Privacy notice — our use of published parking-appeal decisions

Takes effect: on the date it is published on usebeatit.com — 8 August 2026

Last updated: 8 August 2026

This notice is about records of decided parking appeals that we collect from public tribunal registers, together with a smaller hand-picked set of published decisions, court judgments and reports about parking enforcement. If you are a Beat It customer, the information you give us when you use our service is covered by our main privacy policy at usebeatit.com/privacy — not this page.

Contents

The short version

We are Beat It, a parking-appeal service. Tribunals publish their decisions on parking appeals, and we collect those published decisions to learn which arguments win and which lose, so that the appeal letters we write for our customers are better. Some of those published decisions are about identifiable people — possibly you. This page explains what we hold, why, who else can see it, what is still unresolved about it, and the rights you have, including the right to object and have your records deleted.

Four things we would rather you heard from us than found out later, each explained in full below:

  1. A minority of the decisions we hold describe someone's health or disability. Under UK law that is the most protected kind of information, and it needs a specific legal condition on top of our ordinary legal basis. We have not yet confirmed that condition. Our own written assessments say that, as things stand, this part of what we do does not pass. We are seeking independent legal advice. In the meantime the company's director has decided to continue collecting and to keep the texts we already hold, rather than freeze or delete them, which is what our assessments recommended.
  2. We told you, in an earlier version of this notice, that we were storing an identifier under a promise not to. That is now fixed — dated, not quietly dropped from this page. Until 8 August 2026, the tribunal's case reference was stored, on every record in the London register collection, in its original, readable form: a breach of our own signed authorisation. On 8 August 2026 we rewrote every one of those records to the one-way code the authorisation always required, and the collector now checks the database for a readable case reference before every run and refuses to start if it finds one. What that buys you is real: someone who got hold of our database, without also having the secret value the code depends on, could not turn a London register case reference back into a case number. This promise was never made about, and does not extend to, the 43 hand-picked published decisions described below, which keep their ordinary published case references on purpose — see "Where the records come from" for why. It does not stop youusing your own case number to find your own record — see "How to help us find you" below for how that works now.
  3. A second thing we are correcting the same way: the limit set on this round of collecting was breached before anyone noticed, and only then raised. The company's director had signed off a limit of 4,500 individual case pages for this phase. The counter meant to enforce that limit reset itself every night instead of counting across the whole phase, so it never actually stopped collection at 4,500. By the time this was found, on 7 August 2026, around 6,318case pages had already been read — well past the signed limit. The director then made a recorded decision to raise the limit rather than delete what had already been collected, and we built a counter that does not reset, so the new limits are the ones actually enforced from here on. See "What records we hold" below for the numbers.
  4. We do not have permission from London Tribunals to store or commercially use their register content, and their published terms do not allow it. We have written a letter asking for that permission; it has not been sent yet. Collection is continuing meanwhile, on the director's explicit decision.

Who we are

The company legally responsible for this data (in the law's language, the "controller") is Beat It Ltd, company number 17198935, registered in England. Registered office: Apartment 104, 3 Wood Crescent, London, England, W12 7GN. (Company number, company name and registered office checked against the Companies House public register on 7 August 2026.)

For anything in this notice, contact us at support@usebeatit.com.

Data protection officer. We have not appointed one. Whether the law requires us to appoint one — given the scale of this collection and the fact that it includes health-related information — is a question our own assessment has flagged and has not yet answered. We are not telling you the question is settled. If the answer is that we must appoint a DPO, we will, and we will put their contact details here.

