Privacy Notice for Fleet Partner and Corporate Client Contacts
This notice is information provided under Art. 13 and 14 GDPR. It is not a consent and does not require your acceptance.
The contractual counterpart to this notice is Part D (fleet partners) and Part E (corporate
clients) of the Platform Terms of Use (nutzungsbedingungen), together with the signed Fleet
Partner Agreement or Corporate Client Agreement. Where this notice refers to a clause such as
"D2" or "E2", it means a clause of those Parts.
1. Controller and Data Protection Requests
Controller within the meaning of the General Data Protection Regulation (GDPR) for the processing described in this notice:
Emaride EU S.à r.l. société à responsabilité limitée under Luxembourg law represented by its sole manager Ramez Mohamad Alkhalaf Luxembourg [Placeholder: address to follow] Trade register (RCS): registration pending VAT (TVA): registration pending Email: info@emaride.lu
Data protection requests: privacy@emaride.lu
A data protection officer has not been appointed at present. Assessing whether an appointment is required under Art. 37 GDPR, and the appointment itself, are open items before go-live. Until then, privacy@emaride.lu is the responsible point of contact.
2. Who This Notice Applies To — and Who It Does Not
Emaride has three privacy notices. Which one applies to you does not depend on your role in the account, but on where your data comes from.
This notice applies to you as a contact person on the organisation side, that is, if you are
- an owner, member of management, or designated contact person of a fleet partner (role
subcontractor_owner), - a member working in the Platform for a fleet partner (role
subcontractor_member), or - an administrator of a corporate client account who maintains the designated authorised persons (clause E2).
Your data then arises from the contractual relationship between Emaride and your organisation — from the application, onboarding, billing, and ongoing administration of the account.
This notice no longer applies the moment you book or take a ride. Anyone who books a ride or
is transported is a passenger, and the data arising from that — pickup and drop-off address,
route, coordinates, fare, payment method, rating — is governed exclusively by the Privacy
Policy for Passengers (datenschutz). This applies expressly to corporate clients and their
authorised employees too: a ride booked for business purposes is, in data protection terms,
the same processing as a ride booked privately.
Both notices can apply to you at the same time. If you administer a corporate client account
and also book rides yourself, this notice governs your contact, contract, and billing data,
while datenschutz governs your rides. That is not a contradiction but the consequence of two
distinct processing operations.
This notice does not apply to drivers. Drivers receive the Privacy Notice for Drivers
(datenschutz-fahrer), because Directive (EU) 2024/2831 and Art. 22 GDPR additionally apply to
them — location processing, automated allocation of rides, and automated measures. None of that
concerns contact persons. If, as the owner of a fleet partner, you are also approved as a
driver yourself, both notices apply to you: this one for the contractual relationship, the
driver notice for your activity behind the wheel.
| Where the data comes from | Applicable notice |
|---|---|
| your organisation's contractual relationship with Emaride (application, onboarding, billing, account) | this notice |
| a booked or completed ride — private or business | datenschutz |
| your activity as an approved driver | datenschutz-fahrer |
| your own organisation's processing (personnel file, payroll, duty planning) | your organisation, not Emaride (clause 9) |
3. Categories of Data Processed
What is personal data here is primarily your own contact data. We also list purely company-related details — company name, invoice prefix, payment term — because they sit in the same records and can be attributable to you.
