Getting started

Security and data protection

Data control in practical terms: hosting in Germany, role-based access, retention periods, data processing on behalf of customers, subprocessors and data exports.

Why it matters

Fleet data can also be personal data

Trips, driving licences and fine cases relate to people. Anyone collecting that data must be able to explain where it is held and when it is deleted.

Today

Scattered across four systems

The driver list sits in a folder, receipts in an inbox and deadlines in a spreadsheet on one computer. No one has a reliable view of who can access what.

The result

A data request becomes a search exercise

When a driver asks what data is held about them, the hunt begins. Information that first has to be found is not readily accessible.

The standard

One place, one rule

Every entry is linked to a vehicle and a role, with a defined purpose and a retention period.

Legal basis

Three commitments you can rely on

No wall of certificates. Just controls you can verify in day-to-day operations.

Operated in the Frankfurt data centre

The database and files are held in the Frankfurt (EU) data centre. Where third-party services are required, we name them below.

Roles instead of blanket access

Fleet management, leadership and accounting use the same vehicle record but do not see the same fields. Access follows each person's responsibilities.

Retention periods instead of indefinite storage

Data is deleted once it has served its purpose rather than being kept indefinitely. The next section gives an example.

A tidy service hall at night, with a white van and grey car in a pool of light

Security

Only what you can verify.

No wall of certificates. Trips, driving licences and fine cases relate to people, so anyone collecting them must say when the data will be deleted.

3 commitments verifiable 3 years default period
Service providers we use

Illustrative image — not a real customer job

An example, not a blanket promise

Three years by default

Anyone who drives a pool vehicle appears in its usage history. Every driver change is timestamped. By default, the driver assignment is deleted three years after the usage period ends, unless a fine case is still open. The period can be configured.

Proof

Evidence is never guessed

If someone asks who drove a vehicle at a particular time and there is no matching entry, the answer is ‘Pool, unknown’, not ‘probably’. Guesswork helps neither you nor the driver.

Other parties with access

Every third-party provider is named

Modern platforms rely on third parties. What matters is naming them clearly.

Data processing agreement

You remain the controller

Your company remains the controller and we process data on your behalf. The processing agreement establishes that relationship from the outset.

On-site service partners

Only the assigned job

A service partner sees the vehicle, location and time window for their job, but not your costs, drivers or the rest of your fleet.

Next step

Test it with your own fleet

Data protection is proven in the workflow, starting with the first vehicle you add.

How onboarding works

Import the fleet, assign roles and create the first job. Four steps over two weeks. See onboarding and rollout

What falls through the gaps without a system

Calculate the cost of managing a fleet manually. What does doing nothing cost?

Your fleet. Handled.Start with a vehicle.

Build your fleet record

Control and evidence

Limit access, trace changes and take your data with you.

Security does not end at login: scope rules are enforced server-side, evidence carries a checksum and exports remain available.

Audit log

Relevant administration changes remain traceable with time and acting person.

Scoped permissions

Users see only vehicles and activity within their organisational scope.

SHA-256 checksums

Evidence can be verified against its stored checksum.

Data export

Company data can be provided in the available export formats.

Subprocessors

The current list of service providers is documented publicly.