SECTION 1 — GDPR & DATA PROTECTION POLICY
1. Purpose of This Policy
This policy explains how RK Motors MOT Centre Ltd (“we”, “us”, “the Company”) collects, uses, stores, shares, and protects personal data belonging to customers, employees, suppliers, and other individuals. It ensures compliance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- ICO (Information Commissioner’s Office) guidance
We are committed to handling all personal data lawfully, fairly, securely, and transparently.
________________________________________
2. Scope
This policy applies to:
- All employees, contractors, apprentices, and temporary staff
- All personal data processed by the Company
- All systems, digital tools, paper records, and communication channels used for business operations
It covers data relating to:
- Customers
- Employees
- Job applicants
- Suppliers and business partners
- Website visitors
________________________________________
3. Personal Data We Collect
We only collect data necessary for MOT testing, servicing, repairs, customer communication, and legal compliance.
3.1 Customer Data
- Name
- Address
- Phone number
- Email address
- Vehicle registration, VIN, MOT history
- Payment information (processed securely via third-party providers)
- CCTV footage (for safety and security)
3.2 Employee & Applicant Data
- Contact details
- Identification documents
- Payroll and bank details
- Right to work information
- Training and qualification records
- CCTV footage
3.3 Website Data
• Contact form submissions
• IP address and browser information
• Cookies (where applicable)
________________________________________
4. Lawful Basis for Processing
- Purpose Lawful Basis
- Booking MOTs, repairs, servicing Contract
- Customer communication Legitimate interest
- Legal MOT record keeping Legal obligation
- Invoicing & payments Contract / Legal obligation
- CCTV for safety & crime prevention Legitimate interest
- Employee payroll & HR Legal obligation / Contract
- Marketing (opt-in only) Consent
________________________________________
5. How We Use Personal Data
We use personal data to:
- Book and manage MOT and repair appointments
- Contact customers about their vehicle
- Provide invoices, quotes, and service updates
- Maintain MOT and service history
- Improve customer service and operations
- Ensure workplace and customer safety
- Meet legal and insurance requirements
We do not sell personal data to third parties.
________________________________________
6. Sharing Personal Data
We may share data with:
- DVSA (for MOT testing compliance)
- Payment processors (e.g., card machine providers)
- Insurance companies (where required)
- IT service providers (secure hosting, email systems)
- Accountants and payroll services
- Law enforcement (if legally required)
All third parties must comply with UK GDPR and sign appropriate data processing agreements.
________________________________________
7. International Data Transfers
We do not routinely transfer personal data outside the UK. If a service provider stores data abroad, we ensure:
- Adequacy decisions, or
- ICO-approved safeguards (e.g., Standard Contractual Clauses)
________________________________________
8. Data Security Measures
We use appropriate technical and organisational measures, including:
- Secure password-protected systems
- Encrypted devices where applicable
- CCTV with restricted access
- Locked filing cabinets for paper records
- Regular data backups
- Staff training on data protection
- Access controls based on job role
- Secure disposal of documents and hardware
________________________________________
9. Data Retention
- We keep data only as long as necessary.
- Data Type Retention Period
- MOT records Minimum 2 years (DVSA requirement)
- Customer invoices & financial records 6 years (HMRC requirement)
- CCTV footage 14–30 days unless required for investigation
- Employee records 6 years after employment ends
- Job applications 6 months
________________________________________
10. Data Subject Rights
Individuals have the right to:
- Access their data
- Correct inaccurate data
- Request deletion
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent (for marketing)
- Lodge a complaint with the ICO
Requests can be made via email or in writing.
________________________________________
11. Submitting a Data Request
- Email: (Insert official email)
- Phone: (Insert number)
- Address: (Insert address)
We respond within one month, as required by law.
________________________________________
12. Marketing Communications
We only send marketing messages if:
- You have given explicit consent, or
- You are an existing customer, and the message relates to similar services
You can opt out at any time.
________________________________________
13. CCTV Policy Summary
CCTV is used for:
- Crime prevention
- Staff and customer safety
- Protecting property
Footage is stored securely with restricted access and retained for a limited period.
________________________________________
14. Employee Responsibilities
All staff must:
• Follow this policy
• Keep data secure
• Report data breaches immediately
• Only access data necessary for their role
Failure to comply may result in disciplinary action.
________________________________________
15. Data Breach Procedure
If a breach occurs:
- It is reported immediately to the Data Protection Lead
- We assess the risk and impact
- We notify the ICO within 72 hours if required
- We inform affected individuals where necessary
- We document all breaches and corrective actions
________________________________________
16. Policy Review
This policy is reviewed annually or sooner if:
- Laws change
- Business processes change
- New systems or technologies are introduced
________________________________________
SECTION 2 — WEBSITE PRIVACY NOTICE
1. Introduction
This Website Privacy Notice explains how RK Motors MOT Centre Ltd collects, uses, and protects personal data when you visit our website: https://rkmotcentre.co.uk.
We are committed to protecting your privacy and ensuring transparency in how your information is handled.
________________________________________
2. Information We Collect Through the Website
2.1 Information You Provide Directly
- Contact form submissions (name, email, phone number, message)
- Booking requests
- Email enquiries
2.2 Information Collected Automatically
- IP address
- Browser type and version
- Device information
- Pages visited
- Time spent on the website
- Cookies and tracking technologies
________________________________________
3. Cookies
Our website may use cookies to:
- Enable essential website functions
- Improve performance and user experience
- Analyse website traffic
- Support security features
You can disable cookies in your browser settings at any time.
________________________________________
4. How We Use Website Data
We use website-collected data to:
- Respond to enquiries
- Improve website performance
- Monitor security and prevent misuse
- Analyse visitor behaviour (e.g., Google Analytics)
We do not use website data for automated decision-making or profiling.
________________________________________
5. Sharing Website Data
We may share website-related data with:
- IT hosting providers
- Website maintenance providers
- Analytics services (e.g., Google Analytics)
All third parties must comply with UK GDPR.
________________________________________
6. External Links
Our website may contain links to external sites. We are not responsible for the privacy practices of those websites.
________________________________________
7. Your Rights as a Website User
You have the right to:
- Request access to your data
- Request correction or deletion
- Object to processing
- Withdraw consent (where applicable)
________________________________________
8. Contact Information
For any privacy-related queries:
Email: [email protected]
Address: RK MOT CENTRE LTD Priestley Way, Crawley RH10 9NT