Corporate Policy

Information Security Policy.

Black Fleet London is committed to protecting the confidentiality, integrity and availability of information used to manage passenger journeys, commercial relationships and essential business operations.

This public policy summarises our information-security principles. Detailed technical configurations, system architecture, credentials, recovery locations and security-sensitive procedures are not published.

Policy owner Director, Black Fleet London Ltd
Applies to Users, systems, suppliers and operational information
Review cycle At least annually or following material change
Policy status Approved corporate framework
Purpose

Protecting information required for safe and dependable operations.

The purpose of this policy is to establish the principles Black Fleet London applies to protect information, accounts, systems, devices and communications against unauthorised access, misuse, loss, alteration and avoidable interruption.

Information security supports passenger confidentiality, operational continuity, financial control, supplier governance and compliance with applicable data-protection obligations.

Scope of this policy

  • Booking, quotation, client and passenger information
  • Chauffeur, vehicle, compliance and supplier records
  • Financial, invoicing and payment-status information
  • Email, messaging, websites and operational platforms
  • Company-owned and authorised personal devices
  • Employees, contractors, operating partners and suppliers
  • Electronic records and relevant paper-based information
Policy Statement

Security proportionate to information, operations and risk.

Black Fleet London seeks to maintain appropriate organisational and technical controls reflecting the nature of its information, the services being delivered and the potential consequences of loss, misuse or operational interruption.

01

Authorised access

Information and systems should be accessed only by authorised users with a genuine operational or business requirement.

02

Least necessary privilege

Access should be limited to the minimum functionality and information reasonably required for the user’s role.

03

Secure information handling

Information should be stored, transmitted and disclosed using proportionate safeguards and approved workflows.

04

Operational resilience

Essential information and systems should be recoverable through proportionate continuity and backup arrangements.

05

Prompt incident reporting

Suspected compromise, phishing, loss or unauthorised access should be escalated without unnecessary delay.

06

Continuing improvement

Security controls should develop in response to incidents, system changes, threats and operational experience.

Security Principles

Eight principles guiding information-security decisions.

01 Confidentiality

Information should be available only to authorised individuals and organisations with a legitimate need.

02 Integrity

Information should remain accurate, complete and protected from unauthorised or accidental alteration.

03 Availability

Essential information and systems should remain accessible to authorised users when operationally required.

04 Authentication

Users should demonstrate their identity before accessing protected accounts, systems or records.

05 Least privilege

Users should receive only the access necessary to perform their authorised responsibilities.

06 Defence in depth

Security should not depend on one control where additional proportionate protection is reasonably available.

07 Secure by design

Security should be considered when systems and workflows are introduced, changed or integrated.

08 Accountability

Material access, decisions and incidents should remain attributable and appropriately recorded.

Information and Asset Management

Protecting the systems, devices and information the operation depends on.

Black Fleet London should maintain reasonable visibility of important information assets, accounts, devices, platforms and suppliers supporting essential business activity.

A

Operational platforms

Booking, quotation, allocation, compliance, finance and journey-status systems supporting service delivery.

B

User accounts

Administrative, operator, driver, client, email, payment and supplier accounts used for business activity.

C

Devices

Computers, phones, tablets and other authorised devices used to access company information.

D

Communications

Email, telephone, messaging and notification channels used for operational and corporate communication.

E

Business records

Client, passenger, journey, compliance, supplier, finance and audit records.

F

Websites and domains

Public websites, booking pages, domain records and associated administrative services.

G

External services

Hosting, cloud, payment, communications and professional services used by the company.

H

Credentials and recovery data

Passwords, authentication methods, recovery details and other sensitive access information.

Access Control

Access based on role, approval and operational necessity.

Accounts and permissions should be issued deliberately, reviewed when responsibilities change and removed when they are no longer required.

Individual accounts Shared access should be avoided where individual accountability is reasonably achievable.
Strong authentication Important systems should use appropriate passwords and additional authentication where available.
Role-based access Users should access only the information and functions required for their authorised role.
Prompt removal Access should be changed or removed following departure, role change or loss of operational need.
Account and Credential Security

Credentials treated as confidential security information.

Passwords, authentication codes, recovery information and administrative credentials must not be disclosed to unauthorised individuals.

Users should report suspected credential compromise immediately rather than waiting for evidence that an account has been misused.

Credential expectations

  • Use strong and suitably unique passwords
  • Use multi-factor authentication where available and appropriate
  • Do not share passwords or authentication codes
  • Do not approve unexpected login requests
  • Protect password-manager and account-recovery access
  • Change credentials following suspected compromise
  • Remove dormant or unnecessary accounts
Device and Software Security

Devices protected throughout their operational use.

Devices accessing company information should be maintained with reasonable safeguards against theft, unauthorised access, malware and avoidable software vulnerabilities.

Personal devices used for authorised business activity remain subject to appropriate confidentiality and security expectations.

Device-security expectations

  • Device passcodes, passwords or biometric protection
  • Current supported operating systems and security updates
  • Approved software and applications
  • Automatic screen locking where appropriate
  • Protection against loss, theft and unauthorised physical access
  • Prompt reporting of missing or compromised devices
  • Secure removal of company information when access ends
Email, Messaging and Phishing

Unexpected requests verified before sensitive action is taken.

Fraudulent emails, messages, websites and calls may attempt to obtain credentials, personal information, payments or unauthorised changes to operational records.

01

Verify unusual requests

Sensitive, urgent or unexpected instructions should be verified through a trusted and independent contact route.

02

Inspect links and senders

Users should consider the sender, destination, context and language before opening links or attachments.

