Skip to content

Data processing agreement

Last updated: 3 September 2026

This Data Processing Agreement is concluded under Article 28(3) of the GDPR between the organisation using eTMS24, as controller, and eTrans24 Sp. z o.o., as processor. It forms part of the Terms of Service and applies for as long as the organisation has an eTMS24 account.

Parties, subject matter and duration

The controller is the organisation that holds an eTMS24 account. The processor is eTrans24 Sp. z o.o., ul. Gen. Władysława Sikorskiego 166/lok. 0.03, 18-400 Łomża, Poland, KRS 0001125679, NIP 7162845197.

The subject matter is the processing of personal data that the controller enters into eTMS24 or that arises from using it. The agreement takes effect when the account is created and ends when the account is closed and the deletion described below is complete.

Where this agreement and the Terms of Service disagree about personal data, this agreement prevails. It is governed by Polish law and by the GDPR; if a provision turns out to be invalid, the rest stays in force.

Nature and purpose of the processing

We process personal data only to provide the service the controller subscribed to: planning loads, issuing transport orders, keeping fleet, driver and contractor records, sending documents and messages on the controller's behalf, issuing and settling invoices, and — where the controller switches it on — submitting and receiving invoices through the Polish national e-invoicing system (KSeF).

We do not process the controller's data for our own purposes. We do not sell it, and we do not use it to train machine-learning models.

Categories of data subjects

  • The controller's own people: administrators, dispatchers, accountants and drivers holding an account.
  • Drivers recorded in the fleet and assigned to loads, including those without an account.
  • Contact people at contractors — customers, carriers and suppliers.
  • Contact people at loading and unloading locations.
  • Individuals named on invoices, transport orders and transport documents, including sole traders.

Categories of personal data

The controller may enter the following categories. eTMS24 requires no special categories within the meaning of Article 9 GDPR, and the controller must not enter any:

  • Identification and contact data: names, business email addresses, telephone numbers, positions, employer.
  • Driver data: licence and qualification details, assigned vehicle, assigned loads and the times worked on them.
  • Business and financial data: addresses, tax identifiers, bank account numbers, invoice lines, amounts and payment dates.
  • Documents the controller uploads: CMR notes, scans, photographs and correspondence, which may contain further personal data of the controller's choosing.
  • Account and audit data: sign-in times, IP addresses, browser identification, and the record of acceptance of these documents.

Documented instructions

We process personal data only on the controller's documented instructions. The Terms of Service, this agreement and the controller's own use of the application together are those instructions; anything beyond them must be sent in writing to hello@etms24.com.

If European Union or Member State law requires us to process data beyond those instructions, we will tell the controller before doing so, unless that law forbids the notice.

We will tell the controller if, in our view, an instruction infringes data protection law.

Confidentiality

Everyone we authorise to process the controller's personal data is bound by a written confidentiality obligation that outlasts their engagement. Access is granted only where the work requires it and is withdrawn when it no longer does.

Security measures

We apply the following technical and organisational measures under Article 32 GDPR:

  • Tenant isolation enforced by the database itself, through PostgreSQL row-level security: one organisation's queries cannot reach another organisation's rows. It is not application code that could be bypassed.
  • Role-based access control inside each organisation, so an account reaches only what its role allows.
  • Encryption in transit (TLS) on every connection, and encryption at rest for the database, file storage and backups.
  • KSeF credentials stored encrypted under a key held outside the database, and never written to logs.
  • Passwords stored only as salted hashes, one active session per user, and email confirmation before an account can be used.
  • Automated daily backups with point-in-time recovery, held in the European Union.
  • Production separated from development, administrative access restricted to named people, and administrative operations logged.

Sub-processors

The controller gives general written authorisation for the sub-processors listed in the Annex to this agreement. Each is bound by data protection obligations no less protective than those set out here, and we remain fully liable to the controller for their performance.

We will give at least 30 days' notice by email to every account administrator before adding or replacing a sub-processor. The controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the controller may terminate the affected part of the service without penalty.

Transfers outside the European Economic Area

Personal data is stored in the European Union. Where a sub-processor's support or operations reach that data from a third country, the transfer is covered by the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914) together with the supplementary measures those clauses call for. Transmission to the Polish Ministry of Finance is domestic and involves no third-country transfer.

Assisting the controller

  • Data subject requests: if a data subject approaches us about data we hold for a controller, we pass the request on without undue delay and do not answer it ourselves. We assist through the application's own functions and, where those are not enough, by hand.
  • We assist with data protection impact assessments and with prior consultation of the supervisory authority, so far as the information is ours to give.
  • We make available the information needed to demonstrate compliance with Article 28 GDPR.

Personal data breaches

If we become aware of a personal data breach affecting the controller's data, we notify every account administrator by email without undue delay and in any case within 48 hours. The notice describes the nature of the breach, the categories and approximate number of records concerned, the likely consequences and the measures taken or proposed.

Notifying the supervisory authority and the data subjects is the controller's decision and the controller's obligation; we assist with it.

Audit and information

On request, and no more than once a year, we provide the information needed to demonstrate compliance with this agreement, including a description of our security measures and the current sub-processor list.

The controller may audit that compliance itself, or through an auditor it mandates who is not a competitor of ours. Audits take place during business hours, on at least 30 days' written notice, without disrupting the service and without any access to other customers' data. Each party bears its own costs. An audit by a supervisory authority proceeds on that authority's terms.

Return and deletion

On termination the controller may ask for an export of its personal data in a standard format; we deliver it within 30 days of the request.

We delete the controller's personal data within 60 days of the end of this agreement, including from backups as they roll over — except where European Union or Member State law requires us to keep it. In that case we keep only what the law requires, for only as long as it requires, and go on protecting it under this agreement.

Annex — authorised sub-processors and recipients

As of the date at the top of this page, the following are authorised:

  • Supabase — database, authentication and file storage. Receives: all application data. Hosted in the European Union.
  • Vercel — application hosting, content delivery and cookieless analytics. Receives: request data and everything passing through the application. European Union regions.
  • Stripe — billing for eTMS24 itself. Receives: the controller's billing contact, company name, address, tax identifier and payment details. Card numbers are handled by Stripe and never reach us.
  • Resend — sending email from the application: transport orders, invoices and notifications. Receives: recipient addresses, subject lines, message content and attachments.
  • Amazon Web Services (SES) — the fallback route for the same email. Receives: as above.
  • Cloudflare — DNS and inbound mail routing for our own domains. Receives: connection metadata and the content of mail addressed to us.
  • Ministry of Finance of the Republic of Poland (KSeF) — not a sub-processor but a statutory recipient. Where the controller switches e-invoicing on, structured invoice data is submitted to, and downloaded from, the national system on the controller's behalf under the Polish VAT Act.
Back to the home page