AITRACK / LEGAL INFORMATION
Privacy Policy
Aitrack privacy notice: website and platform data, purposes, roles, retention, service providers and your data protection rights.
Updated: 4 October 2026 · Version 1.0Scope of this notice
This notice distinguishes the presentation website from Aitrack platform services. Browsing this website does not create an account, activate GPS or collect your device location. Demo maps and vehicles do not represent your location. Sections about accounts, drivers, payments and artificial intelligence apply when you use the relevant platform services.
Data and services on this website
The website is hosted on Cloudflare Pages. HTTP requests involve technical data such as IP address, user-agent, requested resources and timestamps for website delivery and security (legitimate interests, GDPR Art. 6.1.f). Fonts and images are hosted on this website. The interactive coverage map uses OpenStreetMap: loading tiles shares your IP address and request data with the OpenStreetMap Foundation; see the OSMF privacy policy.
The contact form prepares a draft in your email application: it does not automatically submit or store its content on the website server. If you send the email, we process the received data to reply, assess pre-contractual requests (Art. 6.1.b) or handle other relevant communications (Art. 6.1.f). Requested data helps us handle your enquiry; without contact details we may be unable to reply. Do not include passwords, API keys or unnecessary personal data. Correspondence is retained as needed to handle the enquiry, meet applicable obligations or protect legal rights; contact [email protected] for further details.
Google Analytics 4 loads only after consent to analytics. Our tag does not enable personalised advertising or Google Signals. Consent is optional and can be withdrawn; refusing it does not prevent browsing. The Cookie Policy explains identifiers, duration and preferences. Store, social and platform links open separate services governed by their own notices.
1. Data controller
The data controller for data collected through this site and for customer administrator accounts is Nicola Tomassini, Italian VAT ID 02887590418 (sole trader under the Italian flat-rate tax scheme).
Contact: [email protected].
For data processed on behalf of customers (see the "Roles" section), the customer is the controller and Aitrack acts as processor.
2. Roles: controller and processor
Aitrack is a B2B fleet management platform. We take on two distinct roles when processing data:
As controller, for site visitors' data and for customers' administrator accounts (registration, sign-in, billing, support).
As processor (Art. 28 GDPR), for data we process on behalf of the customer as part of the service, in particular device positions and driver data. Here the customer is the controller and determines purposes and means; Aitrack processes the data only on the customer's instructions, under a data processing agreement (DPA).
If you are a driver or an employee of one of our customers, to exercise your rights you should contact your employer (the controller); we assist them as processor.
3. Data we process
We process the following categories of data:
- Account and contact: name, surname, email, phone, username, authentication provider.
- Credentials: password (stored only as a bcrypt hash) and, if enabled, two-factor authentication.
- Location: latitude, longitude, speed, heading and time of GPS devices, with route history.
- Driving events: accelerations, braking, idling, speeding.
- Driver records and RFID badges: when the customer uses driver identification.
- Activity log (audit): administrator actions, IP address, user agent.
- Payments: amounts, last 4 digits of the card and customer identifier at the payment provider; we never process the full card number.
- Notifications: push notification tokens and service email subjects.
- Support: tickets, category and messages sent to support.
- AI assistant conversations: questions and answers, which may contain device or place names.
- Site technical data: see the Cookie Policy.
We do not process special categories of data (Art. 9 GDPR): no biometric, health or trade-union data. Location can indirectly reveal sensitive information: for this reason we apply data minimisation and restrict access to people authorised by the customer.
4. Location and driver monitoring
Location monitoring is the core function of the service and is carried out on behalf of the customer (controller). The data is collected by GPS devices installed on the customer's assets.
When monitoring concerns assets assigned to workers, the customer must comply with applicable remote-monitoring law (in Italy, Article 4 of the Workers' Statute, with the required union agreements or authorisations) and adequately inform data subjects. Aitrack provides supporting tools, such as per-user access permissions, defined retention periods and activity logs.
5. Purposes and legal bases
We process data for the following purposes, on the corresponding legal bases:
- Providing the service (account, tracking, history, alerts, reports): performance of the contract (Art. 6.1.b); for driver data, a lawful basis identified and documented by the customer-controller.
- Security and abuse prevention (activity log, rate limiting): legitimate interest (Art. 6.1.f) and legal obligations (Art. 6.1.c).
- Billing and tax obligations: legal obligation (Art. 6.1.c) and performance of the contract.
- Customer support: performance of the contract.
