Skip to content

Privacy policy

Last updated: 27 July 2026

This policy explains what eTrans24 Sp. z o.o. does with personal data in connection with eTMS24. It is written to be read rather than to be survived, and it names the companies that process data on our behalf.

This document is being reviewed by our legal counsel. If anything here is unclear, please write to us and we will answer plainly.

Who is responsible

The controller is eTrans24 Sp. z o.o., ul. Gen. Władysława Sikorskiego 166/lok. 0.03, 18-400 Łomża, Poland, entered in the National Court Register under KRS 0001125679, NIP 7162845197, REGON 529589339.

For questions about this policy or about your data, write to kontakt@etms24.com.

Two different roles

We are the controller of data about the people who sign up for and administer eTMS24: names, work email addresses, the organisation they belong to, and how they use the service.

We are a processor for the operational data our customers enter into the system: their contractors, contacts, drivers, vehicles, loads, orders and invoices. That data belongs to the customer, who decides why it is held. We process it only to run the service for them, on their instructions.

What we collect and why

  • Account data: name, email address, role and organisation. Needed to give you an account and keep it secure. Basis: performance of a contract.
  • Operational data: everything you enter into the system while working. Held so the service can do its job. Basis: performance of a contract, and our customer's own basis where we act as processor.
  • Demo requests: the name, company, email, optional phone number, fleet size and message you send us through the contact form, plus a salted hash of your IP address used only to limit abuse of that form. Basis: our legitimate interest in responding to enquiries.
  • Email delivery records: whether a message we sent on your behalf was delivered, bounced or complained about. Basis: performance of a contract.
  • Usage measurement: aggregate page views and performance data through Vercel Web Analytics, which sets no cookies and does not build a profile of you. Basis: legitimate interest in knowing whether the site works.

Who processes data for us

We use a small number of subprocessors, each under a data processing agreement:

  • Supabase: database, authentication and file storage, hosted in the European Union.
  • Vercel: application hosting, content delivery and cookieless analytics.
  • Resend: sending the emails you send from the system, and the notifications we send you.
  • Amazon Web Services (SES): a fallback email sending route.

Where data is held

Application data is stored in the European Union. Some of our subprocessors are established outside the EEA; where that leads to a transfer, it is covered by the European Commission's standard contractual clauses.

How long we keep it

  • Account and operational data: for as long as the organisation has an account, and then for up to 60 days so an account can be restored after an accidental closure.
  • Demo requests: up to 24 months from the last contact, unless you ask us to delete them sooner.
  • Email delivery records: 12 months.
  • Invoicing records we are required to keep under Polish accounting law: for the statutory period.

Your rights

Under the GDPR you may ask for access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Write to kontakt@etms24.com and we will respond within one month.

If our answer does not satisfy you, you may complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) in Warsaw.

Where we act as a processor for your employer or client, please direct your request to them; we will support them in answering it.

Security

Data is encrypted in transit and at rest. Access between customers is separated at the database level by row-level security, so one organisation's queries cannot reach another organisation's rows. Access within your own organisation is governed by the role you have been given.

No system is beyond failure. If a breach affects your data and is likely to put your rights at risk, we will tell you and the supervisory authority within the deadlines the GDPR sets.

Changes

If this policy changes materially, we will tell account administrators by email before the change takes effect. The date at the top always reflects the current version.

Back to the home page