What records we hold

Counted in our database on 8 August 2026 (these numbers grow with every collection run):

  • 49,892 records from the London Tribunals register of appeals (the Environment and Traffic Adjudicators — the tribunal that decides appeals against London council parking and traffic penalties), covering roughly the most recent 12 months of decided appeals. We collect from this register by automated means, and collection is ongoing. The earliest record in our database is dated 23 July 2026 — that is the earliest collection we can evidence from our own records, rather than a certified start date.
  • Of those, 6,594 records hold material taken from the individual case's own page(counted 8 August 2026) — and 6,004 of them include the adjudicator's written reasons, the text explaining why the appeal was allowed or refused; the others hold structured details from the case page without the full reasons. The rest of the records are index entries only. These numbers grow, because the collector is still working backwards through older cases.
  • There is a limit on how much more we can collect in this round — and that limit was not properly enforced for a period, which we would rather you heard from us. The original signed limit for this phase was 4,500 individual case pages. The counter meant to enforce it reset itself every night instead of counting across the whole phase, so it never actually stopped collection at 4,500. By the time this was noticed, on 7 August 2026, around 6,318case pages had already been read. Once this was known, the company's director made a recorded decision to raise the limit rather than delete what had already been collected, and we built a counter that does not reset, so the limit now actually stops collection when it is reached. The limits as raised are 20,000 pages of the register's list view (used to find new cases) and 50,000 individual case pages (used to fetch the full reasoning text), in total. At the pace we have been collecting, we expect collection to stop on its own around 1 October 2026, when that allowance runs out, and a review is scheduled for that date — the same date already set for reconsidering the health-data position. The limits can only be changed by another recorded decision; they do not change themselves.
  • 43 individually chosen published decisions and reports, gathered by hand for research. These are not all tribunal decisions and not all from one place, and what we hold for each is not uniform either — some are the full published text, some are substantial verbatim extracts we quote from, and some are short summaries of what a decision said — see "Where the records come from" below.
  • 11 published decisions from Northern Ireland, saved by hand as files on 6 August 2026.

What is in a record.An index entry from the London register contains: the tribunal's case reference (stored as a one-way code since 8 August 2026 — see "The case reference" below), the council or other authority involved, the type of alleged contravention, the outcome, and the date. Not every record contains a ground of appeal — the index entries generally do not.

Where we hold the written reasons, that text can also contain: the street, the date and time of the alleged contravention, and whatever personal circumstances the appellant described to the adjudicator. Those circumstances can include:

  • health conditions or disabilities, sometimes of someone other than the appellant;
  • financial hardship and other sensitive circumstances;
  • other people named or described in passing — a passenger, a family member, a carer, a witness — who never appealed anything themselves;
  • children and vulnerable adults, where a decision describes them. We cannot rule this out and we assume it happens;
  • adjudicators, named in their professional capacity;
  • identifiers of the appellant or others that remain inside the text itself — see the next section, which explains this honestly.

What we strip out, and what may still be in there

Please read the limit first: assume that a decision text we hold may still contain identifying details. The system for stripping identifying details out of text — what our assessments call "redaction" — has not been built or tested, and we are not going to describe it as though it had been.

  • Genuinely never written to our storage: the appellant's name, the vehicle registration mark and the Penalty Charge Notice number as separate fields. The London collector reads them only so it can find and strike them out of the text, then discards them. They are not stored.
  • Not guaranteed: identifiers inside the free-text reasons. The London collector does run a step that replaces case references and telephone numbers found in the prose before storing it — but the last check of that step recorded in our code covered the 278 texts stored at the time, and we now hold over 6,000 (counted 8 August 2026). It does not cover the 43 hand-picked texts or the 11 Northern Ireland texts at all, and the properly tested removal system described in our assessments has not been built. Names, initials, references or vehicle details can survive inside stored text.

The case reference: what went wrong, and how we fixed it

Stated plainly, because it matters, and because a mistake we already admitted to you deserves a dated correction, not a quiet rewrite.

When collection from the London register was authorised, it was authorised on the condition that the tribunal's case reference must not be retained — it was to be stored only as a one-way code: a jumble of letters and numbers worked out from the reference by a calculation that cannot be reversed, using a secret value kept outside our code repository and outside the database — in a settings file on the machine that does the collecting — so that the code cannot be cracked by simply trying every possible reference.

