FleetSmart Consultants

Legal

Information Handling Procedure

1. Purpose

This procedure sets out the company-wide method for handling information throughout its lifecycle at FleetSmart Consultants. It covers collection, creation, classification, access, use, storage, retention, printing, correction and secure disposal, including information processed through FleetPro UK and the DVLA ADD service.

2. Scope

The procedure applies to all business and personal information handled by FleetSmart Consultants in electronic or paper form, including customer records, driver and vehicle information, uploaded documents, account information, reports, emails, contracts, system logs, credentials, integrations and regulatory data.

3. Classification before handling

  • Public - approved for public distribution.
  • Internal - routine company information not intended for public distribution.
  • Confidential - customer, driver, commercial, contractual or other personal/business information requiring controlled access.
  • Restricted - highly sensitive data such as raw DVLA responses, passwords, API secrets, authentication tokens and privileged security information.

4. General information lifecycle

  1. Collect or create only information that is necessary for a defined and legitimate business, contractual, legal or regulatory purpose.
  2. Classify the information according to its sensitivity and identify who is authorised to access it.
  3. Store electronic information only in approved company systems or cloud services with appropriate access controls.
  4. Use information only for the purpose for which it was collected or another lawful and compatible purpose.
  5. Share information only with an authorised recipient and only to the extent necessary.
  6. Keep information accurate where accuracy is relevant to its use and correct verified errors promptly.
  7. Retain information for the applicable business, contractual, legal or regulatory retention period.
  8. Delete, anonymise or securely destroy information when it is no longer required.

5. Electronic storage and access

  • Confidential and Restricted information must be stored in approved systems rather than personal storage or unapproved applications.
  • Access must be through individual authenticated accounts and limited according to role and business need.
  • FleetPro UK uses organisation-level access controls and Supabase RLS where applicable so customer users can access only their own organisation's information.
  • Privileged credentials and secrets must be stored separately from frontend/client code and must not be disclosed to customer users.

6. Email, transfer and sharing

  • Recipients must be checked before sending Confidential or Restricted information.
  • Only the minimum information necessary should be shared.
  • Restricted information must not be sent through personal email, consumer messaging applications or other unapproved channels.
  • Where information is shared with a Data Controller, processor, supplier or other third party, applicable contractual, confidentiality and data-protection requirements must be followed.
  • International transfers or accessibility must be assessed where personal data may be made accessible outside the United Kingdom.

7. Downloads, printing and paper records

  • Downloads of Confidential or Restricted information should be avoided unless required for a legitimate purpose.
  • Locally stored copies must be protected and deleted when no longer required.
  • Printed Confidential or Restricted information must be kept away from public or unauthorised access.
  • Paper records containing sensitive information must be securely destroyed, for example by cross-cut shredding or an approved confidential-waste service.

8. Data quality and corrections

Information that appears incorrect, mismatched or associated with the wrong customer, driver or record must not be silently reassigned. Access should be restricted where appropriate while the source is verified. Corrections must be made only after sufficient verification and, where relevant, an audit trail retained.

9. Retention and disposal

Each category of information must be retained only for its approved period. At expiry it must be deleted, anonymised or securely destroyed unless a legal, contractual, regulatory or documented Data Controller requirement justifies continued retention. Copies should not be retained in unapproved locations after the authoritative record is deleted.

10. Subject rights and data-protection requests

Requests relating to personal data must be handled according to FleetSmart Consultants' role in the relevant processing activity. Where FleetSmart Consultants acts as Data Processor, the request should be referred promptly to the relevant Data Controller unless FleetSmart Consultants is legally required to respond directly, and reasonable assistance should be provided in accordance with the data-processing agreement.

11. Security incident handling

  • Restrict or disable compromised access where safe and appropriate.
  • Preserve relevant logs and evidence and identify the information, systems and organisations potentially affected.
  • Prevent further disclosure or access and rotate compromised credentials or secrets where necessary.
  • Inform the relevant Data Controller without undue delay where FleetSmart Consultants acts as Processor.
  • Assess whether DVLA, the ICO or another party must be notified under applicable legal or contractual requirements.
  • Record the incident, response, outcome and corrective actions.

12. DVLA ADD handling procedure

  • Confirm the request relates to an authorised FleetPro UK customer organisation and a driver belonging to that organisation.
  • Ensure the check is carried out under the customer's documented instructions and that any required driver authority or consent process has been satisfied.
  • Submit only the information required for the authorised DVLA enquiry. DVLA credentials and API secrets must remain within protected server-side systems.
  • Receive the DVLA response into the protected backend. Raw DVLA response data is accessible only to the authorised FleetSmart Consultants administrator for legitimate administration, troubleshooting, security or compliance purposes.
  • Validate that the result is associated with the correct customer organisation and driver.
  • FleetPro UK converts relevant result information into a licence-check report. Customer users are given access to the generated report rather than unrestricted raw DVLA response data.
  • Make the report available only to authenticated and authorised users belonging to the driver's customer organisation. Organisation controls and RLS must prevent cross-organisation access.
  • Retain the DVLA licence-check record in the Supabase database hosted in London for 12 months from the check date.
  • At the end of the retention period, delete or anonymise the record unless a lawful, contractual or documented Controller requirement requires different treatment.

13. DVLA-specific restrictions

  • Raw DVLA response data must not be copied to personal cloud storage, removable media, messaging applications or unapproved systems.
  • Raw data must not be exposed through public endpoints, frontend bundles, public logs, screenshots or support material unless appropriately redacted and legitimately required.
  • Where a licence-check report is downloaded or printed by an authorised customer user, the customer organisation is responsible for securely handling its copy as Data Controller.
  • FleetPro UK is deployed using Vercel infrastructure that may operate across the UK, EU and United States, while the Supabase database holding licence-check records is hosted in London. These arrangements must remain consistent with information supplied to DVLA and applicable UK data-protection requirements.

14. Review

This procedure will be reviewed at least annually and whenever there is a material change to company systems, FleetPro UK data flows, hosting, retention, access-control arrangements, the DVLA ADD integration, or relevant legal or contractual requirements.

Approved by Rhys Hughes on behalf of FleetSmart Consultants — 4 September 2026. Version 2.0.