Your employer or fleet operator may provide additional privacy information describing how it uses VERIGO and manages employee, driver and operational records.
Introduction
This Privacy Policy explains how CMD Group of Services, operating the VERIGO fleet management and compliance platform, collects, uses, stores and protects personal information.
This policy applies when you use the VERIGO website, driver application, administrative portal, contact forms, support services and related fleet-management functionality.
It applies to drivers, transport managers, administrators, employees, contractors, customer representatives, website visitors and other authorised platform users.
Who is responsible for your information?
The organisation responsible for deciding how and why personal information is processed is:
In some circumstances, the organisation that employs you or provides your access to VERIGO may be the data controller, while CMD Group of Services acts as a data processor providing software and related services on that organisation's instructions.
The exact roles may depend on the customer agreement and the particular information being processed.
Information we may collect
The information processed through VERIGO depends on the features used by your organisation and your role.
Account and identity information
- Full name, username, internal user ID and account role.
- Business email address, telephone number and contact information.
- Employer, organisation, depot, department or tenant information.
- Authentication information and account-security records.
- Profile settings, permissions, signatures and acknowledgements.
Driver and licence information
- Driving licence number and licence-check information.
- Licence status, categories, restrictions, endorsements and expiry dates.
- Driver qualification, CPC, medical, training and compliance information.
- Consent records, including the date, time and method of consent.
- Employment-related fleet information supplied by an authorised customer.
Vehicle and operational information
- Vehicle, trailer and asset identifiers.
- Registration numbers, mileage, odometer readings and fuel records.
- Vehicle assignments and driver-to-asset relationships.
- Inspection, walkaround-check and maintenance records.
- Defect reports, repair details, parts, labour and workshop information.
- Breakdown, recovery and vehicle-status information.
Incident and accident information
- Incident, collision, accident and near-miss details.
- Date, time, location, vehicle and journey information.
- Photographs, videos, documents, diagrams and supporting evidence.
- Witness, third-party and insurance-related details.
- Descriptions of damage, injury or surrounding circumstances.
Incident records may sometimes contain sensitive information, including health or injury information. Such information should only be submitted where necessary and authorised.
Device and technical information
- IP address, browser type, operating system and device type.
- Application version, device identifiers and technical configuration.
- Login records, timestamps and security-event information.
- Error reports, diagnostic data and performance information.
- Approximate or precise location where an enabled feature requires it and the user or organisation has authorised its use.
Communications
- Contact-form enquiries and application requests.
- Customer-support conversations.
- Emails, telephone records and implementation communications.
- Feedback, complaints and information-rights requests.
How information is collected
We may receive personal information:
- Directly from you when you create or use an account.
- When you complete an inspection, report, form or acknowledgement.
- From the organisation that employs you or provides your platform access.
- From an authorised transport manager, administrator or workshop user.
- From vehicle, licence or compliance services where lawful access has been configured.
- Automatically from your device when you use the website or application.
- From third parties involved in an incident, claim, repair or compliance process.
How and why we use information
Personal information may be processed to:
- Create, authenticate and manage user accounts.
- Provide role-based access to the VERIGO platform.
- Maintain fleet, trailer, driver and compliance records.
- Manage inspections, defects, incidents, accidents, maintenance and repairs.
- Send operational, safety, compliance or account notifications.
- Provide reports, audit evidence and management information.
- Respond to enquiries and provide technical or customer support.
- Protect accounts, investigate misuse and maintain platform security.
- Diagnose technical problems and improve performance and usability.
- Comply with legal, regulatory, insurance and contractual requirements.
- Establish, exercise or defend legal claims.
- Develop and improve VERIGO services using appropriately protected information.
VERIGO may provide AI-assisted summaries or recommendations. These features are intended to support authorised users. They should not replace the judgement of a qualified transport manager, safety professional, legal adviser or other accountable decision-maker.
Lawful bases for processing
Depending on the circumstances, information may be processed under one or more of the following lawful bases:
Processing necessary to provide VERIGO services, administer an account or perform a customer agreement.
Processing needed to meet legal, regulatory, employment, safety, record-keeping or compliance obligations.
Processing necessary for platform security, service administration, fraud prevention, business operations and service improvement where those interests are not overridden by individual rights.
Processing based on clear consent where consent is the appropriate lawful basis, including certain optional device permissions or communications.
Where special-category information is processed, an additional legal condition will also be required. This may include employment and social-protection obligations, substantial public interest, legal claims, vital interests or explicit consent, depending on the situation.
International transfers
Some technology providers may process or store information outside the United Kingdom.
Where a restricted international transfer takes place, appropriate safeguards will be used where required. These may include adequacy regulations, approved contractual protections, the UK International Data Transfer Agreement or another lawful transfer mechanism.
How long information is retained
Information is retained only for as long as reasonably necessary for the purpose for which it was collected, subject to customer instructions and legal, regulatory, contractual, insurance and dispute-resolution requirements.
Retention periods may depend on:
- The type of record and the reason it was created.
- The duration of the customer relationship.
- Fleet, maintenance, employment and compliance record-keeping requirements.
- Insurance, incident, accident and legal-claim limitation periods.
- Security, fraud-prevention and audit requirements.
- A valid deletion, restriction or objection request.
When information is no longer required, it will be deleted, anonymised or securely disposed of where reasonably practicable.
Security
Appropriate technical and organisational measures are used to protect personal information against unauthorised access, accidental loss, destruction, alteration or disclosure.
Measures may include:
- Role-based access and account permissions.
- Authentication controls and password protection.
- Encryption during network transmission.
- Logging, monitoring and security-event investigation.
- Access limitations for staff and service providers.
- Backups, recovery procedures and infrastructure protections.
- Periodic review of software dependencies and security controls.
No online system can guarantee absolute security. Users must keep their login details confidential, use secure devices and notify their administrator or VERIGO support of suspected unauthorised access.
Application permissions
The VERIGO Driver application may request device permissions where required for a feature.
Permissions can normally be managed through your device settings. Disabling a required permission may prevent the associated feature from working correctly.
Your data-protection rights
Subject to applicable law and exemptions, individuals may have the right to:
- Ask whether their personal information is being processed.
- Request access to their personal information.
- Request correction of inaccurate or incomplete information.
- Request deletion of information in certain circumstances.
- Request restriction of processing.
- Object to certain processing based on legitimate interests.
- Receive certain information in a portable format.
- Withdraw consent where processing relies on consent.
- Raise concerns about automated decision-making where applicable.
- Complain to the Information Commissioner's Office.
To exercise a right, contact support@cmdgroupofservices.com. We may need to verify your identity and clarify the scope of the request.
Where CMD Group of Services processes information on behalf of your employer or another customer organisation, the request may need to be referred to that organisation as the relevant controller.
Children
VERIGO is a business fleet-management platform and is not intended for general use by children.
Customer organisations must ensure that accounts are created only for appropriately authorised users and in accordance with applicable employment and data-protection requirements.
Questions and complaints
Privacy questions, requests or complaints can be sent to:
You also have the right to complain to the UK Information Commissioner's Office. We encourage you to contact us first so that we have an opportunity to address your concern.
Visit the ICO websiteChanges to this policy
This Privacy Policy may be updated to reflect changes to VERIGO, our providers, legal requirements or processing activities.
The latest version will be published on this page with an updated revision date. Material changes may also be communicated through the platform or by another appropriate method.
Questions about this policy can be sent to support@cmdgroupofservices.com.
