This Data Handling Policy should be read alongside our Privacy Policy, which explains your rights and our lawful bases for processing, and our Cookie Policy.

Scope and purpose

This policy applies to all personal data that we collect, process, or store in connection with our price comparison and lead generation service. It covers:

  • Data submitted by users via our quote request form
  • Data generated automatically (e.g., IP addresses, analytics)
  • Data shared with our Supplier network
  • Data stored in our CRM and other systems
  • Data retained for legitimate business purposes (e.g., supplier monitoring, legal compliance)

We are committed to processing personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

Data handling lifecycle - overview

The diagram below illustrates how personal data moves through our systems from submission to deletion.

[User submits quote request via website form] │ ▼ [Data encrypted in transit (TLS 1.3)] │ ▼ [Data stored temporarily in web server logs (deleted after 7 days)] │ ▼ [Data entered into our CRM system] │ ▼ [Lead is made available to Suppliers (max 10 suppliers)] │ ▼ [Suppliers view lead and may submit quotes] │ ▼ [Lead remains active for 6 months from last interaction] │ ▼ [Automatic deletion from CRM and active systems] │ ▼ [Data retained in encrypted backups for up to 30 additional days, then permanently deleted]

Data collection - from website to CRM

3.1 Quote request form

When you submit a quote request, the following data is collected:

  • Name, email address, phone number, postcode
  • Vehicle registration (looked up via DVLA API to retrieve make, model, engine code, fuel type, year)
  • Mileage
  • Description of the engine problem

All data is transmitted from your browser to our servers using TLS 1.3 encryption (the current industry standard). Our website uses HTTPS across all pages.

3.2 Web server logs

For security and debugging purposes, our web servers temporarily log:

  • IP address
  • Browser type and version
  • Timestamp of request
  • Pages requested

These logs are retained for 7 days and then automatically deleted. They are not used for any purpose other than detecting and preventing malicious activity (e.g., DDoS attacks, brute force attempts).

3.3 CRM processing

Once your quote request is validated, the data is entered into our Customer Relationship Management (CRM) system.

FieldDetails
CRM platform[CRM NAME - e.g., HubSpot / Salesforce / custom platform] - insert your actual CRM here
Location of CRM serversUnited Kingdom (primary)
Data encryption at restAES-256
Access controlsRole-based access; only designated staff can access personal data
Audit loggingAll access to personal data is logged

Our CRM is configured to:

  • Automatically record the date and time of each lead
  • Track which Suppliers have viewed the lead (and when)
  • Enforce the supplier cap (maximum 10 Suppliers per lead)
  • Automatically close leads after 6 months of inactivity

Data sharing with Suppliers - mechanism and safeguards

Sharing your data with Suppliers is the core function of our service. We have implemented specific technical and contractual safeguards to protect your data while enabling Suppliers to provide accurate quotes.

4.1 How a lead is shared

StepDescription
1Your completed quote request enters our CRM.
2The CRM identifies relevant Suppliers based on vehicle type, engine code, and your postcode location.
3An anonymised version of your lead (showing vehicle details, failure description, and postcode - but not your name, email, or phone number) is presented to Suppliers in their dashboard.
4Suppliers who are interested and have the required engine in stock may choose to “unlock” your lead.
5Upon unlocking, the Supplier receives your full contact details (name, email, phone number).
6The Supplier can then contact you directly to provide a quote (by phone, email, or SMS).
7Cap applied: Once a total of 10 Suppliers have unlocked your lead, the lead is automatically closed and no further Suppliers can access your contact details.

4.2 Why we use this model

This “unlock” model balances:

  • Your privacy - Suppliers cannot see your contact details unless they are genuinely interested and have the engine in stock. This reduces unwanted contact.
  • Competitive quotes - Limiting to 10 Suppliers ensures you receive enough quotes for meaningful comparison without being overwhelmed by excessive calls.
  • Supplier accountability - The unlock action is logged, and we monitor Supplier behaviour. Suppliers who unlock leads but never quote, or who misuse contact details, are removed from our network.

4.3 Supplier contractual safeguards

Every Supplier signs a binding Data Sharing Agreement (DSA) before joining our network. The DSA requires Suppliers to:

  • Act as an independent data controller for any personal data they receive
  • Use your data only for the purpose of providing a quote for the specific engine you requested
  • Not add your data to any marketing database or mailing list
  • Not share your data with any third party (including subcontractors) without your explicit consent
  • Retain your data only as long as necessary to fulfil the quote and any resulting contract
  • Indemnify Engines Market against any fines, claims, or losses arising from their breach of data protection law or the DSA

Suppliers who breach these terms are removed from our network immediately.

Security measures - technical and organisational

We have implemented a range of security measures to protect personal data from accidental loss, unauthorised access, alteration, or disclosure.

5.1 Technical measures

MeasureImplementation
Encryption in transitTLS 1.3 across all website traffic. HSTS (HTTP Strict Transport Security) enabled.
Encryption at restAES-256 encryption for all databases and backups.
Access controlsRole-based access control (RBAC) for staff and Suppliers. Multi-factor authentication (MFA) required for all staff accounts with access to personal data.
Network securityWeb application firewall (WAF), DDoS protection, regular vulnerability scanning.
API securityAll APIs (including DVLA lookup) use API keys with rate limiting and IP whitelisting where appropriate.
Backup securityEncrypted backups stored separately from production systems. Retention period: 30 days for daily backups.
Supplier portal securitySuppliers access our platform via unique, password-protected accounts with MFA encouraged. Session timeouts after 30 minutes of inactivity.

5.2 Organisational measures

MeasureImplementation
Data protection policiesThis policy, together with our Privacy Policy and internal staff handbook, sets out clear rules for handling personal data.
Staff trainingAll employees receive mandatory data protection training upon hiring and annually thereafter (see Section 7).
Access reviewsQuarterly audits of staff access rights. Access is revoked immediately when no longer required.
Incident response planA written plan for responding to data breaches (see Section 9).
Third-party risk managementAll data processors (e.g., hosting provider, CRM provider, analytics provider) are vetted and sign data processing agreements that comply with UK GDPR.

Data retention and deletion - specific processes

We retain personal data only as long as necessary for the purposes set out in our Privacy Policy. The table below explains the retention periods and deletion mechanisms.

Data categoryRetention periodDeletion mechanism
Active lead data (quote requests with recent interaction) 6 months from the user’s last interaction (e.g., receiving a quote, clicking a link in a follow-up email, or contacting support). Automated deletion script runs daily. After 6 months, data is permanently removed from the CRM and active databases.
Abandoned lead data (quote requests with no interaction within 30 days) 30 days from submission, then marked as abandoned. Deleted at the 6-month point from submission (same as active leads). Same automated deletion.
Supplier-viewed lead data (anonymised statistics only) Anonymised after 12 months (e.g., “lead ID 12345” becomes an anonymous row with no personal identifiers). Manual anonymisation script run quarterly.
Web server logs 7 days Automated deletion.
Backups 30 days (daily backups rotated). Deleted after 30 days. Automated rotation.
Customer support emails and call recordings 6 months from the date of the communication Manual deletion after 6 months, except where required for legal proceedings.
Complaint records (relating to Suppliers) 6 years (to defend against potential legal claims) Manual review and deletion after 6 years, unless a specific retention notice applies.

6.1 User-requested early deletion

You have the right to request erasure of your personal data before the retention period expires. There is no fee for this request.

To request early deletion, email dpo@enginesmarket.co.uk with the subject line “Erasure request”. We will:

  1. Verify your identity
  2. Delete your personal data from our active systems within 30 days
  3. Confirm deletion to you in writing

Important: Data already shared with Suppliers cannot be retrieved from their systems. You must contact them directly to request deletion from their records.

6.2 Deletion verification

We maintain logs of deletion activities for audit purposes. These logs do not contain personal data - only record identifiers (e.g., “Lead ID 12345 deleted on [date] by automated script”). Our Data Protection Officer reviews deletion logs quarterly.

Staff training on data protection

All Engines Market employees receive comprehensive data protection training. Our training programme includes:

Training componentFrequencyContent
Induction training Upon hiring UK GDPR basics, data protection principles, handling personal data securely, reporting breaches.
Annual refresher Every 12 months Updates to law, new threats (e.g., phishing), case studies of real breaches, refresher on our policies.
Role-specific training As needed For staff with access to CRM or Supplier management: additional modules on access control, data sharing agreements, and handling subject access requests.
Phishing simulations Quarterly Simulated phishing emails sent to all staff to test awareness.
Breach response drills Annually Tabletop exercises simulating a data breach to test our incident response plan.

Training records are maintained by our Data Protection Officer. Staff who fail mandatory training are not permitted to access personal data until training is completed.

Supplier data handling - our oversight

While Suppliers are independent data controllers, we take steps to ensure they handle data appropriately while it is within our platform’s control.

