Skip to main content
TRAKCORP Asset & Fleet Tracking
Operations manual 01 of 03

Privacy notice

  • In force from 7 August 2026
  • Issue 1
  • TRAKCORP LTD, company 17005499
  • Territory: United Kingdom

1. Scope of this manual, and who issues it

Terms used in this section

The company
TRAKCORP LTD, carrying company number 17005499 on the register for England and Wales.
This manual
The document you are reading. It sets down standing procedure, not intentions.
Operator
A business running vehicles, trailers, plant or tools that has put them on the platform.
You
Whoever is reading: a visitor, a contact at an operator, somebody signed in, or a driver of a tracked vehicle.

The office filed against that company number is where formal papers are served on us. Nobody sits in it waiting for callers, and anything posted there reaches the work slower than email does.

Three separate things fall inside this manual, and the right answer usually turns on which of them is being asked about. First, the paperwork the company keeps in order to run itself: enquiries, invoices, supplier files. Second, the tracking record held inside the platform on an operator's behalf. Third, any iOS or Android application issued under the TRAKCORP name, which sits on top of that same record.

The rulebook underneath is the UK General Data Protection Regulation, held in force by section 3 of the European Union (Withdrawal) Act 2018, read alongside the Data Protection Act 2018 and PECR, the Privacy and Electronic Communications Regulations 2003. Where a procedure below cites the UK GDPR, that is the instrument meant.

How to read this manual. Every procedure below is written as standing procedure: what happens to a record, who touches it, how long it is held and what you may demand about it. Nothing here is aspiration. Where a procedure names a component you do not use, it simply does not reach you.

2. Which hat we are wearing

Terms used in this section

Controller
Whoever settles the reason a record exists and the means by which it is kept.
Processor
Whoever holds and works that record under written instruction from the controller.
Tracking data
Position reports, journeys, geofence events and the driver assignments attached to them.

TRAKCORP wears two hats. Nearly every procedure in this manual runs differently depending on which one is on at the time, so each section from here carries a marker saying which.

2.1 Wearing the controller hat

We settle the purpose and the means ourselves for records about people dealing with TRAKCORP as a business: anyone writing to hello@trakcorp.uk, contacts at operators talking through an evaluation, account administrators, suppliers, and anybody corresponding with us over a legal matter. The duty in those cases runs from us straight to you, and section 10 is the counter you come to.

2.2 Wearing the processor hat

Tracking data inside the platform belongs to the operator that collected it. That operator picks which assets carry a unit, fixes the reason, decides who in its own business may open the record, and chooses a history window from the range we support. TRAKCORP writes the software, runs the servers and keeps the record intact. Nothing beyond that is ours to decide.

Drivers should read that twice. Where the van you drive carries a unit, the business that fitted it is almost always the controller of where you have been, and TRAKCORP is not. Paragraph 10.11 sets out what happens when you write to us anyway.

2.3 The paperwork behind the processor hat

Processing terms answering Article 28 are signed before a single position report is accepted from an operator. They fix subject matter and duration, the nature and purpose of the work, the categories of record and of individual, our confidentiality duty, the Article 32 safeguards, the conditions attaching to any supplier we bring in, the help we owe on individual requests and on Articles 32 to 36, what happens to the record at the end, and the information an audit may call for. Those terms sit beside the terms of service, and on any matter they cover they outrank this manual.

2.4 Standing prohibitions

Personal data is never sold. One operator's record is never mixed into another's, never mined to build a feature for a competitor, and never put to advertising use. Load figures used to size the servers count vehicles, requests and errors, never people.

3. Standing inventory A: the company's own files

Hat worn here: controller

Everything the company holds in its own right is listed below, with the ground relied on and its article against each line. Nothing about a person is held outside this list.

