PRIVACY POLICY
| Data controller | Dawa Exec Ltd |
|---|---|
| Company number | 17265271 |
| Registered office | 4 Forbes Street, London, E1 1PF, United Kingdom |
| TfL private hire operator licence | 12015 |
| VAT registration | GB 521 5818 03 |
| ICO registration | ZC168060 |
| Website | https://dawaexec.com |
| Privacy contact | Director, Dawa Exec Ltd – info@dawaexec.com |
| Telephone | +44 (0)20 3679 1998 |
| 24/7 booking / journey support | +44 (0)7417 514014 |
| Document owner | Director, Dawa Exec Ltd |
| Effective date | 14 September 2026 |
| Area | Typical legal basis | Position |
|---|---|---|
| Bookings | Contract / legal obligation / legitimate interests | Journey and passenger information needed to provide and evidence the service |
| Accounts & billing | Contract / legal obligation | Portal account, invoicing, payment and finance records |
| Accessibility data | Article 6 basis + appropriate special-category condition | Only what is reasonably needed for requested assistance/service |
| Service messages | Contract / legitimate interests / legal obligation | Operational messages are separate from marketing |
| Marketing | Consent or another lawful marketing basis where permitted | Opt-out and preferences respected |
1. Who we are and scope of this Privacy Policy
1.1 Dawa Exec Ltd (“Dawa”, “we”, “us” or “our”) is the data controller for the personal data described in this Privacy Policy where we decide why and how that information is processed.
1.2 This Privacy Policy applies to personal data processed in connection with Dawa Exec, Dawa Exec Chauffeurs, Dawa Cars, our websites and portals, private hire and chauffeur bookings, client accounts, billing, customer support, complaints and related business operations.
1.3 This Policy explains what personal data we collect, why we use it, the lawful bases we rely on, who we may share it with, how long we keep it and the rights available to individuals under applicable UK data protection law.
1.4 This Policy is intended to be read with our Terms & Conditions, Passenger Booking Contract, Cancellation & Refund Policy, Payment & Billing Information and Cookie Policy where relevant.
2. Personal data we may collect
2.1 Identity and contact data, such as name, email address, telephone number, postal or billing address and account reference.
2.2 Booking and journey data, such as pickup and destination details, stops, booking date and time, passenger name, journey instructions, travel references, flight or train details, vehicle or service class and booking status.
2.3 Account and organisation data, such as organisation name, company number, VAT number, billing information, purchase order or internal references, authorised users, permissions and account-facility information.
2.4 Payment and finance data, such as transaction references, payment status, invoice and receipt records, account exposure, refunds and credit notes. Where an approved payment provider handles card processing, Dawa does not need to store the Customer’s full card details itself.
2.5 Communication data, such as emails, portal messages, telephone or support records, complaint correspondence and other communications with Dawa. Where a telephone booking or journey-support call is recorded, the recording may also be personal data.
2.6 Operational and service data, such as chauffeur and vehicle allocation information, arrival and journey-status timestamps, cancellation or no-show records, incident information and lost-property records.
2.7 Technical and security data, such as account login records, IP address, device or browser information, authentication events, security logs and website or portal usage information where generated.
2.8 Accessibility or special-service information that a Customer or Passenger chooses to provide where it is needed to arrange or perform the requested service.
3. How we obtain personal data
3.1 We obtain personal data directly from Customers, Passengers, account administrators and authorised users when they create an account, request a quote, make or manage a Booking, pay an invoice, contact us or use our websites or portals.
3.2 Where one person or organisation makes a Booking for another Passenger, we may receive the Passenger’s details from the person or organisation making the Booking.
3.3 We may receive operational information from Chauffeurs and approved Partner Operators where this is necessary to perform, manage or evidence a Booking.
3.4 We may receive payment, fraud-prevention, technical or service information from payment providers, hosting or communications providers and other suppliers acting for or with Dawa.
3.5 Where appropriate, we may use public or business information, such as company information, to verify an organisation or administer a business account.
4. Why we use personal data and our lawful bases
4.1 Contract: we process personal data where necessary to take steps at a Customer’s request, accept and perform a Booking, provide journey services, operate a client account, issue invoices or receipts, process payments and provide service-related support.
4.2 Legal obligation: we process information where necessary to comply with applicable licensing, private hire, tax, accounting, data protection, safeguarding, regulatory or other legal obligations.
4.3 Legitimate interests: we may process information where reasonably necessary for interests such as fraud prevention, service quality, operational record-keeping, security, complaints handling, incident investigation, debt recovery and improving our systems, provided those interests are not overridden by the rights and interests of the individual.
4.4 Consent: we rely on consent where this is the appropriate lawful basis, including certain optional marketing, non-essential cookies or specific processing of special-category information where explicit consent is appropriate.
4.5 Vital interests: in exceptional circumstances, we may process information where this is necessary to protect a person’s life or physical safety.
4.6 Where more than one lawful basis could apply, we use the basis that properly reflects the purpose and circumstances of the processing. We do not rely on consent for core Booking processing where the information is needed to provide the requested service.
