Legal

Privacy Policy

Last updated: 20 August 2026

01

1. Who is responsible

The controller of the personal data described in this notice is: „АНДИМАКС“ ООД ("Andimax" Ltd.), a Private limited company registered in the Bulgarian Commercial Register. UIC (ЕИК): 203076382 VAT: BG203076382 Registered seat: Bulgaria, Sofia 1113, Izgrev district, Iztok, 1 Samokov St., fl. 8, ap. 37 Represented by: Върбин Христов Дичев; Георги Руменов Бояджиев Corporate site: https://www.andimax.net/ TOVR is the trading name of the platform operated by that company. Contact for anything in this notice: [email protected] Security reports: [email protected] The full company details also have their own page — see the Imprint.
02

2. Data protection officer

We have NOT appointed a data protection officer. We state that rather than leaving it unsaid because Art. 37 GDPR makes it mandatory in some cases and you are entitled to know which position we take. Our assessment is that our core activity is providing a freight platform rather than large-scale monitoring of individuals, and that the thresholds in Art. 37(1)(b) and (c) are not met at our current scale. Section 10 explains why that is a judgement rather than an obvious answer, and what we do instead. All data protection questions go to [email protected] and are handled by the management.
03

3. What we process

Account and user data • Name, work email address, password credentials handled by our authentication layer, sign-in method, profile picture if you upload one. • Interface preferences: language, time zone, units, display currency. • Activity in the product: sign-ins, actions taken on shipments, chains and offers. Company data • Company name, address, UIC/VAT number, transport licences, CMR insurance and the documents you upload to prove them. • Billing address, invoices and payment status. Card details are handled by Stripe and never reach our servers. Operational data • Vehicle registrations, positions, availability windows and capacity, received from telematics integrations or from public radars. • Driver records where a telematics integration supplies them: name, driving licence number, tachograph driving and working times, rest periods, eco-driving scores. • Shipments, routes, prices, offers and the outcome of negotiations. Contacts and communications • Names, phone numbers and email addresses of carrier and shipper contacts, including people who are not TOVR users. • The content of emails, chat messages and calls conducted through the platform, and transcripts of calls. • AI-generated summaries and behavioural profiles of contacts — responsiveness, negotiating behaviour, reliability — stored in our contact intelligence tables. Technical data • IP address, user agent, timestamps, and error diagnostics. • Product analytics and session replay, but ONLY where you have consented — see section 13.
04

4. Why we process it, and on what legal basis

Providing the platform to your company — Art. 6(1)(b) GDPR, performance of a contract (for our users), and Art. 6(1)(f), legitimate interest (for named contacts at a customer or carrier who are not themselves a party to the contract). Freight matching, chain building and dispatch, including processing vehicle positions and driver hours — Art. 6(1)(b) and Art. 6(1)(f). The legitimate interest is our customer's interest in operating their fleet lawfully and efficiently, and ours in providing the service. AI assistance in TOVR fOS: natural-language dispatch, document reading, drafting and negotiating messages — Art. 6(1)(b) for your own company's data, Art. 6(1)(f) for third-party contact data appearing in it. Contacting carriers and shippers on behalf of a customer, by email, chat or telephone — Art. 6(1)(f). Our legitimate interest is arranging transport; yours is being reachable about freight you have offered or requested. You can object at any time, see section 11. Profiling of carrier and shipper contacts to rank likely partners for a load — Art. 6(1)(f). See section 9 for what this does and does not decide. Billing, accounting and tax — Art. 6(1)(b) and Art. 6(1)(c), compliance with a legal obligation under Bulgarian commercial and tax law. Security, abuse prevention, rate limiting and audit logging — Art. 6(1)(f). Product analytics and session replay — Art. 6(1)(a), consent, and Art. 5(3) of the ePrivacy Directive for the storage and access on your device. We do NOT claim legitimate interest for any of this. Nothing is loaded before you answer the banner, and withdrawing is one click. Marketing emails to people who asked for them — Art. 6(1)(a), consent, withdrawable in every message.
05

