Versie 2026-10 / Version 2026-10
TrapSpotter BV · Trekschurenstraat 245, 3500 Hasselt, Belgium · enterprise number 1031.603.017 (RLE Antwerp, Hasselt division) · VAT BE1031603017 · privacy@trapspotter.com
This data processing agreement is the contract referred to in Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR). It forms part of the business terms for TrapSpotter Teams and Fleet and applies between the business that uses the console (the customer), as controller, and TrapSpotter BV (TrapSpotter), as processor. Terms used in this agreement have the meaning given to them in the GDPR.
1. Subject matter
1.1 TrapSpotter processes personal data for the customer in order to provide the console and the features of Teams and Fleet. Annex 1 describes, for each feature, the subject matter, the nature, the purpose, the data subjects, the data and the retention period.
1.2 As regards the processing of personal data, this agreement prevails over the business terms.
2. Roles
2.1 The customer is the controller for the data in Annex 1. It determines the purposes, has a legal basis for each processing operation (for data about traffic offences, also a basis permitted under Article 10 GDPR; see Annex 4), informs the data subjects and responds to their requests.
2.2 TrapSpotter is the processor of that data.
2.3 TrapSpotter is itself the controller, outside this agreement, for: each user's own TrapSpotter account and their use of the app outside the features in Annex 1 (such as alerts, navigation, reports and Premium), the contract and billing data of the customer and its contact persons, the security of the service and the prevention of misuse, and statistics that identify no one. TrapSpotter's privacy policy describes that processing.
3. Instructions
3.1 TrapSpotter processes the data only on documented instructions from the customer, including with regard to transfers to a third country. The instructions are: this agreement, the business terms, and what the customer and its managers set or do in the console. The customer gives other instructions in writing.
3.2 If Union or Member State law requires TrapSpotter to process data without an instruction, TrapSpotter informs the customer of this in advance, unless that law prohibits such notification.
3.3 If, in TrapSpotter's opinion, an instruction infringes the GDPR or other data protection rules, TrapSpotter informs the customer immediately. It then need not carry out the instruction until the customer confirms or amends it.
4. Confidentiality
4.1 Only TrapSpotter staff and subcontractors who need the data for their tasks have access to it, and they are bound by confidentiality.
4.2 TrapSpotter's admin console shows staff no trips, routes, addresses or positions, and cannot open a customer's console. Only the system administrators have technical access to the database, for maintenance, security and fixing errors. For support, TrapSpotter looks at a customer's data only if the customer asks, and only at what is needed for that purpose.
5. Security
TrapSpotter takes the technical and organisational measures in Annex 2 (Article 32 GDPR) and maintains them. It may adapt them, provided that the level of protection does not decrease.
6. Sub-processors
6.1 The customer gives TrapSpotter general authorisation to engage the sub-processors in Annex 3.
6.2 TrapSpotter gives notice of a new or replacement sub-processor at least 30 days in advance, by email to the company's owner in the console. The customer may object, stating reasons, within that period. If the parties cannot find a solution, the customer may terminate the agreement before the sub-processor starts; anything it paid in advance for the period after that is refunded.
6.3 TrapSpotter imposes on each sub-processor, by contract, data protection obligations that correspond to this agreement (Article 28(4) GDPR), and remains fully liable to the customer for the performance of those obligations.
7. Transfers outside the European Economic Area
7.1 The service's database and files are located in the European Union (Stockholm, Sweden), and TrapSpotter's own servers in Germany. Some sub-processors process data in or from a country outside the European Economic Area (EEA); Annex 3 states which ones and where.
7.2 Such a transfer takes place only with a safeguard under Chapter V of the GDPR: an adequacy decision of the European Commission (for the United States: the EU–US Data Privacy Framework, for companies certified under it) or the European Commission's standard contractual clauses. Annex 3 states the safeguard for each sub-processor.
8. Assistance
8.1 Data subject requests. In the console, the customer can view, export and correct the data, delete vehicles and documents, and take members and clients out of use. What the customer cannot do itself, such as erasing trips, TrapSpotter carries out at the customer's written request within ten working days.
8.2 If TrapSpotter itself receives a request from a data subject concerning the customer's data, it forwards the request to the customer within five working days and does not respond on the substance, unless the customer asks it to.
8.3 TrapSpotter assists the customer with security, the data protection impact assessment (DPIA) and any prior consultation of the supervisory authority, with the information available to it, including these annexes and the DPIA template for each country.
8.4 This assistance is free of charge, except for requests that are manifestly unfounded or excessive; in that case, TrapSpotter may, with the customer's agreement, charge a reasonable fee.
9. Personal data breaches
9.1 TrapSpotter notifies a personal data breach involving the customer's data without undue delay and at the latest within 48 hours after becoming aware of it, by email to the company's owner and managers, or to the address the customer provides for that purpose.
