Privacy protection
Privacy Policy
Effective date: 1 September 2026.
I. INTRODUCTORY PROVISIONS
Article 1 – Subject Matter of the Privacy Policy
(1) In this Privacy Policy, ALFA LOGISTIKA d.o.o., Andrije Hebranga 16, 47000 Karlovac, OIB: 02706843298 (Company) explains how it processes personal data when acting as a Controller.
(2) This Privacy Policy applies in particular to the processing of personal data in connection with the Websites, enquiries, offers, agreements, user accounts, business communications, support, billing, security, use of the System, mobile applications, integrations, API access, OEM data services and other related services of the Company.
(3) Where the Company processes personal data on behalf of a Customer as a Processor, such processing is governed by the Agreement, the General Terms, the SLA, the Data Processing Addendum and other Applicable Documents.
(4) This Privacy Policy does not replace notices, internal acts, policies, assessments and other documents which the Customer is required to provide to its employees, drivers, vehicle users, application users and other persons whose data it processes through the Service.
Article 2 – Definitions
(1) Terms defined in the General Terms, the SLA, the Data Processing Addendum and other Applicable Documents shall have the same meaning in this Privacy Policy, to the extent applicable.
(2) For the purposes of this Privacy Policy:
a) Personal Data means any information relating to an identified or identifiable natural person;
b) Data Subject means a natural person to whom Personal Data relates;
c) User means a person who uses the Websites, the System, an application, a user account, support, a communication channel or another service of the Company;
d) Customer means a business user, consumer or other person who enters into or uses an Agreement, Offer, Service or other contractual relationship with the Company;
e) Controller means a person who determines the purposes and means of processing Personal Data;
f) Processor means a person who processes Personal Data on behalf of a Controller;
g) General Data Protection Regulation means Regulation (EU) 2016/679, also known as GDPR;
h) Applicable Data Protection Laws means the General Data Protection Regulation, the Act Implementing the General Data Protection Regulation and other regulations applicable to the specific processing;
i) Websites, for the purposes of this Privacy Policy, means the public websites and related product websites of the Company on the domains alfaiot.eu, alfalogistika.hr, gps-cloud.com, si.gps-cloud.com, tacho-cloud.com and gps-marine.com, as well as other websites operated by the Company if a link to this Privacy Policy is published on them or it is otherwise clearly stated that this Privacy Policy applies to them.
Article 3 – Roles of the Company
(1) The Company acts as a Controller where it processes personal data for its own purposes, in particular for the preparation and conclusion of agreements, provision of its own services, administration of user accounts, communication, support, billing, accounting, tax and statutory obligations, security, prevention of misuse, protection of legal claims, management of the Websites and its own business operations.
(2) The Company acts as a Processor where it processes personal data on behalf of a Customer, in particular where the Customer, through the System, monitors, enters, analyses, transfers or processes data concerning its employees, drivers, vehicle users, application users, objects, vehicles, vessels, machinery, location, telemetry, tachograph, sensors, API access, integrations or OEM data services.
(3) The Customer is responsible for the lawfulness of processing which it carries out as a Controller, including the legal basis, purpose, scope, provision of information to Data Subjects, internal acts, employment relationships, exercise of Data Subjects’ rights and relationships with third parties to whom it grants access to data.
(4) If a particular processing operation requires a different role of the Company, for example that of an independent controller, joint controller or a special processing regime, such processing shall be governed by a separate document, notice or contractual relationship.
II. WHAT DATA WE PROCESS
Article 4 – Data You Provide to Us
(1) When you contact us, request an Offer, enter into an Agreement, use the Service, open a user account, request support, order Equipment or communicate with us, we may process:
a) first name and surname;
b) company or trade name, business function, department and authority;
c) email address, telephone number and other contact details;
d) delivery address, billing address and billing details;
e) data from an Offer, Agreement, Order, invoice, payment, work order, support request or other business documentation;
f) the content of messages, enquiries, complaints, requests, attachments and other communications you provide to us.
(2) If Personal Data is provided to us by a person acting not on their own behalf, but on behalf of a Customer or another legal person, that person confirms that they are authorised to provide the data and that the persons to whom the data relates have been informed to the necessary extent.
