Privacy Policy

Draft — pending legal review

This document is a working draft prepared for legal review and is not yet in force. It will take effect on the date confirmed at sign-off. Draft last edited 11 July 2026.

This policy explains how Transport Technical Innovation Ltd(“we”, “us”, “our”) collects and uses personal data in connection with BrakeGuard— the BrakeGuard mobile app, the licence and results service behind it, and the ttil.net website and customer portal. We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.

1. Who we are and how to contact us

BrakeGuard is operated by Transport Technical Innovation Ltd, a company registered in England and Wales (company number [REVIEW: company number]; registered office [REVIEW: registered office address]). For any question about this policy or your personal data, contact us at [REVIEW: privacy contact email, e.g. privacy@ttil.net], or in writing at our registered office marked for the attention of the data protection lead.

[REVIEW: state whether a Data Protection Officer and/or a UK representative has been appointed and give their contact details, or confirm none is required.]

2. Our role: when we are a controller and when we are a processor

BrakeGuard is used by organisations (our customers) to carry out brake-performance tests. Because of that, our role under data-protection law depends on the data in question:

If your personal data appears in a brake-test record because you drive for, or work with, one of our customers, that customer is the controller of that data and your first point of contact for the rights in section 8. We will support them in responding to you. [REVIEW: confirm this controller/processor split and any DPA reference with counsel.]

3. The personal data we process

We process the following categories of personal data:

CategoryExamplesSourceOur role
Account & identityYour name, email address, profile picture and the account identifier from your chosen sign-in provider; your portal role, approval status and which customer you belong to.Your OAuth sign-in provider (e.g. Google) when you sign in.Controller
Licence & deviceLicence code, the customer contact name and email on the licence, device / installation identifiers, device-binding state, and the app version in use.Issued by us and reported by the app during activation.Controller
Brake-test resultsVehicle registration, test date and time, the result (e.g. pass / fail), deceleration figures, the full result record, an encrypted sensor-data trace, and the certificate document.Uploaded by the customer’s licensed devices.Processor (for the customer)
Diagnostic traces (Test/Debug devices only)A high-rate motion-sensor and GPS location trace of a test, used by engineering to diagnose measurement problems. Recorded only while a device is in Test/Debug mode.Uploaded by Test/Debug-flagged devices; the user is shown a notice.Processor (for the customer)
Operational, security & auditRequest metadata and IP address (via our load balancer and web application firewall), portal audit events (who did what), and redacted performance / error diagnostics from your browser.Generated automatically when you use the portal or the API.Controller
CookiesA sign-in session cookie and a CSRF-protection token (see section 9).Set by the portal in your browser.Controller

We do not seek to collect special-category data (such as health or biometric data), and the service is intended for occupational use rather than by children (section 11). Location data is processed only as part of a brake test and, at higher density, only on Test/Debug devices.

4. Why we process it, and our lawful bases

PurposeData usedLawful basis (UK GDPR Article 6)
Provide the portal and the licence / results service; authenticate you; enforce device limits.Account & identity; licence & device.Contract(Art. 6(1)(b)) — to deliver the service you or your organisation hold a licence for.
Record, store and make available brake-test results and diagnostic traces on the customer’s behalf.Brake-test results; diagnostic traces.Processed on the customer’s instructions; the customer’s own basis (typically Contract, Art. 6(1)(b), or their legal obligation) applies. [REVIEW: confirm.]
Keep tamper-evident records for the integrity of attestation and to meet record-keeping expectations.Brake-test results and audit data we retain as controller.Legal obligation (Art. 6(1)(c)) and/or legitimate interests (Art. 6(1)(f)) in a trustworthy certification record. [REVIEW: confirm basis for 7-year retention.]
Keep the service secure and reliable; prevent fraud and abuse; diagnose faults.Operational, security & audit data.Legitimate interests (Art. 6(1)(f)) in the security and reliability of the service.
Operate strictly-necessary cookies.Session and CSRF cookies.Contract / legitimate interests; these cookies are exempt from consent under the Privacy and Electronic Communications Regulations (see section 9).

Where we rely on legitimate interests, we have weighed those interests against your rights and use the data only as described here. You can object to that processing (section 8).

5. Automated decision-making

A brake-test result is a physical measurement of a vehicle’s deceleration, presented to a qualified operator; we do not use it to make a solely-automated decision that produces legal or similarly significant effects about you within the meaning of Article 22. We do not carry out profiling for marketing.

6. Where your data is held, and international transfers

All backend personal data is stored in Google Cloud’s London region (europe-west2) for UK data residency — licence records, result records, audit logs, encryption keys, and operator personal data all stay in this region. We use a small number of processors to run the service:

Our processors are global providers. Where personal data could be accessed from outside the UK (for example for support), that transfer is protected by an appropriate UK GDPR safeguard, such as the UK International Data Transfer Agreement / Addendum or a UK adequacy decision. [REVIEW: confirm the exact transfer mechanism(s) and list them.] We do not sell personal data, and we do not share it with advertisers.

7. Security

Connections use TLS 1.3. Sensitive at-rest data — the encrypted sensor CSV, the certificate document, and diagnostic traces — is encrypted under a per-customer key, so one customer’s data cannot be read from another customer’s storage. Access to the portal is role-based and each customer is isolated from every other customer by design. We minimise personal data in our logs by redacting identifiers such as emails and licence codes before they are written.

8. How long we keep it

DataRetention
Result records, licences, certificates, audit logs and the encrypted sensor CSV7 years (record-keeping for the certification record).
Diagnostic traces (Test/Debug devices)180 days after upload, then cryptographically erased; erased sooner on request.
Crash artefacts90 days.
Backups30 days.
Server logs30 days.
Portal account dataFor as long as your account is active, then deleted or anonymised, subject to any record-keeping obligation above.

We erase backend records for a customer by deleting that customer’s encryption key, which renders their stored sensor and certificate data permanently unreadable (a “cryptographic erasure”). [REVIEW: confirm these are the ratified retention periods.]

9. Cookies

We use strictly-necessary cookies only: a sign-in session cookie and a CSRF-protection token, set when you sign in. They keep you signed in and protect the forms you submit. We set no advertising, analytics, or cross-site tracking cookies, so no cookie banner is required.

To keep the portal fast and reliable, your browser also sends us anonymous performance measurements and, if something breaks, a diagnostic error report. These are sent only to us (not to any third party), and identifiers are stripped before the report is stored.

10. Your rights

Under UK GDPR you have the right to:

To exercise a right, contact us at [REVIEW: privacy contact email]. Where your request concerns brake-test data for which we are only a processor (section 2), please contact the customer organisation that is the controller; we will assist them. We will respond within one month.

If you are unhappy with how we have handled your data you can complain to the UK’s supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk— though we would welcome the chance to resolve it first.

11. Children

BrakeGuard is a professional tool for vehicle operators and testers. It is not directed at children, and we do not knowingly collect their personal data.

12. Changes to this policy

We may update this policy from time to time. When we make a material change we will update the effective date and, where appropriate, tell you through the portal.