Drevora Fleet & Team Management
Features Benefits Pricing Request Demo
Log In Request Demo
Features Benefits Pricing Customer Terms Privacy Policy Cookie Policy
Log In Request Demo

Legal

DREVORA Privacy Policy

v0.5 · Effective 13 September 2026

Version: v0.5
Effective date: 13 September 2026
Operator: Aurimas Jokubaitis, trading as DREVORA, sole trader
Business address: 11 Buckenham Way, Thetford, Norfolk, IP24 1ES, United Kingdom
Email: admin@drevora.uk
Website: drevora.app

1. Who we are

DREVORA is a fleet, workforce and operations management platform operated by Aurimas Jokubaitis, trading as DREVORA, a sole trader based in England, United Kingdom.

This Policy explains how personal information is collected, used, stored and protected when people visit DREVORA websites, create or use accounts, use the web application, progressive web application (PWA) or Android application, contact support or use DREVORA features.

2. Our data-protection roles

DREVORA may act in different roles depending on the purpose of processing.

2.1 When DREVORA acts as controller

DREVORA normally determines the purpose and essential means for:

  • Customer account-owner and administrator records;
  • subscription, billing and transaction records;
  • website enquiries and communications sent directly to DREVORA;
  • DREVORA support requests and responses;
  • security, authentication, abuse-prevention and access logs used for DREVORA's own protection;
  • DREVORA legal, accounting, insurance and business records.

For these activities, DREVORA is responsible for the controller obligations that apply.

2.2 When the Customer is controller and DREVORA is processor

A Customer organisation normally determines why Worker, employment, compliance, vehicle and operational information is processed. For that information, the Customer normally acts as controller and DREVORA acts as processor under the Customer's documented instructions and the DPA.

The Customer is normally responsible for:

  • identifying a lawful basis and any special-category condition;
  • providing privacy information to Workers;
  • deciding which information is necessary;
  • assigning and removing access;
  • responding to Data Subject requests;
  • selecting lawful retention periods; and
  • deleting or anonymising information that is no longer required.

2.3 Worker account and authentication data

A Worker name, work email, telephone number, role, company membership and account identifier are normally processed as part of the Customer's workforce account and therefore on the Customer's behalf. DREVORA may separately act as controller for limited security, direct support, fraud-prevention and legal records generated from use of that account.

Passwords are handled by the authentication provider and are not stored by DREVORA in readable plain text.

3. Personal information we may process

The information depends on the modules enabled by the Customer.

3.1 Account and company information

This may include name, business name, email, telephone number, role, organisation membership, login identifiers, authentication activity, subscription status, billing contact details and communications.

3.2 Worker profile and compliance information

This may include:

  • name, Worker code, work email and telephone number;
  • address where entered;
  • job role, employment type and start or end dates;
  • assigned or default vehicle;
  • profile image and emergency contact;
  • Driving Licence categories and expiry;
  • Driver CPC expiry;
  • Tachograph Card number and expiry;
  • D4 or medical expiry and optional medical document where lawfully enabled;
  • Right to Work and other Customer-configured compliance records.

3.3 Timesheets

This may include work dates, start and finish times, breaks, basic and overtime hours, comments, confirmation, submission, approval, rejection, audit timestamps and related Worker or vehicle information.

3.4 Holiday Requests

This may include requested dates, duration, entitlement, balances, status, comments, approval, rejection and audit records.

3.5 Vehicle and Tyre Checks

This may include Worker, vehicle, checklist answers, OK/Defect/N/A selections, tyre readings, odometer, start and completion times, duration, defect notes, photographs, signatures, correction records and follow-up actions.

When device permission is granted, Vehicle Check records may also include start location, completion location, latitude, longitude, device-reported accuracy and the location capture timestamp. This is a one-time capture at start and at completion, not continuous tracking.

3.6 Driver Reports

This may include vehicle, load, cargo, damage, site or customer incident information, photographs, attachments, comments, status and Office actions.

3.7 Consumables

This may include Worker, vehicle, consumable type, quantity, unit, cost, supplier or site, odometer, receipt, notes and date or time.

3.8 Documents and submissions

This may include document title and type, Worker, vehicle or organisation relationship, reference number, issue and expiry dates, uploaded file, CMR, POD, delivery note, receipt, status, rejection reason and upload history.

3.9 Contacts

This may include contact name, organisation, category, phone, email, address, notes and related Worker or operational relationship.

