Chauffeurz Premium Services Ltd

Data Protection Policy

Effective from 3 August 2026  ·  Reviewed annually

This is the policy that governs how Chauffeurz handles personal information, whether it belongs to a passenger, a chauffeur partner, an employee or a supplier. It sets the standard we hold ourselves to, names who is accountable, and describes what happens when something goes wrong. If you are a customer looking for what we do with your booking details specifically, our Privacy Policy answers that question directly.

Data controllerChauffeurz Premium Services Ltd, trading as Chauffeurz
Company number15328967, registered in England and Wales
Registered office450 Bath Road, West Drayton, England, UB7 0EB
TfL operator licence010942
Policy ownerDirector responsible for data protection
contact@chauffeurz.london
Supervisory authorityInformation Commissioner's Office, ico.org.uk

At a glance

  • One named owner. A director is accountable for this policy, not a committee and not everybody in general.Section 4
  • Seven principles, including accountability. We have to be able to demonstrate compliance, not merely assert it.Section 3
  • Chauffeur partners are bound by contract to protect passenger data to the same standard we apply, and to return or delete it afterwards.Section 11
  • Breaches are reported to the ICO within seventy two hours where the law requires, and to the people affected where the risk is high.Section 15
  • Rights requests are answered within one month, free of charge, through a single point of contact.Section 14
  • Cameras record picture only, with microphones disabled and access restricted to safety, insurance and legal purposes.Section 12

This summary is provided for convenience. The full policy below is what applies.

1. Purpose and scope

1.1 Chauffeurz Premium Services Ltd, trading as Chauffeurz, is committed to protecting the personal information of everyone connected with our services. This policy sets out how we meet that commitment.

1.2 It applies to all personal information we hold, in any format, about passengers and customers, chauffeur partners and their drivers, employees and applicants, corporate account contacts, suppliers, and visitors to our website. It applies to every director, employee, contractor and chauffeur partner acting on our behalf.

1.3 We are registered with the Information Commissioner's Office as a data controller, under registration number ICO 09910305261. We are a private hire vehicle operator licensed by Transport for London under operator licence number 010942.

1.4 This policy is a governance document. It describes our standards and our internal procedures. What we do with a customer's information in practice, and the rights attached to it, are set out in our Privacy Policy, which should be read alongside this one. Where the two documents overlap, the Privacy Policy is the more detailed account of customer data.

2. The law we apply

2.1 Our processing is governed by the United Kingdom General Data Protection Regulation and the Data Protection Act 2018. Electronic marketing and cookies are additionally governed by the Privacy and Electronic Communications Regulations 2003.

2.2 The Data Protection Act 1998 was repealed in 2018 and no longer applies. References to it in earlier versions of our documentation are superseded by this policy.

2.3 The European Union General Data Protection Regulation may apply in addition, and only in addition, where we offer services to individuals located in the European Economic Area or monitor their behaviour there. Where that applies, we comply with it, and we keep under review whether a representative in the European Union is required.

2.4 We also comply with the record keeping obligations attaching to our private hire operator licence, and with tax and accounting law, both of which require us to retain certain records for defined periods.

3. Our principles

3.1 We handle personal information in accordance with the seven principles of United Kingdom data protection law.

Lawfulness, fairness and transparency. We process personal information only where we have a lawful basis, we do not use it in ways people would find unexpected, and we tell people plainly what we are doing.

Purpose limitation. We collect information for specified, explicit purposes and we do not later use it for something incompatible with those purposes.

Data minimisation. We collect what the job requires and nothing beyond it. A booking needs a name, a number, an address and a time. It does not need a life history.

Accuracy. We keep information accurate and up to date, and we correct or delete what is wrong without delay.

Storage limitation. We keep information no longer than we need it, against defined retention periods, and then delete or anonymise it.

Integrity and confidentiality. We protect information against unauthorised access, unlawful processing, loss, destruction and damage, using appropriate technical and organisational measures.

Accountability. We are responsible for compliance and we are able to demonstrate it. This principle is why the rest of this policy exists in writing.

4. Roles and responsibilities

4.1 The board of directors is responsible for compliance with data protection law. A named director owns this policy, approves changes to it, and is the escalation point for data protection matters.

4.2 We are not required to appoint a Data Protection Officer, because we do not carry out large scale systematic monitoring or large scale processing of special category data. We keep that assessment under review as the business grows. The single point of contact for all data protection matters is contact@chauffeurz.london.