Article 5 – Data Generated Through Use of the System and Service
(1) Depending on the agreed Service, System configuration and manner of use, the following may be processed:
a) user data, including username, user ID, role, permissions, log-ins, log-outs, settings and activities in the System;
b) data on Equipment and objects, including the object name in the System, registration number, VIN, IMEI, serial number, SIM/eSIM identifier, model, status, configuration and technical parameters;
c) location, telemetry, sensor and technical data;
d) tachograph data, driver activity, DDD files and other data where such a Service has been agreed;
e) data related to support, the RMA procedure, service, self-activation, self-installation, diagnostics, security requests and audit trail;
f) data related to API access, integrations, exports, imports, OEM data services and authorised data recipients;
g) technical and security logs, including IP address, browser, device, time of access, security events, errors, system logs and other data necessary for the security, stability and demonstrable provision of the Service.
(2) Where the data referred to in paragraph (1) of this Article relates to drivers, employees, vehicle users, application users or other persons of the Customer, the Company generally processes it as a Processor in accordance with the Customer’s instructions, unless the Company has a separate role or legal basis for a particular processing operation.
Article 6 – Data From Websites and Communication Channels
(1) When you visit the Websites or use the Company’s electronic channels, we may process technical data such as IP address, device type, browser, operating system, time of visit, pages viewed, source of visit, error logs, security logs and other data necessary for the operation, security and improvement of the Websites.
(2) If we use cookies or similar technologies, information about the types of cookies, purposes and management options is provided through the Cookie Policy, cookie settings or another appropriate notice on the Websites.
(3) If you complete a form through the Websites, submit an enquiry, subscribe to notifications or request contact, we process the data you enter and the technical data necessary for the secure processing of such request.
Article 7 – Data From Other Sources
(1) We may obtain Personal Data from Customers, System users, authorised persons of Customers, business partners, integration partners, publicly available business sources, registers, competent authorities, data service providers, equipment manufacturers or other persons where this is connected with the Service, a contractual relationship, a statutory obligation or a legitimate business interest.
(2) Where the Company, as Controller, has not obtained data directly from the Data Subject, it shall provide the prescribed information, including the source and categories of data, within a reasonable period, at the latest within one month of obtaining it, or at the latest upon the first communication with the Data Subject or first disclosure to another recipient, if this occurs earlier. Exceptions shall apply only under the conditions set out in Article 14 of the General Data Protection Regulation. Where the Company acts as a Processor, the Data Processing Addendum shall apply.
III. PURPOSES AND LEGAL BASES FOR PROCESSING
Article 8 – Purposes of Processing Where the Company Acts as Controller
(1) The Company may process Personal Data as a Controller for the following purposes:
a) responding to enquiries and communicating with users, prospective users, business partners and other persons;
b) preparing Offers, concluding, performing, amending and terminating Agreements;
c) opening, administering, securing and supporting user accounts;
d) providing the Service to the extent that the Company itself determines the purpose and means of processing;
e) issuing invoices, billing, accounting, tax and other statutory obligations;
f) delivery of Equipment, organisation of technical interventions, service, RMA, support and maintenance of an audit trail;
g) security of the System, Websites, user accounts, infrastructure, Communication Resources and business operations;
h) prevention of misuse, fraud, unauthorised access, technical incidents and security risks;
i) development, maintenance, testing, improvement and analysis of the Service to the extent that processing is lawful and proportionate;
j) sending service, security, administrative and contractual notifications;
k) business communications and direct marketing to the permitted extent;
l) protection of the Company’s rights, claims, property, trade secrets and legal interests;
m) responding to requests from courts, competent authorities, regulators, police, tax authorities and other authorised persons.
Article 9 – Legal Bases for Processing
(1) The Company processes Personal Data only where an appropriate legal basis exists.
(2) Legal bases may include:
a) performance of a contract to which the Data Subject is a party or taking steps at their request before entering into such a contract; for data concerning employees or representatives of a contracting party, another appropriate basis shall apply, for example a legitimate interest in necessary business communication;
b) a statutory obligation, where processing is necessary for accounting, taxation, business records, responding to competent authorities, data protection, electronic communications or other regulations;
c) a legitimate interest of the Company or a third party, where processing is necessary, proportionate and expected, for example for security, prevention of misuse, protection of legal claims, business communication, an existing relationship with a user, improvement of the Service or permitted direct marketing;
d) consent, where processing is voluntary and not necessary for a contract, statutory obligation or legitimate interest, for example for certain marketing notifications, a newsletter, non-essential cookies or other additional processing;
e) protection of vital interests or performance of a task carried out in the public interest only where such basis is applicable in exceptional circumstances.
