Legal

Privacy Policy

Last updated: 12 August 2026

This Privacy Policy explains how Stephen Michael Mornington ("I", "me", "my"; and where the site says "we", "us" or "Apex", that means the same sole trader) collects, uses, stores and shares personal data when you use:

  • the main website apexvehiclesolutions.co.uk (and www);
  • the dealer / ECU file portal and related services on apexfiles.co.uk (and www / subdomains used for the portal);
  • customer, dealer, technician and staff portals;
  • mobile field services (e.g. remapping, diagnostics, locksmith);
  • email, phone and other communications about those services.

I trade as Apex Vehicle Solutions. I am a sole trader in the United Kingdom. I am not a limited company. I am not any third-party limited company that may use a similar name (including any "Apex Vehicle Solutions" company that is not me).

Personal data is processed under the UK GDPR and the Data Protection Act 2018. Electronic marketing follows the Privacy and Electronic Communications Regulations (PECR).

1. Who I am (data controller)

For UK data protection law, the data controller is:

  • Legal name: Stephen Michael Mornington
  • Trading as: Apex Vehicle Solutions
  • Business status: Sole trader — United Kingdom (not a limited company)
  • Business / correspondence address: 135 Ashford Road, Eastbourne, East Sussex, BN21 3UA, United Kingdom
  • Main website: apexvehiclesolutions.co.uk
  • Dealer / file portal domain: apexfiles.co.uk
  • ICO data protection fee / registration: Not yet registered. I am arranging the ICO data protection fee as a sole trader. Until registration is complete, privacy requests still go to the contact details below. See ico.org.uk.
  • Privacy / contact email: apexvehiclesolutions@outlook.com
  • Phone: 07342 340449

I have not appointed a Data Protection Officer (DPO). Privacy requests are handled using the contact details above.

Name clarity: Branding such as "Apex" or "Apex Vehicle Solutions" on these sites refers only to my sole-trader business. It does not mean I am incorporated as, owned by, or the same legal person as any other organisation with a similar name.

2. Websites and portals covered

  • apexvehiclesolutions.co.uk — public marketing site, bookings information, coverage tools, customer-facing content and linked portals where hosted there.
  • apexfiles.co.uk — dealer / trade ECU file portal, credits, file jobs and related account tools (including www or portal hostnames on that domain).
  • Any staff, customer or technician portal operated as part of the same platform and linked from those domains.

The same controller and this notice apply across both domains unless a specific page says otherwise.

3. Personal data I collect

Depending on how you use the services, I may process:

  • Identity & contact: name, email, phone, company name (if trade), postal address, postcode.
  • Account & security: login email, password (stored as a secure hash, not plain text), role (customer / dealer / technician / staff), account status, login and lockout-related security data.
  • Vehicle & job data: registration (VRM), make/model where provided, service type (remapping, diagnostics, locksmith, etc.), booking times, site address, notes, job status and field notes.
  • Locksmith / security-related: information needed to check legitimate ownership or authority before security work. Work may be refused if this cannot be verified.
  • Trade / dealer (apexfiles): business details, credit balance and ledger, ECU file job metadata and history (you should keep your own backups of original files).
  • Technicians: application answers, skills, base postcode, coverage radius, approximate sector location for coverage tools, portal activity.
  • Payment: amount, currency, payment status, billing name/email. Card data is handled by the payment provider (e.g. Stripe); I do not store full card PAN on my servers.
  • Technical: IP address, device/browser type, pages viewed, referrer, logs, cookies and similar identifiers.
  • Communications: emails, form messages, support correspondence, relevant call notes.

I do not intentionally collect special category data (e.g. health, biometrics for identification) as part of standard services. Please avoid putting such data in free-text notes unless strictly necessary.

4. How I collect data

  • Directly from you (register, book, apply, contact forms, portal use, phone/email).
  • Automatically when you use the sites (security logs, cookies, diagnostics).
  • From payment providers when you pay or buy credits.
  • From assigned field technicians or operational tools while delivering a job.
  • From limited public sources where lawful and needed (e.g. basic business checks).

5. Why I use your data (purposes & lawful bases)

PurposeLawful basis
Accounts, sign-in, role-based access, securityContract (Art. 6(1)(b)); legitimate interests — security (Art. 6(1)(f))
Bookings, technician assignment, mobile visits, job statusContract (Art. 6(1)(b))
Ownership / authority checks before locksmith or security-sensitive workLegal obligation and/or legitimate interests — prevent crime & fraud (Art. 6(1)(c)/(f))
Payments and dealer credit purchases (including on apexfiles.co.uk)Contract (Art. 6(1)(b)); legal obligation — tax/accounting (Art. 6(1)(c))
Trade ECU file jobs (upload, process, download, support)Contract (Art. 6(1)(b))
Technician applications, approval, coverage matching, field portalContract / steps prior to contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Public coverage checker (postcode → nearby tech sectors)Legitimate interests — show service availability (Art. 6(1)(f))
Service messages (bookings, job updates, security alerts)Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Marketing email/SMS (only if allowed)Consent (Art. 6(1)(a)) and PECR; or PECR soft opt-in where it applies
Site security, abuse prevention, limited analyticsLegitimate interests (Art. 6(1)(f))
Law, insurers, legal claims, regulatorsLegal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))

Where I rely on legitimate interests, I balance those against your rights. You may object (see Your rights). Where I rely on consent, you may withdraw it at any time without affecting earlier lawful processing.

