Privacy Notice
What personal data we handle, why, who else sees it, and what you can ask us to do about it — including if you are a driver whose employer chose Truckzly.
In effect from
Contents
- 1. Two different roles — read this part first
- 2. Who we are
- 3. If you are a driver, employee or contact of an operator
- 4. What we handle as controller, and why
- 5. Cookies
- 6. Who we share it with
- 7. Where data is held, and transfers abroad
- 8. How long we keep it
- 9. How it is protected
- 10. Your rights
- 11. Changes to this notice
1. Two different roles — read this part first
Truckzly handles personal data in two quite different capacities, and almost everything else on this page depends on which one applies to you.
As a controller. For the people we deal with directly — someone who signs up, an administrator we invite, a person who emails us, a billing contact — we decide why and how their data is used. This notice describes that.
As a processor. For the data an operator puts into Truckzly about its own business — its drivers, its vehicles, its customers, its documents — the operator decides why and how, and we act on its instructions. We do not decide what happens to that data. If you are a driver, that is the part that concerns you — see If you are a driver, employee or contact of an operator.
Our processing on behalf of customers is governed by our Data Processing Agreement.
2. Who we are
Truckzly Solutions SRL, a company registered in Romania, VAT number RO52281367, is the controller for the processing described under What we handle as controller, and why.
For any question about this notice, or to exercise a right, write to contact@truckzly.com.
3. If you are a driver, employee or contact of an operator
Most people whose data passes through Truckzly never chose it. You work for a haulier, your employer bought the system, and it now holds your name, your driver card data, your driving and rest hours, and the position of the vehicle you are in. You are entitled to a straight explanation of that.
Your employer decides all of it. They chose to collect it, they decide how long to keep it and who inside the company can see it, and the law makes them responsible for telling you about it and for having a lawful basis to do it. In data protection terms they are the controller and we are their processor.
What this means in practice. If you want to see your data, correct it, object to it, or have it deleted, ask your employer — they hold those decisions, and we are not permitted to act on such a request from you directly without their instruction. If you contact us anyway, we will not ignore you: we will tell you who the controller is and pass your request to them without undue delay.
What we do not do with it. We do not use your data for our own purposes. We do not sell it, we do not use it for advertising, we do not use it to train artificial intelligence models, and we do not share it between different operators. Access inside Truckzly is restricted to the operator you work for.
You can complain to a supervisory authority at any time — see Your rights.
4. What we handle as controller, and why
Account and identity data — name, work email address, the organisation you belong to, your role, sign-in credentials in hashed form, multi-factor settings, and sign-in and session records. Used to create and secure accounts and to give the right people the right access. Lawful basis: performance of the contract, and our legitimate interest in keeping accounts secure.
Billing data— billing contact and email address, subscription and plan, invoices, and usage measured against your allowances. Card details are entered on our payment provider's own pages and never reach us. Used to charge for the service and to meet accounting and tax obligations. Lawful basis: performance of the contract, and legal obligation.
Support and correspondence — what you write to us and what we write back. Used to answer you and to keep a record of what was agreed. Lawful basis: performance of the contract, and our legitimate interest in running a support function.
Security and audit records— sign-in attempts, privileged actions, and technical logs. Used to detect and investigate abuse and to keep the service secure. Lawful basis: our legitimate interest in the security of the service and our customers' data.
This website. It sets no cookies, runs no analytics and carries no tracking of any kind. We do not know who visits it.
7. Where data is held, and transfers abroad
The service runs in the European Union: the database holding your records and the applications you use are hosted in the EU.
Some of the providers we use are established in the United States — in particular for transactional email, part of the mapping stack, push notification delivery and artificial intelligence inference. Those transfers rely on the European Commission's Standard Contractual Clauses, or on a provider's certification under the EU–US Data Privacy Framework where it holds one, together with additional technical and organisational measures. Details are available on request.
8. How long we keep it
We keep personal data for as long as it is needed for the purpose it was collected for, and then delete it.
- Account data — for as long as the account exists. After an account is closed we retain it for a limited period so it can be exported or reactivated, then delete it.
- Billing records — for the period Romanian accounting and tax law requires, which is longer than the account itself.
- Security and audit records — for a limited period appropriate to investigating incidents.
- Customer data we hold as processor — for as long as the customer instructs. Operators have their own statutory retention duties, particularly for tachograph records, and we will not delete data out from under those obligations without instruction.
Deleted data is removed from backups as those backups age out on their normal cycle.
9. How it is protected
Authorisation is enforced in the database itself rather than only in the interface, so a request for data an account is not entitled to returns nothing regardless of what the application asks for. Each organisation's data is isolated from every other organisation's.
Data is encrypted in transit. Access to production systems is restricted to the people who need it. Multi-factor authentication is available and we recommend it. Privileged actions are written to an audit record that cannot be edited afterwards.
We do not hold ISO 27001, SOC 2 or any comparable certification, and we would rather say so than imply otherwise.
If a personal data breach occurs, we will notify the supervisory authority and affected customers as the GDPR requires. Where we act as processor, we notify the customer without undue delay so that they can meet their own obligations.
10. Your rights
Where we are the controller, you have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we relied on it.
Write to contact@truckzly.com. We will respond within one month, and tell you if we need longer because the request is complex. There is no charge. We may need to verify who you are before acting.
Where we act as a processor for an operator — which includes almost everything about drivers — the request has to go to that operator. SeeIf you are a driver, employee or contact of an operator.
We do not make automated decisions that produce legal or similarly significant effects about individuals.
If you are unhappy with how we have handled your data you can complain to a supervisory authority. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP). You may also complain to the authority where you live or work.
11. Changes to this notice
We update this notice when what we do changes. The date at the top always shows the version in force. Where a change materially affects you, we will tell account administrators by email rather than relying on you noticing.