PRIVACY POLICY


VTS Expert Ltd - MOT Scheduler Platform


Effective Date: 02/10/2026

Last Updated: 02/10/2026




1. WHO WE ARE


VTS Expert Ltd (Company Number: [details pending]) is a data processor that provides scheduling and client management software for Vehicle Testing Stations. Our registered office is at [details pending].


Data Protection Officer: support@vtsexpert.co.uk




2. WHAT THIS POLICY COVERS


This Privacy Policy explains how we handle personal data when you use our MOT Scheduler platform. It covers:

  • Data we collect about you as our customer (VTS owners/staff)
  • How we process your clients' data on your behalf
  • Your rights and our obligations under GDPR



  • 3. DATA PROCESSING RELATIONSHIP


    3.1 You Are the Data Controller

    When you use our platform to manage your clients' information:

  • **YOU** determine what personal data to collect and why
  • **YOU** are responsible for GDPR compliance with your clients
  • **YOU** must obtain appropriate consents and provide privacy notices
  • **YOU** handle data subject requests from your clients

  • 3.2 We Are the Data Processor

  • **WE** process your clients' data only on your instructions
  • **WE** implement appropriate security measures
  • **WE** assist with data subject requests where technically feasible
  • **WE** notify you of any data breaches



  • 4. PLATFORM ADMINISTRATION & GDPR COMPLIANCE


    4.1 Customer Data Isolation

  • **VTS Expert platform staff CANNOT access your clients' personal information**
  • Individual customer data remains isolated within your VTS account
  • Cross-VTS data access is technically and legally prevented
  • Only you and your authorized staff can access your clients' data

  • 4.2 Platform Administration Data Processing

    What Our Platform Staff Can Access:

  • ✅ Aggregate statistics (total VTS count, subscription metrics)
  • ✅ Billing information for your VTS subscription
  • ✅ Technical support logs (when you contact us)
  • ✅ Usage analytics (anonymized and aggregated)

  • What Our Platform Staff CANNOT Access:

  • ❌ Your clients' names, addresses, phone numbers
  • ❌ Individual appointment details
  • ❌ Vehicle registration numbers
  • ❌ Any personal data about your customers

  • Legal Basis: Legitimate interest in providing platform services and customer support


    4.3 Admin Role Safeguards

  • **Role-Based Access:** Only authorized platform staff have admin access
  • **Audit Logging:** All admin actions are logged and monitored
  • **Data Minimization:** Admin interfaces show only aggregate data
  • **Purpose Limitation:** Admin access is strictly for platform management



  • 5. YOUR RIGHTS AS OUR CUSTOMER


    5.1 Data Subject Rights

    You have the right to:

  • Access your personal data we hold about you
  • Correct inaccurate information
  • Request deletion of your data
  • Object to processing
  • Data portability
  • Withdraw consent (where applicable)

  • 5.2 Your Clients' Rights

    Your clients must contact YOU directly for:

  • Access to their personal data
  • Corrections or deletions
  • Complaints about data processing
  • Consent withdrawal

  • We will assist you in responding to these requests where technically feasible.




    6. DATA SECURITY


    6.1 Technical Safeguards

  • End-to-end encryption for all data transmissions
  • Database encryption at rest
  • Regular security audits and penetration testing
  • Multi-factor authentication for admin access
  • Role-based access controls

  • 6.2 Organizational Safeguards

  • Regular staff training on data protection
  • Clear data handling procedures
  • Incident response procedures
  • Regular GDPR compliance reviews



  • 7. DATA RETENTION


    7.1 Platform Administration Data

  • Account information: Retained while your subscription is active + 7 years
  • Billing records: 7 years (UK tax requirements)
  • Support logs: 3 years
  • Usage analytics: 2 years (anonymized)

  • 7.2 Your Client Data

  • **You control retention periods** for your clients' data
  • We provide tools to help you comply with retention policies
  • Data can be exported or deleted at any time
  • Automated deletion capabilities available



  • 8. INTERNATIONAL TRANSFERS


    8.1 Data Location

  • Primary data storage: UK/EU data centers
  • Backup systems: UK/EU only
  • No routine transfers outside UK/EU

  • 8.2 Third-Party Services

    Where we use third-party services (cloud hosting, payment processing):

  • All providers are GDPR-compliant
  • Appropriate safeguards in place (Standard Contractual Clauses)
  • Regular compliance assessments



  • 9. CHANGES TO THIS POLICY


    We may update this Privacy Policy from time to time. We will:

  • Notify you of material changes
  • Provide 30 days' notice before changes take effect
  • Post the updated policy on our website
  • Send notifications to your registered email address



  • 10. CONTACT US


    For any privacy-related questions or concerns:


    Email: support@vtsexpert.co.uk

    Post: VTS Expert Ltd, [details pending]

    Phone: [details pending]


    Data Protection Officer: support@vtsexpert.co.uk




    11. SUPERVISORY AUTHORITY


    You have the right to lodge a complaint with the Information Commissioner's Office (ICO):


    Website: https://ico.org.uk/

    Phone: 0303 123 1113

    Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF




    This Privacy Policy was last updated on 02/10/2026




    *This policy is designed to comply with UK GDPR and Data Protection Act 2018. For specific legal advice, please consult with qualified legal professionals.*


    See also our Terms of Service.