24X7 (Fleet Services) Ltd Customer Privacy & GDPR Policy
Last updated: January 2026
Applies to: Customers booking journeys with 24X7 (Fleet Services) Ltd
1. Introduction
2. Who We Are
Company name: 24X7 (Fleet Services) Ltd
Role: Data Controller
Regulator: Information Commissioner’s Office (ICO)
ICO Registration: 24X7 (Fleet Services) Ltd is registered with the ICO and complies with UK data protection requirements. Registration Number ZA563825
Customers may contact us regarding data protection at:
Email: [email protected]
Phone number: 01279 661111
3. What Customer Data We Collect
We may collect the following personal data when you book or use our taxi services:
- Name
- Phone number.
- Email address.
- Pickup and drop-off addresses.
- Journey details (date, time, route).
- Payment information (processed securely via third parties and encrypted).
- Call recordings (for training, safety, and quality assurance).
- Any special assistance or accessibility requirements.
We do not collect more data than is necessary to deliver our service.
3. What Customer Data We Collect
We process personal data under the following lawful bases:
Contractual necessity – to provide booked journeys
Legitimate interests – to improve safety, service quality, and customer support
Legal obligations – regulatory, licensing, or tax requirements
Consent – where required (e.g., marketing communications)
5. How We Use Customer Data
We use customer data to:
- Process and manage bookings.
- Contact customers regarding journeys.
- Provide customer support.
- Ensure passenger and driver safety.
- Improve service performance.
- Handle complaints, refunds, and service issues.
- Meet legal and licensing obligations.
We never sell customer data to third parties.
6. Use of Trusted Partners & Call Handling Providers
24X7 (Fleet Services) Ltd may use trusted third-party partners to support booking calls, customer service, or technical systems.
All trusted partners:
- Are ISO 27001 certified (part of the ISO 27000 family).
- Follow strict information security and data protection controls.
- Operate under legally binding Data Processing Agreements (DPAs).
- Are audited to ensure compliance with GDPR and security best practices.
What ISO 27001 / ISO 27000 Standards Ensure
The ISO 27000 family of standards provides a framework for managing sensitive information securely, including:
- Strong access controls and identity management.
- Secure handling and encryption of personal data.
- Risk management and breach prevention procedures.
- Regular security audits and compliance reviews.
- Incident response and breach reporting processes.
- Business continuity and disaster recovery planning.
- Staff training on data protection and cyber security.
This ensures customer data is handled securely, confidentially, and responsibly.
7. Data Storage & International Transfers
- Customer data is stored within Europe only.
- No data is processed in countries without adequate data protection safeguards or where standards not met.
8. Call Recording & Monitoring
Telephone calls may be recorded for:
- Quality assurance
Training. - Safety and dispute resolution.
- Fraud prevention.
- Call recordings are:
- Securely stored.
- Access-restricted.
- Retained only as long as necessary.
- Deleted in line with retention policies.
9. Data Retention
We only retain customer data for as long as necessary to:
- Deliver services.
- Meet legal or licensing requirements.
- Resolve complaints or disputes.
- Once data is no longer needed, it is securely deleted or anonymised.
10. How We Protect Customer Data
24X7 (Fleet Services) Ltd uses strong technical and organisational safeguards, including:
- Encrypted systems and secure servers.
- Role-based access controls.
- Secure payment processing.
- Regular system security testing
- Staff confidentiality training.
- Breach detection and response procedures.
11. Customer Rights Under GDPR
Customers have the right to:
- Access their personal data.
- Request correction of inaccurate data.
- Request deletion (“Right to be Forgotten”).
- Restrict or object to processing.
- Request data portability.
- Withdraw consent where applicable.
- Lodge a complaint with the ICO.
Requests can be made by contacting us at: [email protected]
12. Marketing Communications
We only send marketing communications if:
- Customers have given consent, or
- There is a lawful basis under UK marketing rules.
Customers can opt out at any time.
13. Data Breach Procedure
If a data breach occurs:
- We investigate immediately.
- We notify the ICO where legally required.
- We notify affected customers if there is a risk to their rights or freedoms.
- We take corrective action to prevent recurrence.
14. Changes to This Policy
15. Contact Us
If you have questions about this policy or your personal data:
Email: [email protected]
Phone number: 01279 661111
Company: 24X7 (Fleet Services) Ltd