Skip to main content

Mercia Fleet Management

Privacy Policy

1. Privacy Policy

1.1

Everyone has rights with regard to the way in which their personal data is handled. During the course of our activities, we will collect, store and process personal data about our staff, customers, suppliers and other third parties, and we recognise that the correct and lawful treatment of this data will maintain confidence in the organisation and will provide for successful business operations.

1.2

Data users are obliged to comply with this policy when processing personal data on our behalf. Any breach of this policy may result in disciplinary action.

1.3

Data retention periods are closely aligned with those demanded by HMRC as we provide taxable benefits and payroll deduction calculations, as such these are subject to change.

2. About this Policy

2.1

The types of personal data that we may be required to handle include information about current, past and prospective staff, suppliers, customers and others that we communicate with. The personal data, which may be held on paper or on a computer or other media, is subject to certain legal safeguards specified in the General Data Protection Regulation (GDPR) and other regulations.

2.2

This policy and any other documents referred to in it sets out the basis on which we will process any personal data we collect from data subjects, or that is provided to us by data subjects or other sources.

2.3

This policy does not form part of any employee’s contract of employment and may be amended at any time.

2.4

This policy sets out rules on data protection and the legal conditions that must be satisfied when we obtain, handle, process, transfer and store personal data.

3. Definition of data protection terms

3.1

Data is information which is stored electronically, on a computer, or in certain paper-based filing systems.

3.2

Data subjects for the purpose of this policy include all living individuals about whom we hold personal data. A data subject need not be a UK national or resident. All data subjects have legal rights in relation to their personal information.

3.3

Personal data means data relating to a living individual who can be identified from that data (or from that data and other information in our possession). Personal data can be factual (for example, a name, address or date of birth) or it can be an opinion about that person, their actions, and behavior.

3.4

Data controllers are the people who or organisations which determine the purposes for which, and the manner in which, any personal data is processed. They are responsible for establishing practices and policies in line with the GDPR. We are the data controller of all personal data used in our business for our own commercial purposes.

3.5

Data users are those of our employees whose work involves processing personal data. Data users must protect the data they handle in accordance with this data protection policy and any applicable data security procedures at all times.

3.6

Data processors include any person or organization that is not a data user that processes personal data on our behalf and on our instructions. Employees of data controllers are excluded from this definition but it could include suppliers which handle personal data on our behalf.

3.7

Processing is any activity that involves the use of the data. It includes obtaining, recording or holding the data, or carrying out any operation or set of operations on the data including organising, amending, retrieving, using, disclosing, erasing or destroying it. Processing also includes transferring personal data to third parties.

3.8

Sensitive personal data means information about a person’s racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health or condition or sexual life, or about the commission of, or proceedings for, any offence committed or alleged to have been committed by that person, the disposal of such proceedings or the sentence of any court in such proceedings, genetic data, and biometric data where processed to uniquely identify a person (for example a photo in an electronic passport). Sensitive personal data can only be processed under strict conditions, including a condition requiring the express permission of the person concerned.

4. Data protection principles

Anyone processing personal data must comply with the principles of data protection. These provide that personal data must be:

(a)

Processed lawfully, fairly and in a transparent manner in relation to individuals.

(b)

Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes (further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes).

(c)

Adequate, relevant and limited to what is necessary for relation to the purposes for which they are processed (Data Minimisation).

(d)

Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purpose for which they are processed, are erased or rectified without delay.

(e)

Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals.

(f)

Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
The data controller is responsible for and must be able to demonstrate compliance with these principles.

5. Fair and lawful processing

5.1

The GDPR is not intended to prevent the processing of personal data but to ensure that it is done fairly and without adversely affecting the rights of the data subject.

5.2

For personal data to be processed lawfully, they must be processed on the basis of one of the legal grounds set out in the GDPR. These include, among other things, the data subject’s consent to the processing, or that the processing is necessary for the performance of a contract with the data subject, for the compliance with a legal obligation to which the data controller is subject, or for the legitimate interest of the data controller or the party to whom the data is disclosed. When sensitive personal data is being processed, additional conditions must be met. When processing personal data as data controllers in the course of our business, we will ensure that those requirements are met.

6. Specified, Explicit and Legitimate Purposes

6.1

In the course of our business, we may collect and process the personal data set out in the 1. This may include data we receive directly from a data subject (for example, by completing forms or by corresponding with us by mail, phone, email or otherwise) and data we receive from other sources (including, for example, business partners, sub-contractors in technical, payment and delivery services, credit reference agencies and others).

6.2

We will only process personal data for the specific purposes set out in the 1 or for any other purposes specifically permitted by the GDPR. We will notify those purposes to the data subject when we first collect the data or as soon as possible thereafter.

7. Notifying data subjects

7.1

If we collect personal data directly from data subjects, we will inform them about their rights under the GDPR including:

(a)

The purpose or purposes for which we intend to process that personal data and the legal basis for the processing.

