Passdesk

Privacy policy

Last updated April 2026

Who we are

Passdesk is a software platform used by independent driving schools (each, a "school") to manage their learners, instructors, lessons, purchases, and progress records. Each school is the "data controller" for data it collects; Passdesk Ltd is the "data processor" operating the service on their behalf.

This policy describes what personal data we hold, why we hold it, the lawful basis under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and the rights you have over it.

Data we collect

Account data — your name, email, phone number, address, password hash, role and the school you belong to. Supplied by you on signup or by a school administrator when they invite you.

Learner profile — date of birth, provisional licence number, theory and practical test dates, medical self-declarations, and emergency contact or guardian details where you are under 18. Used to schedule lessons, comply with DVSA rules, and run safeguarding procedures.

Instructor compliance — ADI / PDI badge number, badge expiry, DBS check date and certificate number, insurance policy number and expiry. Stored to prove DVSA compliance during inspections.

Lessons, progress and purchases — when lessons were booked and completed, ratings and notes on competencies, products you bought, amounts paid, and the status of each purchase.

Technical data — the JWT session cookie / token issued when you sign in, the IP address you signed in from (in access logs kept for up to 30 days), and the user-agent of your browser. No analytics or advertising cookies are used.

Why we use it

To operate the service you or your school asked us to provide — book and run driving lessons, record progress, process purchases, and keep the inspectors' paperwork up to date. The lawful basis is contract for anything necessary to deliver the service, legal obligation for records we must keep (tax, DVSA, DBS), and legitimate interests for security logging and fraud prevention.

We never sell your data or share it with advertisers.

Who we share it with

Within Passdesk, data is only visible to staff at your school and to Passdesk Ltd support engineers acting on the school's instructions. Otherwise, we share data with: our cloud hosting provider (stores the database), our email provider (delivers transactional email like password resets and invites), and regulators or law enforcement where we are legally required to do so.

How long we keep it

Active account data is retained while your account is active. If you stop using the service, we flag your records for review after 3 years of inactivity; records with no legal retention requirement are then deleted. Financial records (purchases, invoices) are retained for 7 years as required by HMRC. Audit logs are retained for 2 years.

Your rights

Under UK GDPR you have the right to: access the data we hold about you; correct inaccurate data; request erasure of data we no longer need; restrict processing; object to processing based on legitimate interests; and receive a portable copy of the data you provided to us.

You can export a copy of your data at any time from the My account page. For erasure, correction or any other subject-access request, contact the Data Protection Officer above (or the email below if none is listed).

Cookies

We use one essential cookie for sign-in (the session JWT). No analytics, advertising or tracking cookies are set. Under the UK Privacy and Electronic Communications Regulations (PECR), essential cookies do not require opt-in consent; we still show a one-off banner the first time you visit so you know we set it.

Complaints

If you think we have mishandled your data, please contact the DPO first. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.

Contact

For anything relating to the Passdesk platform itself, contact privacy@passdesk.co.uk.


This page is provided as a template. Schools remain responsible for the accuracy of the information shown above and for keeping their operator details up to date.