Legal

Data processing agreement for TrapSpotter Teams and Fleet

The data processing agreement (GDPR Article 28) between your company, as the controller, and TrapSpotter, as the processor, for Teams and Fleet.

Versie 2026-10 / Version 2026-10

TrapSpotter BV · Trekschurenstraat 245, 3500 Hasselt, Belgium · enterprise number 1031.603.017 (RLE Antwerp, Hasselt division) · VAT BE1031603017 · privacy@trapspotter.com

This data processing agreement is the contract referred to in Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR). It forms part of the business terms for TrapSpotter Teams and Fleet and applies between the business that uses the console (the customer), as controller, and TrapSpotter BV (TrapSpotter), as processor. Terms used in this agreement have the meaning given to them in the GDPR.

1. Subject matter

1.1 TrapSpotter processes personal data for the customer in order to provide the console and the features of Teams and Fleet. Annex 1 describes, for each feature, the subject matter, the nature, the purpose, the data subjects, the data and the retention period.

1.2 As regards the processing of personal data, this agreement prevails over the business terms.

2. Roles

2.1 The customer is the controller for the data in Annex 1. It determines the purposes, has a legal basis for each processing operation (for data about traffic offences, also a basis permitted under Article 10 GDPR; see Annex 4), informs the data subjects and responds to their requests.

2.2 TrapSpotter is the processor of that data.

2.3 TrapSpotter is itself the controller, outside this agreement, for: each user's own TrapSpotter account and their use of the app outside the features in Annex 1 (such as alerts, navigation, reports and Premium), the contract and billing data of the customer and its contact persons, the security of the service and the prevention of misuse, and statistics that identify no one. TrapSpotter's privacy policy describes that processing.

3. Instructions

3.1 TrapSpotter processes the data only on documented instructions from the customer, including with regard to transfers to a third country. The instructions are: this agreement, the business terms, and what the customer and its managers set or do in the console. The customer gives other instructions in writing.

3.2 If Union or Member State law requires TrapSpotter to process data without an instruction, TrapSpotter informs the customer of this in advance, unless that law prohibits such notification.

3.3 If, in TrapSpotter's opinion, an instruction infringes the GDPR or other data protection rules, TrapSpotter informs the customer immediately. It then need not carry out the instruction until the customer confirms or amends it.

4. Confidentiality

4.1 Only TrapSpotter staff and subcontractors who need the data for their tasks have access to it, and they are bound by confidentiality.

4.2 TrapSpotter's admin console shows staff no trips, routes, addresses or positions, and cannot open a customer's console. Only the system administrators have technical access to the database, for maintenance, security and fixing errors. For support, TrapSpotter looks at a customer's data only if the customer asks, and only at what is needed for that purpose.

5. Security

TrapSpotter takes the technical and organisational measures in Annex 2 (Article 32 GDPR) and maintains them. It may adapt them, provided that the level of protection does not decrease.

6. Sub-processors

6.1 The customer gives TrapSpotter general authorisation to engage the sub-processors in Annex 3.

6.2 TrapSpotter gives notice of a new or replacement sub-processor at least 30 days in advance, by email to the company's owner in the console. The customer may object, stating reasons, within that period. If the parties cannot find a solution, the customer may terminate the agreement before the sub-processor starts; anything it paid in advance for the period after that is refunded.

6.3 TrapSpotter imposes on each sub-processor, by contract, data protection obligations that correspond to this agreement (Article 28(4) GDPR), and remains fully liable to the customer for the performance of those obligations.

7. Transfers outside the European Economic Area

7.1 The service's database and files are located in the European Union (Stockholm, Sweden), and TrapSpotter's own servers in Germany. Some sub-processors process data in or from a country outside the European Economic Area (EEA); Annex 3 states which ones and where.

7.2 Such a transfer takes place only with a safeguard under Chapter V of the GDPR: an adequacy decision of the European Commission (for the United States: the EU–US Data Privacy Framework, for companies certified under it) or the European Commission's standard contractual clauses. Annex 3 states the safeguard for each sub-processor.

