Less downtime. More progress.

Trust Center

Prepair is the system of record for last-mile fleets. Operational data, vehicle history and personal data of drivers and fleet staff sit with us. Here you will find the security controls behind the platform, how we handle personal data, which subprocessors are involved, and how to request the documents that are not public.

Compliance

Last updated 24 September 2026. Material changes are recorded in the change log.

TÜV NORD - ISO/IEC 27001:2022

ISO/IEC 27001:2022

Our information security management system is certified to ISO/IEC 27001:2022 by TÜV NORD, with a formally appointed Security Officer and an annual internal and external audit cycle.

Certified since 17 September 2026 · CERT-003280-TN
GDPR / AVG

GDPR

We process personal data as a processor on our customers' documented instructions, under a Data Protection Agreement concluded in accordance with Article 28(3) GDPR.

Operating in line with the GDPR
Hosting
Microsoft Azure, West Europe
Data residency
Production and staging in the EEA
Encryption
TLS 1.2+ and AES-256
Availability target
99.8% per month
Breach notification
Within 24 hours
Backup recovery window
Point in time, 7 days

Security and data protection

The controls below are the ones described in the technical and organisational measures annex to our Data Protection Agreement, and are maintained within our ISMS. The last two cards set out how personal data is governed.

Infrastructure and hosting

  • Hosted on Microsoft Azure, West Europe (Netherlands)
  • Production and staging environments within the EEA
  • Separated development, test, acceptance and production environments
  • Per-tenant data segregation
  • TLS 1.2 or higher in transit, AES-256 at rest
  • Critical infrastructure patches applied within 48 hours of release

A number of supporting services operate outside the EEA, for transactional email, network protection and data processing support. Each is listed under Subprocessors with its transfer mechanism.

Access and identity

  • Role-based access control on least-privilege principles
  • Roles aligned to the platform model: fleet owner, fleet manager, teamlead, plusser, driver, supplier, administrator
  • Multi-factor authentication where technically supported
  • Single sign-on via OIDC where a customer has configured it
  • Administrative access to production restricted to named individuals and logged

Authentication in the Driver App may be vehicle-based rather than individual-based, depending on the customer's configuration. We state this explicitly because it affects what platform records can and cannot evidence about an individual.

Resilience and monitoring

  • Daily backups, stored redundantly within the EEA
  • Point-in-time recovery within a rolling 7-day window
  • Long-term retention backups for statutory retention and audit
  • Restore procedures tested periodically under our ISMS
  • Application, access and administrative logging
  • Automated availability monitoring at five-minute intervals
  • Security logs retained 6 to 12 months

Backups are accessible only to Prepair and its authorised subprocessors. Customers can request written confirmation of the most recent restore test.

Organisation and supply chain

  • ISMS under ISO/IEC 27001:2022 with an appointed Security Officer
  • Documented information security policy, communicated to employees and relevant external parties
  • Confidentiality obligations for employees and contractors, and NDAs with any party that can access confidential data
  • Documented incident management and personal data breach procedures with defined escalation
  • Internal and external ISMS audits on an annual cycle
  • Suppliers assessed on defined criteria and re-evaluated periodically
  • Versioned source control, documented releases and acceptance criteria for changes

Software development is carried out by a dedicated development partner under contract, managed within our ISMS as part of the supply chain, including a data processing agreement and periodic supplier evaluation.

Data protection roles

  • The customer is the controller, Prepair is the processor
  • Data Protection Agreement concluded in accordance with Article 28(3) GDPR
  • Personal data processed only on the customer's documented instructions
  • Data subject requests forwarded to the customer without undue delay
  • Subprocessor changes notified 30 days in advance, with a right to object

The customer determines the purposes of processing, which is why requests from data subjects are routed to them rather than answered by us.

What we process, and for how long

  • Whose data: the customer's drivers, teamleads, fleet managers and other authorised users, and where applicable contact persons at repair partners
  • Account and identity: name, business email address, optional telephone number, role, user ID, optional personnel number, and authentication status
  • Operational records: audit trail of user, action and timestamp, vehicle and trip context, photographs of vehicle, cargo space and cabin condition, and user-entered notes on checks, damages and defects
  • Support: contact details, ticket content and attachments
  • Retention: set per data category in the Data Protection Agreement and configurable within limits

Not processed: special categories of personal data within the meaning of Article 9 GDPR, such as health or biometric data, and data relating to criminal convictions or offences. Customers are asked not to submit these through the platform.

