Summary
This summary is provided for convenience in accordance with Article 12(1) of the UK GDPR. It does not form part of the Policy and does not vary the clauses below.
- DIGITALSOM LTD acts as controller in respect of Authorised User account data, and as processor in respect of Customer Data generated by a Customer's fleet. See clause 4.
- The Platform processes continuous vehicle location data, video and still images capable of identifying individuals, and driver identity data including driving licence numbers. See clause 5.
- Production data is hosted in the United Kingdom and protected using encryption in transit and at rest. Retention depends on the type of record, the Customer's instructions and applicable legal obligations. See clauses 10 and 11.
- Personal Data is not sold and is not disclosed for advertising purposes. No advertising is served. See clause 9.
- The Android application performs no independent collection of Personal Data. See clause 15.
- Requests under clause 16 should be addressed to admin@raad-iot.com.
01Introduction and scope
- This privacy policy (the "Policy") sets out the basis on which DIGITALSOM LTD processes Personal Data relating to identified or identifiable natural persons in connection with the Raad IoT platform and its associated properties.
- The Policy applies to:
- the marketing website at raad-iot.com;
- the application at portal.raad-iot.com (the "Platform"); and
- the Android application published on Google Play as "Raad IoT - by Digitalsom", package identifier com.raad.iot (the "App").
- The Policy does not govern Processing carried out by a Customer in its capacity as Controller. Where a Customer determines the purposes and means of Processing, that Customer's own privacy notice applies to the Data Subject, and clause 4 governs the allocation of responsibility between the parties.
- Capitalised terms have the meanings given in clause 2. A reference to a clause is a reference to a clause of this Policy.
- Nothing in this Policy operates to limit, exclude or vary a right conferred on a Data Subject by Applicable Data Protection Law. To the extent of any inconsistency between this Policy and Applicable Data Protection Law, Applicable Data Protection Law prevails.
02Definitions
- In this Policy, the following terms have the following meanings.
| Term | Meaning |
|---|---|
| Applicable Data Protection Law | The UK GDPR, the DPA 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, the Kenya DPA, the Kenya Regulations, the EU GDPR to the extent that it applies, and any other data protection or privacy legislation applicable to the Processing described in this Policy. |
| Authorised User | A natural person to whom credentials for the Platform have been issued. Credentials are provisioned by us or by a Customer administrator; the Platform provides no facility for self-registration. |
| Controller | Has the meaning given in Article 4(7) of the UK GDPR. |
| Customer | An organisation that has contracted for the Platform, whether directly with us or through a Partner. |
| Customer Data | Personal Data uploaded to, generated within, or transmitted to the Platform by or on behalf of a Customer, including telematics, video, fuel, metering, compliance and driver records relating to that Customer's operation. |
| Data Subject | Has the meaning given in Article 4(1) of the UK GDPR. |
| Device | A telematics unit, camera, meter, sensor or other item of hardware that transmits data to the Platform. |
| DPA 2018 | The Data Protection Act 2018 of the United Kingdom. |
| EU GDPR | Regulation (EU) 2016/679. |
| ICO | The Information Commissioner's Office, being the supervisory authority for the United Kingdom. |
| Kenya DPA | The Data Protection Act, 2019 (No. 24 of 2019) of the laws of Kenya. |
| Kenya Regulations | The Data Protection (General) Regulations, 2021 made under the Kenya DPA. |
| ODPC | The Office of the Data Protection Commissioner, being the supervisory authority for Kenya. |
| Partner | A reseller authorised to distribute the Platform under its own brand. |
| Personal Data | Has the meaning given in Article 4(1) of the UK GDPR, and includes personal data as defined in section 2 of the Kenya DPA. |
| Processing | Has the meaning given in Article 4(2) of the UK GDPR, and "Process" is construed accordingly. |
| Processor | Has the meaning given in Article 4(8) of the UK GDPR. |
| Special Category Data | Personal Data of the categories listed in Article 9(1) of the UK GDPR, and sensitive personal data as defined in section 2 of the Kenya DPA. |
| Sub-processor | A third party engaged by us to carry out Processing on behalf of a Customer. |
| Tenant | The logically separated account within the Platform allocated to a Customer. |
| UK GDPR | The United Kingdom General Data Protection Regulation, as defined in section 3(10) of the DPA 2018. |
| We, us, our | DIGITALSOM LTD, as further identified in clause 3. |
| You, your | The Data Subject to whom the relevant Personal Data relates. |
03Identity and contact details of the controller
- Where we act as Controller, the Controller is DIGITALSOM LTD (company number 11946318), a company incorporated in England and Wales, whose registered office is at 413 Coventry Road, Small Heath, Birmingham, B10 0TH, United Kingdom.