03

Protect authentication codes

Passwords and authentication codes should never be supplied in response to an unsolicited request.

04

Verify payment changes

New bank details or urgent financial instructions should be checked through an established contact route.

05

Report suspicious activity

Suspected phishing or impersonation should be reported promptly even where no information appears to have been disclosed.

06

Contain mistakes quickly

Users who have clicked, downloaded or disclosed information should report the event immediately rather than concealing it.

Secure Information Sharing

Information shared according to assignment and recipient.

Operational information should be issued only to authorised recipients and should be limited to what is reasonably required to perform the relevant journey or business activity.

Confidential information should not be placed into group communications or informal channels without considering who can access, copy or retain it.

Information-sharing controls

  • Confirm the recipient before sending sensitive information
  • Share only information required for the authorised purpose
  • Do not disclose client email addresses to chauffeurs
  • Avoid unnecessary passenger data in group messages
  • Use approved systems and communication channels
  • Report accidental disclosure promptly
  • Do not reuse operational information for unrelated purposes
Backup and Recovery

Essential information recoverable after disruption

Important information should be supported by proportionate backup, recovery or replication arrangements reflecting its operational value, availability requirements and the consequences of loss.

Recovery arrangements should be reviewed and, where appropriate, tested so the existence of a backup is not confused with the ability to restore it.

Continuity

Alternative operating arrangements during system interruption

Where normal systems are unavailable, authorised personnel may use controlled temporary records and alternative communication methods to protect imminent and time-critical journeys.

Temporary information should be transferred securely into the normal operating record when systems are restored.

Suppliers and External Services

External access remains subject to security and confidentiality requirements.

Suppliers, licensed private hire operators and technology providers may receive or access information required to provide an authorised service.

External involvement does not remove the need for appropriate selection, contractual protection, access limitation and incident-reporting arrangements.

Supplier-security considerations

  • Nature and sensitivity of information involved
  • Access required to deliver the agreed service
  • Confidentiality and data-protection obligations
  • Account and permission management
  • Security and breach-reporting expectations
  • Business-continuity and recovery arrangements
  • Return or deletion of information when services end
Security Incident Management

Suspected incidents contained, assessed and recovered through a controlled process.

An information-security incident may include unauthorised access, malware, phishing, account compromise, data loss, device theft, service interruption or accidental disclosure.

01 Report

Raise the suspected incident through the appropriate internal route.

02 Contain

Take reasonable immediate action to prevent further access, loss or spread.

03 Assess

Identify affected accounts, systems, information and operational services.

04 Recover

Restore trusted access and essential functionality using approved measures.

05 Communicate

Notify relevant parties or authorities where required and appropriate.

06 Improve

Record lessons, corrective action and any required policy or system changes.

Do not conceal security mistakes

Employees, contractors, operating partners and suppliers should report suspected compromise promptly. Early reporting may significantly reduce passenger, operational, financial and reputational consequences.

Personal Data Breaches

Security incidents assessed for data-protection consequences.

Where an incident affects personal information, Black Fleet London should assess whether it constitutes a personal data breach and whether legal notification or communication obligations apply.

Information-security response and data-protection response should be coordinated rather than treated as unrelated processes.

Assessment considerations

  • Nature and sensitivity of affected information
  • Number and categories of individuals involved
  • Whether information was accessed, altered or disclosed
  • Likelihood and severity of harm
  • Effectiveness of containment measures
  • Contractual or regulatory notification requirements
Roles and Responsibilities

Information security supported by clear accountability.

01 Director

Provides governance oversight, approves the policy and reviews significant security risks, incidents and corrective actions.

02 Administrators and operations

Manage authorised access, operational records, system workflows, escalation and appropriate information sharing.

03 Suppliers and operating partners

Protect information received for authorised services and report suspected loss, misuse or compromise promptly.

04 All authorised users

Protect credentials and devices, follow applicable instructions and avoid accessing or sharing information without a legitimate need.

Awareness and Responsible Behaviour

Security depends on systems, controls and informed users.

Relevant users should receive proportionate guidance concerning the systems, information and security risks connected to their responsibilities.

Awareness should be refreshed when threats, systems or operational processes materially change.

Awareness topics may include

  • Passwords and multi-factor authentication
  • Phishing, impersonation and payment fraud
  • Secure passenger-information handling
  • Device loss and account compromise
  • Suspicious links, files and software
  • Incident reporting and containment
  • Remote working and public-network risks
Monitoring and Records

Security activity reviewed proportionately

Black Fleet London may maintain and review access records, account changes, operational audit histories, incident records and system alerts where proportionate and lawful.

Monitoring should support security, accountability, service continuity and investigation rather than unjustified surveillance.

Policy Review

Controls developed alongside systems and risk

This policy should be reviewed at least annually and following a material cyber incident, significant system change, new technology integration or identified weakness.

Relevant procedures and access arrangements should be updated where the review identifies a proportionate need.

No claim of absolute security

Information-security controls reduce risk but cannot eliminate every threat or guarantee that incidents will never occur. Black Fleet London therefore combines preventive controls with reporting, containment, recovery and continuous improvement.

Related Governance

Information security supported by connected controls.

RELATED

Data Protection Policy

Lawful processing, privacy rights, data minimisation and personal-data breach management.

RELATED

Business Continuity Policy

Operational recovery, alternative working and service-continuity principles.

RELATED

Supplier Code of Conduct

Security, confidentiality and incident-reporting expectations for suppliers and operators.

Security and Corporate Due Diligence

Need further information-security information?

Corporate clients and prospective partners may contact Black Fleet London to discuss information-security requirements, supplier onboarding or proportionate supporting evidence.