3.10 Support and diagnostic information

A bug report or feedback submission may include category, title, description, steps to reproduce, screenshots, rating, response and status. DREVORA may attach limited diagnostic information such as:

  • app version and platform;
  • current route or screen;
  • online or offline state;
  • browser or Android WebView user agent;
  • screen dimensions;
  • locale and timezone;
  • submission timestamp.

DREVORA does not intentionally collect passwords, complete authentication tokens, secret environment values or private session content in support metadata.

3.11 Technical and security information

This may include IP address, browser and device type, operating system, authentication time, session identifiers, security events, provider logs, error records and essential cookie or local-storage information.

Where error monitoring is configured for a deployment, limited diagnostic event data may also be sent to the error-monitoring provider (see section 11).

4. Mobile, PWA, offline storage and device permissions

4.1 The Android application and supported web and PWA environments may store limited information locally so that authentication, preferences and supported workflows can function reliably.

4.2 Offline Vehicle Checks and related media may be stored temporarily on the device or in browser storage until synchronisation completes.

4.3 Device-side information can be removed by app deletion, browser clearing, operating-system cleanup, device loss or storage failure.

4.4 Camera, photo or file permissions are used only where the user chooses a feature requiring an image or attachment.

4.5 Biometric app lock is processed by the device operating system. DREVORA does not receive or store a fingerprint, face image or biometric template.

4.6 Vehicle Check location is requested only when relevant to the Vehicle Check workflow and only when device permission is granted. The application attempts a one-time location capture when a Vehicle Check starts and another one-time capture immediately before completion.

4.7 This is not continuous, background or live location tracking. Location is supporting evidence attached to the Vehicle Check record.

4.8 Denying location permission, or a failed or timed-out location lookup, does not prevent the Worker from completing the Vehicle Check. In that case the check may be saved without location coordinates.

5. How information is collected

Information may be collected:

  • from Customer account owners and administrators;
  • from invited Office users, managers and Workers;
  • when a form, checklist, Timesheet or report is completed;
  • when a photograph, signature, receipt or document is uploaded;
  • when device location is captured for a Vehicle Check under section 4;
  • automatically through authentication, security and essential technical systems;
  • from Stripe for subscription billing and payment processing;
  • from email providers when transactional messages are sent;
  • from support enquiries and feedback;
  • from the marketing website demo or contact forms, including bot-protection checks where used.

DREVORA does not obtain Worker information directly from government databases unless a specific integration is introduced, contractually enabled and disclosed.

6. How we use information

Personal information may be used to:

  • create, authenticate and manage accounts;
  • separate Customer organisations and enforce roles;
  • provide subscribed DREVORA modules;
  • store and synchronise online and offline records;
  • send account, security and transactional notifications;
  • process subscriptions and payments;
  • provide support and respond to feedback;
  • investigate errors, abuse and security incidents;
  • maintain audit, accounting and legal records;
  • comply with law and defend legal claims;
  • improve reliability, accessibility and security;
  • display approximate weather information for a company location where that feature is used.

DREVORA does not sell personal information, use Worker Data for advertising or create advertising profiles from Worker Data.

7. Lawful bases when DREVORA acts as controller

Depending on the activity, DREVORA may rely on:

  • Contract: to create and manage Customer accounts, subscriptions and requested support;
  • Legal obligation: for tax, accounting, legal requests and regulatory duties;
  • Legitimate interests: for security, fraud prevention, service reliability, support management, business records and legal claims, after considering individual rights;
  • Consent: only where genuinely appropriate, such as optional marketing communications.

Consent is not normally relied upon for core Worker Data entered by an employer. Where DREVORA acts as processor, the Customer determines the lawful basis.

8. Medical and special-category information

Medical document uploads are optional and should remain disabled unless the Customer determines that processing is lawful and necessary.

A D4 or medical expiry date and an uploaded medical document may reveal health information. The Customer is responsible for the lawful basis, special-category condition, necessity, access, retention and deletion.

DREVORA does not require diagnoses, medication details, detailed conditions, full examination answers, unnecessary medical history or broad doctor's notes.

9. Payment information

Stripe is used for subscription billing and payment processing.

Stripe may process billing contact details, payment status, transaction identifiers, subscription identifiers, invoice information and payment-failure status.

DREVORA does not receive or store complete payment-card numbers.

Stripe may act as an independent controller for some of its payment and legal-compliance processing.

