Data Protection & GDPR Compliance Policy
British Auto Records • Operated by zevseraLTD
Last Updated: June 2026 • Compliant with UK Data Protection Act 2018
🔒 Certified Privacy & Data Security Standards
British Auto Records operates in rigorous compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and Information Commissioner’s Office (ICO) guidelines. We ensure lawful, fair, and transparent handling of all vehicle identifiers and customer personal data.
01 Commitment to UK GDPR Standards
zevseraLTD (trading as British Auto Records) is committed to protecting the privacy, integrity, and confidentiality of all personal data collected through britishautorecords.co.uk.
Our data governance procedures ensure adherence to modern international standards, including the UK GDPR, EU GDPR (where applicable to European visitors), and the Privacy and Electronic Communications Regulations (PECR).
02 The Seven Core UK GDPR Principles
We strictly govern all data engineering, retrieval, and storage workflows against the 7 fundamental principles of Article 5 of the UK GDPR:
- Lawfulness, Fairness & Transparency: Personal data is processed solely under valid legal grounds with complete customer clarity.
- Purpose Limitation: Collected data is utilized strictly for generating vehicle audit reports and fulfilling legal accounting duties.
- Data Minimisation: We only collect what is strictly necessary. We do not solicit unnecessary personal disclosures.
- Accuracy: Customer details are validated upon entry, and vehicle history is updated via real-time official registries.
- Storage Limitation: Customer report download archives are maintained for 90 days before secure anonymization.
- Integrity & Confidentiality: Modern cryptographic standards protect data at rest and in transit against unauthorized tampering or loss.
- Accountability: Complete audit trails and security protocols are maintained by our designated compliance officers.
03 Treatment of Vehicle Registration Marks (VRM)
Under ICO guidance, a Vehicle Registration Mark (VRM) can, in specific circumstances, be linked with an individual by authorized statutory bodies (such as the police or DVLA). British Auto Records treats all UK VRMs and VIN numbers with the same rigorous security protocols as personal data:
- Vehicle searches are encrypted with TLS 1.3 in transit.
- Our reports explicitly exclude personal names, phone numbers, and physical residential addresses of prior keepers to safeguard owner privacy.
- Reports only disclose vehicle-centric records: mechanical safety, MOT test histories, write-off markers, mileage logs, and outstanding finance flags.
04 Technical & Cybersecurity Protections
Our technological safeguards include:
- 256-Bit SSL/TLS Transport Encryption: End-to-end security between client browsers, application servers, and upstream registries.
- PCI-DSS Level 1 Gateway Integration: Payment card numbers are processed directly by Stripe’s tokenized, vaulted infrastructure and never touch our servers.
- Database Encryption at Rest: AES-256 encrypted database volumes hosted in Tier-3 UK/EU cloud data facilities.
- Automated Vulnerability Monitoring: Routine automated penetration testing, DDoS filtering, and web application firewall (WAF) inspections.
05 Exercising Your GDPR Rights
You have full autonomy over your data. To exercise any of your rights:
- Subject Access Request (SAR): Request an export of all data associated with your email address or order number.
- Right to Erasure (De-indexing / Forget Me): Request complete purging of your contact records from our active databases.
- Right to Rectification: Request immediate update of incorrect contact records.
- Right to Restrict or Object: Submit an objection to non-essential processing.
Submit your request to support@britishautorecords.co.uk with the subject line GDPR Rights Request. In compliance with UK GDPR Article 12, all requests are fulfilled within one calendar month free of charge.
06 Data Breach Protocols & ICO Reporting
In the highly unlikely event of a security incident resulting in a personal data breach, British Auto Records maintains an immediate response procedure. In compliance with Articles 33 and 34 of the UK GDPR, we will notify the UK Information Commissioner’s Office (ICO) within 72 hours and notify affected data subjects without undue delay where there is a high risk to individual rights and freedoms.
Data Protection Office & Contact Details
Contact our compliance desk for data protection inquiries or Subject Access Requests: