Privacy Policy
Last updated: 4 June 2026
1. Who we are and who this policy is for
This Privacy Policy describes how Lets.Tech ("we", "us", "our")
processes personal data in connection with the Lets.Tech Portal (the "Service"),
an automatic number plate recognition (ANPR) and vehicle access management
platform.
The Service is used by our business customers ("Clients", "you"). We
provision a Client account for each Client; the Client logs in to upload,
view and manage the personal data of the individuals whose vehicles are
captured by ANPR or who are otherwise recorded in the Client's vehicle
list ("End Users" — for example drivers, contractors, staff or visitors).
Controller / Processor status.
- In relation to End User personal data — including vehicle registration marks captured by ANPR, event timestamps and images, and the driver/keeper records the Client uploads — the Client is the Data Controller and we act as Data Processor on the Client's documented instructions.
- In relation to the Client's own account data — for example the email address used to log in, hashed passwords, authentication logs and audit trails of actions performed inside the Service — we act as Data Controller.
2. What personal data we process
2.1 Client account data (we are Controller)
- The Client's login email and one-way hashed password.
- The Client's role, permissions and the site(s) the Client is authorised to access.
- Authentication, session and audit log records (timestamps, IP address, user agent, actions performed within the Service).
- Communications the Client sends to us (support requests, password resets).
2.2 End User personal data (we are Processor; the Client is Controller)
- Vehicle registration marks captured by ANPR cameras at sites operated by the Client.
- Date, time, camera, direction of travel and event images associated with each capture.
- End User records uploaded by the Client by spreadsheet — including first name, last name, pass classification, hierarchy, company and vehicle registration mark.
- Derived presence and movement records (on site / off site state).
A vehicle registration mark is personal data under UK GDPR because it can
be linked to an identifiable individual (the registered keeper). Where the
Client uploads driver or staff names alongside plates, those rows are
personal data of the named End User.
3. Lawful bases for processing
3.1 Client account data (where we are Controller)
- Contract (Art. 6(1)(b)): to provide the Service to the Client under our agreement.
- Legitimate interests (Art. 6(1)(f)): to secure the Service and unauthorised access, maintain audit trails and protect the integrity of the data held in the Service. A Legitimate Interests Assessment ("LIA") is available on request.
- Legal obligation (Art. 6(1)(c)): where retention or disclosure is required by law, for example in response to a lawful request from law enforcement.
3.2 End User personal data (where we are Processor)
The Client is solely responsible for establishing the
lawful basis under Article 6 UK GDPR (and, where applicable, the condition
under Article 9) for the End User personal data the Client uploads to or
causes to be processed through the Service. The Client is also responsible
for providing the information required by Articles 13 and 14 to End Users
and for obtaining any consent required under the UK GDPR, the Data
Protection Act 2018, PECR or any other applicable law. We process such
data only on the Client's documented instructions.
4. Where data comes from
- Directly from the Client when the Client logs in or interacts with the Service.
- From ANPR cameras and edge devices installed at sites operated by the Client.
- From the Client itself, including via Excel spreadsheet upload of End User and vehicle records.
5. Who we share data with
- The Client and any further Client accounts the Client has asked us to provision for the same organisation, with access to the relevant site(s).
- Sub-processors engaged to provide hosting, storage, email delivery and operational support. A current list of sub-processors is available on request.
- Law enforcement, regulators or courts where we are legally required to disclose, or where the Client lawfully instructs us to disclose.
We do not sell personal data. We do not use personal data for advertising
or third-party profiling.
6. Retention
Retention periods for End User personal data are set by the Client as
Data Controller. Our default operational maximums, unless the Client
instructs otherwise, are:
- ANPR event captures and images: 30 days from end of event.
- End User records uploaded by the Client: retained until deleted by the Client or termination of the Service.
- Authentication and audit logs: 12 months.
- Client account records: for the duration of the account plus a reasonable period to address legal or contractual obligations.
On termination of the Client's contract with us, we will delete or return
End User personal data in accordance with the Client's instructions.
7. Data subject rights
Where we act as Controller in respect of the Client's own
account data, the Client may exercise the following rights under UK GDPR,
subject to the conditions and exemptions in law:
- Right of access (Article 15).
- Right to rectification (Article 16).
- Right to erasure (Article 17).
- Right to restriction of processing (Article 18).
- Right to data portability (Article 20).
- Right to object (Article 21), including to processing based on legitimate interests.
- Right not to be subject to solely automated decisions producing legal or similarly significant effects (Article 22).
Where we act as Processor in respect of End User personal
data, requests from End Users should be directed to the Client, who is
the Data Controller of that data. We will assist the Client in responding
to such requests as required by Article 28(3)(e) UK GDPR.
To exercise a right in relation to your Client account data, contact
jacob@letstech.co.uk. You also have the right
to lodge a complaint with the Information Commissioner's Office (ICO) at
ico.org.uk.
8. Security
We implement appropriate technical and organisational measures designed to
protect personal data against unauthorised or unlawful processing,
accidental loss, destruction or damage — including encryption in transit,
access controls, role-based authorisation, password hashing, audit
logging and segregated environments. No system is perfectly secure; we
follow recognised industry practice and review our controls on an ongoing
basis.
9. Automated processing
The Service uses automated optical character recognition to extract
vehicle registration marks from camera images and matches them against
vehicle lists uploaded by the Client. Matching results do not, in
themselves, constitute a decision producing legal effects on an End User —
any enforcement, access or operational decision is taken by the Client
with human involvement.
10. Changes to this policy
We may update this Privacy Policy from time to time. The "last updated"
date at the top of this page reflects the latest version. Material changes
will be brought to your attention through the Service.
11. Contact
Questions about this Privacy Policy should be sent to
jacob@letstech.co.uk.
← Back to login