Introduction
Welcome to OfficeSystems ("we", "our", or "us"). We are committed to protecting your privacy and ensuring that your personal data is handled in a safe, transparent, and responsible manner. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at https://www.office-systems.co.uk and use our suite of workplace, rota, logistics, and stock management applications (collectively, the "Services").
This policy has been written in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the privacy requirements set out by Google for web and application services. Please read this policy carefully. By using our Services, you acknowledge that you have read and understood this Privacy Policy.
Who We Are and How to Contact Us
OfficeSystems is owned and operated by J.Noble & Office-systems.co.uk, the data controller responsible for your personal data. As the data controller, we determine the purposes and means by which your personal data is processed.
If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us:
Email: admin@office-systems.co.uk
Website: https://www.office-systems.co.uk/contact-us
Operated by: J.Noble & Office-systems.co.uk
Information We Collect
We collect various categories of information to provide and improve our Services. The data we collect depends on how you interact with our website and which applications you subscribe to and use.
When you create an account, subscribe to a product, or activate a free trial, we collect the following information directly from you:
Full name · Email address · Company name · Password (stored in encrypted form) · Subscription status and billing period · Trial activation dates
Our suite of tools processes specific operational data that is necessary for their functionality. When you use these applications, you may enter data about yourself, your employees, your fleet, or your business operations. The table below details exactly what each application collects and why.
| Application | Data Collected | Purpose |
|---|---|---|
| Driver Rota Manager Pro Driver Rota Manager |
Driver names, shift times, vehicle registrations, duty types, break durations, holiday and absence records, driver availability, email addresses and phone numbers (Pro tier: for SMS/email notifications). | To generate conflict-free driver rotas, balance shifts, manage holidays, and notify drivers of their schedules. |
| Working Hours | Employee names, daily clock-in and clock-out times, break durations, pay rate configurations, overtime flags, bank holiday flags, unsocial hours data, estimated tax, pension, and National Insurance deductions. | To calculate daily pay, overtime, and unsocial hour uplifts, and to generate audit-ready timesheets and monthly payroll summaries. |
| Office Staff Scheduler | Staff names, department assignments, weekly rota schedules, holiday and absence requests, real-time attendance records, shift swap and cover requests, staff availability calendars. | To plan weekly rotas, track attendance, manage holiday requests, and coordinate department coverage. |
| Delivery Route Planner | Start location, destination address, intermediate via points (delivery addresses), saved custom locations (e.g., depots, regular delivery addresses), route history. | To calculate fastest-path routes, optimise fuel usage, and provide turn-by-turn navigation for delivery drivers. |
| Fleet Dispatch Manager | Driver names and assignments, delivery addresses, consignment details, live delivery status updates, QR code scan data (timestamps and scan events for proof of delivery), customer contact details where provided for notifications. | To assign and dispatch jobs, track deliveries end-to-end in real time, capture proof of delivery, and provide a live operations dashboard. |
| Road Ready | Vehicle details (make, model, registration number, type), driver names, pre-departure and post-trip inspection logs, defect reports and resolution records, maintenance schedules, MOT expiry dates, tax expiry dates, vehicle service history. | To ensure DVSA compliance, manage fleet safety, record legally required inspection data, and schedule preventative maintenance. |
| Inventory Control | Product names, SKU codes, stock quantities, warehouse and location data, unit costs and valuations, stock movement logs (inbound and outbound), supplier names and contact details, purchase order references. | To track stock levels across locations, calculate inventory valuations, trigger low-stock alerts, and generate audit-ready inventory reports. |
When you access our website or applications, we automatically collect certain technical information. This includes your IP address, browser type and version, operating system, device type, the pages you visit, time spent on each page, navigation paths through our site, and login timestamps. This data is collected through standard web server logs and session management and is used to maintain security, diagnose technical issues, and understand how our Services are used.
When you purchase a subscription, payments are processed securely through PayPal. We do not store your full credit card number, bank account details, or other sensitive payment credentials on our servers. We retain only the transaction reference, the subscription product, the billing period selected, and the activation status necessary to manage your access to the Services.
How We Use Your Information
We use the information we collect only for legitimate purposes and always in accordance with a valid lawful basis under the UK GDPR. The table below sets out each purpose and the legal basis we rely on.
How We Share Your Information
We do not sell, rent, or trade your personal data to third parties. We only share your information in the limited circumstances described below.
Service Providers: We may share data with carefully selected third-party vendors who assist us in operating our Services. This includes cloud hosting providers, email and SMS delivery services, and payment processors (PayPal). All such providers are bound by data processing agreements that restrict how they may use your data and require them to maintain appropriate security standards.
Legal Requirements: We may disclose your information if required to do so by applicable law, court order, or governmental or regulatory authority — for example, providing DVSA-compliant inspection records to the relevant authority upon a lawful request.
