Privacy Policy

Privacy Notice

Who We Are

This privacy notice is issued by Haloniq Ltd (“Haloniq”, “we”, “us” or “our”), the provider of the Haloniq fleet management and telematics software-as-a-service platform (the “Platform”).

Haloniq is a private limited company incorporated in England and Wales with company number 16506914 and registered office at Unit 2, Brigade House Station Road, South Darenth, Dartford, Kent, United Kingdom, DA4 9BD.

Haloniq is the controller of personal data described in this notice. Where Haloniq processes personal data on behalf of its customers as a processor (for example, personal data our customers upload to or generate through the Platform, such as driver, vehicle, telematics, and media data), that processing is governed by our contract with the relevant customer and the customer’s own privacy notice, not this document. If you are a driver, vehicle user, or other individual whose data has been uploaded to the Platform by your employer or another organisation using Haloniq, please refer to that organisation’s privacy notice, as they are the controller responsible for that data.

Marketing activities relating to Haloniq’s products and services, and the Haloniq website, are owned and operated by Brigade Electronics Group plc, a sister company of Haloniq, which acts as an independent data controller for these activities — that is, Brigade Electronics Group plc decides its own purposes and means of processing for marketing and website-related personal data, and is not acting on Haloniq’s instructions in relation to that processing. This notice does not cover, and is not intended to describe, processing carried out by Brigade Electronics Group plc in that capacity. For information about how Brigade Electronics Group plc processes your personal data for marketing or website purposes, please see their privacy policy Privacy Policy – Brigade Electronics.

Data Protection Officer

Given the nature and scale of our processing activities, we have appointed a Data Protection Officer (DPO) in accordance with Article 37 of the UK GDPR and the EU GDPR.

Our DPO is responsible for informing and advising us on our data protection obligations, monitoring our compliance with this notice and applicable data protection law, providing advice on data protection impact assessments, cooperating with supervisory authorities, and acting as a point of contact for the Information Commissioner’s Office (ICO), relevant EU supervisory authorities, and individuals whose data we process.
Our Data Protection Officer performs their tasks independently and reports directly to senior managements and does not receive instructions regarding the exercise with those tasks, in accordance with Article 38 of the UK GDPR and the EU GDPR.

You can contact our Data Protection Officer directly with any question about this notice, our use of your personal data, or to exercise any of your rights as follows:

DPO
Haloniq Ltd
Brigade House, The Mills, South Darenth, Kent, DA4 9BD
+1 (260) 766-4343
privacy@haloniq.com

Scope of This Notice

This notice explains how Haloniq collects, uses, shares, and protects personal data when we act as a controller — that is, when we decide the purposes and means of processing. This includes personal data relating to:

    • Our authorised reseller contacts and business partners and their representatives;
    • Our end customers’ business contacts and administrators, in relation to account management, support, billing, and platform configuration;
    • Prospective customers who contact Haloniq directly in relation to onboarding or platform demonstrations (general marketing activity, including the Haloniq website, is operated separately by Brigade Electronics Group plc as an independent controller — see Section 1);
    • Visitors to and users of our mobile application, in relation to app operation and security;
    • Our own employees, contractors, and administrators, in relation to system access; and
    • Suppliers and professional advisers.

This notice applies to individuals in the United Kingdom and the European Economic Area, and is issued in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) (Regulation (EU) 2016/679), and the Data Protection Act 2018.

Website Users

The Haloniq website is owned and operated by Brigade Electronics Group plc, a sister company of Haloniq, which acts as the data controller for personal data collected through the website — including through cookies and similar technologies, IP address and analytics data, and any contact, demo request, or enquiry forms submitted through the website.

For information about how your personal data is collected and used when you visit our website, including details of the cookies used and how to manage your preferences, please see Brigade Electronics Group plc’s privacy policy Privacy Policy – Brigade Electronics.

How We Use Your Personal Data

The table below sets out the categories of personal data we process as a controller, the purposes for which we use it, the legal basis we rely on, and how long we retain it.

