Legal and privacy

Privacy Policy

How VERIGO and CMD Group of Services collect, use, store and protect personal information.

Last updated: 28 July 2026United Kingdom
Important information

Your employer or fleet operator may provide additional privacy information describing how it uses VERIGO and manages employee, driver and operational records.

Section 01

Introduction

This Privacy Policy explains how CMD Group of Services, operating the VERIGO fleet management and compliance platform, collects, uses, stores and protects personal information.

This policy applies when you use the VERIGO website, driver application, administrative portal, contact forms, support services and related fleet-management functionality.

It applies to drivers, transport managers, administrators, employees, contractors, customer representatives, website visitors and other authorised platform users.

Section 02

Who is responsible for your information?

The organisation responsible for deciding how and why personal information is processed is:

CMD Group of Services
135 Warwick Road
Solihull
B92 7HN
United Kingdom

In some circumstances, the organisation that employs you or provides your access to VERIGO may be the data controller, while CMD Group of Services acts as a data processor providing software and related services on that organisation's instructions.

The exact roles may depend on the customer agreement and the particular information being processed.

Section 03

Information we may collect

The information processed through VERIGO depends on the features used by your organisation and your role.

Account and identity information

  • Full name, username, internal user ID and account role.
  • Business email address, telephone number and contact information.
  • Employer, organisation, depot, department or tenant information.
  • Authentication information and account-security records.
  • Profile settings, permissions, signatures and acknowledgements.

Driver and licence information

  • Driving licence number and licence-check information.
  • Licence status, categories, restrictions, endorsements and expiry dates.
  • Driver qualification, CPC, medical, training and compliance information.
  • Consent records, including the date, time and method of consent.
  • Employment-related fleet information supplied by an authorised customer.

Vehicle and operational information

  • Vehicle, trailer and asset identifiers.
  • Registration numbers, mileage, odometer readings and fuel records.
  • Vehicle assignments and driver-to-asset relationships.
  • Inspection, walkaround-check and maintenance records.
  • Defect reports, repair details, parts, labour and workshop information.
  • Breakdown, recovery and vehicle-status information.

Incident and accident information

  • Incident, collision, accident and near-miss details.
  • Date, time, location, vehicle and journey information.
  • Photographs, videos, documents, diagrams and supporting evidence.
  • Witness, third-party and insurance-related details.
  • Descriptions of damage, injury or surrounding circumstances.

Incident records may sometimes contain sensitive information, including health or injury information. Such information should only be submitted where necessary and authorised.

Device and technical information

  • IP address, browser type, operating system and device type.
  • Application version, device identifiers and technical configuration.
  • Login records, timestamps and security-event information.
  • Error reports, diagnostic data and performance information.
  • Approximate or precise location where an enabled feature requires it and the user or organisation has authorised its use.

Communications

  • Contact-form enquiries and application requests.
  • Customer-support conversations.
  • Emails, telephone records and implementation communications.
  • Feedback, complaints and information-rights requests.
Section 04

How information is collected

We may receive personal information:

  • Directly from you when you create or use an account.
  • When you complete an inspection, report, form or acknowledgement.
  • From the organisation that employs you or provides your platform access.
  • From an authorised transport manager, administrator or workshop user.
  • From vehicle, licence or compliance services where lawful access has been configured.
  • Automatically from your device when you use the website or application.
  • From third parties involved in an incident, claim, repair or compliance process.
Section 05

How and why we use information

Personal information may be processed to:

  • Create, authenticate and manage user accounts.
  • Provide role-based access to the VERIGO platform.
  • Maintain fleet, trailer, driver and compliance records.
  • Manage inspections, defects, incidents, accidents, maintenance and repairs.
  • Send operational, safety, compliance or account notifications.
  • Provide reports, audit evidence and management information.
  • Respond to enquiries and provide technical or customer support.
  • Protect accounts, investigate misuse and maintain platform security.
  • Diagnose technical problems and improve performance and usability.
  • Comply with legal, regulatory, insurance and contractual requirements.
  • Establish, exercise or defend legal claims.
  • Develop and improve VERIGO services using appropriately protected information.

VERIGO may provide AI-assisted summaries or recommendations. These features are intended to support authorised users. They should not replace the judgement of a qualified transport manager, safety professional, legal adviser or other accountable decision-maker.

Section 06

Lawful bases for processing

Depending on the circumstances, information may be processed under one or more of the following lawful bases:

Contract

Processing necessary to provide VERIGO services, administer an account or perform a customer agreement.

Legal obligation

Processing needed to meet legal, regulatory, employment, safety, record-keeping or compliance obligations.

Legitimate interests

Processing necessary for platform security, service administration, fraud prevention, business operations and service improvement where those interests are not overridden by individual rights.

Consent

Processing based on clear consent where consent is the appropriate lawful basis, including certain optional device permissions or communications.

