Privacy Policy
Draft — pending legal review
This document is a working draft prepared for legal review and is not yet in force. It will take effect on the date confirmed at sign-off. Draft last edited 11 July 2026.
This policy explains how Transport Technical Innovation Ltd(“we”, “us”, “our”) collects and uses personal data in connection with BrakeGuard— the BrakeGuard mobile app, the licence and results service behind it, and the ttil.net website and customer portal. We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.
1. Who we are and how to contact us
BrakeGuard is operated by Transport Technical Innovation Ltd, a company registered in England and Wales (company number [REVIEW: company number]; registered office [REVIEW: registered office address]). For any question about this policy or your personal data, contact us at [REVIEW: privacy contact email, e.g. privacy@ttil.net], or in writing at our registered office marked for the attention of the data protection lead.
[REVIEW: state whether a Data Protection Officer and/or a UK representative has been appointed and give their contact details, or confirm none is required.]
2. Our role: when we are a controller and when we are a processor
BrakeGuard is used by organisations (our customers) to carry out brake-performance tests. Because of that, our role under data-protection law depends on the data in question:
- We are the controller for the personal data we decide the purposes and means of processing ourselves: your portal account and sign-in data, visitors to the ttil.net website, the licensing relationship, billing, and our operational, security, and audit records.
- We are a processorfor the personal data contained in the brake-test records and diagnostic traces that a customer’s licensed devices upload — for example a vehicle registration, the operator’s details, or location recorded during a test. Here the customer organisation is the controller and we process that data on their behalf, on their instructions, under our agreement with them.
If your personal data appears in a brake-test record because you drive for, or work with, one of our customers, that customer is the controller of that data and your first point of contact for the rights in section 8. We will support them in responding to you. [REVIEW: confirm this controller/processor split and any DPA reference with counsel.]
3. The personal data we process
We process the following categories of personal data:
| Category | Examples | Source | Our role |
|---|---|---|---|
| Account & identity | Your name, email address, profile picture and the account identifier from your chosen sign-in provider; your portal role, approval status and which customer you belong to. | Your OAuth sign-in provider (e.g. Google) when you sign in. | Controller |
| Licence & device | Licence code, the customer contact name and email on the licence, device / installation identifiers, device-binding state, and the app version in use. | Issued by us and reported by the app during activation. | Controller |
| Brake-test results | Vehicle registration, test date and time, the result (e.g. pass / fail), deceleration figures, the full result record, an encrypted sensor-data trace, and the certificate document. | Uploaded by the customer’s licensed devices. | Processor (for the customer) |
| Diagnostic traces (Test/Debug devices only) | A high-rate motion-sensor and GPS location trace of a test, used by engineering to diagnose measurement problems. Recorded only while a device is in Test/Debug mode. | Uploaded by Test/Debug-flagged devices; the user is shown a notice. | Processor (for the customer) |
| Operational, security & audit | Request metadata and IP address (via our load balancer and web application firewall), portal audit events (who did what), and redacted performance / error diagnostics from your browser. | Generated automatically when you use the portal or the API. | Controller |
| Cookies | A sign-in session cookie and a CSRF-protection token (see section 9). | Set by the portal in your browser. | Controller |
We do not seek to collect special-category data (such as health or biometric data), and the service is intended for occupational use rather than by children (section 11). Location data is processed only as part of a brake test and, at higher density, only on Test/Debug devices.
4. Why we process it, and our lawful bases
| Purpose | Data used | Lawful basis (UK GDPR Article 6) |
|---|---|---|
| Provide the portal and the licence / results service; authenticate you; enforce device limits. | Account & identity; licence & device. | Contract(Art. 6(1)(b)) — to deliver the service you or your organisation hold a licence for. |
| Record, store and make available brake-test results and diagnostic traces on the customer’s behalf. | Brake-test results; diagnostic traces. | Processed on the customer’s instructions; the customer’s own basis (typically Contract, Art. 6(1)(b), or their legal obligation) applies. [REVIEW: confirm.] |
| Keep tamper-evident records for the integrity of attestation and to meet record-keeping expectations. | Brake-test results and audit data we retain as controller. | Legal obligation (Art. 6(1)(c)) and/or legitimate interests (Art. 6(1)(f)) in a trustworthy certification record. [REVIEW: confirm basis for 7-year retention.] |
| Keep the service secure and reliable; prevent fraud and abuse; diagnose faults. | Operational, security & audit data. | Legitimate interests (Art. 6(1)(f)) in the security and reliability of the service. |
| Operate strictly-necessary cookies. | Session and CSRF cookies. | Contract / legitimate interests; these cookies are exempt from consent under the Privacy and Electronic Communications Regulations (see section 9). |
Where we rely on legitimate interests, we have weighed those interests against your rights and use the data only as described here. You can object to that processing (section 8).
