Terms & Conditions

Including Schedule 1 – Data Processing Agreement

Last updated: 4 August 2026

These Terms apply to business customers using the Flagship Dispatcher website, platform and related services. Schedule 1 forms part of the Contract whenever Flagship Dispatcher processes personal data on behalf of a Customer.

1. About us

Flagship Dispatcher is a trading name and software service operated by Flagship Transfers Limited, a company registered in England and Wales under company number 14615959.

Our registered office is:

98 Parthenon Drive

Liverpool

England

L11 7AQ

You can contact us at:

Email: flagshipdispatcher@gmail.com

Website: flagship-dispatcher.co.uk

In these Terms, “Flagship Dispatcher”, “we”, “us” and “our” refer to Flagship Transfers Limited.

2. About these Terms

These Terms govern access to and use of:

•  The Flagship Dispatcher website

•  The Flagship Dispatcher public demonstration

•  Free-trial accounts

•  Paid Flagship Dispatcher memberships

•  The operator dashboard

•  The Flagship Dispatcher Driver App where it is made available through a subscribing operator; and

•  Related tools, integrations, communications and support services.

These Terms apply to business customers only.

Flagship Dispatcher is designed for private hire, airport transfer, chauffeur and other transport businesses.

By creating an Account, starting a Trial or purchasing a Subscription, you confirm that you are acting wholly or mainly for business purposes and not as a consumer.

If you accept these Terms on behalf of a company, partnership or another organisation, you confirm that you have authority to enter into the Contract on its behalf.

Drivers and other Authorised Users may also be required to accept separate Driver App Terms of Use.

These Terms include the Data Processing Agreement set out in Schedule 1. Schedule 1 applies whenever Flagship Dispatcher processes Customer Personal Data on behalf of the Customer and forms a binding part of the Contract.

The Privacy Policy and Cookie Policy are separate notices explaining how personal information and cookies are used. They do not replace Schedule 1.

3. Definitions

In these Terms:

Account means the Flagship Dispatcher account created for a Customer.

Authorised User means an owner, administrator, employee, contractor, dispatcher, driver or other person whom the Customer allows to access or use the Service.

Contract means the agreement between the Customer and Flagship Dispatcher consisting of these Terms, including Schedule 1 – Data Processing Agreement, the applicable Order and any additional terms expressly agreed in writing.

Customer means the business, company, sole trader, partnership or organisation that creates an Account, starts a Trial or purchases a Subscription.

Customer Data means information entered, uploaded, generated or otherwise processed through the Service on behalf of the Customer, including booking, passenger, customer, driver, vehicle, document, financial and payment-status information.

Data Processing Agreement means the data processing terms contained in Schedule 1 of these Terms.

Driver App means the Flagship Dispatcher mobile application made available to drivers and other Authorised Users.

Fees means subscription, usage, add-on or other charges shown when the Customer purchases or renews the Service.

Order means the plan, checkout summary, order form or other written confirmation setting out the Subscription selected by the Customer.

Service means the Flagship Dispatcher website, operator dashboard, Driver App and associated features supplied under the Contract.

Subscription means paid access to the Service under a selected membership or plan.

Subscription Period means the period during which the Customer has paid access to the Service.

Trial means free, limited-period access made available before a paid Subscription begins.

4. Accepting the Contract

The Contract begins when the Customer:

•  Selects a box or button confirming acceptance of these Terms

•  Creates an Account after being given access to these Terms

•  Signs an Order that incorporates these Terms; or

•  Activates a paid Subscription.

The person accepting the Contract confirms that:

•  The registration information supplied is accurate

•  They are at least 18 years old

•  They are authorised to act for the Customer; and

•  The Customer agrees to be bound by the Contract.

Where there is a conflict between documents forming the Contract, the following order of precedence applies:

•  A separately signed Order or written agreement

•  Schedule 1 – Data Processing Agreement, for matters concerning the processing and protection of Customer Personal Data

•  These Terms and Conditions

•  The plan description or pricing information shown when the Subscription is purchased; and

•  Other policies or documents referenced by these Terms.

A Customer’s own purchase order or standard terms will not apply unless we expressly agree to them in writing.

5. The Flagship Dispatcher Service

Flagship Dispatcher provides hosted software tools intended to help transport operators manage activities such as:

•  Bookings and return journeys

•  Driver and vehicle allocation

•  Booking status and dispatch information

•  Driver and vehicle documents

•  Driver earnings and payout records

•  Customer and passenger information

•  Invoices, expenses and payment status

•  Customer communications

•  Live tracking

•  Reviews and review requests

•  Subcontracted work

•  Marketplace activity; and

•  Other administrative and operational functions.

The exact features available depend on:

•  The Customer’s plan

•  Account configuration

•  Country or operating area

•  Device and operating system

•  Integrations enabled by the Customer

•  Product development and availability; and

•  Any limits shown in the applicable Order.

We grant the Customer a limited, non-exclusive, non-transferable and revocable right to access and use the Service during the Trial or Subscription Period in accordance with the Contract.

The Customer does not purchase or obtain ownership of the Flagship Dispatcher software, source code, database structure or underlying technology.

6. We provide software, not transport services

Flagship Dispatcher is a software provider.

Unless expressly agreed otherwise in writing, we do not:

•  Accept passenger bookings as a private hire operator

•  Provide passenger transport

•  Supply vehicles or drivers

•  Employ or engage the Customer’s drivers

•  Set the Customer’s fares

•  Collect passenger fares on behalf of the Customer

•  Act as a party to contracts between the Customer and its passengers

•  Act as a party to arrangements between operators, drivers or subcontractors

•  Guarantee that a driver, vehicle or operator is licensed or insured

•  Manage the Customer’s transport business; or

•  Assume the Customer’s regulatory responsibilities.

The Customer remains responsible for its transport operation and all transport services it provides, accepts, arranges or subcontracts.

Use of Flagship Dispatcher does not by itself demonstrate compliance with private hire licensing requirements, transport law, employment law, tax law, data protection law, safeguarding rules or local authority conditions.

7. Free Trial

Eligible businesses may receive a 30-day free Trial.

The Trial begins when the Customer completes Account onboarding unless we confirm another start date in writing.

No payment card is required to begin the Trial, and the Customer will not automatically be charged when the Trial ends.

A paid Subscription will begin only when the Customer actively selects a paid plan and completes the required payment or billing process.

Unless we agree otherwise:

•  Only one Trial is available per business

•  Trial access may be limited or changed

•  Trial features may include test, preview or early-access functionality

•  No guaranteed service level applies during the Trial

•  We may refuse or end a Trial where we reasonably believe it is being misused; and

•  The Trial may not be transferred to another business.

The Customer should maintain its own backup and dispatch procedures during the Trial and should not rely solely on a Trial Account for safety-critical or time-critical transport operations.

If the Customer does not activate a paid Subscription, access to the Account may stop when the Trial ends.

Unless the Customer starts a paid Subscription, we may delete Customer Data held in the Trial Account 30 days after the Trial ends.

The Customer is responsible for exporting any information it wishes to retain before that date.

8. Public demonstration

We may provide a public or shared demonstration of Flagship Dispatcher.

The demonstration is provided only to help potential customers explore the Service. It may:

•  Contain sample information

•  Have reduced functionality

•  Be changed or reset without notice

•  Be used by several people

•  Be unavailable from time to time; and

•  Not reflect the final or current production version.

Users must not enter real passenger information, driver documents, payment details, confidential business information or other personal information into the public demonstration.

We may remove any information entered into the demonstration at any time.

The public demonstration must not be used for live transport operations.

9. Paid Subscriptions

A paid Subscription begins when the Customer purchases or activates a paid plan.

The features, limits, Fees and billing period applicable to the Subscription will be shown in the Order or during checkout.

Unless the Order states otherwise:

•  Subscriptions are billed monthly in advance

•  Subscriptions automatically renew for successive monthly periods

•  The Customer may cancel at any time

•  Cancellation takes effect at the end of the current paid billing period; and

•  Access continues until the end of that period unless the Account is suspended or terminated under these Terms.

The number of drivers, administrators, bookings, messages, documents or other resources included may depend on the selected plan.

Additional features, increased limits, SMS messages, storage, integrations or other services may be subject to separate Fees.

10. Founding Membership and Legacy Accounts

Founding Membership is an early-access membership that may be limited to a specified number of businesses.

Unless the applicable offer expressly states otherwise:

•  Starting a Trial does not reserve a Founding Membership place

•  A place is secured only when an eligible Customer activates a paid Founding Membership while places remain available

•  Founding Membership is attached to the subscribing business and cannot be transferred or sold

•  Legacy Account status continues only while the Subscription remains active and the Account remains in good standing

•  Cancelling the Subscription may permanently end the Customer’s Founding Membership and Legacy Account status; and

•  A former Founding Member is not guaranteed the right to rejoin on the same price, status or benefits.

The benefits of Founding Membership are those expressly described in the Order or offer presented when the Customer subscribes.

Legacy Account status does not automatically guarantee that every future feature, add-on, separate product or third-party service will be included without additional charge.

Where an Order expressly states that a founding price is protected, that protection applies to the base Subscription while the Customer maintains a continuous paid Subscription.

It does not prevent us from charging separately for:

•  VAT or other taxes

•  Third-party usage costs

•  SMS or communications usage

•  Optional add-ons

•  Increased usage limits

•  Bespoke development

•  Additional storage

•  Additional integrations; or

•  New products separate from the original membership.

11. Fees and payment

The Customer must pay the Fees shown in the Order.

Unless stated otherwise:

•  Fees are charged in advance

•  Fees are payable in pounds sterling

•  Fees exclude VAT and other applicable taxes

•  VAT will be added where legally chargeable; and

•  The Customer is responsible for bank, card, currency-conversion or payment-provider charges.

The Customer authorises us and our payment provider to charge the selected payment method for recurring Fees where recurring billing applies.

The Customer must keep its billing and payment information accurate and up to date.

If a payment fails, we may:

•  Retry the payment

•  Contact the Customer for an alternative payment method

•  Restrict access to paid features

•  Suspend the Account; or

•  Terminate the Subscription where payment remains outstanding.

We will normally give the Customer a reasonable opportunity to correct an accidental payment failure before terminating the Account.

The Customer must notify us promptly if it believes a charge is incorrect.

12. Price changes

We may change Subscription prices by giving the Customer at least 30 days’ notice.

A price change will normally take effect from the Customer’s first renewal date following the notice period.

The Customer may cancel the Subscription before the new price takes effect.

Price changes do not affect a protected founding price where the applicable Order expressly promises continuing price protection, except for:

•  Taxes

•  Third-party costs

•  Usage charges

•  Optional add-ons

•  Increased limits

•  Bespoke services; and

•  Separate products.

13. Cancellation and refunds

The Customer may cancel a monthly Subscription at any time.

Cancellation takes effect at the end of the current paid billing period unless we agree to an earlier date.

The Customer will continue to have access to the paid Service until the end of that period, subject to these Terms.

The Customer will not be charged for a further billing period after a valid cancellation has taken effect.

Except where required by law or expressly agreed by us:

•  Fees already paid are non-refundable

•  No refund is given for an unused part of a monthly billing period

•  Failure to use the Account does not entitle the Customer to a refund; and

•  Suspension caused by the Customer’s breach does not entitle the Customer to a refund.

Cancellation must be completed using the cancellation option shown in the Account or by contacting us at flagshipdispatcher@gmail.com from an authorised Account email address.

If we terminate a paid Subscription for convenience rather than because of the Customer’s breach, we will refund prepaid Fees relating to the period after termination.

14. Customer Accounts

The Customer must provide complete and accurate registration information.

The first administrator created during onboarding will normally have authority to manage the Account and other Authorised Users.

The Customer is responsible for:

•  Deciding who receives Account access

•  Assigning appropriate permissions

•  Removing access when a person no longer works with or for the Customer

•  Keeping Account information current

•  Protecting passwords and authentication methods

•  Protecting devices used to access the Service; and

•  Activity carried out through its Account by Authorised Users.

Login details must not be shared with people who have not been authorised by the Customer.

The Customer must notify us promptly if it suspects that:

•  An Account has been accessed without permission

•  A password or device has been compromised

•  Customer Data has been unlawfully accessed

•  An Authorised User is misusing the Service; or

•  A security incident has occurred.

We may require the Customer or an Authorised User to reset a password, complete additional verification or take other reasonable security steps.

15. Drivers and other Authorised Users

The Customer may give drivers, dispatchers, staff members and contractors access to relevant parts of the Service.

The Customer is responsible for ensuring that each Authorised User:

•  Is authorised to access the information made available to them

•  Uses the Service only for the Customer’s legitimate business purposes

•  Follows these Terms and any applicable Driver App Terms

•  Keeps their Account secure

•  Uses passenger and booking information confidentially

•  Protects devices used to access the Service; and

•  Complies with applicable laws and the Customer’s internal procedures.

Access to the Driver App does not create an employment, worker, agency, partnership or contractor relationship between Flagship Dispatcher and the driver.

Any employment, contractor, payment, disciplinary or operational relationship is between the Customer and the relevant driver or Authorised User.

16. Customer responsibilities

The Customer is solely responsible for operating its business lawfully.

This includes responsibility for:

•  Holding all required private hire, operator, transport or business licences

•  Ensuring drivers and vehicles are properly licensed

•  Checking insurance, MOT, vehicle plates, driving licences and other documents

•  Conducting required driver, safeguarding or background checks

•  Ensuring bookings are accepted and subcontracted lawfully

•  Setting fares and agreeing passenger terms

•  Paying drivers, employees and subcontractors

•  Accounting for tax, VAT and other financial obligations

•  Handling complaints, refunds, lost property and passenger disputes

•  Meeting accessibility and equality obligations

•  Complying with local authority and licensing conditions

•  Providing suitable training to Authorised Users; and

•  Maintaining emergency and business-continuity arrangements.

Document expiry dates, warnings, checklists and approval indicators within the Service are administrative tools only.

The Customer must independently confirm the authenticity, validity and suitability of driver and vehicle documents.

Flagship Dispatcher does not certify that a person, business or vehicle is legally permitted to undertake transport work.

17. Customer Data and accuracy

The Customer is responsible for the accuracy, quality and legality of Customer Data.

The Customer must check important information before relying on it, including:

•  Passenger names and contact details

•  Pickup and drop-off addresses

•  Journey dates and times

•  Flight information

•  Passenger numbers

•  Vehicle requirements

•  Driver allocation

•  Fares and payment status

•  Driver earnings

•  Document expiry dates; and

•  Subcontracting information.

The Service may automate calculations or display information entered by the Customer, its drivers, passengers or third-party providers.

Such information may be incomplete, delayed or incorrect.

The Customer must maintain appropriate human oversight of its transport operation.

18. AI-assisted features

The Service may include features that use automated or artificial-intelligence technology, including tools that extract booking information from text or other content.

AI-generated or AI-extracted information may be inaccurate, incomplete or placed in an incorrect field.

The Customer must review and confirm all information before:

•  Creating a booking

•  Assigning a driver

•  Contacting a passenger

•  Issuing an invoice

•  Sending a payment link

•  Subcontracting work; or

•  Taking another operational action.

AI-assisted features are administrative tools and must not be used as the sole basis for safety-critical, legal, licensing, employment or financial decisions.

The Customer must not submit information to an AI-assisted feature unless it has the right and lawful basis to process that information.

19. Payments, invoices and financial tools

Flagship Dispatcher may allow the Customer to record fares, invoices, expenses, driver earnings and payment status or connect with external payment providers.

These tools are provided for administrative purposes.

Unless expressly agreed otherwise:

•  Flagship Dispatcher does not receive or hold passenger funds

•  We are not a bank, accountant, tax adviser or regulated payment institution

•  We do not guarantee that a passenger, operator or subcontractor will make payment

•  Payment links may be processed by an independent payment provider

•  The Customer’s agreement with its payment provider applies separately; and

•  The Customer remains responsible for checking financial records and calculations.

The Customer should obtain professional accounting or tax advice where necessary.

Information displayed as driver earnings, company commission, expenses, VAT, profit or outstanding payments must be checked by the Customer before it is used for payroll, tax returns, accounts or payments.

20. Emails, SMS messages and review requests

The Service may allow the Customer to send:

•  Operational messages

•  Booking confirmations

•  Payment links

•  Tracking links

•  Review requests

•  Marketing messages; and

•  Other communications.

The Customer is responsible for the content, recipients and timing of those communications.

The Customer must ensure that it has:

•  A lawful basis for using the recipient’s personal information

•  Any consent required to send marketing messages

•  Provided appropriate privacy information

•  Respected objections and opt-out requests

•  Used accurate sender information; and

•  Complied with data protection and electronic-marketing laws.

Flagship Dispatcher may restrict communications activity that appears unlawful, abusive, misleading, excessive or likely to damage our systems or communications providers.

SMS, email and other communications may be delayed, blocked, filtered or rejected by third-party networks and are not guaranteed to reach the recipient.

21. Maps, navigation, flights and live tracking

Routes, estimated journey times, maps, navigation links, flight information and live tracking may depend on information supplied by third parties.

Such information may be delayed, incomplete or inaccurate.

The Customer and its drivers must independently check:

•  Road closures

•  Traffic conditions

•  Pickup restrictions

•  Airport procedures

•  Flight changes

•  Vehicle suitability

•  Parking restrictions; and

•  The safety and legality of any proposed route.

Drivers must not interact with the Service in a manner that is unsafe or unlawful while driving.

Live tracking must be used only where the Customer has a lawful basis and has provided drivers and other affected individuals with appropriate privacy information.

22. Marketplace and subcontracted work

Flagship Dispatcher may provide tools allowing users to advertise, share, request, accept, award or manage work involving another driver or operator.

Flagship Dispatcher provides the technical platform only.

We do not:

•  Guarantee that marketplace work will be offered or accepted

•  Endorse a driver, operator or business

•  Verify every licence, insurance policy or legal requirement

•  Set commercial terms between marketplace users

•  Guarantee payment

•  Guarantee the quality or completion of a journey

•  Resolve every dispute between users; or

•  Become a party to the resulting transport or subcontracting agreement.

Each participating business is responsible for:

•  Verifying the identity and authority of the other party

•  Checking licences, insurance and vehicle suitability

•  Agreeing prices, payment terms and cancellation arrangements

•  Determining who accepts and fulfils the passenger booking

•  Keeping legally required booking and subcontracting records

•  Sharing passenger information lawfully

•  Informing passengers where required; and

•  Resolving disputes directly with the other party.

Any acceptance score, rating, activity indicator or similar information is provided as a general administrative aid. It is not a guarantee, verification or professional recommendation.

We may remove marketplace content or suspend marketplace access where we reasonably believe it creates legal, security, reputational or operational risk.

23. Acceptable use

The Customer and its Authorised Users must not:

•  Use the Service unlawfully or fraudulently

•  Use the Service to operate unlicensed transport services

•  Upload information they have no right to use

•  Misuse passenger or driver information

•  Send unlawful or unsolicited marketing

•  Harass, threaten or discriminate against another person

•  Upload viruses, malware or harmful code

•  Attempt to gain unauthorised access to an Account or system

•  Interfere with the security, stability or performance of the Service

•  Circumvent usage limits or access controls

•  Scrape or systematically extract information without permission

•  Reverse engineer, decompile or attempt to discover the Service’s source code, except where the law expressly permits it

•  Copy the Service or use it to create a substantially similar competing product

•  Remove copyright, trade mark or ownership notices

•  Use automated tools in a manner that places an unreasonable load on the Service

•  Upload special-category or criminal-offence information unless necessary, lawful and supported by the relevant Service feature; or

•  Allow an unauthorised third party to access the Service.

We may investigate suspected misuse and take reasonable steps to protect the Service, our customers and affected individuals.

24. Third-party services and integrations

The Service may connect with or rely on third-party services, including:

•  Hosting and cloud-storage providers

•  Mapping and navigation services

•  Flight-information providers

•  Payment processors

•  Email and SMS providers

•  Authentication providers

•  App stores

•  Analytics or security tools; and

•  Other software selected by the Customer.

Third-party services may have their own terms, privacy policies, charges and usage limits.

We are not responsible for a third party’s independent service, decision, outage, suspension, information or conduct.

We may replace, change or discontinue an integration where the third-party provider:

•  Changes its service

•  Withdraws access

•  Increases charges

•  Stops supporting the integration

•  Creates a security risk; or

•  Creates a legal or regulatory risk.

Where a discontinued integration is a material part of a paid plan, we will take reasonable steps to provide notice and, where practicable, an alternative.

25. Service availability and maintenance

We will provide the Service with reasonable care and skill.

However, we do not guarantee that the Service will be continuously available or completely free from errors.

The Service may be unavailable because of:

•  Planned maintenance

•  Emergency maintenance

•  Software updates

•  Internet or telecommunications failures

•  Third-party outages

•  Cybersecurity incidents

•  Hardware failures

•  Power failures

•  Legal or regulatory requirements

•  Events beyond our reasonable control; or

•  Work required to prevent damage or unlawful access.

Where practicable, we will provide advance notice of planned maintenance likely to cause material disruption.

No guaranteed response time, uptime percentage or service credit applies unless we expressly agree to a separate Service Level Agreement in writing.

The Customer must maintain appropriate alternative communication, dispatch and booking procedures for periods when the Service is unavailable.

26. Data protection

For personal information that Flagship Dispatcher collects and uses for its own Account administration, billing, security, fraud prevention, legal compliance and business purposes, Flagship Dispatcher acts as a data controller.

Where Flagship Dispatcher processes passenger, driver, booking, customer, staff or other personal information on behalf of the Customer and according to the Customer’s instructions:

•  The Customer will normally act as the data controller; and

•  Flagship Dispatcher will normally act as the data processor.

Where the Customer processes personal information on behalf of another organisation, such as a council, school, corporate customer, booking provider or another transport operator:

•  That organisation may act as the data controller

•  The Customer may act as a data processor; and

•  Flagship Dispatcher may act as a subprocessor.

The Customer is responsible for:

•  Identifying an appropriate lawful basis for its processing

•  Providing required privacy information to passengers, drivers, staff and other individuals

•  Ensuring that personal information entered into the Service is relevant, accurate and not excessive

•  Handling requests from individuals concerning their information

•  Setting appropriate retention periods

•  Ensuring that driver or employee monitoring is lawful, necessary and proportionate

•  Obtaining any required permissions or consent

•  Giving Flagship Dispatcher lawful documented instructions; and

•  Complying with applicable data protection and electronic communications laws.

Where Flagship Dispatcher acts as a processor or subprocessor, the Data Processing Agreement contained in Schedule 1 applies and forms part of the Contract.

If there is a conflict between this section, another general provision of these Terms and Schedule 1 concerning the processing or protection of Customer Personal Data, Schedule 1 will take precedence to the extent of that conflict.

Our use of personal information for our own purposes is explained in the Flagship Dispatcher Privacy Policy.

27. Ownership of Customer Data

As between the Customer and Flagship Dispatcher, the Customer retains ownership of Customer Data.

The Customer grants us permission to host, copy, transmit, display, organise, back up and otherwise process Customer Data only as necessary to:

•  Provide and secure the Service

•  Carry out the Customer’s instructions

•  Prevent fraud and misuse

•  Meet legal obligations

•  Provide support

•  Investigate technical problems; and

•  Enforce the Contract.

The Customer confirms that it has all rights and lawful authority required to provide Customer Data to us.

We may generate and use statistical or aggregated information about use of the Service where that information has been anonymised so that it does not identify the Customer, passengers, drivers or other individuals.

28. Data export and deletion

The Customer should regularly export information it requires for:

•  Business continuity

•  Accounting

•  Licensing

•  Insurance

•  Dispute handling; and

•  Legal record-keeping.

Following cancellation or termination, we will normally make Customer Data available for export for 30 days, provided that:

•  Fees due have been paid

•  The Account was not terminated for serious unlawful activity or security abuse; and

•  We are not legally prohibited from providing access.

After that period, we may delete or anonymise Customer Data.

Deleted information may remain in protected backup systems for up to 90 days before being overwritten through the normal backup cycle.

Information retained in backups will not be restored to active use unless required for disaster recovery, security, legal compliance or investigation of an incident.

The Customer remains responsible for retaining records it is legally required to keep.

29. Confidentiality

Each party may receive confidential business, technical, financial or commercial information belonging to the other.

Each party must:

•  Keep the other party’s confidential information secure

•  Use it only for the Contract

•  Disclose it only to people who need it and are subject to confidentiality obligations; and

•  Not disclose it to another person without permission, except where legally required.

Confidential information does not include information that:

•  Is publicly available through no breach of the Contract

•  Was lawfully known to the receiving party before disclosure

•  Is received lawfully from an independent third party; or

•  Is independently developed without using the other party’s confidential information.

These confidentiality obligations continue after the Contract ends.

30. Intellectual property

All intellectual-property rights in Flagship Dispatcher, including the software, source code, database structure, design, branding, documentation, workflows and website content, belong to us or our licensors.

Except for the limited right to use the Service under these Terms, no intellectual-property rights are transferred to the Customer.

The Customer must not copy, distribute, sell, license, alter or create derivative products from any part of the Service without our written permission.

The Customer retains ownership of its own branding, content and Customer Data.

Where the Customer gives us comments, suggestions or feedback about the Service, the Customer allows us to use that feedback without restriction or payment, provided that we do not publicly identify the Customer without permission.

31. Suspension

We may suspend all or part of an Account where we reasonably believe that:

•  Fees are overdue

•  The Account is being used unlawfully

•  These Terms have been materially breached

•  An Account or password has been compromised

•  Customer Data creates a security threat

•  The Customer’s activity may damage the Service or another person

•  Suspension is required by law or a competent authority; or

•  Immediate action is needed to protect passengers, drivers, customers, our systems or third-party services.

Where practicable, we will explain the reason and give the Customer an opportunity to correct the issue.

We may suspend access immediately where delay could create a material legal, security or safety risk.

Suspension does not remove the Customer’s obligation to pay Fees that became due before or during a suspension caused by the Customer’s breach.

32. Termination by us

We may terminate the Contract immediately by written notice where the Customer:

•  Commits a serious or repeated breach of these Terms

•  Fails to correct a remediable material breach within a reasonable period after notice

•  Fails to pay undisputed Fees

•  Uses the Service for fraud, unlawful transport or other illegal activity

•  Seriously compromises the security of the Service

•  Becomes insolvent or ceases trading; or

•  Creates a risk that we cannot reasonably manage through suspension.

We may also discontinue the Service or terminate a Subscription for business reasons by giving at least 30 days’ notice.

Where we terminate a prepaid Subscription for business reasons and not because of the Customer’s breach, we will refund the unused proportion of prepaid Fees.

33. Consequences of termination

When the Contract ends:

•  The Customer’s right to use the Service ends

•  Authorised Users may lose access

•  Outstanding Fees become payable

•  The Customer should export required Customer Data

•  Founding Membership or Legacy Account status may be lost

•  We may delete Customer Data in accordance with section 28; and

•  Provisions intended to continue after termination remain effective.

Sections concerning payment, confidentiality, intellectual property, data protection, liability, indemnities, governing law and any provisions that by their nature should survive will continue after termination.

34. Our warranties

We warrant that we will provide the paid Service with reasonable care and skill.

We do not warrant that:

•  The Service will always be uninterrupted or error-free

•  Every error will be corrected immediately

•  The Service will meet every Customer requirement

•  Use of the Service will increase bookings, revenue or profit

•  Passenger or driver information will always be accurate

•  Third-party information or services will always be available

•  Every feature will be available on every device

•  The Service alone will make the Customer legally compliant; or

•  Customer Data can never be lost or accessed unlawfully.

Nothing in these Terms excludes any warranty or obligation that cannot legally be excluded.

35. Limitation of liability

Nothing in these Terms excludes or limits liability for:

•  Death or personal injury caused by negligence

•  Fraud or fraudulent misrepresentation

•  Deliberate unlawful conduct; or

•  Any other liability that cannot legally be excluded or limited.

Subject to the paragraph above, neither party will be liable for:

•  Indirect or consequential loss

•  Loss of profit

•  Loss of revenue

•  Loss of anticipated savings

•  Loss of business opportunity

•  Loss of contracts

•  Loss of goodwill or reputation; or

•  Loss arising from a failure to maintain reasonable backup or business-continuity procedures.

This exclusion applies whether the loss was foreseeable or whether the party had been told that it might occur.

Subject to the exclusions above, our total aggregate liability arising from or connected with the Contract in any 12-month period will not exceed the greater of:

•  £500; or

•  The total Subscription Fees paid or payable by the Customer during the 12 months immediately preceding the event giving rise to the claim.

Where the Customer’s paid Subscription has been active for less than 12 months when the event giving rise to the claim occurs, the calculation will use the Subscription Fees paid or payable from the beginning of the paid Subscription up to the date of that event.

All claims arising from the same event or a series of connected events will be treated as one claim.

For a claim arising solely from use of a free Trial or public demonstration, our total aggregate liability will not exceed £100.

The liability cap does not apply to:

•  The Customer’s obligation to pay Fees

•  Liability arising from the Customer’s fraud

•  The Customer’s deliberate misuse of the Service

•  The Customer’s infringement of our intellectual-property rights; or

•  The Customer’s indemnity obligations under section 36.

The limitations and exclusions in this section apply to claims in contract, negligence, tort, misrepresentation, breach of statutory duty or otherwise, to the fullest extent permitted by law.

36. Customer indemnity

The Customer will indemnify Flagship Dispatcher against reasonable losses, liabilities, damages, costs and third-party claims to the extent that they arise from:

•  Transport services provided, arranged or subcontracted by the Customer

•  The Customer operating without appropriate licensing or insurance

•  Unlawful or unauthorised Customer Data

•  The Customer’s breach of data protection or electronic-marketing law

•  Passenger, driver, employee or subcontractor claims arising from the Customer’s business

•  The Customer’s misuse of the Service; or

•  A material breach of these Terms by the Customer or an Authorised User.

We will notify the Customer of a relevant third-party claim and provide reasonable cooperation.

The Customer must not settle a claim in a manner that:

•  Admits liability on our behalf

•  Imposes an obligation on us; or

•  Damages our rights or reputation,

•  without our written consent.

37. Website, blog and help content

Information on the public website, blog, help pages and demonstration is provided for general information.

It is not legal, licensing, employment, accounting, tax, insurance or professional advice.

We may update website content as the Service develops.

Images, screenshots and descriptions may show planned, preview, beta or illustrative functionality.

Links to third-party websites are provided for convenience. We are not responsible for the content, security or privacy practices of independent websites.

38. Changes to the Service

We may update the Service to:

•  Add or improve features

•  Correct errors

•  Improve security

•  Meet legal or regulatory requirements

•  Maintain compatibility

•  Respond to changes made by third-party providers; or

•  Remove functionality that is no longer practical or safe to maintain.

We will not knowingly make a change that materially removes the core value of a paid plan without reasonable notice, unless immediate action is required for legal or security reasons.

Features labelled as beta, test, preview or early access may be changed, suspended or withdrawn more frequently.

39. Changes to these Terms

We may update these Terms.

Where a change materially affects a paid Customer’s rights or obligations, we will normally provide at least 30 days’ notice by:

•  Email

•  A notice through the Account; or

•  A notice on the website.

A change may take effect sooner where required by law, security needs or a third-party service provider.

The notice will state the effective date.

If the Customer does not agree to a material change, it may cancel the Subscription before the change takes effect.

Continued use of the paid Service after the effective date will constitute acceptance of the updated Terms.

Changes will not apply retrospectively to a dispute that arose before the change took effect.

40. Events outside our control

Neither party will be responsible for delay or failure caused by an event beyond its reasonable control.

Such events may include:

•  Natural disasters

•  Fire or flood

•  War or civil disorder

•  Government action

•  Widespread telecommunications failure

•  Widespread cloud-service failure

•  Power failure

•  Industrial action

•  Cyberattack; or

•  Failure of essential infrastructure.

The affected party must take reasonable steps to reduce the effect of the event and resume performance.

This section does not excuse the Customer’s obligation to pay Fees already due.

41. Assignment

The Customer may not transfer the Contract, Subscription or Account to another business without our written permission.

We may transfer the Contract as part of a genuine sale, restructuring or transfer of the Flagship Dispatcher business, provided that the transfer does not materially reduce the Customer’s contractual rights.

42. No partnership or agency

The Contract does not create a partnership, joint venture, employment relationship, franchise or agency between the Customer and Flagship Dispatcher.

Neither party has authority to enter into a contract or make a commitment on behalf of the other.

43. Third-party rights

Unless these Terms expressly state otherwise, a person who is not a party to the Contract has no right to enforce it under the Contracts (Rights of Third Parties) Act 1999.

44. Entire agreement

The Contract constitutes the entire agreement between the parties concerning the Service.

The Customer acknowledges that it has not relied on a statement that is not included in the Contract.

Nothing in this section excludes liability for fraud or fraudulent misrepresentation.

45. Severability

If a court finds that part of these Terms is unlawful or unenforceable, that part will be treated as removed or modified to the minimum extent necessary.

The remaining provisions will continue in effect.

46. Waiver

A delay or failure to enforce a right does not mean that the right has been waived.

A waiver is effective only where it is confirmed in writing and applies only to the particular circumstances for which it was given.

47. Notices

We may send contractual notices to the email address registered to the Customer’s Account.

The Customer is responsible for keeping that address current and monitoring it.

Notices to Flagship Dispatcher should be sent to:

flagshipdispatcher@gmail.com

A notice sent by email will normally be treated as received on the next business day, provided that the sender does not receive a delivery-failure message.

48. Disputes

The parties should first attempt to resolve any dispute through good-faith discussions.

A Customer should send details of the dispute to flagshipdispatcher@gmail.com, including:

•  The business name

•  The relevant Account email

•  A description of the issue

•  Relevant supporting information; and

•  The outcome requested.

The parties should allow a reasonable period for investigation and resolution before beginning court proceedings, except where urgent legal protection is required.

49. Governing law and jurisdiction

The Contract and any dispute or non-contractual obligation arising from it are governed by the laws of England and Wales.

The courts of England and Wales will have exclusive jurisdiction.

Flagship Transfers Limited  |  Company No. 14615959  |  Page

FLAGSHIP DISPATCHER  |  TERMS AND CONDITIONS

Schedule 1 – Data Processing Agreement

This Schedule forms a binding part of the Flagship Dispatcher Terms and Conditions.

D1. Parties and incorporation

This Data Processing Agreement forms Schedule 1 to the Flagship Dispatcher Terms and Conditions and is entered into between:

•  The Customer, being the company, sole trader, partnership or other business identified in the relevant Flagship Dispatcher Account, Order or Subscription; and

•  Flagship Transfers Limited, trading as Flagship Dispatcher, a company registered in England and Wales under company number 14615959, whose registered office is 98 Parthenon Drive, Liverpool, England, L11 7AQ.

Email: flagshipdispatcher@gmail.com

In this Schedule, Flagship Transfers Limited is referred to as “Flagship Dispatcher”, “we”, “us”, “our” or the “Processor”.

The Customer and Flagship Dispatcher are each a “Party” and together the “Parties”.

D2. Purpose of this Agreement

The Customer uses the Flagship Dispatcher platform to manage its transport operation.

In providing the Service, Flagship Dispatcher may process personal information about passengers, customers, drivers, staff members, contractors, subcontractors and other individuals on the Customer’s behalf.

This Agreement governs that processing and forms part of the contract between Flagship Dispatcher and the Customer.

It is intended to satisfy the requirements applying to contracts between controllers and processors under Article 28 of the UK GDPR.

D3. Definitions

In this Agreement:

Applicable Data Protection Law

“Applicable Data Protection Law” means all data protection, privacy and electronic communications laws applying to the processing covered by this Agreement, including where applicable:

•  The UK General Data Protection Regulation

•  The Data Protection Act 2018

•  The Privacy and Electronic Communications Regulations 2003

•  The EU General Data Protection Regulation

•  The Data (Use and Access) Act 2025

•  Any legislation replacing, amending or supplementing those laws; and

•  Any binding regulatory requirements applying to the relevant processing.

Customer Personal Data

“Customer Personal Data” means Personal Data contained within Customer Data or otherwise processed by Flagship Dispatcher on behalf of the Customer in connection with the Service.

It does not include information that Flagship Dispatcher processes as an independent controller for its own account administration, billing, legal compliance, fraud prevention, security or business-management purposes.

Data Subject

“Data Subject” means an identified or identifiable individual to whom Customer Personal Data relates.

Personal Data

“Personal Data” means any information relating to an identified or identifiable individual.

Personal Data Breach

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.

Processing

“Processing”, “Process” and “Processed” include collecting, recording, organising, structuring, storing, adapting, retrieving, consulting, using, transmitting, disclosing, combining, restricting, deleting or destroying Personal Data.

Restricted Transfer

“Restricted Transfer” means a transfer of Customer Personal Data that is subject to the international-transfer restrictions under Applicable Data Protection Law.

Service

“Service” means the Flagship Dispatcher operator dashboard, Driver App, booking tools, website-builder functionality, booking forms, integrations and associated software services provided to the Customer.

Special Category Data

“Special Category Data” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric identification data, health information, or information concerning a person’s sex life or sexual orientation.

Subprocessor

“Subprocessor” means a third party appointed by Flagship Dispatcher to process Customer Personal Data on behalf of the Customer.

Terms

“Terms” means the Flagship Dispatcher Terms and Conditions accepted by the Customer.

Terms such as Controller, Processor, Data Subject and Supervisory Authority have the meanings given to them under Applicable Data Protection Law.

D4. Application and precedence

This Schedule applies whenever Flagship Dispatcher processes Customer Personal Data on behalf of the Customer.

It becomes binding at the same time as the Contract, including when the Customer:

•  Accepts the Flagship Dispatcher Terms

•  Creates or activates an Account after being provided with these Terms

•  Activates a paid Subscription

•  Signs an Order incorporating these Terms; or

•  Otherwise agrees to the Contract electronically or in writing.

This Schedule remains in force for as long as Flagship Dispatcher or a Subprocessor processes Customer Personal Data.

If there is a conflict between this Schedule and the general Terms regarding the protection or processing of Customer Personal Data, this Schedule takes precedence.

If there is a conflict between this Schedule and an approved international-transfer mechanism, the international-transfer mechanism takes precedence in relation to that transfer.

D5. Roles of the Parties

D5.1 Customer as Controller

Where the Customer decides why and how Customer Personal Data is processed through the Service:

•  The Customer acts as Controller; and

•  Flagship Dispatcher acts as Processor.

D5.2 Customer acting for another Controller

Where the Customer processes Personal Data on behalf of another Controller, such as a council, booking provider, corporate customer or another transport operator:

•  The Customer acts as a Processor

•  Flagship Dispatcher acts as a Subprocessor; and

•  The Customer confirms that it has authority from the relevant Controller to appoint Flagship Dispatcher.

The Customer must ensure that its instructions to Flagship Dispatcher are consistent with instructions received from the relevant Controller.

D5.3 Separate responsibilities

Each Party must comply with the obligations that apply to it under Applicable Data Protection Law.

Nothing in this Agreement changes the legal role of a Party where that role is determined by the facts and Applicable Data Protection Law.

D6. Details of the processing

The subject matter, duration, nature and purpose of the processing, together with the categories of Data Subjects and Personal Data, are described in Annex A.

The Customer authorises Flagship Dispatcher to process Customer Personal Data as reasonably necessary to:

•  Provide the Service

•  Host and store Customer Data

•  Display information to authorised operator users and drivers

•  Process bookings and journey information

•  Manage drivers, vehicles and documents

•  Provide communications and notification functions

•  Provide live-location and job-progress functions where enabled

•  Provide payment, invoicing and finance-related tools

•  Provide subcontracting and marketplace tools

•  Provide support requested by the Customer

•  Maintain backups and business continuity

•  Protect the security and integrity of the Service

•  Prevent fraud, misuse and unauthorised access

•  Correct faults and maintain the Service

•  Comply with documented Customer instructions; and

•  Delete or return Customer Personal Data in accordance with this Agreement.

D7. Documented instructions

Flagship Dispatcher will process Customer Personal Data only:

•  On the Customer’s documented instructions

•  As required to provide the Service

•  As described in the Terms and this Agreement

•  As instructed through the Customer’s use and configuration of the Service

•  As requested through authorised support communications; or

•  Where required by applicable law.

The Customer’s configuration of user permissions, platform features, communications, integrations, retention settings and processing functions constitutes documented instructions.

Where applicable law requires Flagship Dispatcher to process Customer Personal Data other than on the Customer’s instructions, Flagship Dispatcher will inform the Customer before carrying out that processing unless the law prohibits such notification.

Flagship Dispatcher will notify the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law.

Flagship Dispatcher may suspend an affected instruction until the Parties have clarified or corrected it.

Flagship Dispatcher will not:

•  Sell Customer Personal Data

•  Use Customer Personal Data for unrelated advertising

•  Create advertising profiles from Customer Personal Data

•  Process Customer Personal Data for an unrelated independent commercial purpose; or

•  Disclose Customer Personal Data except as authorised by this Agreement, the Customer or applicable law.

Flagship Dispatcher may create statistical or aggregated information from use of the Service where that information has been anonymised so that it no longer identifies the Customer or any individual.

D8. Customer responsibilities

The Customer is responsible for determining whether its collection and use of Customer Personal Data is lawful.

The Customer must:

•  Have an appropriate lawful basis for each processing activity

•  Provide required privacy information to passengers, drivers, staff and other Data Subjects

•  Obtain consent where consent is legally required

•  Ensure Customer Personal Data is relevant, accurate and not excessive

•  Enter only information reasonably required for legitimate business purposes

•  Establish appropriate retention periods

•  Respond to Data Subject requests

•  Comply with electronic-marketing requirements

•  Ensure driver and employee monitoring is lawful, necessary and proportionate

•  Control which Authorised Users can access Personal Data

•  Remove access promptly when no longer required

•  Protect its user accounts, passwords and devices

•  Maintain appropriate backups and continuity arrangements

•  Carry out any required Data Protection Impact Assessment

•  Ensure that instructions given to Flagship Dispatcher are lawful; and

•  Inform Flagship Dispatcher of any change that materially affects the lawfulness of the processing.

The Customer must not instruct Flagship Dispatcher to process Personal Data in a manner that infringes Applicable Data Protection Law.

D9. Children and vulnerable passengers

The Customer may use the Service in connection with school transport, special educational needs transport, social-care transport or services involving children or vulnerable adults.

The Customer remains responsible for:

•  Establishing a lawful basis for that processing

•  Providing appropriate privacy information

•  Applying safeguarding requirements

•  Limiting access to authorised personnel

•  Ensuring that only necessary information is entered

•  Determining whether a Data Protection Impact Assessment is required; and

•  Applying any requirements imposed by a council, school, care organisation or other relevant authority.

Flagship Dispatcher will process such information only as instructed through the Service and in accordance with this Agreement.

D10. Special Category Data and criminal-offence information

The Service may allow the Customer to enter information concerning:

•  Disability or accessibility requirements

•  Medical or health-related travel requirements

•  Special assistance

•  Safeguarding requirements

•  Driver background-check status

•  Disclosure and Barring Service information; or

•  Other Special Category Data or criminal-offence information.

The Customer must not enter this information unless:

•  It is necessary for a legitimate purpose

•  The Customer has identified an appropriate lawful basis

•  An additional condition for processing Special Category Data or criminal-offence information applies

•  The information provided is limited to what is necessary

•  Access is restricted appropriately; and

•  The Customer has provided required privacy information.

Flagship Dispatcher does not independently determine whether the Customer is entitled to process such information.

Unless a specific Service feature expressly requires it, the Customer should record only the status, outcome or expiry information needed for operational purposes rather than unnecessary copies or details.

D11. Confidentiality and authorised personnel

Flagship Dispatcher will ensure that people authorised to process Customer Personal Data:

•  Access it only where required for their role

•  Are subject to contractual or statutory confidentiality duties

•  Receive appropriate instructions concerning data protection and security

•  Process the information only as authorised; and

•  Have access removed when it is no longer required.

Access by Flagship Dispatcher personnel will be limited according to role and legitimate need.

Customer Personal Data may be accessed for support only where necessary to investigate a request, correct an error, protect the Service or comply with an authorised instruction.

D12. Security

Flagship Dispatcher will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against:

•  Accidental or unlawful destruction

•  Loss

•  Alteration

•  Unauthorised disclosure

•  Unauthorised access

•  Misuse; and

•  Unavailability.

The measures will take account of:

•  The nature and sensitivity of the Personal Data

•  The scope, context and purpose of the processing

•  The likelihood and severity of risks to individuals

•  Available technology

•  Implementation costs; and

•  The need to maintain confidentiality, integrity, availability and resilience.

The measures maintained by Flagship Dispatcher are described in Annex B.

Flagship Dispatcher may update its security measures as technology and risks change, provided that it does not materially reduce the overall protection of Customer Personal Data.

The Customer acknowledges that security is a shared responsibility. The Customer must configure user access appropriately, protect its own devices and credentials, and ensure its Authorised Users use the Service securely.

Appropriate security measures under Article 32 are risk-based and should address confidentiality, integrity, availability, resilience, recovery and regular testing.

D13. Personal Data Breaches

Flagship Dispatcher will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Where available, the notification will include:

•  A description of the nature of the breach

•  The categories of affected Data Subjects

•  The categories of affected Personal Data

•  The approximate number of affected records or individuals

•  The likely consequences

•  Measures taken or proposed to contain or address the breach

•  Measures intended to reduce possible adverse effects; and

•  Contact information for further communication.

Where complete information is not immediately available, Flagship Dispatcher may provide information in stages as the investigation develops.

Flagship Dispatcher will take reasonable steps to:

•  Contain the breach

•  Preserve relevant evidence

•  Investigate the cause

•  Mitigate adverse effects

•  Correct relevant vulnerabilities; and

•  Prevent a recurrence where reasonably possible.

Flagship Dispatcher will provide reasonable assistance to help the Customer determine whether notification to the ICO, another authority or affected individuals is required.

Unless legally required to act independently, the Customer is responsible for deciding whether and how to notify:

•  The ICO

•  Another Supervisory Authority

•  Affected individuals

•  A council or contracting authority

•  An insurer; or

•  Another relevant organisation.

Notification by Flagship Dispatcher does not constitute an admission of fault or liability.

D14. Data Subject requests

If Flagship Dispatcher receives a request directly from a Data Subject concerning Customer Personal Data, it will:

•  Notify the Customer without undue delay

•  Provide the request to the Customer where legally permitted; and

•  Not respond substantively unless authorised by the Customer or required by law.

Taking account of the nature of the processing, Flagship Dispatcher will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests involving:

•  Access

•  Rectification

•  Erasure

•  Restriction

•  Objection

•  Data portability; and

•  Rights relating to automated decision-making, where applicable.

The Customer remains responsible for:

•  Verifying the requester’s identity

•  Determining whether the request is valid

•  Applying any exemptions

•  Responding within the applicable deadline; and

•  Keeping an appropriate record of the response.

Where a request requires substantial bespoke technical work beyond the standard functions of the Service, Flagship Dispatcher may charge reasonable costs agreed with the Customer in advance, except where charging would conflict with Applicable Data Protection Law.

D15. Assistance with compliance

Taking account of the nature of the processing and the information available to it, Flagship Dispatcher will provide reasonable assistance to help the Customer comply with obligations concerning:

•  Security of processing

•  Personal Data Breach assessments and notifications

•  Communication of breaches to Data Subjects

•  Data Protection Impact Assessments

•  Prior consultation with the ICO or another authority

•  Data Subject rights

•  Records of processing

•  Controller-processor accountability; and

•  International-transfer assessments.

The Customer must provide sufficient information about the proposed processing for Flagship Dispatcher to provide meaningful assistance.

D16. Subprocessors

The Customer gives Flagship Dispatcher general written authorisation to appoint the Subprocessors listed in Annex C.

Flagship Dispatcher will ensure that each Subprocessor processing Customer Personal Data is subject to a written agreement requiring data-protection obligations that provide an equivalent level of protection to the relevant obligations in this Agreement.

Flagship Dispatcher remains responsible to the Customer for the performance of its Subprocessors’ data-protection obligations to the extent required by Applicable Data Protection Law.

Changes to Subprocessors

Flagship Dispatcher may appoint or replace a Subprocessor.

Where reasonably practicable, Flagship Dispatcher will give the Customer advance notice of a material new Subprocessor by:

•  Email

•  A notification within the Customer’s Account

•  Updating a published Subprocessor list; or

•  Another appropriate written method.

The Customer may object within 14 days of receiving notice where it has reasonable and documented data-protection grounds.

The Parties will work in good faith to resolve the objection.

Where the objection cannot reasonably be resolved, Flagship Dispatcher may:

•  Avoid using the Subprocessor for that Customer where technically and commercially practical

•  Discontinue the affected feature; or

•  Allow the Customer to terminate the affected Service.

Where termination results solely from a valid unresolved Subprocessor objection, Flagship Dispatcher will refund any prepaid Subscription Fees covering the unused period of the affected Service.

Flagship Dispatcher may appoint a Subprocessor on shorter notice where urgent action is reasonably required to:

•  Address a security incident

•  Prevent service interruption

•  Comply with law

•  Replace a provider that has unexpectedly ceased providing a service; or

•  Protect Customer Personal Data.

Flagship Dispatcher will provide notice as soon as reasonably practicable in those circumstances.

D17. Customer-selected third-party services

The Customer may choose to connect the Service to third-party products such as:

•  Payment services

•  Mapping or navigation services

•  Email providers

•  Accounting software

•  Booking platforms

•  Flight-information services; or

•  Other integrations.

Where the Customer enters into a contract directly with the third party, that third party may act as:

•  The Customer’s processor

•  An independent controller; or

•  Another recipient of Personal Data.

The third party’s own terms and privacy documentation will apply to its independent processing.

Flagship Dispatcher is not responsible for processing carried out independently by a third party selected and controlled directly by the Customer.

The Customer instructs Flagship Dispatcher to transfer information to a connected service where the Customer activates and uses that integration.

D18. International transfers

Flagship Dispatcher will not make a Restricted Transfer of Customer Personal Data unless:

•  The Customer has authorised the transfer

•  The destination is covered by applicable adequacy regulations

•  An approved safeguard is in place

•  A legally available exception applies; or

•  Another lawful transfer mechanism is used.

Approved safeguards may include:

•  The UK International Data Transfer Agreement

•  The UK Addendum to the EU Standard Contractual Clauses

•  Approved EU Standard Contractual Clauses where the EU GDPR applies

•  Binding corporate rules

•  An approved certification or code mechanism; or

•  Another safeguard recognised by Applicable Data Protection Law.

Where required, Flagship Dispatcher will:

•  Enter into an appropriate transfer agreement

•  Carry out a transfer-risk assessment

•  Apply reasonable supplementary measures

•  Assess the relevant recipient

•  Keep appropriate transfer records; and

•  Provide relevant information to the Customer.

The Customer authorises transfers necessarily arising from use of the approved Subprocessors identified in Annex C, subject to the safeguards described above.

A UK processor that initiates a transfer to an overseas Subprocessor is responsible for complying with the applicable international-transfer rules.

D19. Government and law-enforcement requests

Where Flagship Dispatcher receives a legally binding request for Customer Personal Data from a court, regulator, government body or law-enforcement authority, it will, where legally permitted:

•  Notify the Customer

•  Review the validity and scope of the request

•  Seek clarification where appropriate

•  Challenge an unlawful or disproportionate request where reasonably possible

•  Disclose only information legally required; and

•  Document its response.

Nothing in this section requires Flagship Dispatcher to act unlawfully or place itself in contempt of court.

D20. Return and deletion of Customer Personal Data

During the Subscription, the Customer may use available Service functions to access or export Customer Personal Data.

When the Contract ends, the Customer may choose to:

•  Export or receive a return of Customer Personal Data; or

•  Request deletion of Customer Personal Data.

Unless the Customer requests earlier deletion, Flagship Dispatcher will normally keep the Account available for data export for up to 30 days after termination.

After that period, Flagship Dispatcher may delete or anonymise Customer Personal Data held in active systems.

Customer Personal Data held in protected backups may remain for up to 90 days after deletion from active systems, after which it will be overwritten or deleted through the normal backup cycle.

During that backup period:

•  Backup information will remain protected

•  It will not be used for an unrelated purpose

•  It will not normally be restored to active systems

•  Access will remain restricted; and

•  If restored for disaster recovery, it will remain subject to this Agreement and be deleted again in accordance with the applicable cycle.

Flagship Dispatcher may retain information where required by law, court order, regulatory requirement or the establishment, exercise or defence of legal claims.

Any retained information will remain protected and will not be processed for another purpose.

On reasonable written request, Flagship Dispatcher will confirm completion of deletion, subject to backup cycles and legal-retention obligations.

The Customer is responsible for exporting records it is legally required to retain before access ends.

D21. Audits and compliance information

Flagship Dispatcher will provide information reasonably necessary to demonstrate compliance with the processor obligations covered by this Agreement.

This may include, where available and appropriate:

•  Relevant security documentation

•  Policies or summaries

•  Subprocessor information

•  Data-location information

•  Breach-response information

•  Independent provider reports

•  Security-assessment responses; and

•  Evidence concerning deletion or access controls.

The Customer may conduct a reasonable audit itself or through an independent auditor.

Except where an audit follows a significant Personal Data Breach, suspected material non-compliance or a regulatory request:

•  The Customer should give at least 20 Business Days’ written notice

•  Audits should normally be limited to once in any 12-month period

•  The audit must take place during normal business hours

•  The auditor must be appropriately qualified

•  The auditor must be subject to confidentiality obligations

•  The audit must not unreasonably interfere with Flagship Dispatcher’s business

•  The audit must not expose another customer’s information

•  The audit must not compromise Service security; and

•  The Customer will bear its own audit costs.

Flagship Dispatcher may satisfy an audit request initially by providing written information, security documentation or appropriate third-party assurance.

Direct system access, penetration testing or source-code inspection requires separate written agreement and appropriate security controls.

These restrictions do not prevent an audit or inspection legally required by the ICO or another competent authority.

D22. Records and regulatory cooperation

Flagship Dispatcher will maintain records of processing activities where required by Applicable Data Protection Law.

Flagship Dispatcher will cooperate with the ICO or another competent Supervisory Authority in relation to processing covered by this Agreement.

The Customer must promptly provide information reasonably required to respond to a regulatory enquiry relating to the Customer’s instructions or use of the Service.

D23. Independent-controller processing by Flagship Dispatcher

Flagship Dispatcher may act as an independent Controller for certain information, including information used for:

•  Customer-account administration

•  Subscription billing

•  Contract management

•  Fraud prevention

•  Service security

•  Authentication

•  Legal compliance

•  Insurance

•  Establishing or defending legal claims

•  Business communications; and

•  Managing its relationship with the Customer.

That independent processing is governed by the Flagship Dispatcher Privacy Policy rather than this Agreement.

Where the same information is used both on the Customer’s behalf and for a legitimate independent purpose, the relevant legal role will depend on the processing activity concerned.

D24. Liability

Liability arising from or connected with this Agreement is subject to the limitation-of-liability and indemnity provisions contained in the Flagship Dispatcher Terms and Conditions, including section 35 and section 36 of those Terms.

Nothing in this Agreement:

•  Limits the statutory rights of a Data Subject

•  Restricts the powers of the ICO or another Supervisory Authority

•  Excludes liability that cannot legally be excluded; or

•  Prevents a Party from seeking contribution from another Party to the extent permitted by Applicable Data Protection Law.

Each Party remains responsible for its own compliance with the obligations that apply directly to it.

D25. Duration and termination

This Agreement begins when it becomes binding under D4.

It remains in force until Flagship Dispatcher has:

•  Stopped processing Customer Personal Data; and

•  Deleted or returned Customer Personal Data in accordance with D20.

Provisions concerning confidentiality, security, deletion, audits, liability and international transfers continue for as long as Flagship Dispatcher or a Subprocessor retains Customer Personal Data.

D26. Changes to this Agreement

Flagship Dispatcher may update this Agreement where reasonably necessary to:

•  Comply with changes in law

•  Follow binding regulatory guidance

•  Reflect changes to the Service

•  Update Subprocessors

•  Improve data-protection safeguards; or

•  Correct an error or ambiguity.

Flagship Dispatcher will provide reasonable notice of a material change.

An update will not materially reduce the protection of Customer Personal Data unless:

•  Required by law

•  Required to address a serious security risk; or

•  Agreed with the Customer.

Where a change materially and adversely affects the Customer’s data-protection rights, the Customer may object before the change takes effect.

D27. Notices and data-protection contact

Data-protection notices to Flagship Dispatcher should be sent to:

Flagship Dispatcher

Email: flagshipdispatcher@gmail.com

The Customer must keep its own account and data-protection contact information accurate.

Notices may be sent through email, the Customer Account or another agreed written method.

D28. Governing law and jurisdiction

This Agreement and any dispute or non-contractual obligation arising from it are governed by the laws of England and Wales.

The courts of England and Wales will have exclusive jurisdiction, unless Applicable Data Protection Law requires otherwise.

Flagship Transfers Limited  |  Company No. 14615959  |  Page

FLAGSHIP DISPATCHER  |  TERMS AND CONDITIONS

Annex A – Details of the Processing

A1. Subject matter

The processing of Personal Data required to provide the Flagship Dispatcher dispatch-management platform, Driver App and connected services to the Customer.

A2. Duration

Processing will continue:

•  During the Customer’s Trial

•  During the paid Subscription

•  During any agreed transition or export period

•  For up to 30 days after termination for active-system export, unless earlier deletion is requested

•  For up to 90 days in protected backups; and

•  For any longer period where retention is legally required.

A3. Nature and purpose

The purposes of processing may include:

•  Creating and managing bookings

•  Managing quote requests

•  Managing passenger and customer records

•  Managing outbound and return journeys

•  Assigning drivers and vehicles

•  Displaying assigned work in the Driver App

•  Recording journey status and progress

•  Providing dispatch and operational oversight

•  Providing live location and tracking functions

•  Managing driver and vehicle documents

•  Recording document approvals and expiry dates

•  Managing driver earnings and payouts

•  Recording fares, invoices and payment status

•  Managing expenses

•  Providing payment links

•  Sending emails, SMS messages and push notifications

•  Sending review requests

•  Managing subcontracted work

•  Providing marketplace functionality

•  Managing account customers

•  Providing bulk-booking functionality

•  Providing booking forms and website-builder functions

•  Providing navigation and flight-information integrations

•  Providing AI-assisted booking extraction where enabled

•  Providing support and troubleshooting

•  Maintaining security logs

•  Preventing fraud and misuse

•  Maintaining backups; and

•  Deleting or returning information.

A4. Processing operations

Processing may include:

•  Collection

•  Recording

•  Organisation

•  Structuring

•  Storage

•  Retrieval

•  Consultation

•  Display

•  Transmission

•  Sharing with authorised users

•  Sharing with approved Subprocessors

•  Updating

•  Correction

•  Restriction

•  Export

•  Backup

•  Deletion; and

•  Destruction.

A5. Categories of Data Subjects

Customer Personal Data may relate to:

•  Passengers

•  Prospective passengers

•  Customers and bookers

•  Corporate account contacts

•  Children

•  Parents and guardians

•  Vulnerable adults

•  Individuals requiring accessible or assisted transport

•  Drivers

•  Prospective drivers

•  Passenger assistants

•  Vehicle owners

•  Customer employees

•  Dispatchers

•  Administrators

•  Contractors

•  Subcontractors

•  Personnel of other transport operators

•  Emergency contacts

•  Council, school, care-provider or corporate contacts

•  Users submitting quote or booking forms

•  Individuals leaving reviews or feedback; and

•  Other individuals whose information is lawfully entered by the Customer.

A6. Types of Personal Data

Customer Personal Data may include:

Identity information

•  Names

•  Titles

•  Customer or passenger references

•  User IDs

•  Driver IDs

•  Dates of birth where required

•  Profile photographs; and

•  Identity or licensing document information.

Contact information

•  Telephone numbers

•  Email addresses

•  Home or business addresses

•  Emergency-contact information; and

•  Communication preferences.

Journey and booking information

•  Pickup and drop-off addresses

•  Intermediate stops

•  Journey dates and times

•  Return-journey information

•  Flight, train or ferry information

•  Passenger numbers

•  Luggage information

•  Child-seat requirements

•  Vehicle requirements

•  Journey notes

•  Booking references

•  Booking history

•  Cancellation information

•  No-show records

•  Waiting-time records

•  Subcontracting information; and

•  Marketplace information.

Driver and staff information

•  Contact details

•  Driver status

•  Availability

•  Assigned and completed jobs

•  Employment or contractor status

•  Driver earnings

•  Payment records

•  Performance or acceptance information

•  Checklist records

•  Notes

•  Communications; and

•  Account-access information.

Driver and vehicle documents

•  Driving-licence information

•  Private hire driver-licence information

•  Operator or vehicle-licence details

•  Insurance documents

•  MOT documents

•  Vehicle plate information

•  Registration numbers

•  Vehicle make, model, colour and capacity

•  Document images

•  Expiry dates

•  Approval status

•  Background-check status where configured; and

•  Other documents required by the Customer.

Location information

•  Driver location

•  Vehicle location

•  Journey progress

•  Route information

•  Pickup arrival information

•  Tracking-link information; and

•  Location timestamps.

Financial and transaction information

•  Fares

•  Driver pay

•  Commission

•  Expenses

•  Invoice information

•  Account balances

•  Payment method category

•  Payment status

•  Payment-link information

•  Transaction identifiers; and

•  Refund or cancellation information.

The Service is not intended to store full payment-card numbers, card security codes or online-banking credentials.

Communications

•  Email and SMS content

•  Push-notification information

•  Customer messages

•  Driver messages

•  Booking notes

•  Complaint information

•  Support communications

•  Review requests

•  Review history; and

•  Communication delivery status.

Technical and security information

•  Account identifiers

•  Device identifiers

•  Push-notification tokens

•  IP addresses

•  Browser and device information

•  Login information

•  Authentication records

•  Audit logs

•  Error logs

•  Security events; and

•  App diagnostic information.

A7. Special categories and sensitive information

Depending on the Customer’s use of the Service, Customer Personal Data may include:

•  Health information

•  Disability information

•  Accessibility requirements

•  Mobility requirements

•  Special assistance

•  Safeguarding information

•  Information concerning children

•  Criminal-offence or background-check status; and

•  Other sensitive passenger or driver information.

The Customer controls whether such information is entered and is responsible for establishing the necessary lawful basis and safeguards.

A8. Frequency

Processing may occur continuously while the Customer uses the Service.

Location processing may occur at intervals while relevant Driver App or tracking functions are enabled.

Communications processing occurs when messages or notifications are sent.

Backup and security processing may occur automatically and regularly.

A9. Geographical scope

Customer Personal Data may be processed:

•  In the United Kingdom

•  Within the Customer-selected cloud-hosting region

•  In the European Economic Area

•  In countries covered by UK adequacy regulations; and

•  In other countries where an approved Subprocessor operates, subject to lawful transfer safeguards.

A10. Customer rights and obligations

The Customer retains the right to:

•  Determine the purpose of the processing

•  Configure the Service

•  Add, amend and delete Customer Data

•  Control Authorised Users

•  Request assistance

•  Export information

•  Give additional lawful instructions

•  Object to relevant Subprocessor changes

•  Request return or deletion; and

•  Exercise its audit rights under this Agreement.

Flagship Transfers Limited  |  Company No. 14615959  |  Page

FLAGSHIP DISPATCHER  |  TERMS AND CONDITIONS

Annex B – Technical and Organisational Security Measures

Flagship Dispatcher will maintain measures appropriate to the risk presented by the processing. The following measures describe the security framework applied to live Customer Personal Data, taking account of the relevant Service, provider and risk.

B1. Information-security governance

Flagship Dispatcher will:

•  Assign responsibility for information security

•  Maintain appropriate security and data-protection procedures

•  Assess material security risks

•  Review measures as the Service changes

•  Document material incidents

•  Maintain a process for responding to breaches; and

•  Review significant security weaknesses and remedial actions.

B2. Access control

Flagship Dispatcher will use controls designed to ensure that:

•  Users have unique accounts

•  Access is limited according to role

•  Operator information is logically separated between Customer accounts

•  Privileged access is restricted

•  Access is removed when no longer required

•  Administrative access is limited to authorised personnel

•  Support access is used only where necessary; and

•  Access permissions can be reviewed.

B3. Authentication

Security measures will include, as appropriate:

•  Password requirements

•  Secure password hashing

•  Protection against repeated unauthorised login attempts

•  Secure session management

•  Session expiry

•  Reset and recovery controls

•  Multi-factor authentication for privileged infrastructure access

•  Protection of authentication tokens; and

•  Revocation of compromised sessions or credentials.

B4. Encryption and transmission security

Flagship Dispatcher will use:

•  HTTPS and current TLS protection for data transmitted between supported browsers, apps and the Service

•  Encryption for production cloud storage, databases, volumes and backups where supported and appropriate

•  Secure methods for transferring administrative information

•  Restricted access to encryption keys and credentials; and

•  Protected secret-management practices.

B5. Uploaded documents

Driver, vehicle and company documents will be protected through measures designed to ensure that:

•  Storage is not publicly browsable

•  Access requires authentication or an appropriately controlled link

•  Links are time-limited or access-controlled where appropriate

•  Documents are available only to authorised users

•  Storage permissions are reviewed

•  Unnecessary public access is blocked; and

•  Deleted documents are removed in accordance with applicable retention processes.

B6. Application and infrastructure security

Flagship Dispatcher will maintain reasonable measures concerning:

•  Secure configuration

•  Network controls

•  Firewalls or equivalent cloud controls

•  Separation of production and development environments

•  Patch management

•  Dependency updates

•  Vulnerability management

•  Code review or change review

•  Restricted production access

•  Protection of credentials and API keys

•  Secure deployment processes; and

•  Removal or disabling of unused access.

B7. Tenant separation

The Service will use technical and application controls intended to prevent one Customer from accessing another Customer’s Personal Data.

Database queries, object-storage access, API requests and user permissions should apply the relevant Customer or tenant identifier.

B8. Logging and monitoring

Flagship Dispatcher will maintain appropriate logs concerning matters such as:

•  Authentication

•  Failed login attempts

•  Privileged activity

•  Security-relevant account changes

•  System errors

•  Infrastructure events

•  Unauthorised-access attempts; and

•  Material administrative actions.

Logs will be protected from unauthorised alteration and retained for a period appropriate to the security purpose.

B9. Backups and resilience

Measures will include:

•  Regular backups appropriate to operational risk

•  Restricted access to backups

•  Protection of backup credentials

•  Separation of backup copies where appropriate

•  Processes for restoring systems

•  Periodic review or testing of recovery processes

•  Monitoring of backup failures; and

•  Deletion through the normal backup lifecycle.

B10. Incident management

Flagship Dispatcher will maintain procedures for:

•  Identifying security incidents

•  Escalating incidents

•  Containing affected systems

•  Preserving relevant evidence

•  Investigating causes

•  Assessing affected Personal Data

•  Notifying Customers

•  Recovering services

•  Recording decisions; and

•  Applying lessons learned.

B11. Mobile and notification security

Flagship Dispatcher will:

•  Limit sensitive information included in lock-screen push notifications where reasonably possible

•  Use authorised notification services

•  Protect notification tokens

•  Avoid including unnecessary passenger information in notification payloads

•  Apply appropriate app authentication

•  Revoke access when a driver account is disabled; and

•  Take reasonable steps to prevent unauthorised access to Driver App information.

B12. Location information

Location information will be subject to controls designed to:

•  Restrict visibility to authorised users

•  Associate location information with the correct Customer

•  Limit collection to relevant app or operational functions

•  Prevent unrelated public access

•  Apply appropriate retention

•  Stop or restrict processing when the relevant tracking function is no longer active; and

•  Protect tracking links against unauthorised use.

B13. Staff and contractors

People with access to Customer Personal Data will be:

•  Subject to confidentiality obligations

•  Given access according to need

•  Provided with appropriate security instructions

•  Required to protect credentials

•  Required to report suspected incidents; and

•  Have access removed when their role ends.

B14. Supplier management

Flagship Dispatcher will:

•  Assess relevant service providers

•  Use written agreements

•  Apply Article 28-equivalent obligations to Subprocessors

•  Review available security information

•  Monitor material provider changes

•  Maintain a Subprocessor record; and

•  Apply lawful international-transfer safeguards.

B15. Development and testing

Where reasonably practicable:

•  Live Personal Data will not be used in public demonstrations

•  Test information will be fictional, anonymised or minimised

•  Development access will be restricted

•  Changes will be tested before production release

•  Security-sensitive changes will receive appropriate review; and

•  Software secrets will not be deliberately published in source code or public repositories.

B16. Deletion and disposal

Flagship Dispatcher will use processes designed to:

•  Remove deleted information from active systems

•  Restrict access during retention periods

•  Overwrite backup information through the normal lifecycle

•  Revoke obsolete access

•  Delete temporary exports when no longer required; and

•  Securely dispose of storage media where applicable.

B17. Physical security

Physical security for cloud-hosted infrastructure will primarily be provided by the relevant cloud infrastructure provider.

Flagship Dispatcher will apply reasonable controls to any device or location under its direct control that can access production systems.

Flagship Transfers Limited  |  Company No. 14615959  |  Page

FLAGSHIP DISPATCHER  |  TERMS AND CONDITIONS

Annex C – Approved Subprocessors

Only providers actually used for the relevant Service or Customer will process Customer Personal Data.

C1. Amazon Web Services

Provider: Amazon Web Services, Inc. and relevant AWS affiliates.

Purpose

•  Cloud infrastructure

•  Compute services

•  Data storage

•  Object and document storage

•  Databases

•  Backups

•  Network and security services; and

•  Transactional email delivery where Amazon SES is used.

Information processed: Customer Personal Data required to host and operate the Service.

Processing location: Primarily the AWS region selected by Flagship Dispatcher, together with limited support, security and ancillary processing locations permitted under the AWS contractual arrangements.

C2. Google services and Firebase

Provider: Google LLC and relevant Google affiliates.

Purpose

•  Support email and customer communications where Gmail or Google Workspace is used

•  Firebase Cloud Messaging

•  Mobile push notifications

•  Mobile app infrastructure

•  Crash or diagnostic services where enabled

•  Mapping, geocoding or location services where enabled; and

•  Other Google Cloud or Firebase services configured for the Service.

Information processed may include

•  Device tokens

•  User identifiers

•  Notification information

•  App diagnostic information

•  Locations

•  Addresses; and

•  Mapping queries.

Processing location: United Kingdom, European Economic Area, United States and other permitted service locations, subject to applicable transfer safeguards.

C3. Twilio

Provider: Twilio Inc. and relevant Twilio affiliates.

Purpose

•  SMS delivery

•  Telephone-number services

•  Communication delivery

•  Delivery-status reporting; and

•  Related communications infrastructure.

Information processed may include

•  Recipient telephone numbers

•  Sender information

•  Message content

•  Booking or payment-link information included in a message

•  Delivery status; and

•  Communication metadata.

Processing location: United Kingdom, European Economic Area, United States and other permitted Twilio service locations, subject to applicable transfer safeguards.

C4. Stripe

Provider: Relevant Stripe group entity, including Stripe Payments UK Ltd where applicable.

Purpose

•  Subscription payment processing

•  Customer-enabled payment links

•  Payment-status information

•  Transaction processing; and

•  Fraud-prevention services.

Information processed may include

•  Customer or payer name

•  Email address

•  Billing information

•  Transaction identifiers

•  Payment status

•  Payment amount; and

•  Payment metadata.

Stripe may act as a Processor for some activities and as an independent Controller for others. Its own services agreement, privacy documentation and Data Processing Agreement apply to its processing.

C5. Apple Push Notification Service

Provider: Apple Inc. and relevant Apple affiliates.

Purpose

•  Delivering push notifications to iOS devices; and

•  Supporting the Driver App on Apple devices.

Information processed may include

•  Device tokens

•  App identifiers

•  Notification payloads; and

•  Delivery-related technical information.

Notification content should be limited to what is operationally necessary.

C6. Updates and optional providers

Only providers actually used for the relevant Service or Customer will process Customer Personal Data.

If Flagship Dispatcher introduces another provider that will process Customer Personal Data on its behalf, including an artificial-intelligence, flight-information, analytics, error-monitoring, email or communications provider, that provider will be added to the approved Subprocessor information and notice will be provided in accordance with D16.

An optional AI-assisted feature will not be enabled to send live Customer Personal Data to an unnamed third-party AI provider until appropriate contractual and international-transfer safeguards are in place and the Customer has been informed in accordance with D16.

A third-party service selected and contracted directly by the Customer is governed by D17 and is not treated as a Flagship Dispatcher Subprocessor merely because the Customer connects it to the Service.