1. Controller and contact
The controller of data collected for registration, contact, entering into and performing the contract, payments, invoicing and service security is KP Solutions Krzysztof Piszczek, NIP 9261465949, ul. Winna Góra 5/2, 46-034 Pokój, email: admin@kilometrowkavat.pl. No data protection officer has been appointed; this address may be used for all enquiries.
The customer company is generally the controller of its drivers', employees', trip, location and vehicle-use data. The provider's role as processor is described in the Data Processing Agreement. Drivers should receive a separate privacy notice from their company.
2. Data categories and sources
- customer and administrator details: buyer type, business or personal name, company NIP, address, email and optional telephone number;
- account data: identifier, password hash, role, assignments, app token, sign-ins and consents or declarations made during registration;
- vehicle and register data: name, registration number, odometer, driver, time, purpose, route, distance, notes, historical 100% or 50% VAT deduction profile, business or private classification, person classifying the trip and classification time;
- telemetry: GPS points, start, stop and end locations, moving time, distance, average and maximum speed, and vehicle connection events;
- technical data: a hash of the IP address at registration, device, app version, synchronisation, Bluetooth and location diagnostics, and errors;
- at registration: Google reCAPTCHA token and verification result, and technical data processed by Google to distinguish users from bots;
- after consent to public-site analytics: Analytics client identifier, pages visited, referral source, approximate location, browser and device information, selected plan and billing cycle, and, for purchases, an anonymous transaction identifier, net amount, VAT and currency;
- when the Features page is opened: technical data sent by the browser to the embedded YouTube player, in particular the IP address, device and browser information, page address and player interactions;
- correspondence: contact or Enterprise form submissions and support history;
- billing: plan, limits, cycle, price-list version, period, pro formas, invoices, amounts, VAT, payment status and identifier, and 360 Księgowość and KSeF identifiers where applicable.
Data come from the user, customer, app and device; payment data also come from Paynow or bank transfer confirmation. Invoice data may be returned by 360 Księgowość and KSeF. Company verification with the Polish statistical office, GUS, is disabled.
3. Purposes, legal bases and legitimate interests
- account creation, the Try it plan, entering into and performing the contract, support and payment — Article 6(1)(b) GDPR;
- invoices, KSeF, taxes and accounting — Article 6(1)(c) GDPR;
- security, fraud prevention, diagnostics, evidence of acceptance of terms, complaints and claims — Article 6(1)(f) GDPR; the interest is secure service provision and defence of rights;
- protecting registration with Google reCAPTCHA — Article 6(1)(f) GDPR; the interest is preventing automated registrations, abuse and excessive load on the service;
- contact and Enterprise forms — Article 6(1)(b) GDPR for offer enquiries, or (f) for general correspondence;
- electronic marketing — only after obtaining the separate consent required by law; registration does not subscribe users to a newsletter;
- measuring public-site use through Google Analytics — Article 6(1)(a) GDPR, only after voluntary consent, which may be withdrawn at any time;
- driver data and telemetry — the customer company determines the legal basis, and the provider acts on its documented instructions.
Under a mixed-use profile, the administrator or authorised driver may mark a record as private. Until approval, it remains a draft and may contain GPS points and identified addresses. Approval as private deletes those details from the active database; only data needed for odometer continuity and vehicle-use accounting remain. If location should not be collected even before approval, the user should pause monitoring before a private trip.
4. Recipients and their roles
Data may be received by authorised persons and suppliers necessary for the service: OVHcloud (hosting), SEOHOST (email), Geoapify (maps and geocoding), 360 Księgowość (invoicing), Paynow by mElements S.A. (payments), Google Ireland Limited (Google Analytics, only with consent, and YouTube on the Features page , as well as Google reCAPTCHA at registration ), banks, technical support and backup providers. The scope is limited to the relevant function.