- Site statistics: consent (Art. 6.1.a); see Cookie Policy.
6. Retention period
We keep data for as long as necessary for the purposes and, in any case:
- Account data: for the duration of the relationship and up to 30 days after a deletion request.
- Location and route history: depending on the plan, from 30 days (base plan) up to 12 months (professional plans); Enterprise plans can reach 36 months on request. The limit also applies to heatmaps, replay and reports.
- Real-time position: cached for 24 hours.
- Driving events: aligned with history retention.
- Activity log (audit): 12 months (configurable).
- Billing data: 10 years, for tax obligations (Art. 2220 Italian Civil Code).
- Session (refresh) tokens: up to 30 days after last use.
- Data export links: valid for 7 days, then they expire.
On expiry, data is permanently deleted or anonymised.
7. Providers and processors
To provide the service we rely on selected providers, who process data as processors on our instructions:
- Amazon Web Services (AWS): infrastructure hosting (European Union).
- Cloudflare: content delivery, DNS and attack protection.
- Stripe: payment processing.
- Artificial intelligence providers (Anthropic, OpenAI, Google): only for AI features and only on aggregated data (see "Artificial intelligence").
- Google: platform services where used; on this website, Google Analytics 4 only with consent. Website fonts are local.
- Email and push notification providers: sending service communications and notifications.
With each provider that processes personal data we enter into a data processing agreement (DPA) under Art. 28 GDPR. An up-to-date list of providers is available on request at [email protected].
8. Transfers outside the EU
Some providers (in particular AI services, payments and push notifications) may process data outside the European Union, typically in the United States.
In such cases, transfers rely on the safeguards under Chapter V of the GDPR (Arts. 44-49), such as the European Commission's Standard Contractual Clauses and, where applicable, the provider's participation in the EU-US Data Privacy Framework. We are finalising the formalisation of all transfer safeguards; for the current status you can write to us at [email protected].
9. Data security
We adopt appropriate technical and organisational measures, including:
- Encryption in transit (TLS).
- Passwords protected with bcrypt hashing and two-factor authentication available.
- Authentication with signed, expiring and revocable tokens.
- History integrity via a cryptographic chain (SHA-256 hash-chain): positions are tamper-evident and verifiable.
- Access control with per-customer isolation, request rate limiting and an activity log.
In the event of a personal data breach that poses a risk to data subjects' rights, we notify the supervisory authority within 72 hours and, where required, inform data subjects without undue delay.
10. Artificial intelligence and automated decision-making
The service includes artificial intelligence features and automatic alerts. As a provider under Regulation (EU) 2024/1689 (AI Act), we transparently explain how they work.
Automatic alerts: rules that generate notifications when events occur (e.g. speeding, entering an area, tampering). These are purely informational tools.
AI features: driving behaviour analysis, fine estimation, predictive maintenance, assisted automation building and a report assistant. Regarding these features:
- No automated decision with legal or similarly significant effects is made about individuals (Art. 22 GDPR): outputs are supportive, always subject to the customer's human oversight and open to being contested and changed.
- AI outputs are clearly presented as such and, where applicable, their factors are shown (no "black box"); you have the right to an explanation.
- Raw location data is never sent to language models: only aggregated data reaches the AI. Customer data is not used to train third-party models.
The impact assessments (DPIA under the GDPR and FRIA under the AI Act) for these features are being finalised.
11. Your rights
You can exercise the rights under Arts. 15-22 GDPR at any time: access, rectification, erasure, restriction, portability, objection and withdrawal of consent.
From the platform you can:
- Export your data in a readable format (JSON), including a full package sent by email with an expiring link.
- Delete your account: the request immediately disables access and data is permanently erased after 30 days.
- Rectify your name and email from settings.
If you are a driver or an employee of one of our customers, address your requests to your employer (the controller). For any other request, write to us at [email protected]: we respond without undue delay, normally within one month, subject to a reasoned extension where GDPR Article 12 permits.
12. Right to lodge a complaint
If you believe the processing of your data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. In Italy this is the Garante per la protezione dei dati personali (garanteprivacy.it). You may also contact the authority of the EU Member State where you reside.
13. Cookies
This site uses cookies and similar technologies. For details on the tools we use, their purposes and how to manage consent, see the Cookie Policy.
14. Changes to this policy
We may update this notice to reflect changes in the service or in the law. The updated version is always published on this page, with the last-updated date at the top. We will highlight any material changes.