1. Who We Are
Data Controller:
Onward 2 Upward Ltd trading as Why Knott Hire
56 Woodland Avenue, Pencoed, Bridgend, CF35 6UP
Company registration: 12707392
ICO registration number: ZB575356
Contact for data protection queries:
Email: info@whyknotthire.co.uk · Phone: 07983 896389
We are a motorhome hire company based in Bridgend, South Wales. This policy explains how we collect, use, store and protect your personal data when you make a booking, use our online booking system, interact with our AI chat assistant, or otherwise engage with our services.
2. What Data We Collect and Why
2.1 Booking and Customer Data
When you make a booking, we collect:
| Data | Purpose | Lawful Basis |
|---|---|---|
| Full name and surname | To identify you and create your booking | Contract |
| Email address | To send booking confirmations, receipts, reminders and documents | Contract |
| Phone/mobile number | To contact you about your booking | Contract |
| Home address | Required for our hire terms and for legal documents | Contract |
| Date of birth | To verify you meet our minimum age requirement (25 years) | Contract / Legal obligation |
| Party size and composition | To ensure vehicle suitability and safety compliance | Contract |
| Booking dates, vehicle choice, extras selected | To fulfil your hire | Contract |
| Collection and return time preferences | To arrange your hire | Contract |
| Additional driver names and details | To name drivers on the rental agreement and verify entitlement | Contract / Legal obligation |
2.2 Driving Licence and Identity Data
We are legally required to verify that all drivers meet our hire requirements. We collect:
| Data | Purpose | Lawful Basis |
|---|---|---|
| Driving licence (front and back photograph) | To verify licence validity, category and identity | Legal obligation / Contract |
| DVLA check code (share code) | To electronically verify entitlement, penalty points and disqualifications via DVLA Access to Driver Data (ADD) | Legal obligation |
| Proof of address documents (photographs) | To verify residency and identity | Contract / Legal obligation |
| DVLA licence check result | To confirm eligibility to hire | Legal obligation |
| Last 8 digits of driving licence number | To cross-reference the DVLA check | Legal obligation |
DVLA ADD: Where we use the DVLA's Access to Driver Data API, we are a registered Controller. Data obtained from the DVLA is used solely to verify driver eligibility. It is not shared with third parties and is retained only for the duration required below.
2.3 Payment Data
| Data | Purpose | Lawful Basis |
|---|---|---|
| Payment card details (tokenised) | To process deposit, balance (including monthly Pay Monthly instalments where chosen), and security deposit payments | Contract |
| Transaction IDs and payment status | To maintain accurate financial records | Contract / Legal obligation |
| Payment history per booking | For invoicing, receipts and VAT records | Legal obligation |
We do not store your full card number. Card data is tokenised by Opayo (Elavon Financial Services Ltd) and we only retain the token and transaction reference. Opayo is PCI DSS compliant. Where you choose to pay by monthly instalments (Pay Monthly), Opayo securely retains a card token so we can take each agreed instalment automatically under your Continuous Payment Authority, until the plan is complete, cancelled by you, or cancelled with your card issuer.
2.4 Communications Data
| Data | Purpose | Lawful Basis |
|---|---|---|
| Email correspondence | To communicate about your booking | Contract |
| AI chat conversation content | To provide customer support | Legitimate interests |
| WhatsApp messages (where used) | To communicate about your booking | Legitimate interests / Contract |
| Email open & click tracking | Our emails may contain a small invisible image and tracked links that tell us, in aggregate, whether emails were opened and which links were clicked, so we can improve our communications. We do not use this to build individual profiles. | Legitimate interests |
| Notification delivery records | We keep a record of which notifications we attempted to send you and on which channel (email, WhatsApp or push) and whether they succeeded, so we can diagnose delivery problems. No message content is stored in these records. | Legitimate interests / Contract |
2.5 Technical and Usage Data
| Data | Purpose | Lawful Basis |
|---|---|---|
| IP address (server logs) | Security, fraud prevention, system integrity | Legitimate interests |
| Booking system usage data | To operate and improve the booking system | Legitimate interests |
| First-party analytics events (pages and vehicles viewed, searches, booking-funnel steps) | To understand how the booking site is used so we can improve it. We always record this anonymously and in aggregate (a temporary per-visit identifier only, no personal data); we only link a visit to a returning device or to your booking if you accept analytics. | Legitimate interests (anonymous aggregate) / Consent (identified) |
3. How We Use Your Data
We use your personal data to:
- Process and manage your motorhome hire booking
- Verify that all named drivers are legally entitled to drive our vehicles
- Process payments and issue VAT receipts and invoices
- Send you booking confirmations, payment receipts, pre-collection reminders and return instructions
- Generate legal hire documents including the Rental Agreement, VE103 letter of authorisation and (where applicable) RAC Vehicle on Hire application
- Notify our team of new bookings and payments for operational purposes
- Respond to your enquiries via chat, email or WhatsApp
- Comply with our legal and regulatory obligations
- Prevent fraud and protect the security of our business and vehicles
We do not use your data for automated decision-making that has legal or similarly significant effects, except for licence eligibility checks (which you can request a human review of at any time).
4. Data Sharing and Third-Party Processors
We share your data only where necessary with trusted third parties acting as data processors on our behalf. All processors are bound by data processing agreements.
| Processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase Inc. | Database storage of booking records, uploaded documents and conversation history | UK (London region) | UK-region project; SOC 2 Type II; SCCs/IDTA cover any support access from outside the UK |
| Vercel Inc. | Hosting of booking system and serverless functions; cookieless Web Analytics (aggregated, anonymised usage statistics, only with your consent) | UK (London region) | Functions pinned to London (lhr1); ISO 27001; SCCs/IDTA |
| Cloudflare, Inc. | Content delivery network (CDN), DNS and security (DDoS protection, web application firewall and TLS encryption) for our public website. Processes visitors' connection data (such as IP address) to route, cache and protect page requests. Our booking system and customer portal are served directly and are not routed through Cloudflare's cache. | US (global edge network; UK visitors are normally served from the London edge) | UK IDTA / EU SCCs; EU–US Data Privacy Framework; ISO 27001; strictly-necessary security processing only — no advertising or tracking |
| Opayo / Elavon Financial Services Ltd | Payment processing and card tokenisation | UK / EU | PCI DSS Level 1; FCA regulated |
| IONOS SE | Email delivery (SMTP) | EU (Germany) | GDPR-compliant EU processor |
| Anthropic PBC | AI chat assistant (Claude) — processes message content | US | SCCs; data not used for model training per enterprise terms |
| Google (Google Ireland Ltd / Google LLC) | Google Analytics — anonymised website‑usage statistics; and Google Ads — measuring whether an advertisement led to a booking. This includes “Enhanced Conversions”, where a one‑way hashed (irreversible) form of your email address and name is shared with Google solely to match a booking to an ad click. All of this happens only with your consent. | EU / US | Consent Mode v2 (advertising & analytics storage stay off unless you accept); customer data hashed (SHA‑256) in your browser before it is sent; SCCs / EU–US Data Privacy Framework |
| Microsoft (Microsoft Ireland Operations Ltd / Microsoft Corporation) | Microsoft Clarity — anonymised session replay and heatmaps showing how visitors move through the booking site so we can improve it; on-page text and anything you type are automatically masked. This happens only with your consent. | EU / US | Loaded only if you accept analytics cookies; text & form inputs masked by default; not used for advertising and not sold; SCCs / EU–US Data Privacy Framework |
| RAC Motoring Services | Vehicle on Hire (VE103) application for European travel | UK | Necessary for legal document processing |
| DVLA | Driving licence verification via Access to Driver Data | UK | UK Government; DVLA ADD agreement |
| Meta Platforms / WhatsApp | WhatsApp messaging (where used) | US / EU | SCCs; Meta DPA |
| Xero (Xero Limited) | Accounting & VAT invoicing — booking reference, customer name/address and invoice amounts are recorded for our bookkeeping (the refundable security deposit is never sent) | EU / US | Data processing agreement; SCCs; ISO 27001 |
| Prodigi (print-on-demand) | Printing & posting a physical gift card — recipient name & address (only when a hard-copy gift voucher is purchased) | UK / EU | Used solely to print & post the card; data processing agreement |
We do not sell your personal data to any third party. We do not share your data with any other organisation without your explicit consent, except where required by law.
