Privacy notice
Last updated 30 August 2026
This notice explains what Haulage One Stop Solution Ltd does with personal data in TOC, which is the transport operator compliance service at mytoc.co.uk and in the TOC mobile app.
Who we are
Haulage One Stop Solution Ltd is a company registered in England and Wales, company number 16774658, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. TOC is our product, and the company is registered with the Information Commissioner’s Office under registration reference ZC173085.
Questions about this notice, or about personal data we hold, go to privacy@mytoc.co.uk, or in writing to the registered office above. Either reaches the people responsible for data protection here.
The two roles we act in, and why it matters to you
TOC holds two different kinds of personal data, and we are responsible for them in different ways. Which one applies to you decides who you ask about your data.
Records an organisation keeps about its workforce
When a transport operator uses TOC, it puts records into the service about the people it is responsible for. Names, job titles, the licences and cards they hold, what they have been asked to read and acknowledged, the vehicle checks they have completed, and any defects they have reported.
For those records the operator is the data controller and we are a data processor acting on its instructions. The operator decides who appears on its staff list, what it records about them, and how long it keeps it. We do not decide any of that and we do not use those records for our own purposes.
If you are a driver, or anyone else whose details are in TOC because an organisation put them there, ask that organisation first. They decide what is held about you and they are the ones who can correct or remove it. TOC is used for employees, agency drivers, contractors, warehouse and office staff and others, so the organisation responsible for your records is not always your employer.
If you come to us instead, we will tell you who the organisation is and pass your request to them promptly. We will not change or delete their records of our own accord, because that decision is theirs to make. We are required to help them answer you, and we do: that is part of what a processor is for, and it is written into our agreements.
We do not collect these records from you. They reach us because an organisation entered them or uploaded them, or because you used TOC and it recorded what you did. Your sign-in details arrive the same way: if you have a TOC account, the organisation created it and gave you the username and the first password, rather than you signing up. If you want to know where a particular detail about you came from, the organisation can tell you, and it is their job to have told you they use a service like this.
Accounts, and this website
For the TOC account of anyone who uses it, whether they bought it, administer it or were given a sign-in by the organisation they work for, and for anybody who visits this website, we are the data controller. That covers the account itself: who it belongs to, keeping it secure, and the technical records of it being used. It is separate from the compliance records inside the organisation, which are the organisation’s. The rest of this notice tells you what we do in that role, and it also describes what happens to workforce records so that operators and their people can see how the service handles them.
What is held
| What | Who it is about | Why it is there |
|---|---|---|
| Name, email address or username, job title, and where an organisation uses them, a staff reference, site and department | Account holders and members of a workforce | To identify who is signing in and what they are responsible for |
| Qualifications an operator chooses to record, such as a driving licence, a driver CPC card, a tachograph card or a medical, with reference numbers and expiry dates | Members of a workforce | So an operator can show that the people driving its vehicles are entitled and fit to do so |
| Scanned documents an operator attaches to those records | Members of a workforce | Evidence behind the dates, where the operator chooses to hold it |
| Records of documents issued and acknowledged, including when a person read and acknowledged them | Members of a workforce | To show what people have been told and when |
| Vehicle checks, including the answers given, how long the check took, photographs or video of any defect, the driver's signature on the declaration, and any note recorded when a defect is repaired | Drivers | To record that a walkaround was carried out and what it found |
| Answers to an assessment attached to a document, the mark, and whether it was passed | Members of a workforce | So an organisation can show that a person understood what they were asked to read, rather than only that they opened it |
| An audit record of actions taken in the service, and who took them | Anybody using TOC | So an operator can show what happened to a record and account for it afterwards |
| Technical information created by using the service: your IP address, the kind of device and operating system, the app or browser version, sign-in session and device records, and a report when something goes wrong | Anybody using TOC | To keep the service working and secure, to keep you signed in, and to find and fix faults |
Data about health
An operator may record that a driver holds a medical certificate and when it expires, and may attach a copy of it. That is data concerning health, which UK data protection law treats as a special category and protects more strictly.
