Last updated
DrivePlan is software that driving schools use to run their business: scheduling lessons, tracking learner progress, issuing invoices and managing exams. Doing that involves personal data about learners, instructors and school staff.
This policy explains what we hold, why, for how long, who else sees it, and what you can require of us. It is written to be read, not to be survived.
DrivePlan is operated by TODO — registered company name (TODO — legal form), registered at 5 Boulevard Jules Guesde, 93200 Saint-Denis, France, TODO — RCS registry, SIREN TODO — SIREN.
For any question about this policy or about your personal data, write to privacy@driveplan.net. Our data-protection contact is TODO — data-protection contact.
We handle personal data in two capacities, and which one applies decides who you should approach.
When a driving school uses DrivePlan, that school decides what to record about its learners and instructors, and why. The school is the controller; we act on its instructions under a data-processing agreement.
If you are a learner or an instructor and you want to see, correct or erase your data, your school is the right place to start. Contact us instead if the school does not respond, or if you would rather come to us directly — we will help, and we will tell the school.
For the accounts of the people who sign schools up, for our billing records, for support conversations, and for visitors to our marketing website, we are the controller and decide these things ourselves.
The list below is what the product actually stores. Not every field is used by every school — some are optional, and a school may choose not to collect them.
| Category | Data |
|---|---|
| Account and staff data | First and last name, email address, telephone number, role, profile photo, and sign-in credentials managed by our authentication provider. |
| School and billing data | School name, postal address, geographic coordinates of that address, billing address, VAT details, subscription and payment status. |
| Learner data | Name and title, email address, telephone number, postal address and city, country, date of birth, identity-document number, photograph, licence category, join date, and account status. |
| Guardian data | For a learner who is a minor: the name, relationship, email address and telephone number of a parent or guardian. |
| Uploaded documents | Files a school attaches to a learner file — typically identity documents, licence paperwork and medical certificates. |
| Learning and assessment data | Lessons taken, duration and remaining lesson credit, skill assessments, completed objectives, initial driving assessment, instructor comments, exam dates, results and scores. |
| Financial data | Orders, invoices, payments and refunds attached to a learner. |
| Support data | Support tickets and their message threads, including whatever you choose to write in them. |
| Technical data | IP address, browser and device type, and — on our marketing website and only with your consent — audience-measurement data. |
We do not ask for special-category data under Art. 9. If a school uploads a medical certificate into a learner file, that document may contain health information; schools are responsible for deciding whether to do so and on what basis.
Every purpose needs a lawful basis. Ours are set out below, per purpose, as Art. 13(1)(c) requires.
| Purpose | Legal basis |
|---|---|
| Providing the platform to a school: scheduling, learner records, progress tracking, invoicing | Performance of our contract with the school (Art. 6(1)(b)). For the learners and instructors whose data appears in it, we act on the school’s instructions as its processor. |
| Creating and administering an account, authenticating sign-ins | Performance of a contract (Art. 6(1)(b)). |
| Taking subscription payments and keeping accounting records | Contract (Art. 6(1)(b)) and compliance with a legal obligation (Art. 6(1)(c)). |
| Sending lesson reminders by email and push notification | Performance of the contract between the learner and their school, on the school’s instructions. Each recipient can switch these off in their own preferences. |
| Answering support requests | Contract (Art. 6(1)(b)) and our legitimate interest in running a supportable service (Art. 6(1)(f)). |
| Keeping an audit trail of actions taken on records | Legitimate interest in security, accountability and dispute resolution (Art. 6(1)(f)), and Art. 5(2). |
| Securing the service and investigating abuse | Legitimate interest (Art. 6(1)(f)). |
| Measuring the audience of our marketing website | Your consent (Art. 6(1)(a)), which you can withdraw at any time. |
| Sending marketing emails about DrivePlan to business contacts | Consent, or our legitimate interest in contacting driving schools about a product for driving schools (Art. 6(1)(f)). Every message carries an unsubscribe link. |
Learning to drive starts before adulthood in most of the countries we serve, so a substantial share of the learner records in DrivePlan belong to minors. We treat that as the default rather than the exception.
In practice that means: guardian contact details are stored so a school can reach a responsible adult; identity documents and dates of birth are only visible to the learner’s own school administrators and to the learner themselves; and a minor’s record is erased on the same terms as anyone else’s.
The relationship is between the learner (or their guardian) and the driving school — a school is responsible for obtaining whatever authorisation local law requires before enrolling a minor and recording their data. We do not offer accounts directly to children.
These periods are enforced by scheduled jobs, not left to good intentions. A school can extend them where it has a reason to; it cannot shorten them below what the law requires it to keep.
| Data | Retention |
|---|---|
| Invoices, payments, orders, lessons and exam records | Ten years from the record’s date. French commercial law requires accounting records to be kept for this long, which overrides an erasure request for these records (Art. 17(3)(b)). Deleted automatically afterwards. |
| Learner file | For as long as the learner is active with the school, then three years without activity, after which the identifying data is erased automatically. |
| Identity documents and other uploaded files | Deleted when the learner file is erased, or earlier if the school removes them. |
| Account and staff data | For the life of the account. Erased when the account is closed, subject to the accounting period above. |
| Audit trail | One year. |
| Support tickets | For the life of the account, so we can see the history of an issue. |
| Contact-form enquiries | Three years from our last exchange with you, in line with CNIL guidance on prospect data. |
| Cookie consent record | Thirteen months, then we ask again. |
We do not sell personal data, and we do not share it for anyone else’s advertising.
We use a small number of service providers to run the platform — hosting, email delivery, payments, AI features. Each one is bound by a data-processing agreement, may only act on our instructions, and receives only what its job requires.
We publish the full list, including what each provider does, where it processes data, and on what legal footing, on our sub-processors page. Schools are notified before we add a new one.
We also disclose data where a law or a court requires us to, and we may transfer records as part of a merger or acquisition — in which case the acquirer is bound by this policy or gives you notice before anything changes.
We are established in France, but the platform itself runs on Google Cloud infrastructure located in the United States. That means the records described in this policy — learner files, lessons, invoices, uploaded documents — are stored and processed outside the European Economic Area.
That transfer relies on one of two things: the European Commission’s adequacy decision for the EU–US Data Privacy Framework, where the recipient is certified under it; or the Commission’s Standard Contractual Clauses together with an assessment of the destination country and additional technical measures, principally encryption in transit and at rest. Our sub-processors page states which applies to each provider and where each one processes data.
We would rather tell you this plainly than describe ourselves as European and leave you to discover otherwise. If your school needs its data held inside the EEA, say so before you sign — it is a decision about where we run the database, not something that can be patched afterwards.
An earlier version of this policy cited the Privacy Shield. That framework was invalidated by the Court of Justice in July 2020 and we do not rely on it for anything. The reference should not have survived; it has been removed.
No system is perfect. If we discover a breach that is likely to put your rights at risk, we notify the CNIL within 72 hours and tell the people affected without undue delay.
Under the GDPR you can require the following of us. Exercising any of them is free, and we answer within one month — we will tell you if a request is complex enough to need longer.
To exercise any of these, write to privacy@driveplan.net. If you are a learner or instructor at a driving school, that school holds your record and is usually quicker — but you can always come to us.
If you are not satisfied with how we handle your request, you can lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), our supervisory authority: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — https://www.cnil.fr/fr/plaintes. You can also complain to the authority where you live or work.
DrivePlan includes optional AI features — summarising instructor feedback on lessons, and letting a school operate the product through an external AI assistant if it chooses to connect one.
Where a feature sends text to an AI provider, that text can contain personal data such as a learner’s name inside a written comment. The providers involved are named on our sub-processors page.
Two limits apply. No AI feature makes a decision about a person on its own — output is a suggestion for a human to act on. And an external AI assistant is never given more access than the person who connected it already had; sensitive fields such as identity-document numbers, dates of birth and guardian contacts are withheld by default.
We update this policy when what we do changes. The date at the top always reflects the current version.
For a change that materially affects you, we give notice before it takes effect — by email to account holders, and in the product. Where a change concerns something you consented to, we ask again rather than assuming the old answer still applies.
Privacy and data-protection questions: privacy@driveplan.net
Everything else: contact@driveplan.net
Post: TODO — registered company name, 5 Boulevard Jules Guesde, 93200 Saint-Denis, France