(3) If processing is based on consent, the Data Subject may withdraw consent at any time. Withdrawal of consent shall not affect the lawfulness of processing carried out before its withdrawal.
(4) If processing is based on a legitimate interest, the Data Subject has the right to object in accordance with this Privacy Policy and Applicable Data Protection Laws.
Article 10 – Processing on Behalf of the Customer
(1) Where the Company acts as a Processor, the Customer, as Controller, determines the purpose and legal basis for processing.
(2) In that case, the Company processes Personal Data in accordance with the Customer’s Documented Instructions, the Agreement, the General Terms, the SLA, the Data Processing Addendum and Applicable Documents.
(3) If you are a driver, employee, vehicle user, application user or other person whose data the Customer processes through the System, you should generally contact the Customer as Controller with questions regarding the legal basis, purpose of monitoring, internal rules, employment-law basis, notices and use of data.
(4) If you submit a request to the Company and it follows from the request that it concerns processing carried out by the Company on behalf of the Customer, the Company may forward the request to the Customer or refer you to the Customer, unless regulations require otherwise.
Article 11 – Profiling and Automated Decision-Making
(1) The System may enable analytical functionalities, reports, rankings, alerts, driving indicators, telemetry analyses, display of deviations, zone rules, alarms and similar functionalities.
(2) Where such functionalities are used in relation to drivers, employees or other persons of the Customer, the Customer determines the purpose of use, legal basis, consequences, rules of interpretation and manner of informing Data Subjects.
(3) The Company does not make automated decisions producing legal or similarly significant effects for the Data Subject within the meaning of the General Data Protection Regulation, unless such processing is expressly described in a separate notice or document.
Article 12 – Business Communications and Marketing
(1) The Company may process business contact details for the purpose of communicating with existing and prospective Business Users, responding to enquiries, sending information about the Service, service notifications, security notifications, changes to Legal Documentation and other notifications connected with a contractual or business relationship. Service, security, administrative and contractual notifications are not marketing messages where they are necessary for entering into or performing a business relationship, security or compliance with a statutory obligation.
(2) The Company directs newsletters and other promotional email messages at the market of Business Users, namely legal persons and other Business Users at their business contact addresses, to the extent permitted by Applicable Laws and where the content is connected with their activity, business interest or reasonably expected need for the Company’s Services.
(3) The Company does not direct newsletters or other promotional email messages to Consumers. If the Company establishes that a Consumer has mistakenly been included in a marketing record intended for Business Users, it shall remove that Consumer from active marketing distribution, without prejudice to the sending of necessary service, security, administrative or contractual notifications on another appropriate basis.
(4) Where a business email address or other business contact detail identifies a natural person acting for a Business User, the Company processes it only to a proportionate and expected business extent. A legitimate interest in processing a business contact detail does not replace consent where consent is required for sending a marketing message under electronic communications regulations.
(5) Direct marketing by email shall be carried out only where an appropriate legal basis and permission exist under Applicable Laws, including consent, permitted communication with an existing user concerning the Company’s own similar Services, or another lawful basis. The Company shall thereby limit itself to business addresses, business functions and contacts connected with an activity or possible business need for the Service.
(6) Every marketing message must clearly identify the sender, must not conceal the identity of the Company and must contain a simple, free and effective option to unsubscribe by replying to the message or through a link for permanent unsubscribe.
(7) Any person may request at any time to stop receiving marketing notifications. Following an objection or unsubscribe, the Company shall cease using the contact for direct marketing and record a permanent unsubscribe so that the contact is not included again without a new demonstrable request, except to the extent that minimum processing is necessary to maintain the unsubscribe record, prevent repeat sending, comply with a statutory obligation or fulfil another permitted purpose.
IV. RETENTION, RECIPIENTS AND SECURITY
Article 13 – Retention Periods
(1) We retain Personal Data only for as long as necessary for the purpose of processing, performance of contractual and statutory obligations, security, billing, evidence, protection of legal claims or another lawful reason. Upon expiry of the applicable period, we delete or anonymise the data, unless another valid legal basis exists for further retention.
