Privacy and Data Protection Policy

Lawful, fair, secure and transparent use of personal information

Policy owner

Board of Directors

Approved

27 August 2026, version 1.0

Approved by

Yogen Limbu

Next review

28 August 2027

Same Day Courier 247 Ltd

Company no. 16300645 · Registered office: 20 Wenlock Road, London, N1 7GU

How Same Day Courier 247 Ltd collects, uses, shares, retains and protects personal information under UK data-protection law.

1. Who we are

Same Day Courier 247 Ltd, trading as Same Day Courier 247, provides courier, freight-forwarding and road-transport services.

For the purposes of UK data-protection law, the Company will normally act as a data controller for the personal information it collects and uses.

Privacy enquiries and complaints may be sent to the Data Protection Contact at Same Day Courier 247 Ltd, 20 Wenlock Road, London, N1 7GU, or by email to transport@samedaycourier247.com.

2. Purpose

The Company is committed to handling personal information lawfully, fairly, securely and transparently.

This policy applies to personal information relating to customers, customer representatives, consignees, suppliers, drivers, subcontractors, employees, applicants and other individuals with whom the Company deals.

3. Information we may collect

Depending on the circumstances, the Company may collect:

  • Names and business contact details.
  • Collection and delivery addresses.
  • Consignee telephone numbers and delivery instructions.
  • Booking and consignment information.
  • Proof-of-delivery signatures, names and photographs.
  • Correspondence, telephone-call information and complaint records.
  • Invoicing and payment information.
  • Driver, vehicle, licence and insurance details.
  • Location, route or telematics information where used.
  • CCTV or dashcam footage where used.
  • Employment or subcontractor information.
  • Information required to investigate a claim, incident or suspected fraud.

Information reasonably required

The Company will seek to collect only information that is reasonably necessary.

4. How we use personal information

The Company may use personal information to:

  • Provide quotations and accept bookings.
  • Arrange collections, transport and deliveries.
  • Communicate with customers, drivers and consignees.
  • Provide tracking and proof of delivery.
  • Manage customer and supplier accounts.
  • Issue invoices and process payments.
  • Appoint and manage drivers and subcontractors.
  • Deal with complaints, claims, losses, damage and insurance matters.
  • Maintain safety, security and service quality.
  • Prevent or investigate fraud and unlawful activity.
  • Comply with legal, regulatory, tax and accounting obligations.
  • Market the Company's services where permitted by law.

Lawful bases

The Company will normally rely on one or more of the following lawful bases:

  • Performance of a contract or steps requested before entering a contract.
  • Compliance with a legal obligation.
  • The Company's or a third party's legitimate interests.
  • Consent, where consent is required.
  • The establishment, exercise or defence of legal claims.

5. Data-protection principles

The Company will take proportionate steps to ensure that personal information is:

  • Processed lawfully, fairly and transparently.
  • Collected for clear and legitimate purposes.
  • Adequate, relevant and limited to what is necessary.
  • Accurate and corrected where required.
  • Retained only for as long as reasonably necessary.
  • Protected against unauthorised access, loss, destruction or disclosure.

6. Sharing information

The Company may share relevant personal information with:

  • Customers, senders and consignees.
  • Drivers, owner-drivers and subcontracted hauliers.
  • Freight, logistics and delivery partners.
  • IT, communications, accounting and payment-service providers.
  • Insurers, loss adjusters, solicitors and professional advisers.
  • Government departments, regulators, courts or law-enforcement bodies.
  • Another organisation involved in a business sale, merger or restructuring.

Proportionate sharing controls

Only information reasonably required for the relevant purpose should be shared.

Where a supplier processes personal information for the Company, proportionate contractual and security arrangements will be used.

7. International transfers

Where personal information must be transferred outside the United Kingdom, the Company will take reasonable steps to ensure that the transfer is lawful and that appropriate safeguards are used where required.

8. Security

The Company will use proportionate technical and organisational measures, which may include:

  • Password and access controls.
  • Limiting access to those who require the information.
  • Secure systems and reputable service providers.
  • Staff and subcontractor confidentiality requirements.
  • Secure storage and disposal.
  • Maintaining appropriate backups.
  • Procedures for reporting and managing suspected data breaches.

Reporting suspected data breaches

Any suspected loss, unauthorised disclosure or misuse of personal information must be reported immediately to a director or the Data Protection Contact.

9. Retention

Personal information will be retained in accordance with the Company's Data Retention and Secure Disposal Policy.

Information may be retained for longer where reasonably required for legal proceedings, an insurance matter, a regulatory investigation or another documented legal obligation.

10. Individual rights

Depending on the circumstances, an individual may have the right to:

  • Request access to their personal information.
  • Request correction of inaccurate information.
  • Request deletion of information.
  • Request restriction of processing.
  • Object to processing.
  • Receive certain information in a portable format.
  • Withdraw consent where processing is based on consent.

Conditions that apply to rights

These rights are subject to legal conditions and exemptions. Requests should be sent to the Data Protection Contact.

The Company may request evidence of identity before disclosing personal information.

11. Data-protection complaints

A person who is dissatisfied with how the Company has handled their personal information may submit a complaint by email or post using the contact details above.

The Company will:

  • Provide a clear way for a complaint to be made.
  • Acknowledge receipt within 30 days.
  • Make appropriate enquiries without undue delay.
  • Keep the complainant informed of material progress.
  • Communicate the outcome without undue delay.

Complaint records and the ICO

A record of the complaint, investigation and outcome will be maintained for an appropriate period.

An individual may also raise the matter with the Information Commissioner's Office.

12. Marketing

The Company will only send electronic marketing where it has an appropriate lawful basis and has complied with applicable direct-marketing rules.

Marketing communications will include a reasonable method of opting out. Opt-out requests will be respected, although limited information may be retained on a suppression list to prevent further marketing.

13. Responsibilities and breaches

Everyone working for or on behalf of the Company must:

  • Handle personal information confidentially.
  • Use it only for authorised business purposes.
  • Keep it accurate where reasonably possible.
  • Protect it from unauthorised access.
  • Report suspected breaches promptly.

Serious or deliberate breaches

Serious or deliberate breaches may result in disciplinary action or termination of a commercial relationship.

14. Review

This policy will be reviewed at least annually and following any material change in the Company's processing activities or applicable law.

Approval

This policy was approved on behalf of Same Day Courier 247 Ltd.

Director's nameDateVersion
Yogen Limbu27 August 20261.0

Questions about this policy can be sent to transport@samedaycourier247.com.

View all policies