That condition was not met, for a period. From when this collection began until 8 August 2026, the case reference was stored on every record in its original, readable form. That was a breach of the written authorisation the collection runs under, and earlier versions of this notice said so plainly.

It is fixed now, and here is exactly what we did. On 8 August 2026 we rewrote every one of the roughly 49,900 records then held in the London register collection — and every case reference sitting inside our own internal review queue (a separate, smaller list used to flag clusters of cases that might be worth a refund review) — to the one-way code the authorisation always required. This rewrite, and the promise behind it, covers the London register collection and that review queue only. The 43 hand-picked published decisions and the 11 Northern Ireland decisions were never subject to this promise and were not touched by this rewrite — they keep their ordinary published case references on purpose; see "Where the records come from" below for why. We also changed the collection system so that, before every run, it checks our main record store for a readable, original case reference and refuses to start if it finds one; within a run, the code path it uses only ever writes the coded form, never the original. One limit on that safeguard, stated honestly rather than glossed over: the before-every-run check looks at the main record store only — it does not itself also check the smaller internal review queue each time. As of 8 August 2026 that queue holds 62 entries and every reference inside them is coded, not raw, because today its entries are built from the already-coded main record store — but the automatic check that would catch a readable reference reappearing there directly, on some future run, has not been built yet. We checked our own database directly before publishing this notice and found zero readable case references in the London register collection or its review queue — the two places this promise covers. We did not check, because the promise never covered, the separately held 43 hand-picked texts or the 11 Northern Ireland files, which keep readable published references by design.

The honest consequence of fixing it, stated precisely rather than oversimplified. The code cannot be turned back into the original case reference — that is the whole point of it, and it means someone who obtained a copy of our database on its own, without the secret value the code depends on, could not recover a single case number from the London register collection. (This paragraph is about that collection only: the 43 hand-picked published decisions are not coded at all and keep their ordinary published case references — see "Where the records come from" below for why.) But the calculation works the same way every time it is run: if you give us your London register case number, we can run it through that same calculation and get the same code back, then find your exact record by looking for that code directly — a precise match, not a guess. So your case number is still the most reliable thing you can give us for a London register case. What changed on 8 August 2026 is only that nobody can type it straight into a database search any more — someone has to run it through the calculation first. See "How to help us find you" below for exactly how that works, and what to give us if you do not have your case number — or if your case is one of the 43 hand-picked decisions, which are found by their published citation directly, with no calculation involved.

Where the records come from

We did not get this information from you. It comes from publicly accessible sources. Specifically:

  • The statutory register of appeals published by London Tribunals (londontribunals.gov.uk and the register application it links to) — the source of the 49,892 records (counted 8 August 2026). Anyone can search that register; it is searchable by appellant name and by PCN number.
  • The Department of Justice Northern Ireland website (justice-ni.gov.uk) — the source of the 11 Northern Ireland decisions, which the Department itself published with names removed.
  • The 43 hand-picked items are of mixed origin, and we would rather be specific than tidy. From our own records of where each came from: at least seven are from Traff-iCase / keycases.info (the curated key-cases collection funded by PATROL); one is from a London Tribunals key-cases file; about twelve come from the NPAS Joint Report 2004; about seven are register decisions quoted on the Pepipoo motoring forum rather than taken from a tribunal site; the remainder are court judgments, a decision of the Upper Tribunal for Scotland, and other second-hand collections. Being exact about the limit of that answer: for roughly 35 of the 43 we have the recorded source but have not individually classified where each one ultimately came from. If one of them is yours and you ask, we will tell you what our record of its source actually says. Because of that mixed origin, the depth of what we hold varies too: the register decisions quoted on Pepipoo, for example, are extracts and quotations rather than the full published text; we have not gone through all 43 to sort full texts from extracts from summaries, so we describe them honestly as a mix rather than claiming a precision we do not have.

