1. Controller and scope
DIGIDENT LTD, company 17055539, is the controller for account administration, service security, billing records, support, optional marketing and the creation and operation of FleetStart Radar's public-source signal products. Contact us at digidentAI@proton.me or at our registered office below. DIGIDENT LTD is registered with the Information Commissioner's Office under reference ZC210644.
This notice covers website visitors, account users, prospective and current business customers, marketing subscribers, support contacts and people whose professional or business-related information appears in the official public sources we monitor. Customers are separate controllers for their own prospecting decisions, exports and private workspace content. For private Customer content, DIGIDENT may act as processor under our data processing terms.
2. Personal data we process
- Account data: name, work email, company, role or buyer type, territory, password hash, verification status and relevance preferences such as preferred operator size, licence classes, trigger focus, sectors, exclusions, high-level offer summary and commercial objective.
- Security and technical data: session identifiers, IP-derived security records, login attempts, timestamps, request and error logs, device/browser information supplied in requests and audit events.
- Billing data: chosen plan, billing interval, GoCardless customer, mandate, subscription and payment references, payment state, paid-through date and cancellation history. We do not store full bank-account details.
- Service content: saved notes, pipeline status, owners, next actions, follow-up dates, dismissal reasons, customer-entered opportunity or outcome values, public contact details entered by users, job locations, filters, exports and support correspondence.
- Local AI opportunity-guidance data: allow-listed public signal fields and high-level account preferences consisting of supplier role, offer summary, territory, sectors, licence classes, trigger focus and commercial objective. Private notes, named contacts, emails, phone numbers, customer communications, job locations, client data and Research Partner exports are excluded from prompts. Fixed Useful, Not relevant or Needs correction ratings may be stored against the generated brief; no feedback comment is required or collected through that control.
- Research Partner data, only after separate opt-in: defined events for opening provided evidence links, changing a signal pipeline status, selecting a fixed opportunity-stage reason, recording a fixed activity type and exporting opportunities, saved leads or CQC directory results; the event time; associated public signal fields; consent and withdrawal history; and the resulting subscription-credit record. Searches, private notes, activity-note text, contacts, emails, phone numbers, private job locations, client data, free text and activity outside FleetStart are excluded. Event records remain account-linked until withdrawal so the credit and deletion rights can be administered, and are treated as pseudonymous personal data during that period.
- Marketing data: consent record, source, preferences, confirmation and unsubscribe status, and email delivery history.
- Public-source data: organisation and trading names, licence or registration identifiers, business or operating addresses, publication events, professional names or roles and other information made available by official registers or public websites.
3. Sources
We receive data directly from users and Customers; from service providers such as Cloudflare, GoCardless and Resend; and from public sources including Traffic Commissioner publications, CQC data, DfT Street Manager open data, Companies House and publicly accessible organisation websites. Customers may add their own research and notes.
4. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Create accounts, authenticate users, provide the portal, exports, preferences, support and requested communications. | Contract, or steps requested before contract. |
| Administer subscriptions, payment state, cancellations, accounting and tax records. | Contract and legal obligation. |
| Protect accounts, prevent abuse, investigate incidents, maintain audit records and improve reliability. | Legitimate interests in operating a secure and reliable B2B service; legal obligation where applicable. |
| Collect and structure official public-source information into business opportunity and source-health tools. | Legitimate interests in providing timely B2B market and operational intelligence, balanced against the limited impact of using information already made public for professional or regulatory purposes. |
| Generate optional tailored opportunity guidance on OpenAI-hosted Luna through the protected DIGIDENT API account infrastructure, validate it in the hosted service and measure fixed quality ratings. This is inference for the service, not training or a decision with legal or similarly significant effect. | Contract and legitimate interests in providing and improving an evidence-bound B2B decision-support feature. Customers can disable local AI guidance and retain deterministic functionality. |
| Send account, security, payment, cancellation, support and service-status messages. | Contract, legal obligation and legitimate interests. These are not optional marketing. |
| Send Fleet Growth Pulse or occasional product marketing. | Consent where requested. Consent can be withdrawn at any time. |
| Operate the optional Research Partner programme, apply its subscription credit and use allow-listed automatic workflow events with public signal features to evaluate and improve signal classification. | Consent for research-data use; contract for the requested price change and billing administration. Participation is optional and consent can be withdrawn at any time. |
| Establish, exercise or defend legal claims and comply with regulators or lawful requests. | Legal obligation and legitimate interests. |
5. Public-source professional data
Some official records concern sole traders, named licence holders, registered managers, directors or other identifiable professionals. We minimise the fields presented, keep source links and dates, avoid special-category data, do not use the service to make decisions with legal or similarly significant effects, and require Customers to verify records and comply with marketing law.
