1. Introduction
FluxTrackOS (“the Platform”, “we”, “us”, “our”) is a multi-tenant fleet tracking platform operated by Hillmorton Design & Development (“the Company”). This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our web portal, mobile application, and API services (collectively, “the Services”).
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), the Data Protection Act 2018, and all other applicable data protection legislation.
2. Data Controller
The data controller for information processed through FluxTrackOS is:
Hillmorton Design & Development
Privacy: [email protected]
Security: [email protected]
Website: hillmortondnd.co.uk
Where the Platform is used by an organisation (a “Tenant”), that Tenant may act as a joint controller or independent controller for data processed through their tenancy, depending on the circumstances. In such cases, Tenants are responsible for ensuring they have a lawful basis to process their employees’ or drivers’ data through the Platform.
3. Data We Collect
3.1 Account & Identity Data
Single Sign-On (SSO) is handled by our own OpenID Connect (OIDC) implementation. The only supported identity providers are Microsoft 365 / Entra ID and Google Workspace. When you sign in, we receive:
- Email address
- Display name
- External authentication provider ID
- Role within your organisation (admin, manager, operator, driver)
We do not collect or store passwords. Authentication is delegated entirely to your identity provider.
3.2 Location Data
The FluxTrackOS mobile application collects GPS coordinates when a driver starts and ends a journey. Specifically:
- Latitude, longitude, and accuracy at journey start
- Latitude, longitude, and accuracy at journey end
- Timestamp of each location capture
Location data is collected only at discrete events (start/end of a journey), not continuously. The mobile app requests explicit consent before accessing location services, and drivers can review this consent at any time.
3.3 Journey Data
- Journey start and end timestamps
- Journey duration
- Key location notes (e.g., site name or address)
- General notes added by the driver
- Job type classification
- Journey status (started, completed, cancelled)
- Photographs taken at journey start and/or end (if captured by the driver)
3.4 Vehicle Data
- Vehicle registration number
- Vehicle metadata (make, model, year, colour, fuel type) — sourced from DVLA vehicle lookup
- Vehicle status (available, in transit, maintenance, retired)
- Last-known location (encrypted)
- Vehicle type classification
3.5 Device & Technical Data
- IP address (for rate limiting and audit logs)
- Browser user agent string
- Device type and operating system (from the mobile application)
- NFC tag identifiers (when scanning vehicle NFC tags)
3.6 Audit Logs
We maintain audit logs of security-relevant actions performed on the Platform, including:
- User ID and action type
- Resource accessed or modified
- IP address and user agent
- Timestamp
4. How We Use Your Data
| Purpose | Lawful Basis (GDPR Art. 6) |
|---|---|
| Providing and operating the Platform | Performance of a contract (Art. 6(1)(b)) |
| Authenticating users via SSO | Performance of a contract (Art. 6(1)(b)) |
| Recording driver journeys and vehicle movements | Legitimate interests of the Tenant in fleet management (Art. 6(1)(f)) |
| Processing location data for journey logging | Consent (Art. 6(1)(a)) — obtained via the mobile app |
| Sending email notifications on journey completion | Legitimate interests (Art. 6(1)(f)) |
| Maintaining audit logs for security and compliance | Legitimate interests (Art. 6(1)(f)) |
| Rate limiting and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Enforcing vehicle retention and legal holds | Legal obligation (Art. 6(1)(c)) |
| Providing technical support to Tenants via consent-based support key access | Legitimate interests (Art. 6(1)(f)) — providing contracted support services, with Tenant-initiated consent safeguard |
5. Data Storage & Security
5.1 Hosting Location
All data is stored on servers operated by Netcup GmbH, located in Germany (European Union). Netcup GmbH is fully GDPR-compliant and holds multiple security and compliance certifications. You can review their certifications at netcup.com/en/about-netcup/certifications. No personal data is transferred outside the European Economic Area (EEA) or the United Kingdom unless specifically disclosed in this policy.
5.2 Encryption
- In transit: All data is transmitted over HTTPS (TLS 1.2+).
- At rest: Sensitive data — including GPS coordinates, location notes, and last-known vehicle positions — is encrypted using AES-256-GCM with tenant-specific encryption keys.
- Key management: Encryption keys are managed via the OVHcloud Key Management Service (KMS), a KMIP-compatible managed service with encrypted backups across multiple regions. Keys are isolated per tenant. You can review OVHcloud’s compliance certifications at ovhcloud.com/en-gb/compliance.
5.3 Security Standards & Privacy Governance
Hillmorton Design & Development operates in alignment with the principles and controls of Cyber Essentials, ISO 27001 (Information Security Management), and ISO/IEC 27701 (Privacy Information Management). While we have not yet obtained formal certification for these standards, we actively implement their recommended controls across our infrastructure, development practices, and operational procedures. We are committed to pursuing formal certification as the business scales.
As part of our ISO 27701 alignment, we maintain the following governance artefacts:
- Data Protection Impact Assessment (DPIA) covering all high-risk processing activities
- Record of Processing Activities (ROPA) per GDPR Article 30
- Incident Response Plan with defined breach notification procedures aligned to the GDPR 72-hour reporting requirement
- Automated data retention with configurable per-tenant retention periods and erasure workflows
A designated Privacy Lead within Hillmorton Design & Development is responsible for overseeing data protection compliance, maintaining these governance documents, and serving as the point of contact for data protection enquiries. For privacy matters, contact [email protected].
5.4 Multi-Tenant Isolation
FluxTrackOS enforces strict data isolation between tenants using PostgreSQL Row-Level Security (RLS) policies. Each tenant’s data is logically separated at the database level, ensuring no tenant can access another tenant’s data.