Where special-category information is processed, an additional legal condition will also be required. This may include employment and social-protection obligations, substantial public interest, legal claims, vital interests or explicit consent, depending on the situation.

Section 07

Who information may be shared with

Information is not sold as part of the normal operation of VERIGO.

Where necessary and lawful, information may be shared with:

  • The organisation that provides or manages your VERIGO account.
  • Authorised administrators, transport managers, compliance staff and workshop personnel.
  • Hosting, infrastructure, email, storage, security and technical-support providers.
  • Professional advisers, insurers, claims handlers, auditors and legal representatives.
  • Vehicle, licence, maintenance or regulatory-data providers configured by an authorised customer.
  • Police, courts, regulators, enforcement agencies or public authorities where required or permitted by law.
  • A buyer, investor or successor organisation involved in a legitimate corporate transaction, subject to appropriate safeguards.

Service providers acting on our behalf are expected to use information only for authorised purposes and to apply suitable confidentiality and security protections.

Section 08

International transfers

Some technology providers may process or store information outside the United Kingdom.

Where a restricted international transfer takes place, appropriate safeguards will be used where required. These may include adequacy regulations, approved contractual protections, the UK International Data Transfer Agreement or another lawful transfer mechanism.

Section 09

How long information is retained

Information is retained only for as long as reasonably necessary for the purpose for which it was collected, subject to customer instructions and legal, regulatory, contractual, insurance and dispute-resolution requirements.

Retention periods may depend on:

  • The type of record and the reason it was created.
  • The duration of the customer relationship.
  • Fleet, maintenance, employment and compliance record-keeping requirements.
  • Insurance, incident, accident and legal-claim limitation periods.
  • Security, fraud-prevention and audit requirements.
  • A valid deletion, restriction or objection request.

When information is no longer required, it will be deleted, anonymised or securely disposed of where reasonably practicable.

Section 10

Security

Appropriate technical and organisational measures are used to protect personal information against unauthorised access, accidental loss, destruction, alteration or disclosure.

Measures may include:

  • Role-based access and account permissions.
  • Authentication controls and password protection.
  • Encryption during network transmission.
  • Logging, monitoring and security-event investigation.
  • Access limitations for staff and service providers.
  • Backups, recovery procedures and infrastructure protections.
  • Periodic review of software dependencies and security controls.

No online system can guarantee absolute security. Users must keep their login details confidential, use secure devices and notify their administrator or VERIGO support of suspected unauthorised access.

Section 11

Application permissions

The VERIGO Driver application may request device permissions where required for a feature.

Camera
Scanning asset QR codes and capturing photographs for inspections, defects, incidents, accidents or supporting evidence.
Location
Recording an authorised location for incidents, accidents, breakdowns, weather-related features or relevant operational events.
Files and media
Selecting, uploading, downloading or storing documents and supporting evidence.
Notifications
Delivering account, compliance, assignment, safety and operational notifications.

Permissions can normally be managed through your device settings. Disabling a required permission may prevent the associated feature from working correctly.

Section 12

Cookies and local device storage

The website and application may use cookies, session storage, local storage or similar technologies for essential functions such as:

  • Keeping users signed in.
  • Maintaining account security.
  • Remembering role or interface preferences.
  • Preserving required application state.
  • Detecting errors and protecting the service.

Where non-essential analytics, advertising or tracking technologies are introduced, appropriate information and consent controls should be provided before those technologies are used.

Section 13

Your data-protection rights

Subject to applicable law and exemptions, individuals may have the right to:

  • Ask whether their personal information is being processed.
  • Request access to their personal information.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of information in certain circumstances.
  • Request restriction of processing.
  • Object to certain processing based on legitimate interests.
  • Receive certain information in a portable format.
  • Withdraw consent where processing relies on consent.
  • Raise concerns about automated decision-making where applicable.
  • Complain to the Information Commissioner's Office.

To exercise a right, contact support@cmdgroupofservices.com. We may need to verify your identity and clarify the scope of the request.

Where CMD Group of Services processes information on behalf of your employer or another customer organisation, the request may need to be referred to that organisation as the relevant controller.

Section 14

Children

VERIGO is a business fleet-management platform and is not intended for general use by children.

Customer organisations must ensure that accounts are created only for appropriately authorised users and in accordance with applicable employment and data-protection requirements.

Section 15

Questions and complaints

Privacy questions, requests or complaints can be sent to:

You also have the right to complain to the UK Information Commissioner's Office. We encourage you to contact us first so that we have an opportunity to address your concern.

Visit the ICO website
Section 16

Changes to this policy

This Privacy Policy may be updated to reflect changes to VERIGO, our providers, legal requirements or processing activities.

The latest version will be published on this page with an updated revision date. Material changes may also be communicated through the platform or by another appropriate method.

Privacy contact

Questions about this policy can be sent to support@cmdgroupofservices.com.