    Why these 43 keep their ordinary published references, unlike the London register collection above. The no-readable-case-reference promise described in "The case reference" section was made for, and applies to, the automated London register collection — a bulk automated pull of appellants who did not choose to be individually featured. These 43 items are the opposite: a small set of decisions individually chosenfor research, the way a lawyer or a journalist keeps a folder of notable judgments. We cite each one by its ordinary published case reference or citation, in the same way a published court judgment is cited by its case number, because that is how these decisions are meant to be found and checked — and because no promise was ever made to code them. If your case is one of these 43, you can ask us about it using its published reference directly; see "How to help us find you" below.

Tribunals publish decisions so that justice is done in the open; anyone can read them at the sources above.

Is your information in these records?

Possibly, if any of these is true:

  • You appealed a parking or traffic penalty to one of the tribunals above and your case was decided in the period we collect (for the London register, roughly the last 12 months).
  • You were mentioned in someone else's appeal — as a passenger, a family member, a carer, or another person referred to in the written reasons — even though you never appealed anything yourself.
  • You are an adjudicator whose decisions appear in the register.

The sensitive part: health and disability

Some of the written reasons mention a person's health condition or disability — for example a medical emergency, a Blue Badge issue, or a condition affecting mobility. We do not have figures on how often this happens and we are not going to guess.

Health information is the most protected kind of personal data in UK law. Using it needs a specific extra condition on top of an ordinary legal basis — and that applies to collecting and storing it, not just to anything clever we might do with it later.

Where we actually stand, without softening it:

  • The condition we intend to rely on is the part of the law that allows personal data to be used for research and statistics (Article 9(2)(j) UK GDPR with Schedule 1 paragraph 4 of the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025).
  • We have not confirmed that this condition covers what we are doing. Independent legal advice has been identified as necessary and has not yet been obtained.
  • Our own written assessment says that, until that is confirmed, this part of our activity — the collection and storage we are doing today, not merely a future step — does not pass. It recommended freezing the affected texts, with deletion as the fallback.
  • That recommendation has not been implemented. The company's director decided instead to continue collecting, and to keep the texts already held while making them safer, with the intention of deleting the raw texts once the information has been extracted from them and checked. That decision was taken with the position stated to him in these terms. Collection is expected to stop around 1 October 2026, when the collection budget runs out, and a review of this decision is scheduled for that date. The decision can only be changed by another recorded decision — it does not change itself automatically.

We think you are entitled to know that, rather than read a sentence saying the matter is in hand.

Why we collect these records

One purpose: to work out, from the pattern of decided cases, which appeal arguments tribunals accept and which they reject — especially the arguments that reliably lose — so that the appeals we prepare for our customers avoid known losing arguments and put the strongest honest case forward. We use the records to study arguments, not people. This is a commercial purpose: we sell a parking-appeal service, and this analysis makes it better. It also serves motorists more widely, because councils see thousands of outcomes and an individual motorist sees one.

Who else can see this data, and where it sits

  • Our database host. Most of the records sit in a database run by Supabase, hosted in Amazon Web Services' London region. The data is encrypted while travelling and while stored.
  • Copies of what is (and is not) in the database. Being complete about this: the 11 Northern Ireland decisions exist only as files on a company computer — there is no ingestion process that puts them into the database, and no database rows to go with those files. The 43 hand-picked texts are different: they exist both as database rows and as a file, and also inside an older research document. Supabase separately keeps automatic backups of the database itself. How long those backups keep a deleted record is something we have not yet established.
  • GitHub, Inc. The file containing the 43 hand-picked decision texts is stored in a private code repository hosted by GitHub, Inc., a US company, including in that repository's history. That same private repository is where the wider software we use to build and run Beat It is also kept — this one file is the only place inside it holding any of the personal data this notice describes. "Private" means not publicly visible; it does not mean nobody else holds it — GitHub the company stores it on its systems. See "Does the data leave the UK?" below for what legal protections apply to this.
  • Who inside Beat It can reach it.We are not going to tell you access is limited to a carefully controlled few, because the work to make that true has not been done yet. What is true: the database is reached using a single master password that unlocks everything in it (a "high-privilege key"), held by the company's director, and by an AI coding assistant running on his own computer under his control — whose sessions are transmitted to Anthropic, the company that provides it. The working rule is that the assistant only ever queries counts and column names, never decision text. That rule is currently a discipline, not a technical block; building the technical block is outstanding work. Whether any decision text was read through that channel in the past is being audited; we are not asserting it never happened, because we cannot prove that.
  • Planned — an AI provider (this has not started). We plan to send decision texts — with names, case references, vehicle marks, postcodes and exact dates removed first — to an AI provider (Anthropic or OpenAI) so that its model can turn the free text into short standard labels: the ground argued, the outcome, the type of reasoning. That step has not started. It will not start unless and until our written assessments are completed and every condition in them is met, including the legal confirmation described above. If it goes ahead, we will update this notice to name the chosen provider before it starts.

