Last updated 5 August 2026
1. Controller and contact
Dean Martin, trading as DMSM Driving School and Dean Martin School of Motoring ("DMSM", "we", "us"), is the data controller for learner, instructor, waiting-list, lesson, payment, progress, message and business records managed through the app.
Contact us at info@deanmsm.co.uk, 07969 856 944, or Office 5, The Plough Business Hub, Church Street, Gainsborough, DN21 2JR.
Scope
2. Who this policy covers
This policy covers current, former and prospective learners; people on the waiting list; parents, guardians and emergency contacts; the instructor and authorised DMSM staff; and people who contact DMSM about tuition or app services.
Information
3. Personal data we process
Identity and account data: names, dates of birth, phone numbers, email and home addresses, pickup or drop-off addresses, driving-licence details, learner status, availability, previous experience, user and learner IDs, account and invitation status, session and security records, and terms-acceptance records.
Tuition and safety data: lesson bookings and history, attendance, cancellations, locations, progress and syllabus levels, lesson notes, tests and faults, reminders, messages, attachments and any relevant medical, medication, disability, neurodiversity, anxiety, eyesight, fitness-to-drive, support, safeguarding or safety information.
Payment and business data: lesson payments, purchase history, prepaid and allocated credit, remaining credit, refunds, adjustments, payment references and optional Starling Bank business-account transaction matches. The app does not collect learner card numbers, CVVs, bank passwords or learner online-banking credentials.
Device and service data: push tokens, device platform, app and operating-system version, notification status, network and synchronisation status, server revisions, limited security and diagnostic data, typed map or postcode searches, map coordinates returned for a session, IP address and provider-generated identifiers.
The current iOS app does not request precise device GPS location. A typed address, postcode, pickup point or map search can still describe a real place.
Sources
4. Where data comes from
We receive data directly from learners, prospective learners, parents or guardians, the instructor and authorised staff; from normal app use; from DMSM business systems and the service providers listed below; and from relevant SMS, email, telephone, website or social-media correspondence.
Purpose and lawful basis
5. Why we use personal data
We use data to create and secure app access; manage enquiries, waiting lists, learners, lessons, availability, pickup points, progress, tests, notes and attachments; maintain an accurate server-authoritative record across authorised devices; record payments and credit; send service messages; plan tuition safely; provide support; prevent conflicting changes; and meet business, accounting, tax, insurance, safeguarding and legal duties.
Our lawful bases are contract, legitimate interests, legal obligation and consent, depending on the activity. Vital interests or substantial-public-interest conditions may apply in exceptional safety or safeguarding cases.
Health, disability and other special-category information is processed only where both a UK GDPR lawful basis and a valid Data Protection Act condition apply, including explicit consent where appropriate, vital interests, legal claims or safeguarding and substantial-public-interest conditions. Consent may be withdrawn, but another lawful basis may still require DMSM to retain essential records.
Service providers
6. Who processes app data
Firebase and Google Cloud: authentication, learner access, the authoritative database, live updates, Cloud Functions, security controls and Firebase Storage for lesson attachments. They may process account and contact details, app records, messages, attachments, logs, IP addresses and security or diagnostic data.
Expo, Apple and Google: Expo push services, Apple Push Notification service and Firebase Cloud Messaging process push tokens, platform details, notification content and delivery data. Lock-screen visibility depends on device settings.
PureSMS by divergent: processes destination phone numbers, sender name, SMS content, timestamps, delivery status and routing information for lesson, payment, account and service messages.
Mapbox: supplies map tiles and geocoding and may receive typed searches, requested map areas or coordinates, IP address, device or connectivity details, SDK identifiers and map telemetry. DMSM does not use this information for advertising or cross-app tracking.
Starling Bank: when DMSM enables payment matching, Starling supplies transaction information from the DMSM business account to a protected backend function. This does not give the app access to a learner's bank account or credentials.
We may also disclose proportionate data to advisers, accountants, insurers, regulators, safeguarding bodies, courts or law-enforcement authorities where lawfully required. DMSM does not sell personal data or share it for third-party advertising.
Messages
7. SMS, push and direct contact
DMSM may send service messages about lessons, payments, delays, learner access, available gaps, progress, safety or important driving-school information. Push permission can be changed in device settings. Learners can ask DMSM to stop non-essential SMS, although direct contact may still be necessary for booked lessons, payment administration, account security or safety.
Authoritative sync
8. Local device data and offline use
The cloud service is authoritative for instructor and learner records. The app may keep limited session information, secure credentials or tokens, editor drafts and a last-known copy for fast, safe startup.
When the app cannot confirm a fresh server state, cached information is read-only. It cannot be used to overwrite newer cloud data. Editing becomes available only after the app has a current, server-confirmed state. Local information may remain until sign-out, clearing, app removal or operating-system cleanup.
International processing
9. International transfers
Some providers or subprocessors may process data outside the United Kingdom. Where required, DMSM relies on an applicable UK adequacy arrangement, UK International Data Transfer Agreement or Addendum, approved contractual safeguards or another lawful transfer mechanism, together with appropriate security measures.
Storage limitation
10. Retention
We retain data only as long as reasonably needed for tuition, support, accounting, tax, insurance, legal, safety, safeguarding, fraud-prevention, complaint or dispute purposes. We consider the type of record, whether tuition or account administration remains active, legal or contractual requirements, risk of a claim and provider retention settings.
Waiting-list records are reviewed when an enquiry is withdrawn or inactive. Active learner and lesson records are retained while tuition and related administration continue. Access credentials and sessions are revoked when an account closes. Accounting, payment, insurance, legal, safety and safeguarding records may be retained after app access ends where a valid obligation or legitimate need remains. Unneeded messages, attachments and profile information are deleted or anonymised during record review.
In-app request
11. Account deletion and data rights
A learner can start an account-deletion request in the app at Learner Profile > Account data > Request account deletion. The request is stored durably in the authoritative database, remains available after the app closes or another device is used, and shows its status and expected completion date.
After learner access is revoked, the app can continue showing the deletion result for up to 90 days. The device retains the random status token and DMSM retains only its one-way hash and expiry for that limited status check. It cannot be used to sign in, restore the account or access learner records. A daily cleanup removes expired status hashes while preserving the pseudonymous deletion audit.
DMSM will complete a valid request within 30 calendar days. Learner app access and active sessions are revoked as part of completion; personal data no longer needed is deleted; completion remains available through the saved in-app status check; and a final push notification may be sent where available. If identity evidence is reasonably needed, DMSM will request it promptly. The completion response explains any limited categories retained for accounting, tax, insurance, legal claims, complaints, safety or safeguarding, and why.
You may also request access, correction, erasure, restriction, eligible data portability, or object to legitimate-interests processing, and may withdraw consent where consent is the basis. Contact DMSM using section 1. You can complain to the Information Commissioner's Office, although we would appreciate the chance to address the concern first.
Protection
12. Security
DMSM uses authenticated access, Firebase security rules, server-side authorisation, encrypted network transport, protected backend secrets, server-confirmed writes, restricted learner views and secure device storage where available. No internet service is completely secure, so users should protect their device and login details and report suspected misuse promptly.
Young learners
13. Children and young learners
Driving learners are usually aged 17 or over, but a younger person may use the service in limited lawful circumstances. DMSM processes only what is needed for tuition, safety, account administration and legal duties. A parent or guardian may contact DMSM, subject to the learner's own rights and the circumstances.
Updates
14. Changes to this policy
We may update this policy when the app, providers, data uses, law or business processes change. The version and date at the top identify the current notice. Material changes may also be communicated in the app or directly where appropriate.