1. UK and EU scope
The intended launch covers the UK and selected EU markets. UK GDPR and the Data Protection Act 2018, as amended including by the Data (Use and Access) Act 2025, apply where their scope is met. EU GDPR can also apply to an organisation outside the EU when it offers services to, or monitors the behaviour of, people in the EU.
Current onboarding remains UK-specific: it validates UK postcodes and displays GBP, miles and UK time. Publishing this page does not enable EU onboarding or settle country-specific employment, tax, ePrivacy or consumer requirements.
2. Who to contact about a record
- Business account information or platform security: contact UNLIMIT DIGITAL LTD.
- A delivery, payment record or driver shift entered by a takeaway: contact that takeaway first; it normally controls those records.
- If the responsible controller is unclear, write to the company with enough information to identify the takeaway and record. Do not include a password or full identity document.
3. The rights available to you
- Access your personal information and information about its use.
- Ask for inaccurate information to be corrected and for incomplete information to be completed.
- Request erasure or restriction when the legal conditions apply.
- Object to processing based on legitimate interests and to direct marketing.
- Request portable data where the legal requirements are met.
- Withdraw consent for processing based on consent, without affecting earlier lawful processing.
- Complain to the relevant supervisory authority and seek available remedies.
4. Making a request
Write to UNLIMIT DIGITAL LTD, FAO Data Protection, 31–33 Worcester Street, Gloucester, England, GL1 3AJ. State the right you wish to exercise, the account or takeaway involved, relevant dates and how we can reply. No particular wording or paid service is required.
Rights requests generally require a response without undue delay and within one month, subject to applicable rules on identity verification, clarification and permitted extensions. Where an extension is lawful, the controller must explain it within the initial period. The UK and EU rules must be applied separately where they differ.
A complete case-handling and deletion process is still a launch requirement. The shift CSV export is a business report, not a complete response to every individual’s access or portability request.
5. Data protection complaints
Use the same postal address, marked “Data protection complaint”. Explain the concern and preferred reply method. Under the current UK complaints requirements, controllers must offer an accessible complaint route, acknowledge complaints within thirty days, investigate appropriately and communicate the outcome without undue delay.
You can contact the ICO at ico.org.uk/make-a-complaint/ or find the competent EU/EEA authority through the EDPB directory. The EDPB itself does not handle ordinary individual complaints. The company still needs to nominate a monitored complaints owner before launch.
6. Driver monitoring safeguards
Takeaways must assess necessity and proportionality, give drivers clear notice, choose a valid lawful basis and consult workers or representatives where appropriate. A phone permission or employment-contract clause is not a substitute. Screen the proposed tracking for a data protection impact assessment and complete one before any processing likely to create high risk.
The API accepts locations only during active shifts. Closing a shift clears the stored position. Native controls and scheduled shift expiry are implemented; field-tested battery behaviour remains a release check. Optional, one-time availability sharing is a separate driver-initiated action with a fifteen-minute discovery lifetime. Do not introduce covert or off-shift tracking.
7. Accountability before launch
The company must document processing activities, security measures, retention, breach handling, controller–processor contracts and any international transfers. Assess whether EU representation under Article 27, a DPO, and the UK data protection fee are required. A UK registered office does not replace an EU representative where one is required.
This page explains the intended approach. dropLog. is not claiming GDPR certification, a completed DPIA, ISO certification or blanket legal compliance.
Official guidance & references
The sources below inform the review. They do not certify this product or replace the company’s operational responsibilities.
EU General Data Protection RegulationEDPB: controller and processor responsibilitiesICO: subject access guidanceICO: data protection complaints requirements, June 2026Find your European data protection authorityICO: monitoring workers