6. Portals and roles

  • Customers — bookings, vehicles, service history.
  • Dealers — trade profile, credits and file jobs (primarily via apexfiles.co.uk).
  • Technicians — application data, coverage, assigned jobs. Public coverage tools use approximate sector locations, not full home addresses.
  • Staff users (if any) — operational access under internal controls.

7. Who I share data with

I do not sell your personal data. I may share data with:

  • Field technicians / subcontractors assigned to a job (details needed to attend);
  • Payment processors (e.g. Stripe);
  • Hosting, database, email and infrastructure providers acting as processors;
  • Postcode / geocoding services for coverage and location matching;
  • Professional advisers and insurers where needed;
  • Police, courts or regulators where required by law or to prevent crime;
  • A buyer only if the sole-trader business is sold or transferred, with appropriate safeguards.

8. International transfers

Services are aimed at the United Kingdom. Some providers (hosting, email, payments, CDN) may process data in the EEA, US or elsewhere. Where personal data leaves the UK, I use a lawful transfer mechanism under UK GDPR Chapter V where required (for example UK adequacy regulations, the UK IDTA / Addendum to EU SCCs, or other permitted safeguards).

9. How long I keep data

  • Account data — while active, then a short wind-down unless law requires longer.
  • Booking / job records — often up to about 6 years after the job (claims / tax).
  • Dealer credit and invoice records — usually about 6 years for UK tax/accounting.
  • Unsuccessful technician applications — limited period (e.g. up to 12 months) unless you agree longer.
  • Successful technician engagement data — while engaged and a reasonable period after.
  • Security logs — shorter operational windows unless investigating an incident.
  • Marketing opt-out lists — as long as needed to honour your choice.

10. Security

  • TLS encryption in transit for the websites and portals;
  • Hashed passwords;
  • Role-based access control;
  • Abuse protections (e.g. lockouts) where enabled;
  • Least-privilege access for processors;
  • Breach assessment and, where UK GDPR requires, notification to the ICO and affected individuals.

11. Cookies

Cookies and similar technologies may keep you signed in, secure the session, remember preferences, support payments, and (if enabled) measure performance. Strictly necessary cookies do not need consent. Non-essential cookies are used only with consent where PECR requires it. See also the Cookie Policy.

12. Marketing

Electronic marketing (email/SMS) is only sent where PECR allows — usually with consent, or soft opt-in for similar products where you are an existing customer and can refuse easily. Marketing messages include an unsubscribe option. Messages about bookings, security or your account are service messages, not marketing.

13. Your rights

Under UK GDPR you can ask to:

  • Be informed (this notice);
  • Access your personal data;
  • Rectify inaccurate data;
  • Erase data in certain cases;
  • Restrict processing in certain cases;
  • Receive data portability where the rules allow;
  • Object to legitimate-interests processing and to direct marketing;
  • Withdraw consent where processing is based on consent;
  • Complain to the ICO (section 16).

Coverage matching and job assignment are operational tools and can be reviewed — contact me if an outcome affects you. I aim to respond to rights requests within one month (or longer if the law allows for complex requests). I may need to verify your identity.

14. Children

Services are aimed at adults and businesses. I do not knowingly offer accounts to under-18s. If you believe a child's data has been provided inappropriately, contact me so it can be removed where required.

15. Changes

This notice may be updated from time to time. The "Last updated" date will change. Important changes may be highlighted on the site or notified to account holders where appropriate. When I complete ICO registration, this page will be updated with the registration reference.

16. Contact and complaints

Privacy questions or requests:

  • Stephen Michael Morningtontrading as Apex Vehicle Solutions
  • Email: apexvehiclesolutions@outlook.com
  • Phone: 07342 340449
  • Post: 135 Ashford Road, Eastbourne, East Sussex, BN21 3UA, United Kingdom
  • Web: apexvehiclesolutions.co.uk · Portal: apexfiles.co.uk

You can also complain to the UK regulator:

  • Information Commissioner's Office (ICO)
  • ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Please contact me first so I can try to resolve your concern quickly.

Controller summary

Stephen Michael Mornington, sole trader, trading as Apex Vehicle Solutions. Address: 135 Ashford Road, Eastbourne, BN21 3UA. Sites: apexvehiclesolutions.co.uk (main) and apexfiles.co.uk (dealer/file portal). Not a limited company. Not any third-party company with a similar name. ICO registration: not yet completed.