9.2 The notification contains, as far as known: the nature of the breach, the categories and approximate number of data subjects and of data records, the likely consequences, the measures taken and proposed, and a contact person. Anything not yet known follows as soon as it is known.
9.3 The customer decides on notifying the supervisory authority and the data subjects (Articles 33 and 34 GDPR); TrapSpotter assists it with this and documents the breach.
10. Information and audits
10.1 TrapSpotter makes available to the customer the information needed to demonstrate that it complies with this agreement: among other things, this agreement with its annexes, a description of the measures and the list of sub-processors.
10.2 If that information is not sufficient, the customer may, at its own expense, have an audit carried out by an independent auditor who is bound by confidentiality. An audit takes place at most once a year (except after a breach or at the request of a supervisory authority), on the basis of a written plan provided at least 30 days in advance, during office hours, and without access to other customers' data. For sub-processors, their own audit reports and certifications apply.
11. Retention and end
11.1 During the agreement, the retention periods in Annex 1 apply. The customer may at any time ask in writing for data to be erased earlier; TrapSpotter does so within ten working days.
11.2 After the end of the subscription, the customer can still export its data in the console for 30 days. After that, TrapSpotter erases all data in Annex 1 within 30 days, unless Union or Member State law requires storage. Erased data disappears from the backups when they expire, within 30 days at most.
11.3 On request, TrapSpotter confirms the deletion in writing.
12. Liability
As regards data subjects, Article 82 GDPR applies. Between the parties, the liability provisions of the business terms apply, except to the extent that the law prohibits this.
13. Term, governing law and jurisdiction
This agreement applies for as long as TrapSpotter processes personal data for the customer. This agreement is governed by Belgian law; disputes are submitted to the courts designated in the business terms.
Annex 1. Description of the processing
Nature of the processing. Collecting via the app and the console, storing, organising, displaying, calculating (hours, kilometres, allowances), exporting, sending (email, push notifications) and erasing.
Data subjects. The customer's owners and managers; drivers (employees and other workers whom the customer invites); invited persons; contact persons of the customer's clients.
Duration. For as long as the agreement runs, and thereafter the period in clause 11.
Per feature:
Members and invitations (Teams and Fleet). Data: first name, surname, email address, phone number, job title, employee number, notes, role, status, seat, whether an owner or manager also has their own work trips recorded, dates of invitation, acceptance and departure. Purpose: managing access and seats. Retention: for as long as the member exists; a member who has left or been removed is kept for as long as work data is linked to them, at the latest until the end of the agreement. An invitation is valid for 7 days and, once it has been used, revoked or has expired, is erased at the latest 90 days after it was sent.
Workdays (Fleet). Data: start and end, the reason for the end (stopped by the driver, automatic stop, end of the subscription, the driver's departure), the vehicle or the driver's own car. Purpose: working time and kilometres per workday. Retention: until the end of the agreement, unless the customer asks for erasure earlier.
Trips (Fleet). Data: start and end time, start and end position with address, the route taken (simplified), the distance, the client, the vehicle or the driver's own car, a note, and whether the trip is private. For a private trip, only the time and the distance remain: the places, the route and the client are permanently erased on the server, and the database does not accept a private trip with such data. Purpose: proving trips and visits, calculating kilometres and allowances. Retention: as for workdays.
Live positions (Fleet, only if the customer switches them on). Data: position, direction of travel and speed according to the phone, and the time; at most once a minute, only during a workday and never during a private trip. The console shows the position, not the speed. Purpose: knowing who is where during work (planning, assistance). Retention: erased after 30 minutes, at the end of the workday, when the driver leaves the company, and immediately for all drivers when the customer switches live positions off.
Clients and addresses (Fleet). Data subjects: the customer's clients and their contact persons. Data: name, address, position, label, contact person, phone number, note. Purpose: linking trips to visits and showing addresses in the app. Retention: until the end of the agreement, unless the customer asks for erasure earlier.
Vehicles and documents (Fleet). Data: number plate, make, model, year of manufacture, fuel, odometer reading, assigned driver; type of document, reference, expiry date. An email to the owner and the managers 30 days and 7 days before a document expires. Purpose: managing the fleet and knowing who drove which vehicle. Retention: until the customer deletes them, at the latest until the end of the agreement.
Receipts (Fleet). Data: date, type, merchant, amount, VAT, litres, photo, status, who decided and when. The photos are kept in private storage: only the driver who submitted them and the owner and managers can see them, via links that are valid for five minutes. Purpose: reimbursing expenses. Retention: until the end of the agreement, unless the customer asks for erasure earlier. The customer itself keeps what it must keep for its accounting.