No Beat It customer sees decision texts or individual case records.

Does the data leave the UK?

  • The main database is in the UK (Amazon Web Services, London region).
  • The file of 43 decision texts sits with GitHub, Inc., a United States company. We reviewed GitHub's own published terms on 7 August 2026. What we found, stated as plainly as the position allows:
    • GitHub publishes a standard set of legal protections for moving personal data out of the UK — a form of contract called "Standard Contractual Clauses", completed with the UK regulator's own addendum for UK data — and anyone can read the full text, without asking, at github.com/customer-terms/github-data-protection-agreement. GitHub also separately says it follows a US government privacy scheme (the "Data Privacy Framework"); its own listing under that scheme currently shows as "under re-certification review" rather than a plain "active" status.
    • The problem: it is not established that either protection actually covers our account. GitHub's own description says the contract carrying those legal protections applies to its paid business plans — Enterprise, Teams, Copilot. Our account is on GitHub's free plan, which is not one of the plans that description names. Until GitHub confirms in writing that a free-plan account is covered too, we are not going to tell you the protection applies, because we do not know that it does.
    • GitHub does not publish a fixed number of days after which a deleted file, or even a fully rewritten repository, is guaranteed gone from its systems and backups. Deleting the file would not, by itself, remove it from GitHub's systems — a further request to GitHub's support team would be needed, and GitHub gives no timeframe for how long that takes either.
    • What we have not yet done, stated honestly: we have not yet written to GitHub to ask whether a free-plan account is covered, and we have not yet removed the file from the repository. Both remain open as at the date this notice was published — email support@usebeatit.com for the current position. Once this is resolved, either because GitHub confirms the protection applies or because we remove the file, we will update this notice to say which and, if a safeguard applies, how to get a copy of it.
  • Our own assessment still requires this to be resolved before we send either of the permission letters described below, and in any event before the planned AI step starts.
  • The planned AI step, if it goes ahead, would involve sending data to a US-headquartered company under (a) a written contract limiting what they may do with it (a "data-processing agreement") and (b) a standard set of contract terms approved by the UK's data-protection regulator for sending personal data abroad (the "UK Addendum to the EU standard contractual clauses"). Because that step is planned and not current, none of that is in place yet. Once it is, you will be able to ask us for a copy.

How long we keep it

What actually causes deletion today, first, because it is the honest answer: nothing expires by itself. There is no automatic deletion in our systems. A record is deleted today only if a person deletes it — because you objected or asked us to, because a source body asked us to, or because we decided to. That is the real retention position on the day this notice publishes.

The periods below are proposed, not agreed, and not yet enforced. They have not been formally signed off, and the job that would enforce them has not been built. We are telling you the intention, labelled as an intention.

