Privacy Policy
How DriverWell collects, uses, and protects your personal data
Last updated: 29 March 2026
1. Introduction
DriverWell ("we", "us", "our") is a mental health and wellbeing platform designed specifically for professional drivers. We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding your personal information.
Data Controller
DriverWell, operated by Peter McKenna
Website: driverwell.co.uk
Contact: [email protected]
2. Data We Collect
We collect the minimum amount of personal data necessary to provide our services. We do not sell your data to third parties.
Account Information
- Name (as provided by your login provider)
- Email address
- Login method (e.g. Google)
- Account creation date
Legal basis: Contract performance (Art. 6(1)(b) UK GDPR)
Health & Wellbeing Data
- Mood check-in entries (mood score, alertness, stress level, optional notes)
- Fatigue logs (driving/rest minutes)
- Blood glucose readings (if you use the diabetes tracker)
- Wellness logs (hydration, exercise, sleep, back pain scores)
- Meal plans
Legal basis: Explicit consent (Art. 9(2)(a) UK GDPR) — health data is a special category
Community & Communication Data
- Forum posts and replies (using your chosen display name, not your real name)
- AI chat conversations with RoadMate
- Push notification preferences
Legal basis: Legitimate interest (Art. 6(1)(f) UK GDPR)
Testimonial & Story Submissions
- Story content (text, video links, or uploaded videos)
- Your name, role/title, and company type
- Video files (MP4, WebM, MOV) uploaded to secure cloud storage
- YouTube and TikTok links (if you choose to share)
- Submission timestamp and approval status
Legal basis: Explicit consent (Art. 6(1)(a) UK GDPR)
Influencer Partnership Data
- Name and bio/description
- Profile picture (uploaded or from social media)
- Social media platforms (TikTok, YouTube, Instagram, Facebook)
- Platform profile URLs and follower counts
- Tier level (Bronze, Silver, Gold)
- Active/inactive status
Legal basis: Explicit consent (Art. 6(1)(a)) + Legitimate interest (Art. 6(1)(f)) for public profile display
Technical Data
- Anonymous page view analytics (page visited, timestamp, session ID)
- Browser type and device information (for responsive design)
- Push notification subscription endpoint (if you opt in)
Legal basis: Legitimate interest (Art. 6(1)(f) UK GDPR)
3. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide mood tracking and wellbeing features | Health & wellbeing data | Consent |
| Display your check-in streaks and achievements | Mood entry timestamps | Contract |
| Enable peer support forum | Display name, post content | Legitimate interest |
| Provide AI chat support (RoadMate) | Chat messages | Consent |
| Send check-in reminders (if opted in) | Push subscription | Consent |
| Improve the platform (anonymous analytics) | Page views, session data | Legitimate interest |
| Employer fleet management (if linked) | Vehicle type, employer link | Consent |
| Display your testimonial/story on the platform | Story content, name, role, video files | Consent |
| Display influencer profile on sponsors page | Name, bio, picture, platforms, follower counts | Consent + Legitimate interest |
| Process video testimonials for admin review | Video files, submission metadata | Consent |
4. Data Storage & Security
Your data is stored securely using industry-standard measures:
- Encryption in transit: All data is transmitted over HTTPS (TLS 1.2+)
- Secure authentication: We use OAuth 2.0 for login — we never store your password
- Database security: Data is stored in encrypted databases with access controls
- Minimal data collection: We only collect what is necessary to provide our services
- No third-party advertising: We do not share your data with advertisers
- Video storage: Video files are stored in secure cloud storage (S3) with encryption
5. Data Retention
We retain your personal data only for as long as necessary to provide our services:
| Data Type | Retention Period |
|---|---|
| Account information | Until you delete your account |
| Mood & health data | Until you delete your account or request erasure |
| Forum posts | Until you delete your account (anonymised display names retained) |
| AI chat conversations | Until you delete the conversation or your account |
| Analytics data | Aggregated and anonymised — retained indefinitely |
| Push notification subscriptions | Until you unsubscribe or delete your account |
| Testimonial submissions (pending approval) | 30 days (then deleted if not approved) |
| Approved testimonials & videos | Indefinitely (or until you request deletion) |
| Influencer applications (pending review) | 90 days (then deleted if not approved) |
| Active influencer profiles | While influencer account is active |
| Inactive influencer data | 30 days after deactivation (then deleted) |
6. Your Rights Under UK GDPR
Under the UK GDPR, you have the following rights regarding your personal data:
Right of Access
Request a copy of all personal data we hold about you. Use the 'Download My Data' feature in your account settings.
Right to Erasure
Request deletion of your account and all associated data. Use the 'Delete My Account' feature in your account settings.
Right to Rectification
Request correction of inaccurate personal data. Contact us to update your information.
Right to Restrict Processing
Request that we limit how we use your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format (JSON). Available via 'Download My Data'.
Right to Object
Object to processing based on legitimate interest. Contact us to exercise this right.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days as required by law.
7. Third-Party Services
We use a limited number of third-party services to operate DriverWell:
| Service | Purpose | Data Shared |
|---|---|---|
| OAuth Provider (Google) | User authentication | Name, email (from your Google account) |
| AI Language Model | RoadMate AI chat | Chat messages (processed, not stored by provider) |
| Web Push Service | Push notifications | Browser push endpoint (no personal data) |
We do not use any advertising networks, social media trackers, or third-party analytics platforms that track individual users.
8. Children's Privacy
DriverWell is designed for professional drivers aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from a minor, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes through the platform. The "last updated" date at the top of this page indicates when the policy was last revised.
10. Complaints
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the UK's data protection authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
We encourage you to contact us first at [email protected] so we can try to resolve your concern.
11. GDPR & ePrivacy Compliance
DriverWell is fully compliant with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (ePrivacy Regulations).
Cookie Consent Management
We implement a comprehensive cookie consent banner that allows you to:
- Accept or reject non-essential cookies
- Customize your cookie preferences by category
- Withdraw or modify consent at any time
- View detailed information about each cookie
Lawful Basis for Processing
All processing of personal data is based on one of the following lawful bases under Article 6 UK GDPR:
- Consent: For health data, marketing communications, and analytics
- Contract: To provide the DriverWell platform and services
- Legitimate Interest: For platform improvement and security
Special Category Data (Health Data)
Health and wellbeing data is processed under Article 9(2)(a) UK GDPR (explicit consent). You have the right to withdraw this consent at any time, which will prevent us from processing your health data but will not affect the lawfulness of processing before withdrawal.
Data Retention
We retain personal data only for as long as necessary to provide services or as required by law. Health data is retained for 7 years to comply with NHS and occupational health guidelines. You can request deletion of your data at any time.
12. Contact Us
For any questions about this Privacy Policy or your personal data, please contact:
Peter McKenna
DriverWell — Data Controller
Email: [email protected]
Website: driverwell.co.uk
