Privacy Policy
Last updated: now · GVL Compliance App
Guardian Vehicle Logistics Ltd (“GVL Recovery”, “we”, “us”) is committed to protecting the privacy of everyone who uses the GVL Compliance App. This notice explains what personal data we collect, why we collect it, how we use it, who we share it with, and the rights you have under UK data protection law.
1. Who we are
Guardian Vehicle Logistics Ltd is a company registered in England and Wales, trading as GVL Recovery. We are the data controller for personal data processed through the GVL Compliance App. You can contact our compliance team about this notice or any data protection matter at compliance@gvlogistics.net.
2. What personal data we collect
The GVL Compliance App processes the following categories of personal data:
- Identity and account data — your full name, business email address, the organisation (subcontractor or internal) you are linked to, the role you have been granted (Driver, Principal or Admin), and your sign-in history.
- Authentication data — sign-in events provided by Microsoft Entra ID (formerly Azure Active Directory). We do not see or store your Microsoft password; Microsoft confirms your identity to us and provides a secure token.
- Compliance check data — walkaround check responses, defect notes, odometer readings, vehicle registration numbers, signatures, and any photographs you submit as part of an inspection.
- Location data — if you use the Clock in/out feature (used by PAYE drivers for overtime tracking), the app records the GPS coordinates of your device at the moment of clock-in or clock-out. This is used only to confirm that you are physically at the GVL Recovery yard. We do not track your continuous location.
- Standard Operating Procedure (SOP) acceptance — the date and time at which you accepted the GVL Recovery Standard Operating Procedure.
- Technical data — standard server logs (IP address, browser type, time of request) generated automatically when you use the app.
3. Why we collect it — lawful basis
We process your personal data under the following lawful bases set out in UK GDPR Article 6:
- Legitimate interests (Article 6(1)(f)) — the operation of the GVL Compliance App is necessary for our legitimate interest in meeting our obligations as an operator licence holder, demonstrating DVSA roadworthiness compliance for our fleet and our subcontractor fleet, evidencing driver walkaround checks, managing defect rectification, and protecting the safety of the public and road users.
- Legal obligation (Article 6(1)(c)) — we are required to keep records of vehicle inspections and defect rectifications under DVSA Guide to Maintaining Roadworthiness and as a condition of our operator licence.
- Contract (Article 6(1)(b)) — where you are a PAYE driver, processing your clock-in/out data is necessary to calculate hours worked and pay you correctly under your contract of employment.
4. Who we share your data with
We do not sell your personal data and we do not share it with third parties for marketing purposes. We share limited data only with the following categories of recipient, and only where necessary:
- Microsoft Corporation — as our identity provider (Microsoft Entra ID) and cloud hosting provider (Microsoft Azure, UK South region). Microsoft is ISO/IEC 27001 certified. Data processed by Microsoft on our behalf is governed by their Data Processing Addendum.
- The Driver and Vehicle Standards Agency (DVSA), the Office of the Traffic Commissioner, or other regulators — if requested as part of an audit, formal investigation or as required by law.
- Your subcontractor company — if you are a driver employed or sub-contracted by a Principal organisation, that Principal can see check records and defect records that you have submitted while operating their vehicle. They cannot see records you submit for any other organisation.
- Our internal compliance team — named members of Guardian Vehicle Logistics Ltd staff (currently the Managing Director, Compliance Department and Finance Department) have access to all records for the purpose of running the operator licence.
5. How long we keep your data
- Walkaround check records, defect records and SOP acceptance records — retained for a minimum of 15 months from creation, in line with DVSA Guide to Maintaining Roadworthiness. We typically retain for longer (up to 7 years) to support insurance, contract and regulatory enquiries.
- Clock-in / clock-out records and overtime calculations — retained for 7 years in line with HMRC payroll record-keeping requirements.
- User account data — retained for as long as you are an active driver, Principal or staff member, and for a reasonable period afterwards (typically 24 months) so that completed compliance records remain attributable.
- Server access logs — retained for up to 90 days for security and operational monitoring.
6. Where your data is stored
All data is stored on Microsoft Azure infrastructure located in the United Kingdom (UK South region). Microsoft Azure is ISO/IEC 27001 certified. Photographs are stored in Azure Blob Storage with private access; database records are stored in Azure SQL Database with encryption at rest and in transit.
7. Your rights
Under UK GDPR, you have the right to:
- access the personal data we hold about you (subject access request);
- have inaccurate personal data corrected;
- have your personal data erased in certain circumstances (note: this right does not override our regulatory obligation to retain compliance records under our operator licence);
- restrict or object to certain processing;
- data portability where applicable;
- withdraw consent where we rely on consent (note: we generally do not rely on consent — see “Lawful basis” above).
To exercise any of these rights, please contact us at compliance@gvlogistics.net. We will respond within one month of receiving your request.
8. Cookies and tracking
The GVL Compliance App uses only essential cookies necessary for sign-in security (session cookies issued by our server and by Microsoft Entra ID). We do not use advertising cookies, third-party analytics or social-media tracking on this application.
9. Security
We protect your data using industry-standard measures: encrypted transit (HTTPS / TLS), encryption at rest on Azure, role-based access control, multi-factor authentication enforced via Microsoft Entra ID, and least-privilege access for our staff. No system is ever 100% secure, but we take our obligations seriously and review our controls regularly.
10. Complaints
If you are not satisfied with how we handle your personal data, please contact us in the first instance at compliance@gvlogistics.net. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s data protection regulator:
Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Web: ico.org.uk
11. Changes to this notice
We may update this privacy notice from time to time. Any material changes will be highlighted to you the next time you sign in. The “Last updated” date at the top of this page shows when it was last revised.
© 2026 Guardian Vehicle Logistics Ltd. All rights reserved.