Early access for UK transport operators View the Founding Customer Programme

Data protection policy

GLS is designed so that operational and commercial data is handled responsibly, with clear separation between customers and controls that support lawful and secure processing.

Version: 0.6 Last reviewed: Jan 2026 Review cycle: Annual or upon material change

Purpose

This policy describes how GLS supports the protection of personal and commercial data processed within the platform. The objective is to ensure appropriate confidentiality, integrity and availability of data while enabling legitimate operational use.

Scope

This policy applies to all data stored or processed within GLS, including personal data relating to drivers, customers, suppliers and employees, together with operational freight and commercial records.

Principles

  • Only data necessary for operational purposes should be collected
  • Data belonging to one tenant must not be visible to another
  • Access should be role-based and limited to legitimate use
  • Security and privacy controls should be designed-in
  • Data must be handled lawfully and ethically

Data protection controls in GLS

Tenant isolation

Each tenant’s operational data is logically separated. Requests for data require valid tenant context and authorisation to prevent accidental or unauthorised cross-tenant access.

Access control

Users are assigned roles that determine what data they may view or modify. Sensitive actions are logged to support accountability and investigation if required.

Secure handling of personal data

GLS supports operators in processing personal data — such as driver and contact details — in a structured, access-controlled environment that reduces the risk of uncontrolled data duplication or loss.

Data integrity

Platform controls are designed to help protect data against accidental alteration or unauthorised deletion, with backups available to support recovery.

Data in transit and at rest

Industry-standard encryption is used for data transmitted between systems and for stored customer data.

Alignment with legal and regulatory expectations

GLS supports alignment with applicable data protection laws, including GDPR principles relating to security, access control, purpose limitation and accountability. Customers remain the data controller for their own operational data.

Customer responsibilities

Customers are responsible for:

  • ensuring a lawful basis for any personal data entered into GLS
  • assigning appropriate roles and permissions to internal users
  • responding to data subject requests where applicable
  • keeping local devices and credentials secure

Retention

Data retention is managed in accordance with commercial and legal requirements. GLS will support customers in meeting reasonable retention and deletion obligations where technically feasible.

Limitations

GLS provides platform-level controls for secure processing of data. Customers remain responsible for the accuracy, lawfulness and appropriateness of the data they submit to the platform.

Review

This policy is reviewed at least annually, or sooner if regulation, risk exposure or platform architecture changes materially.