PRIVACY NOTICE
Users of 365 Smart Platform App (“the Mobile App")
This notice explains to you how we collect and process personal data which we may collect from or about you on the Mobile App. It also explains your rights and who to contact if you have any questions about this notice. This privacy notice supplements our other privacy notices and is not intended to override them.
1. Who is the data controller?
For most purposes, the Controller of your personal data will be the entity which collects it from you and that entity’s privacy notice should explain how your personal data is being processed.
West Midlands Accessible Transport Limited trading as National Express Accessible Transport (“NEAT”) will be the Controller of certain personal data which is processed by the Mobile App. NEAT will be the Controller of any personal data which it receives from third parties or which it collects on behalf of third parties (including, without limit, WMCA) where such personal data is being used for the purposes set out in section 4 of this privacy notice.
NEAT will also be the Controller of any personal data which it collects from any equipment which it has installed on any vehicles it uses to perform the services or on any of its premises, such as CCTV.
NEAT’s representative for the purposes of this privacy notice is the National Express UK Data Protection Officer, who can be contacted using the contact details provided at the end of this notice.
2. What personal data is collected from and/or about you on the App?
We collect the following types of personal data about you and any person for whom you are responsible and who travels on a service covered by the Mobile App:
- if you register to use our websites and/or apps, your email address and password;
- information about your location if you are on board one of our vehicles; and
- any other personal data that you provide to us in the app or which is provided to us by a third party.
We collect this personal data in the following ways:
- by you: ○ creating an account with us
- by us: ○ using telematics systems operating on transport services performed for us
In addition, each time you visit our website or use our apps we may automatically collect the following information:
- technical data, including IP address;
If you are involved in an incident on board one of our vehicles then we may process further personal data about you. The full information relating to this can be found here.
3. What do we do with your personal data?
We process your personal data for the following purposes:
- Business necessity: to respond to, investigate, manage, keep records of and report on incidents that occur on or affect passenger transport services operated by us or on our behalf.
- Legal and regulatory compliance: to ensure compliance with applicable laws and regulations to which we are subject, including those which require us to report incidents. ● Health & safety and security purposes: to seek to ensure the health and safety and security of our customers/passengers, other road users and other members of the public.
- Evidential purposes: to facilitate the conduct of any investigation into incidents, whether by us or any law enforcement or regulatory authorities, and/or to enable the conduct of any complaints and/or legal claims by or against us in relation to incidents.
- Legal purposes: to enforce and defend our legal rights.
We may process special category personal data for the purposes of establishing, exercising or defending legal claims.
We may process your personal data because we have a legal obligation to do so, for example under road transport and licensing laws, under health & safety laws or pursuant to court rules and orders. Where we process your personal data because we have a legal obligation to do so, there is no right to object to that processing.
In all other cases, we process your personal data on the basis of our legitimate interest. Where we process your personal data on the basis of our legitimate interest, you have the right to object to our use of your personal data. However, we do not have to stop processing personal data where we have compelling grounds that override your interests, or where we need to process your data in order to establish, exercise or defend legal claims. If you have any objections please contact the National Express UK Data Protection Officer (see details below).
4. What are our obligations to collect, and your obligations to provide, personal data?
We have no obligation to collect, and you have no obligation to provide, your personal data on this mobile app. However we may not be able to provide you with our products and services or deal with your questions or complaints if you do not provide us with your personal data.
5. Who will we share your personal data with? We may share your personal data with:
- other National Express Group companies;
- any funders of the services operated by us or on our behalf, including WMCA and Birmingham City Council;
- our suppliers, and sub-contractors, who help us to provide our products and services to you;
- our suppliers and contractors who help us respond to, investigate and manage incidents;
- our legal and professional advisors;
- our claims handlers, insurance brokers and insurers;
- government bodies and regulatory authorities, including the Driver and Vehicle Standards Agency, the Police and other crime prevention and detection agencies and the UK Information Commissioner’s Office;
- the Traffic Commissioners, the courts and other dispute resolution arbitrators and mediators, other parties to legal proceedings and passenger transport watchdogs; and
- other companies that take on any part of our business as a result of a restructure, merger or transfer of that part of our business.
Where we share your personal data with subcontractors or business partners for the purpose of them providing products and services to you, it may be essential to do this to fulfil a contract with you or as necessary in relation to any incidents relating to such services. Such parties will either receive such personal data as our processor (in which case we remain liable for that processor’s actions) or in some instances as a controller in their own right (in which case you should refer to their privacy notice).
In addition, if you follow a link to any of the websites of advertisers and affiliates on our websites or apps, these third party websites may have their own privacy notices or policies. We do not accept any responsibility or liability for these notices or policies or the third parties’ handling of your personal data. Please check the relevant third party’s privacy notice before you submit any personal data to them.
We do not accept any responsibility or liability for third party controllers or their handling of your personal data. Please check the relevant third party controller’s privacy notice.
6. Do we transfer your personal data outside of the UK?
There may be occasions where it is necessary for us to transfer your personal data to a country outside of the United Kingdom (“UK”). It may also be processed by third parties outside the UK who work for us (or for one of our service providers). It is possible that the country concerned may not be deemed to provide a similar level of protection for individuals’ rights in relation to their personal data as in the UK.
Where we transfer your personal data to other National Express Group companies and/or third parties who process your personal data on our behalf in countries outside the UK we use one of the following safeguards:
- we will transfer to a non-UK Country whose privacy laws ensure an appropriate level of protection for personal data; or
- we will put in place appropriate contracts with a third-party that means they must offer a similar level of protection for personal data as the UK.
7. For how long will we process your personal data?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including satisfying any legal, or reporting requirements in respect of our relationship with you. Where we process your personal data to fulfil:
- a legal obligation, we will process such personal data for so long as necessary to fulfil that obligation; or Where we process your personal data based on:
- our legitimate interest, we will process such personal data for so long as necessary to achieve that legitimate interest, which will typically be for 6 years after we collect your personal data or the last time we use your personal data (or longer in relation to any legal claims that might arise having regard to the nature of any potential claims and the limitation of liability periods that apply to them) We will also process your personal data for as long as necessary to respond to, manage and investigate any incident. We will also retain your personal data for at least six (6) years from the date of the incident, or if later, the date on which all regulatory investigations and legal claims or potential legal claims relating to the incident have been fully and finally concluded, having regard to the nature of any potential claims and the limitation of liability periods that apply to them. We may also retain your personal data for longer if we cannot delete it for legal, regulatory or technical reasons.
8. What rights do you have in relation to your personal data?
You have a number of rights in relation to your personal data. These include the right, subject to exceptions, to:
- access your personal data
- request the rectification or erasure of your personal data
- request restrictions on the processing of your personal data
- object to our processing of your personal data If you wish to exercise any of these rights please contact the National Express UK Data Protection Officer.
9. What should you do if you have any questions or complaints?
If you have any questions or complaints about how we process your personal data, or otherwise about the matters set out in this privacy notice, please contact the National Express UK Data Protection Officer at:
● Address: Data Protection Officer, National Express, National Express House, Birmingham Coach Station, Mill Lane, Digbeth, Birmingham B5 6DD or
● Email address: data.protection@nationalexpress.com
You also have the right to complain at any time to the UK Information Commissioner's Office about how we use your personal data and can contact them on their helpline: 0303 123 1113 or website at https://ico.org.uk/