Fines, "Who was driving?" (Fleet; only the owner and the managers). Data subjects: drivers. Data: number plate, date, time and place of the offence, the authority's reference, date of receipt, deadline, status, the trip and driver found, the question to the driver and their answer, notes. This is data relating to criminal offences within the meaning of Article 10 GDPR. Purpose: finding the driver and, where the law requires it, designating the driver within the deadline (Annex 4). Retention: automatically erased at the latest 24 months after the date of the offence. The customer erases it earlier where the law applicable to it or its supervisory authority requires this; for example, in France the CNIL recommends erasing the data for the designation 45 days after receipt of the fine, and in the Netherlands an owner or keeper may not keep a register of offences (Annex 4).
Mileage statement (Fleet). Calculated from the workdays and trips when the customer requests it: business kilometres in the driver's own car and in a company vehicle, the number of private trips (without places), workdays, hours and the allowance; per client: visits, kilometres and time on site. Purpose: preparing the mileage allowance and invoicing to clients. Retention: not stored separately.
Audit log (Teams and Fleet). Data: who did what in the console and when (for example, a member invited or removed, a setting changed). Purpose: security and accountability. Retention: until the end of the agreement.
Emails and push notifications (Teams and Fleet). Data: name, email address and company name in invitations; to drivers, a push notification when there is a question about a fine or when the server has ended a workday; to owners and managers, reminders about documents and fine deadlines. Purpose: the features above. Retention: the providers keep delivery logs in accordance with Annex 3.
Annex 2. Technical and organisational measures
- Hosting in the EU. Database, file storage and server functions at Supabase in the AWS region eu-north-1 (Stockholm, Sweden); own servers for maps and addresses at Hetzner in Falkenstein (Germany).
- Encryption. TLS in transit; encryption of stored data by the hosting provider.
- Access through controlled functions. Apps and browsers have no direct access to the tables (row level security on every table, with no privileges for users). On every call, each function checks who the user is, which company they belong to and which role they have, and whether the company is active.
- Roles. Owner, manager and driver. A driver sees only their own data. Fines are visible only to the owner and the managers.
- Minimal recording. Only during a workday, with an automatic stop. Private trips are stripped on the server. Live positions are off by default, at most one per minute, and are erased after 30 minutes. Fines are erased at the latest 24 months after the offence.
- Invitations. A random 256-bit key, of which only the hash is stored; valid for 7 days and usable once.
- Receipts. Private storage; readable only via links that are valid for five minutes.
- Misuse. Rate limiting on write actions and on sensitive functions; bot protection when signing in to the console.
- Audit log. Actions in the console are logged.
- TrapSpotter staff. Access on a need-to-know basis and subject to a duty of confidentiality; the admin console shows no trips, routes, addresses or positions and cannot open a customer's console.
- Secrets. Keys are kept in the providers' management environments, not in the source code.
- Vulnerabilities. Daily check of the software used for known vulnerabilities.
- Tests. Automated tests check the access rules for each role.
- Error reporting. Errors are reported with technical data (error type, version, device, user ID), without the content of trips or positions.
- Backups by the hosting provider, which expire within 30 days at most.
- Incidents. A procedure to detect, contain and document breaches and to notify them to the customer within 48 hours.
Annex 3. Sub-processors
For the service:
- Supabase Pte. Ltd. (Singapore), with Amazon Web Services as hosting provider. Database, authentication, file storage (including the photos of receipts) and server functions. Location: AWS region eu-north-1 (Stockholm, Sweden); support by Supabase, Inc. from the United States may involve access. Safeguard: standard contractual clauses (module 2) in Supabase's data processing agreement.
- Hetzner Online GmbH (Gunzenhausen, Germany). TrapSpotter's own servers: the map in the console and looking up an address for a position. Location: Falkenstein, Germany. No transfer.
- Mapbox, Inc. (United States). Fallback for looking up an address for a position when TrapSpotter's own server does not respond. Receives only coordinates, no name or user ID. Location: United States. Safeguard: EU–US Data Privacy Framework; standard contractual clauses.
- Plus Five Five, Inc. (Resend, United States). Sending emails (invitations, reminders). Sending from Ireland; email data and logs are stored in the United States. Safeguard: standard contractual clauses; EU–US Data Privacy Framework.
- Functional Software, Inc. (Sentry, United States). Error reports from the app and the console: error type, version, device, user ID. Location: European Union (Frankfurt); some account data in the United States. Safeguard: EU–US Data Privacy Framework; standard contractual clauses as a fallback.
- Vercel Inc. (United States). Hosting of the console at fleet.trapspotter.com: serves the pages and, in doing so, receives the IP address and technical data of the browser. Location: global network. Safeguard: EU–US Data Privacy Framework; standard contractual clauses.
