Legal

Privacy Policy

Last updated: 19 July 2026

1. Who we are and when this policy applies

oembrain is a workshop management service operated by OEM DRIVE LTD. For account, billing, security and service-administration data, OEM DRIVE LTD is generally the data controller. A subscribing workshop is generally the controller of the customer, vehicle, job and invoice records it enters into its workspace; we process those records on the workshop's instructions to provide the service.

Controller: OEM DRIVE LTD
Companies House number: 14824413
Address: 10 Duncombe Street, Bletchley, Milton Keynes, MK2 2LY
Privacy contact: [email protected]
ICO registration reference: ZC192774 (Tier 1; registered 07 July 2026; expires 06 July 2027)

No separate data protection officer is currently appointed. Privacy questions and rights requests should be sent to the privacy contact above.

2. Personal data we handle

  • Account data, including name, email, password hash, verification state, language and consent records.
  • Workshop details, subscription state and billing-provider references.
  • Workshop records entered by users, such as customer contact details, vehicles, jobs, notes, invoices and payments.
  • Security and operational data, including session identifiers, IP addresses in limited audit/rate-limit records, timestamps and technical error logs.
  • Website usage and performance metrics, including page views and browser performance timings collected through Cloudflare Web Analytics.
  • Integration data when enabled, including DVLA/DVSA lookup results, Xero organisation details and encrypted OAuth credentials, and Stripe billing events.
  • Optional marketing consent. Marketing is not a condition of using the service.

3. Purposes and lawful bases

We use data to create and secure accounts, provide workshop features, generate documents and exports, operate requested integrations, administer subscriptions, understand website usage and performance, respond to support requests, prevent abuse, maintain audit trails and meet legal obligations.

Depending on the activity, our lawful basis is performance of a contract, our legitimate interests in operating and securing the service and supporting customers, compliance with a legal obligation, or consent where we specifically ask for it (for example optional marketing). Workshops are responsible for identifying and explaining their own lawful basis for customer data they put into oembrain.

4. Sharing and service providers

We do not sell personal data. We share it only where needed to provide or protect the service, comply with law, or complete a properly managed business transaction. Current provider categories include:

  • DigitalOcean for application hosting and managed database infrastructure;
  • Brevo for transactional email delivery;
  • Stripe for subscription checkout, billing and payment administration;
  • Xero, only when a workshop chooses to connect and use the accounting integration;
  • DVLA and DVSA services for requested UK vehicle lookups, where available; and
  • Cloudflare for website delivery, security and Cloudflare Web Analytics. Web Analytics collects page-view and performance metrics without cookies or other client-side storage and is designed not to track individuals across Cloudflare customers' websites.

Providers may use their own subprocessors. The exact processing locations can change and are not represented here as exclusively UK-based. Where UK personal data is transferred internationally, we require an applicable lawful transfer mechanism and appropriate safeguards, such as UK adequacy regulations or approved contractual protections, as required.

5. Retention

We keep data while needed to provide and secure the service and for applicable legal, accounting, dispute and fraud-prevention needs. Retention varies by record type and contractual or legal requirement. A detailed production retention and backup-erasure schedule is still being finalised. Deletion requests are reviewed so active billing, backups, integrations and records subject to retention duties can be handled safely. When data is no longer needed, it is deleted or anonymised in line with the applicable schedule.

6. Security

The application uses controls including tenant-scoped database access, password hashing, CSRF protection, restricted cookies, role checks and audit records. No internet service can guarantee absolute security. Workshop owners should control user access and protect downloaded exports.

7. Your choices and rights

Depending on applicable law and the circumstances, individuals may have rights to access, correct, erase or restrict data, object to some processing, obtain portable data, withdraw consent, and complain to a supervisory authority. These rights can have exceptions. Workshop customers should normally contact the workshop first because the workshop controls their service records. Account owners can export workshop data and submit a guarded deletion request from Privacy & workshop data settings. Other requests can be sent to [email protected]; identity and authority may need to be verified.

The UK supervisory authority is the Information Commissioner's Office (ICO). You can find current complaint routes and contact guidance at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address your concern first, but contacting us does not affect your right to complain to the ICO.

8. International access and changes

Authorised providers may process data outside the UK under the safeguards described above. Material policy changes will be dated here and, where appropriate, communicated in the service.

Cookie Policy · Terms and Conditions