5. Where the data comes from when it is not from you

Some of the people whose data we hold never signed up for TOVR. Art. 14 GDPR requires us to say where their data came from: • Telematics providers connected by a carrier — Frotcom, Mapon, Wialon, OBS, Volvo, ZF Transics and others. Source of vehicle positions and of driver records including tachograph hours. • Freight exchanges and load boards — TIMOCOM, LKW Walter, Trans.eu / Teleroute, Lardi-Trans, Cargopedia, Saloodo, CargoRadar, Transporeon. Source of shipment listings and of the contact details attached to them. • Public registers and public company data, for company verification. • Our customers themselves, who enter or import their partners' contact details. • Mailboxes a user connects (Gmail or Microsoft 365), where message contents are read to extract freight information. If you are one of those people, there is a notice written for you: see "Notice for drivers and contacts".
06

6. Who receives it

Inside TOVR, access is limited to the organisation the data belongs to and is enforced on every query by our authorisation layer. Our staff access production data only where support or incident handling requires it. Outside TOVR, we use processors. The complete list, with the country of each and what it receives, is on its own page: Sub-processors. In summary they are our hosting provider (Hetzner, Germany), our ingress provider (Cloudflare), AWS in eu-central-1 for email and file storage, Stripe for billing, PostHog EU Cloud for consented analytics, AI providers for the assistant, voice providers for telephony, and the freight exchanges and telematics systems you connect. We also transmit matching results back into integrated carrier systems where a customer has connected them. We do NOT sell personal data, and we do not run advertising or cross-site tracking of any kind. We disclose data to public authorities only where we are legally required to.
07

7. Transfers outside the EU and EEA

Our application, database and geo stack are hosted in Germany. Analytics, where consented, is on PostHog's EU Cloud. Some processors are in the United States: Anthropic, Deepgram, ElevenLabs, Cartesia, Telnyx, and parts of Cloudflare, Stripe, Google and Microsoft. Transfers to them take place under the European Commission's Standard Contractual Clauses (Decision 2021/914), supplemented by encryption in transit, and — where the provider participates — the EU-US Data Privacy Framework. You may ask us for a copy of the safeguards applying to a specific transfer at [email protected]. Address lookup and route calculation do NOT leave our infrastructure: we run our own Photon and Valhalla instances rather than sending addresses to a mapping service.
08

8. How long we keep it

• Account and company data: for the life of the account, then 5 years, matching Bulgarian commercial record-keeping obligations. • Invoices, payment records and accounting data: 10 years, as Bulgarian tax law requires. • Vehicle position history: 90 days, then aggregated so it no longer identifies a vehicle or a driver. • Driver records, including tachograph driving and working times: 12 months from collection, unless the carrier's own legal retention obligation requires longer, in which case it is theirs to keep and not ours. • Shipments, chains, offers and their outcomes: for the life of the account plus 5 years, as commercial records. • Chat transcripts and AI conversations: 24 months. • Call audio: 30 days. Transcripts: 12 months. • Contact intelligence profiles: 24 months from the last interaction, then deleted. • API request metadata (timestamp, tool name, response status): 30 days. Request payloads are not logged. • Security and audit logs: 12 months. • Consented analytics and session replay: as configured in PostHog, currently 12 months for events and 30 days for replays. Where a retention period conflicts with a legal obligation to keep a record, the legal obligation wins and we keep only what that obligation covers.
09

9. Automated decision-making and profiling

TOVR scores and ranks. It does not decide. We build profiles of carrier and shipper contacts — how quickly they respond, how they negotiate, how reliably they complete a load — and we score freight matches and price suggestions. These are used to ORDER what a dispatcher sees and to draft messages a dispatcher sends. A human dispatcher chooses which carrier is contacted, which offer is made and which load is awarded. There is no automated decision producing legal effects concerning a person, or similarly significantly affecting them, within the meaning of Art. 22(1) GDPR. We take that position deliberately and we accept the consequence: if we ever automate an award or a rejection end-to-end, this section changes and the safeguards of Art. 22(3) apply. If you believe a decision about you was in fact taken without human involvement, write to [email protected] and we will tell you what happened and correct it.
10

