Privacy policy
Privacy Policy - TROJAN AUTOS LIMITED
1. Introduction
TROJAN AUTOS LIMITED ("we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we1 collect, use, and share your personal data2 in accordance with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA 2018).
2. Data Controller
Trojan Autos, is the data controller responsible for your personal data.
3. Personal Data We Collect
We may collect the following types of personal data:
Contact Information: Name, address, telephone number, email address.
Vehicle Information: Vehicle registration number, make, model, VIN, service history, crash history.
Payment Information: Payment card details, bank account details (collected for processing payments only, and not stored).
Job Information: Details of the work carried out on your vehicle, including estimates, invoices, and job cards.
Communication Data: Records of correspondence with you, including emails, letters, and phone calls.
CCTV footage: Where applicable, footage from CCTV systems installed on our premises.
Website Data: IP address, browser type, and other technical information collected when you visit our website (if applicable).
4. How We Collect Your Personal Data
We collect your personal data in the following ways:
Directly from you when you provide it to us, such as when you book a service, request an estimate, or make a payment.
Automatically when you visit our website (using cookies and similar technologies, if applicable).
From third parties, such as payment processors.
From CCTV systems on our premises.
5. Purposes of Processing Your Personal Data
We process your personal data for the following purposes:
To provide you with our services, including vehicle repairs, servicing, and maintenance.
To process payments and manage your account.
To communicate with you about your vehicle and our services.
To comply with legal and regulatory obligations.
To improve our services and customer experience.
To ensure the security of our premises and prevent crime.
For record keeping.
6. Legal Basis for Processing Your Personal Data
We rely on the following legal bases for processing your personal data:
Contract:3 Processing is necessary for the performance of a contract with you.
Legal Obligation: Processing is necessary for compliance with a legal obligation.4
Legitimate Interests: Processing is necessary for our legitimate interests,5 provided your rights and freedoms do not override those interests. This includes, but is not limited to, the running of our business, and the protection of our property.
Consent: Where you have given us consent to process your personal data for a specific purpose. You have the right to withdraw your consent6 at any time.
7. Sharing Your Personal Data
We may share your personal data with the following third parties:
Payment processors to process payments.
Suppliers and subcontractors who assist us in providing our services.
Legal and regulatory authorities when required by law.
CCTV footage may be shared with law enforcement agencies if a crime is suspected.
8. Data Security
We have implemented appropriate technical and organisational measures to protect your personal data from unauthorised access, use,7 or disclosure. These are in line with industry standards and advise from the NCSC.
9. Data Retentions
We will retain your personal data for as long as necessary to fulfill the purposes for which it was collected,8 including for the purpose of satisfying any legal, accounting, or reporting9 requirements. Generally, we will keep your data for 7 years, to adhere to HMRC requirements.
10. Your Rights
Under the UK GDPR and DPA 2018, you have the following rights:
Right to Access: You have the right to request access to your personal data.
Right to Rectification: You have the right10 to request that we correct any inaccurate or incomplete personal data.
Right11 to Erasure: You have the right to request that we delete your personal data in certain circumstances.
Right to Restriction of Processing: You have the right to request that we restrict the processing12 of your personal data in certain circumstances.
Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and13 machine-readable format.
Right to Object: You have the right to object to the processing of your personal14 data in certain circumstances.
Right to Withdraw Consent:15 Where we rely on consent, you have the right to withdraw your consent at any time.
Right to complain: You have the right to lodge a complaint16 with the Information Commissioner’s Office (ICO).
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our data processing practices, please contact17 us:
Trojan Autos Limited
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting18 the updated policy on our website19 or by other means.
Date: 31/03/2025
Revision 1