Privacy notice
- Effective 7 August 2026
- Version 1.0
- TRAKCORP LTD, company 17005499
- Jurisdiction: United Kingdom
1. Who we are and what this notice covers
This notice is published by TRAKCORP LTD, registered in England and Wales under company number 17005499, registered office 12 Heritage Mews, Mill Road, Great Yarmouth, NR31 0HW. "You" means whoever is reading: a website visitor, a contact at an operator, a platform user, or a driver whose vehicle is tracked with it.
It covers the data we handle in running this company and website, the data inside the platform for operator customers, and the data our mobile applications will handle once published.
The law throughout is the UK General Data Protection Regulation, Regulation (EU) 2016/679 as retained by section 3 of the European Union (Withdrawal) Act 2018, with the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003. We call it the UK GDPR.
Stage of the company. TRAKCORP LTD was incorporated on 1 February 2026. The platform is in build and in use with a small number of pilot operators. Nothing is published on the Apple App Store or Google Play at the effective date. Sections describing the mobile applications govern them from the moment they appear, and are marked where they describe something that does not yet exist.
1.1 Registration with the Information Commissioner
[TO CONFIRM: our registration number under the data protection fee regime. It will be published in this paragraph once issued, and until then this notice does not claim a registration is in place.]
2. Our two roles: controller and processor
TRAKCORP handles personal data in two distinct legal capacities, and almost every answer below depends on which applies. Every section after this one carries a role marker.
2.1 Where TRAKCORP is the controller
We are the controller, deciding purposes and means, for data about people who deal with TRAKCORP as a business: website visitors, anyone emailing hello@trakcorp.uk, contacts at operators discussing the pilot, account administrators, suppliers, and anyone corresponding about a legal matter. Our obligations run directly to you, and section 10 is where you exercise your rights.
2.2 Where TRAKCORP is the processor
We are the processor, acting only on documented instructions, for tracking data in the platform. When an operator fits a unit to a van, the operator decides why it is tracked, who may see the record, how long history is kept within the limits we offer and what it is used for. The operator is the controller; we supply the software and store the data.
That matters most to drivers. If you drive a tracked vehicle, your employer or the hirer is normally the controller of your position data, not TRAKCORP. Section 10.11 explains the routing.
2.3 Article 28 terms
Every operator enters into data processing terms meeting Article 28: subject matter and duration, nature and purpose, categories of data and data subject, processing only on documented instructions, confidentiality, Article 32 security, conditions for sub-processors, assistance with rights requests and Articles 32 to 36, deletion or return at the end, and information for audits. They sit alongside the terms of service and take precedence over this notice for anything they cover.
2.4 What we never do
We do not sell personal data, share tracking data between operators, use one operator's history to build a feature for another, or use tracking data for advertising. Platform performance is measured from metrics that identify no vehicle, asset or person.
