Privacy Policy

Effective from .

This policy explains how Transport Technical Innovation Ltd (“we”, “us”, “our”) collects and uses personal data in connection with BrakeGuard — the BrakeGuard mobile app, the licence and results service behind it, and the ttil.net website and customer portal. We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.

1. Who we are and how to contact us

BrakeGuard is operated by Transport Technical Innovation Ltd, a private limited company registered in England and Wales (company number 14618630; registered office The Stable Yard, 25–33 Vicarage Road, Stony Stratford, Milton Keynes MK11 1BN, United Kingdom). We are the controller of the personal data described in section 2 as ours.

For any question about this policy or your personal data, email privacy@ttil.net, or write to us at our registered office marked for the attention of the data protection lead. We have not appointed a Data Protection Officer, because the nature and scale of our processing do not require one under Article 37, and as a UK company we do not need a UK representative; our data protection lead is responsible for this policy and for handling your requests.

2. Our role: when we are a controller and when we are a processor

BrakeGuard is used by organisations (our customers) to carry out brake-performance tests. Because of that, our role under data-protection law depends on the data in question:

If your personal data appears in a brake-test record because you drive for, or work with, one of our customers, that customer is the controller of that data and your first point of contact for the rights in section 10. We will support them in responding to you.

3. The personal data we process

We process the following categories of personal data:

CategoryExamplesSourceOur role
Account & identityYour name, email address, profile picture and the account identifier from each sign-in method linked to your account; your portal role, approval status and which customer you belong to; and the sessions you have open.Your sign-in provider (Google, Microsoft or Apple, where offered) when you sign in; or, for a portal account your organisation asked us to set up directly, the email address they gave us and the one-time sign-in credential we email to it.Controller
Licence & deviceLicence code, the customer contact name and email on the licence, device / installation identifiers, device-binding state, and the app version in use.Issued by us and reported by the app during activation.Controller
BillingThe name, work email and work phone number of the person your organisation names as its billing contact, and the invoices we raise to that organisation.Your organisation, when it takes out or renews a licence.Controller
Brake-test resultsVehicle registration, test date and time, the result (e.g. pass / fail), deceleration figures, the full result record, an encrypted sensor-data trace, and the certificate document.Uploaded by the customer’s licensed devices.Processor (for the customer)
Diagnostic traces (Test/Debug devices only)A high-rate motion-sensor and GPS location trace of a test, used by engineering to diagnose measurement problems. Recorded only while a device is in Test/Debug mode.Uploaded by Test/Debug-flagged devices; the user is shown a notice.Processor (for the customer)
In-product feedbackThe kind of feedback and any rating you gave; anything you type, which is free text and may contain personal data if you choose to include it; and a technical snapshot taken when you opened the form — the screen or page, app or browser version, device or browser identity, licence and installation identifiers, and (from the app) sensor, calibration, GPS signal-quality, upload-queue and recent-activity state. From the portal, the account you were signed in with. On a Test/Debug device only, a link to one named diagnostic recording, which does contain location data.You, when you send feedback; your device or browser, automatically, at that moment.Controller
Operational, security & auditRequest metadata and IP address (via our load balancer and web application firewall), portal audit events (who did what — recorded as identifiers, never as free text), a record that we sent you an email (identifiers only, never its content), and redacted performance / error diagnostics from your browser.Generated automatically when you use the portal or the API.Controller
CookiesA sign-in session cookie and a CSRF-protection token (see section 9).Set by the portal in your browser.Controller

We do not seek to collect special-category data (such as health or biometric data), and the service is intended for occupational use rather than by children (section 11). Location data is processed only as part of a brake test and, at higher density, only on Test/Debug devices.

4. Why we process it, and our lawful bases

PurposeData usedLawful basis (UK GDPR Article 6)
Provide the portal and the licence / results service; authenticate you; enforce device limits; send you a sign-in credential or password reset when your organisation asks us to set up your account.Account & identity; licence & device.Contract (Art. 6(1)(b)) where you hold the licence yourself; otherwise our legitimate interest (Art. 6(1)(f)) in delivering the service to the organisation you use it on behalf of.
Invoice our customers and keep our statutory accounting records.Billing.Legitimate interests (Art. 6(1)(f)) in invoicing our own customers — Contract (Art. 6(1)(b)) where you are a sole trader contracting with us directly — and legal obligation (Art. 6(1)(c)) for the retained accounting and VAT record.
Record, store and make available brake-test results and diagnostic traces on the customer’s behalf.Brake-test results; diagnostic traces.Processed on the customer’s instructions; the customer’s own basis (typically Contract, Art. 6(1)(b), or their legal obligation) applies.
Keep tamper-evident records for the integrity of attestation and to meet record-keeping expectations.Brake-test results and audit data we retain as controller.Legal obligation (Art. 6(1)(c)) for the statutory audit record, and legitimate interests (Art. 6(1)(f)) in a trustworthy certification record and in establishing, exercising or defending legal claims.
Receive, triage and act on feedback you send us about the product; diagnose reported faults and decide what to improve.In-product feedback: your message, rating and category, and the technical snapshot captured with it.Legitimate interests (Art. 6(1)(f)) — our interest in diagnosing faults in, and improving, our own product. You chose to send it; only our staff can read it; we keep it for a limited period; and you can object at any time. For this data we are the controller, not a processor.
Keep the service secure and reliable; prevent fraud and abuse; diagnose faults.Operational, security & audit data.Legitimate interests (Art. 6(1)(f)) in the security and reliability of the service.
Operate strictly-necessary cookies.Session and CSRF cookies.Contract / legitimate interests; these cookies are exempt from consent under the Privacy and Electronic Communications Regulations (see section 9).

