1. Data Controller
The data controller responsible for your personal data is:
Uptimus ApS
Hans Jensens Vej 19
2900 Hellerup, Denmark
CVR: 43 33 52 35
Email: info@uptimus.dk
2. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR Article 6:
- Contractual necessity (Art. 6(1)(b)): Processing necessary to provide the fleet management services you or your employer have contracted for, including account management, vehicle tracking, trip recording, internal messaging, and related features.
- Legitimate interest (Art. 6(1)(f)): Processing necessary for our legitimate business interests, such as improving our services, preventing fraud, ensuring platform security, and content moderation. We balance these interests against your rights and freedoms.
- Legal obligation (Art. 6(1)(c)): Processing necessary to comply with applicable laws, such as tax regulations, employment law, and road safety requirements.
- Consent (Art. 6(1)(a)): Where required, such as for background location access on your device. You may withdraw consent at any time without affecting the lawfulness of prior processing.
3. Personal Identification Information
We collect personal identification information from users when they register for the Platform, are invited by their organization, fill out forms, or use our services. This may include:
- Full name, email address, and phone number
- Driver’s license information and license categories
- CPR number (Danish social security number) — collected only when required for driver compliance verification, processed under strict access controls, and never shared with third parties beyond what is legally required
- Profile photo
- Employment information (role, organization)
- Biometric authentication tokens (fingerprint/face ID references — we store a cryptographic token, not the biometric data itself)
Personal identification information is collected only when voluntarily submitted or when provided by your organization’s administrator as part of the service.
4. Location Data
- Device Location: With your permission, our apps access your device’s precise location. In the driver app, this includes background location access to track trips, routes, and driver position while driving. In the manager app, this is used to display your position on the fleet map.
- Vehicle Location: The apps collect and display GPS coordinates from connected vehicles and telemetry devices for the purpose of fleet tracking, route history, and location-based alerts. This data is stored on our servers and is accessible only to authorized users within your organization.
- Third-Party Services: Location data may be shared with Google Maps for the purpose of rendering maps and calculating routes within the apps. Google’s use of this data is governed by their own privacy policy.
5. Communication Data
The Platform provides internal messaging and communication features that allow users within the same organization to communicate. When you use these features, we collect and store:
- Messages: The content of messages you send and receive, including text, images, and file attachments
- Metadata: Timestamps, sender and recipient identifiers, conversation participants, and read receipts (when messages are viewed by recipients)
- Comments: Comments posted on vehicles, tasks, inspections, service records, and damage reports, including mentions of other users and emoji reactions
- Support conversations: Messages exchanged with our support team, including any files shared
Who can access your messages: Messages are accessible to the conversation participants and may be accessible to administrators within your organization. Uptimus support staff may access messages only when necessary to provide technical support or respond to reports of misuse. Messages are scoped to your organization — users in other organizations cannot see your messages.
Important: When you delete a message, it is marked as deleted and no longer visible to participants, but the record may be retained in our systems for a limited period for legal compliance and dispute resolution purposes (see Section 10: Retention).
6. User-Generated Content
The Platform allows users to create and share content, including:
- Vehicle inspection reports and photos
- Damage reports with images
- Comments and activity notes on fleet records
- Documents (driver’s licenses, compliance certificates, invoices)
- Messages and attachments sent through the internal messaging system
User-generated content is stored within your organization’s account and is subject to the access controls set by your organization’s administrators.
7. Non-personal Identification Information
We collect non-personal identification information about users whenever they interact with the Platform. This may include device type, operating system, browser name, app version, and technical information about your means of connection, such as Internet service provider and similar information.
8. How We Use Collected Information
We collect and use information for the following purposes:
- Service delivery: To provide fleet management services, including vehicle tracking, trip recording, inspection management, and internal communication features
- Internal messaging: To facilitate communication between users within the same organization, deliver message notifications, and maintain conversation history
- Customer support: To respond to your requests, questions, and support needs
- Safety and compliance: To monitor driver compliance, vehicle condition, and generate alerts for safety-critical events
- Content moderation: To review reported messages and enforce our acceptable use policy
- Service improvement: To understand how users interact with the Platform and improve our services
- Communications: To send service-related notifications, updates, and security alerts. You may opt out of non-essential communications at any time
9. Content Moderation, Blocking, and Reporting
To ensure a safe and professional environment, the Platform provides the following tools:
- Report a message: You can report any message you find inappropriate or offensive. Reports are reviewed by our team and appropriate action is taken. You may optionally provide a reason for the report.