5. Automated decision-making
A brake-test result is a physical measurement of a vehicle’s deceleration, presented to a qualified operator; we do not use it to make a solely-automated decision that produces legal or similarly significant effects about you within the meaning of Article 22. We do not carry out profiling for marketing.
6. Where your data is held, and international transfers
All backend personal data is stored in Google Cloud’s London region (europe-west2) for UK data residency — licence records, result records, audit logs, encryption keys, and operator personal data all stay in this region. We use a small number of processors to run the service:
- Google Cloud Platform— hosting, database, encrypted object storage, key management and logging, all in
europe-west2. - Google, and any other sign-in provider you choose(for example GitHub, Microsoft or Apple, where offered) — solely to authenticate your sign-in; we receive your name, email and a provider account identifier.
- Cloudflare— authoritative DNS only (it resolves our domain name; it is not a proxy in front of the service and does not process request content).
Our processors are global providers. Where personal data could be accessed from outside the UK (for example for support), that transfer is protected by an appropriate UK GDPR safeguard, such as the UK International Data Transfer Agreement / Addendum or a UK adequacy decision. [REVIEW: confirm the exact transfer mechanism(s) and list them.] We do not sell personal data, and we do not share it with advertisers.
7. Security
Connections use TLS 1.3. Sensitive at-rest data — the encrypted sensor CSV, the certificate document, and diagnostic traces — is encrypted under a per-customer key, so one customer’s data cannot be read from another customer’s storage. Access to the portal is role-based and each customer is isolated from every other customer by design. We minimise personal data in our logs by redacting identifiers such as emails and licence codes before they are written.
8. How long we keep it
| Data | Retention |
|---|---|
| Result records, licences, certificates, audit logs and the encrypted sensor CSV | 7 years (record-keeping for the certification record). |
| Diagnostic traces (Test/Debug devices) | 180 days after upload, then cryptographically erased; erased sooner on request. |
| Crash artefacts | 90 days. |
| Backups | 30 days. |
| Server logs | 30 days. |
| Portal account data | For as long as your account is active, then deleted or anonymised, subject to any record-keeping obligation above. |
We erase backend records for a customer by deleting that customer’s encryption key, which renders their stored sensor and certificate data permanently unreadable (a “cryptographic erasure”). [REVIEW: confirm these are the ratified retention periods.]
9. Cookies
We use strictly-necessary cookies only: a sign-in session cookie and a CSRF-protection token, set when you sign in. They keep you signed in and protect the forms you submit. We set no advertising, analytics, or cross-site tracking cookies, so no cookie banner is required.
To keep the portal fast and reliable, your browser also sends us anonymous performance measurements and, if something breaks, a diagnostic error report. These are sent only to us (not to any third party), and identifiers are stripped before the report is stored.
10. Your rights
Under UK GDPR you have the right to:
- be informed about how we use your data (this policy);
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased, where an exception (such as our record-keeping obligation) does not apply;
- restrict or object to processing, including processing based on legitimate interests;
- data portability, where processing is by automated means under contract or consent; and
- not be subject to a solely-automated decision with legal or similarly significant effects (section 5).
To exercise a right, contact us at [REVIEW: privacy contact email]. Where your request concerns brake-test data for which we are only a processor (section 2), please contact the customer organisation that is the controller; we will assist them. We will respond within one month.
If you are unhappy with how we have handled your data you can complain to the UK’s supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk— though we would welcome the chance to resolve it first.
11. Children
BrakeGuard is a professional tool for vehicle operators and testers. It is not directed at children, and we do not knowingly collect their personal data.
12. Changes to this policy
We may update this policy from time to time. When we make a material change we will update the effective date and, where appropriate, tell you through the portal.