Inventory A, in force 7 August 2026
File What sits on it How it reaches us Why it is held Ground Retention Who else touches it
Correspondence Name, email, employer, job title, what you wrote, when it landed Sent by you Reading it, answering it, remembering the thread later Art. 6(1)(f). Interest: an address published for correspondence cannot work unless the post is read and kept 24 months after the last message Mail supplier
Operator enquiries Contact name and email, business, fleet size, asset mix, kit already fitted, depot list Sent by you on the enquiry form of words Judging whether your kit and your operation fit the platform, and answering you Art. 6(1)(f). Interest: carrying forward a conversation you started 24 months after the last exchange, or sooner if you ask Mail supplier
Administrator logins Name, work email, telephone, role, permission set, sign-in stamps, hashed password Opened by the operator, or by the person Issuing and securing a way into the platform Art. 6(1)(b) where the person is our counterparty, else Art. 6(1)(f). Interest: running a business account Term of the agreement, then 12 months Hosting and mail suppliers
Invoicing Billing contact and address, VAT number, invoice lines, sums, payment dates, last four digits of a card The operator, and the payment supplier Raising invoices, chasing them, filing statutory accounts Art. 6(1)(b) for the payment itself. Art. 6(1)(c) for the accounting file, under the Companies Act 2006 and the Value Added Tax Act 1994 Six years, see section 7 Payment supplier, accountant, HMRC where owed
Fault reports Name, email, account reference, the symptom described, any log or screenshot attached You or a colleague Finding the fault and clearing it Art. 6(1)(b) where support is owed under an agreement, else Art. 6(1)(f). Interest: keeping a fault route open 36 months after the ticket closes Hosting and mail suppliers
Edge logs Shortened IP, path requested, status code, user agent, referrer, stamp Your browser, through the network fronting this site Serving pages, turning away abuse, chasing an error Art. 6(1)(f). Interest: holding a public site up and defending it against automated traffic Supplier's own window, see section 7 Cloudflare, Inc.
Supplier and legal files Business contact details, contract correspondence, anything inside a claim, complaint or regulator enquiry The supplier, you, a regulator, a third party Buying goods and services; running and defending a legal matter Art. 6(1)(b) or Art. 6(1)(f) for suppliers. Art. 6(1)(c) where a statute compels, else Art. 6(1)(f), interest: defending claims. Art. 9(2)(f) for any special category material inside a claim Six years from the end of the contract or the matter, longer while a limitation period runs Accountant, mail supplier, legal advisers, insurers, a court or the ICO

This table scrolls sideways on narrow screens.

There is no marketing list behind this inventory. Contact data is never bought in, and no line above feeds advertising of any kind. Should that ever change, the table changes first.

4. Standing inventory B: what arrives through the platform

Hat worn here: processor, operator holds the controller hat

These categories reach us because an operator put them on the platform. The purpose behind each is the operator's, and so is the ground. We name the ground an operator ordinarily relies on because drivers deserve to see it written down, but it is not ours to pick and not ours to defend.

Inventory B, in force 7 August 2026
Record What sits on it How it reaches us Operator's purpose Ground the operator usually relies on Retention Who else touches it
Position reports Unit ID, UTC stamp, latitude, longitude, speed, heading, satellite count, HDOP, ignition state, supply voltage Telematics units and battery tags Knowing where an asset stands and where it has been Art. 6(1)(f). Interest: protecting the operator's own plant and checking work billed for. Some rely instead on Art. 6(1)(b) or 6(1)(c) Operator's setting. Default 24 months, floor 3 months That operator's users, hosting supplier
Journeys Start and finish stamp and position, route line, distance, duration, idle time, asset and driver attached Stitched by us out of position reports Settling questions about attendance, delivery, hours run and utilisation As above Follows the position report setting That operator's users, hosting supplier
Geofence events Boundary and asset ID, arrival or departure, stamp, time spent inside Worked out from positions against boundaries the operator drew Logging arrival and departure at depots, sites and customer premises As above Follows the position report setting That operator's users, anything wired in by API or webhook, hosting supplier
Driver records Name or reference, which asset the person is paired to, shift pattern, driver ID token Keyed in by the operator Tying a journey to the person who ran it Art. 6(1)(f), or Art. 6(1)(b) under the employment contract, as the operator settles it Operator's setting, cleared when the account closes That operator's users, hosting supplier
Platform logins Name, work email, hashed password, role, last sign-in, session IDs The operator, or the user Governing who may open which asset and how far back Art. 6(1)(b) between operator and user, or Art. 6(1)(f) in access control Cleared when the account closes, section 14 Hosting and mail suppliers
Access log User ID, action taken, record opened or exported, stamp, source IP Written by the platform itself Showing who opened a journey record, and who took a copy away Art. 6(1)(f). Interest: answering for who looked at monitoring material 13 months That operator's administrators, hosting supplier
Application data Device model, OS build, app build, push token, crash trace, device location where granted The application on a user's handset Running the app, pushing the alerts an operator configured, clearing crashes Art. 6(1)(a) consent for handset location and for push. Art. 6(1)(f) for crash traces Crash traces 90 days. Push token until the app is removed Hosting supplier, Apple and Google push services

