Aroute Privacy Policy

Version: 1.0 | Effective date: February 19, 2026 | Market: UK (aroute.co.uk)

§1. Data Controller

The data controller is:

Emversa Maciej Łukowski

ul. Sielska 17a

60-129 Poznań, Poland

VAT ID: PL9720811257

Email: office@emversa.com

§2. Definitions

  1. Aroute Platform – a web application (PWA) and iOS mobile application for maintaining vehicle mileage records.
  2. Organisation – a business entity that has entered into a service agreement with the Controller.
  3. Driver – a user assigned to an Organisation, recording trips.
  4. UK GDPR – the retained EU GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018 and amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019.
  5. Data Protection Act 2018 – the UK Data Protection Act 2018, which supplements the UK GDPR.
  6. PECR – the Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended.

§3. Roles in Data Processing

3.1. Controller as Data Controller

The Controller (Emversa) is the data controller within the meaning of UK GDPR with respect to:

  • data of Organisation Administrators (management accounts),
  • Organisation contact data,
  • marketing data (newsletter, consents),
  • contact form data.

3.2. Controller as Data Processor

The Controller (Emversa) acts as a data processor within the meaning of Art. 28 UK GDPR with respect to:

  • Driver data processed on behalf of the Organisation,
  • Driver trip and location data.

In this scope, the Organisation is the data controller for its Drivers' personal data, and Emversa processes data based on the Data Processing Agreement (DPA).

3.3. Organisation's Information Obligation

The Organisation, as the data controller for Drivers' personal data, is obligated to fulfil the information obligation towards Drivers pursuant to Art. 13 UK GDPR before they start using the Platform.

§4. Categories of Processed Data

4.1. User Account Data

DataPurposeLegal BasisRetention Period
Email addressIdentification, login, communicationArt. 6(1)(b) UK GDPR – contract performanceDuration of account
First and last nameIdentificationArt. 6(1)(b) UK GDPRDuration of account
Password (hashed)AuthenticationArt. 6(1)(b) UK GDPRDuration of account
Language preferencesInterface localisationArt. 6(1)(f) UK GDPR – legitimate interestDuration of account
Working hours and daysAuto-trip configurationArt. 6(1)(b) UK GDPRDuration of account

4.2. Organisation Data

DataPurposeLegal BasisRetention Period
Company nameIdentificationArt. 6(1)(b) UK GDPRDuration of account
UK VAT / Company NumberInvoicingArt. 6(1)(c) UK GDPR – legal obligation5 years from end of tax year (Polish tax law)
Registered addressInvoicingArt. 6(1)(b) UK GDPR5 years from end of tax year (Polish tax law)
Billing emailInvoice deliveryArt. 6(1)(b) UK GDPRDuration of account
CurrencyBillingArt. 6(1)(b) UK GDPRDuration of account

4.3. Trip Data

DataPurposeLegal BasisRetention Period
GPS coordinates (start/end)Route documentationArt. 6(1)(b) UK GDPR + consentDuration of account
Addresses (start/end)Route documentationArt. 6(1)(b) UK GDPRDuration of account
TimestampsTrip timeArt. 6(1)(b) UK GDPRDuration of account
Odometer readingsDistance verificationArt. 6(1)(b) UK GDPRDuration of account
DistanceMileage reportingArt. 6(1)(b) UK GDPRDuration of account
Speed (max/average)AnalyticsArt. 6(1)(f) UK GDPRDuration of account
Trip type (business/private)VAT classificationArt. 6(1)(c) UK GDPRDuration of account
Reimbursement amountCost settlementArt. 6(1)(b) UK GDPRDuration of account

4.4. GPS Checkpoints

PARTICULARLY SENSITIVE DATA – precise location

DataPurposeLegal BasisRetention Period
Latitude/longitudeRoute recordingArt. 6(1)(b) UK GDPR + consentDuration of account
AltitudeRoute accuracyArt. 6(1)(b) UK GDPRDuration of account
GPS accuracy (metres)Data qualityArt. 6(1)(b) UK GDPRDuration of account
HeadingRoute analysisArt. 6(1)(b) UK GDPRDuration of account
Instantaneous speedSpeed monitoringArt. 6(1)(b) UK GDPRDuration of account
Address (geocoded)Location identificationArt. 6(1)(b) UK GDPRDuration of account
TimestampTime accuracyArt. 6(1)(b) UK GDPRDuration of account

When GPS points are collected:

  • At trip start
  • Every 5 minutes during active trip
  • Every 250 metres of movement
  • At trip end
  • Backbuffer (up to 5 minutes before trip confirmation in auto-trip mode)

Note: GPS points are NOT collected in manual entry mode.

