Authorised access
Information and systems should be accessed only by authorised users with a genuine operational or business requirement.
Professionally managed chauffeur and passenger transport for private, corporate, aviation and procurement clients.
Black Fleet London is committed to protecting the confidentiality, integrity and availability of information used to manage passenger journeys, commercial relationships and essential business operations.
This public policy summarises our information-security principles. Detailed technical configurations, system architecture, credentials, recovery locations and security-sensitive procedures are not published.
The purpose of this policy is to establish the principles Black Fleet London applies to protect information, accounts, systems, devices and communications against unauthorised access, misuse, loss, alteration and avoidable interruption.
Information security supports passenger confidentiality, operational continuity, financial control, supplier governance and compliance with applicable data-protection obligations.
Black Fleet London seeks to maintain appropriate organisational and technical controls reflecting the nature of its information, the services being delivered and the potential consequences of loss, misuse or operational interruption.
Information and systems should be accessed only by authorised users with a genuine operational or business requirement.
Access should be limited to the minimum functionality and information reasonably required for the user’s role.
Information should be stored, transmitted and disclosed using proportionate safeguards and approved workflows.
Essential information and systems should be recoverable through proportionate continuity and backup arrangements.
Suspected compromise, phishing, loss or unauthorised access should be escalated without unnecessary delay.
Security controls should develop in response to incidents, system changes, threats and operational experience.
Information should be available only to authorised individuals and organisations with a legitimate need.
Information should remain accurate, complete and protected from unauthorised or accidental alteration.
Essential information and systems should remain accessible to authorised users when operationally required.
Users should demonstrate their identity before accessing protected accounts, systems or records.
Users should receive only the access necessary to perform their authorised responsibilities.
Security should not depend on one control where additional proportionate protection is reasonably available.
Security should be considered when systems and workflows are introduced, changed or integrated.
Material access, decisions and incidents should remain attributable and appropriately recorded.
Black Fleet London should maintain reasonable visibility of important information assets, accounts, devices, platforms and suppliers supporting essential business activity.
Booking, quotation, allocation, compliance, finance and journey-status systems supporting service delivery.
Administrative, operator, driver, client, email, payment and supplier accounts used for business activity.
Computers, phones, tablets and other authorised devices used to access company information.
Email, telephone, messaging and notification channels used for operational and corporate communication.
Client, passenger, journey, compliance, supplier, finance and audit records.
Public websites, booking pages, domain records and associated administrative services.
Hosting, cloud, payment, communications and professional services used by the company.
Passwords, authentication methods, recovery details and other sensitive access information.
Accounts and permissions should be issued deliberately, reviewed when responsibilities change and removed when they are no longer required.
Passwords, authentication codes, recovery information and administrative credentials must not be disclosed to unauthorised individuals.
Users should report suspected credential compromise immediately rather than waiting for evidence that an account has been misused.
Devices accessing company information should be maintained with reasonable safeguards against theft, unauthorised access, malware and avoidable software vulnerabilities.
Personal devices used for authorised business activity remain subject to appropriate confidentiality and security expectations.
Fraudulent emails, messages, websites and calls may attempt to obtain credentials, personal information, payments or unauthorised changes to operational records.
Sensitive, urgent or unexpected instructions should be verified through a trusted and independent contact route.
Users should consider the sender, destination, context and language before opening links or attachments.
Passwords and authentication codes should never be supplied in response to an unsolicited request.
New bank details or urgent financial instructions should be checked through an established contact route.
Suspected phishing or impersonation should be reported promptly even where no information appears to have been disclosed.
Users who have clicked, downloaded or disclosed information should report the event immediately rather than concealing it.
Operational information should be issued only to authorised recipients and should be limited to what is reasonably required to perform the relevant journey or business activity.
Confidential information should not be placed into group communications or informal channels without considering who can access, copy or retain it.
Important information should be supported by proportionate backup, recovery or replication arrangements reflecting its operational value, availability requirements and the consequences of loss.
Recovery arrangements should be reviewed and, where appropriate, tested so the existence of a backup is not confused with the ability to restore it.
Where normal systems are unavailable, authorised personnel may use controlled temporary records and alternative communication methods to protect imminent and time-critical journeys.
Temporary information should be transferred securely into the normal operating record when systems are restored.
Suppliers, licensed private hire operators and technology providers may receive or access information required to provide an authorised service.
External involvement does not remove the need for appropriate selection, contractual protection, access limitation and incident-reporting arrangements.
An information-security incident may include unauthorised access, malware, phishing, account compromise, data loss, device theft, service interruption or accidental disclosure.
Raise the suspected incident through the appropriate internal route.
Take reasonable immediate action to prevent further access, loss or spread.
Identify affected accounts, systems, information and operational services.
Restore trusted access and essential functionality using approved measures.
Notify relevant parties or authorities where required and appropriate.
Record lessons, corrective action and any required policy or system changes.
Employees, contractors, operating partners and suppliers should report suspected compromise promptly. Early reporting may significantly reduce passenger, operational, financial and reputational consequences.
Where an incident affects personal information, Black Fleet London should assess whether it constitutes a personal data breach and whether legal notification or communication obligations apply.
Information-security response and data-protection response should be coordinated rather than treated as unrelated processes.
Provides governance oversight, approves the policy and reviews significant security risks, incidents and corrective actions.
Manage authorised access, operational records, system workflows, escalation and appropriate information sharing.
Protect information received for authorised services and report suspected loss, misuse or compromise promptly.
Protect credentials and devices, follow applicable instructions and avoid accessing or sharing information without a legitimate need.
Relevant users should receive proportionate guidance concerning the systems, information and security risks connected to their responsibilities.
Awareness should be refreshed when threats, systems or operational processes materially change.
Black Fleet London may maintain and review access records, account changes, operational audit histories, incident records and system alerts where proportionate and lawful.
Monitoring should support security, accountability, service continuity and investigation rather than unjustified surveillance.
This policy should be reviewed at least annually and following a material cyber incident, significant system change, new technology integration or identified weakness.
Relevant procedures and access arrangements should be updated where the review identifies a proportionate need.
Information-security controls reduce risk but cannot eliminate every threat or guarantee that incidents will never occur. Black Fleet London therefore combines preventive controls with reporting, containment, recovery and continuous improvement.
Lawful processing, privacy rights, data minimisation and personal-data breach management.
Operational recovery, alternative working and service-continuity principles.
Security, confidentiality and incident-reporting expectations for suppliers and operators.
Corporate clients and prospective partners may contact Black Fleet London to discuss information-security requirements, supplier onboarding or proportionate supporting evidence.