1. Parties and roles
The business customer is the controller of its drivers', employees' and contractors' data. KP Solutions Krzysztof Piszczek, NIP 9261465949, is the processor (“Processor”). The customer declares that it is entitled to entrust the data for processing and provides users with the required information.
2. Subject matter, duration, nature and purpose
The Processor receives, records, organises, stores, links to accounts and vehicles, geocodes, analyses trip legs, displays, classifies according to authorised user actions, reports, backs up, diagnoses and deletes data to provide trip-register and fleet features. Processing runs from account activation until deletion or return of data after the service ends, allowing for the normal 14-day backup cycle.
3. Data subjects and data
Data subjects: customer administrators, drivers, employees and contractors using vehicles. Data: full name, business email, roles, assignments, vehicle and registration number, vehicle VAT profile, business or private classification, odometer readings, dates, times, purposes, routes, coordinates, stops, distances, speeds, notes, account identifiers and app-related technical logs. The service is not intended for deliberate submission of special categories of data under Article 9 GDPR or criminal-conviction data.
4. Documented instructions
The Processor acts only on documented instructions arising from the contract, account configuration, authorised user actions and customer requests, including for transfers. If law requires other processing, the Processor informs the customer before it begins, unless prohibited by law. The Processor promptly reports an instruction that infringes applicable rules and may suspend its execution.
5. Confidentiality and personnel
Access is limited to authorised persons as necessary for their duties and subject to statutory or contractual confidentiality. Permissions are granted by role, periodically reviewed and withdrawn when access is no longer needed.
6. Security
- HTTPS/TLS for transmission, password hashing and app tokens;
- authorisation by company, role and assignment, and organisation isolation in the portal and API;
- restricted administrative access, updates, event logging and diagnostics;
- daily database backups, weekly code backups, backup destination availability checks and 14-day retention;
- GPS point retention of up to 3 months relative to the vehicle's latest telemetry, immediate removal of points and addresses after approval as a private trip, and mobile log retention of up to 90 days;
- recovery and incident-response procedures and periodic assessment of security effectiveness.
Measures may evolve provided the overall level of protection is not reduced. The Processor considers the state of the art, costs, the nature of the data and risks to individuals.
7. Subprocessors
The customer gives general authorisation for subprocessors needed for the service. Current categories and providers handling entrusted data are: VPS infrastructure — OVHcloud; transactional email — SEOHOST; maps and geocoding — Geoapify. The backup repository remains under the Processor's control. 360 Księgowość and Paynow handle customer billing data and do not receive entrusted trip or GPS data.
The Processor notifies the administrator by email of a planned addition or replacement of a subprocessor at least 14 days before the change. During that time the customer may raise a reasoned data-protection objection. The parties seek a solution; if none is possible, the customer may terminate the part of the service requiring that subprocessor before the change. The subprocessor is bound by obligations providing no less protection than this agreement, and the Processor remains responsible for their performance under Article 28 GDPR.
8. Transfers
The Processor does not transfer entrusted data outside the EEA without a lawful mechanism and documented instruction. Before a transfer, it informs the customer of the recipient, country and basis and provides information on safeguards, unless law or security restricts disclosure.
9. Assistance to the customer
Taking account of the nature of processing and available information, the Processor assists with data-subject rights and obligations under Articles 32–36 GDPR, including risk assessment, breach notifications, impact assessments and consultations. A driver's request concerning entrusted data is forwarded to the customer unless the customer instructs otherwise.
The customer is responsible for lawful monitoring instructions, informing drivers, setting private-use rules and not using tracking beyond what is necessary for the stated purpose. Marking a trip as private and deleting its detailed location supports data minimisation but does not replace assessment of the legal basis or the customer's obligations.
10. Breaches
The Processor informs the customer of a confirmed breach of entrusted data without undue delay after becoming aware of it. As information becomes available, it provides the nature and scope, categories of people and data, possible consequences, measures taken or proposed, and an operational contact. Information may be provided in stages. Notification does not determine fault or whether the customer must notify an authority.
11. Termination, return and deletion
At the customer's choice, after the service ends the Processor provides the available data export in a commonly used format and deletes the data, or deletes them without prior export. Deletion instructions require secure confirmation. Active data are deleted without undue delay, and backups expire within 14 days at the latest. The deletion obligation does not cover data the Processor must retain by law as a separate controller.
12. Information and audits
The Processor provides information needed to demonstrate compliance. The customer may audit personally or through an independent auditor bound by confidentiality, generally no more than once a year and with at least 14 days' notice. These restrictions do not apply to a justified audit following a breach or at an authority's request. An audit must not disclose other customers' data or weaken security. Each party bears its own costs unless the audit reveals material non-compliance by the Processor.
13. Precedence and contact
For processing on behalf of the customer, this appendix takes precedence over conflicting service terms. In other matters, the service terms and GDPR apply. Instructions, questions, objections to subprocessors and reports should be sent to admin@kilometrowkavat.pl.