10. Our position on large-scale monitoring

We hold tachograph driving and working times, rest periods, eco-driving scores and AI-generated behavioural profiles. Applied to drivers and to contacts, that is data about individuals' working behaviour, collected continuously and evaluated systematically. Whether it amounts to "regular and systematic monitoring of data subjects on a large scale" under Art. 35 and Art. 37 GDPR is arguable, and we would rather state a position than stay silent. Our position: the monitoring is regular and systematic, but it is not, at our current scale, large-scale within the meaning of the Article 29 Working Party's guidance — the number of data subjects, the geographic extent and the duration are all limited, and each carrier's data is processed for that carrier alone. What we do because that position could change: • We have carried out a data protection impact assessment for the driver-records and contact-profiling processing, and we review it when either changes materially. • We keep the tachograph retention short (12 months) and the position history shorter (90 days). • We will appoint a DPO and publish the appointment here if the scale changes. If you disagree with our assessment, we would like to hear it: [email protected].
11

11. Your rights

Under the GDPR you have the right to: • access — a copy of the personal data we hold about you and the information in this notice (Art. 15); • rectification — correction of inaccurate data, and completion of incomplete data (Art. 16); • erasure — deletion, where one of the grounds in Art. 17 applies; • restriction — that we stop processing but keep the data, while a dispute is resolved (Art. 18); • portability — the data you gave us, in a machine-readable format, and transmission to another controller where technically feasible (Art. 20); • objection — to any processing we base on legitimate interest, including profiling, on grounds relating to your particular situation (Art. 21(1)), and ABSOLUTELY to direct marketing (Art. 21(2)); • withdrawal of consent — at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3)); • not to be subject to a decision based solely on automated processing (Art. 22) — see section 9. To exercise any of these, write to [email protected], or use the data controls in your account settings. We answer within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We do not charge for this. If you are a driver or a business contact rather than a TOVR user, the same rights apply — see "Notice for drivers and contacts" for how to use them without an account.
12

12. Complaints

If you think we have handled your data unlawfully, please tell us first — [email protected] — so we can fix it. You also have the right to lodge a complaint with a supervisory authority, whether or not you contact us. Ours is: Комисия за защита на личните данни (CPDP) — Commission for Personal Data Protection (CPDP) Sofia, Bulgaria https://www.cpdp.bg/ You may also complain to the supervisory authority of the EU member state where you live or work, or where the alleged infringement took place.
13

13. Cookies, analytics and session replay

Strictly necessary cookies keep you signed in and keep the platform secure. They are set on the basis of Art. 5(3) ePrivacy, which exempts what is strictly necessary to provide the service you asked for. Everything else needs your consent, and asks for it before anything is loaded: • Product analytics (PostHog, EU servers, running in cookieless memory-only mode). • Session replay, which is a SEPARATE choice and is never switched on by consenting to analytics. You can accept all, reject all, or choose per category, and change your answer at any time through the "Cookie settings" link in the footer of every page, or in Settings → Preferences → Privacy. We honour Global Privacy Control and Do Not Track as a rejection, and in that case we do not show you a banner at all. The complete inventory — every cookie, every browser storage key, what it holds and how long it lasts — is in the Cookie Policy.
14

14. Security and vulnerability reporting

We use TLS 1.2 or better on every connection, hash API credentials irreversibly (SHA-256), scope access tokens, and enforce tenant isolation on every database query through our authorisation layer. Uploaded documents are stored in AWS eu-central-1 with encryption at rest. If you discover a security vulnerability in TOVR's platform or API, report it to [email protected]. Our machine-readable contact is at https://tovr.eu/.well-known/security.txt. We acknowledge reports within 48 hours and give a resolution timeline within 5 business days. Please do not test against other customers' data. We notify the CPDP within 72 hours of becoming aware of a personal data breach where Art. 33 requires it, and we notify affected individuals directly where Art. 34 requires it.
15

15. Changes to this notice

We update this notice when the processing changes. The date at the top is the date of the current version. Where a change materially affects you — a new purpose, a new category of recipient, a new legal basis — we tell you before it takes effect, by email to account holders and by a notice in the product. A change that only clarifies wording is published here without separate notification. This version replaces the notice of 17 May 2026, which named Supabase and Google Cloud Platform as our host and database. Neither is used by TOVR and neither ever received your data under this platform; the reference was inaccurate and has been removed.
Privacy Policy | TOVR