Privacy Policy
Last updated: 16 September 2026
Document Reference: TCH-UK-PRIV-2026-V1
Statutory Framework: UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018 (DPA 2018), Privacy and Electronic Communications Regulations (PECR).
1. Statutory identification & regulatory status
1.1 Data Controller & Operator Identity: This Privacy Policy governs the processing of personal data by Tachyo LTD, a private limited company incorporated under the laws of England and Wales, registered under Company Number 12356231, with its registered office situated at 20 South Street, Doncaster, England, DN4 5FH ("Tachyo", "we", "us", or "our").
1.2 Supervisory Authority Registration: Tachyo LTD maintains formal notification and registration with the Information Commissioner's Office (ICO) in the United Kingdom as a fee-paying controller and processor under the Data Protection (Charges and Information) Regulations 2018.
1.3 Data Protection Officer & Point of Contact: Inquiries regarding statutory data rights, exercise of Articles 15–22 UK GDPR privileges, or regulatory requests must be directed to:
- Direct Email: privacy@tachyo.co.uk
- Postal Address: Data Protection Officer, Tachyo LTD, 20 South Street, Doncaster, DN4 5FH.
2. Dual-capacity operating framework (controller vs. processor)
The legal status of Tachyo LTD fundamentally bifurcates depending on the specific category of personal data and the commercial context of collection:
2.1 Tachyo as an Independent Data Controller (Account & Billing Data): Tachyo LTD acts as an independent Data Controller pursuant to Article 4(7) of the UK GDPR with respect to:
- (a) Direct customer registration, administrative credentials, corporate contact identities, and Transport Manager authorization records;
- (b) Commercial payment processing tokens, invoicing records, VAT registrations, and transaction audit trails;
- (c) Direct customer support transcripts, platform usage diagnostics, telemetry crash reports, and system telemetry logs;
- (d) Marketing communications governed strictly by PECR and opted-in commercial correspondence.
2.2 Tachyo as a Data Processor (Customer Fleet & Telematics Operations): Tachyo LTD acts strictly as a Data Processor pursuant to Article 4(8) of the UK GDPR on behalf of the commercial Customer (the Haulier, Logistics Operator, or Carrier) who acts as the primary Data Controller with respect to:
- (a) Driver mobile application telematics, including real-time GPS coordinates, route histories, and speed pings;
- (b) Driver shift timestamps, continuous driving counters, tachograph advisory calculations, and Working Time Directive (WTD) intervals;
- (c) Driver photographic defect submissions (walkaround checks), uploaded fuel receipts, pump receipts, and vehicle registration linkage;
- (d) Subcontractor, agency worker, or PAYE driver payroll rate attributions and route yields.
2.3 Absence of Direct Driver Employment Nexus: Tachyo LTD maintains no direct contractual, employment, or agency nexus with individual drivers operating mobile telematics endpoints. The commercial Customer warrants that it maintains lawful basis under Article 6 of the UK GDPR to instruct Tachyo LTD to process driver personal data.
3. Exhaustive taxonomy of processed data
Tachyo LTD collects and processes distinct categories of electronic, visual, and spatial information across the web platform and native driver mobile interfaces:
3.1 Account & Identity Records:
- (a) Full legal name, corporate trade name, job title, and transport role (e.g., Operator Licence Holder, Transport Manager, Traffic Dispatcher, Driver);
- (b) Business contact details, including corporate physical address, dispatch depot postcodes, business email address, and mobile dispatch telephone numbers;
- (c) Encrypted password hashes, session cookies, multi-factor authentication (MFA) tokens, and IP audit trails.
3.2 Real-Time Spatial & Device Telematics (GPS & Hardware Data):
- (a) High-frequency Global Navigation Satellite System (GNSS/GPS) coordinates, including latitude, longitude, altitude, horizontal accuracy tolerances, and bearing;
- (b) Telematics vector calculations, including calculated road speeds (mph), acceleration curves, idling stationary states, and depot geofence entry/exit pings;
- (c) Mobile hardware diagnostics: hardware model (e.g., iPhone 15, Samsung Galaxy), operating system version, mobile network operator, battery level percentage, and location permission state (Always, While Using, Denied).
