Production servers are dedicated machines operated by Hetzner Online GmbH in Falkenstein, Germany. Database replicas, file storage and backups also remain within the EU. The client application contains no advertising trackers.
1. Who we are
cloudGPS ("cloudGPS", "we", "us") is a fleet telematics platform β GPS tracking, fuel monitoring, geofencing, maintenance and driver management β developed and operated by a UkrainianβEstonian team, with production infrastructure located entirely in the European Union.
The platform operator and contracting entity is:
Private Entrepreneur Oleksandr Oliinyk (sole proprietor registered in Ukraine, registration no. 3137207472), Zaporizhzhia, Ukraine.
Email: info@cloudgps.online (also for all privacy matters).
2. Our roles under the GDPR
cloudGPS acts in two distinct roles:
- As a processor β for fleet telematics data (vehicle positions, routes, fuel, driver identification and similar data described in section 4). Our customer β the fleet operator, dealer or partner who holds the account β is the controller of this data and decides why and how it is processed. Processing is governed by our Data Processing Agreement (DPA).
- As a controller β for account and billing data, support communications, security logs and data submitted through our websites.
Partner (white-label) portals. The platform is also offered by our partners under their own brand and domain. If you use a partner-branded portal, your contract is with the partner named in your agreement, and cloudGPS processes your data at the platform level β under the same EU-hosting and security commitments described in this policy, and under a sub-processing agreement with the partner (see the DPA, Clause 2.3). The partner may publish its own privacy notice in addition to this one and may send notifications via its own email provider.
3. Where your data is stored
- All production data β telemetry, driver, account and billing data β is stored on dedicated servers operated by Hetzner Online GmbH in Falkenstein, Germany (EU), in ISO 27001-certified data centers.
- The database runs as a replicated cluster across three nodes, all located in German data centers.
- File attachments (e.g. driver photos, invoice PDFs) and backups are stored on Hetzner storage within the EU.
- Application error monitoring (Sentry) uses the EU data region β error reports are ingested and stored in Germany.
- We do not use cloud services outside the European Union to store customer data.
4. What data we process
As a processor (fleet data, on behalf of our customers)
- Vehicle location data: GPS coordinates, speed, heading, routes, mileage, engine hours;
- Telemetry and sensor readings: ignition, fuel level, temperature, CAN-bus and other inputs from tracking devices;
- Device identifiers: IMEI, serial numbers, SIM identifiers;
- Driver identification events: iButton / RFID key IDs and the driver assignments derived from them;
- Data entered by the customer: driver names, phone numbers, photos, vehicle registration plates, geofences, notes;
- Reports and alerts generated from the above.
As a controller
- Account data: name, login, email, phone, company, language and interface preferences;
- Billing data: invoices, payment records, company requisites;
- Support communications: tickets, chat messages and related context;
- Technical and security logs: IP addresses, login history, browser/device information β kept to protect accounts and investigate abuse;
- Website enquiries: name, email, phone, company and message submitted through forms on cloudgps.online.
5. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the platform and its features to our customers | Performance of a contract β Art. 6(1)(b) |
| Billing, invoicing and accounting | Legal obligation β Art. 6(1)(c); contract β Art. 6(1)(b) |
| Account security: fraud prevention, brute-force and credential-stuffing protection, abuse investigation | Legitimate interest β Art. 6(1)(f) |
| Responding to enquiries and support requests | Contract β Art. 6(1)(b); legitimate interest β Art. 6(1)(f) |
| Service improvement based on aggregated, de-identified usage statistics | Legitimate interest β Art. 6(1)(f) |
| Visitor statistics on the marketing website | Consent / legitimate interest β see Cookies |
6. Information for drivers and employees
If your employer or contractor uses cloudGPS to monitor its vehicles, the employer is the controller of the monitoring data. It decides which vehicles are tracked, for what purposes, and for how long the data is kept. Please direct requests about your data (access, correction, erasure) to your employer first β we assist them in fulfilling such requests under the DPA.
