Legal resources
Documents, policies & compliance
Everything in one place: our business terms, privacy and environmental policies, plus our security certifications, sub-processors and how to report a security issue.
Legal & policies
Business Terms & Conditions
The terms governing the supply of Mobilityways products and services.
Download PDF →Privacy Policy
How we collect, use and protect personal data across our products.
Read policy →Carbon Reduction Plan
The environmental policy and carbon reduction commitments for Mobilityways' own carbon footprint.
Download PDF →Website Terms of Use
The terms and of use for accessing Mobilityways.com and the content on it.
View →Compliance & certifications
Verification of our compliance against global standards, achieving certifications, attestations or audit reports.
ISO 27001:2022, certificate 249029
View certificateStatement of Applicability
Download PDFCyber Essentials
View digital certificateProcurement frameworks
Mobilityways is an approved supplier on a range of public-sector procurement frameworks and dynamic purchasing systems, making it quicker and more compliant for government, NHS and public bodies to buy our services. Skip lengthy tenders and procure Mobilityways through the framework that fits your organisation, with terms and due diligence already in place.
View our frameworksTrust & security
Mobilityways implements security controls and capabilities to ensure fit-for-purpose protections are applied where they’re needed most, and access is limited to only those that require it.
Security & Privacy White Paper
A comprehensive document detailing the measures and controls we use to protect Mobilityways and our customers’ data, and to comply with local and international laws, standards and regulations, all in one place.
Download white paperPolicies & processes include
- Access Control Policy
- Acceptable Use Policy
- Business Continuity Plan
- Clear Desk and Screen Policy
- Cryptographic Policy
- Password & MFA Policy
- Remote & Hybrid Working Policy
- Secure Engineering Principles
- Supplier Management Policy
- User Endpoint Device Policy
Please speak to your account manager to request further documents and evidence of our management systems, governance and compliance. Our policies, standards, procedures and guidelines are compliant with the ISO 27001:2022 information security standard.
Sub-processors
Mobilityways relies on various sub-processors to handle data on our behalf. These providers are carefully selected and regularly audited.
| Sub-processor | Type | Data storage location |
|---|---|---|
| Microsoft Azure | Cloud storage / CDN, managed app services, managed SQL database | London (UK South) & Cardiff (UK West) |
| Bird – Email (formerly SparkPost EU) | API service for queued email notifications | EU, Western Europe |
| API mapping and routing services | N/A, no data stored | |
| HubSpot | Member support ticketing system | EU – Germany |
| Brevo | Email campaign and marketing delivery services | EU – France |
Reporting & service status
Report a security issue
To report a vulnerability or suspected security issue, email report[at]mobilityways.com with as much detail as possible and we will respond as soon as possible.
Service status
See the operational status of the Mobilityways platform and other products and services at status.mobilityways.com.