This Data Handling Policy should be read alongside our Privacy Policy, which explains your rights and our lawful bases for processing, and our Cookie Policy.
Scope and purpose
This policy applies to all personal data that we collect, process, or store in connection with our price comparison and lead generation service. It covers:
- Data submitted by users via our quote request form
- Data generated automatically (e.g., IP addresses, analytics)
- Data shared with our Supplier network
- Data stored in our CRM and other systems
- Data retained for legitimate business purposes (e.g., supplier monitoring, legal compliance)
We are committed to processing personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
Data handling lifecycle - overview
The diagram below illustrates how personal data moves through our systems from submission to deletion.
Data collection - from website to CRM
3.1 Quote request form
When you submit a quote request, the following data is collected:
- Name, email address, phone number, postcode
- Vehicle registration (looked up via DVLA API to retrieve make, model, engine code, fuel type, year)
- Mileage
- Description of the engine problem
All data is transmitted from your browser to our servers using TLS 1.3 encryption (the current industry standard). Our website uses HTTPS across all pages.
3.2 Web server logs
For security and debugging purposes, our web servers temporarily log:
- IP address
- Browser type and version
- Timestamp of request
- Pages requested
These logs are retained for 7 days and then automatically deleted. They are not used for any purpose other than detecting and preventing malicious activity (e.g., DDoS attacks, brute force attempts).
3.3 CRM processing
Once your quote request is validated, the data is entered into our Customer Relationship Management (CRM) system.
| Field | Details |
|---|---|
| CRM platform | [CRM NAME - e.g., HubSpot / Salesforce / custom platform] - insert your actual CRM here |
| Location of CRM servers | United Kingdom (primary) |
| Data encryption at rest | AES-256 |
| Access controls | Role-based access; only designated staff can access personal data |
| Audit logging | All access to personal data is logged |
Our CRM is configured to:
- Automatically record the date and time of each lead
- Track which Suppliers have viewed the lead (and when)
- Enforce the supplier cap (maximum 10 Suppliers per lead)
- Automatically close leads after 6 months of inactivity
Data sharing with Suppliers - mechanism and safeguards
Sharing your data with Suppliers is the core function of our service. We have implemented specific technical and contractual safeguards to protect your data while enabling Suppliers to provide accurate quotes.
4.1 How a lead is shared
| Step | Description |
|---|---|
| 1 | Your completed quote request enters our CRM. |
| 2 | The CRM identifies relevant Suppliers based on vehicle type, engine code, and your postcode location. |
| 3 | An anonymised version of your lead (showing vehicle details, failure description, and postcode - but not your name, email, or phone number) is presented to Suppliers in their dashboard. |
| 4 | Suppliers who are interested and have the required engine in stock may choose to “unlock” your lead. |
| 5 | Upon unlocking, the Supplier receives your full contact details (name, email, phone number). |
| 6 | The Supplier can then contact you directly to provide a quote (by phone, email, or SMS). |
| 7 | Cap applied: Once a total of 10 Suppliers have unlocked your lead, the lead is automatically closed and no further Suppliers can access your contact details. |
4.2 Why we use this model
This “unlock” model balances:
- Your privacy - Suppliers cannot see your contact details unless they are genuinely interested and have the engine in stock. This reduces unwanted contact.
- Competitive quotes - Limiting to 10 Suppliers ensures you receive enough quotes for meaningful comparison without being overwhelmed by excessive calls.
- Supplier accountability - The unlock action is logged, and we monitor Supplier behaviour. Suppliers who unlock leads but never quote, or who misuse contact details, are removed from our network.
4.3 Supplier contractual safeguards
Every Supplier signs a binding Data Sharing Agreement (DSA) before joining our network. The DSA requires Suppliers to:
- Act as an independent data controller for any personal data they receive
- Use your data only for the purpose of providing a quote for the specific engine you requested
- Not add your data to any marketing database or mailing list
- Not share your data with any third party (including subcontractors) without your explicit consent
- Retain your data only as long as necessary to fulfil the quote and any resulting contract
- Indemnify Engines Market against any fines, claims, or losses arising from their breach of data protection law or the DSA
Suppliers who breach these terms are removed from our network immediately.