| Category | Specifically |
|---|---|
| Your account | first and last name, email address, phone number, password (hashed), language setting, country, your role (owner or member), optional profile picture, notification preferences, display preferences |
| Assignment to the organisation | the link between your account and the fleet partner, and your role within it |
| Application data | from the public application form: company name, contact person's name, email, phone number, country, your free-text description, review status, and the reason and reviewer where an application is accepted or rejected |
| Organisation and contract data | company name, the organisation's business email and phone number, country, status (onboarding, active, paused, cancelled, deactivated, rejected), pause reason, cancellation effective date, rejection reason |
| Tax and invoicing details | VAT identification number, tax number, invoice prefix, agreed payment term |
| Bank details for payouts | account holder's name, bank name, and IBAN |
| Link to the payment service provider | the identifier of the account created with the payment service provider and the payout authorisation status (see clause 5) |
| Billing data | commission and fee invoices, payouts, chargebacks, payment status |
| Support and communication data | tickets, chat histories with support (AI-assisted where applicable), emails and notifications sent |
| Log and security data | change log (who triggered which change and when), login attempts with IP address, and for every active sign-in session the device and browser, the IP address and the approximate location derived from it (country and city) — so that you can spot and end sessions you do not recognise in your profile |
| Metadata of technical access | for interface keys you create: label, prefix, last four characters, who created the key, last use, revocation |
Bank details are additionally ring-fenced: in the Platform, account holder, bank name, and IBAN are accessible only to the owner role and to authorised Emaride staff; the manager role has no access to them. This is enforced in the database access rules, not merely in the user interface.
Company records. Under clause D2.5 (b) of the Terms of Use, the fleet partner stores its
company records on the Platform: transport authorisation, proof of the operating or fleet
liability insurance, trade or commercial register record, optionally a tax clearance certificate
and a social security clearance certificate, and any other documents the fleet partner adds
itself. We store the file, the document type, the issue and expiry dates, the review status
and, where applicable, a rejection reason; superseded versions are kept as history. These
records concern the organisation. They contain personal data — such as the names of managing
directors, owners, signatories, or beneficial owners — only in so far as it appears on the
document itself; the Platform has no input fields of its own for such information. Access is
limited to the users of your fleet partner account and to Emaride staff authorised for fleet
partners in the relevant market, who review the records. The files are held in non-public
storage with our hosting provider (clause 6). The evidence under clause D2 at driver and
vehicle level — driving licence, vehicle registration, contrôle technique, insurance per
vehicle — is not data about your contact persons; datenschutz-fahrer applies to it.
We do not process special categories of personal data (Art. 9 GDPR) about you.
4. Purposes and Legal Bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Handling your application as a fleet partner | Art. 6(1)(b) (pre-contractual measures) |
| Creating and administering the partner or corporate client account and your access | Art. 6(1)(b) |
| Performing the Fleet Partner Agreement or Corporate Client Agreement | Art. 6(1)(b) |
| Verifying the approval conditions and the required authorisations (clause D2) | Art. 6(1)(c) and (f) |
| Storing the company records to evidence the fleet partner's authorisation and insurance (clause D2.5) | Art. 6(1)(b) and (c) |
| Know-Your-Business, anti-money-laundering, and sanctions screening (clause 5) | Art. 6(1)(c) (legal obligation) |
| Billing commission and platform fees, processing payouts | Art. 6(1)(b) and (c) |
| Retention of accounting and tax records | Art. 6(1)(c) |
| Fraud prevention, Platform security, protection against account takeover | Art. 6(1)(f) (legitimate interests) |
| Support and communication regarding your contract and your account | Art. 6(1)(b) and (f) |
| Transactional email and in-app notifications | Art. 6(1)(b) |
| Logging of security- and billing-relevant operations | Art. 6(1)(f) and (c) |
| Administering and securing technical interface access | Art. 6(1)(b) and (f) |
| Evidencing and enforcing rights under the contract | Art. 6(1)(f) |
| Blocklist preventing re-registration after serious abuse | Art. 6(1)(f) (legitimate interest) |
No processing based on consent. None of the processing listed relies on your consent, and there is no consent mechanism. We do not send marketing or advertising messages to contact persons; all notifications are transactional (application status, invitations, invoices, payouts, document reminders, support, security notices).
5. Know-Your-Business, Anti-Money-Laundering, and Sanctions Screening
Under clause 4.3 of the Fleet Partner Agreement, a fleet partner must provide the beneficial-ownership and identity information required for know-your-business (KYB), anti-money-laundering (AML), and sanctions-screening obligations. That screening is a legal obligation and relies on Art. 6(1)(c) GDPR; no consent is obtained for it, and consent would not be the correct basis.
