Privacy notice
This notice explains how personal data is handled in DTDT under the UK GDPR and the Data Protection Act 2018. It is written in plain English on purpose.
Version 1.0 · In effect from 16 August 2026
Who is responsible for your data
DTDT is used by service businesses — garages, salons, trades — to record work for their own customers. That matters for who is responsible:
- The business you booked with is the controller of your customer record, your job, the messages and the proof photos and videos. They decide what to record and how long to keep it.
- DTDT is their processor for that data — we host it and act on their instructions.
- DTDT is the controller for provider accounts, billing, support correspondence and the security and operation of the platform itself.
If you are a customer and want your record changed or deleted, the quickest route is the business that served you. You can also raise a request from your job tracker page and we will pass it to them and log it.
What we hold
- Provider account data: name, email address, phone number, role, workspace settings and sign-in metadata.
- Customer records created by a business: name, email address, phone number and identifiers such as a registration number or booking reference.
- Job data: title, tasks, appointment dates and times, notes, expectation answers, approvals, hold-on messages and the conversation on each task.
- Proof captures: photos and videos of the work, together with the time of capture, the device-reported location where available, and who captured them.
- Feedback and referrals you choose to submit after a job.
- Technical data needed to run and secure the service: IP address, browser type and error logs.
Proof captures can incidentally include people, vehicles or property. Businesses are asked not to capture more than the work requires and must never deliberately record health or other special category data.
Why we hold it, and our lawful basis
- To deliver the service — running your job, showing you live progress and recording what was agreed, done and approved. Basis: performance of a contract, or the legitimate interests of the business you booked with in keeping an accurate record of the work.
- To send job emails — tracker links, approval requests, appointment changes and completion notices. Basis: contract / legitimate interests.
- To keep the service secure and working — abuse prevention, error diagnosis, audit trails. Basis: legitimate interests.
- Optional assistance features — where a business enables them, a capture may be analysed to check an expectation. Basis: legitimate interests of the business; it can be switched off in their settings.
- Non-essential cookies and marketing — only ever with your consent, which you can withdraw at any time. See the cookie policy.
- Legal obligations — where we must keep records or respond to lawful requests.
Where your data is stored
Customer and job data, including proof photos and videos, is stored in United Kingdom (London). We do not routinely transfer it outside the UK. Where a supporting service listed on the sub-processors page processes data outside the UK, that transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or another lawful mechanism.
Who we share it with
- The business you booked with, and their staff working on your job.
- Anyone holding your private tracker link — so only share it with people you want to see the job.
- Our sub-processors, listed publicly and bound by contract.
- Authorities, where we are legally required to disclose.
We do not sell personal data and we do not share it for third-party advertising.
How long we keep it
- Active jobs: for as long as the job is open in the business's workspace.
- Completed jobs: archived 30 days after they reach TRUST, and kept as the business's record of the work unless they delete it sooner.
- Cancelled jobs: archived after 7 days.
- Provider accounts: for as long as the workspace is active, then deleted within 30 days of closure.
- Backups: overwritten on a rolling cycle of no more than 30 days.
The business you booked with can delete your record at any time, and we delete a workspace's data on request when their use of the service ends.
Your rights
Under UK GDPR you have the right to:
- Be told what personal data is held about you and get a copy of it (access).
- Have inaccurate data corrected (rectification).
- Have data deleted where there is no good reason to keep it (erasure).
- Restrict how your data is used while a concern is looked into.
- Receive data you provided in a portable, machine-readable form.
- Object to processing based on legitimate interests, including any direct marketing.
- Withdraw consent at any time where consent is the basis, without affecting past processing.
- Not be subject to a solely automated decision with legal or similarly significant effects. DTDT does not make such decisions; assistance features only suggest, and a person always decides.
To exercise a right, contact the business you booked with, use the "Your data" section on your job tracker, or email ian@bluemeetswhite.com. We respond within one month. We may ask you to verify your identity first.
Complaints
If you are unhappy with how your data has been handled, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office: ico.org.uk, helpline 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
Children
DTDT is a tool for businesses and their customers and is not intended for children. We do not knowingly create accounts for under-16s.
Changes to this notice
When this notice changes materially we update the version and effective date at the top, and tell workspace owners by email.
Who we are
This service is operated by Ian Baird T/A Blue Meets White, trading as Blue Meets White, of Office 1, Izabella House, 24-26 Regent Place, City Centre, Birmingham, B1 3NJ, United Kingdom.
Contact for anything in this document, including data protection requests: ian@bluemeetswhite.com.