WhatProposed period
Full decision texts (the written reasons)What happens today:nothing about a text's age causes it to be deleted automatically — see "What actually causes deletion today" above. Our intention:delete the full text of each case once we have extracted the information we need from it and checked that extraction, a deliberate decision the company's director made on 6 August 2026, not a fallback. The outer limits we have set ourselves, on top of that intention: 36 months from the date we collected a text, extendable only by a signed, reasoned amendment; or 24 months from the last time a text was used for extraction, if that comes sooner — a text unused that long is deleted at that review. What this table row is, honestly: a policy promise, not a mechanised deletion — no job exists yet that enforces any of these periods automatically.
Summary records of each case in the London register collection (authority, contravention type, outcome, date, case reference stored as a one-way code since 8 August 2026)Up to 5 years from creation.
Published statisticsWe have published none. If we ever do, they will be combined counts only (see below). Whether such counts still amount to personal data is something we would have to test before publishing anything — we have not done that test, because nothing has been published.
Copies held by an AI provider, if that step ever startsGoverned by that provider's terms — typically deleted within 30 days, with exceptions we have documented and would name here before starting.

Two things this table has not said until now, added here rather than left implied — and both about the 43 hand-picked published decisions, not the London register collection above.

On the case reference.The "Summary records" row above is about the London register collection only, exactly as everywhere else in this notice that promise appears. The 43 hand-picked published decisions are not covered by it and never were — they keep their ordinary, readable published case references on purpose, because that is how these decisions are meant to be found and checked. See "The case reference" and "Where the records come from" above for why.

On retention for the curated extracts and summaries. This table has never said, until this sentence, which period governs the curated textual extracts and short summaries within the 43 — as distinct from the ones among them that are the full published text. Our position, written down here for the first time, dated 8 August 2026: they follow the same period as the "Full decision texts" row above. Our own supporting documents do not set a separate period for them, so absent a reason to treat them differently, the same period applies.

The same proposal includes reviewing every year whether we still need this data at all. That yearly review is part of the proposal too — it is not yet a process we run.

Regardless of the periods above, we aim to delete the relevant records within 30 days if: you object(we have committed not to contest objections — see "Your rights"); or the tribunal or body that published the material reasonably asks us to. Please read the honest limits on delivery in "Your rights" below.

The permission question, stated plainly

This is not, strictly, information the privacy rules require us to give you. We are including it because a notice that says "collection is ongoing" while leaving this out would not be honest.

We reviewed each source's published terms on 6–7 August 2026. What that review found:

  • London Tribunals — conflict.Their copyright statement says their content may be printed or downloaded "for your personal and non-commercial use only", and that you may not, without their express written permission, "commercially exploit the content" or "store it in any other website or other form of electronic retrieval system". We are a commercial service and we store their content in a database. What we are doing is outside their published terms. We have drafted a letter asking for exactly the written permission their terms describe; it has not been sent yet, and collection is continuing meanwhile on the director's explicit decision. Nothing on their site forbids automated reading as such, and our collector is set to one request every 10 seconds, which matches the rate their own robots file asks of automated visitors — though we have not independently measured what the live collector does against that setting. The storage and commercial-use conflict is real and unresolved.
  • Traff-iCase / keycases.info — unsettled. Their site says decisions are "in the public domain" while the footer claims copyright. That is ambiguous, and ambiguity is not permission. We collect nothing from that site; a letter asking them to clarify has been drafted and not sent.
  • First-tier Tribunal for Scotland (General Regulatory Chamber) — conflict. Their terms allow reproduction "for personal or in-house use only", which does not cover a commercial product. We have no permission letter for this body. We run no collection from that site, and we have not yet established whether any of its material is among our 43 hand-picked items.
  • Department of Justice Northern Ireland — clear. That material is published under the Open Government Licence, which permits re-use including commercial re-use, provided the source is credited.

To be exact about permission, because the four entries above differ: we hold no licence or permission covering the London register material, the Traff-iCase material or the Scottish material. The Northern Ireland decisions are the one exception — those are covered by the Open Government Licence, which does permit what we do with them, provided we credit the Department of Justice as the source.