Individuals may incidentally be visible in photographs. Our policy is to keep people out of frame where reasonably possible, and this is communicated to users in our Terms of Service.

Personal data breaches

We notify the customer without undue delay and in any event within 24 hours of becoming aware of a personal data breach, including the nature of the breach, the likely consequences, and the measures taken or proposed. Where not all information is available within that period, we provide the remainder as soon as reasonably possible.

The customer remains responsible for notifying the supervisory authority and, where required, data subjects. We provide reasonable assistance.

Subprocessors

The third parties we engage to process personal data in connection with the platform, as of 5 August 2026. We notify customers of any intended addition or replacement at least 30 days in advance, and customers can object on reasonable data protection grounds within 14 days. To join the notification list, or to change who receives it, email [email protected].

SubprocessorRoleLocationOutside EEATransfer mechanism
Microsoft Ireland Operating Microsoft AzureHosting and infrastructure for the platformEU, West Europe (Netherlands)NoNot applicable
about:blankNamed in our Data Protection Agreement, available on requestSoftware development, maintenance and support, with access to the production environmentNetherlandsNoNot applicable
Microsoft Ireland Operating Microsoft 365Business email and support correspondenceEUNoNot applicable
HubSpotCRM and support ticketing, including ticket content and attachmentsEU and United StatesYesStandard Contractual Clauses, HubSpot Data Processing Agreement
Twilio SendGridDelivery of transactional email notificationsUnited StatesYesStandard Contractual Clauses, Twilio Data Protection Addendum
CQ Damage-data processing support for the platformUnited KingdomYesUK adequacy decision
CloudflareContent delivery, security and DDoS protectionUnited States, global networkYesStandard Contractual Clauses
Integration partnersIntegration and data exchange, where configured by the customerEUNoNot applicable

Availability, maintenance and support

What we aim for, how it is measured, and what we ask of you.

Availability

We target 99.8% platform availability, measured monthly. This is a service objective rather than a guaranteed result. Availability is sampled automatically at five-minute intervals.

Maintenance

Where maintenance is planned, we aim to carry it out outside office hours and to notify customers at least five days in advance.

Service levels

The applicable Service Level Agreement sets out how availability is measured, how errors are prioritised, and what response and recovery times apply per priority level.

Keep a fallback for the start of a shift

Because pre-shift vehicle checks happen at the start of a shift, we recommend that every customer keeps a documented fallback procedure, so that checks can be recorded by other means and entered afterwards if the platform is not reachable at that moment.

Responsibility for ensuring that a vehicle is roadworthy remains with the customer at all times, as set out in our Terms of Service.

Documents and reporting

Not everything is public. Request what you need, or tell us about something we should fix.

Available on request

  • Data Protection Agreement, including processing description, technical and organisational measures and subprocessor list
  • Service Level Agreement
  • ISO/IEC 27001 certificate and summary audit report
  • Confirmation of the most recent backup restore test
  • Information security policy summary

Request these via [email protected]. We may ask for a mutual non-disclosure agreement before sharing audit material.

Reporting a vulnerability

If you believe you have found a security vulnerability in our platform or website, we would like to hear from you. Email [email protected] with a description of the issue, the steps needed to reproduce it, and how we can reach you.

We ask that you give us reasonable time to investigate and remediate before disclosing publicly, that you do not access, modify or delete data belonging to others, that you do not degrade the service for other users, and that you do not run automated scanning that places load on our infrastructure. In return, we will confirm receipt, keep you informed of progress, credit you if you would like that, and will not pursue legal action against researchers who act in good faith and within these limits.

Please do not use this address for support questions or requests about your own personal data. For those, contact [email protected] or the organisation that granted your platform access.

Change log

Material changes to this page, and to the subprocessor list in particular, are recorded here.

DateChange
24 September 2026ISO/IEC 27001:2022 certification added: certified by TÜV NORD since 17 September 2026, certificate CERT-003280-TN.
5 August 2026First publication of this page.