(b)

The types of third parties, if any, with which we will share or to which we will disclose that personal data.

(c)

The means, if any, with which data subjects can limit our use and disclosure of their personal data including the right to object to processing.

(d)

The right of subject access.

(e)

The right to be forgotten.

(f)

The right to withdraw consent, where processing is based on consent.

(g)

The right to rectification if data is inaccurate or incomplete.

(h)

Rights related to automated decision making and profiling.

7.2

If we receive personal data about a data subject from other sources, we will provide the data subject with this information as soon as possible thereafter.

7.3

We will also inform data subjects whose personal data we process that we are the data controller with regard to that data.

8. Data Minimisation

We will only collect personal data to the extent that it is required for the specific purpose notified to the data subject.

9. Accurate data

We will ensure that personal data we hold is accurate and kept up to date. We will check the accuracy of any personal data at the point of collection and at regular intervals afterward. We will take all reasonable steps to destroy or amend inaccurate or out-of-date data.

10. Storage Limitation

We will not keep personal data longer than is necessary for the purpose or purposes for which they were collected. We will take all reasonable steps to destroy, or erase from our systems, all data which is no longer required.

11. Processing in line with data subject’s rights

We will process all personal data in line with data subjects’ rights, in particular, their right to:

(a)

Request access to any data held about them by a data controller (see also clause 15).

(b)

Object to processing, including in particular to prevent the processing of their data for direct marketing purposes.

(c)

Ask to have inaccurate data amended (see also clause 9).

(d)

Request the deletion or removal of personal data where there is no compelling reason for its continued processing.

(e)

Prevent processing that is likely to cause damage or distress to themselves or anyone else.

(f)

Obtain and reuse their personal data for their own purposes (where that right applies)

12. Data security

12.1

We will take appropriate security measures against unlawful or unauthorized processing of personal data, and against the accidental loss of, or damage to, personal data. If there is a data security breach which will result in a risk to the data subject we will report that breach to the regulator without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

12.2

We will put in place procedures and technologies to maintain the security of all personal data from the point of collection to the point of destruction. Personal data will only be transferred to a data processor if he agrees to comply with those procedures and policies, or if he puts in place adequate measures himself.

12.3

We will maintain data security by protecting the confidentiality, integrity and availability of the personal data, defined as follows:

(a)

Confidentiality means that only people who are authorised to use the data can access it.

(b)

Integrity means that personal data should be accurate and suitable for the purpose for which it is processed.

(c)

Availability means that authorised users should be able to access the data if they need it for authorised purposes. Personal data should therefore be stored on our central computer system instead of individual PCs.

12.4

Security procedures include:

(a)

Entry controls. Any stranger seen in entry-controlled areas should be reported.

(b)

Secure lockable desks and cupboards. Desks and cupboards should be kept locked if they hold confidential information of any kind. (Personal information is always considered confidential.)

(c)

Methods of disposal. Paper documents should be shredded. Digital storage devices should be physically destroyed when they are no longer required.

(d)

Equipment. Data users must ensure that individual monitors do not show confidential information to passers-by and that they log off from their PC when it is left unattended.

(e)

Data Breaches – We shall notify you without delay and within 72 hours is we become aware of any actual breach or reasonable grounds for suspicion of a data breach including without limitation any actual or suspected personal data breach affecting the Data. We shall include in our notification;

(i)

A description of the nature of the breach

(ii)

The details of our contact who can provide further information about the breach

(iii)

A description of the likely consequences of the breach

(iv)

A description of the initial remedial measures taken or proposed to be taken to address the breach

13. Data security

13.1

We will only transfer any personal data we hold to a country outside the European Economic Area (“EEA”) where the conditions of transfer provided for in the GDPR apply.

14. Disclosure and sharing of personal information

14.1

We may share personal data we hold with any member of our group, which means our subsidiaries, our ultimate holding company, and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.

14.2

We may also disclose personal data we hold to third parties:

(a)

In the event that we sell or buy any business or assets, in which case we may disclose personal data we hold to the prospective seller or buyer of such business or assets.

(b)

If we or substantially all of our assets are acquired by a third party, in which case personal data we hold will be one of the transferred assets.

14.3

If we are under a duty to disclose or share a data subject’s personal data in order to comply with any legal obligation, or in order to enforce or apply any contract with the data subject or other agreements; or to protect our rights, property, or safety of our employees, customers, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.

14.4

We may also share personal data we hold with selected third parties for the purposes set out in the 1.

15. Dealing with subject access requests

15.1

Data subjects must make a formal request for information we hold about them. This must be made in writing. Employees who receive a written request should forward it to their line manager immediately.

15.2

When receiving telephone inquiries, we will only disclose personal data we hold on our systems if the following conditions are met:

(a)

In the event that we sell or buy any business or assets, in which case we may disclose personal data we hold to the prospective seller or buyer of such business or assets.

(b)

If we or substantially all of our assets are acquired by a third party, in which case personal data we hold will be one of the transferred assets.

