Last updated: 17 September 2026
Security and data protection are fundamental to the way OvonOne is designed and operated.
OvonOne provides technology used by automotive businesses to manage customer journeys, products and services. We recognise the responsibility that comes with processing customer and business information and maintain technical and organisational controls designed to protect the confidentiality, integrity and availability of our systems and data.
This page provides an overview of our approach to security.
UK hosting and data residency
OvonOne's production platform and customer data are hosted in the United Kingdom using Amazon Web Services (AWS).
Our production infrastructure is designed to provide appropriate separation, resilience and access control for the services we operate.
Customer data is stored within the UK.
Encryption
We use encryption to protect information both in transit and at rest.
Connections to OvonOne services are protected using modern encrypted transport protocols.
Production databases, file storage, backups and other applicable storage services use encryption at rest.
Access control
Access to production systems and customer information is restricted to authorised personnel who require access for legitimate business purposes.
We apply controls including:
- role-based access;
- least-privilege access principles;
- authentication controls;
- restricted administrative access;
- logging of relevant system activity; and
- periodic review of access where appropriate.
Access is removed or adjusted when an individual's role or responsibilities change.
Infrastructure security
OvonOne's infrastructure is hosted on AWS and managed using controlled, repeatable infrastructure and deployment processes.
Our approach includes:
- separation of production and non-production environments;
- restricted access to production infrastructure;
- infrastructure managed through code and controlled change processes;
- network and application-level security controls;
- encrypted data storage;
- automated backups;
- operational monitoring; and
- logging of relevant system and security activity.
We regularly review our infrastructure as the platform and the services we use evolve.
Secure software development
Security is considered throughout the development and deployment of OvonOne.
Our software development practices include:
- source control and change tracking;
- code review;
- automated testing;
- controlled deployment processes;
- dependency and software package management;
- separation of development and production environments;
- restricted production access; and
- review and remediation of identified security issues.
Changes to our production services are made through controlled deployment processes rather than by making routine manual changes directly to production systems.
Production data
Production personal information is not ordinarily used in development or testing environments.
Where realistic data is required for software development or testing, we prefer synthetic, anonymised or non-production information.
Where production information is exceptionally required for investigation or support purposes, access is restricted to authorised personnel and the minimum information necessary for the task should be used.
Monitoring and logging
We maintain operational and security logging appropriate to the systems we operate.
Monitoring is used to help us:
- identify service failures;
- investigate unexpected behaviour;
- detect potential security issues;
- troubleshoot technical problems;
- maintain platform reliability; and
- investigate incidents.
Access to logs containing potentially sensitive information is restricted.
Logs are subject to defined retention periods and are not intended to provide permanent storage of customer information.
Backups and resilience
OvonOne maintains automated backups and recovery arrangements for critical production data and services.
Backups are:
- encrypted where applicable;
- access controlled;
- retained according to defined lifecycle rules; and
- managed separately from normal application access.
Our infrastructure and backup arrangements are designed to support recovery following system failure or data loss.
Backup systems are intended for disaster recovery and resilience and are not used as a permanent archive for customer information.
Data retention and deletion
OvonOne maintains a documented Data Retention Policy and Retention Schedule.
Personal information is retained only for as long as reasonably necessary for the purpose for which it was collected and for applicable contractual, legal, regulatory, accounting, audit and dispute-resolution requirements.
Core customer, product and transaction records are generally retained for up to seven years following the end of the relevant customer relationship, product or transaction.
Other information, such as operational logs and call recordings, is subject to shorter retention periods appropriate to its purpose.
Where practical, retention and deletion requirements are enforced through automated technical controls.
Information reaching the end of its retention period is securely deleted or irreversibly anonymised unless there is a legitimate reason for continued retention.
Data protection
OvonOne maintains processes and documentation to support compliance with applicable UK data protection requirements, including the UK GDPR and Data Protection Act 2018.
These include:
- a Record of Processing Activities;
- a Data Retention Policy and Retention Schedule;
- a public Privacy Notice;
- processes for handling data subject rights;
- personal data breach and incident management;
- supplier and third-party controls; and
- staff data protection and information security training.
Further information about how we process personal information is available in our Privacy Notice.
People and training
Security is not solely a technical responsibility.
OvonOne employees are subject to confidentiality obligations and receive data protection and information security training.
Our training is based on guidance and training material from the Information Commissioner's Office (ICO) and is supplemented with information relevant to OvonOne's own systems, activities and responsibilities.
Employees with access to systems and customer information are expected to follow our security, confidentiality and data protection requirements.
Incident management
OvonOne maintains processes for identifying, investigating, containing and responding to security incidents and personal data breaches.
Potential incidents are assessed to determine:
- what happened;
- which systems or information may be affected;
- the potential impact;
- the appropriate containment and remediation;
- whether customers, partners or other organisations need to be informed; and
- whether notification to the Information Commissioner's Office or affected individuals is required.
Relevant incidents and decisions are documented in our incident and personal data breach records.
We review incidents to identify appropriate corrective actions and opportunities to improve our controls.
Suppliers and third parties
We use selected third-party technology and service providers to operate OvonOne.
Where a supplier processes personal information on our behalf, we consider the nature of the information and service when assessing the appropriate contractual, data protection and security requirements.
Suppliers processing personal information on our behalf are expected to provide appropriate safeguards and to process that information only for the agreed purposes.
Where information is provided to another organisation acting as an independent data controller, such as a finance provider, that organisation is responsible for the security and processing of the information it receives.
Business continuity
Our infrastructure and operational arrangements are designed to reduce the impact of individual system failures and support recovery of critical services.
This includes appropriate use of:
- managed cloud infrastructure;
- automated backups;
- infrastructure-as-code;
- controlled deployment processes;
- system monitoring; and
- recovery procedures.
Our resilience arrangements are reviewed as the platform and its operational requirements evolve.
Vulnerability management
We take reasonable measures to identify and address vulnerabilities affecting the OvonOne platform and the technology on which it depends.
This includes maintaining software dependencies, monitoring relevant security information and assessing identified vulnerabilities according to their potential impact.
Security issues are prioritised and remediated according to the risk they present.
Responsible disclosure
We welcome responsible reports from security researchers and others who believe they have identified a security vulnerability affecting OvonOne.
Security issues should be reported privately to:
Please provide enough information for us to understand and reproduce the issue where possible.
We ask that researchers:
- do not access, modify or download customer information beyond what is strictly necessary to demonstrate an issue;
- do not disrupt or degrade our services;
- do not use social engineering against our employees, customers or partners;
- do not attempt physical attacks against our premises or personnel;
- do not publicly disclose a potential vulnerability before we have had a reasonable opportunity to investigate and address it; and
- act in good faith.
We will investigate credible reports and aim to maintain appropriate communication with the person reporting the issue.
Security enquiries
Customers, prospective customers and partners may contact us with security or information assurance questions.
Security: security@ovon.co.uk
Privacy and data protection: privacy@ovon.co.uk
Ovon One Limited
Company number 16842434
C4DI Suite 4, Building 1
31-38 Queen St
Kingston upon Hull
HU1 1UU
United Kingdom
Keeping our security approach current
Security requirements and threats change over time.
We continually develop our technical and organisational controls as OvonOne, our infrastructure and the services we provide evolve.
This page may be updated periodically to reflect material changes to our security practices.