- Enquiries concerning this Policy, requests made under clause 16, and questions about our data protection practices should be addressed to admin@raad-iot.com.
- This Policy is issued by our United Kingdom establishment. Nothing in it limits rights that may apply under the data-protection law of the country in which you live or work. The jurisdiction-specific information at clause 17 applies where the relevant law applies to the Processing.
04Controller and processor roles
- Two distinct categories of Processing are carried out in connection with the Platform, and the allocation of responsibility differs between them. The distinction determines against whom a Data Subject is to exercise the rights described in clause 16.
- We act as Controller in respect of Personal Data relating to Authorised Users, being the account, authentication, session, role and audit records described in clauses 5.3 and 5.4. In respect of that Processing we determine the purposes and the means, and this Policy constitutes the information required to be provided by Articles 13 and 14 of the UK GDPR.
- We act as Processor in respect of Customer Data. The Customer determines which vehicles are fitted with Devices, which cameras are installed and in what direction they are oriented, which drivers are enrolled, which modules are enabled, and what is retained. We Process Customer Data only on the documented instructions of the Customer, in accordance with Article 28 of the UK GDPR and section 42 of the Kenya DPA.
- Where we act as Processor, the Customer is the Controller and is responsible for establishing a lawful basis for the Processing, for providing the information required by Articles 13 and 14 of the UK GDPR to the Data Subjects concerned, and for responding to requests made under Articles 15 to 22. A Data Subject who is a driver, employee or contractor of a Customer is to direct any request concerning telematics, video, fuel or document records to that Customer. Where such a request is received by us we will refer it to the Customer and notify the Data Subject that we have done so. We will not disclose, rectify or erase Customer Data at the instance of a person other than the relevant Customer, save where required to do so by law.
- The agreement with the relevant Customer governs the Processing instructions, confidentiality, security, assistance with rights requests, retention and deletion of Customer Data. We require written data-processing terms before Processing Customer Data on a Customer's behalf where Applicable Data Protection Law requires them.
05Categories of personal data processed
- The categories set out below are derived from the data model of the Platform. The categories actually Processed in respect of any given Customer depend upon the modules that Customer has enabled and the Devices it has deployed.
- Website and sales-enquiry data. When a person asks us for a demonstration, a proposal or other information, we process the name, business contact details, organisation, message and correspondence supplied by that person. We use this information to respond to the request and manage the prospective business relationship.
- Account and authentication data.
- Email address, name, and profile photograph where one is supplied.
- A password hash and a salt unique to the Authorised User. The password itself is not stored.
- A one-time password secret, where two-factor authentication is enabled.
- The date and time of the most recent sign-in.
- Session cookies, and password reset tokens stored in hashed form.
- Where a Customer has enabled Microsoft sign-in, the object identifier and tenant identifier received from Microsoft Entra ID.
- Tenant membership, role assignments, and saved dashboard configuration.
- Activity and administrative records.
- An audit log recording the identity of the acting user, the action performed, the affected record, the time of the action, and the values before and after the change. The acting user's email address is copied into each entry so that the record remains intelligible following deletion of that user's account.
