LiteTMS.eu Privacy Policy
This Privacy Policy sets out the rules for the processing and protection of personal data of users of the website and the LiteTMS.eu B2B SaaS platform (the "Platform"). It has been drafted based on the principle of data protection by design (Privacy by Design) and in compliance with applicable laws, including the GDPR, the Digital Services Act (DSA), the EU Data Act, and the Artificial Intelligence Act (AI Act).
I. Data Controller and Data Processor
- Data Controller: With respect to the data of website visitors (landing page), data of company representatives registering an account, and billing and settlement data, the Controller is CodeJungle Sp. z o. o. with its registered office in Kawki (Kawki 51, 42-140 Panki), NIP (Tax ID): 5742064222, KRS (National Court Register): 0000722231, REGON (National Business Registry): 369658794.
- Data Processor: With respect to any data entered into the System by the Client (including data of employees, drivers, contractors, and fleet geolocation), the Client (transport company) remains the Controller of such data. CodeJungle Sp. z o. o. acts exclusively in the capacity of a Data Processor, acting upon the documented instructions of the Client on the basis of a Data Processing Agreement (DPA).
II. Purposes and Legal Bases of Data Processing by the Controller
We process your personal data for the following purposes:
- Provision of services and account management: Registration of a workspace (tenant) and technical communication. The legal basis is the necessity for the performance of a contract (Article 6(1)(b) of the GDPR).
- Billing and accounting: Processing of payment data. The legal basis is compliance with a legal obligation (Article 6(1)(c) of the GDPR).
- Security and analytics (Privacy by Design): We use our own instance of the Umami statistics system (self-hosted) and Cloudflare Turnstile protection to secure forms against bots without excessive user tracking and without sharing data with external advertising networks. We also process audit logs of system activity. The legal basis is our legitimate interest in ensuring the security and optimization of the platform (Article 6(1)(f) of the GDPR).
III. Data Recipients and Sub-processors
To ensure the highest quality of the Platform, we cooperate with the following service and technology providers:
- Infrastructure and cloud: OVH (servers), Cloudflare (Proxy, Turnstile, Cloudflare R2 for files), Amazon S3 (backups).
- Billing and Invoicing: Stripe payment operator (which, under financial law, also acts as an independent Controller) and API integration via Fakturownia.pl.
- Communication: EmailLabs (transactional emails), SMSAPI.pl (SMS gateway), Google Firebase (push notifications in the mobile app).
- External interfaces: OpenRouter to support Artificial Intelligence functionalities.
IV. Anonymized Maps and Telematics Integrations
The System utilizes a diversified API ecosystem (including HERE Maps, Google Maps, Mapbox) for routing and search. For the purpose of data minimization, the Platform transmits solely geographic coordinates to these providers, without any driver or vehicle identifiers. Where the System is integrated with the Client's external GPS providers, LiteTMS supplies the technical tool only. It is the Client who decides whether and how to lawfully use GPS with respect to their personnel. The Client is responsible for ensuring a lawful legal basis for processing location data, fulfilling information duties towards drivers and employees, and implementing GPS-monitoring rules compliant with labour law and data-protection law.
V. Artificial Intelligence (AI Act)
The Platform utilizes Smart Assistant functionalities. Please be advised that as part of this service, the User interacts directly with a generative system. LiteTMS configures the AI features to limit the processing of data by external providers. Where possible, we select settings and models that limit prompt retention and do not use Client data for model training. The scope of processing may depend on the selected provider or model and is described in the sub-processor list and documentation.
VI. Data Retention Period and Export (Data Act)
- Soft-Delete Mechanics: Upon the deletion of data (or a workspace), they enter a protective mechanism (quarantine) for 30 days. After this period, they are permanently deleted from production systems. Backup copies containing this data expire with the backup rotation cycle (full backups may be retained for up to 12 months) and serve solely to restore the System after a failure; we do not use them to restore individual, previously deleted data.
- Accounting: We retain billing data for 5 years from the end of the calendar year.
- Data Export (EU Data Act): We provide Clients with the freedom of data portability. During the term of the agreement and up to 30 days following its termination, the Client may export their datasets from the system free of charge in a commonly used machine-readable format.
VII. Data Transfers outside the EEA
LiteTMS production data is hosted in the European Union. Where limited access or a transfer outside the EEA occurs with selected technology providers (e.g., AWS, Stripe, Cloudflare, OpenRouter services), it takes place in accordance with the GDPR, in particular on the basis of appropriate safeguards such as Standard Contractual Clauses (SCC) approved by the European Commission or other guarantees provided for by law.
VIII. Your Rights
In accordance with the GDPR, you have the right to request access to your data, their rectification, erasure, restriction of processing, the right to object to processing, the right to data portability, and the right to lodge a complaint with a supervisory authority (PUODO - President of the Personal Data Protection Office). Please direct any privacy-related questions to contact@litetms.eu.
IX. Cookies
The website and the System use essential cookies (including for session handling and form security). For statistics, we use our own privacy-friendly, self-hosted instance of Umami, and forms are protected by Cloudflare Turnstile. You will find detailed information in the separate Cookies Policy.