(2) Where the Company acts as Controller, the following general criteria apply:
a) data connected with enquiries and Offers which did not lead to the conclusion of an Agreement shall be retained for three years from the last material communication;
b) data connected with an Agreement, Service, user account, support, billing and delivery shall be retained for the duration of the contractual relationship and for five years after its termination, except for data subject to a longer statutory or agreed period;
c) invoices and accounting records shall be retained for at least eleven years, calculated from the last day of the financial year to which they relate, or longer if an Applicable Law requires a longer period;
d) technical, access and security logs shall be retained for twelve months from their creation, unless they are connected with a security incident, misuse, dispute, legal claim or request from a competent authority;
e) data processed on the basis of consent for marketing email shall be retained until consent is withdrawn or the purpose ceases, and minimum evidence of consent or another demonstrable request shall be retained for five years after withdrawal or cessation of use, unless another legal basis exists for further retention;
f) business contact details for marketing where there is no active business relationship shall be retained for two years from the last documented interest or material communication, or until an earlier objection or unsubscribe;
g) following a permanent unsubscribe, only the minimum record necessary to prevent repeat marketing communications shall be retained while the Company carries out marketing or until the contact demonstrably requests inclusion again;
h) data and documentation connected with an incident, misuse, debt, objection, dispute, legal claim or proceedings of a competent authority may be retained until the final conclusion of the proceedings, collection or protection of rights and expiry of the applicable periods.
(3) Where the Company acts as a Processor, the retention period is governed by the Agreement, the SLA, the Data Processing Addendum, the Customer’s instructions and the technical capabilities of the System. Unless expressly agreed otherwise, the ordinary availability of historical telemetry and location data generated in IoT and telematics systems shall last for 12 months from its creation. This period does not apply to the Company’s contractual, accounting, billing, marketing, security or other business records.
(3a) Downloaded original DDD files from tachographs and driver cards shall be stored in the archive of the agreed Service for the period determined by the agreed package, with a minimum of 12 months where European Union tachograph regulations apply to the Customer. The Customer, as Controller, is responsible for determining whether a longer period applies to its operations and for timely exporting and retaining the data necessary to comply with its statutory obligations. Available original DDD files and reports shall be exported through the functionality of the System, in supported formats and time intervals.
(4) Backups, replications, technical logs and other internal technical mechanisms shall not be deemed a customer archive or a separate data retention service for the Customer.
Article 14 – Recipients and Categories of Recipients
(1) Personal Data may be available to persons who require access for a lawful processing purpose, including employees, associates, providers of hosting, cloud computing, telecommunications services, SIM/eSIM resources, data centres, security tools, email, business applications, support, accounting, billing, delivery, service, development, integrations, OEM data services, legal and other professional services.
(2) Personal Data may also be provided to the Customer, users authorised by the Customer, integration partners, Authorised Data Recipients, data service providers, equipment manufacturers or other third parties where this is necessary for the Service, where requested or enabled by the Customer, where a contractual or statutory basis exists, or where necessary for the protection of rights and security.
(3) The Company does not sell Personal Data to third parties.
(4) In this Privacy Policy, the Company publicly states categories of recipients rather than a detailed list of actual suppliers, technical partners and their infrastructure. The identity of an actual recipient of Personal Data shall be provided only where necessary for the exercise of the Data Subject’s rights, a request by a competent authority or another obligation under Applicable Laws, to the necessary extent and while protecting the rights of other persons, the security of the System and confidential information.
Article 15 – Transfers Outside the European Economic Area
(1) Personal Data may be transferred outside the European Economic Area only where an appropriate legal basis and safeguard mechanism exist under Applicable Data Protection Laws.
(2) Such mechanisms may include an adequacy decision, standard contractual clauses, supplementary safeguards, an exemption permitted by law or another lawful transfer mechanism.
(3) Information about the applicable transfer mechanism and how to obtain a copy of the appropriate safeguards may be requested through the contact details in Article 22 of this Privacy Policy. The Company may protect or redact parts not necessary for the exercise of the Data Subject’s rights, in particular prices, commercial terms, technical architecture, security details, Personal Data of other persons and other confidential information, but shall not withhold information which it is required to provide under Applicable Laws.
Article 16 – Security of Personal Data
(1) The Company implements appropriate technical and organisational measures to protect Personal Data against unauthorised access, loss, destruction, alteration, disclosure, misuse or other improper processing.