8. Assistance

8.1 Data subject requests. In the console, the customer can view, export and correct the data, delete vehicles and documents, and take members and clients out of use. What the customer cannot do itself, such as erasing trips, TrapSpotter carries out at the customer's written request within ten working days.

8.2 If TrapSpotter itself receives a request from a data subject concerning the customer's data, it forwards the request to the customer within five working days and does not respond on the substance, unless the customer asks it to.

8.3 TrapSpotter assists the customer with security, the data protection impact assessment (DPIA) and any prior consultation of the supervisory authority, with the information available to it, including these annexes and the DPIA template for each country.

8.4 This assistance is free of charge, except for requests that are manifestly unfounded or excessive; in that case, TrapSpotter may, with the customer's agreement, charge a reasonable fee.

9. Personal data breaches

9.1 TrapSpotter notifies a personal data breach involving the customer's data without undue delay and at the latest within 48 hours after becoming aware of it, by email to the company's owner and managers, or to the address the customer provides for that purpose.

9.2 The notification contains, as far as known: the nature of the breach, the categories and approximate number of data subjects and of data records, the likely consequences, the measures taken and proposed, and a contact person. Anything not yet known follows as soon as it is known.

9.3 The customer decides on notifying the supervisory authority and the data subjects (Articles 33 and 34 GDPR); TrapSpotter assists it with this and documents the breach.

10. Information and audits

10.1 TrapSpotter makes available to the customer the information needed to demonstrate that it complies with this agreement: among other things, this agreement with its annexes, a description of the measures and the list of sub-processors.

10.2 If that information is not sufficient, the customer may, at its own expense, have an audit carried out by an independent auditor who is bound by confidentiality. An audit takes place at most once a year (except after a breach or at the request of a supervisory authority), on the basis of a written plan provided at least 30 days in advance, during office hours, and without access to other customers' data. For sub-processors, their own audit reports and certifications apply.

11. Retention and end

11.1 During the agreement, the retention periods in Annex 1 apply. The customer may at any time ask in writing for data to be erased earlier; TrapSpotter does so within ten working days.

11.2 After the end of the subscription, the customer can still export its data in the console for 30 days. After that, TrapSpotter erases all data in Annex 1 within 30 days, unless Union or Member State law requires storage. Erased data disappears from the backups when they expire, within 30 days at most.

11.3 On request, TrapSpotter confirms the deletion in writing.

12. Liability

As regards data subjects, Article 82 GDPR applies. Between the parties, the liability provisions of the business terms apply, except to the extent that the law prohibits this.

13. Term, governing law and jurisdiction

This agreement applies for as long as TrapSpotter processes personal data for the customer. This agreement is governed by Belgian law; disputes are submitted to the courts designated in the business terms.

Annex 1. Description of the processing

Nature of the processing. Collecting via the app and the console, storing, organising, displaying, calculating (hours, kilometres, allowances), exporting, sending (email, push notifications) and erasing.

Data subjects. The customer's owners and managers; drivers (employees and other workers whom the customer invites); invited persons; contact persons of the customer's clients.

Duration. For as long as the agreement runs, and thereafter the period in clause 11.

Per feature:

  1. Members and invitations (Teams and Fleet). Data: first name, surname, email address, phone number, job title, employee number, notes, role, status, seat, whether an owner or manager also has their own work trips recorded, dates of invitation, acceptance and departure. Purpose: managing access and seats. Retention: for as long as the member exists; a member who has left or been removed is kept for as long as work data is linked to them, at the latest until the end of the agreement. An invitation is valid for 7 days and, once it has been used, revoked or has expired, is erased at the latest 90 days after it was sent.

  2. Workdays (Fleet). Data: start and end, the reason for the end (stopped by the driver, automatic stop, end of the subscription, the driver's departure), the vehicle or the driver's own car. Purpose: working time and kilometres per workday. Retention: until the end of the agreement, unless the customer asks for erasure earlier.

