Privacy Policy
Last updated: 29 May 2026
NEAT Transport ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our accessible transport booking platform.
We comply with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
1. Information We Collect
Personal Information
We collect the following types of personal information:
- Account Information: Name, email address, phone number, role (Admin, Coordinator, Manager, Driver)
- Business Information: Company name, address, registration details (for business accounts)
- Driver Information: License number, vehicle details, accessibility features, insurance details, DBS check status
- Booking Information: Pickup/dropoff locations, postcodes, date and time, passenger count
- Accessibility Needs: Wheelchair requirements, assistance needs, communication preferences, medical considerations
- Passenger Initials: For audit purposes (we do NOT collect full resident names for privacy)
Automatically Collected Information
- Device Information: IP address, browser type, operating system
- Usage Data: Pages visited, features used, time spent on platform
- Location Data: Approximate location (for service availability)
2. How We Use Your Information
We use your information for:
- Service Delivery: Processing bookings, matching passengers with appropriate drivers, coordinating accessible transport
- Communication: Booking confirmations, driver notifications, service updates
- Safety & Compliance: Verifying driver credentials, maintaining audit trails (CQC compliance), incident reporting
- Platform Improvement: Analyzing usage patterns, improving matching algorithms, enhancing accessibility features
- Legal Obligations: Complying with care sector regulations, responding to legal requests
- Account Management: User authentication, password resets, role-based access control
3. Legal Basis for Processing
Under GDPR, we process your data based on:
- Contract Performance: Processing bookings and providing transport services
- Legitimate Interests: Platform security, fraud prevention, service improvement
- Legal Obligation: CQC compliance, safeguarding requirements, tax/accounting obligations
- Consent: Marketing communications (where applicable)
- Vital Interests: Emergency situations involving passenger safety
4. Information Sharing
We share your information with:
Within the Platform
- Drivers: Receive booking details (pickup/dropoff, time, accessibility needs) - NOT full passenger names
- Care Company Staff: Managers see bookings for their houses; Coordinators oversee their areas; Admins have full oversight
- Audit Trail: All booking actions are logged with user initials for CQC compliance
Third-Party Service Providers
- Hosting: Cloudflare (infrastructure and security)
- Payment Processing: PayPal (for future payment features)
- Email Services: For booking confirmations and notifications
Legal Requirements
We may disclose information if required by law, court order, or regulatory authority (e.g., CQC, police investigations).
5. Data Retention
- Active Accounts: Data retained while account is active and for 12 months after last activity
- Booking Records: Retained for 7 years (CQC compliance requirement)
- Incident Reports: Retained for 7 years (legal and insurance purposes)
- Driver Credentials: Retained while driver is active, plus 3 years for insurance purposes
- Marketing Data: Until consent is withdrawn or account deleted
6. Your Rights Under GDPR
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data (subject to legal obligations)
- Restrict Processing: Limit how we use your data
- Data Portability: Receive your data in a machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for marketing communications
- Complain: Lodge a complaint with the Information Commissioner's Office (ICO)
To exercise your rights, contact us at: privacy@neattransport.co.uk
7. Data Security
We implement appropriate security measures:
- Encryption: All data transmitted using HTTPS/TLS encryption
- Authentication: Secure password hashing, role-based access control
- Infrastructure: Hosted on secure Cloudflare infrastructure
- Access Controls: Limited staff access to personal data on need-to-know basis
- Regular Audits: Security reviews and vulnerability assessments
- Incident Response: Procedures for data breach notification within 72 hours
9. Third-Party Services
Our platform may contain links to third-party websites or services. We are not responsible for their privacy practices. Please review their privacy policies before providing any personal information.
10. Children's Privacy
Our platform is designed for use by care professionals and drivers (18+). We do not knowingly collect personal information from children under 18. Bookings for vulnerable adults and children are made by authorized care staff, and we only collect passenger initials (not full names) for privacy protection.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a notice on our platform. The "Last updated" date at the top indicates when changes were last made.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
NEAT Transport
Email: privacy@neattransport.co.uk
Data Protection Officer: dpo@neattransport.co.uk
Information Commissioner's Office (ICO):
If you're not satisfied with our response, you can contact the ICO:
https://ico.org.uk/make-a-complaint/