In accordance with Article 28 GDPR - Last updated: July 2026
This data processing agreement forms part of the terms of service and applies whenever FleetHub processes personal data on behalf of the customer. The customer is the data controller; FleetHub is the data processor.
FleetHub processes personal data solely to deliver the service to the customer, and only on the documented instructions of the customer. Processing lasts for as long as the customer uses the service and ends upon termination of the agreement, subject to statutory retention obligations.
The processing covers hosting, storing, displaying and processing data required for fleet management: managing vehicles, bookings, approvals, mileage, damage reports and users, and sending related notifications.
Data subjects: administrators and employees of the customer.
Personal data: name, email address, role, login data, and data entered by the user (bookings, trips with origin and destination, mileage, damage reports with any photos). See also Annex A.
FleetHub processes the personal data only according to the customer instructions, as laid down in the agreement and the service itself. FleetHub does not sell or reuse the data for its own purposes. If a legal obligation requires FleetHub to process otherwise, the customer is informed beforehand, unless the law prohibits this.
Everyone at FleetHub with access to the personal data is bound by confidentiality and processes the data only as far as necessary for the service.
FleetHub takes appropriate technical and organizational measures to protect the data, including encrypted connections, strict separation of data per company (isolation at database level), role-based access control, and logging of sign-ins. An overview is provided in Annex B.
To deliver the service, FleetHub relies on sub-processors, for example for hosting, database and authentication, email delivery and payment processing. Equivalent data protection obligations apply to each sub-processor. A current overview is available on request via our contact details. When a sub-processor changes, the customer is informed and may object on reasonable grounds.
FleetHub assists the customer, as far as reasonable, in meeting its obligations: with requests from data subjects (access, correction, erasure, portability), with a data protection impact assessment (DPIA) and with demonstrating compliance.
In the event of a personal data breach, FleetHub informs the customer without undue delay, with the information the customer needs to meet its own notification obligation.
Personal data is in principle processed within the European Economic Area. If a transfer to a third country nevertheless takes place, it only happens with appropriate safeguards such as the European Commission standard contractual clauses.
After the end of the agreement, FleetHub deletes the personal data, or returns it to the customer on request, subject to statutory retention obligations. Bookings older than the retention period are deleted automatically.
On reasonable request, FleetHub makes available to the customer the information needed to demonstrate compliance with this agreement, and cooperates with an audit under reasonable conditions.
Liability under this data processing agreement follows the provisions of the terms of service, without prejudice to the mandatory rules of the GDPR.
Subject matter, duration, nature and purpose: see articles 1-2. Categories of data subjects and personal data: see article 3.
Encryption in transit, per-company isolation at database level, role-based access, sign-in logging, and automatic deletion after the retention period.
Categories: hosting, database and authentication, email delivery, payment processing. A current overview is available on request via our contact details.
FleetHub is an application by IT-SmartSystems - VAT BE 1041.263.326