Corporate Policy

Data Protection Policy.

Black Fleet London is committed to handling personal information lawfully, fairly, transparently and securely while limiting access and disclosure according to genuine operational need.

This public policy explains our principal data-protection commitments. Detailed system configurations, access controls and security-sensitive procedures are maintained separately.

Data controller Black Fleet London Ltd
Policy owner Director, Black Fleet London Ltd
Review cycle At least annually or following material change
Legal framework UK GDPR and Data Protection Act 2018
Purpose

Personal information protected throughout the operational lifecycle.

The purpose of this policy is to establish the principles Black Fleet London applies when collecting, using, sharing, retaining and deleting personal information.

Data protection forms part of booking management, passenger communication, chauffeur allocation, compliance administration, financial processing, client support and corporate governance.

Scope of this policy

  • Clients, bookers, passengers and prospective customers
  • Employees, applicants, contractors and business contacts
  • Chauffeurs, vehicle owners and operating partners
  • Suppliers, professional advisers and corporate representatives
  • Website, booking, payment and operational-platform information
  • Electronic records and relevant paper-based information
Policy Statement

Privacy managed through lawful purpose, controlled access and accountability.

Black Fleet London will seek to process personal information only where there is a defined purpose and an appropriate lawful basis. Personal information should not be collected or disclosed merely because it may be convenient to do so.

01

Defined purpose

Personal information should be collected and used for identified, legitimate and appropriately communicated purposes.

02

Minimum necessary access

Access should be restricted according to role, responsibility and genuine operational necessity.

03

Controlled disclosure

Information should be shared only with authorised recipients and only to the extent reasonably required.

04

Appropriate security

Reasonable organisational and technical measures should protect information against unauthorised access, loss or misuse.

05

Respect for individual rights

Valid data-protection requests should be identified, verified and handled through an appropriate process.

06

Evidence of compliance

Relevant decisions, policies, contracts and records should support demonstrable accountability.

Data Protection Principles

Seven principles guiding the handling of personal information.

Black Fleet London applies the UK GDPR principles throughout the collection, use, storage, sharing and deletion of personal information.

01 Lawfulness, fairness and transparency

Processing should have an appropriate legal basis and should not be misleading, unfair or unnecessarily concealed.

02 Purpose limitation

Information should be collected for specified purposes and not reused incompatibly without appropriate consideration.

03 Data minimisation

Information should be adequate, relevant and limited to what is reasonably necessary.

04 Accuracy

Reasonable steps should be taken to keep material information accurate and correct significant errors.

05 Storage limitation

Personal information should not be retained in identifiable form longer than necessary for its purpose.

06 Integrity and confidentiality

Information should be protected through appropriate security and controlled information handling.

07 Accountability

The company should be able to demonstrate how data-protection obligations are considered and applied.

Information We May Process

Information connected to journeys, relationships and lawful business administration.

A

Identity and contact details

Names, telephone numbers, email addresses, company details and relevant contact preferences.

B

Journey information

Pick-up and destination details, dates, times, flight information, passenger numbers, luggage and stops.

C

Operational information

Booking status, allocation details, communications, journey updates, service notes and incident records.

D

Payment and account information

Transaction references, invoices, payment status and corporate-account administration.

E

Compliance information

Licensing, vehicle, insurance, identity and supplier information required for lawful operations.

F

Website and enquiry data

Enquiry submissions, technical information, preferences and relevant website interactions.

G

Employment and contracting data

Information relating to applicants, workers, contractors, suppliers and business relationships.

H

Special requirements

Limited accessibility, medical or safeguarding information where necessary to arrange suitable service.

Lawful Processing

Processing based on the purpose and circumstances involved.

The lawful basis applied will depend on why information is required. Black Fleet London should identify and document an appropriate basis before processing personal information.

Contract Processing necessary to quote, book, manage or complete an agreed service.
Legal obligation Processing required to meet applicable legal, regulatory, tax or record-keeping duties.
Legitimate interests Proportionate processing supporting service delivery, security, administration or business protection.
Consent or other basis Consent or another lawful condition may be used where appropriate to the specific activity.
Operational Information Sharing

Only the information reasonably required to perform the assignment.

Passenger transport requires selected information to be shared with those responsible for service delivery. This does not justify unrestricted access to the complete client or booking record.

Information made available to an operator, chauffeur or supplier should be limited according to role, assignment and operational necessity.

Controlled-sharing requirements

  • Share journey information only with authorised recipients
  • Limit contact details to what is required for service delivery
  • Do not disclose the client’s email address to chauffeurs
  • Avoid placing unnecessary personal information in group messages
  • Do not reuse passenger information for unrelated purposes
  • Escalate suspected unauthorised disclosure promptly
Security and Access Control

Access aligned with role, responsibility and operational necessity.

Black Fleet London applies proportionate organisational and technical controls intended to reduce the risk of unauthorised access, accidental loss, improper alteration and unnecessary disclosure.

Security controls are reviewed as systems, risks and operational requirements develop.

Security principles

  • Role-based and authorised access
  • Appropriate authentication and account management
  • Controlled operational information sharing
  • Secure storage and transmission where appropriate
  • Audit and operational records where proportionate
  • Prompt reporting of suspected loss or compromise
  • Access removal following role or relationship changes
Retention and Disposal

Information retained according to purpose, obligation and risk.