- Application programming interface tokens issued for machine access, stored in hashed form, together with the identifier of the issuing administrator and the time of last use.
- Location and movement data.
- Position, speed and heading of tracked vehicles and assets, recorded continuously for so long as the relevant Device transmits.
- Trip and stop histories derived from those positions.
- Geofence entry and exit events.
- Street addresses resolved from coordinates and cached, so that a given point is resolved once.
- Driver data.
- Name, email address, telephone number, driving licence number, and free-text notes recorded by Customer personnel.
- Radio-frequency identification or iButton token identifiers, by which a Device determines the identity of the driver in control of a vehicle.
- Driver profile photograph.
- Driver session records, being the assignment of a driver to an asset for a stated period.
- Driver behaviour events raised by the rules engine, including speeding and idling events.
- Driver portal submissions. A Customer may issue a personalised enrolment link to a driver. Data submitted through that link is stored on the Platform and comprises name, email address, telephone number, driving licence number, vehicle registration and vehicle particulars, free-text notes, and any documents uploaded by the submitting individual. A submission remains pending until approved or rejected by the Customer.
- Compliance documents. Insurance certificates, logbooks, inspection reports, roadworthiness and registration certificates, service records and other files associated with a vehicle or a driver, together with the file name, media type, size, issue date and expiry date of each.
- Video and still images.
- Still images and video recorded by in-vehicle cameras which, depending upon the installation, may depict the driver, the vehicle cabin, and the forward carriageway including other road users.
- Video recorded by fixed cameras at Customer premises, including depots and offices, which may depict any person present at those premises.
- Credentials for third-party camera systems connected by a Customer, stored in encrypted form.
- Fuel, metering and sensor data.
- Fuel transactions, tank level readings, and refuelling and drain events, which may be associated with a named driver and a vehicle.
- Meter readings and consumption records.
- Prepaid meter top-up records, including the amount, the token issued, the email address of the person who processed the transaction, and an external payment reference. Payment card numbers are not Processed by us; card payments are effected at the payment provider.
- Readings from connected sensors.
- Operational records. Maintenance tasks and inspections, tyre and fitment records, alerts and alert incidents, guard cases together with their evidence and approvals, support cases with comments and file attachments, saved reports, scheduled reports and the email addresses to which they are distributed, and carbon and emissions records.
- Device and SIM data. Device identifiers, configuration profiles, electronic lock rules, and a log of every command transmitted to a Device. In respect of SIM cards, the integrated circuit card identifier, the mobile subscriber number, the network on which the SIM is camped, data and short message usage, and the last known location reported by the mobile network operator for that SIM.
- Analytical outputs. Insights, agent runs, actions proposed or taken by the analytical layer, and user feedback upon those outputs. Each insight cites the records from which it was derived and may accordingly reference a Device, an alert or a coordinate.
06Sources of personal data
- Personal Data is obtained from the following sources.
- From the Data Subject directly, upon creation of an account, configuration of two-factor authentication, upload of a document, submission through the driver portal, or the opening of a support case.
- From the Customer, where its personnel import driver, asset or document records, or enrol Devices.
- From Devices in the field, which transmit autonomously and without any action on the part of the Data Subject.
- From Microsoft Entra ID, where the Customer has enabled Microsoft sign-in, comprising the object identifier, the tenant identifier and the email address.
- From service providers, comprising mobile network operators and the SIM management platform (SIM status, usage and cell location), connected camera platforms (footage and camera state), and geocoding providers (street addresses resolved from submitted coordinates).
- Personal Data is not obtained from data brokers or from publicly scraped sources.