The organisation acting as controller decides whether to hold it, and is responsible for identifying both a lawful basis under Article 6 and, because it is special category data, a condition under Article 9. Depending on the condition it relies on, the Data Protection Act 2018 may also require it to keep an Appropriate Policy Document. Which of those applies depends on the organisation and how it operates, and it is not something we can decide on anybody’s behalf.
Where we act as processor we handle this information only on that organisation’s instructions, we do not read it for any purpose of our own, and it is subject to the same access controls as the rest of that organisation’s records.
What we do not collect
The TOC mobile app does not collect location data. It has no access to your location, asks for no location permission, and records nothing about where you or a vehicle are. It reads no contacts, no calendars and no messages, and it does not track you across other apps or websites.
The app can use the camera, the microphone and your photo library, and only when you choose to attach something to a defect you are reporting. A photograph or video of a fault can catch somebody who happens to be nearby, and where that happens the organisation running the check is responsible for it as part of its own records. Drivers are asked to photograph the fault and not the yard. Nothing is captured in the background. Where you attach a photograph or video, the record notes whether it was taken at the time or chosen from your phone, because those are different kinds of evidence.
Our lawful bases
Where we are the controller, we rely on the following.
- Contract. Where our agreement to provide TOC is with you personally, for example if you are a sole trader who has taken out TOC yourself, or where you have asked us for something before entering into one.
- Legitimate interests. Creating, maintaining and securing accounts for the people who use TOC on behalf of an organisation, keeping the service working, preventing misuse, and contacting account holders about the service they are using. Most people who use TOC have no contract with us: their organisation does, and their account exists because that organisation asked for it. We have weighed our interest in running the service against the interests of the people affected and consider it fair, because it goes no further than running it. You can object; see the section on your rights.
- Legal obligation. Keeping business records where the law requires us to.
Where an organisation is the controller of its own workforce records, the lawful basis for each kind of information it holds is that organisation's to identify, and it is not something we determine or assume. TOC can hold records about drivers, warehouse and office staff, agency workers and contractors, and what justifies holding one will not always justify holding another.
Where the data is held, and who else handles it
The database, the sign-in system and every uploaded file are stored in London, in the United Kingdom, and the service runs there. That is where the records sit at rest, and it is worth separating from where they can be reached: our suppliers are international businesses, and their terms allow them to process data and provide support from outside the United Kingdom, including the United States. So the honest position is that the records are held here and may be accessed from elsewhere in the course of running the service and supporting it.
Where that happens, UK law requires an approved safeguard. We have accepted the data processing terms of each supplier listed below, and the table names the transfer mechanism each of those terms provides for. Which one carries a particular transfer depends on that supplier's terms, so the table describes what is in place rather than ruling on every flow, and we keep it under review as suppliers change their terms.
| Supplier | What they do | Where |
|---|---|---|
| Supabase | Database, sign-in, and storage of uploaded files | Stored in London. Support and administration may reach it from elsewhere. Its terms provide for the UK Addendum to the standard contractual clauses |
| Vercel | Runs the website and the service it talks to | Served from London. Its terms allow processing in the United States and elsewhere, and provide for the UK International Data Transfer Addendum |
| Resend | Delivers the service's email, such as an invitation to join an organisation. It receives the recipient's address and the content of that message, and nothing else | Runs in the United States. Its terms provide for the standard contractual clauses with the UK Addendum |
| Sentry | Receives a report when the mobile app or the service behind it hits an error. We configure both to send no personal information by default and to strip the signed-in user, the request and the trail of requests leading to it, so what is meant to remain is the fault, the version it happened on and the kind of device. A crash report is built from whatever the code was holding when it failed, so we cannot promise nothing personal is ever caught in one | Held in Germany, with processing and support from the United States permitted under its terms, which provide for the UK Addendum to the standard contractual clauses |
| Expo | Builds the mobile app and delivers updates to it. We send it no records from TOC, but a handset checking for an update makes a request Expo receives directly, and by its own account that gives it the device operating system, a randomised token telling it whether an update has been downloaded, and the IP address it came from. Expo sets out what it does with that in its own privacy policy | United States. Expo certifies to the UK Extension to the EU-US Data Privacy Framework |
This list is the current one. If we add a supplier that will handle personal data, or replace one of these, we will tell the organisations using TOC beforehand and update this page, so that anybody who wants to object has the chance before it happens.