We require our customers to inform drivers about vehicle monitoring in accordance with applicable employment and data protection law.
7. Sub-processors and third parties
We never sell personal data and do not share it with advertising networks. We use a small number of service providers:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Dedicated servers, storage and backups for all production data | Germany (EU) |
| Functional Software, Inc. (Sentry) | Application error monitoring | EU data region (Germany) |
| Anthropic | AI support assistant: processes support conversation text and relevant device context when you use the support chat; API data is not used to train models | USA (DPF / SCC safeguards) |
| ADM.tools | Delivery of transactional email (service notifications, website enquiries) | Ukraine (SCC safeguards) |
| Google Ireland Ltd (Google Analytics) | Visitor statistics on the marketing website cloudgps.online only β not used inside the client application | EU / USA (DPF) |
| Cloudflare, Inc. | DNS for our domains; application traffic does not pass through Cloudflare | Global (DPF / SCC) |
Map imagery (e.g. HERE) is fetched and cached by our own EU servers; map providers do not receive your account data or user identifiers.
The current sub-processor list for customers under a DPA is maintained in Annex III of the DPA. We give customers at least 30 days' notice before adding or replacing a sub-processor. White-label partners may configure their own SMTP server for notifications to their clients; in that case email is delivered by the provider chosen by the partner.
8. International transfers
All customer data at rest remains in the European Union (section 3). Our engineering and support team operates from the EU (Estonia) and Ukraine. Remote administrative access from Ukraine is protected by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) together with strict technical controls: multi-factor authentication, key-only SSH access, role-based access control and audit logging.
Transfers to sub-processors outside the EU/EEA (see section 7) are safeguarded by the EUβU.S. Data Privacy Framework and/or Standard Contractual Clauses.
9. Data retention
- Fleet telemetry and driver data β retained for the duration of the service agreement, so customers keep access to their historical routes and reports. After termination, data is deleted or returned in accordance with the DPA, no later than 90 days after termination, unless the customer requests earlier deletion.
- Account data β for the life of the account and up to 90 days after closure.
- Billing and accounting records β retained as required by applicable law (typically 3 years).
- Security and access logs β up to 12 months, unless needed longer for an ongoing investigation.
10. Security
- TLS encryption for all web, mobile and API traffic;
- EU-only infrastructure on dedicated (not shared) servers in ISO 27001-certified data centers;
- Network segmentation, firewalls and origin isolation behind dedicated load balancers;
- SSH access by cryptographic keys only; multi-factor authentication for administrative access;
- Role-based access control and per-tenant data isolation;
- Automated protection against brute-force and credential-stuffing attacks;
- Replicated three-node database cluster, regular backups and 24/7 monitoring;
- Audit logging of administrative operations and a defined incident response process.
In the event of a personal data breach we notify affected customers without undue delay and support them in meeting their obligations under Articles 33β34 GDPR.
11. Your rights
Under the GDPR you have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to data portability. Where processing is based on consent, you may withdraw it at any time.
To exercise these rights, email info@cloudgps.online. If your data was entered into the platform by your employer (the fleet operator), we may redirect your request to them as the controller β see section 6.
You also have the right to lodge a complaint with the supervisory authority of your EU member state of residence or workplace.
12. Cookies and analytics
Marketing website (cloudgps.online)
The website uses Google Analytics to measure aggregate visitor statistics, and browser storage to remember your language choice. You can opt out of Google Analytics with the GA opt-out browser add-on or by blocking analytics cookies in your browser.
Client portal (client.cloudgps.online and partner portals)
The client application uses no advertising cookies and no third-party analytics. It stores only functional data in your browser: session tokens, language and interface preferences. Error reports (Sentry, EU region) are sent only when an application error occurs.
13. Changes to this policy
We may update this policy as the service evolves. The current version with its effective date is always published at cloudgps.online/privacy/. For material changes affecting customers under a DPA, we provide notice in advance.
14. Contact
Privacy questions, data subject requests, DPA signing: info@cloudgps.online.
Postal address available on request.