Paynow acts under its own payment-operator obligations and receives, among other things, the payment identifier, amount, currency, description and payer's email, but not trips or GPS data. 360 Księgowość receives buyer and document data. Geoapify receives coordinates or text needed for maps and geocoding. Data may be disclosed to authorities when required by law.
Google Analytics receives public-site usage data only after consent. E-commerce measurement covers price-list views, plan selection, checkout initiation and purchases confirmed by the payment system. For a purchase, we send the plan and cycle name, net amount, VAT, PLN and a random technical identifier containing neither the pro forma number nor customer details. We do not send names, email addresses, NIP numbers, form data, vehicles, trips or GPS data. Advertising features and Google sign-in remain inactive.
The YouTube player on the Features page is embedded from youtube-nocookie.com in privacy-enhanced mode and loads with the page. Technical transmission is described in detail in the cookies notice.
Google reCAPTCHA v3 loads only on the registration page to protect the form from bots. It works without a checkbox and returns a risk score. For this purpose, Google may receive technical information about the browser, device, IP address and interactions. The server sends Google the response token for verification, but not the registration form fields. Use of reCAPTCHA is also subject to Google's privacy policy and terms.
5. Retention periods
- account and operational data — for the contract and restricted-access period, and then until account deletion or expiry of the applicable claim period;
- detailed GPS points for business and unclassified trips — up to 3 months back from the vehicle's latest telemetry record; points and identified addresses of a trip approved as private are deleted immediately after approval; odometer values and distance remain in the register;
- mobile diagnostic logs on the server — up to 90 days; local logs can be deleted in the app;
- database backups — 14 days; deleted data are not restored to the active service;
- invoices, KSeF data and the minimal accounting trail — for the period required by tax and accounting law, generally until the liability limitation period expires, allowing for suspension or interruption;
- evidence of the contract and payments, complaints and correspondence — until the end of the relevant period for pursuing or defending claims;
- security data — for incident analysis and the time needed to defend claims;
- Google Analytics — cookies normally for up to 2 years; user-level and event-level data according to the Analytics retention setting, which may be 2 or 14 months for a standard property.
- reCAPTCHA token — used directly for a single verification and not stored in the service database; technical data held by Google are subject to Google's retention rules.
Account deletion requires a signed email link and final confirmation. Email scanners do not trigger deletion. Accounting data required by law are separated from the active account.
6. Your rights
Depending on the legal basis, you have rights of access, a copy, rectification, erasure, restriction, portability, objection and withdrawal of consent without affecting earlier processing. Requests may be sent to admin@kilometrowkavat.pl. The applicant's identity may be verified as necessary to protect data.
You may complain to the President of the Polish Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warszawa, uodo.gov.pl. For data processed on behalf of a company, the driver should first contact the company that assigned their account; the provider assists that company in fulfilling the request.
7. Required data
Data marked as required are necessary for the relevant action. Businesses provide a NIP; private individuals do not. Missing data prevent registration, payment or contact. Bluetooth and location permissions are voluntary, but without them automatic recording is unavailable and manual recording may be necessary.
8. Automation
The system automatically detects legs, stops, returns, addresses and trip metrics. The result is a draft for an authorised person to review. Business or private classification is not assigned solely automatically. The administrator resolves conflicts between two drivers. We do not make decisions producing legal effects for individuals solely by automated means or profile them for marketing.
9. Transfers outside the EEA
The core infrastructure is hosted in the European Economic Area. For Google services, including Google Analytics and YouTube, data may be processed using Google infrastructure or entities outside the EEA under the conditions and safeguards described by Google, in particular an appropriate mechanism under Chapter V GDPR. Users may request an up-to-date list of suppliers and safeguards.
10. Security
Measures include HTTPS, password hashing, roles and assignments, company isolation in the portal and API, app tokens, limited administrative permissions, backups, updates and diagnostics. Measures are periodically assessed in proportion to risk; details that could facilitate bypassing security are not published.