3. Data inventory: where we are the controller
Role: TRAKCORP is the controller
This is the complete inventory of personal data we hold as controller, with the lawful basis and its UK GDPR article on every row.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Enquiry correspondence | Name, email, employer, job title, message content, timestamp | You, by email | Reading, answering and recording what you sent | Art. 6(1)(f). Interest: replying to correspondence sent to a published address, impossible without reading and keeping it | 24 months from the last message | Email provider |
| Pilot programme enquiries | Contact name, email, company, fleet size, asset types, current system, depot locations | You, in the pilot email | Assessing fit, and shaping what we build next | Art. 6(1)(f). Interest: progressing a business relationship you initiated | 24 months from last contact, or on request | Email provider |
| Account administrators | Name, work email, telephone, role, permissions, sign-in timestamps, password hash | The operator, or the individual | Creating and securing platform access | Art. 6(1)(b) where the individual is our counterparty, otherwise Art. 6(1)(f). Interest: administering a business contract | Contract plus 12 months | Hosting and email providers |
| Billing records | Billing contact and address, VAT number, invoice lines, amounts, payment dates, partial card identifiers | The operator, the payment provider | Invoicing, collection, credit control, statutory accounts | Art. 6(1)(b) for payment. Art. 6(1)(c) for the accounting record, under the Companies Act 2006 and the Value Added Tax Act 1994 | Six years, see section 7 | Payment provider, accountant, HMRC where required |
| Support requests | Name, email, account reference, fault description, attached logs or screenshots | You or a colleague | Diagnosing and fixing faults | Art. 6(1)(b) where support is contractual, otherwise Art. 6(1)(f). Interest: operating a support route | 36 months from closure | Hosting and email providers |
| Website server logs | Truncated IP, request path, status, user agent, referrer, timestamp | Your browser, via our content delivery network | Serving the site, blocking abuse, diagnosing errors | Art. 6(1)(f). Interest: keeping a public website available and defending it against automated attack | Provider retention, see section 7 | Cloudflare, Inc. |
| Supplier contacts | Name, business email and telephone, role, contract correspondence | The supplier | Buying goods and services, managing those contracts | Art. 6(1)(b), or Art. 6(1)(f). Interest: managing our supply chain | Contract plus six years | Accountant, email provider |
| Legal correspondence | Any data in a complaint, claim, regulator enquiry or rights request | You, a regulator, a third party | Handling the matter and defending legal claims | Art. 6(1)(c) where a statute requires it, otherwise Art. 6(1)(f). Interest: defence of legal claims. Art. 9(2)(f) for special category data | Six years from resolution, longer if a limitation period runs | Legal advisers, insurers, the ICO or a court |
This table scrolls sideways on narrow screens.
We operate no marketing list, run no advertising and buy no contact data. If that changes, this table changes with it.
4. Data inventory: where we are the processor
Role: TRAKCORP is the processor, the operator is the controller
These categories reach us inside the platform. The purpose is set by the operator and the lawful basis is the operator's to establish and record. We state the basis an operator will ordinarily rely on because it helps drivers, but we do not decide it and cannot answer for it.
| Category | Example fields | Source | Purpose set by operator | Operator's usual lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Position reports | Device ID, UTC timestamp, latitude, longitude, speed, heading, satellite count, HDOP, ignition state, external voltage | Telematics units and asset tags | Knowing where an asset is and where it has been | Art. 6(1)(f). Interest: protecting the operator's assets and verifying work performed. Some rely on Art. 6(1)(b) or 6(1)(c) | Operator setting. Target default 24 months, down to 3 months | The operator's users, hosting provider |
| Journeys | Start and end time and position, polyline, distance, duration, idle time, assigned asset and driver | Derived by us from positions | Answering questions about attendance, delivery, hours run, utilisation | As above | As for position reports | The operator's users, hosting provider |
| Geofence events | Geofence and asset ID, entry or exit, timestamp, dwell duration | Derived from positions against operator boundaries | Recording arrival and departure at depots, sites and customer premises | As above | As for position reports | The operator's users, any system connected by API or webhook, hosting provider |
| Driver records | Name or reference, person to asset assignment, shift pattern, driver ID token | Entered by the operator | Linking a journey to the person responsible | Art. 6(1)(f), or Art. 6(1)(b) under the employment contract, as the operator determines | Operator setting, deleted on account closure | The operator's users, hosting provider |
| Platform user accounts | Name, work email, password hash, role, last sign-in, session IDs | The operator, or the user | Controlling who sees which assets and which history | Art. 6(1)(b) between operator and user, or Art. 6(1)(f) in access control | Deleted on account closure, section 14 | Hosting and email providers |
| Audit and access logs | User ID, action, record viewed or exported, timestamp, source IP | Generated by the platform | Showing who looked at a journey record and who exported it | Art. 6(1)(f). Interest: accountability for access to monitoring data | 13 months | The operator's administrators, hosting provider |
| Mobile application data | Device model, OS version, app version, push token, crash diagnostics, location where granted | The application on the user's device | Delivering the app, sending configured alerts, fixing crashes | Art. 6(1)(a) consent for device location and push. Art. 6(1)(f) for crash diagnostics | Crash diagnostics 90 days. Push tokens until uninstall | Hosting provider, Apple and Google push services |
This table scrolls sideways on narrow screens.
