What we collect, why, who is responsible for it, and what you can do about it — including for operators whose machine use is recorded by TAD i-am.
This policy was written around the data TAD i-am actually processes — tags, licences, training expiry dates, GPS positions, journeys, ignition events, IMEI and battery voltages. It is a solid starting point, but it is not legal advice. Have it reviewed before you publish, and check it against what your systems really do.
Anything highlighted like this needs your real values — ICO registration number, named privacy contact, hosting and network providers, and retention periods. Search the page for the highlights and replace them all.
T.A.D. Communications Ltd (“TAD”, “we”, “us”) is a company registered in England and Wales, number 03429988, with its registered office at Unit 3 Peerglow Industrial Estate, Olds Approach, Watford, Hertfordshire WD18 9SR and its trading address at 15 Chancerygate Business Centre, Whiteleaf Road, Hemel Hempstead, Hertfordshire HP3 9HD.
We are registered with the Information Commissioner's Office under registration number [ICO registration number].
For questions about this policy or about your information, contact [email protected] or call 01923 712430, marking it for the attention of [named privacy contact].
This is the most important thing to understand about TAD i-am, so it is worth being plain about it.
We decide how and why information is used when we are dealing with you as our customer or enquirer: website enquiries, quotes, orders, invoices, support calls, and our own business records.
When your organisation uses the TAD i-am system, the records about your operators, drivers and staff — their names, tags, licences, training expiry dates, locations and machine activity — are yours. Your organisation is the controller of that data and we act as your processor, handling it on your documented instructions.
If you are an operator or driver whose activity is recorded by TAD i-am, and you want to exercise your rights over that data, the first place to go is your employer. We will assist them in responding, but we cannot act on their data without their instruction.
This site is deliberately light-touch. We do not run advertising trackers, and we do not sell data to anyone.
When TAD i-am is running on your machines, the system processes the following. Much of it relates to identifiable individuals, which is why section 2 matters.
So that machines can be used outside mobile coverage, a copy of the driver and training records needed to make an access decision is held on the i-am unit in each machine, and refreshed automatically whenever those records change in the portal.
Because a tag is held by a named person and location is recorded against the machine they started, this data can show where an identifiable individual was, and when. It should be treated accordingly.
Vehicle telematics is a form of workplace monitoring, and there are rules about it. Your employer — not TAD — is responsible for meeting them, but you are entitled to know how this works.
If you believe you are being monitored without being told, raise it with your employer. If that does not resolve it, you can complain to the ICO — see section 11.
Where we are the controller, we rely on the following:
| What for | Lawful basis |
|---|---|
| Responding to enquiries and preparing quotations | Legitimate interests — responding to someone who has approached us |
| Supplying goods, hire and fitting; managing your account | Performance of a contract |
| Support, warranty work and service records | Performance of a contract, and our legitimate interest in supporting what we install |
| Invoicing, accounting and statutory records | Legal obligation |
| Site security and keeping systems working | Legitimate interests — protecting our business and our customers |
| Occasional updates about products and services to existing customers | Legitimate interests, with an unsubscribe link on every message |
Where we act as your processor for TAD i-am data, the lawful basis is a matter for you as controller. Most organisations rely on legitimate interests, or on legal obligation where the purpose is health and safety compliance. You should record which, and be able to justify it.
We do not sell personal information, and we do not share it for anyone else's marketing.
We do use suppliers who process data on our behalf, under contract:
We may also disclose information where we are required to by law, by a regulator, or by a court, and where necessary to establish or defend legal claims.
We aim to keep personal data within the United Kingdom or the European Economic Area. Where a supplier processes data outside those areas, we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, together with appropriate safeguards.
Details of the current arrangements are available on request: [confirm where your hosting and mapping suppliers process data].
| Type | Kept for |
|---|---|
| Enquiries that do not lead to an order | 12 months |
| Customer and contract records, install notes | 6 years after the end of the relationship, to cover the limitation period |
| Invoices and accounting records | 6 years, as required by HMRC |
| TAD i-am event, location and journey data | [retention period] — this is your decision as controller, and should be no longer than you can justify |
| Portal user accounts | For as long as the account is active, then deleted on your instruction |
| Website server logs | [period set by your host] |
When a retention period ends we delete the data or anonymise it so that no individual can be identified from it.
No system is completely secure. If a breach occurs that is likely to result in a risk to people's rights and freedoms, we will notify the ICO within 72 hours where we are the controller, and will notify you without undue delay where we are your processor.
This website does not set advertising or analytics cookies.
The only third-party content that can set a cookie is the Google Map on the contact page, and that is not loaded until you press the button to load it. If you never press it, Google receives nothing from your visit.
The tad-tracker portal uses a strictly necessary session cookie to keep you logged in. It is required for the service to work and cannot be switched off.
You can block or delete cookies through your browser settings. Doing so will not affect this website.
Under UK data protection law you have the right to:
To exercise any of these where we are the controller, email [email protected]. We will respond within one month. There is normally no charge.
If your request concerns data held in the TAD i-am system by your employer, please go to them first — see section 2.
If you are unhappy with how we have handled your information, tell us first on [email protected] or 01923 712430 and we will try to put it right.
You also have the right to complain to the Information Commissioner's Office at any time:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint
We review this policy periodically and will update it when our practices change. The date at the top of the page shows when it was last revised. Where a change materially affects how we use your information, we will tell affected customers directly rather than relying on you noticing.
Questions about this document, or need our data processing agreement for your compliance file? Ring 01923 712430 or email [email protected]. We would rather explain it than have you guess.