse, billing the operator, and communicating with account administrators about the service. Where we are the controller, the lawful bases described below apply.
3. The personal data involved
| Category | What it includes | Whose data | Our role |
|---|---|---|---|
| Account data | Name, work email, job title, phone number, sign-in identity, role and operating-centre access, invitation history | All users | Controller (account identity) / Processor (role assignment within the operator) |
| Driver records | Driver name, walkaround checks completed, defects reported, declarations signed, nil-defect records, check timing and location of the operating centre | Drivers | Processor |
| Technician records | Assigned work, labour sessions and timers, parts used, repair records, rework attempts, mechanic declarations | Technicians | Processor |
| Transport Manager records | Sign-off decisions, quality-control reviews, return-to-service authorisations, policy changes made | Transport Managers and nominated staff | Processor |
| Workshop and external provider users | Contact details of the provider's staff, work carried out, estimates and invoices raised | Third-party maintenance provider staff | Processor |
| Vehicle and compliance records | Vehicle identity, inspection schedules, MOT and plating dates, maintenance history, defect and VOR history | Relates to assets, but attributes work to named individuals | Processor |
| Audit logs | Every change: who, when, previous value, new value and stated reason | All users | Processor (operator's audit trail) / Controller (platform integrity) |
| Uploaded evidence | Photographs of defects and repairs, signatures, scanned documents, generated evidence packs | Drivers, technicians, sign-off staff | Processor |
| Technical, device and security data | IP address, browser and device details, sign-in successes and failures, lockouts, two-step verification events, trusted-device records, error diagnostics | All users | Controller |
| Communications | Reminder and notification email, support correspondence, in-product messages | All users | Controller (service and support) / Processor (operator reminders) |
We do not ask for special category data. Please do not record health information, and do not upload photographs of people where a photograph of the vehicle or component would do.
4. Why we use it, and on what lawful basis
| Purpose | Data used | Lawful basis (where we are controller) |
|---|---|---|
| Creating accounts and authenticating users | Account data, technical data | Performance of a contract with the operator; our legitimate interest in a functioning, identified user base |
| Keeping the service secure — rate limiting, lockouts, two-step verification, fraud and abuse prevention | Security and device data | Legitimate interests (protecting the service and its users); legal obligation to secure personal data |
| Providing support and service communications | Account data, correspondence | Performance of a contract; legitimate interests |
| Billing and account administration | Account and operator data, billing contacts | Performance of a contract; legal obligation (tax and accounting records) |
| Diagnosing faults and improving reliability | Technical and error data, aggregated usage counts | Legitimate interests (maintaining and improving a service the operator relies on) |
| Meeting our own legal and regulatory obligations | Any of the above as required | Legal obligation |
| Fleet compliance management, inspections, defects, maintenance and evidence | Driver, technician, vehicle and evidence data | Determined by the operator as controller — typically their legal obligation as an O-licence holder, and their legitimate interests in road safety |
We do not use personal data held in the platform to train machine learning models, and we do not sell personal data or share it for anyone else's marketing.
5. Who sees the data
- People within your own operator, limited by the role and operating-centre access their administrator gives them. Operator data is isolated at database level: one operator cannot query, export or infer another operator's records.
- External maintenance providers your operator chooses to work with, restricted to the job cards shared with them.
- Our sub-processors, who host, transmit and deliver the service. The current schedule is published and kept up to date.
- Professional advisers, auditors and insurers, where genuinely necessary and under duties of confidence.
- Enforcement authorities and courts where the law requires it, or where an operator produces an evidence pack for DVSA or a Traffic Commissioner.
Our own staff access operator data only where it is necessary to run or support the service, under access controls and logging, and never to browse compliance records out of interest.
6. International transfers
Customer data is stored at rest in the European Union (Ireland). Where a sub-processor operates outside the UK, the transfer is covered by UK adequacy regulations or by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment and appropriate technical measures such as encryption in transit and at rest. The sub-processor schedule states the location and mechanism for each one.
7. How long it is kept
Retention differs by record type, because a sign-in log and a brake test record are not the same thing. Compliance evidence is retained for the statutory and DVSA-expected periods even where the operational record around it has aged out, and it is never removed by a generic sweep. The full matrix is published in the retention overview.
8. Security
Encryption in transit and at rest, row-level isolation between operators enforced by the database itself, role-based permissions checked on the server rather than in the browser, two-step verification required for privileged roles, sign-in throttling, short-lived signed links for evidence files, and an append-only audit trail that administrators cannot rewrite. The security overview describes these controls in full.
9. Your rights
Under the UK GDPR and the Data Protection Act 2018 you may request access to your personal data, correction of inaccurate data, erasure in certain circumstances, restriction of processing, portability of data you provided, and you may object to processing based on legitimate interests. Where processing relies on consent you may withdraw it at any time without affecting earlier processing.
Erasure is not absolute. We must refuse, or partly refuse, where the record is compliance evidence an operator is legally required to keep, where it forms part of an audit trail evidencing who authorised safety-critical work, or where it is needed to establish or defend a legal claim. In those cases we will tell you which exemption applies. Where a person leaves an operator we end their access and, where appropriate, reduce their identification in historical records rather than destroying the compliance evidence itself.
To exercise a right, contact your operator's administrator, or contact us at privacy@fleetverified.co.uk. We respond within one month and will tell you promptly if we need to extend that for a complex request. We may ask for proof of identity.
10. Complaints
Please raise concerns with us first at privacy@fleetverified.co.uk — we would rather fix a problem than have you take it elsewhere unresolved. You have the right to complain to the Information Commissioner's Office at any time: ico.org.uk, helpline 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
12. Changes to this notice
Each version is numbered and dated, and the version in force when you accepted it is recorded against your account. Where a change materially affects how personal data is used we will notify account administrators and, where appropriate, ask for acceptance again before continued use.