Privacy Policy
Last updated: 3 May 2026
1. Who we are
HauliK("we", "us", "our") provides fleet management and transport compliance software, including the HauliK web platform and the HauliK Driver mobile application.
For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller for personal data processed through our services.
Contact: info@matmad.co.uk
2. Data we collect
We collect the following categories of personal data:
| Category | Data collected | Purpose |
|---|---|---|
| Account data | Name, email address, role (driver / dispatcher / admin) | Account registration and management |
| Job & activity data | Job assignments, job status updates, timestamps, odometer readings, collection and delivery locations | Providing transport management services |
| Vehicle inspection data | Walkaround check answers, defect descriptions, check outcome (pass / advisory / fail), vehicle and trailer registration numbers | Compliance records and safety reporting |
| Proof of delivery | Recipient name, digital signature, delivery photos (JPEG) | Confirming successful deliveries to transport operators |
| Device photos | Images taken via camera when recording vehicle defects or proof of delivery | Attached to inspection and delivery records |
| Messages | Text messages sent between drivers and dispatchers within the app | In-app communication |
| Working time | Shift start / end times, break periods | Working time compliance reporting |
| Technical data | IP address, device type, app version, error logs | Security, bug fixing, and service improvement |
We do not collect precise GPS / location data, payment card details, or government-issued ID numbers.
3. How we use your data
We process your data to:
- Provide, operate and maintain the HauliK platform and Driver app
- Assign jobs to drivers and track job progress in real time
- Record vehicle safety inspections and generate compliance reports
- Store proof-of-delivery records on behalf of transport operators
- Enable in-app messaging between drivers and office staff
- Monitor working time for drivers' hours compliance
- Send notifications about job assignments or status changes
- Investigate and resolve technical issues
- Meet our legal and regulatory obligations
4. Legal basis for processing
| Purpose | Legal basis |
|---|---|
| Providing the service | Performance of a contract (UK GDPR Art. 6(1)(b)) |
| Compliance records | Legal obligation (UK GDPR Art. 6(1)(c)) — transport operators are required by law to keep vehicle inspection records |
| Working time records | Legal obligation (UK GDPR Art. 6(1)(c)) — Working Time Regulations 1998 |
| Service improvement & security | Legitimate interests (UK GDPR Art. 6(1)(f)) |
5. Who we share your data with
We do not sell your personal data. We may share it with:
- Your employer / transport operator — job records, inspection reports, and proof of delivery are visible to the company that manages your account.
- Supabase Inc. — our cloud database and authentication provider. Data is stored in EU data centres. Supabase is a data processor acting on our instructions.
- Vercel Inc. — our hosting provider. They process request data (IP address, headers) for serving the web platform.
- Legal authorities — where required by law, court order, or regulatory requirement.
6. Data retention
| Data type | Retention period | Reason |
|---|---|---|
| Job records | 7 years | Legal / accounting requirements |
| Vehicle inspection records | 15 months (minimum legal requirement for O-licence holders) | DVSA / traffic commissioner compliance |
| Proof of delivery records | 7 years | Commercial / legal requirements |
| Account data | Duration of employment + 12 months after account deletion | Operational continuity |
| Messages | 12 months | Dispute resolution |
| Technical logs | 90 days | Security and debugging |
Inspection and job records may be retained longer where required by a transport operator's own legal obligations.
7. Your rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — request deletion of your data (subject to legal retention requirements)
- Restriction — ask us to limit processing while a dispute is resolved
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent
To exercise any of these rights, email info@matmad.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
8. Data security
All data is transmitted over HTTPS. Data at rest is encrypted by Supabase using AES-256. Access to personal data is restricted to authorised personnel and controlled by role-based access within the platform. We review our security practices regularly.
9. International transfers
Your data is stored in EU data centres operated by Supabase. Where any transfer outside the UK / EEA is necessary, we ensure appropriate safeguards are in place (standard contractual clauses or adequacy decisions).
10. Children
Our services are not directed at children under 18. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of our services after an update constitutes acceptance of the revised policy.
12. Contact
For any privacy-related queries or to exercise your rights, contact us at:
HauliK
Email: info@matmad.co.uk
Website: haulik.co.uk
HauliK is a product of Mat Mad LTD · Company No. 09270153 · 10 Hay Wain Lane, Midway, Swadlincote, DE11 0XJ