Security measures - technical and organisational
We have implemented a range of security measures to protect personal data from accidental loss, unauthorised access, alteration, or disclosure.
5.1 Technical measures
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.3 across all website traffic. HSTS (HTTP Strict Transport Security) enabled. |
| Encryption at rest | AES-256 encryption for all databases and backups. |
| Access controls | Role-based access control (RBAC) for staff and Suppliers. Multi-factor authentication (MFA) required for all staff accounts with access to personal data. |
| Network security | Web application firewall (WAF), DDoS protection, regular vulnerability scanning. |
| API security | All APIs (including DVLA lookup) use API keys with rate limiting and IP whitelisting where appropriate. |
| Backup security | Encrypted backups stored separately from production systems. Retention period: 30 days for daily backups. |
| Supplier portal security | Suppliers access our platform via unique, password-protected accounts with MFA encouraged. Session timeouts after 30 minutes of inactivity. |
5.2 Organisational measures
| Measure | Implementation |
|---|---|
| Data protection policies | This policy, together with our Privacy Policy and internal staff handbook, sets out clear rules for handling personal data. |
| Staff training | All employees receive mandatory data protection training upon hiring and annually thereafter (see Section 7). |
| Access reviews | Quarterly audits of staff access rights. Access is revoked immediately when no longer required. |
| Incident response plan | A written plan for responding to data breaches (see Section 9). |
| Third-party risk management | All data processors (e.g., hosting provider, CRM provider, analytics provider) are vetted and sign data processing agreements that comply with UK GDPR. |
Data retention and deletion - specific processes
We retain personal data only as long as necessary for the purposes set out in our Privacy Policy. The table below explains the retention periods and deletion mechanisms.
| Data category | Retention period | Deletion mechanism |
|---|---|---|
| Active lead data (quote requests with recent interaction) | 6 months from the user’s last interaction (e.g., receiving a quote, clicking a link in a follow-up email, or contacting support). | Automated deletion script runs daily. After 6 months, data is permanently removed from the CRM and active databases. |
| Abandoned lead data (quote requests with no interaction within 30 days) | 30 days from submission, then marked as abandoned. Deleted at the 6-month point from submission (same as active leads). | Same automated deletion. |
| Supplier-viewed lead data (anonymised statistics only) | Anonymised after 12 months (e.g., “lead ID 12345” becomes an anonymous row with no personal identifiers). | Manual anonymisation script run quarterly. |
| Web server logs | 7 days | Automated deletion. |
| Backups | 30 days (daily backups rotated). Deleted after 30 days. | Automated rotation. |
| Customer support emails and call recordings | 6 months from the date of the communication | Manual deletion after 6 months, except where required for legal proceedings. |
| Complaint records (relating to Suppliers) | 6 years (to defend against potential legal claims) | Manual review and deletion after 6 years, unless a specific retention notice applies. |
6.1 User-requested early deletion
You have the right to request erasure of your personal data before the retention period expires. There is no fee for this request.
To request early deletion, email dpo@enginesmarket.co.uk with the subject line “Erasure request”. We will:
- Verify your identity
- Delete your personal data from our active systems within 30 days
- Confirm deletion to you in writing
Important: Data already shared with Suppliers cannot be retrieved from their systems. You must contact them directly to request deletion from their records.
6.2 Deletion verification
We maintain logs of deletion activities for audit purposes. These logs do not contain personal data - only record identifiers (e.g., “Lead ID 12345 deleted on [date] by automated script”). Our Data Protection Officer reviews deletion logs quarterly.
Staff training on data protection
All Engines Market employees receive comprehensive data protection training. Our training programme includes:
| Training component | Frequency | Content |
|---|---|---|
| Induction training | Upon hiring | UK GDPR basics, data protection principles, handling personal data securely, reporting breaches. |
| Annual refresher | Every 12 months | Updates to law, new threats (e.g., phishing), case studies of real breaches, refresher on our policies. |
| Role-specific training | As needed | For staff with access to CRM or Supplier management: additional modules on access control, data sharing agreements, and handling subject access requests. |
| Phishing simulations | Quarterly | Simulated phishing emails sent to all staff to test awareness. |
| Breach response drills | Annually | Tabletop exercises simulating a data breach to test our incident response plan. |
Training records are maintained by our Data Protection Officer. Staff who fail mandatory training are not permitted to access personal data until training is completed.
