Privacy Policy
Last updated: May 2026
This Privacy Policy explains how Lisle Design Ltd (“we”, “us”, “our”) collects,
uses, and protects information when you use the following mobile applications:
- DigidownConnect
- DigidownGo
- DigidownBridge
- TachoReader
Lisle Design Ltd, Unit 10, Riverside House, 11 Luna Place, Dundee Technology Park, Dundee, DD2 1TP,
United Kingdom, is the data controller for the purposes of applicable data
protection law.
1. Overview of Services
The Applications provide tools for interacting with tachograph systems and
related vehicle data.
- TachoReader operates entirely on-device and does not transmit data to our servers.
- DigidownConnect and DigidownGo transmit files to our cloud services, which then forward those files, typically via email.
- DigidownBridge transmits real-time operational and driver-related data to our cloud services and may forward that data to third-party systems.
2. Data We Collect
Depending on which Application you use, we may process the following categories of data:
2.1 Personal Data
- Name, such as driver name
- Email address
2.2 Operational and Device Data
- Device identifiers
- IP address
- Timestamps
- Application usage data
- Diagnostic and log data
2.3 Vehicle and Driver Data
This applies primarily to DigidownBridge.
- Driver identification, such as driver name
- Driver behaviour data, such as driving events
- GPS location data, where enabled
2.4 File Data
- Tachograph files
- Other files uploaded through the Applications
3. How Data Is Used
We use the data described above to:
- Provide and operate the Applications
- Transmit files and data to user-designated recipients
- Forward data to third-party systems configured by the user
- Maintain system functionality and reliability
- Diagnose technical issues and provide support
We do not analyse driver behaviour data for profiling or decision-making
purposes. Data is processed only to deliver the functionality of the service.
4. How Data Flows Through Our Systems
Data collected by the Applications is transmitted to our cloud infrastructure
hosted on Microsoft Azure in the United Kingdom.
From there, data may be:
- Temporarily stored for processing
- Forwarded to third-party systems as configured by the user
- Sent via email using SendGrid
Where data is transmitted via email, this may involve transmission across
third-party networks outside our control.
5. Data Retention
We retain data only for as long as necessary to operate the service and
support users.
5.1 File Data
- By default, files are deleted immediately after successful transmission.
- Optional retention, if enabled by the user, is up to 30 days.
5.2 Real-Time Data - DigidownBridge
- Only the most recent uploaded data is stored.
- Historical real-time data is not retained.
- The most recent uploaded data may include GPS coordinates.
5.3 Logs
- Logs are stored in cloud systems for 7 days.
- Logs are then archived securely for up to 1 year.
5.4 Support Data
Support data is retained only as long as necessary to resolve technical
issues, unless a longer retention period is required for legal, security, or
operational reasons.
6. Legal Basis for Processing
We process personal data under the following legal bases:
- Legitimate interests: to operate, maintain, secure, and support our services, including diagnostics and technical support.
- Performance of a contract: where data processing is necessary to deliver functionality associated with purchased hardware or related services.
- Legal obligations: where applicable laws require us to retain or disclose data.
7. Data Sharing
We do not sell personal data.
We may share data only where necessary:
- With service providers supporting our infrastructure, including Microsoft Azure for hosting and SendGrid for email transmission.
- With third parties explicitly configured by the user to receive data.
All third parties process data on our behalf or under user direction and are
required to handle data securely.
8. International Transfers
Our primary infrastructure is located in the United Kingdom.
Where data is processed outside the United Kingdom, for example via
third-party services, we ensure appropriate safeguards are in place, such as
UK adequacy regulations or standard contractual clauses.
9. Data Security
We implement appropriate technical and organisational measures to protect
data, including:
- Encryption of data in transit
- Access controls and authentication
- Restricted data retention periods
No system can be guaranteed to be completely secure, but we take reasonable
steps to protect data.
10. Your Rights
Under UK data protection law, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Restrict processing
- Object to processing
- Request transfer of your data, where applicable
You also have the right to lodge a complaint with the UK Information
Commissioner’s Office if you believe your data has been handled improperly.
11. Children
These Applications are not intended for use by children, and we do not
knowingly collect data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted
within the Applications or on our website with a revised “Last updated” date.
13. Contact Us