Privacy Policy
1. Controller and processor roles
The company or agency that manages your engagement is the data controller for your contractor and engagement data. It decides why that data is used and how it is handled.
ZERITY LIMITED acts as its data processor. ZERITY LIMITED stores and processes engagement data only on the Controller's documented instructions so that the Platform can provide onboarding, compliance, fleet, invoicing, payment, safety, and related services.
ZERITY LIMITED is not the Controller's Data Protection Officer and does not become the controller of engagement data merely because it hosts, organises, transmits, or exports that data.
ZERITY LIMITED acts as an independent data controller only for platform action and audit logs that it creates for security, fraud prevention, system administration, and legal obligations that apply directly to ZERITY LIMITED. This limited role does not extend to your contractor or engagement data.
2. Data covered by this policy
Depending on the services selected by the Controller, engagement data may include:
- identity, contact, business, tax, right-to-work, driving-licence, and background-check information;
- vehicle, booking, inspection, incident, health and safety, compliance, and training records;
- bank details, invoices, payments, charges, and dispute records;
- delivery, attendance, performance, asset, and engagement communications; and
- documents and photographs submitted for those purposes.
The limited records controlled by ZERITY LIMITED are platform action and audit logs, such as login timestamps, security events, administrative actions, and records that ZERITY LIMITED must retain to meet obligations that apply directly to it.
3. How the data is obtained
Engagement data may be provided by you, the Controller, depots, and verification or service providers acting for the Controller. Technical action and audit logs are created when the Platform is used or administered.
4. Why the data is processed
The Controller determines the purposes and lawful bases for processing engagement data. ZERITY LIMITED processes that data on the Controller's instructions to deliver the Platform services selected by the Controller.
For its limited independent-controller records, ZERITY LIMITED processes platform action and audit logs only to secure and administer the Platform, detect or prevent fraud, investigate faults, and comply with legal obligations directly applicable to ZERITY LIMITED.
5. Sharing and sub-processors
Engagement data is made available only as directed by the Controller, including to authorised operations, compliance, finance, fleet, insurance, verification, communications, payment, and professional-service providers where required for the engagement. ZERITY LIMITED may use contracted sub-processors to host and deliver the Platform.
Neither the Controller nor ZERITY LIMITED sells your personal data. The Controller is responsible for deciding whether engagement data is disclosed and for ensuring that any required international-transfer safeguards are in place. ZERITY LIMITED protects transfers made as the Controller's processor under its contractual obligations.
6. Retention
The Controller sets retention periods for engagement data and instructs ZERITY LIMITED when that data should be deleted or anonymised, subject to applicable law. ZERITY LIMITED retains its own platform action and audit logs only for as long as needed for security, fraud prevention, system administration, or legal obligations directly applicable to ZERITY LIMITED.
7. Security
ZERITY LIMITED applies technical and organisational safeguards to data processed through the Platform, including access controls, encryption, monitoring, backups, and confidentiality obligations. ZERITY LIMITED assists the Controller with personal-data breaches involving engagement data as required by their data-processing agreement.
8. Your data protection rights
Requests to access, correct, erase, restrict, transfer, or object to processing of engagement data must be decided by the Controller. The Privacy Center routes and processes those requests on the Controller's behalf, and ZERITY LIMITED assists the Controller in responding.
If the request concerns only platform action or audit logs controlled by ZERITY LIMITED, contact office@zerity.co.uk. This is ZERITY LIMITED's general privacy contact, not a Data Protection Officer.
You may complain to the Information Commissioner's Office. Complaining does not affect any other legal remedy.
9. Automated decisions
The Controller determines whether automated checks or profiling are used for engagement decisions. ZERITY LIMITED does not independently make decisions about your engagement. Platform checks support the Controller's human review unless the Controller tells you otherwise.
10. Cookies and communications
The Platform uses essential cookies for authentication, session management, and security. Optional analytics or communications are used only where the Controller has configured them and the required lawful basis or consent applies. Communications about your engagement are sent on the Controller's instructions.
11. Children
The Platform is intended for adults engaged as contractors. If you believe a child's data has been submitted, contact the company or agency that manages the relevant engagement through the Privacy Center.
12. Changes and contact
The Controller's own privacy notice may also apply and should identify its privacy contact. This policy may be updated when Platform processing changes.
For questions about ZERITY LIMITED's processor role or the limited platform action and audit logs it controls, contact office@zerity.co.uk.
ZERITY LIMITED, Company No. 14348190, Elizabeth House, Victoria Street, Openshaw, Manchester, M11 2NX, United Kingdom.