What we do and do not do with these records

  • We do not try to identify anyone. We do not attempt to work out who a person in these records is, contact them, or link their decision to anything else we know.
  • We make no decisions about the people in these records. Nothing we do results in a decision, measure or judgement about any individual appellant, and no automated decision is made about anyone in these records. We are not going to go further and tell you this cannot affect you at all: our own risk assessment identifies real risks — a security breach, someone piecing together who a record refers to, and the distress that would cause — and works to reduce them rather than pretending they are zero.
  • We do not publish decision texts. We have published no figures from this data. If we ever do, each published figure will be a combined count— for example "of 40 signage appeals against this council, 12 succeeded" — never an individual case; we would not publish a figure resting on fewer than five decisions, because a small group is easier to pick out; and we would test the figures before release to check they cannot be traced back to an individual. That testing has not been done, because nothing has been published.
  • We do not sell this data.We are deliberately not claiming we "never share" it, because that would not be true: a copy of the 43 hand-picked texts already sits with GitHub, and a disclosure to an AI provider is planned. Both are described above. Two limits on how firmly we can say that: we cannot rule out that a copy of the private code repository exists somewhere else (we do not know who else may have taken a copy), and the question of what the AI coding assistant may have read in the past is still being audited. Apart from those and the hosting arrangements described above, we do not send these records anywhere else, and any new use of the data beyond the purpose described here requires a fresh written assessment and sign-off before it starts.

Your rights, and how to use them

You have these rights over personal data we hold about you:

  • Object — tell us you do not want your records processed.
  • Access — ask whether we hold records about you, and get a copy.
  • Erasure — ask us to delete your records.
  • Rectification — ask us to correct records that are wrong.
  • Restriction — ask us to stop using your records while something is checked or disputed.

How to use them. Email support@usebeatit.com with the subject line "Tribunal decision records". There is no charge. The law gives us one calendar month to respond and we will work to that — but please read "what this means in practice today" below before relying on anything in this section, because the system behind it has not been built.

How to help us find you. Because we do not try to identify the people in these records, please give us enough to locate yours. Which route applies depends on which set of records your case is in. If you appealed to a London tribunal, see the case-reference route below. If you think your case is one of the 43 hand-picked published decisions described in "Where the records come from", it is simpler: those are found by their ordinary published case reference or citation directly — no calculation involved, because we never coded them in the first place.

For a London register case, the most reliable thing you can give us is your case reference. We cannot read a stored code back into a case number — that protection is real, and we are not undoing it. What the calculation actually does, stated precisely rather than loosely: it only runs one way — it is not reversible in either direction on its own. But because the same case reference always produces the same code, we can take the case number yougive us and compute your record's code from it, then find your exact record by looking for that code directly. The code itself still cannot be run backwards to recover a case number from it; only your own case number, going in, lets us reach your record. This changed on 8 August 2026 — before that date we searched directly on the stored reference; now the calculation step comes first, done by hand by whoever is answering your request, but the result is still a precise match on your specific record, not a search of similar ones.

If you do not have your case reference, tell us the council or authority involved, the rough date of the decision, and the outcome, if you remember it, and we will search our records by hand using those details. Being honest about the limits of that route: those details may match more than one record — more than one person can have appealed to the same council around the same time with the same outcome — and we may need to come back and ask you for more, such as the location or the type of alleged contravention, before we can be confident we have found the right one. We do not store names or vehicle registrations as searchable fields either, so a name alone may not find anything.

If you were mentioned in someone else's appeal — as a passenger, a family member, a carer or a witness — you will almost certainly not have a case reference, and we know that. Tell us what you can: roughly when and where it happened, which council, and how you came to be mentioned. We will search the stored text by hand. We may not find it, and if we cannot we will say so rather than leave you wondering. If you are worried and we cannot locate a record, you can still complain to us or to the ICO using the routes below.

On objections, we have made a commitment and we will keep it: we will not argue that our commercial interest outweighs your objection. We will not put you through a balancing debate.