- Block a user: You can block another user to prevent them from sending you messages. You may unblock a user at any time. Blocking is private — the other user is not notified.
- Content filtering: We employ measures to detect and prevent the distribution of objectionable content through the Platform.
When you submit a report, we store the reported message, your identity as the reporter, the reason provided (if any), and the outcome of the review. Reports are reviewed within 24 hours. We may take actions including removing content, issuing warnings, or restricting account access.
10. Retention of Information
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:
- Account data: Retained for the duration of the business relationship between Uptimus and your organization, and for up to 12 months after account termination
- Messages and communication data: Retained for the duration of the business relationship. After account deletion, message content is deleted within 90 days, though anonymized metadata may be retained longer for service improvement
- Location and trip data: Retained for the duration of the business relationship as part of fleet management records
- Reports and moderation records: Retained for up to 24 months to support dispute resolution and legal compliance
- Compliance documents: Retained in accordance with applicable legal requirements (e.g., driver’s license records as required by transport regulations)
- Invoices and financial data: Retained for 5 years in accordance with Danish bookkeeping law (Bogføringsloven)
11. How We Protect Your Information
We adopt appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Multi-tenant data isolation — each organization’s data is logically separated and inaccessible to other organizations
- Role-based access controls within organizations
- Regular security assessments and monitoring
- Secure credential storage with hashed passwords
12. Sub-processors and Third-Party Services
We use the following third-party service providers to operate the Platform. Your data may be processed by these providers in accordance with their own privacy policies and our data processing agreements:
- Hetzner Online GmbH (Germany): Cloud hosting and object storage
- Stripe, Inc. (USA): Payment processing and billing — processes name, email, and billing address
- High Mobility GmbH (Germany): Vehicle telemetry data — processes vehicle identification numbers (VIN) and vehicle data
- Microsoft Azure (EU): Document intelligence services for invoice processing
- Google Maps Platform (USA): Map rendering and route calculation — processes location coordinates
- Expo / React Native (USA): Push notification delivery — processes device tokens and notification content
Where data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place, such as EU Standard Contractual Clauses (SCCs) or adequacy decisions by the European Commission.
13. Sharing Your Personal Information
We do not sell, trade, or rent your personal identification information to third parties. We may share your data in the following circumstances:
- Within your organization: Your organization’s administrators can access user data, messages, and activity within the Platform as part of fleet management operations
- With partner organizations: If your organization uses the vehicle sharing feature, limited vehicle data may be shared with partner organizations under a GDPR Article 26 joint controllership agreement. Only data explicitly permitted by your organization’s administrator is shared.
- With sub-processors: As described in Section 12 above
- Legal requirements: When required by law, regulation, legal process, or governmental request
14. Your Rights
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
- Right of access (Art. 15): You may request a copy of the personal data we hold about you
- Right to rectification (Art. 16): You may request correction of inaccurate or incomplete data
- Right to erasure (Art. 17): You may request deletion of your personal data, subject to legal retention requirements
- Right to restriction (Art. 18): You may request that we limit how we process your data
- Right to data portability (Art. 20): You may request your data in a structured, commonly used, machine-readable format
- Right to object (Art. 21): You may object to processing based on legitimate interests
- Right to withdraw consent (Art. 7): Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at info@uptimus.dk. We will respond within 30 days. If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) at dt@datatilsynet.dk.
15. Changes to This Privacy Policy
Uptimus ApS may update this privacy policy at any time. When we do, we will revise the updated date at the bottom of this page and, for material changes, notify users through the Platform or by email. We encourage users to review this page periodically to stay informed about how we protect your personal information.
16. Your Acceptance of These Terms
By using the Platform, you signify your acceptance of this policy. If you do not agree to this policy, please do not use the Platform. Your continued use of the Platform following the posting of changes to this policy will be deemed your acceptance of those changes.
17. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how your data is handled, please contact us at info@uptimus.dk.
This document was last updated on March 29, 2026.