Data & security

How ExoFleets handles your fleet data

UK GDPR compliant. ICO registered. Fleet telematics data stored and processed exclusively on AWS eu-west-2 (London). Driver IDs pseudonymised at ingestion. Data Processing Agreement available on request.

UK GDPR

Designed with UK GDPR in mind

UK Data Residency

AWS eu-west-2 London only

ICO Registered

Registered data controller

Our data handling practices

UK data residency

All fleet telematics data — vehicle positions, trip records, CAN bus readings, maintenance events — is stored and processed exclusively on AWS eu-west-2 (London). No data leaves the UK. We do not use US-based cloud regions for customer fleet data.

Encryption in transit and at rest

All data transmitted between your telematics system and ExoFleets uses TLS 1.2 or higher. Data stored in our database and object storage is encrypted at rest using AES-256. API keys are hashed and never stored in plain text.

Driver data anonymisation

ExoFleets is built to report on vehicles (VRMs), not individuals. Driver IDs from your telematics feed are hashed and replaced with pseudonymous identifiers during ingestion. We do not retain driver names or personally identifiable driver data at rest. Analytics are keyed to VRM only.

This approach is designed to support your UK GDPR obligations as data controller for your fleet workers' location data.

ICO registration and data processing agreements

ExoFleets Ltd is registered with the UK Information Commissioner's Office (ICO) as a data controller for the personal data we process. When you use ExoFleets, we act as a data processor for your fleet operational data under a Data Processing Agreement (DPA) available on request.

We do not sell or share your fleet data with third parties. Sub-processors we use (AWS, monitoring tooling) are covered by appropriate agreements and operate within the UK or under adequate transfer mechanisms.

ExoFleets is a bootstrapped early-stage company. We have not completed independent security certifications such as ISO 27001 or Cyber Essentials Plus at this stage. We are built with those controls in mind and intend to pursue certification as the business scales. If your procurement process requires evidence of specific certification, please contact us directly to discuss.

Data and security enquiries

If you have questions about our data handling practices, need a copy of the Data Processing Agreement, or are assessing ExoFleets for procurement — contact [email protected] directly. We aim to respond within one working day.

Contact us