This table scrolls sideways on narrow screens.

Special category material under Article 9 is outside the design. The platform carries no field built to hold health, biometric or trade union information, and operators are instructed to keep it out of free text boxes. Anything of that kind keyed in anyway falls outside the instruction we work to.

5. Grounds we work from

Hat worn here: controller

Terms used in this section

Ground
The lawful basis in Article 6 that permits a particular line of the inventory to exist.
Balancing note
The written weighing of our interest against yours, held for each line resting on Article 6(1)(f).

Every lawful basis in play is named against its line in section 3. This section explains what standing behind each one involves.

5.1 Legitimate interests, Article 6(1)(f)

A balancing note exists for each of those lines, weighing what we get out of the processing against your interests, rights and freedoms. The interest is spelled out on the row rather than gestured at as a category. None of them involves profiling, advertising, or passing a record to an outsider for that outsider's own ends. Object under 10.6 and the balancing note behind any row will be sent to you.

5.2 Consent, Article 6(1)(a)

Consent is relied on in two places only: handset location and push notifications inside the applications. It is asked for when the feature is first opened, never bundled with anything else, refusable without losing the rest of the product, and withdrawable through the settings listed in section 12. Withdrawing it stops future processing and cannot undo what has already run.

5.3 Contract and legal obligation, Articles 6(1)(b) and 6(1)(c)

Article 6(1)(b) covers what an agreement with us cannot be performed without: issuing a login, taking payment, running support. Article 6(1)(c) covers the accounting file, anything a court, regulator or law enforcement body compels within its powers, and the reporting duty in section 15.

6. Tracking somebody who is driving

Hat worn here: processor, operator holds the controller hat

Terms used in this section

Monitoring
Any arrangement under which an employer or hirer watches how work is carried out.
Private mode
A setting an operator may switch on so that a permitted personal trip reports status without detailed position.

Put a unit in a van and you are handling personal data about whoever is behind the wheel. A coordinate, a stamp and an assignment together state where an identifiable person stood at a given minute, and the fact that the box is bolted to a vehicle rather than a person changes nothing in law.

6.1 What an operator is expected to have done first

Before a unit starts reporting, we expect the operator to have told its drivers what gets recorded, why, who may open it, how far back it goes and what it will never be used for; to have run an impact assessment where the monitoring is systematic and extensive, which Article 35 requires; and to have asked itself whether a lighter method would do the same job. Watching a workforce this way engages the Information Commissioner's published guidance on monitoring at work. A processor cannot police any of that, so account setup puts the question to the operator and records the answer.

6.2 What the driver's side carries

Private mode is a setting an operator can switch on, and it sits alongside account-level control over who may open a historic journey and how far back an ordinary user may look. The access log in inventory B exists as much for the driver's benefit as the operator's: it is the record of who went looking.

6.3 If you drive a tracked vehicle

Start with your employer or the hirer, because they hold both the answers and the duty. Write to us instead and we will identify the operator where we are permitted to, pass the request across, and help them answer it. Handing your record straight to you without the controller's instruction could itself put a record in the wrong hands, which is why we will not do it.

7. How long a record stays on the shelf

Hat worn here: both, marked per line

Nothing here is kept indefinitely, and no line reads "as long as necessary" without the period being spelled out beside it.

