Privacy Policy
Last updated: 1 April 2026
This Privacy Policy explains how ZappFleet (operated by Enspire Oy, "we", "us", or "our") collects, uses, and protects personal data when you use our fleet management platform and website. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR) and Finnish data protection law.
1. Data Controller
The data controller for personal data processed through the ZappFleet platform is:
Enspire Oy
Operating as: ZappFleet
Website: zappfleet.io
Contact: privacy@zappfleet.io
2. Personal Data We Collect
Account and identity data
- Full name and email address (required for account creation)
- Organisational role (owner, admin, viewer)
- Account creation date and last login timestamp
Fleet and operational data
- Vehicle identifiers (plate numbers, internal IDs)
- MQTT topic identifiers for IoT device communication
- Vehicle lock/unlock events with timestamps
- Driver-to-vehicle assignment records
- Trip log data (if enabled): journey start/end times, duration
Security and audit data
- Login events (successful and failed) with IP addresses
- Administrative actions (audit log entries)
- Rate-limiting attempt records (automatically deleted after 15 minutes)
Communication data
- Messages submitted via the contact form (name, email, company, message text)
- Email correspondence with our team
3. How We Use Your Data
- Providing and operating the ZappFleet fleet management service
- Authenticating users and maintaining account security
- Enabling real-time vehicle control via MQTT IoT
- Generating audit logs for compliance and dispute resolution
- Responding to contact and support enquiries
- Detecting and preventing unauthorised access and fraud
- Complying with legal obligations under Finnish and EU law
4. Legal Basis for Processing
We process personal data under the following GDPR legal bases:
- Contract performance (Art. 6(1)(b)): processing necessary to provide the ZappFleet service to customers
- Legitimate interests (Art. 6(1)(f)): security logging, fraud prevention, and platform integrity
- Legal obligation (Art. 6(1)(c)): compliance with applicable Finnish and EU regulations
- Consent (Art. 6(1)(a)): where you have given explicit consent, e.g. marketing communications
5. Data Sharing and Processors
We do not sell personal data. We share data only with trusted processors necessary to operate the service:
- Supabase Inc. — database and authentication infrastructure (hosted in EU region)
- Resend Inc. — transactional email delivery
All processors have data processing agreements in place and are bound by GDPR-equivalent obligations. No personal data is transferred outside the European Economic Area (EEA) without appropriate safeguards.
6. Data Retention
- Account data: retained for the duration of the contract plus 3 years, then deleted
- Audit log entries: 12 months from creation
- Security event logs: 12 months from creation
- Trip logs: configurable per organisation (30–365 days); default 365 days
- Rate-limit attempt records: automatically purged after 15 minutes
- Contact form messages: 24 months from receipt, then deleted
7. Your Rights Under GDPR
As a data subject you have the following rights:
- Right of access (Art. 15): obtain a copy of your personal data
- Right to rectification (Art. 16): correct inaccurate data
- Right to erasure / right to be forgotten (Art. 17): delete your data (available via the GDPR tools in the dashboard)
- Right to restriction of processing (Art. 18): restrict how we use your data
- Right to data portability (Art. 20): receive your data in a machine-readable format (CSV export available in dashboard)
- Right to object (Art. 21): object to processing based on legitimate interests
- Rights related to automated decision-making (Art. 22): we do not use solely automated decision-making that produces legal effects
To exercise any right, contact us at privacy@zappfleet.io. We will respond within 30 days.
8. Cookies
The ZappFleet dashboard uses localStorage (not cookies) to store your session and language preference. This marketing website (zappfleet.io) does not use tracking or advertising cookies. Essential browser storage is used only to remember your language selection.
9. Data Security
We implement appropriate technical and organisational measures to protect personal data, including: TLS encryption in transit, encrypted database storage, role-based access control, service-role key isolation for sensitive operations, and regular security auditing via the security events log.
10. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu):
tietosuoja.fi
PO Box 800, FI-00521 Helsinki, Finland
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to registered users at least 30 days before taking effect. The date of the most recent update is shown at the top of this page.