What this means in practice today. The system for handling these requests has not been built. Right now this is a person reading an inbox and doing the work by hand. That is a real route and we will use it — but you should know its limits:

  • We can search the database using the details described in "How to help us find you" above — your case reference if you have it (run through the calculation first, rather than typed straight into a search), or the council, the rough date and the outcome if you do not — tell you what we hold, correct it and delete it. That much we can do by hand from day one.
  • Stopping it coming back. The automatic exclusion list — the thing that would make future collection runs skip your case for good — is part of the machinery that has not been built. What we can do today is record your objection and delete the records again if a later collection run re-adds them. We would rather tell you that than let you assume one email ends it permanently.
  • Backups. Deleting a record from the live database does not immediately remove it from the automatic backups, and we have not yet established how long those backups keep it. We will tell you the position when you ask.
  • Other copies. If your case happens to be one of the 43 hand-picked items, a copy also exists in the history of a private code repository. Removing it from there is a separate, larger job than deleting a database row, and we would tell you so rather than imply it was done.
  • Local files. The 11 Northern Ireland decisions exist only as files — there are no database rows for them to begin with, so a Northern Ireland deletion means removing the file, and nothing else. The 43 hand-picked items are different: that file also has a matching row in the database, so a deletion for one of those has to cover both the file and the row, and we would confirm to you that it did.
  • Published figures.None exist. If a combined figure has been published in future, we could not unpick one person's contribution from a total — but the underlying records would be deleted and nothing new would use them.

We would rather tell you that now than promise you a clean end-to-end deletion we cannot yet demonstrate.

Deleting or objecting here affects our copy of the records. The tribunal's own published register is theirs, not ours — to change or remove a decision on the public register itself, you would need to contact the tribunal.

Complaining to us

You have the right to complain to us directly about how we handle your personal data, and we have a legal duty to make that easy, to acknowledge your complaint within 30 days, and to respond without undue delay.

To complain: email support@usebeatit.com with the subject line "Data protection complaint". Tell us what you are complaining about and what you would like us to do. You do not need to use any particular form of words, and you do not need to have contacted us before.

Being straight with you about what receives it: that inbox is read and handled by a person; we do not yet have a dedicated complaints form or automated tracking. The 30-day acknowledgement and the duty to respond apply regardless.

Complaining to the ICO

You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data-protection regulator:

You can go to the ICO whether or not you complain to us first.

Why we are telling you this way, rather than writing to you

Normally, when a company collects personal data from somewhere other than the person themselves, it must tell each person individually. UK law (Article 14(5)(e) and 14(7) UK GDPR) allows a company to publish the information publicly instead, where telling everyone individually is impossible or would take a disproportionate effort, provided it takes appropriate steps to protect people's rights. That is the situation here: the register records name tens of thousands of appellants but include no contact details. Finding addresses for all of those people would itself mean gathering far more personal data about them than we hold now — a bigger intrusion than the one this notice describes. So we publish this information openly instead, and this page is that publication. It is linked from our main privacy policy at usebeatit.com/privacy, and the objection, deletion and complaint routes above are open to everyone in the records.

One more thing, stated plainly: the earliest record we can evidence in our database is dated 23 July 2026 — the earliest collection we can evidence from our own records, rather than a certified start date — and this notice is being published after that collection started. It should have been available sooner.

Dates and changes

  • This notice takes effect on the date it is published: 8 August 2026.
  • Last updated: 8 August 2026.
  • What has already changed this page, dated. On 8 August 2026 we fixed the case-reference fault described above and updated this notice the same day to say so, rather than waiting for a scheduled review. That is the standard we hold ourselves to for everything below.
  • What will change this page next, and when. We will update this notice — and change the date above — before any of the following starts or takes effect: the planned AI-provider step; collection from a new source; the legal answer on the health-related condition; whether GitHub confirms our free-plan account is covered by its data-transfer protections, or we remove the file instead; the permission answers from London Tribunals or PATROL; and the appointment of a data protection officer if we turn out to need one. Several of those are matters this notice currently records as unresolved, and we would rather come back and correct this page than leave a comfortable version of it standing.

Get the Beat It app

Download on theApp StoreGET IT ONGoogle Play