Legal
DREVORA Privacy Policy
v0.3 · Effective 3 Aug 2026
1. Who we are
DREVORA is a fleet, workforce and operations management platform operated by Aurimas Jokubaitis, trading as DREVORA, a sole trader based in England, United Kingdom.
This Policy explains how personal information is collected, used, stored and protected when people visit DREVORA websites, create or use accounts, use the web/PWA or Android applications, contact support or use DREVORA features.
2. Our data-protection roles
DREVORA may act in different roles depending on the purpose of processing.
2.1 When DREVORA acts as controller
DREVORA normally determines the purpose and essential means for:
- Customer account-owner and administrator records;
- subscription, billing and transaction records;
- website enquiries and communications sent directly to DREVORA;
- DREVORA support requests and responses;
- security, authentication, abuse-prevention and access logs used for DREVORA's own protection;
- DREVORA legal, accounting, insurance and business records.
For these activities, DREVORA is responsible for the controller obligations that apply.
2.2 When the Customer is controller and DREVORA is processor
A Customer organisation normally determines why Worker, employment, compliance, vehicle and operational information is processed. For that information, the Customer normally acts as controller and DREVORA acts as processor under the Customer's documented instructions and the DPA.
The Customer is normally responsible for:
- identifying a lawful basis and any special-category condition;
- providing privacy information to Workers;
- deciding which information is necessary;
- assigning and removing access;
- responding to Data Subject requests;
- selecting lawful retention periods; and
- deleting or anonymising information that is no longer required.
2.3 Worker account and authentication data
A Worker name, work email, telephone number, role, company membership and account identifier are normally processed as part of the Customer's workforce account and therefore on the Customer's behalf. DREVORA may separately act as controller for limited security, direct support, fraud-prevention and legal records generated from use of that account.
Passwords are handled by the authentication provider and are not stored by DREVORA in readable plain text.
3. Personal information we may process
The information depends on the modules enabled by the Customer.
3.1 Account and company information
This may include name, business name, email, telephone number, role, organisation membership, login identifiers, authentication activity, subscription status, billing contact details and communications.
3.2 Worker profile and compliance information
This may include:
- name, Worker code, work email and telephone number;
- address where entered;
- job role, employment type and start or end dates;
- assigned or default vehicle;
- profile image and emergency contact;
- Driving Licence categories and expiry;
- Driver CPC expiry;
- Tachograph Card number and expiry;
- D4 or medical expiry and optional medical document where lawfully enabled;
- Right to Work and other Customer-configured compliance records.
3.3 Timesheets
This may include work dates, start and finish times, breaks, basic and overtime hours, comments, confirmation, submission, approval, rejection, audit timestamps and related Worker or vehicle information.
3.4 Holiday Requests
This may include requested dates, duration, entitlement, balances, status, comments, approval, rejection and audit records.
3.5 Vehicle and Tyre Checks
This may include Worker, vehicle, checklist answers, OK/Defect/N/A selections, tyre readings, odometer, start and completion times, duration, defect notes, photographs, signatures, correction records and follow-up actions.
3.6 Driver Reports
This may include vehicle, load, cargo, damage, site or customer incident information, photographs, attachments, comments, status and Office actions.
3.7 Consumables
This may include Worker, vehicle, consumable type, quantity, unit, cost, supplier or site, odometer, receipt, notes and date or time.
3.8 Documents and submissions
This may include document title and type, Worker, vehicle or organisation relationship, reference number, issue and expiry dates, uploaded file, CMR, POD, delivery note, receipt, status, rejection reason and upload history.
3.9 Contacts
This may include contact name, organisation, category, phone, email, address, notes and related Worker or operational relationship.
3.10 Support and diagnostic information
A bug report or feedback submission may include category, title, description, steps to reproduce, screenshots, rating, response and status. DREVORA may attach limited diagnostic information such as:
- app version and platform;
- current route or screen;
- online or offline state;
- browser or Android WebView user agent;
- screen dimensions;
- locale and timezone;
- submission timestamp.
DREVORA does not intentionally collect passwords, complete authentication tokens, secret environment values or private session content in support metadata.
3.11 Technical and security information
This may include IP address, browser and device type, operating system, authentication time, session identifiers, security events, provider logs, error records and essential cookie or local-storage information.
4. Mobile, PWA, offline storage and device permissions
4.1 The Android application and supported web/PWA environments may store limited information locally so that authentication, preferences and supported workflows can function reliably.
4.2 Offline Vehicle Checks and related media may be stored temporarily on the device or in browser storage until synchronisation completes.
4.3 Device-side information can be removed by app deletion, browser clearing, operating-system cleanup, device loss or storage failure.
4.4 Camera, photo or file permissions are used only where the user chooses a feature requiring an image or attachment.
4.5 Biometric app lock is processed by the device operating system. DREVORA does not receive or store a fingerprint, face image or biometric template.
