FleetPro UK

Home · Version 2.0 · Effective 4 September 2026

Information Security Policy

1. Purpose

This policy establishes the company-wide information security requirements of FleetSmart Consultants. It applies to business information, personal data, customer information, operational records, software systems, cloud services and integrations, including FleetPro UK and the DVLA Access to Driver Data (ADD) service.

2. Scope

This policy applies to all information created, received, processed, stored or transmitted by FleetSmart Consultants, and to all people, devices, applications, databases, cloud platforms, suppliers and customer-facing services used for company business.

3. Security objectives

FleetSmart Consultants will protect the confidentiality, integrity and availability of information; restrict access to authorised persons; minimise unnecessary collection and disclosure; maintain appropriate technical and organisational controls; and respond promptly to suspected security incidents.

4. Roles and responsibility

Overall responsibility for information security rests with the authorised proprietor/administrator of FleetSmart Consultants. Access to systems and data must be granted only where required for legitimate business purposes. Customer organisations remain responsible for the actions and permissions of their own authorised users where they act as Data Controller.

5. Information classification

  • Public - information approved for public release, such as published marketing material.
  • Internal - routine business information intended for FleetSmart Consultants use but not public distribution.
  • Confidential - customer, commercial, contractual, account, driver, employee or other personal/business information requiring controlled access.
  • Restricted - particularly sensitive information requiring the strongest controls, including raw DVLA ADD responses, privileged credentials, API secrets, authentication tokens and security configuration.

6. Access control and authentication

  • Individual user accounts must be used; shared accounts are not permitted where individual accounts are available.
  • Access is granted on the principle of least privilege and must be removed or amended when no longer required.
  • FleetPro UK customer users are associated with an organisation and may access only information belonging to that organisation.
  • Supabase Row Level Security (RLS) is used where applicable to enforce organisation and tenant separation at database level.
  • Passwords must be robust and stored securely. Privileged passwords must not be written down or stored insecurely, and administrative devices must not rely on browser-stored passwords for privileged DVLA-related access.
  • Multi-factor authentication should be enabled for privileged cloud and administrative accounts wherever supported and practicable.

7. Secrets, API keys and credentials

  • API keys, service-role credentials, database secrets and other privileged credentials must never be embedded in public source code or exposed in client-side/frontend bundles.
  • Secrets must be held in approved server-side environment or secret-management facilities and access limited to authorised administration.
  • Credentials must be rotated promptly following suspected compromise and periodically where appropriate.

8. Devices and physical security

  • Devices used for company administration must use supported software, current security updates and regularly updated anti-malware/anti-virus protection where applicable.
  • Devices must be protected by authentication and locked whenever unattended.
  • Unauthorised persons must not be permitted to use an authenticated administrative session.
  • Confidential or Restricted printed information must not be left in publicly accessible areas and must be securely destroyed when no longer required.

9. Cloud services, hosting and encryption

  • Approved cloud services must be configured with appropriate access controls and security settings.
  • Data transmitted to and from company web services must use encrypted HTTPS/TLS connections.
  • FleetPro UK is deployed using Vercel infrastructure, which may serve or process application traffic through infrastructure in the United Kingdom, European Union and United States.
  • The Supabase database used by FleetPro UK is hosted in London, United Kingdom.
  • Material changes to hosting, data location or subprocessors affecting personal or Restricted information must be assessed before implementation.

10. Secure software development and vulnerability management

  • Security-sensitive changes must be reviewed and tested before production deployment.
  • Dependencies and software packages must be monitored for known vulnerabilities and updated appropriately.
  • Authentication, authorisation and RLS policies must be tested to prevent cross-organisation access.
  • Production secrets must be excluded from repositories, logs and frontend code.
  • Rate limiting and abuse protection should be applied to authentication and other sensitive endpoints where appropriate.
  • Identified security weaknesses must be prioritised according to risk and remediated in a timely manner.

11. Data minimisation, retention and deletion

Information must be retained only for as long as required for its legitimate business, contractual, legal or regulatory purpose. Where a defined retention period applies, records must be securely deleted or anonymised when that period expires. Retention requirements for specific systems or data types are recorded in the relevant handling procedure or operational process.

12. Backups, resilience and availability

FleetSmart Consultants uses approved cloud providers for hosted application and database resilience. Backup, recovery and availability arrangements must be reviewed periodically and restoration capability considered as part of business continuity planning.

13. Incident and personal data breach management

Suspected loss, unauthorised disclosure, unauthorised access, malware, credential compromise or other security incidents must be contained and investigated without undue delay. Relevant logs and evidence should be preserved, affected credentials secured, and affected Data Controllers, regulators, DVLA or other parties notified where legally or contractually required. Incidents and corrective actions must be recorded.

14. Suppliers and third parties

Suppliers that host, process or can access company information must be selected and managed with regard to information security and data-protection requirements. Supplier access must be limited to what is necessary to provide the service. Appropriate contractual and data-processing terms must be used where required.

15. DVLA Access to Driver Data (ADD)

  • DVLA-derived information is classified as Restricted.
  • Where FleetSmart Consultants acts under the DVLA Processor Model, the customer organisation is the Data Controller and FleetSmart Consultants acts as Data Processor in accordance with documented instructions and the applicable data-processing agreement.
  • Administrative access to raw DVLA response data is restricted to the authorised FleetSmart Consultants administrator. Customer users are provided with a FleetPro UK generated licence-check report rather than unrestricted raw response data.
  • DVLA licence-check records are stored in the Supabase London database for 12 months from the check date, subject to any lawful or documented Controller requirement requiring different treatment.
  • DVLA credentials and privileged integration secrets must remain server-side and must not be exposed to customer users or frontend code.
  • Organisation-level access controls and RLS must prevent one customer organisation from accessing another organisation's drivers or licence-check reports.
  • International access or transfer implications associated with supporting infrastructure must be assessed and handled consistently with UK data-protection requirements and declarations made to DVLA.

16. Review and compliance

This policy will be reviewed at least annually and following a material change to systems, hosting, data processing, legal or contractual requirements, or a significant security incident. Compliance is mandatory for anyone authorised to access FleetSmart Consultants systems or information.

Approved by Rhys Hughes on behalf of FleetSmart Consultants — 4 September 2026. Version 2.0.