Retention schedule, in force 7 August 2026
Record Hat Period Why that period
Accounts, invoices and VAT paperwork Controller Six years, counted from the close of the accounting period Section 388 of the Companies Act 2006 sets three years; paragraph 6 of Schedule 11 to the Value Added Tax Act 1994 sets six for VAT paperwork. One file cannot sensibly be split between two clocks, so the longer one governs the lot
Correspondence and operator enquiries Controller 24 months, or cleared on request Long enough for a thread picked up next year to still make sense, short enough that a two-line question never turns into a permanent file
Fault reports Controller 36 months from closure A recurring fault often only shows itself across two or three cycles, and the ticket history is the evidence behind any defect claim
Account and agreement files Controller Term of the agreement, then six years Section 5 of the Limitation Act 1980 gives six years to bring an action on a simple contract
Position reports, journeys and geofence events Processor Operator's setting. Default 24 months, floor 3 months A plant hire desk arguing over an off-hire date and a courier proving a drop need different depths of history, so the depth belongs to the controller inside the range we support. An arrival event is meaningless once its journey has gone, so the three expire together
Access log inside the platform Processor 13 months A full year plus a month, which is what an audit needs, and what a driver asking who opened their record needs
Sign-in and security logs Both 13 months Spotting misused credentials means holding this week against the same week a year back
Edge logs on the website Controller Cloudflare's own window, days rather than months on our plan They exist to serve a request and turn away an attack, and are worth nothing afterwards
Crash traces from the applications Processor 90 days A crash not chased inside a release cycle gets chased from a fresher trace, never a stale one
Backups Both 35 days, rolling A deleted record survives inside a backup until that backup rolls off. Backups are not edited in place, because cutting into one puts the whole restore path at risk. See 14.3
Individual requests we have answered Controller Six years from closure Article 5(2) puts us to proof of compliance, and a request answered this year can be questioned long afterwards

This table scrolls sideways on narrow screens.

8. Suppliers who handle the data with us

Hat worn here: both

Each supplier below works to a written contract answering Article 28. Where TRAKCORP wears the processor hat, that supplier is a sub-processor beneath us. Their conduct remains our liability towards you.

Suppliers and recipients, in force 7 August 2026
Supplier Job it does What it can reach Where it works Route for any transfer
Cloudflare, Inc. Fronting this website: delivery, DNS, static hosting Connection metadata from the website. No platform record A global edge network, some of it beyond the UK UK Addendum riding on the EU standard contractual clauses, section 9
Mail supplier Post to and from hello@trakcorp.uk, plus mail the platform sends What correspondence contains, names, email addresses Contracted mail supplier acting as processor; named on request UK Addendum where that supplier works outside the UK
Hosting supplier Compute, database and object storage carrying the platform Everything listed in inventory B A United Kingdom region. Contracted hosting supplier acting as processor; named on request None needed while the work stays inside the UK
Payment supplier Card and direct debit collection where we raise the invoice Billing contact, sums, last four digits of a card. Never a full card number Contracted payment supplier acting as processor; named on request UK Addendum where that supplier works outside the UK
Apple Inc. and Google LLC Distributing the applications, billing inside them, pushing alerts Push tokens and store purchase records. Each is its own controller for what its store holds United States and elsewhere, under their own terms The routes each publishes, the UK Addendum among them
Accountant, legal advisers, insurers Statutory accounts and filings; advice on and defence of a claim, when instructed Accounting files holding billing contacts; on a claim, only what bears on the matter United Kingdom None needed

This table scrolls sideways on narrow screens.

8.1 Changing the list

Where we wear the processor hat, operators get 30 days' written warning before any supplier able to reach platform records is added or swapped. An operator may object on reasonable data protection grounds, and where the objection cannot be worked through it may drop the affected service without penalty. This page is the authoritative list, and it changes before the supplier does.

8.2 Disclosures that are not sub-processing

A court order, a statutory information notice or a lawful request from law enforcement can compel disclosure. We check the demand is valid and reaches no wider than the power behind it, hand over only what is called for, and tell the affected controller unless we are forbidden to. Were the business sold, the files would pass to the buyer, who would be held to this manual until publishing its own.

9. Sending data out of the United Kingdom

Hat worn here: both

Terms used in this section

Adequacy
A finding that a destination country protects personal data to a standard the UK accepts.
IDTA
The International Data Transfer Agreement, a standalone UK contract for exporting personal data.
UK Addendum
A rider that lifts the EU standard contractual clauses up to the UK standard.