We collect no special category data as defined by Article 9, and the platform has no field designed to hold it. Operators are instructed not to enter health, biometric or trade union information into free text fields; doing so falls outside our documented instructions.
5. Lawful bases and our legitimate interests
Role: TRAKCORP is the controller
5.1 Legitimate interests, Article 6(1)(f)
Where we rely on legitimate interests we have carried out a balancing assessment weighing our interest against your interests, rights and freedoms. Each interest is named in the tables above rather than left as a category. None involves profiling, advertising or disclosure to a third party for its own purposes. You may object under 10.6, and we will send you the balancing assessment behind any row on request.
5.2 Consent, Article 6(1)(a)
We rely on consent only for device location and push notifications in the mobile applications. It is requested when the feature is first used, is not bundled, can be refused without losing the rest of the product, and can be withdrawn through the settings in section 12. Withdrawal does not affect processing already carried out.
5.3 Legal obligation, Article 6(1)(c)
Relied on for accounting retention, for responses compelled by a court, regulator or law enforcement body acting within its powers, and for the reporting duties in section 15.
6. Vehicle tracking, drivers and workplace monitoring
Role: TRAKCORP is the processor, the operator is the controller
Tracking a vehicle almost always means processing personal data about the person driving it. A position, a timestamp and an assignment together say where an identifiable individual was, and the record being about a van makes no difference in law.
6.1 What we expect an operator to have done
Before switching tracking on we expect an operator to have told its drivers what is tracked, why, who sees it, how long it is kept and what it will not be used for; to have carried out a data protection impact assessment where the monitoring is systematic and extensive, as Article 35 requires; and to have considered a less intrusive option. Vehicle tracking is monitoring of workers, and the Information Commissioner's guidance on monitoring at work applies. We cannot police that as processor, but account setup asks the operator to confirm it.
6.2 Features being built for driver privacy
The platform is being built with a private mode an operator can enable so a vehicle on a permitted personal journey reports status without detailed position, and with controls over who can see historic journeys. The audit log exists for the driver's benefit as much as the operator's.
[TO CONFIRM: the exact behaviour of private mode at first release, including whether position is suppressed or coarsened, to be documented here before the feature ships.]
6.3 If you are a driver
Your employer or the hirer is normally the controller. Ask them first: they hold the answers and the obligation. If you write to us we will identify the operator, pass your request on and help them answer it. We will not disclose your record directly without the controller's instruction, because that could itself be a breach.
7. How long we keep personal data
Role: both, marked per row
We do not keep personal data indefinitely, and we do not say "as long as necessary" without saying what that means.
