Legal
Privacy Notice
This notice explains how Hawke Electric Vehicles collects, uses, shares, transfers and protects your personal data when you use this website, request a quotation, place an order, hire a vehicle, take a service plan, create an account or otherwise deal with us. It also lists the third-party services and application programming interfaces (APIs) we rely on. Please read it carefully.
Who we are and how to contact us
Hawke Electric Vehicles is a trading name of The Hawke Group Ltd, a company registered in England and Wales under company number 16624766. Our registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. References to "we", "us" and "our" mean The Hawke Group Ltd.
The Hawke Group Ltd is the "data controller" for the personal data described in this notice.
For any privacy query, or to exercise your data protection rights, contact our privacy team at privacy@hawkeev.com, call us on 020 4540 5899, or write to the Data Protection Lead, The Hawke Group Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
The personal data we collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
- Identity and contact data: your name, the company or organisation you represent and your role, email address, telephone or mobile number, and postal, billing or delivery address.
- Enquiry, quotation and order data: the vehicles, specifications, sectors, locations, dates, quantities and requirements you tell us about; your messages, notes and callback requests; and the quotations, orders, hire agreements, service plans, deposits and correspondence that follow.
- Account data: where you create an account, your login email, authentication credentials (stored only in hashed or tokenised form), and the records of your orders, vehicles, documents and service history shown in your account.
- Transaction and financial data: details relating to deposits, balances, payments, invoices, hire and service-plan charges. Card payments are processed by our payment provider; we do not see or store full card numbers.
- Documents and uploads: agreements you sign, photographs or files you or our engineers upload (for example service or inspection photos), and proof-of-payment images, stored in private, access-controlled storage.
- Technical and usage data: your IP address and the approximate location (town/region and country) it indicates, device and browser type, the pages you view, the links and vehicles you click, the page you arrived from and your time on the site. We use this to operate and secure the site and to manage our sales enquiries (our legitimate interests). A persistent identifier and session recording (which lets us replay a visit to improve the site) are used only with your consent.
- Communications and marketing data: your contact and marketing preferences, consent records, and a record of our correspondence with you, including emails and SMS messages and their delivery status.
Special category data and children
We do not seek or require special category data (such as health, racial or ethnic origin, or biometric data) and ask that you do not send it to us. If you choose to tell us about an accessibility or mobility requirement so that we can recommend or configure a suitable vehicle, we use that information only for that purpose and on the basis of your consent or substantial public interest, and we delete it when it is no longer needed. Our products and services are aimed at businesses and adults; we do not knowingly collect data from anyone under 18.
How we collect your data
We collect personal data when you provide it directly (for example through a quote, contact, hire, service-plan or callback form, by email, SMS or telephone, or when creating or using an account); automatically through cookies and similar technologies when you use the site (see our Cookie Notice); and occasionally from third parties such as our payment, delivery or, where applicable, finance partners, or from publicly available business sources such as Companies House.
How we use your data and our lawful basis
We only use your personal data where the law allows. Our purposes and lawful bases under the UK GDPR are:
- To respond to enquiries and prepare quotations: necessary for steps taken at your request before entering a contract, and our legitimate interest in dealing with enquiries efficiently.
- To manage orders, deposits, balances, deliveries, hire, service plans, accounts and warranty or service requests: necessary for the performance of our contract with you.
- To take payment and prevent fraud: necessary for our contract and our legitimate interest (and yours) in secure transactions.
- To run, secure, monitor and improve the website and our business, including basic analytics and protecting against abuse, bots and fraud: our legitimate interests, balanced against your rights and freedoms.
- To send you marketing or service updates: only with your consent, or on the basis of the 'soft opt-in' to existing customers for our own similar products, which you can withdraw at any time.
- To enrich analytics, build heatmaps and record anonymised session replays: only with your consent.
- To meet legal, accounting, tax, regulatory and dispute-related obligations: necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
Service providers, sub-processors and the APIs we use
We do not sell your personal data. We rely on a small number of trusted service providers (data processors) who process personal data on our documented instructions, under contracts that meet UK GDPR Article 28, and only for the purposes we set. Several of these are accessed through their APIs. The current providers, what they do, and the data involved are:
- Vercel Inc. — website hosting, content delivery and privacy-friendly web analytics. Processes technical data such as IP address and request logs.
- Neon / our managed database provider — secure storage of enquiry, order, account, hire and service data. Processes the identity, order and account data above.
- Stripe Payments Europe / Stripe, Inc. — card and wallet payment processing and fraud screening. Processes transaction data and the card details you enter directly with Stripe; we do not receive full card numbers (see Payments and card security).
- Vercel Blob storage — private, access-controlled storage of documents, agreements and uploaded photographs.
- Resend — sending transactional and, where you have opted in, marketing emails, and recording delivery status. Processes your name, email and message content.
- Twilio — sending and receiving SMS where you provide a mobile number and opt in. Processes your mobile number and message content.
- Microsoft Clarity — consent-based, anonymised session replay and heatmaps to improve the site. Used only after you accept analytics cookies; sensitive text is masked.
