Privacy Policy
256 Logistics Compliance Hub handles legally-sensitive personal data — passports, Right-to-Work, visas, salaries. Here is exactly how we collect it, why, how long we keep it, and the rights you hold over it.
Who we are
256 Logistics Ltd (“we”, “us”, “our”) is the data controller for personal data processed through this platform. Registered in England & Wales. For any privacy matter, contact director@256logisticsltd.com.
What data we collect
- Employee records — name, date of birth, home address, phone, email, National Insurance number, passport/visa details, salary, contracted hours, job title and department.
- Compliance documents — Right-to-Work, driving licences, tachograph cards, training certificates, and vehicle documents (MOT, insurance, VOR).
- Operational records — daily walk-around checks, defect reports, driver check-ins and PMI schedules.
- System access logs — login timestamps and an audit trail of every data change.
Lawful basis for processing
- Legal obligation (Art. 6(1)(c)) — Operator’s Licence conditions, DVSA requirements, and Right-to-Work duties under the Immigration Act.
- Legitimate interests (Art. 6(1)(f)) — fleet safety records, tachograph compliance and audit readiness.
- Contract (Art. 6(1)(b)) — employment and contractor agreements.
Data retention
We keep each category only as long as the law or sound operation requires, then dispose of it securely.
| Category | Retention | Basis |
|---|---|---|
| Employment records | Employment + 6 yrs | HMRC / employment law |
| Right-to-Work documents | Employment + 2 yrs | Immigration Act 2014 |
| Tachograph / daily checks | 1 year | DVSA operator compliance |
| Defect reports | 15 months | DVSA Maintaining Roadworthiness |
| Audit logs | 3 years | Legitimate interests |
| Database backups | 30 days | Operational continuity |
Your rights
Under UK GDPR you can exercise any of the following — we respond within 30 days.
Request a copy of the data we hold about you.
Ask us to correct inaccurate data.
Request deletion where no legal duty to retain applies.
Pause processing during a dispute, or object to legitimate-interest use.
How we keep it safe
- All data travels over HTTPS (TLS 1.2+); passwords are hashed with bcrypt.
- Documents are stored privately and served only to authenticated, authorised users — never publicly.
- Daily encrypted backups with 30-day retention.
- Role-based access — staff see only what their role allows. CSRF protection and a strict Content-Security-Policy guard every request.
Third parties & complaints
We never sell personal data. Hosting is provided by Hostinger (their policy); configured email alerts are sent via the chosen SMTP provider.
You may complain to the Information Commissioner’s Office at any time: ico.org.uk/make-a-complaint.
Exercise a data right
Email us and we’ll action your request within 30 days.
The soul architects behind 256 Logistics — we design, engineer, and run software built to be trusted with the data that matters.