| Record | Our role | Period | Reason for that period |
|---|---|---|---|
| Accounting records, invoices, VAT records | Controller | Six years from the end of the accounting period | Section 388 of the Companies Act 2006 requires three years; paragraph 6 of Schedule 11 to the Value Added Tax Act 1994 requires six years for VAT records. We apply the longer period to the whole set rather than split one file across two rules |
| Enquiry and pilot correspondence | Controller | 24 months, or immediately on request | Long enough that a conversation resumed next year still has context, short enough that a one line enquiry never becomes a permanent file |
| Support requests | Controller | 36 months from closure | Recurring faults are often only visible across two or three cycles, and support history is the evidence for a defect claim |
| Customer account and contract records | Controller | Contract plus six years | Six years is the limitation period for an action on a simple contract under section 5 of the Limitation Act 1980 |
| Position reports and journeys | Processor | Operator setting. Target default 24 months, down to 3 months | A plant hire business defending an off hire dispute and a courier proving a delivery have different evidential needs, so the period is the controller's choice within the range we support |
| Geofence events | Processor | Same as the operator's journey setting | An arrival event is meaningless without the journey that produced it, so they expire together |
| Platform audit and access logs | Processor | 13 months | Covers a full annual cycle plus a month, which is what an audit or a driver's question about who viewed their record needs |
| Authentication and security logs | Controller and processor | 13 months | Detecting credential abuse means comparing behaviour with the same period a year earlier |
| Website logs at the edge | Controller | Cloudflare's retention, days rather than months on our plan | They serve requests and block attacks, and have no value afterwards |
| Mobile crash diagnostics | Processor | 90 days | A crash not diagnosed within a release cycle is diagnosed from a newer report, not an older one |
| Backups | Controller and processor | 35 days, rolling | Deleted records persist until the backup expires. We do not surgically edit backups, because that risks corrupting the restore path. See 14.3 |
| Records of data subject requests | Controller | Six years from closure | Article 5(2) requires us to demonstrate compliance, and a request answered in 2026 may be questioned years later |
This table scrolls sideways on narrow screens.
8. Recipients and sub-processors
Role: both
Each provider below is a processor to us, or a sub-processor where we are ourselves a processor, and each is bound by a written contract meeting Article 28. We remain liable to you for what they do.
| Provider | What it does | Data it can reach | Location | Transfer mechanism |
|---|---|---|---|---|
| Cloudflare, Inc. | Content delivery, DNS and static hosting | Website connection metadata. No platform data | Global edge network, including outside the UK | UK Addendum to the EU Standard Contractual Clauses, section 9 |
| Email service provider | Mail to and from hello@trakcorp.uk, and platform mail | Correspondence content, names, email addresses | [TO CONFIRM: provider and region, before the pilot opens to general sign-up] | To be stated with the provider |
| Platform hosting provider | Compute, database and object storage for the platform | All platform data in section 4 | A United Kingdom region. [TO CONFIRM: provider and named UK region, once the production agreement is signed] | Not applicable while processing stays in the UK |
| Payment provider | Card and direct debit payments billed by us | Billing contact, amounts, partial card identifiers. Never a full card number | [TO CONFIRM: provider and region, before billing is switched on] | To be stated with the provider |
| Apple Inc. and Google LLC | App distribution, in-app billing and push delivery, once published | Push tokens, store purchase records. Both are controllers for their own store data | United States and elsewhere under their terms | Their published mechanisms, including the UK Addendum |
| Accountant | Statutory accounts and filings | Accounting records containing billing contacts | United Kingdom | Not applicable |
| Legal advisers and insurers | Advice on and defence of claims, when instructed | Only what is relevant to the matter | United Kingdom | Not applicable |
This table scrolls sideways on narrow screens.
8.1 Changes to the list
Where we are the processor we give operators at least 30 days written notice before adding or replacing a sub-processor that can reach platform data. The operator may object on reasonable data protection grounds, and if the objection cannot be resolved may terminate the affected service without penalty. This page is the authoritative list.
8.2 Disclosures that are not sub-processing
We may disclose where legally compelled, for example under a court order, statutory information notice or lawful law enforcement request. We check the request is valid and no wider than the power relied on, disclose only what is required, and tell the affected controller unless prohibited. Records would also transfer to a buyer if the business were sold, and the buyer would be bound by this notice until it published its own.
9. International transfers
Role: both
Platform data is hosted in a United Kingdom region with no routine transfer of position data outside the UK. Some supporting services do involve transfers.
9.1 Adequacy regulations
Where a country is covered by UK adequacy regulations under Article 45 and section 17A of the Data Protection Act 2018, a transfer needs no further mechanism. That includes the European Economic Area, the territories carried over from the European Commission's decisions, and United States organisations certified under the UK Extension to the EU to US Data Privacy Framework.