5. Where Your Data Is Held and International Transfers
Your booking and customer data is hosted in the United Kingdom. Our database and uploaded documents (Supabase) and our application servers (Vercel) are configured to the UK (London) region, and our payment processor (Opayo / Elavon) and email provider (IONOS) operate in the UK / EU.
The principal transfer of data outside the UK is the content of AI chat messages, which is processed by Anthropic (United States) to generate replies. In addition, some of our processors are US-headquartered companies whose technical support staff may, exceptionally, access data from outside the UK. Where any personal data is transferred outside the UK, we ensure adequate safeguards are in place, including UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs), and transfers only to processors certified under appropriate frameworks (e.g. the UK–US Data Bridge where applicable).
Our public website (whyknotthire.co.uk) is delivered and protected through Cloudflare's content-delivery and security network. Cloudflare is a US-headquartered provider that operates a global network of edge servers; visitors in the UK are normally served from its London edge, and it processes visitors' connection data (such as IP addresses) only to deliver, cache and secure the website. Our booking system and customer portal (bookings.whyknotthire.co.uk) are served directly and are not routed through Cloudflare's cache, so your booking and customer data continues to be hosted in the UK as described above.
6. Document and File Storage
Photographs of driving licences and proof of address documents are uploaded by customers through the customer portal. These files are stored in a private, access-controlled storage bucket. Files are not publicly accessible, are only accessible to our administrative staff via authenticated access, and are deleted in accordance with our retention schedule (see Section 7).
7. How Long We Keep Your Data
| Data Category | Retention Period | Reason |
|---|---|---|
| Booking records (name, contact, dates, vehicle, payment status) | 7 years from date of hire | HMRC financial records requirement |
| VAT invoices and payment records | 7 years | Legal obligation (HMRC) |
| Driving licence photos and proof of address | 60 days from return date | To resolve any post-hire disputes |
| DVLA licence check results | 60 days from return date | Post-hire dispute resolution |
| Rental Agreement PDFs | 7 years | Legal obligation |
| AI chat transcripts | 90 days | Customer service quality; deleted on rolling basis |
| WhatsApp conversation threads | 30 days | Customer service purposes |
| Email correspondence | 3 years | Customer service and dispute resolution |
| Expired/unpaid bookings (no deposit within 48 hours) | 30 days then deleted | Operational necessity |
| Contact details kept for marketing | Until you unsubscribe | Only where you have opted into our mailing list |
After the relevant retention period, data is securely deleted from all systems.
We only retain your personal data for marketing if you have opted into our mailing list. Once a booking's mandatory 7-year financial-record period (HMRC) has elapsed, the personal data held against it is automatically erased unless you remain subscribed to our mailing list — we then keep only a non-identifying record (booking reference, dates and amounts) for statistics. You can unsubscribe at any time, after which we stop using your details for marketing.
8. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of access — request a copy of all personal data we hold about you (Subject Access Request). We will respond within one month.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — ask us to delete your data. We may need to retain certain data to comply with legal obligations (e.g. HMRC for 7 years).
- Right to restriction — ask us to restrict processing in certain circumstances.
- Right to data portability — request your booking data in a machine-readable format.
- Right to object — object to processing based on legitimate interests.
- Rights related to automated decision-making — request human review of any automated check (e.g. DVLA licence verification) that affects you.
- Right to withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at info@whyknotthire.co.uk or write to us at the address above. We will respond within 30 days. We may need to verify your identity before processing your request.
8.1 How to request deletion of your data
You can ask us to delete the personal data we hold about you — whether you use the Why Knott Hire website, customer portal, or our mobile app (published by Onward 2 Upward Ltd trading as Why Knott Hire).
To request deletion, do either of the following:
- Email info@whyknotthire.co.uk with the subject line "Data deletion request", including your name and (if you have one) your booking reference; or
- Write to us at: Onward 2 Upward Ltd, 56 Woodland Avenue, Pencoed, Bridgend, CF35 6UP.