4.6 DREVORA does not collect precise location by default. If a future feature collects location, this Policy and the relevant user notice must be updated before use.
5. How information is collected
Information may be collected:
- from Customer account owners and administrators;
- from invited Office users, managers and Workers;
- when a form, checklist, Timesheet or report is completed;
- when a photograph, signature, receipt or document is uploaded;
- automatically through authentication, security and essential technical systems;
- from payment providers when billing is enabled;
- from email providers when transactional messages are enabled;
- from support enquiries and feedback.
DREVORA does not obtain Worker information directly from government databases unless a specific integration is introduced, contractually enabled and disclosed.
6. How we use information
Personal information may be used to:
- create, authenticate and manage accounts;
- separate Customer organisations and enforce roles;
- provide subscribed DREVORA modules;
- store and synchronise online and offline records;
- send account, security and transactional notifications;
- process subscriptions and payments;
- provide support and respond to feedback;
- investigate errors, abuse and security incidents;
- maintain audit, accounting and legal records;
- comply with law and defend legal claims;
- improve reliability, accessibility and security.
DREVORA does not sell personal information, use Worker Data for advertising or create advertising profiles from Worker Data.
7. Lawful bases when DREVORA acts as controller
Depending on the activity, DREVORA may rely on:
- Contract: to create and manage Customer accounts, subscriptions and requested support;
- Legal obligation: for tax, accounting, legal requests and regulatory duties;
- Legitimate interests: for security, fraud prevention, service reliability, support management, business records and legal claims, after considering individual rights;
- Consent: only where genuinely appropriate, such as optional marketing communications.
Consent is not normally relied upon for core Worker Data entered by an employer. Where DREVORA acts as processor, the Customer determines the lawful basis.
8. Medical and special-category information
Medical document uploads are optional and should remain disabled unless the Customer determines that processing is lawful and necessary.
A D4 or medical expiry date and an uploaded medical document may reveal health information. The Customer is responsible for the lawful basis, special-category condition, necessity, access, retention and deletion.
DREVORA does not require diagnoses, medication details, detailed conditions, full examination answers, unnecessary medical history or broad doctor's notes.
9. Payment information
When paid subscriptions are enabled, Stripe or another identified provider may process payments.
DREVORA may receive billing contact, payment status, transaction identifier, subscription identifier, invoice data and payment-failure status. DREVORA does not receive or store complete payment-card numbers.
Payment providers may act as independent controllers for parts of their payment and legal-compliance processing.
10. Transactional email
When enabled, DREVORA may use Resend or another provider to send invitations, authentication messages, account notices, holiday updates, subscription notices, security notices, support responses and website enquiry acknowledgements.
Transactional email is not behavioural advertising.
11. Service providers and Sub-processors
Providers used when the relevant feature is active may include:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, APIs and private file storage |
| Vercel | Web hosting, deployment, delivery and related technical logs |
| Resend | Transactional and support email delivery when enabled |
| Stripe | Subscription billing and payment processing when enabled |
| Cloudflare | DNS, proxy, CDN or security services when enabled |
These providers process only the information required for their service. DREVORA does not share information with advertisers or data brokers.
A current Sub-processor schedule should be maintained before live customer use.
12. International transfers
Some providers may process information outside the United Kingdom.
Where a restricted transfer occurs, DREVORA will rely on an appropriate mechanism, which may include a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, binding corporate rules or another lawful safeguard.
DREVORA does not claim that all processing occurs exclusively in the United Kingdom or EEA.
13. Security
DREVORA uses reasonable technical and organisational measures intended to protect personal information, which may include:
- HTTPS/TLS communications;
- authentication, session and role controls;
- organisation-level isolation and Row Level Security where implemented;
- private storage and temporary signed access links;
- secure Android session storage using platform security where implemented;
- access restrictions, deployment controls and dependency monitoring;
- provider backups, incident response and security logging where available.
No internet-based service can guarantee absolute security or uninterrupted availability.
Customers are responsible for credentials, devices, role assignment, former-user removal, exports and independent copies of important records.
14. Data retention
DREVORA retains personal information only for as long as reasonably necessary for the relevant purpose, Customer instruction, legal duty, security need or legal claim.
The standard framework is:
| Record category | Standard framework |
|---|---|
| Timesheets and approvals | Up to 6 years from the relevant work week or pay-reference period |
| Holiday Requests, entitlement and holiday-pay records | Up to 6 years from the record date or relevant leave year |
| Account, contract, billing, invoice and financial records | Up to 6 years from the relevant financial period or end of relationship |
| Consumables evidence, invoices and receipts | Up to 6 years where used as financial evidence |
| CMR, POD, delivery notes and commercial or tax evidence | Up to 6 years from the relevant transaction or financial period |
| Vehicle Checks, Tyre Checks, defects, repair evidence, photos and signatures | Normally 24 months from completion or closure |
| Drivers' hours and tachograph operational records stored in DREVORA | Normally 24 months, unless another lawful purpose requires longer |
| Driving Licence, Driver CPC and Tachograph Card records | Active engagement plus up to 24 months after archive or engagement end |
| Right to Work evidence | Employment period plus normally 2 years after employment ends |
| Minimum archived Worker or Vehicle profile preserving historical links | Up to 6 years after archive |
| DREVORA support requests and responses | Normally up to 24 months after closure, longer for security or legal claims |
| DREVORA security, audit and technical logs | Shortest necessary period; normally up to 12 months where DREVORA controls the setting |
Medical documents and other special-category data must use the shortest lawful and necessary period selected by the Customer.
