Legal

Privacy Policy

What we collect, why, who is responsible for it, and what you can do about it — including for operators whose machine use is recorded by TAD i-am.

Last updated
11 August 2026
Version
1.0
Sections
15
Governs
UK GDPR / DPA 2018
Please read before publishing

This policy was written around the data TAD i-am actually processes — tags, licences, training expiry dates, GPS positions, journeys, ignition events, IMEI and battery voltages. It is a solid starting point, but it is not legal advice. Have it reviewed before you publish, and check it against what your systems really do.

Anything highlighted like this needs your real values — ICO registration number, named privacy contact, hosting and network providers, and retention periods. Search the page for the highlights and replace them all.

01Who is responsible for your information

T.A.D. Communications Ltd (“TAD”, “we”, “us”) is a company registered in England and Wales, number 03429988, with its registered office at Unit 3 Peerglow Industrial Estate, Olds Approach, Watford, Hertfordshire WD18 9SR and its trading address at 15 Chancerygate Business Centre, Whiteleaf Road, Hemel Hempstead, Hertfordshire HP3 9HD.

We are registered with the Information Commissioner's Office under registration number [ICO registration number].

For questions about this policy or about your information, contact [email protected] or call 01923 712430, marking it for the attention of [named privacy contact].

02Controller or processor — which applies

This is the most important thing to understand about TAD i-am, so it is worth being plain about it.

Where we are the controller

We decide how and why information is used when we are dealing with you as our customer or enquirer: website enquiries, quotes, orders, invoices, support calls, and our own business records.

Where we are a processor

When your organisation uses the TAD i-am system, the records about your operators, drivers and staff — their names, tags, licences, training expiry dates, locations and machine activity — are yours. Your organisation is the controller of that data and we act as your processor, handling it on your documented instructions.

If you are an operator or driver whose activity is recorded by TAD i-am, and you want to exercise your rights over that data, the first place to go is your employer. We will assist them in responding, but we cannot act on their data without their instruction.

03Information we collect through this website

This site is deliberately light-touch. We do not run advertising trackers, and we do not sell data to anyone.

  • Enquiry details. The enquiry form on our contact page does not submit to a server. It opens your own email application with the details filled in, so nothing is stored on this website. Once you send that email, we hold it as we would any other email — see below.
  • Correspondence. Name, company, email address, telephone number and whatever you tell us about your vehicles, machines or requirements.
  • Server logs. Our hosting provider records standard technical information such as IP address, browser type, pages requested and timestamps, for security and to keep the site running.
  • Maps. The map on our contact page is not loaded until you click to load it. If you do, Google will receive your IP address and may set cookies under its own privacy policy.

04Information processed by the TAD i-am system

When TAD i-am is running on your machines, the system processes the following. Much of it relates to identifiable individuals, which is why section 2 matters.

About people

  • First and last name, and work email address.
  • Portal password (stored in hashed form) and access level — Developer, Admin, Manager, User or Driver.
  • The entity or branch the person belongs to.
  • Assigned Bluetooth Tag number and tag battery level.
  • Licence types held, and the expiry date recorded against each.

So that machines can be used outside mobile coverage, a copy of the driver and training records needed to make an access decision is held on the i-am unit in each machine, and refreshed automatically whenever those records change in the portal.

About machines and their use

  • IMEI and SIM number of the unit, vehicle registration, make and model, and the entity it belongs to.
  • Position and postcode, journeys and routes, mileage and time stamps.
  • Ignition on and off events, movement and stationary states, and movement detected while a vehicle is marked as parked.
  • Start-with-tag events, and attempts that were refused.
  • Tag and vehicle battery voltage, G-force readings across three axes, and unit firmware status.

Because a tag is held by a named person and location is recorded against the machine they started, this data can show where an identifiable individual was, and when. It should be treated accordingly.

05If you are an operator or driver being tracked

Vehicle telematics is a form of workplace monitoring, and there are rules about it. Your employer — not TAD — is responsible for meeting them, but you are entitled to know how this works.

  • Your employer must tell you clearly that monitoring is happening, what is collected and why. This should not come as a surprise to you.
  • Your employer should have carried out a data protection impact assessment before deploying the system, and be able to justify the monitoring as necessary and proportionate.
  • You have the right to ask your employer for a copy of the data held about you, and to challenge it if it is wrong.
  • Where a vehicle may be used privately, your employer should explain what happens outside working hours — for example whether tracking is switched off, and how.

If you believe you are being monitored without being told, raise it with your employer. If that does not resolve it, you can complain to the ICO — see section 11.

06Why we use information, and our lawful basis

Where we are the controller, we rely on the following:

What forLawful basis
Responding to enquiries and preparing quotationsLegitimate interests — responding to someone who has approached us
Supplying goods, hire and fitting; managing your accountPerformance of a contract
Support, warranty work and service recordsPerformance of a contract, and our legitimate interest in supporting what we install
Invoicing, accounting and statutory recordsLegal obligation
Site security and keeping systems workingLegitimate interests — protecting our business and our customers
Occasional updates about products and services to existing customersLegitimate interests, with an unsubscribe link on every message

Where we act as your processor for TAD i-am data, the lawful basis is a matter for you as controller. Most organisations rely on legitimate interests, or on legal obligation where the purpose is health and safety compliance. You should record which, and be able to justify it.

07Who we share information with

We do not sell personal information, and we do not share it for anyone else's marketing.

We do use suppliers who process data on our behalf, under contract:

  • Hosting and cloud infrastructure for the portal and this website — [hosting provider].
  • Mobile network operators providing the SIM connectivity in each unit — [network provider].
  • Mapping — Google Maps, used to display positions and routes.
  • Email, accounting and business software[list your providers].
  • Approved installers, where fitting is carried out other than at our workshop.

We may also disclose information where we are required to by law, by a regulator, or by a court, and where necessary to establish or defend legal claims.

08Where information is held

We aim to keep personal data within the United Kingdom or the European Economic Area. Where a supplier processes data outside those areas, we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, together with appropriate safeguards.

Details of the current arrangements are available on request: [confirm where your hosting and mapping suppliers process data].

09How long we keep it

TypeKept for
Enquiries that do not lead to an order12 months
Customer and contract records, install notes6 years after the end of the relationship, to cover the limitation period
Invoices and accounting records6 years, as required by HMRC
TAD i-am event, location and journey data[retention period] — this is your decision as controller, and should be no longer than you can justify
Portal user accountsFor as long as the account is active, then deleted on your instruction
Website server logs[period set by your host]

When a retention period ends we delete the data or anonymise it so that no individual can be identified from it.

10How we keep it safe

  • Portal access is controlled by individual accounts with defined access levels, and passwords are stored hashed rather than in plain text.
  • Data is transmitted between the units and the portal over encrypted connections, in both directions — event data up, driver and training records down.
  • Access to customer data by our own staff is limited to those who need it to do their job.
  • We ask customers not to share accounts between individuals, and to remove access promptly when someone leaves. This is the single most common weak point in any system of this kind.

No system is completely secure. If a breach occurs that is likely to result in a risk to people's rights and freedoms, we will notify the ICO within 72 hours where we are the controller, and will notify you without undue delay where we are your processor.

11Cookies

This website does not set advertising or analytics cookies.

The only third-party content that can set a cookie is the Google Map on the contact page, and that is not loaded until you press the button to load it. If you never press it, Google receives nothing from your visit.

The tad-tracker portal uses a strictly necessary session cookie to keep you logged in. It is required for the service to work and cannot be switched off.

You can block or delete cookies through your browser settings. Doing so will not affect this website.

12Your rights

Under UK data protection law you have the right to:

  • be told how your information is used — which is what this page is for;
  • request a copy of the information held about you;
  • have inaccurate information corrected;
  • ask for information to be deleted, where there is no good reason to keep it;
  • ask us to restrict how it is used while a concern is looked into;
  • object to processing carried out on the basis of legitimate interests;
  • receive certain information in a portable format; and
  • object to decisions made about you by purely automated means.

To exercise any of these where we are the controller, email [email protected]. We will respond within one month. There is normally no charge.

If your request concerns data held in the TAD i-am system by your employer, please go to them first — see section 2.

13Complaints

If you are unhappy with how we have handled your information, tell us first on [email protected] or 01923 712430 and we will try to put it right.

You also have the right to complain to the Information Commissioner's Office at any time:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint

14Changes to this policy

We review this policy periodically and will update it when our practices change. The date at the top of the page shows when it was last revised. Where a change materially affects how we use your information, we will tell affected customers directly rather than relying on you noticing.

Questions about this document, or need our data processing agreement for your compliance file? Ring 01923 712430 or email [email protected]. We would rather explain it than have you guess.