Where we rely on legitimate interests, we have weighed those interests against your rights and use the data only as described here. You can object to that processing (section 10).

5. Automated decision-making

A brake-test result is a physical measurement of a vehicle’s deceleration, presented to a qualified operator; we do not use it to make a solely-automated decision that produces legal or similarly significant effects about you within the meaning of Article 22. We do not carry out profiling for marketing.

6. Where your data is held, and international transfers

All backend personal data is stored in Google Cloud’s London region (europe-west2) for UK data residency — licence records, result records, feedback, audit logs, encryption keys, and operator personal data all stay in this region. We use a small number of processors to run the service:

When you sign in with Google, Microsoft or Apple, that provider handles the sign-in itself as an independent controller under its own privacy policy; we receive only your name, email address and a provider account identifier.

Our contracts for Google Cloud and Google Workspace are with Google Cloud EMEA Limited, an Irish company. The UK recognises the European Economic Area as providing adequate protection for personal data, so no additional safeguard is needed for that transfer; Google’s own onward transfers to its affiliates, including in the United States, are covered by the transfer safeguards in its Cloud Data Processing Addendum (the UK Extension to the EU-US Data Privacy Framework, or the EU Standard Contractual Clauses where that does not apply). Our billing records held by Xero in the United States are protected by the EU Standard Contractual Clauses with the ICO’s International Data Transfer Addendum. Email we send you necessarily leaves our systems: once a message is handed to your own email provider, where it is stored is outside our control. We do not sell personal data, and we do not share it with advertisers.

7. Security

Connections use TLS 1.3. Sensitive at-rest data — the encrypted sensor CSV, the certificate document, diagnostic traces and feedback — is encrypted under a key unique to each licence, so one customer’s data cannot be read from another customer’s storage. Access to the portal is role-based and each customer is isolated from every other customer by design. Sign-in credentials we email are single-use and expire if not redeemed. We minimise personal data in our logs by redacting identifiers such as emails and licence codes before they are written.

8. How long we keep it

DataRetention
Result records, licences, certificates, audit logs and the encrypted sensor CSV7 years (record-keeping for the certification record).
Diagnostic traces (Test/Debug devices)180 days after upload, then cryptographically erased; erased sooner on request.
In-product feedback (your message and the technical snapshot sent with it)180 days after we receive it, then deleted. A diagnostic recording you attached keeps its own 180 days from the day that recording was uploaded, so it is often deleted before the feedback is.
Crash artefacts90 days.
Backups30 days.
Server logs30 days.
Portal account dataFor as long as your account is active. If your organisation removes you, your account is suspended — it can no longer sign in — but is kept until it is erased. When you ask us to erase your account (or we close it), it enters a 30-day grace period during which the erasure can still be cancelled, after which it is permanently deleted from our live systems and drops out of our backups within a further 30 days — subject to the record-keeping obligations above (the audit log keeps an identifier, never your name or email).
Portal invitationsAn invitation is open for 14 days and cannot be used after that. Closed invitations are deleted with your organisation’s other portal records; we are also introducing automatic removal 30 days after an invitation is accepted, withdrawn or expires.
One-time sign-in credentials we email72 hours from issue, whether or not they are used.
Email delivery recordsOur own record that a message was sent: as part of the audit log above (identifiers only). Our email provider keeps its own delivery logs under its own retention terms.
Billing records6 years from the end of the accounting period the invoice falls in, as UK tax and company law require; the billing contact’s details are then removed from the record.

We erase backend records for a customer by deleting the encryption keys for that customer’s licences, which renders the stored sensor, certificate, trace and feedback data permanently unreadable (a “cryptographic erasure”). Portal accounts and billing records sit outside those keys and are deleted by the processes described in the table.

9. Cookies

We use strictly-necessary cookies only: a sign-in session cookie and a CSRF-protection token, set when you sign in. They keep you signed in and protect the forms you submit. We set no advertising, analytics, or cross-site tracking cookies, so we do not ask you for cookie consent.

To keep the portal fast and reliable, your browser also sends us performance measurements and, if something breaks, a diagnostic error report. These are sent only to us (not to any third party), and we strip personal identifiers such as email addresses from them before they are stored.

10. Your rights

Under UK GDPR you have the right to:

To exercise a right, email privacy@ttil.net or write to our registered office (section 1). Where your request concerns brake-test data for which we are only a processor (section 2) — but not in-product feedback, for which we are the controller (see below) — please contact the customer organisation that is the controller; we will assist them. We will respond within one month — extendable by up to two further months for a complex request, in which case we will tell you — and we may ask you to confirm your identity before we act.

Feedback you have sent us. We are the controller for feedback, so requests about it come to us directly and not to your employer. You can ask for a copy, ask us to delete it, or object to our using it, at any time — write to us using the contact details in section 1 and tell us roughly when you sent it and from which device or account. Because feedback sent from the app carries no sign-in identity — the app has no accounts — we can only find it if you can tell us the device or licence it came from, and we will ask you to confirm that the feedback is yours before we release it. Feedback sent from the portal is linked to your account and we can find it directly. All feedback is in any case deleted automatically 180 days after we receive it.

If you are unhappy with how we have handled your data you can complain to the UK’s supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk — though we would welcome the chance to resolve it first.

11. Children

BrakeGuard is a professional tool for vehicle operators and testers. It is not directed at children, and we do not knowingly collect their personal data.

12. Changes to this policy

We may update this policy from time to time. When we make a material change we will update the effective date shown at the top of this page and, where appropriate, tell you through the portal or by email.