07Purposes of processing and lawful bases
- Where we act as Controller, we Process Personal Data for the purposes and upon the lawful bases set out in the table below. Where we rely on legitimate interests, those interests are operating, supporting and securing the business Platform while respecting the rights and freedoms of the individuals concerned.
| Purpose | Lawful basis |
|---|---|
| Responding to a website or sales enquiry | Article 6(1)(b) UK GDPR, where the individual asks us to take steps before entering a contract; otherwise Article 6(1)(f), our legitimate interest in responding to a business enquiry |
| Authentication of Authorised Users and administration of accounts | Article 6(1)(f) UK GDPR: our legitimate interest in providing secure, role-based access to the Platform |
| Recording of administrative actions in the audit log | Article 6(1)(f) UK GDPR: our legitimate interest in maintaining an auditable, secure Platform; and Article 6(1)(c) where a legal obligation applies |
| Transmission of service communications, including password resets, alerts and scheduled reports | Article 6(1)(f) UK GDPR: our legitimate interest in providing the Platform and keeping Authorised Users informed about its operation |
| Investigation of faults and response to support requests | Article 6(1)(f) UK GDPR: our legitimate interest in resolving faults and providing support |
| Maintenance of the security and integrity of the Platform, including the prevention of fraud | Article 6(1)(f) UK GDPR |
- Where we act as Processor, the Customer determines the purpose and the lawful basis of the Processing. The purposes ordinarily relied upon by Customers include the management of their own operations, compliance with transport and road safety legislation, and the protection of vehicles and cargo. A Data Subject seeking particulars of the lawful basis relied upon is to apply to the relevant Customer.
- Personal Data is not Processed for the purposes of advertising, advertising profiling or sale to third parties. No advertising business is operated.
08Special category data
- The Platform is not designed to Process Special Category Data, and an Authorised User is not required to supply such data in order to hold an account.
- Video and still images captured by in-vehicle and fixed cameras may nonetheless permit the identification of a natural person, and may incidentally reveal characteristics falling within Article 9(1) of the UK GDPR. Such material is treated as requiring heightened protection, and the measures at clause 13 apply to it.
- The Platform does not provide facial recognition or other biometric identification designed to uniquely identify a person. A Customer that enables cameras or provides material that may reveal Special Category Data remains responsible, as Controller, for identifying a lawful condition, giving affected people appropriate information and completing any assessment required by Applicable Data Protection Law.
09Recipients and sub-processors
- Disclosure within the Platform. The Platform is organised into three levels of access, being platform, partner and account. A Partner administrator may access the accounts of the Customers beneath it, which is the mechanism by which a Partner supports its own customers. Within a Tenant, access is determined by roles administered by that Customer.
- Sub-processors. The following service providers are engaged in the operation of the Platform as at the date of this Policy.
- DigitalOcean, LLC, for the hosting of the Platform, its database, uploaded files and backups. See clause 10.
- OpenRouter, for the routing of requests to language model providers.
- Twilio SendGrid, for outbound electronic mail, including password resets, alerts and scheduled reports.
- Cloud-IQ, for SIM management and outbound short message service.
- Microsoft Entra ID, where a Customer has enabled Microsoft sign-in.
- Mapping and geocoding providers, being, according to the configuration selected by the Customer, one of MapTiler, Stadia Maps, LocationIQ, HERE, Nominatim operating upon OpenStreetMap data, or Google. Coordinates are transmitted to the provider in order that a map tile or a street address may be returned.
- Third-party camera platforms, being whichever system the Customer has elected to connect.
- We use written terms with Sub-processors that require them to protect Personal Data appropriately and to process it only for the services they provide to us. A Customer may request current Sub-processor information from admin@raad-iot.com. We will give Customer administrators reasonable prior notice of a material new Sub-processor where required by the applicable Customer agreement.
- Disclosure required by law. We may disclose Personal Data where required to do so by a law to which we are subject, or where necessary for the establishment, exercise or defence of legal claims. Where we are permitted to do so, we will notify the relevant Customer before making such a disclosure.
- Corporate transactions. In the event of a merger, acquisition, reorganisation or sale of assets affecting the business or any part of it, Personal Data may be transferred to the acquiring entity.
- No sale. Personal Data is not sold, and is not disclosed to any third party for the purposes of advertising.