§5. Purposes and Legal Bases for Processing

5.1. Contract Performance (Art. 6(1)(b) UK GDPR)

  • Creating and managing user accounts
  • Recording trips and maintaining mileage records
  • Managing vehicles and drivers
  • Generating reports (Vehicle Mileage Log, Reimbursement Summary) and exports
  • Processing reimbursement claims
  • Subscription management
  • Customer support
  • Sending email invitations
  • Sending authentication emails

5.2. Legal Obligation (Art. 6(1)(c) UK GDPR)

  • Tax documentation (UK VAT, Company Number)
  • Invoice data retention (5 years from end of tax year per Polish tax law). UK customers should retain their copies for 6 years per HMRC requirements.
  • Mileage records for VAT purposes
  • VAT verification data retention

5.3. Legitimate Interest (Art. 6(1)(f) UK GDPR)

  • Abandoned registration recovery (lead capture)
  • Service improvement and analytics
  • Security monitoring and fraud prevention
  • Fleet map visualisation (paid feature)
  • Speed analytics and trip statistics (paid feature)
  • Mileage gap and discrepancy detection

5.4. Consent (Art. 6(1)(a) UK GDPR, PECR compliant)

  • Marketing email communication (optional checkbox)
  • Analytics cookies (cookie banner)
  • GPS checkpoint collection
  • Auto-trip detection
  • Contact form processing

§6. Data Processors (Sub-processors)

The Controller uses the following data processors:

ServiceProviderPurposeLocation
SupabaseSupabase Inc.Database hosting, authentication, RLSEU
StripeStripe Payments Europe, Ltd.Payments, invoicesIreland (EU)
VercelVercel Inc.Application hosting, CDNGlobal
ResendResend, Inc.Transactional email deliveryUSA
Google AnalyticsGoogle LLCWebsite analytics (with consent)USA
OpenStreetMap NominatimOpenStreetMap FoundationGeocoding (coordinates → addresses)Global
OSRMProject OSRMRoute distance calculationGlobal
WeatherAPIWeatherAPIWeather conditions during trips-
Companies HouseUK GovernmentCompany verificationUK
ipapi.coipapi.coIP-based country detection-
ip-api.comip-api.comBackup IP-based country detection-

§7. International Data Transfers

Some data processors may transfer data outside the United Kingdom:

ServiceLocationTransfer Mechanism
SupabaseEU/EEAPermitted under UK adequacy regulations
StripeIreland (EU)Permitted under UK adequacy regulations
VercelGlobal (CDN)UK International Data Transfer Agreement (IDTA)
ResendUSAUK International Data Transfer Agreement (IDTA)
Google AnalyticsUSAIDTA + UK Extension to EU-US Data Privacy Framework

All international data transfers are carried out with appropriate safeguards in accordance with UK GDPR requirements.

§8. Data Retention Periods

8.1. Active Accounts

Data CategoryRetention Period
User account dataDuration of account
Organisation dataDuration of subscription
Trip dataDuration of subscription
GPS checkpointsDuration of subscription
Vehicle dataDuration of subscription
Reimbursement claimsDuration of subscription
Invoice data (VAT, Company Number, address)5 years from end of tax year (Polish tax law)
Marketing subscriber dataUntil unsubscribe

8.2. After Subscription End

Voluntary cancellation:

  • Grace period: 90 days from end of paid period
  • During grace period: All data preserved, export available
  • After grace period: Organisation deactivated, data preserved per legal requirements

Non-payment:

  • Immediate access suspension
  • Data preserved for 30 days
  • After 30 days: Organisation deactivated

8.3. Account Deletion (UK GDPR Right to Erasure)

  • Personal data: Deleted
  • Trip and GPS data: Deleted
  • Invoice data (VAT, Company Number, address): Retained 5 years from end of tax year (Polish tax law). UK customers should retain their copies for 6 years per HMRC requirements.

