Data processing agreement
This Data Processing Agreement (the “Agreement”) forms part of the Terms of Service and applies when the customer (the “Controller”) uses AppAlbania GPS to process personal data and AppAlbania, Tiranë, Shqipëri (the “Processor”) processes it on the Controller's behalf, in accordance with Albanian personal data protection legislation.
1. Subject and duration
The Processor provides the GPS tracking platform and related services. Processing lasts while the service is active and until the data is deleted under section 9.
2. Nature and purpose of processing
Collection, storage, display, analysis and transmission of location and vehicle data for fleet management, vehicle security, reporting and the notifications the Controller configures.
3. Categories of data and data subjects
- Data subjects: the Controller's drivers, employees, contractors and customers who use tracked vehicles; panel users.
- Data: GPS position, time, speed, heading, engine status and vehicle sensors, device identifier, plate number, driver name and contact, alerts and reports.
- The platform is not designed for special categories of data. The Controller must not enter them in notes or free-text fields.
4. Controller obligations
- Has a legal basis for tracking and informs data subjects in advance (for example with the employee notice).
- Sets clear rules for private use of vehicles and for periods outside working hours.
- Gives panel access only to people who need it and responds to data subject requests.
5. Processor obligations
- Processes data only on the Controller's documented instructions (the panel configuration and these Terms), unless the law requires otherwise.
- Ensures that staff with access are bound by confidentiality.
- Applies the technical and organisational measures in section 6.
- Reasonably assists the Controller in answering data subject requests and in impact assessments.
- Notifies the Controller without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach.
6. Security measures
- encryption in transit (HTTPS/TLS) and encryption of secrets at rest;
- logical separation of each customer's data, tested at every access point;
- mandatory two-step verification for staff, logging of important actions;
- tracking servers do not expose their administration interface to the internet;
- daily backups and a documented restore procedure.
7. Sub-processors
The Controller authorises the sub-processors needed for the service: server and data-centre providers, Cloudflare, our email provider, the AppAlbania WhatsApp gateway, our SMS provider and, when enabled, Telegram, Stripe and map services. We notify you in advance of new sub-processors; you may object on reasonable grounds within 15 days.
8. International transfers
Where data is transferred outside Albania, this happens only to countries with an adequate level of protection or with appropriate safeguards, as required by law.
9. Return and deletion
During the service the Controller can export data from the panel. History is deleted automatically according to the plan's retention period. After the service ends, data is deleted within 30 days unless the law requires it to be kept.
10. Audit
On reasonable request and with prior notice, the Processor provides the information needed to demonstrate compliance with this Agreement.
11. Data protection contact
AppAlbania · info@appalbania.com · +355 67 496 3486