We may ask you to verify your identity, and we will action your request within 30 days.
What is deleted: your booking and contact details (name, email, phone, address, date of birth), uploaded driving-licence and proof-of-address documents, condition/handover photos, app-notification (push) tokens, and any usage-analytics records associated with you.
What we must keep, and for how long: records we are legally required to retain — chiefly financial and payment transaction records, which we must keep for 7 years to meet HMRC and accounting obligations. These are securely deleted once that period ends. Card numbers are never stored by us (payments are handled by our payment processor).
9. AI Chat Assistant
Our website and customer portal include an AI-powered chat assistant built using Anthropic's Claude. Please be aware:
- Do not share sensitive financial information (card numbers, bank details) via the chat
- Chat messages may include your booking reference and relevant booking details where you have linked your booking
- Conversation content is processed by Anthropic's API in accordance with their data processing agreement
- Chat history is stored temporarily (up to 90 days) to maintain conversation context
- The AI assistant cannot make, change or cancel bookings, and cannot take payments
10. Security
- Encryption in transit: all data between your browser and our systems uses HTTPS/TLS encryption
- Network security: our public website is served through Cloudflare's content-delivery network, which provides TLS encryption, DDoS attack mitigation and a web application firewall
- Encryption at rest: personal data stored in our database is encrypted at rest
- Access controls: admin access requires authenticated login; document files are stored in a private bucket not accessible publicly
- Payment security: card data is handled exclusively by Opayo (PCI DSS Level 1 certified). We never see or store full card numbers
- API security: all API endpoints are protected by authentication tokens
- DVLA data security: we comply with all DVLA ADD security requirements including unique user IDs, robust password protocols and access controls
In the event of a personal data breach that poses a risk to your rights, we will notify the ICO within 72 hours and, where required, notify you directly.
11. Cookies
Our booking system uses essential session cookies to maintain your session while making a booking — these are always on and need no consent. With your consent, we also use Google Analytics cookies to understand how visitors use the booking site so we can improve it. You choose whether to allow analytics cookies via the banner shown when you arrive — Google Consent Mode v2 keeps analytics switched off unless you accept, and you can change your mind at any time. We also use Vercel Web Analytics, which is cookieless and collects only aggregated, anonymised usage statistics (such as page views, referrer, device type and country) — it is loaded only if you accept analytics, so choosing “Essential only” turns it off as well. With your consent, we also use Microsoft Clarity, which records anonymised, masked session replays and heatmaps so we can see where the booking site can be improved (it sets two first-party cookies and automatically hides on-page text and anything you type); like our analytics cookies it loads only if you accept, and choosing “Essential only” keeps it off. With your consent, we also use Google Ads cookies to measure whether an advertisement led to a booking and, where applicable, for remarketing; like our analytics cookies, these are set only if you accept via the banner, and choosing “Essential only” keeps them switched off. We do not set any advertising or cross-site tracking cookies without your consent.
Our public website is served through Cloudflare for security and performance. Cloudflare does not set advertising or tracking cookies; it only uses a strictly-necessary security cookie if it needs to verify that a request is genuine (for example to mitigate malicious or automated traffic), which requires no consent.
The customer portal (bookings.whyknotthire.co.uk) uses session cookies to keep you logged in, and authentication tokens stored locally in your browser to maintain your admin/customer session.
12. Children's Data
Our services are not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data about a child, please contact us immediately.
13. Changes to This Policy
We may update this policy from time to time to reflect changes in our services or legal requirements. We will post the updated policy on our website and, where changes are significant, notify you by email.
14. How to Complain
If you are unhappy with how we have handled your personal data, please contact us first at info@whyknotthire.co.uk.
If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): Website ico.org.uk · Helpline 0303 123 1113 · Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
If you are located in the European Union or EEA, you also have the right to lodge a complaint with the data protection supervisory authority in your country of residence. A list of EU/EEA authorities is available at edpb.europa.eu.
Affiliate links
In our trip guides and your booking portal we may show links to Pitchup.com to help you find a campsite for your trip. Using them is entirely optional, and we do not share your personal data with Pitchup. We currently earn no commission from these links; if that changes we will update this notice.