5. Accessibility, health information and other special-category data
5.1 Information about disability, health or mobility needs may reveal special-category personal data under UK data protection law.
5.2 We do not routinely request health information. Where a Passenger voluntarily provides disability, health or mobility information so that we can arrange requested assistance or an appropriate service, we use only the information reasonably needed for that purpose.
5.3 For the special-category element of that information, Dawa will identify and document an appropriate condition under Article 9 UK GDPR and other applicable law. This may include explicit consent where it can validly be obtained; another lawful special-category condition may apply where the law permits or requires it. Where Dawa relies on explicit consent, it will be obtained clearly and separately from general booking acceptance.
5.4 Withdrawing consent does not require Dawa to erase information that we must retain under another lawful obligation, or information that must be kept for an existing legal claim, regulatory requirement or other applicable lawful purpose.
5.5 We do not use accessibility information to discriminate against a Passenger or to avoid statutory accessibility duties.
6. Bookings made for another Passenger
6.1 A Customer may provide personal data about another Passenger where reasonably necessary to make or manage that Passenger’s Booking.
6.2 The Customer should provide only information that is reasonably necessary for the journey and, where appropriate, make the Passenger aware that their information has been provided to Dawa.
6.3 Where a child is travelling, Dawa may process limited information supplied by the responsible adult or organisation making the Booking where reasonably necessary to provide the journey safely and properly. Dawa does not invite children to create independent business accounts through the Client Portal.
6.4 Where Dawa obtains a Passenger’s personal data from another person, Dawa will provide the Passenger with the privacy information required by applicable data-protection law within the applicable timeframe, normally by providing or linking to this Policy in the first relevant communication with that Passenger, unless a lawful exception applies.
7. Service communications and marketing
7.1 Essential service communications are not marketing. They may include Booking confirmations, journey-status messages, Chauffeur or vehicle information, arrival notifications, security messages, payment or invoice information, complaints correspondence and other communications necessary to operate a Booking or account.
7.2 A Customer cannot opt out of an essential communication where the message is genuinely necessary to perform or administer an active Booking, account, payment or legal obligation.
7.3 Marketing communications, such as promotions, offers or information about new services, are separate from essential service communications.
7.4 Where marketing consent or another lawful marketing basis is required, Dawa will use the appropriate basis, provide a clear way to opt out and respect applicable marketing preferences.
7.5 We do not disguise promotional content as an essential service message.
8. Who we may share personal data with
8.1 Chauffeurs performing the relevant journey, where they need information to collect and transport the Passenger safely and properly.
8.2 Approved and appropriately licensed Partner Operators where Dawa lawfully arranges for another operator to perform all or part of a Booking.
8.3 Payment providers, banks and payment-processing suppliers where necessary to process, reconcile, refund or evidence payments.
8.4 Hosting, IT, portal, communications, security and support providers that process data for Dawa or provide systems we use to operate the service.
8.5 Professional advisers such as accountants, insurers and legal advisers where the information is reasonably required for their professional work.
8.6 Transport for London, HM Revenue & Customs, the police, courts, regulators or other public authorities where disclosure is required by law, necessary for a lawful regulatory purpose or otherwise legally permitted.
8.7 Couriers or other service providers where the Customer asks Dawa to arrange a related service, such as the return of lost property.
8.8 Dawa does not sell Customer or Passenger personal data.
9. Data shared with Chauffeurs and Partner Operators
9.1 Dawa aims to provide Chauffeurs and Partner Operators only with the information reasonably necessary to perform the relevant Booking.
9.2 That information may include the Passenger’s name, pickup and destination details, timing, relevant contact method, required journey instructions and information necessary to deliver an accessibility or special-service requirement.
9.3 Chauffeurs and Partner Operators are not ordinarily given unrelated account, billing or profile information merely because they are performing a journey.
9.4 Where a Booking is subcontracted to a Partner Operator, the information necessary to perform and manage that Booking may be shared with that operator in accordance with the Passenger Booking Contract and applicable law.
10. Payment information
10.1 Dawa may use an approved payment provider to process secure online payments. The payment provider may process card or transaction information under its own legal responsibilities and privacy terms.
10.2 Dawa does not routinely retain full card numbers or security codes in its own Booking or Client Portal records where those details are handled by the approved payment provider.
10.3 Dawa may retain payment references, amounts, status, refund information and other records reasonably necessary for reconciliation, accounting, fraud prevention and customer support.
11. International transfers
11.1 Some hosting, payment, communications, analytics or IT providers may process personal data outside the United Kingdom.
11.2 Where personal data is transferred internationally, Dawa will use a lawful transfer mechanism and appropriate safeguards where required by UK data protection law.
11.3 Safeguards may include a UK adequacy regulation or decision, approved contractual safeguards or another lawful transfer mechanism available under UK data protection law.
11.4 We do not transfer personal data outside the UK merely for convenience without considering the applicable legal requirements.
12. How long we keep personal data
12.1 Dawa does not keep personal data indefinitely by default. Different categories of records have different retention needs based on private hire regulation, tax and accounting rules, contractual requirements, complaints, legal claims and operational necessity.