Platform records sit in a United Kingdom region, and position data is not routinely moved out of it. Some supporting services do involve an export, and each takes one of the three routes below.

9.1 Adequacy regulations

Nothing further is needed where the destination is covered by UK adequacy regulations made under Article 45 and section 17A of the Data Protection Act 2018. That covers the European Economic Area, the territories carried over from earlier European Commission findings, and United States organisations certified under the Data Privacy Framework's UK extension.

9.2 The IDTA

Where no adequacy regulation applies and the counterparty will contract on UK terms directly, the IDTA is used. It was issued under section 119A of the Data Protection Act 2018 and laid before Parliament on 2 February 2022, and it stands on its own without EU clauses underneath it.

9.3 The UK Addendum

Where a supplier already works to the European Commission's 2021 standard contractual clauses, we attach the UK Addendum instead, issued under the same power. It swaps the EU references for UK ones and raises the protection to the UK standard. Cloudflare, Apple and Google each offer terms in that shape, which is what section 8 records against them.

9.4 Assessing the destination first

Before either route is relied on we look at the law and the practice where the data is going, ask whether either would stop the importer keeping to the clauses, and decide what extra measures close whatever gap is left. In practice those measures are encryption on the wire and at rest, cutting the export down to the minimum that does the job, and a contractual duty to tell us about government access demands.

9.5 Asking for a copy

Name the supplier in an email to hello@trakcorp.uk and the route relied on for it comes back to you, with commercial terms blacked out.

10. Handling a request from an individual

Hat worn here: controller for our files, processor for platform records

Terms used in this section

Request
Any exercise of a right in Chapter III of the UK GDPR, however it is worded.
The clock
The one calendar month in 10.10, which starts only once identity is settled.
Routing
The step in 10.11 for anything concerning an operator's tracking record.

Each right below is set out as a procedure: what it gives you, how to fire it, and the circumstances in which it can be turned down. Identity, the clock and routing sit at 10.9 to 10.11 and apply across all of them.

10.1 Being told, Articles 13 and 14

You are owed a plain account of what happens to your personal data, which this manual is written to discharge. How to fire it: read on, or write in. Turned down when: practically never, though for data reaching us indirectly the Article 14(5) exemptions can apply where tracing and telling every individual would take effort out of all proportion to the benefit.

10.2 Access, Article 15

You may ask whether we hold anything about you, receive a copy of it, and be given the surrounding detail Article 15(1) lists: purposes, categories, recipients, retention, your other rights, where it came from, and the safeguards behind any export.

How to fire it: write in with "Subject access request" on the subject line. Turned down when: a request is manifestly unfounded or excessive, where we may refuse or charge a reasonable fee, and must give reasons and point you to the ICO. Anything revealing another person is redacted, and material covered by legal professional privilege or by an exemption in Schedule 2 to the Data Protection Act 2018 may be held back.

10.3 Rectification, Article 16

Wrong data gets corrected and half-finished data gets completed. How to fire it: write in stating what is wrong and what it ought to say. Turned down when: we wear the processor hat, in which case an operator's record cannot be altered on your say-so and 10.11 applies. A logged position is a report of what a device transmitted, so a challenge to one is normally met by attaching your account of it rather than by editing the report, which would gut its evidential worth.

10.4 Erasure, Article 17

Data goes when it is no longer needed, when consent behind it is withdrawn, when an objection under Article 21(1) succeeds, when processing was unlawful, or when the law demands it. How to fire it: write in with "Erasure request" on the subject line, or use section 14 for a platform account. Turned down when: a legal duty keeps the record alive, the six-year accounting file being the usual example, or where it is needed for a legal claim. Backups behave as 14.3 describes.

10.5 Restriction, Article 18

You may require a record to be parked, held but otherwise untouched, while a dispute over accuracy or over legitimate interests is settled, where processing is unlawful but you would rather park it than lose it, or where we have finished with it and you still need it for a claim. How to fire it: write in naming the record and the reason. Turned down when: nothing prevents storage or use for a legal claim, and the parking lifts, on notice to you, once the dispute is done.