- Google Analytics (GA4), where enabled — consent-based aggregate site analytics.
- Ideal Postcodes / postcodes.io — UK address and postcode lookup. When you type a postcode into an address field, that postcode is sent to this open-data API to suggest matching addresses. We send only what you type into that field.
- Upstash / our rate-limiting service, where enabled — short-lived storage of IP-derived data to protect the site against abuse and excessive automated requests.
- Zapier and/or our internal alerting — routing new enquiry and lead notifications to our team. May receive the contact details and message you submit so we can follow up.
- Sanity — our content management system, which stores website content (not customer personal data in the ordinary course).
- Professional advisers (lawyers, accountants, insurers) and, where engaged, delivery, logistics, finance and engineering partners who fulfil or service your order.
International transfers
Some of our providers (for example certain hosting, payment, email and analytics services) may store or process data outside the UK, including in the European Economic Area and the United States. Where they do, we rely on appropriate safeguards recognised under UK data protection law — such as UK 'adequacy' regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with supplementary measures where needed — so that your data continues to receive an essentially equivalent level of protection. You can ask us for more detail on the safeguards that apply.
Artificial intelligence and automated decisions
We do not carry out solely automated decision-making that produces legal or similarly significant effects about you (such as automatically approving or refusing an order or finance). Decisions that matter are taken by our team.
Some images, renders and illustrations on the website are computer-generated or AI-assisted and are illustrative only; they do not involve your personal data. We do not submit your personal data to third-party generative-AI services to train their models.
Payments and card security
Card and wallet payments are handled by our payment provider (Stripe) on their secure, PCI-DSS-compliant infrastructure. Your full card details are entered with the provider and are not seen or stored by us. Bank transfers are made to the account shown in your account area or quotation; we will never email you new or changed bank details, and you should always verify them with us by telephone before sending money.
Marketing
We will only send you marketing where you have consented, or where you are an existing customer and we are contacting you about our own similar products and services (the 'soft opt-in'). Every marketing message includes an easy way to opt out, and you can also opt out at any time by emailing privacy@hawkeev.com or replying STOP to a marketing SMS. We never sell your personal data or share it with third parties for their own marketing.
Other recipients of your data
Beyond the processors listed above, we may share personal data with:
- Regulators, law enforcement, courts or other authorities where we are required to do so by law, or to establish, exercise or defend legal claims.
- A buyer, investor or successor (and their advisers) if we sell, restructure, finance or transfer all or part of our business, subject to appropriate confidentiality.
- Anyone else with your consent or at your direction.
How we keep your data secure and report breaches
We use appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, including encryption in transit, hashed credentials, access controls, private document storage and trusted, contractually bound providers. No transmission over the internet can be guaranteed completely secure, but we review our measures regularly. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours where required, and will notify you without undue delay where the breach is likely to result in a high risk to you.
How long we keep your data
We keep personal data only for as long as we need it for the purposes set out above, including to satisfy legal, accounting, warranty or reporting requirements. As a general guide: we keep unconverted enquiry data only for as long as we need to deal with the enquiry and a reasonable follow-up period; we keep customer, order, hire, service-plan and accounting records for at least six years after the end of our relationship to meet our legal and tax obligations; and we keep consent and marketing-preference records for as long as needed to evidence your choices. After the applicable period, data is securely deleted or anonymised.
Your rights
Subject to certain conditions and exemptions under data protection law, you have the right to:
- Be informed about how we use your data (this notice).
- Access a copy of the personal data we hold about you.
- Have inaccurate data corrected, and incomplete data completed.
- Have your data erased in certain circumstances.
- Restrict or object to our processing in certain circumstances, including objecting to direct marketing at any time.
- Data portability for data you provided to us, where applicable.
- Withdraw consent at any time, where we rely on consent (without affecting processing already carried out).
- Rights in relation to automated decision-making and profiling, which we do not carry out in a way that produces legal or similarly significant effects.
Exercising your rights and complaints
To exercise any of these rights, email privacy@hawkeev.com or write to the address in 'Who we are'. We will verify your identity and respond within one month, though we may extend this by up to two further months for complex or numerous requests and will tell you if we do. Exercising your rights is free in most cases, though we may charge a reasonable fee or refuse to act on manifestly unfounded or excessive requests. If you are not satisfied, you have the right to complain to the ICO at ico.org.uk or 0303 123 1113, but we would welcome the chance to resolve your concern first.
If you are outside the UK
This notice applies to everyone whose personal data we process, wherever you are. If you are in the European Economic Area, references to the UK GDPR should be read as including the EU GDPR where it applies to you, and you may also complain to your local supervisory authority. If you are in the United States, we honour reasonable requests to access, correct or delete your personal data through the contact details in 'Who we are', and we do not sell or share your personal data for cross-context behavioural advertising.
Changes to this notice
We may update this notice from time to time to reflect changes in our practices, the providers we use or the law. The date below shows when it was last updated, and material changes will be highlighted on this page, so please check back periodically. Questions about this notice can be sent to privacy@hawkeev.com.
Last updated July 2026.