Legal
Privacy Notice
How Fleetrion handles personal data and distinguishes controller and processor responsibilities.
Last updated 3 October 2026
1. Scope and who is responsible
This notice explains how personal data is handled in connection with the Fleetrion website, business relationships, accounts, support and the Service.
For website enquiries, business contacts, account administration, security and Fleetrion's own relationship records, Fleetrion—the provider identified in the applicable Customer Agreement—acts as controller. Privacy enquiries may be sent to flosi@fleetrion.com.
For personal data contained in Customer Data, the Customer normally determines the purposes and means of processing and acts as controller. Fleetrion acts as processor on the Customer's documented instructions and under the DPA. The Customer's privacy notice governs its own processing, and data subjects should normally direct requests about Customer Data to that Customer.
2. Personal data we handle
- Business and account data, such as name, business email, company, role, username and access status.
- Customer Data submitted to the Service, which may include vehicle and rental records, damage and repair cases, photographs and attachments, claims, financial or billing records, workflow notes and audit history.
- Technical and security data, such as IP address, device or browser information, session and authentication events, timestamps, logs and actions taken in the Service.
- Communications, support requests, meeting notes and other information a person chooses to provide.
3. Purposes and legal bases
Fleetrion uses controller data to respond to enquiries, establish and manage business relationships, administer accounts, provide support, operate and secure the Service, prevent misuse, maintain audit records and comply with law. Depending on the context, processing is based on steps taken before or performance of a contract, Fleetrion's legitimate interests in operating a secure business service, a legal obligation, or consent where specifically requested.
When Fleetrion acts as processor, the Customer determines the purposes and legal basis. Fleetrion processes Customer Data only to provide and secure the Service, support the Customer, follow documented instructions and meet applicable legal obligations.
4. Service providers, disclosure and transfers
Personal data may be shared with vetted providers that support hosting, storage, security, communications and customer support, subject to contractual confidentiality and data-protection duties. It may also be disclosed when required by law, to protect legal rights or security, or in connection with a corporate transaction subject to appropriate safeguards.
If personal data is transferred internationally, Fleetrion uses the transfer mechanism and safeguards required by applicable data-protection law. Applicable subprocessors and transfer terms for Customer Data are addressed in the DPA.
5. Retention
Customer Data is retained, returned and deleted in accordance with the Customer Agreement, the DPA and the Customer's documented instructions. Deletion may be delayed where data remains in protected backups or must be preserved for an active claim, legal hold, security need, accounting requirement or other legal obligation.
Business contact, account, support and security records are kept while needed for the relationship or stated purpose and afterwards only for as long as reasonably necessary to establish, exercise or defend legal claims, protect the Service and meet legal obligations. Fleetrion does not set a single retention period for all Customer Data.
6. Security
Fleetrion uses technical and organisational measures designed to protect personal data, including access controls, tenant separation, logging and safeguards for stored or transmitted data. No system is completely secure; suspected incidents should be reported promptly to the contact below.
7. Cookies and local storage
Fleetrion uses cookies and browser storage needed for authentication, session management, security and user preferences. If non-essential technologies are introduced, Fleetrion will provide appropriate information and a choice or obtain consent where required by law.
8. Individual rights
Subject to applicable law, individuals may have rights to access, correct or erase personal data, restrict or object to processing, receive portable data, withdraw consent and complain to a data-protection authority. Requests concerning Customer Data should normally be made to the relevant Customer as controller; Fleetrion will assist that Customer as required by the DPA. Other requests may be sent directly to Fleetrion.
9. Data Processing Agreement and contact
The DPA forms part of the Customer Agreement where Fleetrion processes personal data for a Customer. It addresses documented instructions, confidentiality, security, subprocessors, assistance, incidents, international transfers, audits and deletion or return of Customer Data. Customers may request the applicable DPA or ask privacy questions at flosi@fleetrion.com.
This notice may be updated as the Service, law or processing practices change. Material changes will be highlighted on this page or communicated to affected customers where appropriate.