GDPR Compliance Statement
Last Updated: May 3, 2025
1. Introduction
This GDPR Compliance Statement outlines how FLEETA ("we," "us," or "our") processes and protects personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR). This statement applies to all personal data processing activities conducted by FLEETA in relation to our fleet management services, website, and mobile applications.
2. Data Controller Information
FLEETA, operated by Pittasoft Co., Ltd., acts as the data controller for personal data processed through our services. Our Data Protection Officer can be contacted at:
- Email: legal@fleeta.io
- Address: 18000 Studebaker Rd #700, Cerritos, CA 90703
- EU Representative: Jinseop, Yoon
3. Legal Basis for Processing
We process personal data under the following legal bases as defined in Article 6 GDPR:
- Contractual Necessity (Art. 6(1)(b)): Processing necessary for the performance of a contract
- Legal Obligation (Art. 6(1)(c)): Processing necessary for compliance with legal obligations
- Legitimate Interests (Art. 6(1)(f)): Processing necessary for legitimate business interests
- Consent (Art. 6(1)(a)): Processing based on specific, informed, and unambiguous consent
4. Categories of Personal Data
4.1 Customer Data
- Contact information (name, email, phone number)
- Account credentials
- Company information
- Billing information
4.2 Fleet Data
- Vehicle location data
- Driver identification information
- Video footage from dashcams
- Driver behavior metrics
4.3 Technical Data
- IP addresses
- Device information
- Usage logs
- Cookie data
5. Data Subject Rights
Under the GDPR, data subjects have the following rights:
- Right to Access (Art. 15): Obtain confirmation of processing and access to personal data
- Right to Rectification (Art. 16): Correct inaccurate or incomplete personal data
- Right to Erasure (Art. 17): Request deletion of personal data ("right to be forgotten")
- Right to Restriction (Art. 18): Limit the processing of personal data
- Right to Portability (Art. 20): Receive personal data in a structured format
- Right to Object (Art. 21): Object to processing based on legitimate interests
6. Data Protection Measures
We implement appropriate technical and organizational measures to ensure data security, including:
- End-to-end encryption for data transmission
- Access control and authentication systems
- Regular security assessments and penetration testing
- Employee training on data protection
- Data minimization and purpose limitation
- Regular backup procedures
7. International Data Transfers
For transfers of personal data outside the EEA, we ensure appropriate safeguards through:
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (BCRs)
- Adequacy decisions by the European Commission
- Additional technical measures as required
8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, subject to:
- Legal retention requirements
- Contract fulfillment needs
- Legitimate business purposes
- Technical constraints
9. Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities, including:
- Large-scale processing of special categories of data
- Systematic monitoring of public areas
- Profiling with significant effects
- New technologies implementation
10. Data Breach Procedures
In the event of a personal data breach, we will:
- Notify the relevant supervisory authority within 72 hours
- Inform affected data subjects without undue delay
- Document all breaches and remedial actions
- Implement measures to prevent future breaches
11. Subprocessors and Third Parties
We maintain a list of approved subprocessors and ensure they:
- Process data only on documented instructions
- Implement appropriate security measures
- Assist with data subject rights requests
- Delete or return data upon service completion
12. Contact and Complaints
For GDPR-related inquiries or to exercise your rights, contact our legal team at legal@fleeta.io. You have the right to lodge a complaint with a supervisory authority in the EU member state of your residence, workplace, or place of alleged infringement.