This is an English translation provided for convenience. In the event of any discrepancy, the Romanian version available at www.routena.com/gdpr shall prevail.
Definitions
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
“Controller” means the person who determines the purposes and means of the processing of personal data. “Processor” means the person who processes personal data on behalf of the Controller.
Roles of the parties (Controller and Processor)
In relation to the personal data that the Client (the transport operator) enters, imports or generates in the Routena platform — including data of employees, drivers, partners and their contacts — the Client acts as data Controller, and SPECTRALAB SOLUTIONS S.R.L. acts as Processor, in accordance with art. 28 GDPR.
In this capacity, SPECTRALAB SOLUTIONS S.R.L.:
- processes personal data exclusively on the basis of the Client’s documented instructions and for the purpose of providing the services;
- ensures that persons authorized to process the data have committed themselves to confidentiality;
- implements appropriate technical and organizational measures for data security;
- assists the Client, as far as possible, in fulfilling its obligations regarding data-subject requests and data security;
- upon termination of the services, deletes or returns the personal data in accordance with section 3.5 of the Terms and Conditions (automatic deletion within 60 days, or immediate deletion on request within a maximum of 5 working days).
In relation to the data that SPECTRALAB SOLUTIONS S.R.L. processes for its own purposes (for example, account administration, billing of its own services, platform security and improvement), SPECTRALAB SOLUTIONS S.R.L. acts as Controller.
Categories of data processed
Through the platform, depending on the functionalities used by the Client, the following categories of personal data may be processed:
- identification and contact data (name, email, phone, authentication data);
- data about employees and drivers (including documents, licenses, validity dates);
- GPS location data of vehicles and drivers (in real time and, if explicitly permitted, in the background);
- data about partners, clients and their contacts;
- data regarding orders, routes, statuses and transport documents;
- financial and fiscal data necessary for invoicing and reporting (including e-Factura/ANAF);
- technical usage data (IP addresses, browser type, access logs).
Sub-processors
To provide the services, SPECTRALAB SOLUTIONS S.R.L. relies on third-party providers who may process personal data as sub-processors. They are selected so as to offer sufficient guarantees regarding data protection and are contractually bound to comply with obligations equivalent to those set out in this section. The main categories of sub-processors are:
- hosting and cloud infrastructure providers (e.g. Microsoft Azure);
- mapping, geocoding and routing providers (e.g. TomTom, Google Maps);
- authentication and account-management providers (e.g. Clerk);
- payment-processing providers (e.g. Stripe);
- transactional email providers (e.g. MailerSend);
- error and performance monitoring providers (e.g. Sentry).
The transmission of electronic invoices to the ANAF system (SPV) is a legal obligation of the Client as taxpayer; ANAF does not act as a sub-processor of SPECTRALAB SOLUTIONS S.R.L. An up-to-date list of sub-processors can be obtained on request, at [email protected]. The Client will be informed of any intention to add or replace sub-processors, with the possibility to raise reasoned objections.
Data Protection Officer
SPECTRALAB SOLUTIONS S.R.L. has designated a Data Protection Officer (DPO) to oversee the protection of personal data in accordance with the GDPR. You can contact the DPO at [email protected].
Rights of data subjects
Under the GDPR, data subjects have certain rights regarding their personal data, including the right of access, rectification, erasure and data portability. If you wish to exercise these rights or have any questions about the processing of your data, please contact us at [email protected]. Where SPECTRALAB SOLUTIONS S.R.L. acts as Processor, requests concerning data-subject rights should be addressed primarily to the Client (the Controller) that created the user account.
Legal basis for processing
We process your personal data in accordance with the GDPR, on the basis of your consent, in order to provide our services and to fulfill our contractual obligations.
International data transfers
Where your personal data is transferred outside the European Union / European Economic Area, we ensure that adequate safeguards exist for the protection of such data, such as an adequacy decision of the European Commission, the Standard Contractual Clauses (SCC) approved by the European Commission, or other transfer mechanisms provided for by the GDPR. Where possible, data is processed and stored in data centers located within the EU/EEA.
GPS location and driver monitoring
The GPS location and vehicle/driver monitoring functionalities are configured and activated by the Client, in its capacity as Controller and employer. The Client is responsible for establishing a valid legal basis (e.g. legitimate interest or a legal obligation), for appropriately informing the drivers, and for complying with the principles of data minimization and proportionality. SPECTRALAB SOLUTIONS S.R.L. provides the technical functionality as Processor and does not determine the purposes of the monitoring.
Data security
We are committed to taking appropriate measures to protect your personal data against unauthorized access, loss or destruction. We implement technical and organizational measures such as: encryption in transit (HTTPS/TLS), role-based access control, per-Client data isolation (multi-tenant), periodic backups, access logging and security monitoring. Nevertheless, no method of transmission or storage can be guaranteed to be 100% secure.
Data breach notification
In the event of a personal data breach that poses a risk to the rights and freedoms of data subjects, we will notify the competent supervisory authority without undue delay and, where feasible, within a maximum of 72 hours of becoming aware of it. Where we act as Processor, we will inform the Client (the Controller) without undue delay after becoming aware of a breach, so that the Client can fulfill its own notification obligations.
Changes to the privacy policy
We reserve the right to modify this policy at any time in accordance with the requirements of the GDPR. Any change will be posted on this page.
Contact
For questions or concerns regarding the protection of personal data, or to exercise your rights under the GDPR, please contact us at [email protected].