myStreamSuiteTRUST CENTREClear controls. Honest claims.
Effective 11 August 2026How our ISO/IEC 27001 reference should be understood
Security controls designed with reference to ISO/IEC 27001:2022.
This means the architecture and operating controls have been designed with reference to the ISO/IEC 27001:2022 information-security framework. It is not a claim that myStreamSuite is ISO/IEC 27001 certified, audited by ISO, or independently assured.
What myStreamSuite processes
myStreamSuite processes account email addresses, customer and operational records, activity notes, vehicle and diagnostic references, and files supplied by authorised users so the service can operate. Access is isolated by organisation and workspace and controlled by assigned roles, applications and feature permissions.
Necessary storage
Authentication, security, fraud prevention and service-continuity storage are necessary for the service to operate safely. The current necessary-only mode does not disable those essential protections.
Privacy choices
Necessary storage remains enabled for sign-in, security and essential service operation. Optional analytics and marketing tracking are not enabled in this release.
- Necessary storage
- Required · activeAuthentication, security and service continuity.
- Optional analytics
- Not in use · offNo optional analytics beacon is loaded by the application.
- Marketing storage
- Not in use · offNo marketing tracking or campaign storage is loaded by the application.
Necessary-only mode is the current enforced state. No opt-out action is required.
If optional tracking is introduced in a future release, this page must provide an explicit choice before it is loaded. Authentication and security storage will remain separate and required.
Optional analytics and marketing
Optional analytics and marketing tracking are disabled in this release. The application source does not load a Cloudflare Insights beacon or another optional tracking script, and the response security policy blocks those external analytics origins. If optional services are introduced later, they must remain off until an explicit purpose-specific choice is implemented and recorded.
AI intelligence
When workspace AI is enabled, authorised records may be sent to the configured AI provider to create advisory summaries, searches, document extractions or photo labels. Provider storage is disabled by the application. AI results remain subject to workspace permissions and require human review for sensitive customer, financial, order, damage or completion decisions.
Authorised third-party data providers
Some optional search and enrichment features send business search terms or identifiers to contracted data providers so authorised users can review current public business-listing information. The service may retain a provider reference or normalised public business facts after user review to identify the selected listing and prevent duplicates. Provider-specific legal terms remain available in the service terms and to authorised administrators.
Security, access and retention
Short-lived login codes, revocable sessions, passkeys, rate limits, workspace permissions, server-side capability controls and audit records protect the service. Private files are served only after a current workspace and feature-access check. Records follow the organisation’s operational retention and lawful-recordkeeping requirements.
Access, correction and incidents
Requests to access or correct personal information, privacy concerns and suspected data incidents should be directed promptly to the organisation that provided your myStreamSuite access. The organisation remains responsible for its privacy notices, lawful collection and breach-response obligations.