Drivefix Driving School Privacy Policy
Last updated: August 2025
Drivefix Driving School is committed to protecting your privacy and complying with the UK GDPR and Data Protection Act 2018. We collect only the personal information needed to provide driving lessons and related services. This policy explains what data we collect, why and how we use it, how we keep it secure, how long we keep it, and your rights under UK law
Data We Collect
We only collect the basic personal details needed to schedule and manage your lessons. This includes:
Name (e.g. full name)
Contact details: email address and telephone number
Under UK GDPR, this is “personal data” – any information that identifies you. For example, the UK GDPR defines personal data as “any information relating to an identified or identifiable natural person… by reference to an identifier such as a name”
ico.org.uk
. We do not collect any sensitive information (such as health data, race or financial details) in connection with our lessons.
How We Use Your Data
We use your personal data only to provide and improve our driving instruction services, and to communicate with you. Specifically, we use your name and contact details to:
Schedule and manage your lessons: Book, confirm, change or cancel driving lesson appointments.
Send you updates and reminders: Contact you by email or phone about upcoming lessons, cancellations, rescheduling, or other important notices.
Provide customer support: Respond to your questions or requests about lessons and service.
Administrative purposes: Handle billing, receipts or statutory records if applicable (for example, keeping invoices for tax purposes).
Each of these uses is a clear, legitimate purpose. In line with ICO guidance, we explain every purpose of processing in this notice
. For example, the ICO advises organizations to be clear about each reason they use personal data
. We do not use your data for unrelated purposes (like marketing) unless you have specifically consented to that use.
Legal Basis for Processing
Under UK GDPR, we must have a lawful basis to process personal data. For our operations we rely on the following bases
Legitimate Interests: We process your contact data as necessary for our legitimate interests (running the driving school and fulfilling our contract to teach you). For example, we need to contact you to manage bookings and provide lessons. This is in line with Article 6(1)(f) of UK GDPR, which says processing is lawful if it is “necessary for the purposes of the legitimate interests” of the controller (unless your interests override those interests)
. We ensure that our interest in administering your lessons does not override your privacy.
Consent: Where applicable (for instance, if we ask for permission to send you newsletters or promotional messages), we will rely on your consent. Consent means you have “given clear consent… to process their personal data for a specific purpose”
. You may withdraw any consent at any time (see Your Rights below).
We do not rely on other legal bases (such as public task or vital interests) because they do not apply to our private driving school context.
How We Store and Protect Your Data
We take data security seriously. The UK GDPR requires us to process personal data “in a manner that ensures appropriate security of the personal data… using appropriate technical or organisational measures”
. In practice, this means:
Secure storage: Your information is stored on encrypted, password-protected systems or secure software (e.g. a booking database or email) and/or locked filing cabinets for any paper forms.
Access controls: Only authorized staff (e.g. our instructors and administrators) can access your data. We train our staff on confidentiality and data security.
Technical safeguards: We use up-to-date antivirus software, firewalls and secure Wi-Fi for our computers and networks. Electronic backups are kept regularly.
Organizational measures: We regularly review our data security policies and update them as needed. We do not share your personal data with any third parties except as required (e.g. with our driving instructors or legal authorities) and only on a need-to-know basis.
These measures are designed to prevent unauthorized access, loss or damage. In line with Article 5(1)(f) of UK GDPR (the security principle), we protect your data against “unauthorised or unlawful processing and against accidental loss, destruction or damage”
Data Retention
We will only keep your personal data for as long as necessary to fulfill the purposes above and to meet any legal obligations. The UK GDPR’s storage limitation principle says data should be kept “no longer than is necessary for the purposes for which [it] are processed”
How long we keep data: In general, we will retain your records (name and contact details, lesson bookings, invoices) for the duration of your lessons and for a reasonable period afterward. For example, we usually delete or anonymise customer records within 2 years after our last contact with you. However, to comply with legal requirements (such as tax or accounting rules), we may keep certain records (like invoices) for up to 6 years.
Criteria used: We base retention on how long the data is needed for our service or any legal duty. If there is no longer a reason to keep your personal data, we will securely delete or anonymise it.
We will always tell you how long we plan to keep your data (or the criteria for that period) as required by the ICO
. When the retention period is over, or when you ask us to erase your data (see Your Rights), we will delete it in a secure manner, in accordance with UK GDPR and the Data Protection Act.
Your Rights
Under UK GDPR, you have rights regarding your personal data. These include (but are not limited to):
Right of access: You can ask for a copy of your personal data that we hold.
Right to rectification: You can ask us to correct any inaccurate or incomplete data.
Right to erasure (right to be forgotten): You can ask us to delete your personal data when it is no longer needed or if we have no lawful reason to keep it.
Right to restrict processing: You can ask us to limit the way we use your data (for example, if you contest its accuracy).
Right to object: You can object to certain uses of your data (for example, if we rely on legitimate interests for processing you feel is unwarranted).
Right to data portability: You can request that we transfer your data to another organisation (where technically feasible and lawful).
Right to withdraw consent: If any processing is based on your consent (e.g. for marketing emails), you have the right to withdraw that consent at any time.
You can exercise any of these rights by contacting us (see below). The ICO notes these rights must be clearly communicated to individuals
. We will respond to your request without undue delay and within one month, or give you a lawful reason if we cannot.
You also have the right to lodge a complaint with the UK’s data protection regulator (the Information Commissioner’s Office, ICO) if you think we are not handling your data properly
. The ICO’s contact details are: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; 0303 123 1113; www.ico.org.uk.
Contact Information
If you have any questions about this policy or how we handle your personal data, or if you wish to exercise your rights above, please contact Drivefix Driving School:
Address: Drivefix Driving School, Tildesley Road, London SW15 3AU, United Kingdom
Email: info@drivefixdrivingschool.com
Phone:020 3393 3989
(You can also ask for our Data Protection Lead or write to the above address with “Data Protection” on the envelope.)
If you have concerns about how we process your data and we are unable to resolve them, you may contact the ICO as noted above.
Changes to this Policy
We may update this Privacy Policy from time to time (for example, if the law changes). Any changes will be posted on our website and, where appropriate, notified to you by email. The “Last updated” date at the top will reflect the most recent revision.
This Privacy Policy is provided in accordance with Articles 13 and 14 of the UK GDPR. It includes all required information such as our contact details, the purposes of processing, lawful bases (including legitimate interests), retention periods, and your rights
Sources: This policy follows guidance from the UK Information Commissioner’s Office (ICO) on transparency, lawful bases, data security and rights
. The ICO emphasizes clear explanations of data use and individual rights in privacy notices
, and it requires appropriate security measures for stored data
. This policy reflects those requirements and the spirit of UK GDPR.