8.1 Before onboarding

  • Suppliers sign a Data Sharing Agreement (as described in section 4.3)
  • We verify the identity of the individual who will access our Supplier portal (passport or driving licence check)

8.2 Ongoing monitoring

  • We log every time a Supplier views or unlocks a lead
  • We review Supplier behaviour (e.g., unlocking leads but never quoting, excessive unlocking without follow-up)
  • We investigate any complaints received about a Supplier’s handling of personal data
  • Suppliers whose average public review rating falls below 3.5 stars (sustained) or who accumulate multiple substantiated complaints are removed from our network

8.3 Offboarding

When a Supplier leaves our network (voluntarily or by removal):

  • Their access to the Supplier portal is revoked immediately
  • Any leads they have already unlocked remain with them (as they are independent controllers)
  • No new leads are sent to them

Data breach procedure

Despite our security measures, a data breach may occur. We have a documented incident response plan to ensure we respond quickly and in compliance with UK GDPR.

9.1 Definition of a data breach

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

9.2 Internal reporting

All employees and contractors are required to report any suspected data breach immediately to:

  • Data Protection Officer (dpo@enginesmarket.co.uk)
  • IT Security Lead (internal)

Reports can be made by phone, email, or via our internal whistleblowing channel.

9.3 Investigation and containment

Upon receiving a report, our incident response team will:

StepActionTimeframe
1Contain the breach (e.g., revoke access, isolate affected systems, change passwords).Immediate
2Preserve evidence (logs, screenshots, affected data).Within 1 hour
3Assess the scope: what data, how many individuals, who is affected.Within 4 hours
4Determine the likelihood and severity of risk to individuals.Within 24 hours

9.4 Notification to the ICO

If the breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach.

The notification will include:

  • Description of the breach (categories of data, approximate number of individuals and records)
  • Name and contact details of our Data Protection Officer
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

9.5 Notification to affected individuals

If the breach is likely to result in a high risk to individuals (e.g., financial loss, identity theft, significant distress), we will notify affected individuals without undue delay. The notification will describe the breach and provide advice on steps they can take to protect themselves.

9.6 Documentation

We will document all breaches (including those not reportable to the ICO) in an internal breach register. The register includes:

  • Facts about the breach
  • Effects
  • Remedial action taken

This register is reviewed by our Data Protection Officer quarterly to identify patterns and improve security.

International data transfers

We primarily store and process personal data within the United Kingdom. Our CRM and hosting providers are UK-based.

Some service providers (e.g., analytics) may store data outside the UK. In such cases, we ensure an adequate level of protection by using:

  • The UK International Data Transfer Addendum (IDTA)
  • Transfers to countries with UK adequacy decisions (e.g., the EEA, Japan, South Korea)

We do not transfer personal data to countries without adequate protections unless required by law or with your explicit consent.

Policy review and updates

This Data Handling Policy is reviewed:

  • Annually (or more frequently if required by law or significant change in our processing activities)
  • After any data breach (to identify lessons learned and update procedures)
  • When we introduce new systems or Suppliers that affect data handling

The “Last updated” date at the top of this page indicates when the policy was last revised. We will notify users of material changes via email (if we have your email address) and via a notice on our Platform.

Contact us

If you have any questions about this Data Handling Policy, or if you wish to report a concern about how your data is being handled, please contact:

Data Protection Officer
General data enquiries
Complaints about data handling

Postal address (for formal correspondence):
Data Protection Officer
Engine Finders UK Ltd
113 Park Road
Ilford
IG1 1SQ
United Kingdom

Key points for users

How many Suppliers see my contact details-
Maximum 10. You will not be contacted by more than 10 Suppliers.
How do Suppliers get my details-
They must “unlock” your lead (express interest) first. Uninterested Suppliers never see your name, email, or phone number.
How long do you keep my data-
6 months from your last interaction, then automatically deleted.
Can I delete my data earlier-
Yes, free of charge. Email dpo@enginesmarket.co.uk.
What happens to my data after deletion-
It is permanently removed from our active systems and, after 30 days, from backups.
Do you train your staff on data protection-
Yes - annually, plus specific training for roles that access personal data.
What if you have a data breach-
We have a formal response plan and will notify the ICO within 72 hours if required.

This Data Handling Policy was last reviewed and approved by the Data Protection Officer of Engine Finders UK Ltd on 13 June 2026.

Related documents

Privacy, cookies & your rights

Read our Privacy Policy to understand your rights and our lawful bases for processing, or our Cookie Policy for information about how we use cookies.