10. Transactional email

DREVORA may use Resend or another provider to send invitations, authentication messages, account notices, holiday updates, subscription notices, security notices, support responses and website enquiry acknowledgements where those email features are configured.

Transactional email is not behavioural advertising.

11. Service providers and Sub-processors

Providers used for the Service or marketing website may include:

ProviderPurposeStatus
SupabaseDatabase, authentication, APIs and private file storageCore
VercelWeb hosting, deployment, delivery and related technical logsCore
ResendTransactional and support email deliveryActive where email is configured
CloudflareBot protection (Turnstile) on the marketing demo/contact form; DNS, proxy, CDN or other security services where usedTurnstile active on marketing forms; other Cloudflare services as configured
SentryApplication error monitoring and limited diagnostic event dataActive where error monitoring is configured for the deployment
StripeSubscription billing and payment processingActive
Google FontsIcon/font delivery for the marketing websiteUsed on the marketing website
Open-MeteoWeather geocoding and forecast for company-location weather displayUsed where the weather feature is shown

These providers process only the information required for their service. DREVORA does not share information with advertisers or data brokers.

Some providers (for example payment providers, font CDNs or public weather APIs) may process limited technical or request data as independent controllers under their own terms. The DPA Schedule 3 lists Sub-processors engaged for Customer-controlled Personal Data.

Processing may occur in the United Kingdom and/or other countries depending on each provider's live configuration for the Service. DREVORA does not claim that all processing occurs exclusively in the United Kingdom. Where a restricted transfer occurs, an appropriate safeguard is used as described in section 12.

12. International transfers

Some providers may process information outside the United Kingdom.

Where a restricted transfer occurs, DREVORA will rely on an appropriate mechanism, which may include a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, binding corporate rules or another lawful safeguard.

DREVORA does not claim that all processing occurs exclusively in the United Kingdom or EEA.

13. Security

DREVORA uses reasonable technical and organisational measures intended to protect personal information, which may include:

  • HTTPS/TLS communications;
  • authentication, session and role controls;
  • organisation-level isolation and Row Level Security where implemented;
  • private storage and temporary signed access links;
  • secure Android session storage using platform security where implemented;
  • access restrictions, deployment controls and dependency monitoring;
  • provider backups, incident response and security logging where available;
  • optional error monitoring with sanitisation controls where configured.

No internet-based service can guarantee absolute security or uninterrupted availability.

Customers are responsible for credentials, devices, role assignment, former-user removal, exports and independent copies of important records.

14. Data retention

DREVORA retains personal information only for as long as reasonably necessary for the relevant purpose, Customer instruction, legal duty, security need or legal claim.

The standard framework is:

Record categoryStandard framework
Timesheets and approvalsUp to 6 years from the relevant work week or pay-reference period
Holiday Requests, entitlement and holiday-pay recordsUp to 6 years from the record date or relevant leave year
Account, contract, billing, invoice and financial recordsUp to 6 years from the relevant financial period or end of relationship
Consumables evidence, invoices and receiptsUp to 6 years where used as financial evidence
CMR, POD, delivery notes and commercial or tax evidenceUp to 6 years from the relevant transaction or financial period
Vehicle Checks, Tyre Checks, defects, repair evidence, photos, signatures and related location evidenceNormally 24 months from completion or closure
Drivers' hours and tachograph operational records stored in DREVORANormally 24 months, unless another lawful purpose requires longer
Driving Licence, Driver CPC and Tachograph Card recordsActive engagement plus up to 24 months after archive or engagement end
Right to Work evidenceEmployment period plus normally 2 years after employment ends
Minimum archived Worker or Vehicle profile preserving historical linksUp to 6 years after archive
DREVORA support requests and responsesNormally up to 24 months after closure, longer for security or legal claims
DREVORA security, audit and technical logsShortest necessary period; normally up to 12 months where DREVORA controls the setting

Medical documents and other special-category data must use the shortest lawful and necessary period selected by the Customer.

Expiry makes data eligible for deletion or anonymisation but does not guarantee immediate automated deletion. Until automated deletion exists for a category, DREVORA or the Customer may use a review, export, legal-hold or controlled deletion process.

Deleted information may remain temporarily in protected backups until the provider's backup cycle expires. Backup durations depend on provider configuration.

15. Customer export and deletion

Where export functionality exists, Customers may export records in the available formats and should maintain independent copies.

Before closing an account, the Customer should export records it wishes to retain.