10Location of data and international transfers
- The Platform is hosted on infrastructure operated by DigitalOcean, LLC, a subsidiary of DigitalOcean Holdings, Inc., a company incorporated in the United States. The production database, uploaded files and backups are located in that provider's London region, within the United Kingdom.
- Personal Data is encrypted in transit and encrypted at rest.
- Personal Data is not routinely transferred outside the United Kingdom for the purposes of storage.
- Processing may occur outside the United Kingdom in the following circumstances:
- our personnel in Kenya access the Platform in the course of operating and supporting it;
- the Sub-processors identified at clause 9.2 process data outside the United Kingdom, coordinates being transmitted to mapping and geocoding providers, text derived from Platform records being transmitted to model providers by way of OpenRouter, and electronic mail being transmitted through SendGrid; and
- the parent company of our hosting provider is established in the United States, and its personnel may hold administrative access to the hosting infrastructure.
- Where a transfer is a restricted transfer under Applicable Data Protection Law, we will not make it unless a valid transfer mechanism is in place, such as an adequacy decision, appropriate safeguards or a permitted exception. You may request information about the safeguards that apply to a particular transfer by emailing admin@raad-iot.com.
11Retention
- Personal Data is retained for no longer than is necessary for the purposes for which it is Processed, in accordance with Article 5(1)(e) of the UK GDPR and section 25(e) of the Kenya DPA.
- Customer Data of the categories described at clauses 5.5 to 5.13, comprising position and trip history, driver records, video and still images, fuel, metering and sensor readings, operational records and Device and SIM data, is retained in accordance with the Customer's documented instructions, the services and modules it has selected, and any applicable legal obligation.
- Account and authentication records described at clause 5.3 are retained for the life of the relevant Account and for a limited period afterwards where needed to protect the Platform, resolve a dispute, comply with a legal obligation or maintain an audit trail.
- The following periods are enforced by the Platform and are stated without qualification.
- A password reset token is valid for forty-five minutes and may be redeemed once.
- A change of password invalidates every extant session of the affected Authorised User with immediate effect.
- A generated report file carries an expiry date, upon the passing of which the file is deleted and only the record that the report was generated is retained.
- When Customer Data is deleted from active systems, it may remain in protected backup copies until the normal backup-overwrite cycle completes. We do not restore deleted data from a backup except where necessary to recover the Platform, and any restored data remains subject to the applicable deletion instruction. A Customer may request the applicable retention and backup-deletion timetable from admin@raad-iot.com.
12Automated processing and analytical outputs
- The Platform incorporates an analytical layer which reads records of the categories described in clause 5 and produces insights, diagnostics and proposed actions. Requests are routed through OpenRouter to the language model provider selected within the Platform. A request may contain Device identifiers, alert particulars, coordinates and other operational records.
- Outputs are stored against the Tenant of the Customer concerned. An Authorised User may accept, dismiss or comment upon an output, and that feedback is stored with it.
- The analytical layer proposes actions for determination by an Authorised User. It does not take a decision based solely on automated processing which produces legal effects concerning a Data Subject or similarly significantly affects a Data Subject within the meaning of Article 22(1) of the UK GDPR and section 35 of the Kenya DPA. Where a Customer configures the Platform so that a proposed action is executed without human review, that configuration is the act of the Customer as Controller and the resulting obligations fall upon that Customer.
- The model provider used for a request depends on the model selected in the Platform and may change as models are added or removed. Before enabling the analytical layer, a Customer may request the current model-provider list, the relevant data-processing terms and the available retention and training-use controls from admin@raad-iot.com.
13Security of processing and personal data breaches
- We implement appropriate technical and organisational measures in accordance with Article 32 of the UK GDPR and section 41 of the Kenya DPA. The measures presently implemented are as follows.
- Personal Data is encrypted in transit and encrypted at rest.
- Passwords are stored as a hash with a salt unique to each Authorised User.