Activity
Reseller Account Management
Data Hosting and Storage
Backup and Recovery
Data Deletion
Haloniq User Account Management
Technical Support and Service Management
Customer Configuration Management
Audit and System Logs
Billing and Commercial Administration
Mobile Application Management
Platform Security Management
Infrastructure Monitoring
Privacy and Compliance Management
Supplier Contract Management
Who this involves
Reseller contacts
Reseller and end customer users (limited metadata), Haloniq administrators
End customer users, Haloniq administrators
End customer contacts and users
Haloniq employees, administrators, contractors
Reseller and end customer contacts, support contacts
End customer administrators, reseller administrators
End customer/reseller users, administrators, Haloniq employees/contractors
Reseller billing contacts
Mobile application users
End customer/reseller users, employees, administrators
Platform users (metadata only)
Data subjects exercising rights, end customer and reseller contacts
Supplier contacts, professional advisers
Personal data used
Name, business email, telephone number, business address, job title, account history, communications
Infrastructure metadata, storage allocation, tenant identifiers, service metadata, hosting records
Backup metadata, restore records, system identifiers
Deletion requests, deletion logs, audit records
User ID, name, business email, role, permissions, MFA records, login history
Contact details, support tickets, communications, diagnostic information
Administrator names, email addresses, user roles, notification recipients, configuration audit records
Login records, IP addresses, authentication logs, security events, administrative actions, device identifiers
Billing contacts, invoices, payment status, licence records, subscription information
Device identifiers, push notification tokens, application version, crash reports, diagnostic information, app analytics
Security logs, threat intelligence, authentication data, vulnerability reports
Performance metrics, system telemetry, infrastructure logs
Subject access requests, breach records, compliance records
Contact details, contracts, correspondence
Why we use it
To establish and manage commercial relationships, customer onboarding, account administration, contract management and customer communications.
To operate, maintain and secure the SaaS infrastructure, ensure service availability and resilience, and administer cloud resources.
To ensure business continuity, disaster recovery and restoration of services.
To comply with contractual and legal obligations to securely delete personal data.
To manage privileged accounts, identity management and secure access to Haloniq systems.
To provide customer support, manage incidents, maintain service quality and administer support services.
To maintain and secure platform configuration functionality, administer platform features and support customer configuration requests.
To monitor platform security, investigate incidents, detect fraud, maintain audit trails and demonstrate compliance.
To administer subscriptions, invoicing, payments and financial reporting.
To publish, maintain, secure and support the mobile application, manage releases, monitor performance and deliver notifications.
To detect, prevent and investigate cybersecurity threats and maintain platform security.
To monitor platform health, availability, resilience and capacity planning.
To comply with UK GDPR, EU GDPR and other applicable legal obligations.
To manage suppliers, contracts and professional relationships.
Legal basis
Contract (Art. 6(1)(b)); Legitimate Interests (Art. 6(1)(f))
Legitimate Interests (Art. 6(1)(f))
Legitimate Interests (Art. 6(1)(f))
Legal Obligation (Art. 6(1)(c)); Legitimate Interests (Art. 6(1)(f))
Legitimate Interests (Art. 6(1)(f))
Contract (Art. 6(1)(b)); Legitimate Interests (Art. 6(1)(f))
Legitimate Interests (Art. 6(1)(f))
Legitimate Interests (Art. 6(1)(f)); Legal Obligation (Art. 6(1)(c))
Contract (Art. 6(1)(b)); Legal Obligation (Art. 6(1)(c))
Legitimate Interests (Art. 6(1)(f))
Legitimate Interests (Art. 6(1)(f)); Legal Obligation (Art. 6(1)(c))
Legitimate Interests (Art. 6(1)(f))
Legal Obligation (Art. 6(1)(c))
Contract (Art. 6(1)(b)); Legitimate Interests (Art. 6(1)(f))
How long we keep it
Contract period + 6 years
Service life + 12 months operational records
Rolling 30–90 days (unless legal hold applies)
Deletion logs retained 12 months
Employment/engagement + 12 months
24 months after ticket closure
Contract term + 90 days
12–24 months
7 years
Account life + 12 months
12–24 months
12 months
6 years
Contract period + 6 years

Who We Share Your Data With

We share personal data, where necessary and proportionate for the purposes described above, with:

