LiteTMS.eu Privacy Policy
This notice explains, in plain language, how CodeJungle handles personal data on the LiteTMS website, during sales and support, and when operating the LiteTMS platform. It also explains when the Customer, rather than CodeJungle, decides why data is used.
1. Who is responsible
- Controller: CodeJungle Sp. z o. o., Kawki 51, 42-140 Panki, Poland, KRS: 0000722231, NIP: 5742064222, REGON: 369658794 ("CodeJungle", "we"). Contact us about privacy at contact@litetms.eu or by post at the address above.
- We are the controller for the website, registration and account administration, sales and partner contacts, marketing consents, billing, security, legal compliance, and our own business records.
- The Customer is normally the controller for personal data it enters into its workspace, such as employee, driver, contractor, customer, order, document, and GPS data. For that data, we act as processor under the Data Processing Agreement, except where law requires us to use limited data for our own security, fraud-prevention, billing, or legal-compliance purposes.
- If your data was entered by a Customer, please contact that Customer first to exercise your rights. We will assist it as required by the DPA.
2. Data we obtain and where it comes from
- From you: name, business and contact details, account data, communications, support requests, billing details, preferences, and consent records.
- From use of the website or platform: IP address, device and browser information, session and security events, audit logs, feature and page events, timestamps, and approximate location derived from network data.
- From others: an employer or Customer account administrator, a referral Partner, public business registers such as KRS or GUS, and payment, communications, identity, security, mapping, or integration providers.
- Customer-controlled content: the categories depend on the Customer's use and may include professional and employment data, identifiers, addresses, communications, documents, images, voice recordings, vehicle-linked information, and precise location history. The Customer determines the lawful purpose and scope.
3. Why we use data and the legal basis
- Registration, the contract, accounts, and support: to take steps requested before a contract and perform it (Art. 6(1)(b) GDPR). Where the Customer is an organisation and you act for it, our basis is our legitimate interest in concluding and administering the business relationship (Art. 6(1)(f)).
- Payments, invoicing, tax, and accounting: to perform the contract and comply with legal obligations (Art. 6(1)(b) and (c)).
- Security, abuse prevention, troubleshooting, service analytics, and improvement: our legitimate interests in protecting and operating a reliable service and understanding aggregate use (Art. 6(1)(f)). We minimise event properties and do not use advertising networks.
- Contact, waitlist, and Partner enquiries: your request and steps towards a contract (Art. 6(1)(b)) or our legitimate interest in responding to business enquiries (Art. 6(1)(f)).
- Marketing messages: your consent (Art. 6(1)(a) GDPR and applicable electronic-communications law). Consent is optional and may be withdrawn at any time without affecting earlier lawful processing.
- Complaints, legal claims, regulatory requests, and illegal-content notices: legal obligations (Art. 6(1)(c)) and our legitimate interest in establishing, exercising, or defending claims and keeping the service lawful (Art. 6(1)(f)).
Where we rely on legitimate interests, you may object for reasons relating to your situation. You may object to direct marketing at any time and we will stop using your data for that purpose.
4. Is providing data required?
Fields marked as required are needed to process the request, create or administer an account, or meet a legal requirement. Without them, we may be unable to respond or provide the service. Marketing consent and fields marked optional are not required. The Customer decides which data its users must enter into the workspace.
5. Recipients and integrations
Access is limited to authorised staff and suppliers who need it. Depending on the features used, recipients may include:
- hosting, storage, backup, and security: OVHcloud, Amazon Web Services, and Cloudflare;
- payments and invoicing: Stripe and Fakturownia.pl; Stripe generally acts as an independent controller for regulated payment processing;
- communications: EmailLabs, SMSAPI.pl, and Google Firebase Cloud Messaging;
- service analytics: the operator of the configured Umami analytics endpoint, where analytics is enabled;
- maps and routing: HERE, Google Maps Platform, Mapbox, and the provider of an activated Protomaps tile source;
- AI, voice transcription, and speech synthesis: OpenRouter, the model provider selected for an activated AI feature, and ElevenLabs where its speech-to-text or text-to-speech service is configured;
- Customer-selected integrations: telematics, accounting, KSeF, or other providers configured by the Customer.