9.2 The International Data Transfer Agreement
Where there is no adequacy regulation and the counterparty contracts directly on UK terms, we use the International Data Transfer Agreement, the IDTA, issued under section 119A of the Data Protection Act 2018 and laid before Parliament on 2 February 2022. It is a standalone contract needing no EU clauses underneath it.
9.3 The UK Addendum to the EU Standard Contractual Clauses
Where a provider already contracts on the European Commission's 2021 Standard Contractual Clauses, we use the International Data Transfer Addendum to those clauses, the UK Addendum, issued under the same power. It applies the UK GDPR standard on top of the EU clauses and replaces the EU references with UK ones. Cloudflare, Apple and Google all offer terms of that shape, which is what section 8 records against them.
9.4 Transfer risk assessment
Before relying on either we assess the law and practice of the destination country, whether it would prevent the importer honouring the clauses, and what supplementary measures close any gap. In practice those are encryption in transit and at rest, minimisation of what is transferred, and contractual commitments on government access notification.
9.5 Getting a copy
Ask at hello@trakcorp.uk for the mechanism relied on for any provider. We will send it with commercial terms redacted.
10. Your rights under the UK GDPR
Role: controller for our records, processor for platform data
Each right below sets out what it is, how to exercise it and when it can be refused. Identity verification, timing and routing are in 10.9 to 10.11 and apply to all of them.
10.1 The right to be informed, Articles 13 and 14
You have the right to be told what we do with your personal data, which this notice discharges. How to exercise: read it, or email us. When it can be refused: in practice it cannot, though for data obtained indirectly we may rely on the Article 14(5) exemptions where providing the information would involve disproportionate effort.
10.2 The right of access, Article 15
You have the right to confirmation of whether we process your data, a copy of it, and the supplementary information in Article 15(1): purposes, categories, recipients, retention, your other rights, the source, and transfer safeguards.
How to exercise: email us with the subject "Subject access request". When it can be refused: we may refuse or charge a reasonable fee where a request is manifestly unfounded or excessive, and must tell you why and that you can complain to the ICO. We redact information revealing another person's data, and may withhold material subject to legal professional privilege or an exemption in Schedule 2 to the Data Protection Act 2018.
10.3 The right to rectification, Article 16
You have the right to have inaccurate data corrected and incomplete data completed.
How to exercise: email us saying what is wrong and what it should say. When it can be refused: where we are the processor we cannot change an operator's record on your instruction, and route it under 10.11. A recorded position is what a device reported, so a claim that one is wrong is normally handled by adding your statement to the record rather than altering the report, which would destroy its evidential value.
10.4 The right to erasure, Article 17
You have the right to erasure where data is no longer necessary, where you withdraw the consent it relied on, where you object under Article 21(1) and no overriding legitimate ground exists, where processing was unlawful, or where erasure is required by law.
How to exercise: email us with the subject "Erasure request", or for a platform account follow section 14. When it can be refused: where processing is necessary for a legal obligation such as the six year accounting retention, or for legal claims. Backups are covered in 14.3.
10.5 The right to restrict processing, Article 18
You have the right to require us to store data and do nothing else with it while a dispute about accuracy or legitimate interests is resolved, where processing is unlawful but you prefer restriction to erasure, or where we no longer need the data but you need it for a legal claim. How to exercise: email us saying which data and why. When it can be refused: restriction lifts, with notice, once the dispute is resolved, and does not prevent storage or processing for legal claims.
10.6 The right to object, Article 21
You have the right to object at any time to processing based on legitimate interests, on grounds relating to your particular situation. We must stop unless we can demonstrate compelling legitimate grounds overriding your interests, or the processing is for legal claims. The right to object to direct marketing is absolute, and we carry out none. How to exercise: email us with the subject "Objection". When it can be refused: only on those compelling grounds, which we would explain in writing rather than assert.
