Operator Vault ("we", "us", "our") operates Operator Vault, a compliance management platform for Goods Vehicle and PSV operators (the "Service"). We are the data controller for personal data processed through the Service, except where a client operator acts as controller for their own drivers' data (see Section 3).
1. Who we are
Operator Vault is a UK compliance management platform for Goods Vehicle and PSV operators.
Data protection contact: info@operatorvault.co.uk.
ICO registration: our registration with the Information Commissioner's Office is in progress; the registration number will be published here once issued.
2. Scope
This policy applies to personal data we process about operators and their staff who register for and use the Service ("Account Holders").
It also applies to drivers, transport managers and other individuals whose data is entered into the Service by an Account Holder ("Data Subjects"), and to visitors to our website.
3. Controller vs processor — important distinction
For most driver and vehicle data entered into the Service, the operator is the data controller and Operator Vault acts as a data processor on their behalf, under a Data Processing Agreement. We process this data only on the operator's instructions, as set out in our contract with them.
For account-level data (billing, login credentials, usage analytics), Operator Vault is the data controller.
4. What personal data we collect
Account data — name, email, business details and login credentials, about Account Holders.
Trial and sales contact data — phone number (free trial signup only), feedback responses and marketing contact consent status, about Account Holders.
Driver personal data — name, driving licence details, CPC number and expiry, employment documents and training records, about drivers.
Special category data — medical certificate status and expiry, and DBS or criminal record check results (PSV drivers where applicable), about drivers.
Right to work data — right to work documentation, about drivers.
Vehicle and trailer data — registration, VIN, inspection and maintenance history. This is not personal data in itself.
Documents and attachments — uploaded photos, PDFs and scanned certificates; the data subject varies with the document.
Usage data — sign-in times, feature usage and device or browser information, about Account Holders and other users.
5. Special category data — lawful basis
Medical certificate status and DBS or criminal record data are special category data under UK GDPR Article 9 and require an additional lawful condition beyond a standard Article 6 basis. The applicable condition is processing necessary for the operator's compliance with obligations under employment, transport regulatory, or health and safety law (Article 9(2)(b), read with the relevant Schedule 1 DPA 2018 condition), rather than consent — since consent from an employee is generally not considered "freely given" due to the power imbalance in an employment relationship.
We do not store the underlying content of DBS certificates or medical records beyond what is necessary to track check and expiry status, unless the operator chooses to upload supporting documents.
6. How we use personal data
To provide the Service: tracking compliance status, generating reminders and producing audit packs.
To operate Smart Intake: AI-assisted classification of uploaded documents (see our AI disclaimer in the Terms of Service).
To communicate with Account Holders about their account and the Service.
For free trial participants who explicitly consent: to contact them by phone about their trial experience and available offers. This only happens where the person has actively opted in to being contacted — it is never inferred from providing a phone number for account purposes alone, and can be withdrawn at any time.
To maintain security and prevent misuse of the Service, and to comply with our own legal obligations.
7. Who we share data with
We use sub-processors who help us run the Service, under contract requiring UK GDPR-equivalent protections.
Hosting, database and file storage provider: Supabase (infrastructure provided through Lovable Cloud), with data hosted in the EU.
AI classification provider: Google (Gemini models), accessed through the Lovable AI Gateway operated by Lovable Labs Incorporated.
Email routing provider: Resend, used for account, reminder and support email.
Payments provider: Stripe, used for checkout, subscriptions and invoices.
Maintenance providers, where an operator grants them access — restricted to the specific vehicles and contracts assigned to them.
Regulatory bodies, only where the operator chooses to export and share an audit pack, or where we are legally compelled to disclose data.
We do not sell personal data.
8. International transfers
Hosting, database and file storage remain in the EU, covered by the UK adequacy regulations for the EEA.
Where a sub-processor processes data in the United States (currently our AI classification, email and payments providers), transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with the providers' own certification under the UK extension to the EU-US Data Privacy Framework where they hold it.
A full list of sub-processors and their locations is available on request from info@operatorvault.co.uk.
9. Data retention
We retain personal data for as long as the operator's account is active, plus six years after closure, to meet the regulatory retention expectations that apply to transport compliance records, unless the operator requests earlier deletion and no legal retention obligation applies.
Deleted records sit in the recycle bin until an authorised user chooses to permanently remove them. Terms acceptance records are retained for the life of the account plus six years as evidence of what was agreed.
10. Data security
We use industry-standard technical and organisational measures, including encryption in transit and at rest, role-based access controls, operator-scoped separation of records, and restricted access to special category data.
11. Data subject rights
Individuals have the right to access their data, request correction, request erasure (subject to legal retention requirements), restrict or object to processing, and request data portability.
Requests relating to driver data should generally be directed to the relevant operator, as controller. Requests relating to account-level data can be sent to info@operatorvault.co.uk.
Individuals also have the right to complain to the Information Commissioner's Office (ico.org.uk).
12. Children
The Service is not directed at or intended for use by anyone under 18.
13. Changes to this policy
We will update this policy as the Service evolves and notify Account Holders of material changes.
14. Contact
Operator Vault — info@operatorvault.co.uk.