- Cloudflare, Inc. (United States). Bot protection (Turnstile) when signing in to the console: IP address and technical signals from the browser. Location: global network. Safeguard: EU–US Data Privacy Framework; standard contractual clauses. Cloudflare also uses those signals as an independent controller to improve its bot detection.
- Google LLC and Google Ireland Limited (Firebase Cloud Messaging). Push notifications to Android phones: the device token and the text of the notification. Safeguard: EU–US Data Privacy Framework; standard contractual clauses.
- Apple Inc. (United States, Apple Push Notification service). Push notifications to iPhones: the device token and the text of the notification. Apple does not offer a data processing agreement or standard contractual clauses for this; that is why the service's push notifications contain only a generic text, without number plate, place or offence. The driver sees the details only in the app.
For billing (TrapSpotter as controller; for information):
- Stripe Payments Europe, Limited (Ireland): subscription, payments and invoices; transfer to Stripe, LLC (United States) under the EU–US Data Privacy Framework and standard contractual clauses.
- Billit NV (Ghent, Belgium), as soon as sending via Peppol is active: invoices to Belgian customers via the Peppol network; servers in Europe.
Annex 4. Legal basis for fine data (for information)
The customer determines its legal basis. This annex summarises what TrapSpotter found; it is not legal advice. A deadline runs from the date the law specifies (usually the date of sending or the date of the letter), not from receipt.
- Belgium. The legal person, or the natural person who represents it in law, communicates the identity of the driver or, if it does not know it, that of the person responsible for the vehicle, within 15 days of the sending of the request for information (Article 67ter of the Act on the Policing of Road Traffic). Since 1 September 2026, anyone who fails to do so risks a fine of €1,600 to €32,000 (Article 29ter), to be increased by the surcharges (opdeciemen). Legal basis: Article 6(1)(c) GDPR. Article 10 GDPR: Article 10, § 1, 1° of the Act of 30 July 2018 (management of its own disputes), to be confirmed by the customer; the customer keeps the list of the categories of persons with access and ensures that they are bound by confidentiality (Article 10, § 2).
- Luxembourg. The legal representative of the legal person that holds the registration certificate provides the data needed to identify the driver within 45 days of the date of the letter, one month longer for those who do not live in Luxembourg (Articles 4, 8, 8bis and 9 of the amended Act of 25 July 2015). Anyone who fails to do so risks a fine of €1,000 to €10,000 (Article 12). Legal basis: Article 6(1)(c) GDPR. Article 10 GDPR: the same legal obligation; we did not find an express Luxembourg rule for private employers.
- France. The legal representative of a legal person that holds the registration certificate, or that keeps the vehicle, communicates the identity and address of the driver within 45 days of the sending or delivery of the notice of offence, for offences detected by an automatic device (Article L121-6 of the Code de la route). Failure to do so exposes the legal person to a fixed penalty of €675 (€1,000 if the original offence is a misdemeanour). Legal basis: Article 6(1)(c) GDPR. Article 10 GDPR: Article 46 of Act No. 78-17 of 6 January 1978 (Informatique et Libertés), together with Articles A121-1 et seq. of the Code de la route, as confirmed by the CNIL's reference framework 2021-043 on the designation of drivers. That reference framework recommends keeping the data for the designation for 45 days after receipt of the fine; the customer then erases it in the console or asks TrapSpotter to do so.
- Netherlands. For a fine under the Mulder Act (WAHV), there is no obligation to designate the driver: the registered keeper pays (Article 5 WAHV) and, since 1 September 2026, may process personal data in order to recover the fine from the driver (Article 5(2) WAHV). In the case of a penalty order, the owner or keeper is liable unless they disclose the name and address of the driver (Article 181 of the Road Traffic Act 1994, with a basis for criminal data in paragraph 5); in the case of a serious offence, they must disclose the driver within the period set in the demand, which is at least 48 hours (Article 165). Legal basis: Article 6(1)(f) GDPR, or (c) in the case of Article 165. Criminal data about staff is processed under rules adopted with the consent of the works council (Article 33(3) UAVG). The legislator points out that an owner or keeper may not keep a register of offences and may process data only for each specific sanction. According to the legislator, Mulder fines are not data within the meaning of Article 10 GDPR; as a precaution, the service treats them as such.
- Germany. There is no obligation to designate the driver. If the driver cannot be identified, the authorities may require the keeper to keep a logbook (§ 31a StVZO). Legal basis: Article 6(1)(f) GDPR. Article 10 GDPR: we did not find a clear German legal basis for employers; the customer processes this data only for each specific fine and has its legal basis assessed.
A traffic offence falls within Article 10 GDPR, according to the Court of Justice (22 June 2021, C-439/19).