10.7 The right to data portability, Article 20
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your data in a structured, commonly used, machine readable format and to have it transmitted to another controller where technically feasible. How to exercise: email us; we export JSON or CSV. When it can be refused: it does not apply to data processed under legitimate interests or legal obligation, and must not adversely affect others. Where we are the processor, the operator asks and we supply it to them.
10.8 Rights on automated decision making, Article 22
You have the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects. See section 17: we make none.
10.9 Verifying your identity
Disclosing a record to the wrong person is itself a breach, so we must be reasonably satisfied you are who you say you are. Writing from an address already associated with the record is usually enough. Otherwise we ask for information matching you to the record, and failing that one identity document with the parts we do not need obscured. We keep nothing beyond verification, and the clock in 10.10 does not start until we have what we asked for.
10.10 Timing
We respond without undue delay and in any event within one calendar month of the request, or of receiving the identity information we needed. Where a request is complex or you have made several, we may extend by up to two further months, telling you within the first month and why. We charge no fee except in the narrow circumstances in 10.2.
10.11 Requests about platform data
If your request concerns tracking data held for an operator, we cannot answer it ourselves. Within five working days we will tell you we are the processor, identify the operator where permitted, and forward the request. Our contracts oblige us to assist them in responding. Nothing here stops you going straight to the operator, which is usually faster.
11. Security of personal data
Role: both
Article 32 requires measures appropriate to the risk. Ours are stated as measures, not reassurance.
- TLS 1.2 or above for all connections to the website, platform and API, with HTTP Strict Transport Security enabled.
- Encryption at rest for databases, object storage and backups.
- Passwords stored only as salted hashes using a memory hard algorithm.
- Role based access control, so an operator's users see only what their role permits.
- Multi factor authentication on every administrative account we operate, including hosting, DNS, email and source control.
- Least privilege internally, with production access limited and recorded.
- Audit logging of record access and export, retained 13 months.
- Tenant segregation, so one operator cannot reach another's records.
- Dependency and vulnerability monitoring, with security patches on a defined schedule.
- Backups on a rolling 35 day cycle, restore tested.
- Written confidentiality obligations on everyone who can reach personal data.
We do not hold ISO 27001 certification, a SOC 2 report or Cyber Essentials certification, and will not represent otherwise. The measures above are what we do, not what an auditor has confirmed. Any certification obtained will be published here with its certificate reference.
12. Mobile application permissions
Role: processor for operator data, controller for diagnostics
The iOS and Android applications are planned and not yet published. This is the permission set they will request, published in advance so it can be checked against the store listings when they appear. Nothing is requested at install time, and each can be refused.
| Permission | Purpose | Required or optional | If you decline | Revoke on iOS | Revoke on Android |
|---|---|---|---|---|---|
| Location while using the app | Centring the map on you, and confirming site arrival without typing an address | Optional | The map opens on your depot and arrival is confirmed manually | Privacy and Security, Location Services, TRAKCORP, Never | Apps, TRAKCORP, Permissions, Location, Do not allow |
| Location in the background | Recording a journey from a phone where no unit is fitted, such as a hired vehicle | Optional | Phone journey recording is unavailable. Fitted units are unaffected | Privacy and Security, Location Services, TRAKCORP, While Using the App | Apps, TRAKCORP, Permissions, Location, Only while using the app |
| Notifications | Delivering geofence, ignition and power loss alerts the operator has configured | Optional | Alerts appear in the app, nothing is pushed to the device | Notifications, TRAKCORP, Allow Notifications off | Notifications, App settings, TRAKCORP, off |
| Camera | Photographing an asset, defect or delivery for a record | Optional | Attach from your library instead, or attach nothing | Privacy and Security, Camera, TRAKCORP off | Apps, TRAKCORP, Permissions, Camera, Do not allow |
| Photo library | Attaching an existing photograph to a job or asset record | Optional | Take a new photo instead, or attach nothing | Privacy and Security, Photos, TRAKCORP, None | Apps, TRAKCORP, Permissions, Photos and videos, Do not allow |
| Bluetooth | Reading nearby asset tags so a phone can act as a gateway for tools and small plant | Optional | Tags are seen only by fixed gateways, not by your phone | Privacy and Security, Bluetooth, TRAKCORP off | Apps, TRAKCORP, Permissions, Nearby devices, Do not allow |
| Network access | Talking to the platform, without which nothing functions | Required | Not separately prompted; granted by installing an internet application | Cellular, TRAKCORP off restricts mobile data only | Apps, TRAKCORP, Mobile data and Wi-Fi, restrict |
This table scrolls sideways on narrow screens.