  3. Trips (Fleet). Data: start and end time, start and end position with address, the route taken (simplified), the distance, the client, the vehicle or the driver's own car, a note, and whether the trip is private. For a private trip, only the time and the distance remain: the places, the route and the client are permanently erased on the server, and the database does not accept a private trip with such data. Purpose: proving trips and visits, calculating kilometres and allowances. Retention: as for workdays.

  4. Live positions (Fleet, only if the customer switches them on). Data: position, direction of travel and speed according to the phone, and the time; at most once a minute, only during a workday and never during a private trip. The console shows the position, not the speed. Purpose: knowing who is where during work (planning, assistance). Retention: erased after 30 minutes, at the end of the workday, when the driver leaves the company, and immediately for all drivers when the customer switches live positions off.

  5. Clients and addresses (Fleet). Data subjects: the customer's clients and their contact persons. Data: name, address, position, label, contact person, phone number, note. Purpose: linking trips to visits and showing addresses in the app. Retention: until the end of the agreement, unless the customer asks for erasure earlier.

  6. Vehicles and documents (Fleet). Data: number plate, make, model, year of manufacture, fuel, odometer reading, assigned driver; type of document, reference, expiry date. An email to the owner and the managers 30 days and 7 days before a document expires. Purpose: managing the fleet and knowing who drove which vehicle. Retention: until the customer deletes them, at the latest until the end of the agreement.

  7. Receipts (Fleet). Data: date, type, merchant, amount, VAT, litres, photo, status, who decided and when. The photos are kept in private storage: only the driver who submitted them and the owner and managers can see them, via links that are valid for five minutes. Purpose: reimbursing expenses. Retention: until the end of the agreement, unless the customer asks for erasure earlier. The customer itself keeps what it must keep for its accounting.

  8. Fines, "Who was driving?" (Fleet; only the owner and the managers). Data subjects: drivers. Data: number plate, date, time and place of the offence, the authority's reference, date of receipt, deadline, status, the trip and driver found, the question to the driver and their answer, notes. This is data relating to criminal offences within the meaning of Article 10 GDPR. Purpose: finding the driver and, where the law requires it, designating the driver within the deadline (Annex 4). Retention: automatically erased at the latest 24 months after the date of the offence. The customer erases it earlier where the law applicable to it or its supervisory authority requires this; for example, in France the CNIL recommends erasing the data for the designation 45 days after receipt of the fine, and in the Netherlands an owner or keeper may not keep a register of offences (Annex 4).

  9. Mileage statement (Fleet). Calculated from the workdays and trips when the customer requests it: business kilometres in the driver's own car and in a company vehicle, the number of private trips (without places), workdays, hours and the allowance; per client: visits, kilometres and time on site. Purpose: preparing the mileage allowance and invoicing to clients. Retention: not stored separately.

  10. Audit log (Teams and Fleet). Data: who did what in the console and when (for example, a member invited or removed, a setting changed). Purpose: security and accountability. Retention: until the end of the agreement.

  11. Emails and push notifications (Teams and Fleet). Data: name, email address and company name in invitations; to drivers, a push notification when there is a question about a fine or when the server has ended a workday; to owners and managers, reminders about documents and fine deadlines. Purpose: the features above. Retention: the providers keep delivery logs in accordance with Annex 3.

