⬡ HAULION

Privacy Policy

Last updated: March 2026  ·  Effective immediately

Contents
  • 1. Who We Are
  • 2. Data We Collect
  • 3. How We Use Your Data
  • 4. Lawful Basis for Processing
  • 5. Data Retention
  • 6. Data Sharing & Third Parties
  • 7. Security
  • 8. Your Rights (GDPR)
  • 9. Cookies
  • 10. Children
  • 11. Changes to This Policy
  • 12. Contact & Complaints

1. Who We Are

Haulion ("we", "us", "our") is a fleet management software platform. We provide software-as-a-service (SaaS) to transport and logistics businesses ("Tenants") and their staff ("Users").

For the purposes of UK and EU data protection law, Haulion acts as a data processor on behalf of Tenant businesses (who are the data controllers for their drivers, customers, and staff data), and as a data controller for Tenant account and billing information.

Contact: privacy@haulion.com

2. Data We Collect

2.1 Account & Billing Data (Controller)

  • Company name, billing email, contact phone number
  • Subscription plan and payment status
  • Login email addresses and hashed passwords for platform administrators
  • IP addresses and login timestamps for security logging

2.2 Operational Data (Processor — on behalf of Tenants)

The following data is entered by Tenants and their staff and is processed on their behalf:

CategoryExamples
Driver recordsName, email, phone, address, licence number, date of birth, emergency contacts, medical notes
Customer recordsCompany name, contact person, email, phone, address
User accountsName, email address
Job dataCollection/delivery locations, dates, load details, pricing
Invoice dataInvoice amounts, VAT, payment status
Activity logsWho did what and when

2.3 Technical Data

  • Server access logs (IP address, browser, pages visited)
  • Session identifiers (stored as encrypted cookies)
  • Error logs (no personal data intentionally included)

3. How We Use Your Data

  • Providing the service: Processing jobs, generating invoices, managing drivers and vehicles
  • Account management: Billing, plan changes, support
  • Security: Fraud prevention, rate limiting, session management
  • Legal compliance: Maintaining audit trails, responding to lawful requests
  • Service improvement: Aggregated, anonymised usage analytics only

We do not sell your data. We do not use your data for advertising.

4. Lawful Basis for Processing

Processing activityLawful basis (UK GDPR Art. 6)
Providing the SaaS platformContract (Art. 6(1)(b))
Billing and subscription managementContract (Art. 6(1)(b))
Security logging and fraud preventionLegitimate interests (Art. 6(1)(f))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))
Processing driver/customer data for TenantsLegitimate interests of the Tenant (Art. 6(1)(f)) or consent
Consent recordsLegal obligation / Legitimate interests

5. Data Retention

Data is retained for as long as a Tenant's account is active, plus a reasonable period after account closure to comply with legal obligations.

  • Activity logs: Configurable per Tenant (default 90 days)
  • Completed job records: Archived after configurable period (default 12 months), retained for 7 years for financial audit purposes
  • Driver/customer PII: Retained until erasure is requested and approved
  • Account data after cancellation: Deleted within 90 days of account closure
  • Server access logs: 30 days

Tenants may request earlier erasure through the Data & Privacy section of Settings.

6. Data Sharing & Third Parties

We do not sell or rent personal data. We share data only where necessary:

  • Hosting provider: Server infrastructure — data remains within the UK/EEA
  • Email delivery: SMTP provider for transactional emails (verification, password reset)
  • Payment processor: If applicable, for subscription billing only — we do not store card details
  • Legal requirements: We may disclose data if required by law, court order, or regulatory authority

All third-party processors are bound by Data Processing Agreements (DPAs) ensuring GDPR-compliant handling.

7. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or damage. Our security measures include:

  • Encryption of personal data at rest and in transit
  • Secure, one-way hashing of passwords — they are never stored in plain text
  • Enforced HTTPS for all connections to the platform
  • Session management controls including automatic idle timeout
  • Rate limiting on authentication to prevent brute-force attacks
  • Access controls ensuring each organisation's data is strictly isolated
  • Regular review of our security practices

Despite these measures, no internet-based system can guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

Please notify us immediately at privacy@haulion.com if you believe your account or data has been compromised.

8. Your Rights Under UK GDPR

If you are based in the UK or EU, you have the following rights regarding your personal data:

RightDescriptionHow to exercise
Access (Art. 15)Obtain a copy of your personal dataSubmit an export request in Settings → Privacy & GDPR
Rectification (Art. 16)Correct inaccurate dataEdit your profile or contact your workspace admin
Erasure (Art. 17)Request deletion of your dataSubmit an erasure request in Settings → Privacy & GDPR
Portability (Art. 20)Receive your data in a structured formatUse the data export function
Restriction (Art. 18)Restrict processing in certain circumstancesContact us at privacy@haulion.com
Objection (Art. 21)Object to processing based on legitimate interestsContact us at privacy@haulion.com

We will respond to all requests within 30 days. If we cannot fulfil a request, we will explain why.

Right to complain: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time.

9. Cookies

We use only strictly necessary cookies — no analytics or advertising cookies.

CookiePurposeDuration
Session cookie (PHPSESSID)Maintains your authenticated sessionBrowser session / 2 hours idle
CSRF tokenProtects against cross-site request forgerySession

You can disable cookies in your browser settings, but the platform will not function without session cookies.

10. Children

Haulion is a business-to-business service. We do not knowingly collect data from anyone under 18. If you believe a child's data has been entered into the system, please contact us immediately.

11. Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. We will notify Tenant administrators by email of any material changes and update the "Last updated" date above. Continued use of the platform after changes constitutes acceptance of the updated policy.

12. Contact & Complaints

For any privacy questions or to exercise your rights:

  • Email: privacy@haulion.com
  • ICO (UK supervisory authority): ico.org.uk/make-a-complaint

Terms & Conditions  ·  Sign In

© 2026 Haulion. All rights reserved.