- Password reset tokens and application programming interface tokens are stored only as SHA-256 hashes, such that a copy of the database does not permit an account to be reset or the interface to be called.
- Credentials for connected third-party services are encrypted at rest.
- Session cookies are marked HttpOnly with SameSite set to Lax, such that they are not readable by script executing in the page.
- Two-factor authentication by means of an authenticator application is available upon every account.
- Access within a Tenant is governed by roles, and each permission is granted expressly rather than inferred.
- Guard case evidence is hash-chained, such that a record cannot be altered without invalidating the chain.
- No system of security is capable of eliminating risk. The measures above mitigate risk; they do not warrant that a compromise cannot occur.
- Where a personal data breach occurs we will assess it without undue delay and, where the criteria in the applicable legislation are met, will notify:
- the ICO, within seventy-two hours of becoming aware of the breach, in accordance with Article 33 of the UK GDPR;
- the ODPC, within seventy-two hours of becoming aware of the breach, in accordance with section 43 of the Kenya DPA;
- the competent supervisory authority in the European Union, within seventy-two hours, where the EU GDPR applies to the affected Processing; and
- the affected Data Subjects, without undue delay, where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 of the UK GDPR and section 43(2) of the Kenya DPA.
- Where we act as Processor, we will notify the affected Customer without undue delay upon becoming aware of a personal data breach affecting Customer Data, and will provide that Customer with the information it requires in order to discharge its own notification duties as Controller.
14Cookies and similar technologies
- The Platform at portal.raad-iot.com sets the following cookies.
- A session cookie carrying the signed session of the Authorised User.
- A short-lived cookie used during two-factor authentication, between the password step and the code step.
- A short-lived cookie holding the state value for Microsoft sign-in, which prevents the replay of a sign-in response.
- Each of the cookies listed at clause 14.1 is strictly necessary for the provision of the service requested by the Authorised User, and accordingly falls within the exemption at regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003. Consent is not sought for them.
- The Platform sets no analytics cookie, advertising cookie or third-party tracking technology.
- The marketing website at raad-iot.com does not use analytics or advertising cookies. It loads typefaces from Google Fonts, which causes the visitor's browser to connect to Google and may disclose technical information such as an IP address and browser details to that provider. If we introduce a non-essential cookie or tracking technology, we will ask for consent before setting or accessing it.
15Mobile application
- This clause is provided for the assistance of Data Subjects who install the App and of reviewers assessing the Google Play listing.
- The App presents the Platform on an Android device. The session, the cookies described at clause 14.1, and the Processing described throughout this Policy are the same as those arising upon access to the Platform by any other means.
- In respect of the App itself:
- the App performs no collection of Personal Data independently of the Platform, and contains no code for that purpose;
- the App contains no analytics software development kit and no advertising software development kit;
- the App declares no runtime permissions and does not request access to location, camera, contacts, storage or microphone. Location displayed within the App is telemetry transmitted by Devices and served from the Platform; it is not a reading taken from the handset;
- the App displays no advertising and offers no in-application purchase; and
- signing out within the App, or clearing the application data, terminates the session in the same manner as signing out in a browser. Uninstalling the App removes the App and its local data, and does not delete the Authorised User's account, which is administered by the Customer.
- Any Google Play Data safety declaration for the App should be kept consistent with this clause whenever the App or its data practices change.
16Rights of data subjects
- Subject to the conditions and exemptions in Applicable Data Protection Law, you have the following rights in respect of Personal Data for which we act as Controller.
- The right of access to the Personal Data and to the information specified in Article 15 of the UK GDPR and section 26(a) of the Kenya DPA.
- The right to rectification of inaccurate Personal Data under Article 16 of the UK GDPR and section 26(d) of the Kenya DPA.
- The right to erasure under Article 17 of the UK GDPR and section 26(e) of the Kenya DPA.
- The right to restriction of Processing under Article 18 of the UK GDPR.
- The right to data portability under Article 20 of the UK GDPR.