Annex 2. Technical and organisational measures

  • Hosting in the EU. Database, file storage and server functions at Supabase in the AWS region eu-north-1 (Stockholm, Sweden); own servers for maps and addresses at Hetzner in Falkenstein (Germany).
  • Encryption. TLS in transit; encryption of stored data by the hosting provider.
  • Access through controlled functions. Apps and browsers have no direct access to the tables (row level security on every table, with no privileges for users). On every call, each function checks who the user is, which company they belong to and which role they have, and whether the company is active.
  • Roles. Owner, manager and driver. A driver sees only their own data. Fines are visible only to the owner and the managers.
  • Minimal recording. Only during a workday, with an automatic stop. Private trips are stripped on the server. Live positions are off by default, at most one per minute, and are erased after 30 minutes. Fines are erased at the latest 24 months after the offence.
  • Invitations. A random 256-bit key, of which only the hash is stored; valid for 7 days and usable once.
  • Receipts. Private storage; readable only via links that are valid for five minutes.
  • Misuse. Rate limiting on write actions and on sensitive functions; bot protection when signing in to the console.
  • Audit log. Actions in the console are logged.
  • TrapSpotter staff. Access on a need-to-know basis and subject to a duty of confidentiality; the admin console shows no trips, routes, addresses or positions and cannot open a customer's console.
  • Secrets. Keys are kept in the providers' management environments, not in the source code.
  • Vulnerabilities. Daily check of the software used for known vulnerabilities.
  • Tests. Automated tests check the access rules for each role.
  • Error reporting. Errors are reported with technical data (error type, version, device, user ID), without the content of trips or positions.
  • Backups by the hosting provider, which expire within 30 days at most.
  • Incidents. A procedure to detect, contain and document breaches and to notify them to the customer within 48 hours.

Annex 3. Sub-processors

For the service:

  1. Supabase Pte. Ltd. (Singapore), with Amazon Web Services as hosting provider. Database, authentication, file storage (including the photos of receipts) and server functions. Location: AWS region eu-north-1 (Stockholm, Sweden); support by Supabase, Inc. from the United States may involve access. Safeguard: standard contractual clauses (module 2) in Supabase's data processing agreement.
  2. Hetzner Online GmbH (Gunzenhausen, Germany). TrapSpotter's own servers: the map in the console and looking up an address for a position. Location: Falkenstein, Germany. No transfer.
  3. Mapbox, Inc. (United States). Fallback for looking up an address for a position when TrapSpotter's own server does not respond. Receives only coordinates, no name or user ID. Location: United States. Safeguard: EU–US Data Privacy Framework; standard contractual clauses.
  4. Plus Five Five, Inc. (Resend, United States). Sending emails (invitations, reminders). Sending from Ireland; email data and logs are stored in the United States. Safeguard: standard contractual clauses; EU–US Data Privacy Framework.
  5. Functional Software, Inc. (Sentry, United States). Error reports from the app and the console: error type, version, device, user ID. Location: European Union (Frankfurt); some account data in the United States. Safeguard: EU–US Data Privacy Framework; standard contractual clauses as a fallback.
  6. Vercel Inc. (United States). Hosting of the console at fleet.trapspotter.com: serves the pages and, in doing so, receives the IP address and technical data of the browser. Location: global network. Safeguard: EU–US Data Privacy Framework; standard contractual clauses.
  7. Cloudflare, Inc. (United States). Bot protection (Turnstile) when signing in to the console: IP address and technical signals from the browser. Location: global network. Safeguard: EU–US Data Privacy Framework; standard contractual clauses. Cloudflare also uses those signals as an independent controller to improve its bot detection.
  8. Google LLC and Google Ireland Limited (Firebase Cloud Messaging). Push notifications to Android phones: the device token and the text of the notification. Safeguard: EU–US Data Privacy Framework; standard contractual clauses.
  9. Apple Inc. (United States, Apple Push Notification service). Push notifications to iPhones: the device token and the text of the notification. Apple does not offer a data processing agreement or standard contractual clauses for this; that is why the service's push notifications contain only a generic text, without number plate, place or offence. The driver sees the details only in the app.

For billing (TrapSpotter as controller; for information):

  • Stripe Payments Europe, Limited (Ireland): subscription, payments and invoices; transfer to Stripe, LLC (United States) under the EU–US Data Privacy Framework and standard contractual clauses.
  • Billit NV (Ghent, Belgium), as soon as sending via Peppol is active: invoices to Belgian customers via the Peppol network; servers in Europe.