3.3 Compliance & Working Hours Telemetry:
- (a) Shift start, pause, rest, and termination timestamps recorded via manual driver touch-event or telemetry shift triggers;
- (b) Segmented calculation arrays: continuous driving duration (EC 561/2006 4.5-hour counter), cumulative rest periods, 6.0-hour WTD continuous duty counters, and daily shift span (13h/15h spreadover tracking);
- (c) Assigned tractor unit registrations (VRM), trailer identification plates, and digital coupling events.
3.4 Visual Evidence, Image Metadata & OCR Extraction:
- (a) Photographic walkaround defect captures submitted via device camera (e.g., cracked lenses, tyre bulges, bodywork damage);
- (b) Exchangeable Image File Format (EXIF) metadata embedded within uploaded images, including hardware camera specs, timestamps, and embedded GPS location stamps at the moment of photo capture;
- (c) Commercial fuel and lubricant purchase receipts uploaded for expense tracking;
- (d) Optical Character Recognition (OCR) raw text vectors extracted from fuel pump dockets, including date, fuel volume (litres), total financial value (£ GBP), and vendor VAT registration numbers.
4. Statutory lawful bases for data processing (Article 6 UK GDPR)
Under Section 8 of the Data Protection Act 2018 and Article 6(1) of the UK GDPR, Tachyo LTD relies on distinct legal bases to justify the capture and retention of data across its services:
4.1 Performance of Commercial Contract (Article 6(1)(b) UK GDPR):
- (a) Provision of the Tachyo Software-as-a-Service (SaaS) web panel, maintenance of active enterprise tenants, and administrative user identity management;
- (b) Real-time routing of mobile check-in telemetry from driver field units to authorized operator dispatch cockpits;
- (c) Calculation of delivery yields, load matching against carrier CSV/XLSX manifests, and generation of driver gross margin tables.
4.2 Compliance with Statutory & Regulatory Obligations (Article 6(1)(c) UK GDPR):
- (a) Processing transaction ledgers, VAT documentation, and billing manifests pursuant to the Value Added Tax Act 1994 and UK corporate taxation accounting mandates;
- (b) Providing auditable roadworthiness logs, roller brake test records, and defect rectifications necessary for the Customer to discharge duties under the Goods Vehicles (Licensing of Operators) Act 1995 and Driver and Vehicle Standards Agency (DVSA) statutory maintenance guidelines;
- (c) Facilitating compliance with tachograph and driving hours verification pursuant to Retained Regulation (EC) 561/2006 and the Road Transport (Working Time) Regulations 2005.
4.3 Legitimate Commercial Interests (Article 6(1)(f) UK GDPR):
- (a) Algorithmic heuristics applied to raw defect inputs to prioritize workshop triage (e.g., immediate Vehicle Off Road [VOR] grounding notices);
- (b) Security monitoring, network penetration prevention, denial-of-service mitigation, and IP abuse prevention;
- (c) Aggregated, fully anonymized statistical analysis of component failure rates across HGV classes to improve predictive maintenance algorithms (with all vehicle registrations and corporate identifiers scrubbed).
4.4 Operator's Lawful Basis for Employee / Subcontractor Telematics:
- (a) Tachyo LTD does not rely on individual worker "Consent" (Article 6(1)(a)) due to the systemic imbalance of power inherent in employment and agency relationships, as recognized by the Information Commissioner's Office (ICO);
- (b) The Customer warrants that its telematics surveillance is justified under its own Legitimate Interests Assessment (LIA), statutory transport compliance obligations, or formal workforce Data Protection Impact Assessment (DPIA) prior to provisioning the Tachyo Driver application to any driver.
5. Device hardware, GPS telematics & operating system boundary
This section sets out the explicit operational boundary between the Tachyo mobile software layer and the underlying mobile device hardware (Apple iOS and Google Android).
5.1 Device Permissions Architecture:
- (a) Fine Location Services (GNSS/GPS): the mobile application requires permission to access high-accuracy GPS coordinates (
ACCESS_FINE_LOCATIONon Android;kCLAuthorizationStatusAuthorizedAlwaysorkCLAuthorizationStatusAuthorizedWhenInUseon iOS). - (b) Foreground & Background Tracking: continuous route calculations and geofence pings require background execution capability to prevent data loss while navigation software or camera apps run concurrently.