Revoking takes effect immediately and deletes nothing already collected; for that, use section 14. Paths start from Settings and are correct for recent iOS and Android releases.
13. Apple App Tracking Transparency and Google Play Data Safety
Role: controller for store level disclosures
13.1 App Tracking Transparency on iOS
Apple's framework requires permission before tracking a user across apps and websites owned by other companies, or before reading the device advertising identifier. The TRAKCORP applications will do neither. We have no advertising, no advertising software development kits and no analytics that follow a user off our own product, so the applications will not present the prompt at all and their privacy labels will show no data used to track you. Location collected in the app delivers the service to the operator and is linked to the user's account because that is what makes a journey attributable, never to a cross company identifier.
13.2 Google Play Data Safety
Our Data Safety declaration will state that the application collects location, personal information limited to name and email, application activity and crash diagnostics; that it is transmitted encrypted; that it is not shared with third parties for their own purposes; that deletion can be requested through section 14; and that optional collection can be declined. That declaration and this notice come from the same inventory and must agree. If you find them disagreeing, this notice binds us, and we would like to know so we can correct the listing.
[TO CONFIRM: the final Apple privacy label and Google Play Data Safety declarations, to be reproduced here once the applications are submitted.]
14. Closing an account and deleting data
Role: controller for our records, processor for platform data
14.1 The in-app path
When the applications are published, a signed in user deletes their own account at Settings, then Account, then Delete account, confirming with their password. The same path exists in the web application. That removes the person's profile, credentials, sessions, notification tokens and preferences, but not the operator's tracking data, which belongs to the operator. An administrator closes an entire account and all its tracking data at Settings, then Organisation, then Close account, confirming by typing the organisation name.
14.2 The email route
If you cannot sign in, or would rather write, email us with the subject "Delete my account". We verify your identity under 10.9 and complete the deletion, whether or not you have used the applications.
14.3 Timing
We delete from live systems immediately and in any event within 30 days of a verified request. Encrypted backups run on a rolling 35 day cycle and we do not surgically edit them, so deleted records persist there until the backup expires, at most 35 days. During that window they are used for nothing but disaster recovery, and if a restore reinstated deleted data the deletion is reapplied immediately.
14.4 What we keep afterwards, and why
- Accounting records, six years under section 7. They hold billing contacts and amounts, not tracking data.
- The record of your request, showing it was made, verified and completed, six years, so we can demonstrate compliance under Article 5(2).
- Suppression data, the minimum needed to honour a request not to be contacted, since forgetting it would mean contacting you again.
- Anything under legal hold, where a claim, investigation or statutory duty requires preservation. We tell you that is the reason.
- Aggregated statistics that identify nobody, which are not personal data.
14.5 App stores
Removing the application deletes neither your account nor your data, and cancelling a store subscription stops future billing but deletes nothing. Use 14.1 or 14.2.
15. Personal data breaches
Role: both, with different duties in each
A personal data breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
15.1 Where we are the controller, Article 33(1)
We assess every suspected breach as soon as we become aware of it. Where it is likely to result in a risk to the rights and freedoms of individuals we notify the Information Commissioner's Office without undue delay and, where feasible, not later than 72 hours after becoming aware of it, giving reasons for any delay as Article 33(1) requires. Where notification is not required we record the reasoning, because Article 33(5) requires every breach to be documented.
15.2 Where we are the processor, Article 33(2)
We notify the affected operator without undue delay, with no 72 hour clock of our own, because their 72 hours starts when we tell them and any delay of ours consumes it. The notification states the nature of the breach, the categories and approximate numbers of individuals and records, the likely consequences, and the measures taken or proposed. We then assist with their own notification as Article 28(3)(f) requires.
15.3 Telling affected individuals, Article 34
Where a breach is likely to result in a high risk to individuals and we are the controller, we tell them without undue delay in plain language, describing the likely consequences and the measures taken. We need not where encryption rendered the data unintelligible, where later measures make the high risk unlikely, or where individual communication would involve disproportionate effort, in which case we communicate publicly instead. Where we are the processor that decision is the operator's.
15.4 Internally
We contain, assess, notify, remediate, then record. Every breach is written up with what happened, what data was involved, what we told whom and when, and what changed as a result. That record is kept six years.
15.5 Reporting something to us
Email hello@trakcorp.uk with "Security" in the subject; we acknowledge within one working day. We will not take legal action against anyone reporting a genuine vulnerability in good faith who accesses no more data than needed to demonstrate it and gives us a reasonable chance to fix it before disclosing publicly.
16. Cookies and this website
Role: TRAKCORP is the controller
This website is static and sets no cookies of its own. There is no analytics, tag manager, advertising pixel or consent banner, because there is nothing to consent to. Google Fonts is loaded from fonts.googleapis.com and fonts.gstatic.com, so your browser requests them from Google and Google receives your IP address and user agent. Full detail, including what Cloudflare may set for security, is on the cookies page.
17. Automated decision making and profiling
Role: both
We make no decisions about you based solely on automated processing producing legal effects or similarly significant effects, within the meaning of Article 22.
The platform does generate automated outputs: a geofence entry event, an idle time calculation, a utilisation figure. Those are measurements, not decisions. If an operator uses one to decide something about a person, for example in a disciplinary process, the decision is the operator's, made by a human being, and the operator is responsible for it. We do no profiling for marketing, credit or risk scoring.
18. Children
Role: both
The platform and this website are business tools. They are not directed at children, we do not knowingly collect children's personal data, and the applications will be rated accordingly on both stores. If you believe a child's data has reached us, tell us and we will delete it.
19. Changes to this notice
Role: both
This is version 1.0, effective 7 August 2026. When we change it we update the version and effective date at the top of the page. Where a change materially affects how we handle your data, for example a new purpose, lawful basis or sub-processor with access to platform data, we tell affected operators and account holders by email at least 30 days before it takes effect. Editorial corrections are made without notice. We will not treat data we already hold differently on the strength of a changed notice alone where the law requires a fresh basis or consent.
20. Contacting us and complaining to the ICO
Role: both
20.1 Contacting us
Email is the only contact route we operate. Write to hello@trakcorp.uk, or post to TRAKCORP LTD, 12 Heritage Mews, Mill Road, Great Yarmouth, NR31 0HW. We aim to reply within three working days, and to data protection requests within the periods in 10.10. The registered office is an address for service of documents, not a staffed office, so please write rather than travel to it.
We have not appointed a data protection officer. Article 37 does not require one here: our core activities are not large scale regular and systematic monitoring on our own account, and we process no special category data on a large scale. If that changes we will appoint one and publish the details here.
20.2 If you are unhappy with our response
Tell us first and say what you think we got wrong. Complaining to us does not affect your right to go to the regulator.
20.3 Complaining to the Information Commissioner
You have the right to complain to the Information Commissioner's Office, the United Kingdom's supervisory authority, under Article 77 of the UK GDPR:
- Information Commissioner's Office
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Telephone: 0303 123 1113
- Website: ico.org.uk/make-a-complaint
You also have the right to an effective judicial remedy under Article 79 and to compensation under Article 82.
This notice was written for TRAKCORP LTD, company number 17005499, and describes that company only. It is not legal advice to anyone else.