LiteTMS.eu Privacy Policy
This notice explains, in plain language, how CodeJungle handles personal data on the LiteTMS website, during sales and support, and when operating the LiteTMS platform. It also explains when the Customer, rather than CodeJungle, decides why data is used.
1. Who is responsible
- Controller: CodeJungle Sp. z o. o., Kawki 51, 42-140 Panki, Poland, KRS: 0000722231, NIP: 5742064222, REGON: 369658794 ("CodeJungle", "we"). Contact us about privacy at contact@litetms.eu or by post at the address above.
- We are the controller for the website, registration and account administration, sales and partner contacts, marketing consents, billing, security, legal compliance, and our own business records.
- The Customer is normally the controller for personal data it enters into its workspace, such as employee, driver, contractor, customer, order, document, and GPS data. For that data, we act as processor under the Data Processing Agreement, except where law requires us to use limited data for our own security, fraud-prevention, billing, or legal-compliance purposes.
- If your data was entered by a Customer, please contact that Customer first to exercise your rights. We will assist it as required by the DPA.
2. Data we obtain and where it comes from
- From you: name, business and contact details, account data, communications, support requests, billing details, preferences, and consent records.
- From use of the website or platform: IP address, device and browser information, session and security events, audit logs, feature and page events, timestamps, and approximate location derived from network data.
- From others: an employer or Customer account administrator, a referral Partner, public business registers such as KRS or GUS, and payment, communications, identity, security, mapping, or integration providers.
- Customer-controlled content: the categories depend on the Customer's use and may include professional and employment data, identifiers, addresses, communications, documents, images, voice recordings, vehicle-linked information, and precise location history. The Customer determines the lawful purpose and scope.
3. Why we use data and the legal basis
- Registration, the contract, accounts, and support: to take steps requested before a contract and perform it (Art. 6(1)(b) GDPR). Where the Customer is an organisation and you act for it, our basis is our legitimate interest in concluding and administering the business relationship (Art. 6(1)(f)).
- Payments, invoicing, tax, and accounting: to perform the contract and comply with legal obligations (Art. 6(1)(b) and (c)).
- Security, abuse prevention, troubleshooting, service analytics, and improvement: our legitimate interests in protecting and operating a reliable service and understanding aggregate use (Art. 6(1)(f)). We minimise event properties and do not use advertising networks.
- Contact, waitlist, and Partner enquiries: your request and steps towards a contract (Art. 6(1)(b)) or our legitimate interest in responding to business enquiries (Art. 6(1)(f)).
- Marketing messages: your consent (Art. 6(1)(a) GDPR and applicable electronic-communications law). Consent is optional and may be withdrawn at any time without affecting earlier lawful processing.
- Complaints, legal claims, regulatory requests, and illegal-content notices: legal obligations (Art. 6(1)(c)) and our legitimate interest in establishing, exercising, or defending claims and keeping the service lawful (Art. 6(1)(f)).
Where we rely on legitimate interests, you may object for reasons relating to your situation. You may object to direct marketing at any time and we will stop using your data for that purpose.
4. Is providing data required?
Fields marked as required are needed to process the request, create or administer an account, or meet a legal requirement. Without them, we may be unable to respond or provide the service. Marketing consent and fields marked optional are not required. The Customer decides which data its users must enter into the workspace.
5. Recipients and integrations
Access is limited to authorised staff and suppliers who need it. Depending on the features used, recipients may include:
- hosting, storage, backup, and security: OVHcloud (hosting), Cloudflare (network security; files and backups are stored in Cloudflare R2), and Amazon Web Services or another storage provider in the EU, where we keep extra copies there or move storage to it;
- payments and invoicing: Stripe and Fakturownia.pl; Stripe generally acts as an independent controller for regulated payment processing;
- communications: EmailLabs, SMSAPI.pl, and Google Firebase Cloud Messaging;
- service analytics: the operator of the configured Umami analytics endpoint, where analytics is enabled;
- maps and routing: HERE, Google Maps Platform, Mapbox, and the provider of an activated Protomaps tile source;
- AI, voice transcription, and speech synthesis: OpenRouter and the AI model providers to which it routes requests (the provider of the selected model or a provider operating an endpoint for it), and ElevenLabs where its speech-to-text or text-to-speech service is configured;
- AI apps a user connects: the provider of an AI app that a user connects to their account, which processes the data under its own terms and is not our sub-processor (section 7);
- Customer-selected integrations: telematics, accounting, KSeF, or other providers configured by the Customer.
We may also disclose data to professional advisers, insurers, banks, courts, regulators, or public authorities where necessary and lawful. A provider may be our processor, our sub-processor, or an independent controller depending on the service. Current feature-specific information is also shown in the System or integration documentation.
6. Maps, GPS, and AI
- Map, search, and routing functions may send coordinates, addresses or search terms, and technical request data to the selected provider. We minimise direct identifiers, but geographic data is not necessarily anonymous.
- When a Customer uses GPS or personnel-monitoring features, the Customer is responsible for the legal basis, employee or driver notices, access rules, and retention. We provide the technical service and process the data under the DPA.