5.2 Operational Tracking Scope & Hardware Dissociation:
- (a) Active Duty Binding: Tachyo's software engine is programmatically instructed to process and record GPS telemetry vectors exclusively during an active duty shift (from the moment a driver confirms "Start Shift" or "Asset Check-In" until the driver executes "End Shift").
- (b) Hardware Level Persistence: the Customer and the Driver acknowledge that modern mobile operating systems control low-level location chipsets independently. While the Tachyo application halts the recording, processing, and database storage of geographic coordinates upon "End Shift", complete hardware-level decoupling requires the device user to toggle off location permissions in device system settings.
- (c) Strict Exclusion of Post-Shift Processing: Tachyo LTD covenants that it does not inspect, process, log, monetize, or provide to the Transport Manager any geographic location data received outside an active shift state. Any raw location packets pinged while a shift is inactive are dropped at the edge gateway without persistence.
5.3 Camera & Local Media Storage Boundaries:
- (a) Device camera permissions are accessed strictly upon deliberate user initiation to capture visual proof of physical vehicle defects or fuel purchase dockets;
- (b) The application does not maintain persistent background access to the camera hardware or unrelated photo library assets outside the designated capture container.
6. Data residency, security & storage architecture
6.1 Territorial Data Residency (United Kingdom):
- (a) All primary databases, transaction logs, telematics records, and uploaded image files are hosted exclusively within the United Kingdom;
- (b) Physical infrastructure is provisioned through Supabase Inc. utilizing Amazon Web Services (AWS) in the London Region (eu-west-2);
- (c) Tachyo LTD guarantees that zero Customer personal data, driver location coordinates, or compliance dockets are transferred outside the territorial boundaries of the United Kingdom, eliminating cross-border transfer mechanisms under Chapter V of the UK GDPR.
6.2 Cryptographic & Technical Safeguards:
- (a) Data in Transit: all communications between client browsers, native driver mobile endpoints, and the API gateway are encrypted using Transport Layer Security (TLS 1.3), enforcing HTTP Strict Transport Security (HSTS);
- (b) Data at Rest: database storage volumes, database backups, and media buckets are secured using Advanced Encryption Standard (AES-256);
- (c) Access Governance: production database access is governed by strict Role-Based Access Control (RBAC), multi-factor hardware security keys (FIDO2), and automated audit trails.
6.3 Data Minimization & Retention Schedules:
- (a) Fleet Safety Inspections & VOR Records: retained for fifteen (15) months in accordance with DVSA statutory guide to maintaining roadworthiness;
- (b) Driver Working Time & Duty Counters: retained for twenty-four (24) months to fulfill statutory inspection criteria under the Road Transport (Working Time) Regulations 2005;
- (c) Financial & Billing Manifests: retained for six (6) full financial years plus the current operating year pursuant to Section 388 of the Companies Act 2006 and HMRC requirements;
- (d) Raw GPS Coordinate Breadcrumbs: pruned or consolidated into generalized route vectors after ninety (90) days, unless an open insurance claim or active accident report mandates preservation.
7. Authorized third-party sub-processors & infrastructure partners
Tachyo LTD maintains formal Data Processing Agreements containing statutory Article 28 UK GDPR commitments with all downstream service providers:
7.1 Supabase Inc. (Database & Authentication Engine):
- Function: Database hosting, edge compute, and user identity management.
- Location: Dedicated infrastructure deployed in AWS London (eu-west-2), UK.
7.2 Machine-Vision OCR Processing Engine:
- Function: Parsing numerical text from fuel receipt images.
- Security Commitment: Image streams processed ephemerally within the AWS London perimeter without permanent retention of raw imagery outside Tachyo's encrypted storage.
8. Data subject rights, inquiries & subject access requests (SARs)
Under Chapter III of the UK GDPR and the Data Protection Act 2018, individuals possess statutory entitlements regarding their personal data. The operational mechanics for executing these rights depend strictly on whether Tachyo LTD acts as an independent Controller or as a technical Processor.
8.1 Scope of Statutory Rights:
- (a) Right of Access (Article 15 UK GDPR): The entitlement to obtain formal confirmation as to whether personal data is being processed and receive a structured copy of all associated records.
- (b) Right to Rectification (Article 16 UK GDPR): The entitlement to mandate the correction of inaccurate personal data or completion of incomplete operational records.