Individual account deletion may be requested inside DREVORA by an authorised Admin or Worker. When a deletion request is submitted, access for that user account is disabled immediately. Final deletion or anonymisation of personal account data is completed within 30 days, unless the request is cancelled before the scheduled date by an organisation Admin or DREVORA support at admin@drevora.uk.

Operational, compliance and legal records may remain for applicable retention periods. Worker workforce records remain controlled by the Customer organisation. For Customer-controlled personal data processed on the Customer's behalf, DREVORA acts as Processor and the Customer organisation as Controller, as set out in the DPA.

A sole Admin must appoint another Admin before deleting their own Admin account. Company closure is a separate process from individual account deletion.

After company account closure, DREVORA may provide a reasonable final export opportunity where technically and operationally available, with the applicable period communicated as part of the closure process. Data may then be returned, deleted or anonymised under the DPA, retention framework and legal requirements.

DREVORA may retain limited controller records for billing, security, fraud prevention, legal claims, evidence of instructions and statutory duties.

16. Individual rights

Depending on the circumstances, individuals may have rights to request access, correction, deletion, restriction, objection, portability, consent withdrawal and review of certain automated decisions.

16.1 Customer-controlled Worker Data

Workers should normally contact their employer or organisation first for information entered or controlled by that organisation. The Customer normally acts as controller and decides the response. DREVORA will provide reasonable processor assistance where required.

16.2 DREVORA-controlled information

For DREVORA account, billing, direct support or security information, individuals may contact admin@drevora.uk.

Rights may be limited where processing or retention is required by law, legal claims, security, fraud prevention or another lawful exception.

17. Complaints and responsibility allocation

A Worker may complain to the Customer about Customer-controlled processing and may contact DREVORA about DREVORA-controlled processing.

The Customer is responsible to the extent a complaint arises from its lawful-basis decision, privacy information, collection, access, retention, instructions or actions of its Authorised Users.

DREVORA remains responsible to the extent a complaint arises from DREVORA's direct legal obligations, processing outside lawful instructions, unauthorised use, negligence or security failure.

Contractual responsibility allocation does not restrict rights against a controller or processor under Applicable Data Protection Law.

Questions should first be sent to admin@drevora.uk. Individuals also have the right to complain to the Information Commissioner's Office.

18. Cookies and local storage

DREVORA uses essential cookies, secure storage, session storage, IndexedDB or local storage where necessary for authentication, security, preferences, offline queues and essential application functionality.

The marketing website may use Cloudflare Turnstile for bot protection on demo or contact forms. That check may involve limited technical data processed by Cloudflare.

DREVORA does not use advertising cookies or behavioural advertising trackers unless this Policy and any required consent mechanism are updated first.

19. Children

DREVORA is a business platform and is not directed at children.

Customer organisations must not create Worker accounts for individuals who are not legally permitted to perform the relevant role.

20. Automated decisions

DREVORA does not make solely automated employment, dismissal, payroll, medical, disciplinary, roadworthiness or regulatory decisions producing legal or similarly significant effects.

Dashboard indicators, calculations, reminders and warnings are management tools. The Customer remains responsible for review and decisions.

21. Personal-data incidents

DREVORA investigates suspected incidents and takes reasonable steps to contain, assess and remediate them.

Where DREVORA acts as processor, it will notify the affected Customer without undue delay after becoming aware of a relevant breach and provide information as it becomes available.

Where DREVORA acts as controller, it will notify the appropriate authority and affected individuals where legally required.

22. Changes to this Policy

DREVORA may update this Policy for changes in law, providers, security, product functionality or processing.

Material changes may be notified by email, in-app notice or another reasonable method before taking effect where practicable.

The version and effective date will be displayed with the Policy.

23. Contact details

DREVORA Operated by Aurimas Jokubaitis, trading as DREVORA Business structure: Sole trader Business address: 11 Buckenham Way, Thetford, Norfolk, IP24 1ES, United Kingdom Email: admin@drevora.uk Website: drevora.app Effective date: 13 September 2026

← Customer Terms Cookie Policy →
DREVORA

Fleet operations platform for modern transport businesses.

mail admin@drevora.uk

Get the DREVORA Worker app

Get DREVORA Worker on Google Play Download DREVORA Worker on the App Store

Product

Features Benefits Pricing About Us

Legal

Privacy Policy Customer Terms Cookie Policy

Follow us

Data protection registration badge

© 2026 DREVORA. All rights reserved.