Personal information should not be retained indefinitely merely because storage is available. Retention should reflect the original purpose, legal obligations, contractual requirements, dispute periods and legitimate business needs.

Retention considerations

  • The purpose for which the information was collected
  • Legal, tax, regulatory and contractual requirements
  • Potential claims, complaints and dispute-management periods
  • The sensitivity and volume of the information
  • Whether the information remains accurate and necessary
  • Secure deletion, anonymisation or disposal options
Individual Rights

Data-protection requests handled through a controlled process.

Rights apply according to the circumstances and lawful basis involved. Black Fleet London may need to confirm identity and assess whether a legal limitation or exemption applies before responding.

01 Right to be informed

Receive clear information about how and why personal information is used.

02 Right of access

Request confirmation and a copy of personal information, subject to applicable requirements.

03 Right to rectification

Request correction of inaccurate or incomplete personal information.

04 Right to erasure

Request deletion where the relevant legal conditions are met.

05 Right to restrict processing

Request restricted use of information in specified circumstances.

06 Right to data portability

Receive eligible information in a structured format where the right applies.

07 Right to object

Object to certain processing, including relevant direct-marketing activity.

08 Automated decision rights

Receive protections concerning qualifying solely automated decisions.

09 Right to complain

Raise concerns with Black Fleet London and, where appropriate, the ICO.

Data Protection by Design

Privacy considered when systems and workflows are created or changed.

New systems, integrations and operational processes should consider personal-information risks from the beginning rather than attempting to correct avoidable weaknesses after implementation.

Design considerations

  • What information is genuinely required
  • Who needs access and for how long
  • How information will be secured and audited
  • Whether external processors or suppliers are involved
  • How individuals will be informed
  • How requests, corrections and deletion will be handled
  • Whether a formal privacy-risk assessment is required
Suppliers and Processors

External processing subject to appropriate control

Suppliers processing personal information for Black Fleet London should be selected with reasonable regard to capability, confidentiality, security and data-protection responsibilities.

Appropriate contractual terms should define the permitted processing, security expectations, confidentiality, assistance obligations and return or deletion of information.

International Transfers

Transfers outside the United Kingdom assessed before use

Where personal information is transferred or made accessible outside the United Kingdom, the company should consider the destination, service provider and applicable transfer mechanism.

International access should not occur merely because a technical service makes it possible.

Personal Data Breaches

Suspected loss, misuse or disclosure escalated without unnecessary delay.

A personal data breach may involve accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal information.

01 Report

Raise the suspected incident through the appropriate internal route.

02 Contain

Take reasonable immediate steps to prevent further loss or disclosure.

03 Assess

Identify the information, people, recipients and likely consequences.

04 Record

Preserve a factual record of the incident and response decisions.

05 Notify

Consider whether notification to the ICO or affected individuals is required.

06 Improve

Identify corrective actions and verify that material weaknesses are addressed.

Immediate reporting obligation

Employees, contractors, operating partners and suppliers should not delay reporting a suspected breach while attempting to determine independently whether it is serious.

Roles and Responsibilities

Data protection supported by clear operational responsibility.

01 Director

Provides governance oversight, approves the policy and reviews significant data risks, incidents and corrective actions.

02 Operations team

Applies controlled information handling across bookings, allocation, communication, access and operational records.

03 Operating partners and suppliers

Use information only for authorised purposes, maintain confidentiality and report suspected loss or misuse promptly.

04 All authorised users

Follow applicable instructions, protect credentials and avoid accessing or sharing information without a genuine need.

Requests and Concerns

Privacy concerns directed to an appropriate and controlled route.

Individuals may contact Black Fleet London regarding access, correction, deletion, restriction, objection or another data-protection concern.

Requests should include sufficient information to identify the requester and the relevant relationship or booking. Additional identity verification may be required before personal information is disclosed or changed.

Request-handling principles

  • Recognise and record the request promptly
  • Verify identity proportionately
  • Clarify the information or processing involved
  • Protect the rights of other individuals
  • Apply lawful limitations or exemptions where relevant
  • Respond within the applicable legal timeframe
  • Explain complaint and escalation options
Training and Awareness

Privacy responsibilities communicated according to role

Relevant employees, contractors and operating partners should receive proportionate information about confidentiality, secure access, operational sharing and incident reporting.

Additional guidance may be issued when systems, responsibilities or identified risks change.

Monitoring and Review

Controls reviewed against legal and operational change

This policy should be reviewed at least annually and following material legal, operational, technological or organisational change.

Complaints, incidents, access reviews and operational experience may inform corrective action and future improvements.

Relationship with the privacy notice

This policy describes Black Fleet London’s internal governance principles. The company’s public privacy notice should separately explain what information is collected from individuals, why it is used, how long it may be retained and how rights may be exercised.

Related Governance

Data protection supported by connected controls.

RELATED

Information Security Policy

Access control, confidentiality, system protection and security-incident response.

RELATED

Business Continuity Policy

Information availability, operational recovery and contingency principles.

RELATED

Supplier Code of Conduct

Confidentiality and data-handling expectations for suppliers and operators.

Privacy and Corporate Due Diligence

Need data-protection or privacy information?

Contact Black Fleet London regarding a data-protection request, privacy concern, supplier review or proportionate corporate due-diligence requirement.