How ExoFleets handles your fleet data
UK GDPR compliant. ICO registered. Fleet telematics data stored and processed exclusively on AWS eu-west-2 (London). Driver IDs pseudonymised at ingestion. Data Processing Agreement available on request.
UK GDPR
Designed with UK GDPR in mind
UK Data Residency
AWS eu-west-2 London only
ICO Registered
Registered data controller
Our data handling practices
UK data residency
All fleet telematics data — vehicle positions, trip records, CAN bus readings, maintenance events — is stored and processed exclusively on AWS eu-west-2 (London). No data leaves the UK. We do not use US-based cloud regions for customer fleet data.
Encryption in transit and at rest
All data transmitted between your telematics system and ExoFleets uses TLS 1.2 or higher. Data stored in our database and object storage is encrypted at rest using AES-256. API keys are hashed and never stored in plain text.
Driver data anonymisation
ExoFleets is built to report on vehicles (VRMs), not individuals. Driver IDs from your telematics feed are hashed and replaced with pseudonymous identifiers during ingestion. We do not retain driver names or personally identifiable driver data at rest. Analytics are keyed to VRM only.
This approach is designed to support your UK GDPR obligations as data controller for your fleet workers' location data.
ICO registration and data processing agreements
ExoFleets Ltd is registered with the UK Information Commissioner's Office (ICO) as a data controller for the personal data we process. When you use ExoFleets, we act as a data processor for your fleet operational data under a Data Processing Agreement (DPA) available on request.
We do not sell or share your fleet data with third parties. Sub-processors we use (AWS, monitoring tooling) are covered by appropriate agreements and operate within the UK or under adequate transfer mechanisms.
ExoFleets is a bootstrapped early-stage company. We have not completed independent security certifications such as ISO 27001 or Cyber Essentials Plus at this stage. We are built with those controls in mind and intend to pursue certification as the business scales. If your procurement process requires evidence of specific certification, please contact us directly to discuss.
Data and security enquiries
If you have questions about our data handling practices, need a copy of the Data Processing Agreement, or are assessing ExoFleets for procurement — contact [email protected] directly. We aim to respond within one working day.