10.6 Objection, Article 21

Anything resting on legitimate interests can be objected to at any point, on grounds particular to your situation. Processing then stops unless we can show grounds weighty enough to override yours, or it is needed for a legal claim. Objection to direct marketing is absolute, and none is carried out here. How to fire it: write in with "Objection" on the subject line. Turned down when: only on those overriding grounds, which would be set out in writing rather than merely asserted.

10.7 Portability, Article 20

Where processing rests on consent or on a contract and runs by automated means, you may take your data away in a structured, common, machine-readable shape, and have it passed to another controller where that is technically workable. How to fire it: write in; the export comes back as JSON or CSV. Turned down when: the right does not reach data held under legitimate interests or a legal duty, and cannot be used in a way that harms somebody else. Under the processor hat the operator asks and we supply it to them.

10.8 Automated decisions, Article 22

You may refuse a decision reached by machine alone where it carries legal weight or hits you comparably hard. Section 17 explains why none is taken here.

10.9 Settling identity

Sending a record to the wrong person is itself a breach, so we have to be reasonably sure of who is asking. Writing from an address already sitting on the record usually settles it. Failing that we ask for detail matching you to the record, and failing that for one identity document with everything we do not need blacked out. Nothing is kept once identity is settled, and the clock in 10.10 does not start until the answer arrives.

10.10 The clock

An answer goes back without undue delay and at the latest inside one calendar month of the request, or of the identity detail we had to ask for. Where a request is complex, or several have arrived together, up to two further months may be taken, and we will say so inside the first month and explain why. No charge is made except in the narrow case at 10.2.

10.11 Requests about an operator's tracking record

These cannot be answered by us. Inside five working days we will confirm that we hold the processor hat, name the operator where we are permitted to, and pass the request across. Our contracts oblige us to help them answer it. None of that stops you going direct to the operator, which is usually the quicker road.

11. Safeguards standing on the system

Hat worn here: both

Article 32 calls for measures matched to the risk. These are the ones standing today, written as measures rather than as comfort.

  • TLS 1.2 or better on every connection into the website, the platform and the API, with Strict Transport Security switched on.
  • Databases, object storage and backups all encrypted where they sit.
  • Passwords held only as salted hashes from a memory-hard algorithm.
  • Roles governing access, so a user opens only what the role allows.
  • A second factor on every administrative account we run: hosting, DNS, mail and source control alike.
  • Least privilege inside the company, with production access limited and logged.
  • Every record opened or exported written to the access log, held 13 months.
  • Tenant separation, so no operator can reach another operator's assets.
  • Dependencies watched for known vulnerabilities, with patching on a set schedule.
  • Backups rolling on 35 days, with restores tested rather than assumed.
  • Anybody able to reach personal data works under a written confidentiality duty.

12. Permissions the applications ask for

Hat worn here: processor for operator records, controller for diagnostics

The permission set below is the whole of what a TRAKCORP application asks a handset for, and any store listing issued under our name is held to it. Nothing is demanded at install time, and every line can be refused.

Permission set for TRAKCORP iOS and Android applications
Permission Job it does Needed or optional Refuse it and Turn it off on iOS Turn it off on Android
Location while the app is open Centring the map where you stand, and confirming site arrival without typing an address Optional The map opens on your depot and arrival is confirmed by hand Settings, Privacy and Security, Location Services, TRAKCORP, Never Settings, Apps, TRAKCORP, Permissions, Location, Do not allow
Location in the background Logging a journey from a handset where no unit is fitted, a hired vehicle for instance Optional Handset journey logging is unavailable; fitted units carry on regardless Settings, Privacy and Security, Location Services, TRAKCORP, While Using the App Settings, Apps, TRAKCORP, Permissions, Location, Only while using the app
Notifications Delivering the geofence, ignition and power loss alerts an operator configured Optional Alerts wait inside the app and nothing is pushed to the handset Settings, Notifications, TRAKCORP, Allow Notifications off Settings, Notifications, App settings, TRAKCORP, off
Camera and photo library Photographing an asset, a defect or a drop, or attaching a shot already taken Optional Attach from the other source, or attach nothing at all Settings, Privacy and Security, Camera or Photos, TRAKCORP off Settings, Apps, TRAKCORP, Permissions, Camera or Photos and videos, Do not allow
Bluetooth Reading asset tags nearby so a handset can act as a gateway for tools and small plant Optional Tags are picked up by fixed gateways only, never by your handset Settings, Privacy and Security, Bluetooth, TRAKCORP off Settings, Apps, TRAKCORP, Permissions, Nearby devices, Do not allow
Network access Reaching the platform, without which nothing on screen updates Needed Never prompted separately; it comes with installing anything that talks to a server Settings, Cellular, TRAKCORP off, which restricts mobile data alone Settings, Apps, TRAKCORP, Mobile data and Wi-Fi, restrict

This table scrolls sideways on narrow screens.

Withdrawing a permission bites at once and erases nothing gathered beforehand; section 14 is the route for that. Every path above is walked from the Settings app, and holds good for current iOS and Android builds.

13. What the two app stores are told

Hat worn here: controller for the store declarations

13.1 App Tracking Transparency on iOS

Apple's App Tracking Transparency framework requires permission before an app follows a user across apps and websites belonging to other companies, or reads the advertising identifier on the device. No TRAKCORP application does either. There is no advertising in the product, no advertising SDK compiled into it, and no measurement that follows a person off our own service, so the prompt is never raised and the privacy label carries nothing under data used to track you. Location gathered in the app delivers the service to the operator and attaches to the user's own account, because that is what makes a journey attributable; it never attaches to an identifier shared between companies.

13.2 Google Play Data Safety

The Data Safety declaration on Play states that the application handles location, personal detail limited to a name and an email address, app activity and crash traces; that all of it travels encrypted; that none of it is handed to another company for that company's own ends; that deletion runs through section 14; and that the optional lines can be refused. That declaration and this manual are drawn from the same inventory and have to agree. Find them disagreeing and this manual governs, and we would want to hear about it so the listing can be corrected.

14. Account deletion, and wiping the record

Hat worn here: controller for our files, processor for platform records

14.1 From inside the product

Once the applications are published, anybody signed in may delete their own account at Settings, then Account, then Delete account, confirming with a password. The same path runs through the web application. That clears the person's profile, credentials, sessions, notification tokens and preferences. It does not clear the operator's tracking record, which is the operator's property. An administrator closes an entire organisation and everything tracked under it at Settings, then Organisation, then Close account, confirming by typing the organisation name.

14.2 By writing in

Locked out, or would simply rather write, send us a message headed "Delete my account". Identity is settled under 10.9 and the deletion is carried out, whether or not either application was ever installed.

14.3 Timing, and what happens inside backups

Live systems are cleared straight away, and in every case inside 30 days of a verified request. Encrypted backups roll on a 35-day cycle and are never cut into, so a deleted record survives there until its backup rolls off, 35 days at the outside. Through that window the backup is touched for disaster recovery and nothing else, and were a restore ever to bring a deleted record back, the deletion is run again the same day.

14.4 What outlives the deletion, and why

  • The accounting file, six years under section 7. It carries billing contacts and sums, never tracking data.
  • The note of your request, showing it arrived, was verified and was carried out, six years, which is how Article 5(2) is answered.
  • Suppression detail, the bare minimum needed to honour a request never to be contacted again, since forgetting it would put you straight back on the list.
  • Anything under legal hold, where a claim, an investigation or a statutory duty requires it to stand. You would be told that is the reason.
  • Aggregate counts that identify nobody, which are not personal data at all.

14.5 Removing the app is not deletion

Deleting the application off a handset clears neither the account nor the record, and cancelling a store subscription stops the next payment while erasing nothing. Use 14.1 or 14.2.

15. Breach drill

Hat worn here: both, with a different duty under each

Terms used in this section

Breach
A security failure ending with personal data wrecked, lost, altered, exposed to somebody who should not see it, or reachable by them, whether through accident or an unlawful act.
Aware
The point at which we have a reasonable degree of certainty that a security incident has compromised personal data.