We do not sell personal data, we do not share it for advertising, and we do not use it to train machine learning models. TOC does not take payments at present, so there is no payment provider on this list. When that changes the provider will be named here before it starts.
How long it is kept
Workforce records are kept for as long as the organisation that controls them wants them kept. Compliance records typically need to be kept for a period after somebody leaves, so that the organisation can still account for what happened while they were there, and it will have its own retention policy for that.
Where we are the controller, we work to these periods.
- Account details are kept while the organisation is using TOC, and for up to six years after the arrangement ends. We chose six years because it matches the period in which a contract claim can usually be brought, and the period we keep our business records for. Where we do not need something for that long, we delete it sooner.
- Error reports are deleted automatically by our error reporting supplier. Its published retention runs to 90 days at most and is shorter on some plans, and we do not keep our own copy.
- Sign-in sessions expire on their own. A remembered device lasts 30 days unless it is used again.
If we need to keep something longer than this, it will be because a dispute, an investigation or a legal duty requires it, and only for as long as that lasts.
Deleting something removes it from the service, and it can survive a little longer in backups. Our database is backed up daily so that it can be restored after a failure, and a record deleted today will still appear in a backup taken yesterday until that backup ages out. We do not go into backups to retrieve deleted records, and they are not used for any purpose other than restoring the service.
When an organisation stops using TOC we delete or return its data on request, and delete what remains after any period agreed in the contract.
Your rights
Under UK data protection law you can ask to see the personal data held about you and to have it corrected. You can also ask for it to be deleted, for its use to be restricted, or object to how it is used. Those last three depend on the circumstances and on the lawful basis the information is held under, so they do not apply to everything in every case. A request to delete a compliance record, for example, may be refused where the organisation holding it has to keep it.
Where we rely on legitimate interests, you can object. If you do, we will stop unless we can show compelling grounds that override your interests, or we need to keep the information to establish, exercise or defend a legal claim. Tell us what it is about your situation that makes the processing wrong for you, because that is what we have to weigh.
You may also have the right to receive information in a portable form, though only where the conditions for that right are met, which broadly means information you provided that is held by automated means under consent or a contract.
You can complain to the Information Commissioner’s Office at ico.org.uk at any time, though we would rather you raised it with us first so we can put it right.
Which of us you ask depends on the record. For anything an organisation holds about you in TOC, ask that organisation. For your own TOC account, or for anything about this website, ask us at privacy@mytoc.co.uk, or write to us at the registered office above. We will need to be reasonably sure who you are before we hand over personal information, so we may ask you for enough to confirm it, and we will not ask for more than we need. We normally respond within one month. Where the law allows us longer, for a request that is unusually complex or where somebody has made several, we will tell you and explain why.
Keeping it secure
Access is decided by the database itself rather than by the screens in front of it, so somebody using TOC receives records belonging to an organisation they are a member of and not to any other. Uploaded files are private, are never publicly addressable, and are reached only through short-lived links issued to somebody already entitled to see them. Passwords are checked against known breaches, and accounts can be protected with a second factor.
A small number of our people hold the administrative access needed to run and repair the service. That access can reach stored information, including uploaded documents and photographs, and authorised staff may use it where it is necessary to provide support an organisation has asked for, to investigate a fault, or to keep the service secure. It is limited to those whose job needs it and is not a way for anybody to read through customer records at will. When we say we do not use an organisation’s records for our own purposes, this is the exception we mean it to allow: working on the service, at the organisation’s request or to keep it running, and nothing else. Our suppliers hold comparable access to their own platforms under their terms with us.
No service can promise it will never suffer a breach. What happens next depends on which role the information was held in.
Where we are the controller, we assess the breach and report it to the Information Commissioner’s Office where the law requires, within 72 hours of becoming aware of it where that duty applies, and tell the people affected where the law requires that too.
Where we act as processor for an organisation’s workforce records, we tell that organisation without undue delay after becoming aware of a breach affecting its data, and give it what it needs to respond. Deciding whether the Information Commissioner’s Office or the individuals concerned have to be told is then that organisation’s call to make, because it is the controller.
Automated decisions
Where a document carries an assessment, TOC marks the answers automatically against the pass mark the organisation set, and records the result. It also works out and displays whether a qualification is valid, due to expire or out of date.
Nothing follows from any of that on its own. What happens after a failed assessment or an expired licence is decided by a person at the organisation, and TOC takes no employment, disciplinary or compliance action by itself. We do not make decisions about anybody by solely automated means that produce a legal effect or anything similarly significant.
Marketing
We do not use TOC account information for direct marketing, and we do not pass personal data to anybody else for their advertising.
That is separate from messages about the service itself. A message telling you something needs your attention, or that your account has changed, is not marketing, and you cannot opt out of the ones the service depends on. TOC sends email of that kind, such as an invitation to join an organisation, and nothing more. If we ever start sending marketing we will update this notice first and set out the choices you have at the time.
Cookies, and what else is stored on your device
This website sets four cookies. Three of them sign you in and keep you there: one for your session, one to renew it, and one recording whether your account needs a second factor. You could not use TOC without those, so we do not ask for consent to set them.
The fourth remembers a device that has already passed a second factor, so you are not asked for a code every time. That is a convenience rather than a necessity, and we are changing how it works so it is set only if you choose it. Until then it is set automatically after a successful verification, and you can clear it by signing out or clearing your browser storage.
The website also stores one preference in your browser, which is whether you chose the light or dark appearance. It is written only when you pick one, contains no identifier, and is never sent to us.
The mobile app keeps your sign-in tokens in the phone’s keychain, and holds your work on the device so that a walkaround can be completed and a defect reported with no signal. That is the app doing its job rather than anything to do with tracking.
A document may contain a film published by someone else, on YouTube or Vimeo. Opening a document that has one means your device asks that provider for it directly, and the provider learns your address and which film was asked for. We do not receive anything back from them and we cannot see who watched what. YouTube is used through its no-cookie address, which stops it setting cookies on you for opening the document, and Vimeo is asked not to track you. Neither changes the fact that the request reaches them. Films held by your own organisation are served from our own storage and involve nobody else.
Apart from that, there are no advertising cookies, no analytics and no third party tracking in the website or the app.
Children
TOC is a service for businesses and is not directed at children as consumers. An organisation may have people under 18 on its staff list, an apprentice or a young warehouse worker for instance, and TOC does not prevent that. Where it happens, the organisation remains responsible for having a lawful basis and appropriate safeguards for that person's information, as it is for everybody else on its list. TOC has no date of birth field and does not ask for one. It is worth being clear that this is not the same as holding no date of birth at all: a DVLA driver number has one encoded in it, and a photograph of a licence or a CPC card shows it on the card. So an organisation recording a licence is very likely holding a date of birth inside that record, and it should treat it accordingly.
How you are given this notice
It is published here, and linked from the foot of every page on this website, from the account screen in the TOC mobile app, and from the account menu once you are signed in. If an organisation has put your details into TOC, it is also that organisation’s job to tell you it is using a service like this and what it does with your information, and this notice is written so it can point you to it.
Changes
We will update this notice when the service changes in a way that affects it, and the date at the top will change with it. Where a change is significant we will tell the organisations using TOC rather than relying on them noticing.