4.3 Every director, employee, contractor and chauffeur partner is required to follow this policy. Compliance is a condition of working with us.

4.4 Anyone who becomes aware of a suspected breach, a rights request or a data protection concern must report it to the policy owner immediately, and in any event on the same working day.

5. Lawful bases for processing

5.1 We identify and record a lawful basis before we begin any processing. The bases available to us, and the situations in which we rely on them, are as follows.

  • Performance of a contract. Our principal basis. The contract for a journey is between the customer and Chauffeurz Premium Services Ltd, not between the customer and an individual chauffeur, and we process booking data in order to perform it.
  • Legal obligation. Booking records required by our operator licence, accounting records required by tax law, and disclosures required by a court, the police or a regulator.
  • Legitimate interests. Safety and security in our vehicles, prevention of fraud, defence of claims, service improvement, and limited marketing to existing customers. We carry out and record a balancing assessment before relying on this basis.
  • Consent. Non essential cookies, and marketing to people who are not existing customers. Consent is requested separately, in plain terms, by a clear affirmative act, and can be withdrawn at any time as easily as it was given.
  • Vital interests. In an emergency, to protect someone's life, for example passing details to the emergency services after a collision.

5.2 We do not rely on the public task basis. It is not available to a private hire operator, and any earlier reference to public functions in our documentation is withdrawn.

5.3 We do not use consent as a substitute for a proper contractual or legitimate interests basis, because doing so would give people a false impression of choice.

6. Whose information we hold

  • Passengers and customers. Contact details, journey details, arrival references, payment records, correspondence, and camera footage where an incident occurs. Described in full in our Privacy Policy.
  • Chauffeur partners and their drivers. Identity details, licence and insurance documentation, vehicle details, right to work evidence, bank details for payment, and performance and complaint records. We hold this to verify that everyone carrying our passengers is properly licensed and insured, and because our operator licence requires it.
  • Employees and applicants. Recruitment, employment, payroll and pension records, held under contract and legal obligation.
  • Corporate account contacts and suppliers. Business contact details, account and credit information, and correspondence.
  • Website visitors. Technical and analytics data, as described in our Privacy Policy and Cookies Policy.

7. Records of processing

7.1 We maintain a written record of our processing activities, covering the purposes, the categories of individual and information, the recipients, any transfer outside the United Kingdom, the retention periods, and a description of our security measures.

7.2 The record is reviewed at least annually, and whenever we add a new supplier, a new system or a new processing activity.

8. Data minimisation and accuracy

8.1 We collect only what a purpose actually requires. Forms and systems are reviewed so that fields which serve no operational purpose are removed rather than left in place.

8.2 We take reasonable steps to keep information accurate, and we correct errors promptly when they are identified or reported.

8.3 Where a field is optional, it is marked as optional, and a booking is never refused because an optional field is left blank.

9. Retention and disposal

9.1 We retain personal information against defined periods, driven by our licence conditions, by tax and accounting law, and by the ordinary limitation period for legal claims. The periods applying to customer information are published in our Privacy Policy.

9.2 At the end of the applicable period, information is securely deleted or anonymised. Paper records are destroyed securely. Electronic records are deleted from live systems and from backups in the ordinary backup cycle.

9.3 Retention periods are reviewed annually as part of the review of the record of processing.

10. Security

10.1 We protect personal information with measures appropriate to the risk, including encrypted storage, secure and access controlled systems, role based access limited to what each person needs, secure disposal, and confidentiality obligations in every contract of employment and every partner agreement.

10.2 Access to booking data is granted on a need to know basis. A chauffeur partner receives the details of the journey assigned to them and nothing more.

10.3 Devices used to access our systems must be protected by a passcode and kept secure. Personal information must not be stored on personal devices or shared through unapproved channels.

10.4 Security measures are reviewed after any incident and at least annually.

11. Chauffeur partners, sub contractors and suppliers

11.1 Where another organisation processes personal information on our behalf, we use only providers who can give sufficient guarantees of compliance, and we put a written contract in place before any information is shared.

11.2 Every such contract requires the provider to act only on our documented instructions, to keep the information confidential, to apply appropriate security, to assist us with rights requests and breach notification, to obtain our written authorisation before engaging a further sub processor, and to delete or return the information when the work ends.

11.3 Chauffeur partners receive passenger details solely in order to perform the assigned journey. They must not retain those details afterwards, must not contact the passenger for any other purpose, and must not use them for their own marketing or pass them to anyone else.