12.2 Private hire Booking records are retained for at least 12 months from acceptance of the Booking, subject to any longer period that is lawfully required or reasonably necessary for a complaint, dispute, claim or other legitimate purpose.
12.3 Where Dawa records a private hire booking telephone call, the recording will normally be retained for 12 months in line with applicable operator requirements, unless a longer period is lawfully required or reasonably necessary.
12.4 Complaints and lost-property records are retained for at least 12 months in line with applicable TfL operator-record requirements, and may be kept longer where necessary to resolve or evidence the matter.
12.5 VAT invoices, credit notes and core tax or accounting records are normally retained for 6 years, or longer where applicable law requires it.
12.6 Active Client Portal and organisation profile data is retained while the account remains active. When an account closes, profile data is reviewed and information no longer needed is deleted or anonymised, while linked finance, Booking, complaint or legal records continue under their applicable retention periods.
12.7 Routine support communications are retained only for as long as reasonably necessary to deal with the request and protect Dawa’s legitimate interests.
12.8 Incident, dispute, insurance or legal-claim information may be retained for as long as reasonably necessary to investigate, defend or resolve the matter and to meet applicable legal limitation or insurance requirements.
12.9 Marketing preference records may be retained while marketing is active and for a reasonable period afterwards to record an opt-out or demonstrate compliance.
12.10 Where personal data is no longer required, Dawa will delete or anonymise it where reasonably practicable and lawful.
13. Security
13.1 Dawa uses reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
13.2 Measures may include controlled staff access, account authentication, password controls, system administration, secure hosting, backups, supplier controls and monitoring appropriate to the service and risk.
13.3 Customers and authorised users are responsible for keeping their own portal credentials confidential and should notify Dawa promptly if they believe their account or credentials have been compromised.
13.4 No internet or information system can be guaranteed to be completely secure. This Policy therefore does not promise absolute security.
14. Personal data breaches
14.1 If Dawa becomes aware of a suspected personal data breach, we will investigate the incident, take reasonable steps to contain it and assess the potential risk to affected individuals.
14.2 We will document reportable data breaches and notify the Information Commissioner’s Office where the applicable legal reporting threshold is met.
14.3 Where applicable law requires notification to an affected individual because the breach presents the relevant level of risk, Dawa will provide that notification without undue delay.
15. Your data protection rights
15.1 Depending on the circumstances and applicable law, an individual may have rights to be informed about processing, obtain access to personal data, correct inaccurate data, request erasure, restrict processing, object to certain processing and receive or transfer certain data.
15.2 Where processing relies on consent, the individual may withdraw that consent. Withdrawal does not affect processing that was lawful before the withdrawal.
15.3 These rights are not all absolute. Dawa may need to retain or continue processing information where a legal, regulatory, tax, contractual or other lawful ground applies.
15.4 To exercise a data protection right, contact Dawa using the privacy contact details in this Policy. We may request reasonable information to verify identity and protect personal data from unauthorised disclosure.
15.5 Dawa will respond to valid requests within the time required by applicable data protection law, subject to any lawful extension or exemption.
16. Automated functions and account administration
16.1 Certain website or portal functions may operate automatically, for example login security, Booking calculations, account-exposure calculations, payment-status updates or availability controls.
16.2 Dawa does not intend to use solely automated processing to make legal or similarly significant decisions about an individual without the safeguards required by applicable law.
16.3 Material account approvals, suspensions or exceptional decisions may involve human review where appropriate.
17. Cookies and similar technologies
17.1 Our websites and portals may use cookies and similar technologies for security, login, session management, preferences, analytics or other permitted purposes.
17.2 Strictly necessary technologies may operate where required to provide the requested website or portal service. Optional cookies will be handled in accordance with the applicable consent requirements.
17.3 Further information is provided in the Dawa Exec Ltd Cookie Policy.
18. Complaints about privacy
18.1 If you have a concern about how Dawa uses personal data, please contact us first so that we can investigate and respond.
18.2 You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. Information about making a complaint is available from the ICO at https://ico.org.uk.
18.3 Using Dawa’s internal complaints route does not remove any right to contact the ICO or pursue another lawful remedy.
19. Changes to this Privacy Policy
19.1 Dawa may update this Privacy Policy where our processing changes or where legal, regulatory or operational requirements change.
19.2 The current version will show its version number and effective date. Material changes will be communicated appropriately where required.
19.3 Historical records remain subject to the lawful retention and processing rules applicable to those records; a later Policy update does not erase obligations that arose under law or contract.
20. Contact and company information
20.1 Data controller: Dawa Exec Ltd.
20.2 Company number: 17265271.
20.3 Registered office: 4 Forbes Street, London, E1 1PF, United Kingdom.
20.4 ICO registration: ZC168060.
20.5 Privacy contact: Director, Dawa Exec Ltd, via info@dawaexec.com.
20.6 Telephone: +44 (0)20 3679 1998.
20.7 24/7 booking / journey support: +44 (0)7417 514014.
20.8 Website: https://dawaexec.com.
Document status: Current published Version 1.0. Effective 14 September 2026.