15.1 Under the controller hat, Article 33(1)

Every suspected breach is assessed the moment we become aware of it. Where the outcome could put people's rights and freedoms at risk, the ICO is told without undue delay and, where feasible, no later than 72 hours after we became aware, with reasons given for any part of that spent. Where the threshold is not met, the reasoning is written down anyway, because Article 33(5) puts every breach on the record whether or not it is reported.

15.2 Under the processor hat, Article 33(2)

The affected operator is told without undue delay. No 72-hour allowance of our own exists here: their clock starts when our message lands, so every hour we sit on it is an hour taken off them. The message states what happened, the categories and rough numbers of people and records caught by it, what is likely to follow, and what has been done or is proposed. We then help with their own notification, as Article 28(3)(f) requires.

15.3 Telling the people affected, Article 34

Where the risk to individuals is high and we wear the controller hat, those individuals are told without undue delay, in plain words, covering what is likely to follow and what has been done about it. That falls away where encryption left the data unintelligible, where later steps have brought the high risk down, or where reaching everybody individually would take effort out of all proportion, in which case a public statement goes out instead. Under the processor hat the call belongs to the operator.

15.4 The drill itself

Contain, assess, notify, remediate, write up. Each breach gets a written record of what happened, which data was caught, who was told and when, and what changed afterwards. Those records stand for six years.

15.5 Reporting something to us

Write to hello@trakcorp.uk with "Security" on the subject line and you will hear back within one working day. Report a genuine vulnerability in good faith, reach no further into the data than proving it requires, and give us a fair chance to close it before going public, and no legal action will come from us over it.

16. Storage set by this website

Hat worn here: controller

trakcorp.uk is a set of static files. No first-party cookie is written by it, and there is no measurement script, tag container, advertising pixel or consent dialogue anywhere on it. Typefaces come from Google's font hosts, so your browser makes a request to Google and Google sees the address it came from. The full account, including what Cloudflare may write for security reasons, sits on the cookies page.

17. Decisions taken by machine

Hat worn here: both

Nothing about you is decided by automated processing alone in a way that carries legal weight or hits you comparably hard, which is the test Article 22 sets.

The platform certainly produces automated output: an arrival event fires, idle minutes are totted up, a utilisation figure appears. Those are measurements. Should an operator take one of them and decide something about a person on the strength of it, in a disciplinary matter for instance, the decision is that operator's, taken by a human being, and answered for by them. No profiling is run here for marketing, credit or risk scoring.

18. Children

Hat worn here: both

Both the platform and this website are working tools for businesses. Neither is aimed at a child, no child's personal data is knowingly collected, and the store rating on a TRAKCORP application says the same. Tell us if you think a child's details have reached us and they will be cleared.

19. Amending this manual

Hat worn here: both

This is issue 1, in force from 7 August 2026. Any amendment carries a new issue number and date at the head of the page. Where an amendment materially changes how a record is handled, a fresh purpose or ground for instance, or a new supplier able to reach platform records, operators and account holders hear about it by email at least 30 days ahead. Corrections that leave the meaning alone go in without notice. Where the law calls for a fresh ground or a fresh consent, republishing this manual is not treated as having supplied either.

20. Raising it with us, and with the ICO

Hat worn here: both

20.1 Writing to us

Email is the one route this company operates. Write to hello@trakcorp.uk and most answers go back inside three working days; anything engaging a right under section 10 runs to the periods at 10.10. The filed office takes service of documents rather than visitors, so write rather than travel.

No data protection officer has been appointed. Article 37 does not call for one on these facts: monitoring on our own account is neither large scale nor systematic, and no special category data is handled at scale. Appoint one and the details will appear here.

20.2 If our answer does not satisfy you

Come back to us first and say plainly where you think we went wrong. Doing so takes nothing away from your right to go to the regulator instead, or as well.

20.3 Complaining to the Information Commissioner

Article 77 of the UK GDPR gives you the right to complain to the Information Commissioner's Office, which supervises this area across the United Kingdom.

  • Information Commissioner's Office
  • Postal address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Telephone: 0303 123 1113
  • Online: ico.org.uk/make-a-complaint

Article 79 additionally gives you a judicial remedy, and Article 82 a route to compensation for damage suffered.

This manual was drawn up for TRAKCORP LTD, company number 17005499, and describes that company alone. It is not legal advice to anybody else.