GDPR
AutoDeck’s data-protection roles, controls and request paths.
Last updated: 8 September 2026
Controller and processor roles
Each dealership controls the customer and staff data it enters in AutoDeck DMS; the AutoDeck operator processes that data for the dealership. AutoDeck may separately control subscriber-account, billing and public-site data. The DPA template records the processor duties.
Data-subject rights
The service supports access/export, rectification, erasure or anonymisation, restriction and consent withdrawal subject to lawful retention. Requests about dealership data should first go to that dealership; AutoDeck forwards direct processor requests to the relevant controller.
Security and incidents
Controls include tenant isolation, regional databases, role-based access, optional multi-factor authentication, audit trails, TLS and encrypted/authenticated backups where configured. The documented incident process notifies an affected controller without undue delay and supports Articles 32–36 duties.
Contact and supervision
Privacy contact: contact@autodeck.ro. DPO decision/name: [To be confirmed]. For Romanian processing, the supervisory authority is ANSPDCP.
