Loading

Most of our clients are UK and Irish operators, so passenger data we touch is usually subject to the UK GDPR or the EU GDPR. This page sets out how we handle that, in the terms a fleet's own compliance review will ask about.

The short version

You stay the controller. We are your processor. Your passenger data stays in your dispatch platform — we work inside it rather than copying it out. Every engagement starts with a signed data processing agreement and the appropriate international transfer mechanism.

1. Our role

When we run your desk, the fleet is the controller and Ride Dispatchers is the processor under Article 28. We process personal data only on your documented instructions. Where you are a controller established in the UK or EEA, our processing falls in scope of the applicable GDPR.

Separately, for our own sales enquiries and website analytics, we act as a controller. That is covered in our privacy policy.

2. The data processing agreement

We sign a DPA before any agent takes a live call. It is a condition of go-live, not an optional extra. Ours covers the Article 28(3) requirements:

  • Subject matter, duration, nature and purpose of processing.
  • Categories of data subject and personal data.
  • Processing only on documented instructions, including for international transfers.
  • Confidentiality undertakings from everyone with access.
  • Article 32 security measures.
  • Conditions for engaging sub-processors and your right to object.
  • Assistance with data subject rights, DPIAs and breach notification.
  • Deletion or return of data at the end of the engagement.
  • Information and audit rights.

If you would rather use your own DPA template, we will review and sign it. That is common and we do not push back on reasonable terms.

3. International transfers

Our agents are in Pakistan. Neither the UK nor the EU has adopted an adequacy decision for Pakistan, so a transfer mechanism is required and we put one in place:

  • UK controllers: the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
  • EEA controllers: EU Standard Contractual Clauses, controller-to-processor module.

We support your transfer risk assessment with details of our technical and organisational measures, our access-control model, and our position on government access requests. We have never received a government request for client data; if we did, we would challenge it where lawful and notify you unless legally prohibited.

4. Security measures

4.1 Access control

  • Named individual accounts issued by you — no shared logins, ever.
  • Least-privilege roles: an agent sees only the accounts they are rostered on.
  • Multi-factor authentication wherever the client platform supports it.
  • Same-day revocation when an agent leaves the account or the company.
  • Quarterly access reviews, with the report shared on request.

4.2 Operational controls

  • Clean-desk floor: no personal phones, cameras or removable media on the operations floor.
  • Blocked USB storage and restricted outbound file transfer on agent workstations.
  • Supervised floor with named team leads on every shift.
  • Call recording, where enabled, stays in your platform under your retention rules.

4.3 People

  • Background and reference checks before hire.
  • Signed confidentiality and data handling undertakings before first live call.
  • Data protection training at induction and refreshed annually.

5. Sub-processors

We keep the list deliberately short. We do not sub-contract dispatch work to another BPO, and we do not offshore your account a second time.

Sub-processorPurposeLocation
VercelWebsite hostingGlobal CDN / US
FormspreeWebsite enquiry formsUS
Microsoft ClarityWebsite analyticsUS / EU

These serve our own website only — none of them touch your passenger data. We give 30 days' written notice before adding a sub-processor that would, and you may object.

6. Data subject rights

Rights requests about passenger data belong to you as controller. If a passenger contacts us directly we will not respond on the substance; we will forward the request to your nominated contact, normally within two business days, and help you fulfil it. Because the data sits in your platform, you can usually action it yourself faster than we can.

7. Breach notification

If we become aware of a personal data breach affecting your data, we will notify your nominated contact without undue delay and within 24 hours of becoming aware. Our notice will describe what happened, the categories and approximate number of records involved, the likely consequences, and the steps we have taken. We will support your own 72-hour regulator notification. We will not notify your regulator or your passengers on your behalf unless you instruct us to.

8. Retention and deletion

We do not set our own retention period for your data — yours applies, and the records stay in your platform. At the end of an engagement we revoke all agent access and, on your instruction, delete or return anything we hold outside it (SOP documents, reports, call notes) and confirm in writing.

9. Audit

You may audit our compliance with the DPA once in any 12-month period on 30 days' notice, either yourself or through an independent auditor, and more often if a regulator requires it or after a breach. We will also complete your security questionnaire — that resolves most reviews without an on-site visit.

10. Contact

For DPAs, transfer paperwork, security questionnaires or a breach notification: