CYBER SECURITY & DIGITAL SAFETY
Protecting customer information, online services, operational systems and digital driver services.
Last updated: September 2026
CYBER SECURITY ASSURANCE
Commercial digital security assurance for the DVM Group website, online services and associated customer-facing systems.
United Kingdom
Website & online systems
Commercial security assurance
Subject to ongoing review
01. OUR APPROACH TO DIGITAL SECURITY
DVM Group uses a range of digital systems to support commercial logistics, vehicle hire, mobility operations, customer communication and online enquiries.
Because these services may involve customer, driver and operational information, cyber security forms part of the design, operation and maintenance of the website and its associated online systems.
Our objective is to reduce the risk of unauthorised access, accidental disclosure, misuse or loss of information while maintaining practical and reliable digital services.
02. SECURITY ASSURANCE
The defined DVM digital environment has been subject to a commercial cyber security assurance review provided by:
Certificate Reference: 090926/3/H
The assurance relates only to the defined DVM digital environment and systems described on this page and is subject to ongoing technical review.
03. SYSTEMS WITHIN THE SECURITY SCOPE
The DVM digital environment may include the following systems and online services:
Public-facing DVM Group pages, service information and customer-facing website functionality.
Vehicle availability, booking and customer information systems.
Driver onboarding, application and document submission systems where deployed.
Secure driver account and operational access systems where available.
04. WEBSITE & APPLICATION SECURITY
DVM online services are maintained with security controls intended to reduce common risks associated with unauthorised access, malicious input and misuse of internet-facing services.
Security measures may include access restrictions, application updates, input validation, secure connection controls and operational monitoring.
05. DRIVER DOCUMENT SECURITY
DVM mobility operations may require prospective drivers to provide personal information and supporting documents as part of the onboarding and verification process.
Document submission systems are intended to restrict access to authorised personnel involved in application review, verification and onboarding.
Drivers should only submit documents through authorised DVM systems and should not send sensitive information through unofficial communication channels unless specifically requested by an authorised DVM representative.
06. ACCESS CONTROL
Administrative and operational systems should only be accessible to authorised users with a legitimate business requirement.
Access permissions may be separated according to role so that users can access only information required for their responsibilities.
07. PERSONAL DATA HANDLING
Personal information obtained through DVM services should be handled in accordance with the purpose for which it was collected and applicable data protection requirements.
Access to personal data should be limited to relevant operational, administrative or authorised technical personnel.
08. FILE UPLOAD & DOCUMENT CONTROLS
Where online services allow document or image uploads, technical controls may be applied to restrict accepted file types, file sizes and storage locations.
Uploaded information should not be made publicly accessible through normal website navigation.
09. SECURE DATA TRANSMISSION
The DVM website uses HTTPS connections to protect information transmitted between compatible browsers and the website.
Encryption is one of the technical measures commonly used to reduce the risk of information being intercepted while travelling across networks.
10. DATA MINIMISATION
DVM digital systems should not request or retain unnecessary personal information simply because it is technically possible to collect it.
Information requested through online services is intended to remain proportionate to the service being provided or verification being carried out.
11. PRIVACY & COOKIE CONTROLS
Cyber security operates alongside DVM Group's privacy, cookie and data protection controls.
Further information is available here:
12. SECURITY MONITORING & REVIEW
Security is not treated as a one-time configuration.
Digital systems, integrations, access arrangements and operational controls may be reviewed as the website develops, new functionality is introduced or the security environment changes.
13. SECURITY INCIDENTS
Suspected security events should be investigated according to their nature, severity and potential impact.
Where an incident involves personal information, applicable data protection obligations should also be considered.
14. THIRD-PARTY SERVICES & INTEGRATIONS
DVM may use third-party services, hosting platforms, payment technologies, communication tools or external integrations to support its online operations.
Third-party services remain responsible for the security of their own infrastructure and systems. DVM aims to use reputable providers appropriate to the service being delivered.
15. SECURITY ASSURANCE PROVIDER
DJF IT CYBERWORKS LTD
Commercial cyber security assurance provider supporting the defined DVM digital environment.
hello@djfit.pro16. CERTIFICATE INFORMATION
Certificate reference 090926/3/H is a commercial cyber security assurance issued by DJF IT Cyberworks Ltd for the defined DVM Group digital environment. It should not be represented as Cyber Essentials, Cyber Essentials Plus, ISO/IEC 27001, UKAS accreditation or a government-issued cyber security certification unless such certification is separately obtained.
SECURITY OR PRIVACY QUESTION?
Contact us if you have concerns about information submitted through this website or believe you have identified a security issue.
enquiries@dvmbulgar.com
