Privacy and retention

How records are handled

Draft policy for product testing. Obtain legal review and confirm your UK GDPR lawful basis before accepting paying customers.

Information stored

SERMI Records stores account details, workshop membership, vehicle information, registered keeper information, customer identity-document type and number, authority evidence, repair details, signatures and uploaded evidence.

Purpose

The service processes this information to help an Independent Operator create and retain auditable records for security-related repair and maintenance transactions. It does not grant SERMI authorisation and does not connect to manufacturer RMI systems.

Retention

Submitted repair records receive a retention date five years after submission. This version does not delete them automatically. Before production launch, the service needs a reviewed retention and deletion process covering legal holds, backups and customer offboarding.

Access and security

Records are limited to members of the relevant organisation according to their role. Manufacturer passwords, SERMI certificate PINs and dealer credentials must never be entered. Production deployment must use HTTPS, managed encrypted storage, secure backups and a documented incident process.

Your responsibilities

Each workshop remains responsible for confirming its lawful basis, giving appropriate privacy information to customers, handling data-subject requests and meeting SERMI requirements. Contact details for the production data controller must be added before launch.