AutolytixLast updated: April 2026
Autolytix is a dealership management platform operated by Autolytix Ltd(“we”, “us”, “our”). We are registered in England and Wales.
For the purposes of UK data protection law, Autolytix acts as a data controller for the personal data of platform users (dealership staff, owners, investors) and as a data processoron behalf of dealerships (“dealers”) for customer booking data.
You can contact our data protection contact at: privacy@autolytix.co.uk
This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are registered with the Information Commissioner's Office (ICO) as a data controller.
When you register as a dealership or are added as a user, we collect:
Legal basis: Contract performance (Art. 6(1)(b) UK GDPR) — these details are necessary to provide the platform service. Legitimate interests (Art. 6(1)(f)) for security logs.
Dealers enter vehicle records (registration numbers, purchase and sale prices, mileage, documents), financial records, expenses and advertising data. We also query the DVLA and DVSA APIs using vehicle registration numbers to enrich records with make, model, colour, fuel type and MOT status.
Legal basis: Contract performance; DVLA/DVSA queries are made under our legitimate interests to provide accurate vehicle data and under the dealer's legitimate interests as a motor trade business.
Dealers may add investor names, contact details and profit-share arrangements. This data is entered by the dealer and stored on their behalf.
Legal basis: Legitimate interests of the dealer to manage investor relationships.
When a member of the public submits a booking request through a dealer's public booking page, we collect their name, email address, phone number (optional) and any notes they provide.
Legal basis: Legitimate interests (to facilitate a vehicle viewing appointment requested by the individual). The dealer is the data controller for their customers' data; Autolytix processes this data only on the dealer's behalf.
If a dealer connects their Google Calendar, we store an OAuth access token and refresh token for that dealer's Google account. This is used solely to create calendar events when bookings are confirmed. We do not read, access or store any other Google Calendar data.
Legal basis: Consent of the dealer (who grants authorisation via Google's OAuth flow).
Dealers may upload vehicle documents (e.g. V5C, invoices). These may be processed by an AI optical character recognition (OCR) service (Google Gemini) to extract text. Documents may contain personal data such as names and addresses.
Legal basis: Contract performance; legitimate interests to provide document management features.
We collect server-side logs, error reports and general usage patterns to operate and improve the platform. We do not use third-party analytics cookies.
Legal basis: Legitimate interests to maintain platform security and reliability.
When you log in, we store a secure authentication token in your browser's local storage. This token is strictly necessary to maintain your logged-in session and is not used for tracking or advertising. Under PECR, strictly necessary session tokens do not require cookie consent.
We use the following third-party services to operate the platform. Each acts as a data processor under our instructions:
| Processor | Purpose | Location |
|---|---|---|
| Neon (Neon Inc.) | Hosted PostgreSQL database | United States |
| Google LLC | Calendar API, Gemini OCR, OAuth | United States |
| DVLA / DVSA | Vehicle registration enrichment | United Kingdom |
| Replit Inc. | Application hosting and infrastructure | United States |
Transfers to the United States are made under the UK Extension to the EU–US Data Privacy Framework or appropriate Standard Contractual Clauses (SCCs) where applicable.
We do not sell personal data. We do not share personal data with any third party for marketing purposes.
If you are an individual whose data we hold, you have the following rights:
To exercise any of these rights, contact us at privacy@autolytix.co.uk. We will respond within one calendar month as required by UK GDPR.
If you are a customer of a dealership using our platform, your primary right of contact is with that dealership (the data controller). We will cooperate with any erasure or access requests routed through the dealer.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters:
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss or destruction. These include:
In the event of a personal data breach that poses a risk to individuals, we will notify the ICO within 72 hours as required by UK GDPR and will inform affected individuals without undue delay.
Our platform is not directed at or intended for use by anyone under the age of 18. We do not knowingly collect personal data from children.
🧩 Chrome Extension — Required Disclosure
The Autolytix Chrome Extension accesses specific data to provide workflow automation for automotive dealerships. The extension collects and processes personally identifiable information (such as buyer names on lead forms), authentication tokens (to securely link to your Autolytix account), personal communications (to draft AI responses to incoming marketplace leads), and website content (to scrape vehicle details for form autofill). This data is strictly used to provide the core functionality of the extension. We do not sell this data to third parties, nor do we use it for unrelated marketing purposes.
All data accessed by the extension is used exclusively to provide the stated functionality — form auto-fill, lead response drafting, and vehicle data enrichment. Data is passed directly between the extension and your Autolytix account. We do not log, sell, or share extension-accessed data with any third party.
storage — to temporarily hold vehicle transfer data between the Autolytix app and the GOV.UK form pages.scripting / activeTab — to read and fill form fields on GOV.UK, AutoTrader and marketplace pages.tabs — to detect when the user navigates to a supported page and activate the relevant helper.We may update this privacy policy from time to time. When we make material changes we will update the “Last updated” date at the top and, where appropriate, notify registered users by email.