11.4 A breach of these obligations is treated as a breach of the partner agreement and may end the relationship.

12. Cameras in vehicles

12.1 Cameras approved by Transport for London are fitted in some vehicles in our network, for the safety of passengers and chauffeurs and for the handling of incidents, insurance claims and disputes. We rely on legitimate interests, having assessed the impact on privacy.

12.2 Microphones are disabled. Cameras record picture only and do not record conversations.

12.3 Footage is overwritten automatically on a rolling cycle and is retained beyond that only where it relates to a reported incident, a claim, a complaint or a legal or regulatory request. Access is restricted to those purposes and is logged.

12.4 Footage is not used to monitor chauffeur performance generally, and is never used for marketing.

12.5 The retention cycle and the request process are set out in our Privacy Policy.

13. Transfers outside the United Kingdom

13.1 Personal information is transferred outside the United Kingdom only where the receiving country is covered by United Kingdom adequacy regulations, or under an International Data Transfer Agreement or the United Kingdom Addendum to the standard contractual clauses, supported by a transfer risk assessment.

13.2 Transfers are recorded in our record of processing and reviewed annually.

14. Individual rights

14.1 We recognise the rights of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent, the right to object to direct marketing at any time, and the right not to be subject to a decision based solely on automated processing. We do not carry out that kind of automated decision making.

14.2 Requests may be made in any form, to any part of the business, and must be passed to the policy owner on the day they are received. A request does not have to mention this policy or use legal language in order to count.

14.3 We acknowledge the request, verify the identity of the person making it, and respond within one calendar month. Where a request is complex or where several have been made, we may extend that period by up to two further months and will explain why within the first month.

14.4 There is no charge. We may refuse a manifestly unfounded or excessive request, or charge a reasonable fee for it, and we explain our reasoning and the right to complain if we do.

14.5 Some rights are qualified. Where a legal obligation requires us to keep a record, an erasure request cannot override it, and we say so plainly rather than leaving the person waiting.

14.6 Requests and outcomes are logged, so that we can demonstrate how each one was handled.

15. Personal data breaches

15.1 A personal data breach is any security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal information. A misdirected email and a lost phone both count.

15.2 Anyone who suspects a breach must report it to the policy owner immediately. Nobody is penalised for reporting a suspected breach in good faith, including one they caused themselves. Late reporting is the greater risk.

15.3 We contain the incident, assess the risk to the people affected, and record the incident, its effects and the action taken, whether or not it is reportable.

15.4 Where a breach is likely to result in a risk to people's rights and freedoms, we notify the Information Commissioner's Office without undue delay and within seventy two hours of becoming aware of it.

15.5 Where the risk is high, we also tell the people affected directly, in plain language, and explain what they can do about it.

16. Data protection by design

16.1 Data protection is considered at the start of any new system, supplier, website feature or process, not after it has gone live.

16.2 We carry out a Data Protection Impact Assessment where processing is likely to result in a high risk, including any significant new use of camera footage, location tracking or automated profiling. The assessment is documented and reviewed by the policy owner before the processing begins.

17. Direct marketing

17.1 Marketing by email, text or automated call is sent only with consent, or to an existing customer about a similar service where the person was given the chance to opt out when their details were collected.

17.2 Consent to marketing is always requested separately from acceptance of our Terms and Conditions. Booking a journey is never treated as agreement to receive marketing.

17.3 Every marketing message identifies us and provides a working method of opting out. Opt outs are actioned promptly and recorded on a suppression list so that the person is not contacted again by mistake.

18. Training and awareness

18.1 Everyone handling personal information on our behalf receives guidance on this policy when they join, and a refresher at least annually.

18.2 Chauffeur partners are briefed on their obligations under section 11 as a condition of joining the network.

19. Third party websites

19.1 Our website links to services we do not control. Their own privacy notices govern any information you provide to them. We review the providers we integrate with, but we cannot be responsible for their practices.

20. Review and complaints

20.1 This policy is reviewed at least annually by the policy owner, and sooner if the law, our systems or our suppliers change materially. The effective date at the top of this page shows the current version.

20.2 If you have a concern about how we handle personal information, contact us at contact@chauffeurz.london. We would rather hear about it and fix it.

20.3 You also have the right to complain to the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

Chauffeurz Premium Services Ltd, company number 15328967. Licensed by Transport for London, operator licence 010942.
450 Bath Road, West Drayton, England, UB7 0EB. Telephone +44 (0203) 826 4125. Email contact@chauffeurz.london.