5.5 Access Controls
- Role-based access control (RBAC) with four levels: admin, manager, operator, and driver
- API rate limiting per user and per tenant to prevent abuse
- Mobile app supports biometric authentication (fingerprint / Face ID) via device-native security
5.6 Platform Support Access
When a Tenant requests technical support, FluxTrackOS staff may need to access that Tenant’s data to diagnose and resolve issues. This access is governed by a consent-based support key mechanism:
- Each Tenant is assigned a unique support key, visible to Tenant Admins and Managers via the web portal under Settings → Support.
- FluxTrackOS staff cannot access a Tenant’s data unless the Tenant voluntarily provides their support key to our staff. Access is never initiated unilaterally by FluxTrackOS.
- Once a support key is verified, the staff member is granted read access to the Tenant’s data for a maximum of 8 hours, after which access automatically expires.
- Tenants can revoke access at any time by regenerating their support key, which immediately invalidates the previous key and any active access grants.
- All support key verifications, failed verification attempts, and key regeneration events are recorded in the platform audit log, including the identity of the staff member, timestamp, and IP address.
When accessing Tenant data for support purposes, FluxTrackOS staff may view organisation details, user information, vehicle records, journey history, audit logs, and tenant settings. Staff are bound by internal data handling policies and access data solely for the purpose of resolving the Tenant’s support request.
6. Data Sharing
We do not sell your personal data. We may share data with:
- Your Tenant organisation: Admins and managers within your organisation can view journey records, vehicle data, and driver activity as permitted by their role.
- FluxTrackOS support staff: When a Tenant Admin provides their support key to our staff, authorised FluxTrackOS personnel may access the Tenant’s data solely to resolve the support request. Access is time-limited (8 hours), audited, and revocable by the Tenant at any time (see section 5.6).
- Identity providers: Microsoft 365 / Entra ID or Google Workspace for authentication — limited to authentication tokens and basic profile information.
- DVLA: Vehicle registration numbers are sent to DVLA for vehicle data enrichment (make, model, year, colour, fuel type).
- Infrastructure providers: Netcup GmbH (hosting) and OVHcloud (encryption key management), both acting as data processors under Data Processing Agreements.
- Email provider: Transactional emails (journey completion notifications) are sent via our email service. Only the recipient email address and notification content are shared.
- Law enforcement: Where required by law or valid legal process.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy. Automated retention processes enforce the following defaults, which Tenant administrators may adjust via Platform settings:
- Journey records: Automatically purged after the tenant-configured retention period (default: 365 days for completed/cancelled journeys). Tenants can adjust this via Platform settings.
- Audit logs: Retained for a minimum of 12 months for security and compliance purposes, then automatically purged.
- Account data: Retained for the duration of the user’s active account. Driver accounts inactive for 90+ days (configurable) are automatically soft-deleted. Full deletion occurs within 30 days of account closure or upon processing an approved erasure request, unless a legal obligation requires longer retention.
- Vehicle data: Retained while the vehicle is active on the Platform. Vehicles placed under a legal hold are retained until the hold is released.
- Erasure requests: Approved erasure requests are automatically processed after a configurable grace period (default: 14 days), resulting in the permanent deletion of all associated user data.
8. Your Rights Under GDPR
You have the following rights in relation to your personal data:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate personal data.
- Right to erasure (Art. 17): Request deletion of your personal data, subject to legal obligations.
- Right to restriction of processing (Art. 18): Request that we limit the processing of your data.
- Right to data portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)): Where processing is based on consent (e.g., location data), you may withdraw consent at any time via the mobile app settings or by contacting us.
8.1 Exercising Your Rights
You can exercise your data subject rights in two ways:
- Self-service via the Platform: Authenticated users can access the Data Subject Rights API to view a summary of data held about them, export all their personal data in machine-readable JSON format, and submit erasure requests directly through the Platform.
- By email: Contact us at [email protected] and we will respond within one calendar month as required by GDPR.
Tenant administrators can also export data and process erasure requests on behalf of users within their organisation.
9. Cookies & Local Storage
The FluxTrackOS web portal uses essential cookies and local storage for:
- Authentication session cookies: Required to maintain your signed-in session (strictly necessary).
- CSRF protection tokens: Used to protect against cross-site request forgery attacks (strictly necessary).
We do not use tracking cookies, analytics cookies, or third-party advertising cookies. The mobile application stores consent records and authentication tokens in platform-native secure storage: on Android, values are encrypted with AES-256-GCM using a key held in the Android Keystore; on iOS, they are held in the iOS Keychain, restricted to this device and unavailable until the device has been unlocked at least once after restart.
10. International Data Transfers
Your data is processed and stored within the European Union (Germany). Where authentication services involve data routing through providers outside the EEA (e.g., Microsoft 365 / Entra ID or Google Workspace), these transfers are covered by Standard Contractual Clauses (SCCs) or an adequacy decision by the European Commission.
11. Children’s Privacy
FluxTrackOS is a business-to-business platform intended for use by organisations and their employees. We do not knowingly collect data from individuals under the age of 18. If you believe a child has provided personal data to us, please contact us at [email protected] and we will delete the data promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the Platform or by email. The “Last updated” date at the top of this page will always reflect the most recent revision. Continued use of the Services after changes constitutes acceptance of the revised policy.
13. Contact & Complaints
If you have questions about this Privacy Policy or wish to exercise your data protection rights, contact us:
Privacy: [email protected]
Security: [email protected]
If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority. In the United Kingdom, this is the Information Commissioner’s Office (ICO):