Supplier data handling - our oversight
While Suppliers are independent data controllers, we take steps to ensure they handle data appropriately while it is within our platform’s control.
8.1 Before onboarding
- Suppliers sign a Data Sharing Agreement (as described in section 4.3)
- We verify the identity of the individual who will access our Supplier portal (passport or driving licence check)
8.2 Ongoing monitoring
- We log every time a Supplier views or unlocks a lead
- We review Supplier behaviour (e.g., unlocking leads but never quoting, excessive unlocking without follow-up)
- We investigate any complaints received about a Supplier’s handling of personal data
- Suppliers whose average public review rating falls below 3.5 stars (sustained) or who accumulate multiple substantiated complaints are removed from our network
8.3 Offboarding
When a Supplier leaves our network (voluntarily or by removal):
- Their access to the Supplier portal is revoked immediately
- Any leads they have already unlocked remain with them (as they are independent controllers)
- No new leads are sent to them
Data breach procedure
Despite our security measures, a data breach may occur. We have a documented incident response plan to ensure we respond quickly and in compliance with UK GDPR.
9.1 Definition of a data breach
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
9.2 Internal reporting
All employees and contractors are required to report any suspected data breach immediately to:
- Data Protection Officer (dpo@enginesmarket.co.uk)
- IT Security Lead (internal)
Reports can be made by phone, email, or via our internal whistleblowing channel.
9.3 Investigation and containment
Upon receiving a report, our incident response team will:
| Step | Action | Timeframe |
|---|---|---|
| 1 | Contain the breach (e.g., revoke access, isolate affected systems, change passwords). | Immediate |
| 2 | Preserve evidence (logs, screenshots, affected data). | Within 1 hour |
| 3 | Assess the scope: what data, how many individuals, who is affected. | Within 4 hours |
| 4 | Determine the likelihood and severity of risk to individuals. | Within 24 hours |
9.4 Notification to the ICO
If the breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach.
The notification will include:
- Description of the breach (categories of data, approximate number of individuals and records)
- Name and contact details of our Data Protection Officer
- Likely consequences of the breach
- Measures taken or proposed to address the breach
9.5 Notification to affected individuals
If the breach is likely to result in a high risk to individuals (e.g., financial loss, identity theft, significant distress), we will notify affected individuals without undue delay. The notification will describe the breach and provide advice on steps they can take to protect themselves.
9.6 Documentation
We will document all breaches (including those not reportable to the ICO) in an internal breach register. The register includes:
- Facts about the breach
- Effects
- Remedial action taken
This register is reviewed by our Data Protection Officer quarterly to identify patterns and improve security.
International data transfers
We primarily store and process personal data within the United Kingdom. Our CRM and hosting providers are UK-based.
Some service providers (e.g., analytics) may store data outside the UK. In such cases, we ensure an adequate level of protection by using:
- The UK International Data Transfer Addendum (IDTA)
- Transfers to countries with UK adequacy decisions (e.g., the EEA, Japan, South Korea)
We do not transfer personal data to countries without adequate protections unless required by law or with your explicit consent.
Policy review and updates
This Data Handling Policy is reviewed:
- Annually (or more frequently if required by law or significant change in our processing activities)
- After any data breach (to identify lessons learned and update procedures)
- When we introduce new systems or Suppliers that affect data handling
The “Last updated” date at the top of this page indicates when the policy was last revised. We will notify users of material changes via email (if we have your email address) and via a notice on our Platform.
Contact us
If you have any questions about this Data Handling Policy, or if you wish to report a concern about how your data is being handled, please contact:
Postal address (for formal correspondence):
Data Protection Officer
Engine Finders UK Ltd
113 Park Road
Ilford
IG1 1SQ
United Kingdom
Key points for users
This Data Handling Policy was last reviewed and approved by the Data Protection Officer of Engine Finders UK Ltd on 13 June 2026.
Related documents
Privacy, cookies & your rights
Read our Privacy Policy to understand your rights and our lawful bases for processing, or our Cookie Policy for information about how we use cookies.