Corporate Chauffeurs · United Kingdom
Data protection and UK GDPR
This document sets out the internal framework behind our privacy policy: how data protection obligations are applied day to day, from the moment an enquiry arrives to the point a booking record is deleted. It is written for clients who need to understand our approach, and for anyone working on our behalf. It was last reviewed on 27 August 2026.
Section 01
1. Purpose and scope
This framework applies to all personal data processed in connection with chauffeur services, including enquiries, bookings, journey records, payment records and correspondence. It applies to everyone acting on our behalf, including chauffeurs, office staff, contractors and partner operators carrying out a journey under our booking.
Section 02
2. The legal framework we work within
Our obligations arise under the UK General Data Protection Regulation and the Data Protection Act 2018, together with the Privacy and Electronic Communications Regulations for cookies and electronic marketing. The controller for this processing is [To be supplied], and our registration with the Information Commissioner's Office is [To be supplied]. Where a value shows as a placeholder, it has not yet been published on this site.
Section 03
3. Controller and processor roles
For most bookings we act as controller: we decide what data is collected and why, whether the booking comes from an individual, an assistant or a travel manager. Where a corporate client instructs us to process data in a defined way as part of their own travel programme, we may act as processor for that element. The role is agreed in writing at the outset so responsibilities are not left ambiguous.
Section 04
4. The principles we apply
The data protection principles are applied to practical decisions about bookings rather than treated as an abstract checklist. In a chauffeur context that means asking a simple question before recording anything: does the chauffeur or the office actually need this to deliver the journey? Collect only what a quotation or journey genuinely requires Use it for the purpose it was given and no other, unless there is a lawful basis to do so Keep it accurate, and correct addresses, numbers and flight details as soon as we are told Give chauffeurs the details for their own journey, not access to the wider client record Keep it no longer than the booking, accounting and complaint window requires Protect it in transit and at rest, and be able to show how that is done
Section 05
5. Lawful bases in practice
Delivering a confirmed booking is processed on the basis of contract. Retaining invoices and accounting records is a legal obligation. Investigating a complaint, defending a claim and preventing fraud rest on legitimate interests. Optional marketing relies on consent, which is recorded and can be withdrawn at any time. Where legitimate interests are relied on, the balance against the individual's rights is considered rather than assumed.
Section 06
6. Sensitive information
Journeys sometimes involve information about health, mobility or religion, for example where a passenger needs a wheelchair-accessible arrangement or a particular travel arrangement. Such information is recorded only where the journey requires it, in the least detailed form that works, and is passed only to the chauffeur delivering the journey. Passengers are never required to explain a diagnosis in order to travel.
Section 07
7. Chauffeurs and staff
Anyone handling passenger data on our behalf is expected to keep it confidential, use it only for the journey in hand and avoid discussing passengers, destinations or itineraries outside the operational context. Passenger details are not retained on personal devices beyond the period needed for the journey, and are not shared into personal messaging groups or social media in any form.
Section 08
8. Suppliers and subcontracted journeys
Where a journey is carried out by a partner operator, only the details needed to complete that journey are passed on, under an arrangement that obliges them to protect it and use it for nothing else. Technology suppliers who host the website, messaging or booking records are engaged on written terms that address confidentiality, security and the return or deletion of data at the end of the engagement.
Section 09
9. Security measures
Access to booking systems is limited to those who need it, protected by individual accounts and, where the platform supports it, additional authentication. Devices used for booking work are kept up to date and protected. Paper notes taken during a busy day are treated as records too, and are destroyed rather than left in a vehicle or an office tray.
Section 10
10. Personal data breaches
A breach includes loss of a device holding passenger details, sending a booking record to the wrong recipient, or unauthorised access to an account, not just a large-scale technical incident. Anyone who becomes aware of a suspected breach is expected to report it internally straight away so it can be contained and assessed. Where a breach is likely to result in a risk to individuals, it is reported to the Information Commissioner's Office within the statutory timeframe, and affected individuals are told where the risk to them is high.
Section 11
11. Handling data subject requests
Requests to access, correct, delete or restrict personal data are logged when they arrive and answered within one month, with an extension used only where a request is genuinely complex. Requests should be sent to [To be supplied] or raised through the contact page, marked for the attention of [To be supplied]. We may need to confirm identity before releasing information, particularly where a booking was made by a third party.
Section 12
12. Retention and deletion
Retention is driven by purpose. Journey records are held while a query or claim remains realistically possible, financial records for the statutory period, and unsuccessful enquiries for a short window only. When a record reaches the end of its retention period it is deleted or securely destroyed, including copies held in message threads and backups, as far as the systems in use allow.
Section 13
13. Review of this framework
This framework is reviewed as systems, suppliers and services change, and the current edition was last reviewed on 27 August 2026. Clients with their own supplier assurance requirements can request further detail about how a specific element is handled, and we will provide what we can in writing.
Section 14
Related legal documents
These documents are read together. Where one document conflicts with another, the document that deals most specifically with the subject applies to that subject.
Section 15
Questions about this document
If any part of this document is unclear, raise it before you confirm a booking rather than afterwards. Journey-specific requirements are agreed in the written quotation and confirmation, which take precedence over general guidance on this page.