- The right to object to Processing under Article 21 of the UK GDPR, including Processing carried out on the basis of Article 6(1)(f), and under section 26(b) of the Kenya DPA.
- The right to withdraw consent under Article 7(3) of the UK GDPR, where consent is the basis relied upon, without affecting the lawfulness of Processing carried out before the withdrawal.
- The right to lodge a complaint with a supervisory authority, as provided at clause 19.
- A request is to be made to admin@raad-iot.com and should specify the right relied upon and sufficient particulars to enable the Personal Data to be located. Our privacy team owns this request process.
- We may request evidence of identity before acting upon a request. We will use reasonable and proportionate checks, for example confirmation from the email address associated with the account or a request routed through the relevant Customer administrator. We will not request more information than is necessary to verify the requester.
- Where we act as Processor, clause 4.4 applies and the request is to be made to the Customer that is the Controller of the Personal Data concerned.
- No detriment will be applied by reason of the exercise of any right under this clause.
- We will respond to a request within one month of receipt, as required by Article 12(3) of the UK GDPR and, where it applies, the EU GDPR. That period may be extended by two further months where the request is complex or where a number of requests have been received, in which case we will inform you of the extension and of the reasons for it within the first month. Where Kenyan law governs the request, we will meet the applicable statutory time limit: seven days for access and restriction of direct marketing; fourteen days for rectification and erasure; and thirty days for portability. We will give written reasons where a request is refused.
17Jurisdiction-specific provisions
- United Kingdom. We are established in the United Kingdom and the UK GDPR and the DPA 2018 apply to the Processing for which we act as Controller. Those instruments apply by reason of our establishment, and their application does not depend upon the location of our Customers or of any Data Subject. The rights at clause 16 are conferred by that legislation.
- Kenya. Where the Kenya DPA and its Regulations apply to the Processing, the rights at clause 16 apply and the supervisory authority is the Office of the Data Protection Commissioner (ODPC).
- European Union. Where the EU GDPR applies, the rights at clause 16 apply under the corresponding Articles of the EU GDPR. A Data Subject may lodge a complaint with the supervisory authority of the Member State of that Data Subject's residence, place of work or the place of the alleged infringement. Where an EU representative is required by Article 27 of the EU GDPR, we will provide its contact details in this Policy before offering or monitoring the relevant Processing.
18Children
- The Platform is a business application. It is not directed to children, and credentials are not issued to persons under the age of eighteen. Personal Data relating to a person under that age is not knowingly Processed by us as Controller.
- Where a Customer enrols a driver under the age of eighteen in the course of its own operation, that Customer is the Controller in respect of that record and its own obligations fall upon it, including those arising under the age appropriate design code issued under section 123 of the DPA 2018 and under section 33 of the Kenya DPA, where applicable.
19Complaints
- A Data Subject who considers that Processing for which we act as Controller infringes Applicable Data Protection Law is invited to raise the matter with us in the first instance, at the address given at clause 16.2, so that it may be investigated.
- A Data Subject retains the right to lodge a complaint with a supervisory authority irrespective of whether the matter has first been raised with us.
- The supervisory authority for the United Kingdom is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.
- The supervisory authority for Kenya is the Office of the Data Protection Commissioner, to which a complaint may be lodged under section 56 of the Kenya DPA.
- A Data Subject in the European Union may lodge a complaint with the supervisory authority identified at clause 17.3.
- A complaint may be made without cost and without legal representation.
20Amendments to this policy
- This Policy may be amended from time to time. The date stated at the head of this page is the date upon which the current version took effect.
- Where an amendment materially affects the Processing described in this Policy, we will give notice to Customer administrators by electronic mail before the amendment takes effect.
- Changes to this Policy do not reduce any rights provided by Applicable Data Protection Law.
21Contact
- Requests under clause 16 and enquiries concerning this Policy are to be addressed to admin@raad-iot.com. Our identity and registered office are stated at clause 3.1.