DriveVision — Privacy Policy
Last updated: 2026-08-21 · Version 2026-08-21
1. Who we are
1.1. DriveVision (“we”, “us”, “our”) operates the website at drivevision.co.uk and the associated online platform, portals, booking tools, scheduling tools, payment pages and chat services (the “Platform”).
1.2. DriveVision is the data controller in respect of personal data collected and processed through the Platform, except where personal data is processed independently by driving instructors, payment providers or other third parties as separate controllers.
1.3. Our company details
- Organisation
- DriveVision
- Website
- https://drivevision.co.uk
- Privacy email
- privacy@drivevision.co.uk
1.4. For privacy questions, data subject requests, or concerns about how we handle personal data, please contact us using the details in section 15.
2. Scope of this Privacy Policy
2.1. This Privacy Policy explains how we collect, use, share, store and protect personal data when you:
- visit the public website;
- register as a Student or Service Partner;
- apply to become an Instructor;
- use the Student, Instructor, Service Partner or Admin portals;
- make a booking or use the Smart Diary;
- purchase a package or make a payment;
- use the in-app chat assistant or messaging;
- subscribe to newsletters or marketing communications;
- apply for a job; or
- otherwise interact with the Platform.
2.2. This Privacy Policy does not apply to third-party websites or services linked from the Platform, such as WhatsApp, GoCardless, Facebook, Google or mapping services. Please review their privacy policies separately.
2.3. Driving instructors are independent professionals. If you enter into a tuition relationship with an instructor, the instructor may also process your personal data as a separate controller for the purposes of providing lessons. This Privacy Policy does not replace any separate notice provided by the instructor.
3. Personal data we collect
3.1. Guests and public website visitors
- Name, email address, phone number, postal code and address where you submit an enquiry, callback request, contact form or newsletter subscription;
- preferred transmission type (manual/automatic) where required;
- IP address, browser type, device information, pages visited, referral source and approximate location inferred from your IP address;
- chat transcript if you use the guest chat assistant, including any personal data you choose to provide;
- cookie and consent preferences.
3.2. Students / Learners
- Name, email address, username, phone number, postal address and pickup location;
- preferred transmission type and lesson duration;
- driving licence status where required;
- booking, lesson, schedule, Smart Diary availability and intake preferences;
- lesson progress, skills, logbook entries, mock test results and performance data;
- payment preferences, package and credit information, retainer status and transaction history;
- messages, chat transcripts, complaints, change requests and referral activity;
- photograph or video if you provide one after passing your test, or if you upload media;
- social login data if you register or log in via Facebook or Google;
- technical and usage data as described in section 3.7.
3.3. Instructors
- Name, email address, phone number, postal address and territory information;
- driving instructor qualifications, insurance and document uploads;
- bank details for payouts, where provided by you and processed securely;
- availability, diary, calendar, lesson records and Smart Diary data;
- performance, academy progress and document verification status;
- messages, chat transcripts and communication history;
- payout information and payment references;
- technical and usage data as described in section 3.7.
3.4. Service Partners
- Name, email address, username, phone number, postal address;
- referral activity, commission records and pipeline data;
- messages, chat transcripts and communication history;
- technical and usage data as described in section 3.7.
3.5. Admin / Staff
- Name, email address, username, role and access permissions;
- activity logs and audit trails related to admin functions;
- technical and usage data as described in section 3.7.
3.6. Job applicants and instructor applicants
- Name, email address, phone number, postal code, CV, application answers and any documents you upload;
- DV-APP application reference and status information;
- communications relating to your application.
3.7. Automatically collected data
- IP address, device type, operating system, browser type and version;
- pages viewed, date and time of visit, time spent on pages, referral URLs;
- approximate location inferred from IP address or mapping features;
- server logs, security logs and technical diagnostics;
- cookie identifiers and similar tracking technologies as described in section 9.
3.8. Chat and messaging data
- If you use the in-app chat assistant, we may collect the messages you send, responses provided by the assistant, and any personal data you include.
- The chat assistant is a rules-based / keyword system. Voice transcription is disabled by default. If we enable voice transcription in the future, we will only do so with appropriate legal basis, safeguards and where applicable, your explicit consent.
- You must not send passwords, payment card numbers, full bank details or other highly sensitive data through chat.
4. How we use personal data and legal bases
We process personal data for the following purposes and rely on the following lawful bases under UK GDPR:
| Purpose | Categories of data | Lawful basis |
|---|---|---|
| Provide the Platform (registration, login, profiles, booking, scheduling, Smart Diary, payments, credits, retainers, messaging and chat) | Identity, contact, profile, booking, payment, scheduling, technical | Performance of a contract (Article 6(1)(b)) |
| Process enquiries, callback requests and lead management | Identity, contact, enquiry details | Contract / steps before contract (Article 6(1)(b)); legitimate interests in responding to enquiries (Article 6(1)(f)) |
| Process package purchases, subscriptions and payments via GoCardless | Identity, contact, payment, transaction data | Contract (Article 6(1)(b)); legal obligation for financial records (Article 6(1)(c)) |
| Instructor applications, onboarding, document verification and activation | Identity, contact, application, documents, verification | Steps before contract; legitimate interests in assessing suitability (Article 6(1)(b), 6(1)(f)) |
| Service Partner referrals, commissions and dashboards | Identity, contact, referral, commission | Performance of a contract (Article 6(1)(b)) |
| Service messages (confirmations, schedule updates, receipts, reminders, security) | Identity, contact, booking, payment, technical | Contract; legitimate interests in administering services (Article 6(1)(b), 6(1)(f)) |
| Marketing communications and newsletters (where subscribed or soft opt-in permitted) | Identity, contact, marketing preferences | Consent (Article 6(1)(a)); legitimate interests for existing-customer marketing under PECR |
| Analyse and improve the Platform, fix bugs, monitor performance and security | Technical, usage, logs, analytics | Legitimate interests (Article 6(1)(f)) |
| Comply with law, handle data subject requests, prevent fraud, enforce Terms | All categories as necessary | Legal obligation (Article 6(1)(c)); legitimate interests in protecting rights and security (Article 6(1)(f)) |
| Process job applications and manage recruitment | Identity, contact, application data | Steps before employment contract; legitimate interests in recruitment (Article 6(1)(b), 6(1)(f)) |
| Where necessary, protect vital interests of an individual | Relevant personal data | Vital interests (Article 6(1)(d)) |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms. You may object to processing based on legitimate interests as set out in section 13.
5. Special category data and children
5.1. We do not routinely collect special category personal data, such as health information, racial or ethnic origin, or biometric data.
5.2. In limited circumstances, such data may appear in documents you choose to upload, messages you send, or chat transcripts. We ask that you do not provide unnecessary special category data unless it is required for a specific service.
5.3. The Platform is intended for learners who are old enough to hold a provisional driving licence. We do not knowingly market to or collect data from children under 13. If you believe a child under 13 has provided personal data, please contact us and we will delete it.
5.4. If you are under 18, please ensure you have permission from a parent or guardian before using the Platform and providing personal data.
6. Marketing and communications
6.1. We will only send you marketing emails or newsletters where you have given consent, or where you are an existing customer and we are permitted to send similar products or services under the soft opt-in rules in PECR.
6.2. You may unsubscribe at any time using the unsubscribe link in any email, or by updating your preferences through the Platform.
6.3. Service-related communications, such as booking confirmations, payment receipts, schedule updates and security notices, are not marketing and may be sent as part of providing the Platform.
10. International transfers
10.1. Some of our third-party providers may process personal data outside the United Kingdom, including in the United States or other countries.
10.2. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as:
- an adequacy decision by the UK Government;
- Standard Contractual Clauses / International Data Transfer Agreement; or
- other permitted mechanisms under UK GDPR.
10.3. If you would like further information about specific transfers, please contact us using the details in section 15.
11. Data retention
11.1. We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, tax and regulatory requirements.
11.2. Retention periods are recorded in our data retention schedule. We apply the principle of storage limitation and retain personal data only for as long as necessary for the purposes described in this policy, including legal, accounting and regulatory requirements.
11.3. Typical retention categories include:
- Enquiry / lead data: retained while active for follow-up, then deleted or anonymised when no longer needed;
- Student account and lesson records: retained for the life of the account and for a reasonable period afterwards to support service history and legal requirements;
- Payment and financial records: retained for six years from the end of the relevant financial year;
- Chat transcripts: retained for a limited operational period, then deleted or anonymised;
- Newsletter subscriber data: retained until you unsubscribe;
- Job and instructor application data: retained for the recruitment process and a short period afterwards, then deleted or anonymised unless you become engaged.
11.4. Some data may be anonymised and retained for analytics purposes. Anonymised data is no longer personal data.
12. Security
12.1. We implement appropriate technical and organisational measures to protect personal data, including:
- encryption in transit using TLS;
- encryption of certain sensitive fields, such as instructor bank details;
- role-based access controls and restricted access to admin functions;
- access control lists for confidential media such as instructor documents and privacy exports;
- security monitoring, logging and incident response procedures;
- hardened environment configuration for production and staging;
- privacy by design and data minimisation where possible.
12.2. No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we take reasonable steps to protect your data.
12.3. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office and, where required, you without undue delay.
13. Your rights under UK GDPR
You have the following rights, subject to legal limitations:
- Right to be informed about how we use your personal data, as set out in this Privacy Policy;
- Right of access to request a copy of personal data we hold about you;
- Right to rectification to request that inaccurate or incomplete data be corrected;
- Right to erasure to request deletion of your personal data in certain circumstances;
- Right to restrict processing to request that we limit how we use your data in certain circumstances;
- Right to data portability to receive your data in a structured, commonly used and machine-readable format, or ask us to transmit it to another controller where technically feasible;
- Right to object to processing based on legitimate interests, including profiling;
- Right not to be subject to automated decision-making including profiling that produces legal or similarly significant effects;
- Right to withdraw consent where processing is based on consent.
You can exercise some of these rights directly through the Platform, including:
- /privacy/my-data/ — access, export and closure requests;
- /privacy/settings/ — consent and privacy preferences;
- /privacy/request/ — guest privacy requests;
- /privacy/consent/ — manage consent (API endpoint used by the cookie banner).
14. Automated decision-making and profiling
14.1. We do not use automated decision-making that produces legal or similarly significant effects concerning you without human involvement.
14.2. The Platform may use automated processes for scheduling, lead routing, slot availability, skills progress display and similar operational functions. These processes are part of the service and are not used to make decisions that have legal or similarly significant effects on you.
15. Contact us and complaints
15.1. If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:
15.2. You have the right to lodge a complaint with the UK supervisory authority:
16. Changes to this Privacy Policy
16.1. We may update this Privacy Policy from time to time. If we make significant changes, we will notify registered users by email, in-app notification or a prominent notice on the Platform.
16.2. The “Last updated” date at the top of this page indicates when the policy was last revised.
We may update this Privacy Policy from time to time. The “Last updated” date above shows when it was last revised.
7. Social login
7.1. If you choose to register or log in using Facebook or Google, those providers will share with us certain data, such as your name, email address and profile picture, in accordance with their privacy policies and your settings.
7.2. We do not receive your Facebook or Google password.
7.3. We may display badges or icons indicating your social login provider in the Platform where relevant.