Privacy Policy
How AutoDeck processes and protects personal data.
Last updated: 8 September 2026
1. Who we are and our roles
AutoDeck operator: [AutoDeck operator legal name], [company/tax number], [registered address]. Privacy contact: contact@autodeck.ro. The owner must confirm these details and whether a Data Protection Officer is appointed.
For dealership customer and staff data entered in AutoDeck DMS, the dealership is controller and the AutoDeck entity is processor. AutoDeck may be controller for subscriber accounts, service billing and its own public website, depending on the purpose.
2. Data, purposes and legal bases
We may process account and contact details, company and billing details, service configuration, support communications, security/access logs, device and IP data, and optional analytics choices. Dealership-controlled data may additionally include customer identity/contact details, CRM notes, communications, appointments, transaction records and documents.
Purposes include providing and securing the service, support, billing, fraud prevention, legal compliance and—only with consent—public-site analytics or direct marketing. Applicable bases include contract, legal obligation, legitimate interests and consent.
3. Retention
Relevant log IPs are anonymised after 30 days. Romanian audit records are configured for 7 years and legally held documents for 10 years. Other dealership-controlled data follows the dealership’s documented instructions and lawful policy; account and billing data is kept only as required for the service, disputes and legal duties.
4. Recipients and international transfers
Current service paths use Hetzner Online GmbH for EU hosting, Plus Five Five, Inc. (Resend) for transactional email, Twilio for optional SMS, Meta for optional WhatsApp Business, SmartBill for optional dealership-directed invoicing, Stripe entities for subscription payments, and UploadThing only where unmigrated legacy documents remain. The owner must confirm active providers, contracting entities, roles, locations and safeguards before final approval.
Transfers outside the EEA require an Articles 44–49 GDPR mechanism such as adequacy or applicable Standard Contractual Clauses, with supplementary measures where required. See the Data Processing Agreement template.
5. Your rights
Subject to GDPR conditions, you may request access, rectification, erasure, restriction, portability or objection, and withdraw consent without affecting earlier lawful processing. Contact the dealership for dealership-controlled data or the AutoDeck privacy contact for AutoDeck-controlled data.
6. Security and incidents
Controls include tenant isolation, EU regional storage, access roles, optional multi-factor authentication, audit logging, TLS and encrypted/authenticated backup archives where the backup service is configured. Production backup scheduling and restore evidence remain for the owner to confirm. Processor incidents are reported to the affected controller without undue delay.
7. Complaints and contact
You may complain to your competent supervisory authority. For Romanian processing, the authority is ANSPDCP. Contact: contact@autodeck.ro; named privacy contact/DPO decision: [Name or decision].
