Privacy Policy
Last updated: 12 July 2026
This Privacy Policy explains how Lotra Core ("we", "us", "our"), operator of Lotra, collects, uses, and protects personal data when you use our software-as-a-service platform ("the Service"). We are the data controller for personal data we collect from you directly.
1. Data we collect
- Account data: name, email address, login credentials, workspace details.
- Customer data you enter: your buyers' names, contact details, vehicle enquiries, finance quotes, and sales records. You are the data controller for this data; we are the data processor.
- Usage & telemetry: pages visited, features used, device identifiers, IP address, browser type, timestamps.
- Support messages: content of any correspondence with our support team.
2. How we use your data
- To create and manage your account (contract performance).
- To provide, maintain, and improve the Service (legitimate interests).
- To detect and prevent fraud and abuse (legitimate interests).
- To provide customer support (contract performance).
- To send service announcements and, with your consent, marketing communications (consent).
- To meet legal or regulatory obligations (legal obligation).
3. Legal basis
We process personal data under the following legal bases: performance of a contract with you, our legitimate interests in providing and improving the Service, your consent (which you can withdraw at any time), and compliance with legal obligations.
4. Who we share data with
- Service providers & sub-processors: hosting, database, and email infrastructure providers necessary to run the Service.
- Stripe (payment processor): for subscription payments, card processing, invoicing, and fraud prevention. See Stripe's Privacy Policy.
- DVLA: when you use the vehicle lookup feature, we send registration numbers to the DVLA Vehicle Enquiry API.
- Professional advisers (legal, accounting), where necessary.
- Authorities, where required by law.
We do not sell your personal data.
5. International transfers
Some of our providers are based outside the UK/EEA. Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
6. Data retention
We retain personal data for as long as your account is active and for a reasonable period afterwards to meet legal, tax, and accounting obligations, or to resolve disputes. Data you delete from your workspace is removed from active systems within 30 days and from backups within 90 days.
Dealers using Lotra can configure automated retention windows for their own buyer data in Settings → Data Retention. Default windows:
- Closed enquiries — deleted 365 days after they are marked lost or converted.
- Inactive customers — automatically anonymised after 7 years (2,555 days) with no sale, enquiry, or update.
- Anonymised records — hard-deleted 30 days after anonymisation.
Anonymisation is irreversible: names, contact details, addresses, dates of birth, and notes are wiped, and the change is written to the workspace audit log. Dealers may run retention manually, extend the windows to meet FCA record-keeping obligations, or keep retention in "dry-run" mode while they review.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure (subject to legal exceptions).
- Restrict or object to processing.
- Data portability.
- Withdraw consent at any time.
- Complain to the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these rights, email legal@getlotra.com. We aim to respond within one month.
8. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, and audit logging. No system is perfectly secure — we cannot guarantee absolute security.
9. Cookies
We use strictly-necessary cookies to keep you signed in and to remember your workspace. We do not use marketing or advertising cookies. If we add analytics cookies in future, we will request your consent first via a cookie banner.
10. Data Processing Addendum (for dealers)
When you use Lotra to record and manage your buyers' personal data (customers, enquiries, part-exchange details, finance quotes, sale records), the following processor terms apply. This section forms our Data Processing Addendum ("DPA") with you and is designed to satisfy Article 28 of the UK GDPR.
10.1 Roles
- You (the dealer) are the data controller for buyer personal data you enter into the Service.
- Lotra Core (operator of Lotra) is the data processor, acting on your documented instructions (the configuration and inputs you make in the app).
10.2 Subject matter, duration, nature and purpose
- Subject matter: providing the Service.
- Duration: for the term of your subscription plus any export/deletion period set out below.
- Nature and purpose: storing and processing buyer data to operate dealership workflows (inventory, CRM, listings, finance, sales).
- Categories of data subjects: your prospects, customers, and their authorised representatives.
- Categories of personal data: name, contact details, address, vehicle interest, part-exchange details, and financial figures related to a finance quote or sale. We do not require special-category data; you must not enter it.
10.3 Sub-processors
We use the following sub-processors to run the Service:
- Cloudflare / Supabase — application hosting, database, and file storage.
- Stripe — payment processing, subscription billing, and invoicing.
- DVLA Vehicle Enquiry API — vehicle registration lookups (registration numbers only).
- Transactional email provider — sending service and account emails.
We will give reasonable prior notice of any new or replacement sub-processor. You may object on reasonable data-protection grounds within 30 days; if we cannot address the objection you may terminate the affected part of the Service.
10.4 Security measures
We maintain appropriate technical and organisational measures, including:
- TLS encryption for data in transit.
- Encryption at rest for the database and object storage.
- Row-level security so each dealer workspace can only access its own data.
- Role-based access control within workspaces (owner, admin, manager, sales, viewer).
- An immutable audit log of changes to key records.
- Least-privilege access for our staff, with logging of any administrative action.
- Regular backups and tested restoration procedures.
10.5 International transfers
Some sub-processors process personal data outside the UK/EEA. Where they do, we rely on UK/EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision.
10.6 Assistance and breach notification
- We will provide reasonable assistance so you can respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). The Service offers per-customer export and anonymisation tools.
- We will notify you without undue delay, and in any event within 72 hours of becoming aware, of a personal-data breach affecting your data, with the information you need to meet your own reporting duties.
- We will assist with data-protection impact assessments and prior consultations where reasonably requested.
10.7 Return and deletion on termination
On termination or expiry of your subscription you may export your data for 30 days. After that, we will delete or anonymise your data, except where retention is required to meet legal, tax, or accounting obligations (typically up to 7 years for finance and payment records).
10.8 Audit
On reasonable prior written request, and no more than once per year (except following a breach), we will make available information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports where available.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email or in-app notice.
12. Contact
For any privacy questions, contact us at legal@getlotra.com.
See also our Terms & Conditions, Cookie Notice, and Refund Policy.