Defined purpose
Personal information should be collected and used for identified, legitimate and appropriately communicated purposes.
Professionally managed chauffeur and passenger transport for private, corporate, aviation and procurement clients.
Black Fleet London is committed to handling personal information lawfully, fairly, transparently and securely while limiting access and disclosure according to genuine operational need.
This public policy explains our principal data-protection commitments. Detailed system configurations, access controls and security-sensitive procedures are maintained separately.
The purpose of this policy is to establish the principles Black Fleet London applies when collecting, using, sharing, retaining and deleting personal information.
Data protection forms part of booking management, passenger communication, chauffeur allocation, compliance administration, financial processing, client support and corporate governance.
Black Fleet London will seek to process personal information only where there is a defined purpose and an appropriate lawful basis. Personal information should not be collected or disclosed merely because it may be convenient to do so.
Personal information should be collected and used for identified, legitimate and appropriately communicated purposes.
Access should be restricted according to role, responsibility and genuine operational necessity.
Information should be shared only with authorised recipients and only to the extent reasonably required.
Reasonable organisational and technical measures should protect information against unauthorised access, loss or misuse.
Valid data-protection requests should be identified, verified and handled through an appropriate process.
Relevant decisions, policies, contracts and records should support demonstrable accountability.
Black Fleet London applies the UK GDPR principles throughout the collection, use, storage, sharing and deletion of personal information.
Processing should have an appropriate legal basis and should not be misleading, unfair or unnecessarily concealed.
Information should be collected for specified purposes and not reused incompatibly without appropriate consideration.
Information should be adequate, relevant and limited to what is reasonably necessary.
Reasonable steps should be taken to keep material information accurate and correct significant errors.
Personal information should not be retained in identifiable form longer than necessary for its purpose.
Information should be protected through appropriate security and controlled information handling.
The company should be able to demonstrate how data-protection obligations are considered and applied.
Names, telephone numbers, email addresses, company details and relevant contact preferences.
Pick-up and destination details, dates, times, flight information, passenger numbers, luggage and stops.
Booking status, allocation details, communications, journey updates, service notes and incident records.
Transaction references, invoices, payment status and corporate-account administration.
Licensing, vehicle, insurance, identity and supplier information required for lawful operations.
Enquiry submissions, technical information, preferences and relevant website interactions.
Information relating to applicants, workers, contractors, suppliers and business relationships.
Limited accessibility, medical or safeguarding information where necessary to arrange suitable service.
The lawful basis applied will depend on why information is required. Black Fleet London should identify and document an appropriate basis before processing personal information.
Passenger transport requires selected information to be shared with those responsible for service delivery. This does not justify unrestricted access to the complete client or booking record.
Information made available to an operator, chauffeur or supplier should be limited according to role, assignment and operational necessity.
Black Fleet London applies proportionate organisational and technical controls intended to reduce the risk of unauthorised access, accidental loss, improper alteration and unnecessary disclosure.
Security controls are reviewed as systems, risks and operational requirements develop.
Personal information should not be retained indefinitely merely because storage is available. Retention should reflect the original purpose, legal obligations, contractual requirements, dispute periods and legitimate business needs.
Rights apply according to the circumstances and lawful basis involved. Black Fleet London may need to confirm identity and assess whether a legal limitation or exemption applies before responding.
Receive clear information about how and why personal information is used.
Request confirmation and a copy of personal information, subject to applicable requirements.
Request correction of inaccurate or incomplete personal information.
Request deletion where the relevant legal conditions are met.
Request restricted use of information in specified circumstances.
Receive eligible information in a structured format where the right applies.
Object to certain processing, including relevant direct-marketing activity.
Receive protections concerning qualifying solely automated decisions.
Raise concerns with Black Fleet London and, where appropriate, the ICO.
New systems, integrations and operational processes should consider personal-information risks from the beginning rather than attempting to correct avoidable weaknesses after implementation.
Suppliers processing personal information for Black Fleet London should be selected with reasonable regard to capability, confidentiality, security and data-protection responsibilities.
Appropriate contractual terms should define the permitted processing, security expectations, confidentiality, assistance obligations and return or deletion of information.
Where personal information is transferred or made accessible outside the United Kingdom, the company should consider the destination, service provider and applicable transfer mechanism.
International access should not occur merely because a technical service makes it possible.
A personal data breach may involve accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal information.
Raise the suspected incident through the appropriate internal route.
Take reasonable immediate steps to prevent further loss or disclosure.
Identify the information, people, recipients and likely consequences.
Preserve a factual record of the incident and response decisions.
Consider whether notification to the ICO or affected individuals is required.
Identify corrective actions and verify that material weaknesses are addressed.
Employees, contractors, operating partners and suppliers should not delay reporting a suspected breach while attempting to determine independently whether it is serious.
Provides governance oversight, approves the policy and reviews significant data risks, incidents and corrective actions.
Applies controlled information handling across bookings, allocation, communication, access and operational records.
Use information only for authorised purposes, maintain confidentiality and report suspected loss or misuse promptly.
Follow applicable instructions, protect credentials and avoid accessing or sharing information without a genuine need.
Individuals may contact Black Fleet London regarding access, correction, deletion, restriction, objection or another data-protection concern.
Requests should include sufficient information to identify the requester and the relevant relationship or booking. Additional identity verification may be required before personal information is disclosed or changed.
Relevant employees, contractors and operating partners should receive proportionate information about confidentiality, secure access, operational sharing and incident reporting.
Additional guidance may be issued when systems, responsibilities or identified risks change.
This policy should be reviewed at least annually and following material legal, operational, technological or organisational change.
Complaints, incidents, access reviews and operational experience may inform corrective action and future improvements.
This policy describes Black Fleet London’s internal governance principles. The company’s public privacy notice should separately explain what information is collected from individuals, why it is used, how long it may be retained and how rights may be exercised.
Access control, confidentiality, system protection and security-incident response.
Information availability, operational recovery and contingency principles.
Confidentiality and data-handling expectations for suppliers and operators.
Contact Black Fleet London regarding a data-protection request, privacy concern, supplier review or proportionate corporate due-diligence requirement.