8.4. Registration Leads

  • Completed registrations: Converted to user account
  • Abandoned registrations: 30 days, then soft delete

8.5. Contact Inquiries

  • Active: Until inquiry resolution
  • Resolved: Deleted after resolution

§9. Data Subject Rights

Under UK GDPR, you have the following rights:

9.1. Rights Implemented in Platform

RightImplementation
Right of accessUsers can view all their data in the app; Excel export available
Right to rectificationUsers can update profile; Drivers submit trip edit requests
Right to data portabilityExcel/PDF export feature for trip data and reports
Right to withdraw consentCookie settings reset; marketing unsubscribe via profile settings; location consent withdrawal

9.2. Rights Requiring Manual Process

RightProcess
Right to erasureContact: office@emversa.com; Administrator can deactivate users
Right to restriction of processingContact: office@emversa.com
Right to objectContact: office@emversa.com

9.3. Special Notes

  • Invoice data: Retained 5 years from end of tax year per Polish tax law, even after account deletion request. UK customers should retain their copies for 6 years per HMRC requirements.
  • Anonymisation: Preferred over deletion when legal retention is required
  • Response time: We will respond to your request within one month

§10. Data Security

10.1. Technical Measures

  • Encryption in transit: TLS/HTTPS for all communication
  • Encryption at rest: Database encryption (Supabase)
  • Password hashing: bcrypt via Supabase Auth
  • Data isolation: Row-Level Security (RLS) at database level
  • Access control: RBAC (Driver < Administrator)

10.2. Organisational Measures

  • Least privilege policy: Users have access only to necessary data
  • Webhook verification: Stripe and Supabase signature verification
  • Rate limiting: Implemented at edge level (Vercel)

§11. Cookies

Detailed information about cookies is contained in the Cookie Policy available at: aroute.co.uk/cookies.

§12. Data Breach

12.1. Supervisory Authority Notification

In case of a personal data breach that may pose a risk to the rights and freedoms of individuals, the Controller will notify the Information Commissioner's Office (ICO) within 72 hours of breach detection.

12.2. Data Subject Notification

If the breach may pose a high risk to the rights and freedoms of individuals, the Controller will notify affected individuals without undue delay.

§13. Children's Data

  1. The Aroute Platform is intended exclusively for business users (B2B). Organisation account registration and the Administrator role requires being of legal age (18 years old).
  2. A Driver on the Platform may be a minor (16-17 years old) if they are legally employed by the Organisation and hold appropriate driving licences in accordance with applicable law.
  3. In the case of minor Drivers, the Organisation (as the data controller for its employees' personal data) is responsible for:
    • obtaining all required consents from parents or legal guardians in accordance with labour law provisions,
    • fulfilling the information obligation towards the minor and their legal guardians,
    • ensuring data processing compliance with regulations concerning the employment of minors.
  4. Under UK GDPR, the age of consent for data processing is 13 years old. Emversa does not direct marketing services or direct communication to children under 13.

§14. Do Not Track Signals

The Platform does not respond to "Do Not Track" (DNT) signals sent by web browsers. Users may manage their tracking preferences through cookie settings available in the Platform and in the cookie policy.

§15. Automated Decision-Making

The Platform does not use automated decision-making, including profiling, as referred to in Article 22(1) and (4) of UK GDPR, which produces legal effects or similarly significantly affects users. All decisions regarding trip approvals, reimbursement claims, and similar matters are made by authorised users (Organisation Administrators), not by algorithms.

§16. Changes to Privacy Policy

  1. The Controller reserves the right to change this Privacy Policy.
  2. Users will be notified of changes by email at least 14 days before the changes take effect.
  3. The current version of the Privacy Policy is always available at: aroute.co.uk/privacy.

§17. Contact and Complaints

For personal data protection matters, please contact:

Emversa Maciej Łukowski

ul. Sielska 17a

60-129 Poznań, Poland

Email: office@emversa.com

Supervisory Authority for the United Kingdom:

Information Commissioner's Office (ICO)

Wycliffe House, Water Lane

Wilmslow, Cheshire SK9 5AF

United Kingdom

Tel: 0303 123 1113

www.ico.org.uk

Document generated: February 19, 2026