MV Fleet ComplianceMV Fleet Compliance
TermsPrivacyCookiesData ProcessingSub-processorsData complaint
Data protection

Privacy Notice

How MV Fleet Compliance handles account, business and customer-controlled operational information.

1. About this notice

This notice explains how trading as handles personal information. It also explains the important distinction between information MV uses for its own purposes and information a transport operator controls inside its customer account.

Privacy Notice version: .

2. When MV is the controller

MV acts as controller for information used to operate its own business and relationship with customers, including account-holder/contact details, enquiries, contracts, billing and subscription administration, Stripe customer/subscription identifiers and payment-status records, support communications, service security, audit/security logs and legal/compliance records. Full card numbers and bank account details entered into Stripe Checkout or the Stripe Customer Portal are handled by Stripe and are not stored in the MV Fleet Compliance application.

We also act as controller for optional analytics about visits to selected public MV Fleet Compliance pages. Google Analytics is loaded only after the visitor accepts analytics. We use this to understand public website traffic and improve the public service journey. Our implementation does not intentionally send form-field values and strips query strings/fragments from page locations before analytics transmission. Google Analytics is not included inside the secure customer portal, MV Admin area or driver app.

Depending on the purpose, our lawful bases may include performance of a contract, steps requested before entering a contract, compliance with legal obligations and legitimate interests in operating and protecting a business software service. Where we use optional public-site analytics that requires consent, we rely on the visitor’s consent and they can withdraw it through Cookie settings without affecting access to the service. If we later send optional direct marketing that requires consent, that consent will be requested separately.

3. When the operator is the controller and MV is the processor

For most operational fleet and workforce information stored by a customer — such as driver records, licence details, driver cards, training, medical/eyesight records, walkarounds, defects, photographs, timesheets, holiday/expense information and maintenance evidence — the customer operator determines why the data is collected and how it is used. The operator is therefore normally the controller and MV processes the data to provide the platform on the operator’s instructions.

The Data Processing Addendum sets out the processor terms.

4. Special-category and higher-risk information

Driver medical, health and payroll payment information needs extra care.

Health information is special-category personal data. Where a customer chooses to record medical declarations, health restrictions or related evidence, the customer must identify an appropriate UK GDPR Article 6 lawful basis and an applicable Article 9 condition and must limit access to people who genuinely need it. MV processes such information only to provide the service and according to the controller’s instructions, except where law requires otherwise.

Where optional payroll payment details are collected, customers should restrict access to authorised payroll/management users and use them only for legitimate payment administration.

5. Information we may process

  • Names, contact information, job titles and account identifiers.
  • Company, Operator Licence, operating-centre, fleet and maintenance information.
  • Driving licence information, DVLA-check records, DQC and tachograph-card information.
  • Driver medical and eyesight information where the customer chooses to use those functions.
  • Training/onboarding records, signatures, photographs and uploaded evidence.
  • Walkaround, defect, maintenance, PMI, brake-test, MOT, tax, recall and wheel re-torque records.
  • Timesheet, holiday, expense and fuel records where those modules are used.
  • Optional payroll payment details supplied by a driver for the customer operator, including account-holder name, bank/building society, sort code and account number. These details are intended for authorised operator/payroll use and are not shown in ordinary driver lists.
  • Technical security data such as login/session information, audit records, device/browser information and IP-related security records where required to protect the service.
  • Where analytics consent is given on public pages: pseudonymous Google Analytics identifiers, page/path viewed (without our page query strings/fragments), referrer path, browser/device characteristics and related visit/session information used for website statistics.

6. Who receives information

Information may be processed by authorised MV personnel and carefully selected service providers used for hosting, database/authentication/storage, subscription billing and payments, email, device notification delivery and — where public-site analytics consent is given — Google Analytics. The current public list is on our Sub-processors page. More detail on analytics choices is in the Cookie & Device Storage Notice. We may also disclose information where required by law, regulators, courts or to establish, exercise or defend legal claims.

7. International processing

Some technology providers may process or make support/technical services available from outside the UK. Where UK data-protection law requires an international-transfer mechanism, we require an appropriate safeguard or rely on another lawful transfer basis. Customers can contact us for current sub-processor/transfer information relevant to their account.

8. Retention

We do not keep personal information indefinitely merely because storage is available. Controller-side account, contract, support, security and financial records are retained according to their purpose and applicable legal requirements. Customer-controlled operational data is retained while the account is active and afterwards in accordance with the customer’s instructions, contractual exit arrangements, backup cycles and legal requirements. Different transport records may have different regulatory retention needs, so the operator remains responsible for setting/confirming appropriate operational retention periods.

9. Security

MV uses layered technical and organisational controls including authenticated user accounts, company access separation, role-based access, database row-level security, private document storage, HTTPS, audit/history records and protected server secrets. No internet service can promise absolute security, so customers must also manage authorised users, devices and credentials appropriately.

See our Security overview.

10. Your data-protection rights

Depending on the circumstances, people may have rights of access, rectification, erasure, restriction, portability and objection, and rights relating to certain automated decisions. Where MV is only a processor for an operator, we may refer a rights request to that operator because it is the controller responsible for deciding the request.

11. Complaints

You can raise a data-protection complaint using our electronic complaint form or by emailing . We will acknowledge a data-protection complaint within 30 days and investigate/respond without undue delay. You also have the right to complain to the UK Information Commissioner’s Office.

12. Contact

Data protection contact: .

ICO status:

Legal entity
Company number
Registered office
Registered in
Legal and data protection enquiries: