GDPR Compliant

Data Protection & Privacy

Your data security and privacy are our top priorities. Learn how we protect, process, and respect your information in full compliance with GDPR and UK Data Protection Act 2018.

Certified & Compliant

UK GDPR
UK DPA 2018
ICO Registered
Stripe PCI
Data Encrypted
GDPR Compliant
Encrypted
30-day response

Contents

Quick navigation

Overview

Last updated: April 12, 2026

At EcoHaul, we are committed to protecting your privacy and ensuring the security of your personal data. This comprehensive policy outlines our practices regarding data collection, processing, storage, and your rights as a data subject.

Legal Basis for Data Processing

We process your personal data under the following legal bases:

Contractual Necessity

To fulfill our service agreement with you

  • Account creation
  • Service delivery
  • Payment processing

Legitimate Interest

For business operations and improvements

  • Fraud prevention
  • Service optimization
  • Marketing analytics

Legal Obligation

To comply with legal requirements

  • Tax records
  • Legal disputes
  • Regulatory compliance

Consent

When you explicitly agree

  • Marketing emails
  • Cookies
  • Optional features

Scope of This Policy

This policy applies to:

  • All users of EcoHaul's platform (households, businesses, drivers, driver helpers)
  • Website visitors and app users
  • Newsletter subscribers and marketing contacts
  • Anyone who communicates with us

Our Commitment to Your Privacy

The principles that guide us

Transparency

We are clear about what data we collect and why

Security

Your data is protected with industry-leading encryption

Control

You have full control over your personal information

Minimization

We only collect data that is necessary

Accuracy

We keep your data accurate and up-to-date

Accountability

We take responsibility for protecting your data

GDPR Compliance

How we meet European data protection standards

EcoHaul is fully compliant with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We adhere to all seven key principles of data protection:

1

Lawfulness, Fairness & Transparency

We process data lawfully, fairly, and in a transparent manner

Clear privacy notices, lawful processing bases, transparent communications
2

Purpose Limitation

Data is collected for specified, explicit, and legitimate purposes

Defined purposes for each data category, no unexpected use of data
3

Data Minimization

We only collect data that is adequate, relevant, and necessary

Regular data audits, removal of unnecessary data fields
4

Accuracy

Personal data is kept accurate and up to date

User profile management, data quality checks, correction procedures
5

Storage Limitation

Data is kept only as long as necessary

Defined retention periods, automated deletion procedures
6

Integrity & Confidentiality

Data is processed securely with appropriate safeguards

Encryption, access controls, security monitoring, incident response
7

Accountability

We demonstrate compliance with all principles

Documentation, DPIAs, staff training, regular audits

Your Data Rights

What you can do with your personal data

Right to Access

Request a copy of all personal data we hold about you

Simple
30 days

Right to Rectification

Request correction of inaccurate or incomplete data

Simple
7 days

Right to Erasure

Request deletion of your personal data (right to be forgotten)

Moderate
30 days

Right to Restriction

Request restriction of processing your personal data

Moderate
30 days

Right to Portability

Receive your data in a machine-readable format

Simple
30 days

Right to Object

Object to processing based on legitimate interests

Moderate
14 days

How to Exercise Your Rights

To exercise any of these rights, simply click the action button above or contact our Data Protection Officer using the form at the bottom of this page. We'll verify your identity and process your request within the statutory timeframe.

Free of charge
30-day response
Secure process

Security Measures

How we protect your data

We implement industry-leading technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

Encryption

Full
  • 256-bit AES encryption at rest
  • TLS 1.3 in transit
  • End-to-end encryption for sensitive data

Access Control

Full
  • Multi-factor authentication
  • Role-based access control (RBAC)
  • Regular access audits

Monitoring

Full
  • 24/7 security monitoring
  • Real-time threat detection
  • Automated incident response

Backup & Recovery

Full
  • Daily automated backups
  • Geo-redundant storage
  • Tested disaster recovery

Compliance

Full
  • ISO 27001 certified
  • GDPR compliant
  • Regular security audits

Network Security

Full
  • Firewall protection
  • DDoS mitigation
  • Intrusion detection systems

Data We Collect

Types of personal information we process

Identity Data

Full name
Required

Account identification and personalization

Date of birth
Optional

Age verification and legal compliance

Profile photo
Optional

Account personalization

Driver license details
Required

Driver verification (drivers only)

How We Process Your Data

Our data processing activities

We process your personal data for the following purposes, always ensuring it is lawful, fair, and transparent:

Service Delivery

To provide waste collection and recycling services

Contractual Necessity

Processing Activities:

Matching customers with drivers
Coordinating pickups and deliveries
Processing payments
Managing disputes

Account Management

To create and maintain your account

Contractual Necessity

Processing Activities:

User authentication
Profile management
Preference settings
Access control

Communication

To communicate with you about our services

Legitimate Interest / Consent

Processing Activities:

Service notifications
Job updates
Support messages
Marketing (with consent)

AI & Analytics

To improve our services using data insights

Legitimate Interest

Processing Activities:

Price optimization
Route planning
Demand forecasting
Service improvements

Legal Compliance

To comply with legal obligations

Legal Obligation

Processing Activities:

Tax reporting
Regulatory compliance
Dispute resolution
Law enforcement requests

Security & Fraud Prevention

To protect users and prevent misuse

Legitimate Interest

Processing Activities:

Identity verification
Fraud detection
Security monitoring
Incident response

Data Retention

How long we keep your information

We only retain your personal data for as long as necessary to fulfill the purposes outlined in this policy, or as required by law.

Account Data

Active account + 6 years

Legal and accounting requirements

Transaction Records

6 years from transaction

Tax and financial regulations

Communication Logs

1-3 years

Customer service and dispute resolution

Marketing Data

Until consent withdrawn

Marketing communications

Analytics Data

2 years

Service improvement

Security Logs

1 year

Security monitoring and compliance

Data Breach Procedures

Our incident response protocol

Response Timeline

0-1 hours

Initial detection and containment

1-24 hours

Full assessment and impact analysis

24-72 hours

User notification (if required by GDPR)

72 hours

ICO notification (if required)

1-2 weeks

Full remediation and security updates

Ongoing

Monitoring and prevention measures

Prevention Measures

Regular security audits and penetration testing

24/7 security monitoring and threat detection

Employee training on data protection

Incident response drills and simulations

Multi-layered security architecture

Regular backup and disaster recovery testing

How You'll Be Notified

If a breach affects your personal data, we will notify you via:

Email notification
In-app alert
SMS (if urgent)
Push notification

Contact Our Data Protection Officer

We're here to help with your data protection concerns

Contact Information

Phone

TODO-PHONE-NUMBER

Address

EcoHaul Ltd
Data Protection Office
EcoHaul Ltd, London, United Kingdom
Registered in England & Wales

Response Times

General Inquiries

1-2 business days

Data Rights Requests

Within 30 days

Urgent Issues

Within 24 hours

Complaints

Acknowledged in 48 hours

Frequently Asked Questions

Quick answers to common questions

Still have questions?