15.3

Our employees will refer a request to their line manager for assistance in difficult situations. Employees should not be bullied into disclosing personal information.

16. Changes to this policy

We reserve the right to change this policy at any time. Where appropriate, we will notify data subjects of those changes by mail or email.

Type of data

Type of data subject

Type of processing

Purpose of processing

Types of recipient to whom personal data is tranferred

Retention Period

Security measures

Driver Data

Employee

Exchange with DVLA

To check driver license validity

Gov’t Agency

7 years

Encryption and offsite storage

Driver and Vehicle Data

Employee

Shared with insurer and maintenance suppliers

To obtain insurance quotations and book routine maintenance

FCA registered insurers Service and tyre providers

7 years

Quote details submitted via ssl form on secure website service booking normally vial online secure platform. Some may be made over the phone

Driver own Vehicle

Employee

Held and verified within our database

To verify customer  employees are eligible to drive on business journeys

None

7 years

Encryption and offsite storage Driver, HR manager, email, DOB and employer

Driver, HR manager, email, DOB, and employer

Employee

Held within email marketing systems and used for marketing

To educate on our scheme via marketing collateral

None

Until removal requested

Encrypted and hosted within EU

Bank details

Employer and Employee

Held within key2 and used with direct debit mandates for payments

To facilitate payments

None

7 years

Transmitted to secure DD handling company within UK

Privacy Policy

Fleet Evolution Privacy Notice

Fleet Evolution collect personal information in order to improve our customer service and operate our business, we are committed to respecting your privacy so would like to explain how, when and why we collect information about you and how we use it. More information is available within our GDPR policy available on request from Enter Email

You have certain rights which we fully respect and which are designed to protect your personal data, you have the right to see all data we hold on you at any point by contacting us on the above email or to remove yourself from any/all communications.

Your rights include the right to:

  • Object to our processing of your personal data
  • Request copies of all personal data on you we hold, and we remove or correct any personal data we hold on you including any automated routine we use to profile you. If you withdraw consent and have an existing agreement with us this will not affect the lawfulness of that agreement.

Should you wish to exercise these rights please contact us at Enter Email or the address below.

Fleet Evolution Privacy Notice

Fleet Evolution is an employee car scheme and salary sacrifice specialist, registered in the UK, company number, 07401665 whose principal place of business is:

The Dovecote Pimlico Farm,
Austrey Lane, Tamworth B79 0PF,
United Kingdom

Enter Site

01827 830861

The data compliance officer for Fleet Evolution is Andrew Leech, contactable as above or at Enter Email

Where we process your data

Our website

We record all visits to our website and utilise third party services such as Google analytics to automatically record your IP address, pages visited and length of time spent on our website. We also use cookies on our website which are essential in order to maximise your user experience and to allow you to navigate our website. Should you wish to opt out of tracking by Google Analytics please use this link;

https://tools.google.com/dlpage/gaoptout/

Email

To improve our communication and marketing we track emails sent, opened, clicked and subsequent visits to our website. We only email people who have asked for our communications and respect all unsubscribe requests with unsubscribe links in all marketing emails.

Live Chat

We have a live chat function on our website which will record your contact details and communications only if you provide them. You can ask us to stop follow up at any point. The only information stored is that you which you have provided to us.

Who can see my information?

If you’re not a customer your data is viewed in our UK office by our marketing team only. It may be added to our business and email systems which are hosted within the EU on encrypted systems. If you are a customer please refer to our wider GDPR policy. We will never share your data with third parties without your explicit consent although we do use third parties hosted in the EU for email marketing and other marketing purposes with detailed stored in encrypted databases.

How do you process my information?

We only use your data where we feel you have an interest in our products based on your actions. We use your data to improve our website, improve our communications and ensure our communications to all of our visitors are appropriate. We fully respect all unsubscribe requests, we have no interest in clogging up the inbox of those not interested in our services.

How long do you retain my data for?

We will retain your data for no more than 7 years unless you have provided your email address which will be retained indefinitely unless you either request removal or unsubscribe. We retain unsubscribes for 7 years to avoid being readded to our lists via another source (for example, a who attendance).

Our Products and Communications

Fleet Evolution is a market leading supplier of employee car schemes, we provide new cars to employees, fleet management, and salary sacrifice services. We communicate with our customers and prospects via phone, email and other channels via contact details you provide and can request to be removed at any point which can be made to Enter Email

Security

We take security very seriously. Any and all personal information is protected with encryption via our secure website. All of our back-office systems are encrypted and EU hosted.

Complaints

Any complaints should be directed to our data controller

Andrew Leech Enter Email

01827 830861

You may request copies of all information we hold on you at any time or removal of said information subject to legislative restrictions set by HMRC and other such bodies.

Ready to Solve Your
 Fleet Puzzle?

Fleet management is complex, but the right solutions simplify it. Cut costs, streamline logistics, and optimize operations with our expertise. Let’s find the best fit for you.