FleetVerified
Privacy & Legal Centre / Privacy Notice

Privacy Notice

Version 1.0.0 · In effect from 7 August 2026 · Forms part of the agreement

How FleetVerified handles personal data in FleetVerified, the roles the platform provider and the operator each play under UK data protection law, and the rights available to individuals.

Contents

  1. 1. Who this notice is from
  2. 2. Our role and your operator's role
  3. 3. The personal data involved
  4. 4. Why we use it, and on what lawful basis
  5. 5. Who sees the data
  6. 6. International transfers
  7. 7. How long it is kept
  8. 8. Security
  9. 9. Your rights
  10. 10. Complaints
  11. 11. Cookies and on-device storage
  12. 12. Changes to this notice

1. Who this notice is from

FleetVerified is provided by FleetVerified ("we", "us"), registered in England and Wales with company number [to be completed before launch], registered office [to be completed before launch]. Our registration with the Information Commissioner's Office is [to be completed before launch].

Privacy enquiries: privacy@fleetverified.co.uk. Written correspondence: [to be completed before launch], marked for the attention of The Data Protection Lead.

2. Our role and your operator's role

This is the most important part of this notice, because two different organisations decide how your data is used, and which one is answerable depends on the data.

Your employer or the transport operator whose workspace you use (the "operator") is the controller for the fleet and compliance data held in the platform. The operator decides who is invited, which vehicles are recorded, which inspection regime applies and how long optional records are kept, and it is the operator that carries the statutory duties attached to an operator's licence. For that data we act as a processor, handling it on the operator's documented instructions under the data processing agreement.

We are the controller for a narrower set of data that we decide about ourselves: creating and securing the underlying account, protecting the service from abuse, billing the operator, and communicating with account administrators about the service. Where we are the controller, the lawful bases described below apply.

If you are a driver, technician or other member of staff, your first point of contact about your personal data is normally your operator. We will help them respond, and you may still contact us directly.

3. The personal data involved

CategoryWhat it includesWhose dataOur role
Account dataName, work email, job title, phone number, sign-in identity, role and operating-centre access, invitation historyAll usersController (account identity) / Processor (role assignment within the operator)
Driver recordsDriver name, walkaround checks completed, defects reported, declarations signed, nil-defect records, check timing and location of the operating centreDriversProcessor
Technician recordsAssigned work, labour sessions and timers, parts used, repair records, rework attempts, mechanic declarationsTechniciansProcessor
Transport Manager recordsSign-off decisions, quality-control reviews, return-to-service authorisations, policy changes madeTransport Managers and nominated staffProcessor
Workshop and external provider usersContact details of the provider's staff, work carried out, estimates and invoices raisedThird-party maintenance provider staffProcessor
Vehicle and compliance recordsVehicle identity, inspection schedules, MOT and plating dates, maintenance history, defect and VOR historyRelates to assets, but attributes work to named individualsProcessor
Audit logsEvery change: who, when, previous value, new value and stated reasonAll usersProcessor (operator's audit trail) / Controller (platform integrity)
Uploaded evidencePhotographs of defects and repairs, signatures, scanned documents, generated evidence packsDrivers, technicians, sign-off staffProcessor
Technical, device and security dataIP address, browser and device details, sign-in successes and failures, lockouts, two-step verification events, trusted-device records, error diagnosticsAll usersController
CommunicationsReminder and notification email, support correspondence, in-product messagesAll usersController (service and support) / Processor (operator reminders)

We do not ask for special category data. Please do not record health information, and do not upload photographs of people where a photograph of the vehicle or component would do.

4. Why we use it, and on what lawful basis

PurposeData usedLawful basis (where we are controller)
Creating accounts and authenticating usersAccount data, technical dataPerformance of a contract with the operator; our legitimate interest in a functioning, identified user base
Keeping the service secure — rate limiting, lockouts, two-step verification, fraud and abuse preventionSecurity and device dataLegitimate interests (protecting the service and its users); legal obligation to secure personal data
Providing support and service communicationsAccount data, correspondencePerformance of a contract; legitimate interests
Billing and account administrationAccount and operator data, billing contactsPerformance of a contract; legal obligation (tax and accounting records)
Diagnosing faults and improving reliabilityTechnical and error data, aggregated usage countsLegitimate interests (maintaining and improving a service the operator relies on)
Meeting our own legal and regulatory obligationsAny of the above as requiredLegal obligation
Fleet compliance management, inspections, defects, maintenance and evidenceDriver, technician, vehicle and evidence dataDetermined by the operator as controller — typically their legal obligation as an O-licence holder, and their legitimate interests in road safety

We do not use personal data held in the platform to train machine learning models, and we do not sell personal data or share it for anyone else's marketing.

5. Who sees the data

  • People within your own operator, limited by the role and operating-centre access their administrator gives them. Operator data is isolated at database level: one operator cannot query, export or infer another operator's records.
  • External maintenance providers your operator chooses to work with, restricted to the job cards shared with them.
  • Our sub-processors, who host, transmit and deliver the service. The current schedule is published and kept up to date.
  • Professional advisers, auditors and insurers, where genuinely necessary and under duties of confidence.
  • Enforcement authorities and courts where the law requires it, or where an operator produces an evidence pack for DVSA or a Traffic Commissioner.

Our own staff access operator data only where it is necessary to run or support the service, under access controls and logging, and never to browse compliance records out of interest.

6. International transfers

Customer data is stored at rest in the European Union (Ireland). Where a sub-processor operates outside the UK, the transfer is covered by UK adequacy regulations or by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment and appropriate technical measures such as encryption in transit and at rest. The sub-processor schedule states the location and mechanism for each one.

7. How long it is kept

Retention differs by record type, because a sign-in log and a brake test record are not the same thing. Compliance evidence is retained for the statutory and DVSA-expected periods even where the operational record around it has aged out, and it is never removed by a generic sweep. The full matrix is published in the retention overview.

8. Security

Encryption in transit and at rest, row-level isolation between operators enforced by the database itself, role-based permissions checked on the server rather than in the browser, two-step verification required for privileged roles, sign-in throttling, short-lived signed links for evidence files, and an append-only audit trail that administrators cannot rewrite. The security overview describes these controls in full.

9. Your rights

Under the UK GDPR and the Data Protection Act 2018 you may request access to your personal data, correction of inaccurate data, erasure in certain circumstances, restriction of processing, portability of data you provided, and you may object to processing based on legitimate interests. Where processing relies on consent you may withdraw it at any time without affecting earlier processing.

Erasure is not absolute. We must refuse, or partly refuse, where the record is compliance evidence an operator is legally required to keep, where it forms part of an audit trail evidencing who authorised safety-critical work, or where it is needed to establish or defend a legal claim. In those cases we will tell you which exemption applies. Where a person leaves an operator we end their access and, where appropriate, reduce their identification in historical records rather than destroying the compliance evidence itself.

To exercise a right, contact your operator's administrator, or contact us at privacy@fleetverified.co.uk. We respond within one month and will tell you promptly if we need to extend that for a complex request. We may ask for proof of identity.

10. Complaints

Please raise concerns with us first at privacy@fleetverified.co.uk — we would rather fix a problem than have you take it elsewhere unresolved. You have the right to complain to the Information Commissioner's Office at any time: ico.org.uk, helpline 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

11. Cookies and on-device storage

The platform uses only strictly necessary and functional on-device storage, and carries no advertising or third-party analytics technologies. The cookie notice sets out exactly what is stored and why.

12. Changes to this notice

Each version is numbered and dated, and the version in force when you accepted it is recorded against your account. Where a change materially affects how personal data is used we will notify account administrators and, where appropriate, ask for acceptance again before continued use.

Other documents

  • Terms of Service
  • Data Processing Agreement
  • Cookie and On-Device Storage Notice
  • Sub-processors
  • Security Overview
  • Data Retention Overview