- AI features that users interact with are identified in the interface. Some AI features also run automatically while they are active, for example to sort incoming driver messages, check whether a company, place, or list entry already exists, suggest import column mappings, or check a message's language before translating it. Prompts, attachments, relevant workspace context, voice recordings, message text sent for text-to-speech synthesis (voice playback of translated messages), and generated output may be sent to OpenRouter, an AI model provider to which OpenRouter routes the request, or ElevenLabs to answer the request or run the check. Text-based OpenRouter requests are configured to reject endpoints that OpenRouter identifies as collecting request content and to require zero-data-retention routing; if no compatible endpoint is available, that request fails. The AI model used by a feature may change over time within these conditions. Dedicated transcription and speech-synthesis routes and Customer-selected providers may have different retention controls, which are governed by the applicable processor terms and account configuration. CodeJungle does not use Customer Content to train a general-purpose model without separate express permission. Users should minimise personal data and review output before relying on it.
7. AI apps you connect yourself
- When the Customer has turned on the “ChatGPT, Claude & MCP” module, each user may connect an AI app of their choice, such as ChatGPT, Claude, or another app that supports the Model Context Protocol (MCP), to their own LiteTMS account. The app signs in as that user and works only within that user's role and permissions, so it can receive any workspace data that user can see (section 2), for example names, contact details, documents and their expiry dates, vehicles, and reminders. Before agreeing, the user sees what the app asks to read and what it may change.
- The app and the AI model behind it are provided by the app's provider (for example, OpenAI for ChatGPT or Anthropic for Claude), not by CodeJungle. The data the app obtains from LiteTMS reaches that provider and is processed under its own terms and privacy notice, which decide whether it is stored, where it is processed (possibly outside the EEA), and whether it is used to train models. The provider is not our sub-processor, and the zero-data-retention routing described in section 6 does not apply to it.
- LiteTMS receives the requests the app sends, such as a search term or the text of a reminder, and technical data such as the app's name, its web address, and the network address it connects from. We do not receive the user's conversation with the app.
- We keep a record of each connection in the Customer's workspace (the app, the permissions granted, and when it was made and last used). The audit log records each connection, each change, and each request (the tool used and whether it succeeded, not what was asked or answered). The user can see and end their connections in Settings, under Connected apps, and the Customer's account administrators can see and end all of them. A connection also ends after 30 days without use and in any case 180 days after it was made, and it does not work while the module is off or the user's account is inactive. We process these records to provide the connection and keep it secure, on the legal bases in section 3, and keep them as described in section 9.
- For workspace data that the app receives, the Customer remains the controller, and CodeJungle transmits the data at the Customer's request under §5.8 of the Data Processing Agreement. The Customer decides whether to allow AI apps and what each role may see, and is responsible for the legal basis, for informing the people whose data may be shared (for example, drivers and employees), and for its arrangements with the app's provider, including any transfer outside the EEA. To exercise rights over data that an app's provider holds, contact that provider or the Customer. Users should share only what a task needs and check the app's answers before relying on them.
8. International transfers
Core production hosting and storage are in the European Union. Some suppliers or activated integrations may process limited data outside the EEA or allow support access from there. Where required, we use an adequacy decision (including the EU-US Data Privacy Framework for a participating recipient), the European Commission's Standard Contractual Clauses with supplementary measures where appropriate, or another lawful GDPR Chapter V mechanism. You may request information about the relevant safeguard or a copy, with protected commercial information redacted, at contact@litetms.eu. For an AI app that a user connects (section 7), the app's provider decides under its own terms where the app processes data. Where sending data to the app is a transfer outside the EEA, §5.8 of the DPA bases it on an adequacy decision covering that provider or on the safeguards in the Customer's agreement with it.
9. How long we keep data
- Customer workspace data: for the contract, transition and retrieval periods described in the Terms and DPA. After the retrieval period it is deleted from active systems unless law requires retention. Disaster-recovery backups expire under the rotation cycle, which may take up to 12 months, and remain isolated from ordinary use.
- Accounts, contracts, billing, and tax records: for the relationship and then for the limitation, tax, and accounting periods required by law.
- Enquiries, waitlist, and Partner applications: until the request is resolved or participation ends, then for the period needed to document the relationship or defend claims. An unconverted lead is reviewed periodically and deleted when no longer needed.
- Marketing consent records and suppression lists: while consent is active and afterwards for the period needed to demonstrate compliance or ensure that an opt-out is respected.
- Security, audit, and technical logs: for the period reasonably needed to secure the service, investigate incidents, and establish claims; the exact period depends on the log and risk.
When we no longer need data, we delete or anonymise it. A legal hold, dispute, or authority request may extend the relevant period.
10. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, and portability of your data; object to processing based on legitimate interests; and withdraw consent at any time. You may complain to the supervisory authority, in Poland the President of the Personal Data Protection Office (Prezes UODO), or to the authority for your habitual residence, workplace, or alleged infringement.
Send a request to contact@litetms.eu. We may need to verify your identity. Rights are not absolute; if we cannot fulfil a request, we will explain the legal reason.
11. Automated decisions, security, cookies, and changes
- CodeJungle does not make decisions about website visitors, leads, or account representatives based solely on automated processing that produce legal or similarly significant effects. AI suggestions do not make binding operational or employment decisions for the Customer.
- We use technical and organisational safeguards appropriate to risk, including transport encryption, access controls, roles and permissions, tenant isolation, backups, logging, and incident handling. No service can guarantee absolute security.
- Cookies, browser storage, Turnstile, and Umami analytics are explained in the Cookies and Similar Technologies Policy.
- We may update this notice when processing or law changes. We will publish the new version and date; material changes will be communicated through an appropriate channel. Earlier versions are available on request.