Privacy, Security & Cookie Policy
How your company details, transport records, and portal credentials are encrypted, safeguarded, and retained in accordance with UK statutory compliance standards.
Executive Summary • Security at a Glance
Road Legal Compliance & Safety operates under strict technical and organizational measures designed to protect commercial transport operators. We hold only the information necessary to deliver statutory dangerous goods advice and fleet compliance auditing.
1. Data Controller Identification
The Data Controller responsible for personal data processed through this website and the Road Legal Client Portal is:
Specialist Road Transport Compliance & Dangerous Goods Safety Advisory (DGSA)
Operating Territory: London, South East & East of England
Telephone: 07500 958800
Email: info@roadlegal.co.uk • martyn.mcintee@roadlegal.co.uk
2. Information We Collect & Process
In delivering commercial road transport compliance and DGSA statutory services, we collect:
- Commercial Operator Details: Company trading name, registered company number, Operatorβs Licence number (O-licence), operating centre postcode, and depot addresses.
- Contact Credentials: Transport Manager or director full name, professional email address, and direct telephone contact numbers.
- Portal Authentication: Registered email address, cryptographic password hash (generated via adaptive one-way Bcrypt algorithm), session identifier, and last login timestamps.
- Vehicle & Fleet Evidence: Vehicle registration numbers (VRNs), trailer identifiers, fleet size profiles, dangerous goods classifications (UN numbers/classes handled), physical walkaround audit checklists, defect notes, and photographic evidence captured during yard visits or audits.
- Transaction Records: Stripe checkout session identifiers, retainer appointment certificate numbers, billing dates, and invoices settled into Road Legal's designated Monzo Business UK bank account. Note: Credit/debit card numbers are tokenized by Stripe and never stored on our servers.
3. Legal Basis for Processing (UK GDPR Article 6)
We process commercial client data under the following statutory grounds:
- Legal Obligation (Article 6(1)(c)): To fulfill mandatory statutory duties under the Carriage of Dangerous Goods and Use of Transportable Pressure Equipment Regulations 2009 (CDG 2009) and European Agreement concerning the International Carriage of Dangerous Goods by Road (ADR 1.8.3).
- Contractual Performance (Article 6(1)(b)): To provide retainer services, depot gate check sessions, driver briefings, and compliance audit reports agreed under our terms of business.
- Legitimate Interests (Article 6(1)(f)): To maintain audit trails protecting Operator Licence undertakings against DVSA enforcement, roadside prohibitions, and Traffic Commissioner regulatory scrutiny.
4. Security & Technical Safeguards
The Road Legal architecture implements multi-layer technical controls:
- Transport Layer Security: 256-bit TLS/SSL encryption across all connections, with HSTS (HTTP Strict Transport Security) enabled.
- SQL Injection Defense: 100% parameterized PDO prepared statements across all database queries. Zero raw string interpolation.
- Credential Protection: Passwords hashed with Bcrypt (PHP
PASSWORD_DEFAULT) incorporating cryptographic salts. Plaintext passwords are never logged or stored. - Brute-Force Rate Limiting: Automated lockout mechanism triggers after 5 failed authentication attempts for 15 minutes.
- CSRF Token Validation: Cryptographic 64-character tokens validate every form submission.
- Protected Storage: Compliance certificates and photographic evidence are placed in protected server directories outside public HTTP access, streamed exclusively to authorized sessions through authenticated endpoints (
/api/download.phpand/api/audit-photo.php).
5. Cookie Policy (UK PECR Compliance)
Under the Privacy and Electronic Communications Regulations (PECR), we provide full transparency regarding all cookies used:
| Cookie Name | Type • Provider | Purpose | Duration |
|---|---|---|---|
| PHPSESSID | Strictly Necessary (1st party) | Maintains authenticated client portal session and secure access to your statutory document repository. Configured with HttpOnly and SameSite=Strict. |
Session (Closes on browser exit) |
| roadlegal_cookie_consent | Functional (1st party) | Records your cookie preference selection so you are not prompted on every page load. | 12 Months |
Zero Third-Party Advertising: Road Legal does not use third-party tracking pixels, behavioural profiling, or cross-site advertising networks.
6. Statutory Data Retention Schedules
Data is retained strictly in accordance with UK transport law:
- Statutory DGSA Annual Reports: Retained for a mandatory minimum period of 5 years under ADR 1.8.3.3 and CDG 2009.
- Roadworthiness & Gate Check Audit Records: Retained for 15 months to support Operator Licence undertakings and DVSA inspection inquiries.
- Client Account Credentials: Maintained for the active duration of your compliance retainer agreement.
7. Your Statutory Rights (UK GDPR)
Under UK GDPR, you have the right to:
- Access: Request a copy of all personal and commercial records held in your compliance account (Subject Access Request).
- Rectification: Request correction of inaccurate or incomplete transport or contact details.
- Erasure: Request deletion of personal data, subject to statutory retention obligations under CDG 2009 / ADR regulations.
- Complaint: You have the right to lodge a complaint with the UK supervisory authority: Information Commissioner's Office (ICO) at ico.org.uk.
Direct Compliance & Privacy Enquiries
To exercise any data rights or discuss the security of your fleet records, contact Martyn McIntee directly: