Privacy & data responsibility

Your data.
Your control.
Clear accountability.

You should know where your data comes from, what DAIOTA does with it, and how the results return to your organisation.

We provide analytical services. Providing those services does not transfer ownership of your source data to DAIOTA.

Understand your data rightsRead the key questions
A clear path from source to insight
Your organisation or authorised providerFleet, insurance or third-party data source
DAIOTA analytical processingWithin the agreed purpose and integration scope
Analytical outputs via APIReturned to your organisation
Your people. Your decisions.Decision support with human responsibility

Source records and derived analytical outputs are different. Their meaning should remain clear.

Your source data stays yours

Service access does not give DAIOTA ownership of your organisation’s source data.

A defined purpose for processing

Data access and permitted use are tied to the agreed service and integration.

Outputs you can put to work

API delivery brings analytical results back into your organisation’s workflow.

01 / DATA RIGHTS & ROLES

Service access is not data ownership.

Your organisation’s source data does not become DAIOTA’s property because it is used to provide our services. The applicable agreement defines access, permitted use and the rights of your organisation and its authorised data providers.

Contractual rights over data and the privacy rights of individuals are separate. Where information relates to an identifiable person, the responsibilities of each party depend on its actual role, the processing activity and applicable law.

A clear agreement comes first. The purpose, data categories and responsibilities should be understood before an integration begins.

02 / AUTHORISED SOURCES

Data starts with your sources.

Depending on the engagement, DAIOTA receives inputs directly from a fleet operator or insurer, or through an authorised third-party provider. The source and the scope of access are defined for the integration.

Direct from your organisation

Data made available by your fleet or insurance organisation for the agreed analytical service.

Through an authorised provider

Inputs supplied through a third-party source within the permitted scope of the engagement.

Relevant inputs may include vehicle telemetry, activity records and the operational or programme context needed for the service. The actual categories depend on your integration; a general description is not permission to collect additional data.

03 / PURPOSE & INTEGRITY

Analysis does not rewrite the source.

DAIOTA processes authorised inputs to produce the agreed analytical outputs. Processing can include quality checks, standardisation, validation and the creation of derived metrics or estimates.

These operations are different from editing a source record in your organisation’s or provider’s system. Access and any ability to write back to a source system must be explicitly defined in the integration and agreement.

Observed data and estimates must remain distinguishable. An analytical estimate is not an original measurement. Missing or unavailable data must not be presented as an observed zero.

Permitted uses are defined by the engagement. Any separate purpose—such as unrelated advertising, onward sale or model training—requires its own valid authorisation and applicable terms; access for one service is not blanket permission for another use.

04 / DELIVERY

Insights return through your API integration.

DAIOTA delivers analytical results through the agreed API integration so your organisation can use them in its own workflows. The integration defines which outputs are available and who is authorised to receive them.

If your engagement also includes Web or private Slack delivery, those channels and their authorised recipients are defined separately. API delivery does not, by itself, mean that no data is accessed, processed or retained.

Outputs support review and human decisions. They should not be represented as an automatic insurance decision, an accident probability or a causal finding.

05 / DATA HANDLING

Clarity throughout the data lifecycle.

Your service terms and data-processing arrangements should explain the practical boundaries of data handling:

  • Access: the people and service providers permitted to handle data, and for what purpose.
  • Storage and retention: what is retained, where processing takes place, and the retention period or criteria—including logs, caches and backups where applicable.
  • Return and deletion: the arrangements at the end of the engagement, including backup timelines and any applicable legal retention requirements.
  • Transfers and service providers: relevant hosting locations, subprocessors and cross-border processing where applicable.
  • Protection and incident handling: the applicable safeguards, points of contact and arrangements for responding to a data incident.

Ask for the details relevant to your deployment. A delivery method alone does not answer these questions, and a privacy overview is not a substitute for the agreed data-processing terms.

06 / WEBSITE & ENQUIRIES

Business enquiries are a separate data flow.

When you contact DAIOTA or request a demo, the details you choose to provide—such as your name, business email, company and message—are used to handle your enquiry and discuss the relevant service.

Please do not include driver-level records, customer policy files, credentials or other sensitive service data in a general enquiry. Use the agreed integration or an appropriate transfer channel arranged with your organisation.

Website cookies, analytics, technical logs and third-party website services need their own disclosures, reflecting what is actually active. These details, the applicable retention arrangements and the legal entity responsible must be confirmed in the final website policy.

For personal-data requests relating to a fleet or insurance programme, contact the responsible organisation. DAIOTA can help identify the appropriate route within the relevant engagement.

Straight answers

The questions that matter.

Privacy should be understandable before you connect a data source.

Does DAIOTA become the owner of our data?

No. Providing the service does not transfer ownership of your organisation’s source data to DAIOTA. Access and permitted use are defined in the applicable agreement and remain subject to the rights of your organisation and its providers.

Where does DAIOTA receive data from?

From your fleet or insurance organisation, or from an authorised third-party provider, depending on the integration. The source, required inputs and processing purpose are agreed for the engagement.

Do you change the original data?

Analytical processing may standardise inputs or create derived outputs. That is different from changing records in the source system. Any write-back capability must be explicitly defined in the integration and agreement.

How do we receive the results?

Through the agreed API integration. If Web or private Slack is included, its recipients and access boundaries are defined as part of the engagement.

Does API delivery mean no data is stored?

No. API delivery describes how outputs are delivered. Storage, logs, backups and retention must be explained separately for your deployment in the relevant service and data-processing terms.

Can our data be used for another purpose?

Authorisation for the agreed service is not blanket permission for unrelated use. Any separate processing purpose needs its own valid authorisation and applicable terms.

Who should we contact about privacy?

For DAIOTA service or website questions, contact info@daiota.com. If your request relates to a fleet or insurance programme’s personal data, start with the responsible organisation; we can help identify the appropriate route.

Make the boundaries clear

Discuss your data requirements
before you connect.

Let’s clarify the source, permitted use, API outputs and data-handling terms for your organisation.

Staging design preview · 30 September 2026 · Final policy wording, deployment details and legal review remain pending before public release.