Prepair is the system of record for last-mile fleets. Operational data, vehicle history and personal data of drivers and fleet staff sit with us. Here you will find the security controls behind the platform, how we handle personal data, which subprocessors are involved, and how to request the documents that are not public.
Last updated 24 September 2026. Material changes are recorded in the change log.
Our information security management system is certified to ISO/IEC 27001:2022 by TÜV NORD, with a formally appointed Security Officer and an annual internal and external audit cycle.
Certified since 17 September 2026 · CERT-003280-TNWe process personal data as a processor on our customers' documented instructions, under a Data Protection Agreement concluded in accordance with Article 28(3) GDPR.
Operating in line with the GDPRThe controls below are the ones described in the technical and organisational measures annex to our Data Protection Agreement, and are maintained within our ISMS. The last two cards set out how personal data is governed.
A number of supporting services operate outside the EEA, for transactional email, network protection and data processing support. Each is listed under Subprocessors with its transfer mechanism.
Authentication in the Driver App may be vehicle-based rather than individual-based, depending on the customer's configuration. We state this explicitly because it affects what platform records can and cannot evidence about an individual.
Backups are accessible only to Prepair and its authorised subprocessors. Customers can request written confirmation of the most recent restore test.
Software development is carried out by a dedicated development partner under contract, managed within our ISMS as part of the supply chain, including a data processing agreement and periodic supplier evaluation.
The customer determines the purposes of processing, which is why requests from data subjects are routed to them rather than answered by us.
Not processed: special categories of personal data within the meaning of Article 9 GDPR, such as health or biometric data, and data relating to criminal convictions or offences. Customers are asked not to submit these through the platform.
Individuals may incidentally be visible in photographs. Our policy is to keep people out of frame where reasonably possible, and this is communicated to users in our Terms of Service.
We notify the customer without undue delay and in any event within 24 hours of becoming aware of a personal data breach, including the nature of the breach, the likely consequences, and the measures taken or proposed. Where not all information is available within that period, we provide the remainder as soon as reasonably possible.
The customer remains responsible for notifying the supervisory authority and, where required, data subjects. We provide reasonable assistance.
The third parties we engage to process personal data in connection with the platform, as of 5 August 2026. We notify customers of any intended addition or replacement at least 30 days in advance, and customers can object on reasonable data protection grounds within 14 days. To join the notification list, or to change who receives it, email [email protected].
| Subprocessor | Role | Location | Outside EEA | Transfer mechanism |
|---|---|---|---|---|
| Microsoft Ireland Operating Microsoft Azure | Hosting and infrastructure for the platform | EU, West Europe (Netherlands) | No | Not applicable |
| about:blankNamed in our Data Protection Agreement, available on request | Software development, maintenance and support, with access to the production environment | Netherlands | No | Not applicable |
| Microsoft Ireland Operating Microsoft 365 | Business email and support correspondence | EU | No | Not applicable |
| HubSpot | CRM and support ticketing, including ticket content and attachments | EU and United States | Yes | Standard Contractual Clauses, HubSpot Data Processing Agreement |
| Twilio SendGrid | Delivery of transactional email notifications | United States | Yes | Standard Contractual Clauses, Twilio Data Protection Addendum |
| CQ | Damage-data processing support for the platform | United Kingdom | Yes | UK adequacy decision |
| Cloudflare | Content delivery, security and DDoS protection | United States, global network | Yes | Standard Contractual Clauses |
| Integration partners | Integration and data exchange, where configured by the customer | EU | No | Not applicable |
What we aim for, how it is measured, and what we ask of you.
We target 99.8% platform availability, measured monthly. This is a service objective rather than a guaranteed result. Availability is sampled automatically at five-minute intervals.
Where maintenance is planned, we aim to carry it out outside office hours and to notify customers at least five days in advance.
The applicable Service Level Agreement sets out how availability is measured, how errors are prioritised, and what response and recovery times apply per priority level.
Because pre-shift vehicle checks happen at the start of a shift, we recommend that every customer keeps a documented fallback procedure, so that checks can be recorded by other means and entered afterwards if the platform is not reachable at that moment.
Responsibility for ensuring that a vehicle is roadworthy remains with the customer at all times, as set out in our Terms of Service.
Not everything is public. Request what you need, or tell us about something we should fix.
Request these via [email protected]. We may ask for a mutual non-disclosure agreement before sharing audit material.
If you believe you have found a security vulnerability in our platform or website, we would like to hear from you. Email [email protected] with a description of the issue, the steps needed to reproduce it, and how we can reach you.
We ask that you give us reasonable time to investigate and remediate before disclosing publicly, that you do not access, modify or delete data belonging to others, that you do not degrade the service for other users, and that you do not run automated scanning that places load on our infrastructure. In return, we will confirm receipt, keep you informed of progress, credit you if you would like that, and will not pursue legal action against researchers who act in good faith and within these limits.
Please do not use this address for support questions or requests about your own personal data. For those, contact [email protected] or the organisation that granted your platform access.
Material changes to this page, and to the subprocessor list in particular, are recorded here.
| Date | Change |
|---|---|
| 24 September 2026 | ISO/IEC 27001:2022 certification added: certified by TÜV NORD since 17 September 2026, certificate CERT-003280-TN. |
| 5 August 2026 | First publication of this page. |