  • Service providers who support our business operations, including cloud hosting and infrastructure providers, our CRM provider, service desk and ticketing providers, identity management providers, and security monitoring providers;
  • Our authorised resellers and business partners, including Brigade Electronics Group companies, and their representatives;
  • Professional advisers, including our legal advisers, auditors, and finance systems providers;
  • Payment providers and banks, for billing and financial administration;
  • Regulators and supervisory authorities, including the Information Commissioner’s Office (ICO) and relevant EU supervisory authorities, where required by law;
  • Apple and Google, and our mobile analytics provider, in connection with the operation of our mobile application; and
  • Any purchaser or prospective purchaser of our business or assets, in the event of a sale, merger, reorganisation, or similar transaction.

We require our resellers and service providers to protect personal data in accordance with applicable data protection law and only to process it on our instructions or in accordance with their own lawful role, as applicable.

Customer support is provided on our behalf by Brigade Electronics Group plc, using Zendesk, which may include an AI-assisted support agent (Brigade Bot).

International Transfers

Where you are based in the UK, your personal data may be transferred to, and hosted in, the European Economic Area (EEA) in connection with the processing activities described in Section 4 of this notice, where we act as controller.

The UK government has confirmed, through its data protection adequacy regulations, that the EEA provides an adequate level of protection for personal data. This means we can transfer your personal data to the EEA on this basis, without needing to put additional safeguards (such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses) in place for this specific transfer.

If we transfer your personal data to a country that does not benefit from an adequacy decision, we will ensure an appropriate safeguard is in place beforehand, and will update this notice accordingly.

This section does not cover marketing or website-related processing, which is carried out separately by Brigade Electronics Group plc as an independent controller — see Section 1 above and Brigade Electronics Group plc’s own privacy policy for information about any international transfers relevant to that processing

Your Rights

Subject to certain conditions and exemptions under applicable data protection law, you have the following rights in relation to your personal data:

  • The right to be informed about how we use your personal data (as set out in this notice);
  • The right of access to the personal data we hold about you;
  • The right to rectification of inaccurate or incomplete personal data;
  • The right to erasure of your personal data in certain circumstances;
  • The right to restrict our processing of your personal data in certain circumstances;
  • The right to data portability, where we process your data by automated means on the basis of your consent or a contract;
  • The right to object to processing based on legitimate interests, including for direct marketing purposes; and
  • The right to withdraw consent at any time, where we rely on consent as our legal basis, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact us using the details in Section 8 below. We may need to verify your identity before responding to your request.

If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (ico.org.uk). If you are based in the EEA, you may also complain to your local data protection supervisory authority.

How To Complain

Under UK data protection law, you have the right to complain directly to us if you consider that, in connection with your personal data, there has been an infringement of the UK GDPR or Part 3 of the Data Protection Act 2018. We encourage you to raise any concerns with us first, so that we have the opportunity to investigate and put things right.

You can submit a complaint to us:

  • by email or post, using the contact details in Section 9 below.

When we receive a complaint from you, we will:

  • acknowledge receipt of your complaint within 30 days;
  • take appropriate steps to investigate your complaint without undue delay, in a manner that is reasonable and proportionate to the nature and complexity of the issues raised and the impact on you;
  • keep you informed of our progress, including of any anticipated delays; and
  • provide you with the outcome of your complaint without undue delay.

You have the right to complain to a supervisory authority at any time, whether or not you have first complained to us. In the UK, this is the Information Commissioner’s Office (ico.org.uk). If you are based in the EEA, you may also complain to your local data protection supervisory authority.

How To Contact Us

If you have any questions about this notice or how we handle your personal data, or wish to exercise any of your rights, please contact us at:

DPO
Haloniq Ltd
Brigade House, The Mills, South Darenth, Kent, DA4 9BD
+1 (260) 766-4343
privacy@haloniq.com

Changes To This Notice

We may update this notice from time to time to reflect changes in our processing activities or to comply with legal requirements. Where changes are significant, we will take reasonable steps to notify affected individuals. The “Last updated” date at the top of this notice indicates when it was last revised.