- (c) Right to Erasure / "Right to be Forgotten" (Article 17 UK GDPR): The right to request the irreversible deletion of personal data, subject to the statutory retention exclusions detailed in Clause 8.4.
- (d) Right to Restriction of Processing (Article 18 UK GDPR): The right to freeze the active processing of records during ongoing disputes regarding accuracy or lawful basis.
- (e) Right to Data Portability (Article 20 UK GDPR): The entitlement to receive personal data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON).
- (f) Right to Object (Article 21 UK GDPR): The entitlement to challenge data processing predicated upon Legitimate Interests under Article 6(1)(f).
8.2 Processing Subject Access Requests for Direct Account Data (Tachyo as Controller):
- (a) Transport Managers, enterprise account holders, and administrative personnel exercising rights over billing, account credentials, or corporate communications must submit a formal request via email to privacy@tachyo.co.uk.
- (b) Tachyo LTD shall confirm receipt within five (5) business days and complete identity verification using multi-factor cryptographic credentials.
- (c) Compliant disclosures shall be executed without undue delay and at the latest within one (1) calendar month of receipt, extensible by two (2) further months for complex enterprise queries in accordance with Article 12(3) UK GDPR.
8.3 Protocol for Employed, Subcontracted, and Agency Drivers (Tachyo as Processor):
- (a) Where a commercial driver (whether employed via PAYE, engaged as an independent subcontractor, or supplied via an employment agency) submits a SAR directly to Tachyo LTD concerning telematics, GPS traces, fuel receipts, or shift logs, Tachyo LTD acts strictly as a Data Processor.
- (b) Tachyo LTD possesses neither the lawful authority nor the independent legal entitlement to alter, disclose, or delete Customer-controlled operational records without express written authorization from the primary Data Controller (the Haulier / Transport Operator).
- (c) Routing SLA: Tachyo LTD covenants to notify and forward any driver-originated SAR or inquiry to the designated Transport Manager of the relevant Customer within three (3) business days of electronic receipt.
- (d) Tachyo LTD shall provide technical tooling enabling the Customer to extract, export, or redact driver records to fulfill statutory deadlines, but legal accountability for timely response rests exclusively with the Customer.
8.4 Statutory Precedence Over Erasure Requests (Legal & Regulatory Overrides):
- (a) The Right to Erasure under Article 17 is expressly curtailed where continued retention is necessary for compliance with a legal obligation or the establishment, exercise, or defence of legal claims pursuant to Article 17(3)(b) and (e) UK GDPR.
- (b) Requests by drivers to purge shift timestamps, telematics traces, or defect audit logs shall be refused to the extent that such records are mandated for preservation by:
- (i) The Goods Vehicles (Licensing of Operators) Act 1995 (15-month roadworthiness inspection preservation);
- (ii) The Road Transport (Working Time) Regulations 2005 (24-month working time enforcement);
- (iii) The Limitation Act 1980 (statutory 6-year period for commercial contract and tortious negligence claims).
9. Automated processing, algorithmic heuristics & profiling (Article 22 UK GDPR)
This section formally defines the mathematical and heuristic nature of the Tachyo platform to disclaim the existence of solely automated legal decision-making.
9.1 Absence of Solely Automated Determinations:
- (a) Tachyo LTD does not execute automated decision-making processes that produce legal effects concerning individuals or similarly significantly affect them within the statutory definition of Article 22(1) UK GDPR.
- (b) The software does not automatically levy disciplinary sanctions, adjust contractual remuneration rates, or terminate driver access tokens without human intervention.
9.2 Algorithmic Triage & Heuristic UI Indicators:
- (a) The platform applies deterministic algorithms to raw input data to generate advisory visualizations, specifically utilizing:
- (i) Red (#CC0000) for "Critical VOR" states where an unresolved major defect or an overdue inspection (≤ 0 days) is detected;
- (ii) Amber (#F59E0B) for "Action Required / Due Soon" states within user-configured threshold envelopes;
- (iii) Emerald (#10B981) for "Compliant" states where operational tolerances remain within configured parameters.
- (b) These heuristic classifications represent computational summaries of stored database records and do not constitute autonomous expert determinations.
