Roles
For customer workforce and driver records entered into TMS, the customer organization is typically the controller and we act as a processor under documented instructions. For our own marketing site accounts, billing contacts, and platform telemetry, we act as a controller.
Lawful bases
- Contract performance — providing the subscribed TMS features.
- Legitimate interests — securing the service, preventing fraud, and improving reliability, balanced against individual rights.
- Legal obligation — retaining records where transport or tax law requires.
- Consent — where a customer or we rely on consent for a specific optional processing activity.
Special categories
Driver medical card expiry and related compliance fields may imply health-adjacent information. Customers should only collect what is necessary for fitness-to-drive compliance and ensure an appropriate lawful basis before storing such data in TMS.
Data subject rights
Where GDPR applies, individuals may exercise the following rights. Submit requests to support@example.com. If we process data only as a processor, we will forward the request to the relevant customer controller and assist per our agreement.
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to withdraw consent where processing is consent-based
- Right to lodge a complaint with a supervisory authority
Subprocessors and transfers
We use infrastructure and messaging vendors to deliver the service. When personal data leaves the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses or vendor certifications, as applicable.
Security and breach notice
We apply technical and organizational measures including access control, encryption in transit, audit logging, and least-privilege roles. Controllers will be notified of personal data breaches without undue delay as required by law and contract.
Retention and deletion
Retention follows customer configuration and our operational backups. Soft delete and deletion-approval workflows help customers control when records leave active use. Processor deletion assistance is available after contract end subject to legal holds.
DPA
Enterprise customers may request a Data Processing Addendum covering processor obligations, security annexes, and subprocessor lists. Contact support@example.com to initiate that process.
No certification claim
Nothing on this page constitutes a claim that TMS is formally certified for GDPR compliance by a third-party auditor. Legal-sensitive wording requires human/legal review before production reliance.
Questions? Contact us or review related policies in the footer.