Legal · Last updated September 2026

Privacy Policy

1. Data controller

The data controller responsible for your personal data is:

Asset Track Sp. z o.o.
ul. Marszalkowska 115/338
00-102 Warszawa, Poland

KRS: 0001072405
NIP: 5252982554
REGON: 527071236

Email: privacy@theassettrack.com

2. What data we collect

We collect and process the following categories of personal data:

2.1 Account data

  • Email address and name
  • Company or workspace name
  • Role within the workspace
  • Authentication data (password hashes and session records — never a plaintext password)

2.2 Business records you enter

A FleetERP workspace holds the records of your own operation. Where those records identify a person — a customer contact, or the technician named on a job form — you are the controller of that data and we process it on your behalf:

  • Customer, division and contact records
  • Assets and the device identifiers fitted to them
  • Job forms, including who carried out the work and when
  • SIM cards and their receive, activation and deactivation registers
  • Quotations, invoices, credit notes, payments, contracts and subscriptions
  • The mail account the workspace sends from, with its password stored encrypted
  • Attachments and the per-record activity log

2.3 Technical data

  • IP address
  • Browser type and version
  • Device information
  • Pages visited and features used

2.4 Enquiry data

  • The name, email address and message you send through the contact form on this website

3. Legal basis for processing

We process your personal data based on:

  • Contract performance (Art. 6(1)(b) GDPR) — To provide FleetERP services
  • Legitimate interests (Art. 6(1)(f) GDPR) — For analytics, security, responding to enquiries and service improvements
  • Legal obligation (Art. 6(1)(c) GDPR) — When required by law

4. How we use your data

  • Provide and operate your workspace, including authentication and role-based access
  • Store and serve the business records you enter
  • Send service-related communications, and email from your workspace using credentials you configure
  • Respond to enquiries made through this website
  • Improve the product and the user experience
  • Ensure security and prevent abuse

5. Data sharing

We may share your data with:

  • Service providers — Hosting, analytics, and the CRM that receives contact-form enquiries
  • Legal authorities — When required by law

We do not sell your personal data to third parties.

6. International transfers

Your data may be transferred outside the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Transfers to countries with adequate data protection laws

7. Data retention

  • Account data — Duration of your account + 30 days
  • Workspace records — For the duration of your agreement, then deleted or returned as agreed
  • Billing records — 5 years (legal requirement)
  • Analytics data — 26 months (anonymised)
  • Enquiries — Retained in the CRM for as long as the enquiry is live, and no longer than 24 months

8. Your rights

Under GDPR, you have the right to:

  • Access — Request a copy of your personal data
  • Rectification — Correct inaccurate or incomplete data
  • Erasure — Request deletion of your data ("right to be forgotten")
  • Restriction — Limit how we process your data
  • Portability — Receive your data in a machine-readable format
  • Objection — Object to processing based on legitimate interests
  • Withdraw consent — Withdraw consent at any time

To exercise these rights, contact us at privacy@theassettrack.com.

9. Cookies

This website and the application use cookies for:

  • Essential cookies — Authentication and session management
  • Preference cookies — Display settings such as light or dark mode
  • Analytics cookies — Privacy-focused usage analytics

You can control cookies through your browser settings.

10. Security

  • Encryption in transit (TLS/SSL) and at rest
  • Workspace-scoped access on every read and write, enforced server-side rather than in the interface
  • Role-based permissions on every operation
  • Outbound email credentials encrypted at rest
  • Access controls, authentication, and a per-record activity log

11. Children's privacy

FleetERP is a business service not intended for individuals under 18 years of age. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date.

13. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Polish Data Protection Authority:

Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2
00-193 Warszawa, Poland
Website: uodo.gov.pl

14. Contact us