9.3 Mandatory "Human-in-the-Loop" Operational Architecture:
- (a) Any operational action that impacts vehicle roadworthiness, legal compliance, or driver duty status mandates an affirmative manual action by a qualified human operator (e.g., driver walkaround verification, Transport Manager sign-off, or certified workshop clearance).
- (b) The customer acknowledges that Tachyo's algorithms function as operational decision-support software and that sole professional accountability for vehicle release rests with the Operator Licence holder.
9.4 Margin, Yield & Performance Calculations:
- (a) Calculations displayed within profitability and driver yield dashboards (e.g., gross margin percentages, hourly revenue yield, fuel efficiency indicators) are arithmetic aggregations derived from uploaded carrier manifests, shift timestamps, and approved fuel receipts.
- (b) Such calculations serve analytical operational purposes only and must be independently audited by the Customer before implementation in payroll systems or statutory tax filings.
10. Personal data breach management & incident notification
Tachyo LTD maintains rigorous incident response protocols aligned with the Data Protection Act 2018 and National Cyber Security Centre (NCSC) guidance.
10.1 Definition of a Security Incident: A personal data breach constitutes any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed within the AWS London infrastructure.
10.2 Processor-to-Controller Notification Protocols (Article 33(2) UK GDPR):
- (a) Upon confirming a personal data breach affecting Customer fleet, telematics, or driver data, Tachyo LTD shall notify the primary account administrator and designated Transport Manager without undue delay, and in any event within forty-eight (48) hours of formal confirmation.
- (b) The notification shall detail:
- (i) The nature and technical vector of the personal data breach;
- (ii) The approximate categories and volume of data subjects and telematics records implicated;
- (iii) The identity and contact coordinates of the Data Protection Officer;
- (iv) Immediate mitigation measures implemented to contain the security incident;
- (v) Recommended containment actions for the Customer.
10.3 Direct Supervisory Reporting (Tachyo as Controller — Article 33(1) UK GDPR): Where a confirmed breach occurs concerning data for which Tachyo LTD acts as an independent Controller (e.g., administrative account credentials, billing tokens, corporate identity data), Tachyo LTD shall formally notify the Information Commissioner's Office (ICO) within seventy-two (72) hours of becoming aware of the event, unless the breach is assessed as unlikely to result in a risk to the rights and freedoms of natural persons.
10.4 Forensic Preservation & Remediation Commitments: Tachyo LTD shall preserve all relevant network audit trails, server access logs, and edge firewall records within its AWS London perimeter for forensic analysis and provide reasonable technical assistance to Customers in discharging their notification obligations under Article 34 UK GDPR.
11. Statutory disclosures, law enforcement & regulatory cooperation
11.1 Subpoenas, Court Warrants & Judicial Orders:
- (a) Tachyo LTD shall not disclose personal data to third parties except where compelled to do so by a valid order issued by a court of competent jurisdiction within England and Wales (including the High Court, Crown Court, or County Court).
- (b) Prior to executing any judicial disclosure, Tachyo LTD shall review the legal validity of the warrant with external legal counsel and, where legally permissible, provide prompt written notification to the affected Customer to enable them to seek protective relief.
11.2 Regulatory Oversight (DVSA & Traffic Commissioners):
- (a) The Customer acknowledges that records stored within the Tachyo platform concerning vehicle maintenance, defect rectification, and driver hours may be subject to inspection by the Driver and Vehicle Standards Agency (DVSA) or formal request by a Traffic Commissioner for Great Britain under the Goods Vehicles (Licensing of Operators) Act 1995.
- (b) Tachyo LTD provides self-service export utilities to enable Customers to produce required compliance packs during statutory audits or Public Inquiries (PI).
11.3 Police Investigations & Road Traffic Incident Inquiries:
- (a) Under Schedule 2, Part 1, Paragraph 2 of the Data Protection Act 2018, Tachyo LTD may process and disclose specific telematics records (e.g., historical GPS breadcrumbs, speed vectors, or shift logs) to Police forces in England, Wales, or Police Scotland where:
- (i) The request is formally submitted via an official Section 29 / Schedule 2 Data Protection Request Form signed by an authorized Police Officer;
- (ii) The disclosure is strictly necessary for the prevention or detection of crime, or the apprehension or prosecution of offenders (e.g., investigation of fatal or serious road collisions under the Road Traffic Act 1988).