This published notice is intended to make that processing transparent. Providing individual notice to every person in large, changing official datasets may involve disproportionate effort. We keep that assessment under review and apply safeguards including restricted customer access, purpose limitation, correction routes and objection handling. You may object to this use or ask us to correct a record by emailing digidentAI@proton.me with enough detail to identify it.
6. Sharing
We share data only as needed with Cloudflare for hosting and security; Resend for email; GoCardless for payment administration; OpenAI for optional hosted opportunity inference; authorised Customer users; advisers, insurers and authorities where necessary; and a genuine business successor subject to safeguards. Optional inference may run through OpenAI-hosted Luna through the protected DIGIDENT API account or the OpenAI API. AI prompts are allow-listed and exclude private notes, customer communications, email addresses, phone numbers and officer names. GoCardless separately controls the payer and bank information it collects. We do not sell account-user personal data or provide live records for unrestricted public download.
7. International transfers
Some suppliers may process data outside the UK. Where UK data-protection law requires safeguards, we use an adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, plus proportionate technical and contractual measures. Contact us for information about the safeguard relevant to a particular supplier.
8. Retention
- Account and contract records: while active and generally up to six years afterwards for contract, tax and legal claims.
- Provider payment and cancellation records: generally six years after the relevant accounting period or contract ends.
- Security, session, rate-limit and operational logs: the shortest useful period, normally no more than 12 months unless needed for an incident or claim.
- Private workspace content: during active service and a limited recovery/export period after closure, then deleted or anonymised unless retention is legally required.
- Marketing records: until consent is withdrawn or the address is inactive, with a minimal suppression record retained to honour an unsubscribe.
- Public-source signals and baselines: while needed to identify and evidence relevant changes, with stale or corrected records refreshed, restricted or removed where appropriate.
- Research Partner events: while the organisation remains enrolled. On withdrawal, future collection stops and all research events still linked to the account are deleted immediately. A minimal consent, withdrawal and price-change record may be kept for up to six years to evidence the contract and honour the withdrawal. Information already irreversibly anonymised before withdrawal can no longer be linked back to an account.
9. Security
We use access controls, password hashing, secure session cookies, rate limiting, signed provider webhooks, least-privilege secrets, encrypted transport, audit records, monitoring and managed infrastructure controls. No online service is risk-free. We assess and notify personal-data breaches as required by law.
10. Your rights
Depending on the circumstances, you may have rights of access, correction, erasure, restriction, portability and objection. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing.
Your right to object: you may object to processing based on legitimate interests, including public-source professional data. You have an absolute right to object to direct marketing. Email digidentAI@proton.me; marketing emails also include an unsubscribe route.
We may need to verify identity and clarify a request. Rights can be limited where exemptions or another person's rights apply. You may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, telephone 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
11. Automated processing
Signals may be automatically classified, scored and deduplicated to prioritise commercial relevance. When a Customer opens an evidence review, FleetStart may retrieve current company facts from Companies House and generic enquiry routes from an already verified or customer-confirmed organisation website. Website checks are tightly limited to public homepage, about and contact material; we do not guess email patterns, collect personal mobile numbers, scrape social networks or use data-broker contact profiles. Luna may organise supplied company facts and the Customer's high-level operating brief, but contact details and officer names are excluded from its prompt. This does not produce legal or similarly significant effects about an individual. Customers verify the evidence and decide independently whether to contact an organisation.
12. Cookies and storage
The service currently uses only storage strictly necessary for requested functions such as authentication, session security and abuse prevention. We do not currently use advertising or behavioural-tracking cookies. See the cookie notice. Non-essential technology will not be activated before the required information and consent mechanism are provided.
13. Changes and contact
We review this notice when products, suppliers, sources or law change. Material changes will be highlighted where appropriate. The version and effective date appear above.
DIGIDENT LTDCompany number 17055539
Registered in England and Wales
Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
ICO registration: ZC210644
Email: digidentAI@proton.me