Expiry makes data eligible for deletion or anonymisation but does not guarantee immediate automated deletion. Until automated deletion exists for a category, DREVORA or the Customer may use a review, export, legal-hold or controlled deletion process.
Deleted information may remain temporarily in protected backups until the provider's backup cycle expires. Backup durations depend on provider configuration.
15. Customer export and deletion
Where export functionality exists, Customers may export records in the available formats and should maintain independent copies.
Before closing an account, the Customer should export records it wishes to retain.
Individual account deletion may be requested inside DREVORA by an authorised Admin or Worker. When a deletion request is submitted, access for that user account is disabled immediately. Final deletion or anonymisation of personal account data is completed within 30 days, unless the request is cancelled before the scheduled date by an organisation Admin or DREVORA support at admin@drevora.uk.
Operational, compliance and legal records may remain for applicable retention periods. Worker workforce records remain controlled by the Customer organisation. For Customer-controlled personal data processed on the Customer's behalf, DREVORA acts as Processor and the Customer organisation as Controller, as set out in the DPA.
A sole Admin must appoint another Admin before deleting their own Admin account. Company closure is a separate process from individual account deletion.
After company account closure, access may continue for a limited paid or final-export period. Data may then be returned, deleted or anonymised under the DPA, retention framework and legal requirements.
DREVORA may retain limited controller records for billing, security, fraud prevention, legal claims, evidence of instructions and statutory duties.
16. Individual rights
Depending on the circumstances, individuals may have rights to request access, correction, deletion, restriction, objection, portability, consent withdrawal and review of certain automated decisions.
16.1 Customer-controlled Worker Data
Workers should normally contact their employer or organisation first for information entered or controlled by that organisation. The Customer normally acts as controller and decides the response. DREVORA will provide reasonable processor assistance where required.
16.2 DREVORA-controlled information
For DREVORA account, billing, direct support or security information, individuals may contact admin@drevora.uk.
Rights may be limited where processing or retention is required by law, legal claims, security, fraud prevention or another lawful exception.
17. Complaints and responsibility allocation
A Worker may complain to the Customer about Customer-controlled processing and may contact DREVORA about DREVORA-controlled processing.
The Customer is responsible to the extent a complaint arises from its lawful-basis decision, privacy information, collection, access, retention, instructions or actions of its Authorised Users.
DREVORA remains responsible to the extent a complaint arises from DREVORA's direct legal obligations, processing outside lawful instructions, unauthorised use, negligence or security failure.
Contractual responsibility allocation does not restrict rights against a controller or processor under Applicable Data Protection Law.
Questions should first be sent to admin@drevora.uk. Individuals also have the right to complain to the Information Commissioner's Office.
18. Cookies and local storage
DREVORA uses essential cookies, secure storage, session storage, IndexedDB or local storage where necessary for authentication, security, preferences, offline queues and essential application functionality.
DREVORA does not use advertising cookies or behavioural advertising trackers unless this Policy and any required consent mechanism are updated first.
19. Children
DREVORA is a business platform and is not directed at children.
Customer organisations must not create Worker accounts for individuals who are not legally permitted to perform the relevant role.
20. Automated decisions
DREVORA does not make solely automated employment, dismissal, payroll, medical, disciplinary, roadworthiness or regulatory decisions producing legal or similarly significant effects.
Dashboard indicators, calculations, reminders and warnings are management tools. The Customer remains responsible for review and decisions.
21. Personal-data incidents
DREVORA investigates suspected incidents and takes reasonable steps to contain, assess and remediate them.
Where DREVORA acts as processor, it will notify the affected Customer without undue delay after becoming aware of a relevant breach and provide information as it becomes available.
Where DREVORA acts as controller, it will notify the appropriate authority and affected individuals where legally required.
22. Changes to this Policy
DREVORA may update this Policy for changes in law, providers, security, product functionality or processing.
Material changes may be notified by email, in-app notice or another reasonable method before taking effect where practicable.
The version and effective date will be displayed with the Policy.
23. Contact details
DREVORA
Operated by Aurimas Jokubaitis, trading as DREVORA
Business structure: Sole trader
Business address: 11 Buckenham Way, Thetford, Norfolk, IP24 1ES, United Kingdom
Email: admin@drevora.uk
Website: drevora.app
Effective date: 3 August 2026