We may also disclose data to professional advisers, insurers, banks, courts, regulators, or public authorities where necessary and lawful. A provider may be our processor, our sub-processor, or an independent controller depending on the service. Current feature-specific information is also shown in the System or integration documentation.
6. Maps, GPS, and AI
- Map, search, and routing functions may send coordinates, addresses or search terms, and technical request data to the selected provider. We minimise direct identifiers, but geographic data is not necessarily anonymous.
- When a Customer uses GPS or personnel-monitoring features, the Customer is responsible for the legal basis, employee or driver notices, access rules, and retention. We provide the technical service and process the data under the DPA.
- AI features are identified in the interface. Prompts, attachments, relevant workspace context, voice recordings, message text sent for text-to-speech synthesis (voice playback of translated messages), and generated output may be sent to OpenRouter, the selected model provider, or ElevenLabs to answer the request. Text-based OpenRouter requests are configured to reject endpoints that OpenRouter identifies as collecting request content and to require zero-data-retention routing; if no compatible endpoint is available, that request fails. Dedicated transcription and speech-synthesis routes and Customer-selected providers may have different retention controls, which are governed by the applicable processor terms and account configuration. CodeJungle does not use Customer Content to train a general-purpose model without separate express permission. Users should minimise personal data and review output before relying on it.
7. International transfers
Core production hosting and storage are in the European Union. Some suppliers or activated integrations may process limited data outside the EEA or allow support access from there. Where required, we use an adequacy decision (including the EU-US Data Privacy Framework for a participating recipient), the European Commission's Standard Contractual Clauses with supplementary measures where appropriate, or another lawful GDPR Chapter V mechanism. You may request information about the relevant safeguard or a copy, with protected commercial information redacted, at contact@litetms.eu.
8. How long we keep data
- Customer workspace data: for the contract, transition and retrieval periods described in the Terms and DPA. After the retrieval period it is deleted from active systems unless law requires retention. Disaster-recovery backups expire under the rotation cycle, which may take up to 12 months, and remain isolated from ordinary use.
- Accounts, contracts, billing, and tax records: for the relationship and then for the limitation, tax, and accounting periods required by law.
- Enquiries, waitlist, and Partner applications: until the request is resolved or participation ends, then for the period needed to document the relationship or defend claims. An unconverted lead is reviewed periodically and deleted when no longer needed.
- Marketing consent records and suppression lists: while consent is active and afterwards for the period needed to demonstrate compliance or ensure that an opt-out is respected.
- Security, audit, and technical logs: for the period reasonably needed to secure the service, investigate incidents, and establish claims; the exact period depends on the log and risk.
When we no longer need data, we delete or anonymise it. A legal hold, dispute, or authority request may extend the relevant period.
9. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, and portability of your data; object to processing based on legitimate interests; and withdraw consent at any time. You may complain to the supervisory authority, in Poland the President of the Personal Data Protection Office (Prezes UODO), or to the authority for your habitual residence, workplace, or alleged infringement.
Send a request to contact@litetms.eu. We may need to verify your identity. Rights are not absolute; if we cannot fulfil a request, we will explain the legal reason.
10. Automated decisions, security, cookies, and changes
- CodeJungle does not make decisions about website visitors, leads, or account representatives based solely on automated processing that produce legal or similarly significant effects. AI suggestions do not make binding operational or employment decisions for the Customer.
- We use technical and organisational safeguards appropriate to risk, including transport encryption, access controls, roles and permissions, tenant isolation, backups, logging, and incident handling. No service can guarantee absolute security.
- Cookies, browser storage, Turnstile, and Umami analytics are explained in the Cookies and Similar Technologies Policy.
- We may update this notice when processing or law changes. We will publish the new version and date; material changes will be communicated through an appropriate channel. Earlier versions are available on request.