Business Transfers: In the event of a merger, acquisition, or sale of all or part of our business assets, your personal data may be transferred to the successor entity. We will notify you of any such change and the options available to you.
With Your Consent: We may share your information with third parties where you have given us your explicit consent to do so.
Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law. The following retention principles apply:
Account Data (name, email, company, subscription status) is retained for the duration of your active subscription. If you close your account or your subscription lapses without renewal, we will delete or anonymise your account data within a reasonable period, unless we are required to retain it for legal or compliance purposes.
Application Data — such as timesheet records, driver rotas, vehicle inspection logs, dispatch records, and inventory reports — is retained as directed by you, the data controller, to satisfy your own operational, legal, and audit obligations (for example, HMRC payroll record-keeping requirements, or DVSA compliance records).
Technical and Log Data is retained for a limited period for security monitoring and diagnostic purposes, after which it is securely deleted or anonymised.
Payment Transaction References are retained for the period required to manage your subscription and to comply with applicable financial record-keeping obligations.
Data Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration. These measures include encrypted password storage, secure HTTPS data transmission, server-side access controls, and session authentication for all subscribed applications.
However, no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority (the ICO) in accordance with our legal obligations.
Your Data Protection Rights
Under the UK GDPR and the Data Protection Act 2018, you have a number of important rights in relation to your personal data. These rights are summarised below. To exercise any of them, please contact us using the details in Section 2.
You can request a copy of the personal data we hold about you (a Subject Access Request).
You can request that we correct any inaccurate or incomplete personal data we hold about you.
You can request that we delete your personal data, subject to certain legal exceptions.
You can ask us to limit how we use your data in certain circumstances.
You can object to our processing of your data where we rely on legitimate interests as our lawful basis.
You can request that we transfer your data to you or to another organisation in a structured, machine-readable format.
We will respond to all legitimate requests within one month of receipt. If your request is complex or you have made a number of requests, we may extend this period by a further two months, in which case we will notify you. We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive.
Data Processing on Behalf of Our Clients
For the majority of data entered into our applications — such as employee names, driver shift records, vehicle inspection logs, delivery addresses, and stock data — our business customers are the Data Controllers and OfficeSystems acts as the Data Processor. This means our clients determine the purposes and means of processing that data, and we process it solely on their instructions.
If you are an employee, driver, or customer of an OfficeSystems business client, and you wish to exercise your data protection rights (such as requesting access to, or deletion of, your personal data held within one of our applications), you should direct that request to your employer or the company that uses our Services. They are responsible for responding to such requests in their capacity as Data Controller.
OfficeSystems will assist our clients in responding to such requests as required under our data processing obligations.
International Data Transfers
Our servers are primarily located within the United Kingdom and/or the European Economic Area (EEA). Where we engage third-party service providers (such as cloud infrastructure or email delivery services) that may process data outside the UK or EEA, we ensure that an equivalent level of protection is maintained. We achieve this by relying on the UK's adequacy regulations, the International Data Transfer Agreement (IDTA), or standard contractual clauses approved by the ICO, as appropriate.
Cookies and Session Tracking
Our website and applications use session cookies and local storage to manage your authenticated session. These are strictly necessary for the operation of the Services — for example, to keep you logged in as you navigate between pages and applications, and to remember your subscription status.
Strictly Necessary Cookies: These are required for the website and applications to function and cannot be switched off. They are typically set in response to actions you take, such as signing in, setting your billing preferences, or activating a trial. They do not store any personally identifiable information beyond what is required to maintain your session.
We do not currently use advertising cookies, cross-site tracking cookies, or third-party analytics cookies. If this changes in the future, this policy will be updated accordingly and you will be informed.
Third-Party Links
Our website and applications may contain links to third-party websites, services, or resources — for example, links to PayPal for payment processing, or to PDF user guides hosted externally. We are not responsible for the privacy practices, content, or security of any third-party websites. We strongly encourage you to review the privacy policy of every website you visit. This Privacy Policy applies solely to information collected by OfficeSystems.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, our Services, or applicable legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this page. Where the changes are significant, we will take reasonable steps to notify you — for example, by displaying a notice on our website or sending an email to your registered address.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data.
Complaints and How to Contact Us
If you have any concerns about how we handle your personal data, we encourage you to contact us in the first instance so we can address your concerns directly. We take all privacy complaints seriously and will respond promptly.
Email: admin@office-systems.co.uk
Website: https://www.office-systems.co.uk/contact-us
If you remain dissatisfied with our response, or if you believe we are processing your personal data in a way that does not comply with the UK GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent data protection authority:
Website: https://ico.org.uk
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Online complaint form: https://ico.org.uk/make-a-complaint/