Data Protection

Privacy Policy

How DriverWell collects, uses, and protects your personal data

Last updated: 29 March 2026

1. Introduction

DriverWell ("we", "us", "our") is a mental health and wellbeing platform designed specifically for professional drivers. We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding your personal information.

Data Controller

DriverWell, operated by Peter McKenna
Website: driverwell.co.uk
Contact: [email protected]

2. Data We Collect

We collect the minimum amount of personal data necessary to provide our services. We do not sell your data to third parties.

Account Information

  • Name (as provided by your login provider)
  • Email address
  • Login method (e.g. Google)
  • Account creation date

Legal basis: Contract performance (Art. 6(1)(b) UK GDPR)

Health & Wellbeing Data

  • Mood check-in entries (mood score, alertness, stress level, optional notes)
  • Fatigue logs (driving/rest minutes)
  • Blood glucose readings (if you use the diabetes tracker)
  • Wellness logs (hydration, exercise, sleep, back pain scores)
  • Meal plans

Legal basis: Explicit consent (Art. 9(2)(a) UK GDPR) — health data is a special category

Community & Communication Data

  • Forum posts and replies (using your chosen display name, not your real name)
  • AI chat conversations with RoadMate
  • Push notification preferences

Legal basis: Legitimate interest (Art. 6(1)(f) UK GDPR)

Testimonial & Story Submissions

  • Story content (text, video links, or uploaded videos)
  • Your name, role/title, and company type
  • Video files (MP4, WebM, MOV) uploaded to secure cloud storage
  • YouTube and TikTok links (if you choose to share)
  • Submission timestamp and approval status

Legal basis: Explicit consent (Art. 6(1)(a) UK GDPR)

Influencer Partnership Data

  • Name and bio/description
  • Profile picture (uploaded or from social media)
  • Social media platforms (TikTok, YouTube, Instagram, Facebook)
  • Platform profile URLs and follower counts
  • Tier level (Bronze, Silver, Gold)
  • Active/inactive status

Legal basis: Explicit consent (Art. 6(1)(a)) + Legitimate interest (Art. 6(1)(f)) for public profile display

Technical Data

  • Anonymous page view analytics (page visited, timestamp, session ID)
  • Browser type and device information (for responsive design)
  • Push notification subscription endpoint (if you opt in)

Legal basis: Legitimate interest (Art. 6(1)(f) UK GDPR)

3. How We Use Your Data

PurposeData UsedLegal Basis
Provide mood tracking and wellbeing featuresHealth & wellbeing dataConsent
Display your check-in streaks and achievementsMood entry timestampsContract
Enable peer support forumDisplay name, post contentLegitimate interest
Provide AI chat support (RoadMate)Chat messagesConsent
Send check-in reminders (if opted in)Push subscriptionConsent
Improve the platform (anonymous analytics)Page views, session dataLegitimate interest
Employer fleet management (if linked)Vehicle type, employer linkConsent
Display your testimonial/story on the platformStory content, name, role, video filesConsent
Display influencer profile on sponsors pageName, bio, picture, platforms, follower countsConsent + Legitimate interest
Process video testimonials for admin reviewVideo files, submission metadataConsent

4. Data Storage & Security

Your data is stored securely using industry-standard measures:

  • Encryption in transit: All data is transmitted over HTTPS (TLS 1.2+)
  • Secure authentication: We use OAuth 2.0 for login — we never store your password
  • Database security: Data is stored in encrypted databases with access controls
  • Minimal data collection: We only collect what is necessary to provide our services
  • No third-party advertising: We do not share your data with advertisers
  • Video storage: Video files are stored in secure cloud storage (S3) with encryption

5. Data Retention

We retain your personal data only for as long as necessary to provide our services:

Data TypeRetention Period
Account informationUntil you delete your account
Mood & health dataUntil you delete your account or request erasure
Forum postsUntil you delete your account (anonymised display names retained)
AI chat conversationsUntil you delete the conversation or your account
Analytics dataAggregated and anonymised — retained indefinitely
Push notification subscriptionsUntil you unsubscribe or delete your account
Testimonial submissions (pending approval)30 days (then deleted if not approved)
Approved testimonials & videosIndefinitely (or until you request deletion)
Influencer applications (pending review)90 days (then deleted if not approved)
Active influencer profilesWhile influencer account is active
Inactive influencer data30 days after deactivation (then deleted)

6. Your Rights Under UK GDPR

Under the UK GDPR, you have the following rights regarding your personal data:

Right of Access

Request a copy of all personal data we hold about you. Use the 'Download My Data' feature in your account settings.

Right to Erasure

Request deletion of your account and all associated data. Use the 'Delete My Account' feature in your account settings.

Right to Rectification

Request correction of inaccurate personal data. Contact us to update your information.

Right to Restrict Processing

Request that we limit how we use your data in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format (JSON). Available via 'Download My Data'.

Right to Object

Object to processing based on legitimate interest. Contact us to exercise this right.

To exercise any of these rights, email us at [email protected]. We will respond within 30 days as required by law.

7. Third-Party Services

We use a limited number of third-party services to operate DriverWell:

ServicePurposeData Shared
OAuth Provider (Google)User authenticationName, email (from your Google account)
AI Language ModelRoadMate AI chatChat messages (processed, not stored by provider)
Web Push ServicePush notificationsBrowser push endpoint (no personal data)

We do not use any advertising networks, social media trackers, or third-party analytics platforms that track individual users.

8. Children's Privacy

DriverWell is designed for professional drivers aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from a minor, we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of significant changes through the platform. The "last updated" date at the top of this page indicates when the policy was last revised.

10. Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the UK's data protection authority:

Information Commissioner's Office (ICO)

Website: ico.org.uk
Helpline: 0303 123 1113
We encourage you to contact us first at [email protected] so we can try to resolve your concern.

11. GDPR & ePrivacy Compliance

DriverWell is fully compliant with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (ePrivacy Regulations).

Cookie Consent Management

We implement a comprehensive cookie consent banner that allows you to:

  • Accept or reject non-essential cookies
  • Customize your cookie preferences by category
  • Withdraw or modify consent at any time
  • View detailed information about each cookie

Lawful Basis for Processing

All processing of personal data is based on one of the following lawful bases under Article 6 UK GDPR:

  • Consent: For health data, marketing communications, and analytics
  • Contract: To provide the DriverWell platform and services
  • Legitimate Interest: For platform improvement and security

Special Category Data (Health Data)

Health and wellbeing data is processed under Article 9(2)(a) UK GDPR (explicit consent). You have the right to withdraw this consent at any time, which will prevent us from processing your health data but will not affect the lawfulness of processing before withdrawal.

Data Retention

We retain personal data only for as long as necessary to provide services or as required by law. Health data is retained for 7 years to comply with NHS and occupational health guidelines. You can request deletion of your data at any time.

12. Contact Us

For any questions about this Privacy Policy or your personal data, please contact:

Peter McKenna
DriverWell — Data Controller
Email: [email protected]
Website: driverwell.co.uk