(2) Measures may include access management, authentication, role-based permissions, security logs, restricted access for employees and associates, infrastructure protection, backups, availability monitoring, incident handling, verification of authority for security-sensitive requests and other measures appropriate to the nature of processing and the risk.
(3) The Company does not disclose security details where their disclosure could compromise the System, other users, data security, trade secrets or obligations to third parties.
V. RIGHTS OF DATA SUBJECTS
Article 17 – Your Rights
(1) Subject to the conditions laid down by Applicable Data Protection Laws, a Data Subject may have the right to:
a) obtain confirmation as to whether their Personal Data is being processed;
b) access Personal Data;
c) request rectification of inaccurate data or completion of incomplete data;
d) request erasure of data;
e) request restriction of processing;
f) request data portability;
g) object to processing based on a legitimate interest or processing for direct marketing purposes;
h) withdraw consent where processing is based on consent;
i) lodge a complaint with a supervisory authority.
(2) Data Subject rights are not absolute and may be restricted only where a permitted legal basis exists and to the necessary and proportionate extent in order to protect the rights of other persons, trade secrets, the security of the System, a legal claim, a statutory obligation or another protected interest. A trade secret or security reason alone is not a basis for completely refusing a request if the right can be exercised through partial access, redaction of confidential parts or another proportionate measure.
Article 18 – How You Exercise Your Rights
(1) You may send a request to exercise your rights to the contact details in Article 22 of this Privacy Policy.
(2) If there are reasonable doubts as to the identity of the applicant, we may request only additional information necessary to confirm it. Where a request is submitted by a representative, we shall verify their authority. Where necessary, we may request clarification of the scope of the request, without unjustifiably hindering the exercise of rights.
(3) We shall inform the Data Subject of action taken on a request without undue delay and at the latest within one month of receipt of the request. Due to the complexity or number of requests, this period may be extended by a further two months; we shall inform the Data Subject of the extension and the reasons for it within the first month. If we do not act on the request, we shall state within the same initial period the reasons and the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
(4) Exercise of rights is free of charge. Only where a request is manifestly unfounded or excessive, in particular because of its repetitive nature, may the Company charge a reasonable fee taking account of administrative costs or refuse to act on the request. The Company must demonstrate that the request is manifestly unfounded or excessive; repetition of a request alone is insufficient.
Article 19 – Requests Concerning Customer Data
(1) If your request concerns data which the Company processes on behalf of a Customer as a Processor, the Company is generally not authorised to decide on the request independently, but shall refer you to the Customer or forward the request to the Customer, unless regulations require otherwise.
(2) This applies in particular to requests from drivers, employees, vehicle users, application users and other persons whose data the Customer processes through the System for fleet management, work organisation, security, records, tachographs, telemetry, reports, integrations or other purposes of its own.
VI. SPECIAL NOTES
Article 20 – Children and Special Categories of Data
(1) The Company’s Services are not intended for children.
(2) The Services are not intended for the processing of special categories of personal data, data relating to criminal convictions and offences or other particularly sensitive data, unless such processing is expressly agreed, lawful, necessary and governed by an appropriate document.
(3) If the Customer enters or enables the processing of such data without an appropriate legal basis and agreement, it shall be responsible for the lawfulness and consequences of such processing.
Article 21 – Changes to the Privacy Policy
(1) The Company may amend this Privacy Policy in order to comply with regulations, changes to the Service, security requirements, organisational changes, changes to the Websites, technological changes or another justified reason.
(2) The current Privacy Policy shall be published on the Websites.
(3) If a separate notice is required by law or by the nature of the change, the Company shall provide it in an appropriate manner.
Article 22 – Contact
(1) For questions concerning this Privacy Policy, the processing of personal data or the exercise of rights, you may contact the Company:
a) by post: ALFA LOGISTIKA d.o.o., Andrije Hebranga 16, 47000 Karlovac;
b) by email: privacy@alfaiot.eu;
c) through a form or another contact channel published on the Websites.
(2) The Company’s Data Protection Officer is Marina Kostelić. The contact for the Data Protection Officer is privacy@alfaiot.eu.
(3) The supervisory authority for personal data protection in the Republic of Croatia is the Croatian Personal Data Protection Agency.
Article 23 – Language and Prevailing Version
(1) This Privacy Policy was drawn up in Croatian. If an English, Slovenian or other translation is prepared, the Croatian version shall prevail, unless expressly provided otherwise or mandatory law requires otherwise.