Who actually performs the screening is decisive for your rights, so we state it precisely:
- The screening is performed by the payment service provider (Stripe) as part of its own onboarding. You enter your identity, ownership, and bank details directly with it, in its form and under its responsibility as a licensed payment institution.
- Emaride neither sees nor stores those details. When the account is opened, all we transmit to the payment service provider is an internal identifier for your organisation, the business contact email address, and the country. All we receive and store in return is the identifier of the account created there and the information whether payouts are enabled.
- Emaride performs no sanctions screening or AML check of its own — no own database, no own matching, no own score. We take no automated decision about you on that basis.
- If the screening with the payment service provider remains incomplete or is adverse, payouts are not possible and onboarding may be refused or suspended under clause 4.3 of the Fleet Partner Agreement. At Emaride that decision is taken by a person, not by a system, and it is given to you with reasons under clause D5.2.
For access to, rectification, or erasure of the screening details held by the payment service provider, please therefore address that provider; we will assist you and name the right point of contact (privacy@emaride.lu).
Emaride takes no automated individual decisions within the meaning of Art. 22 GDPR about contact persons. The restriction, suspension, and termination procedures under clause D5 come with a statement of reasons on a durable medium and a review by a person (clause D5.4).
Exception: the blocklist. The blocklist can prevent re-registration after a serious exclusion (clause 4). Placing someone on the blocklist is decided by a person at Emaride, who records the reasons in writing. What happens at a later registration attempt is the enforcement of that earlier decision, not its formation. If only a name matches, nothing is decided at all — the case is referred to a person for review. If you believe a refusal was made in error, contact privacy@emaride.lu; we will review the case personally.
6. Recipients and Processors
Further recipients
- Emaride staff and mandated auditors — restricted by role and country, for approval, billing, support, and compliance. Only expressly authorised persons have access to the bank details.
- Authorities — where legally required, in particular tax and supervisory authorities and law-enforcement authorities within their powers.
- Tax advisers, auditors, and legal advisers — where necessary to comply with legal obligations or to pursue legal claims.
- Drivers of your fleet partner — on request we name to a driver the contact point we hold on file for their fleet partner, so that they can exercise their rights against their employer or principal.
Your contact data is not disclosed to passengers.
Processors (Art. 28 GDPR)
| Service | Purpose | Location | Basis |
|---|---|---|---|
| Supabase | Hosting, database, auth, storage | EU (Frankfurt) | DPA |
| Stripe | Payment processing and payouts (Merchant of Record), KYB/AML screening under its own responsibility (clause 5) | US/IE | DPA + SCC |
| Google Maps Platform | Maps, geocoding, routing | US | DPA + SCC |
| Mapbox | Map rendering (web) | US | DPA + SCC |
| Resend | Transactional email (invitations, invoices, document reminders) | US | DPA + SCC |
| Twilio (via Supabase Auth) | SMS delivery for phone-login OTP — not currently in use | US | DPA + SCC |
| OpenAI | Regulatory digest, AI ticket triage; no storage of the transmitted content at the processor | US | DPA + SCC |
| Expo | Push notifications | US | DPA + SCC |
| Vercel | Hosting of the web dashboard and landing page | US | DPA + SCC |
| Apple | Single sign-on (optional) — not currently in use | US | DPA + SCC |
| Single sign-on (optional) — not currently in use | US | DPA + SCC |
Emaride does not hold or manage ride funds itself; cashless card processing is handled exclusively by Stripe as the licensed payment service provider and Merchant of Record (clause D4.1).
Not all listed services are currently in use. Twilio, Apple and Google are marked "not currently in use" above: phone login by SMS is switched off and has been removed from the app, and signing in with an Apple or Google account is not enabled. No personal data is currently processed through these three services. They remain in the table because they are technically provided for; if we put one of them into operation, that applies from that point and not retroactively.
The "Basis" column describes the contractual requirement for each processor engaged, not the state currently achieved: for processing within the EU a data processing agreement (DPA) under Art. 28 GDPR is envisaged, and for transfers to third countries the EU Standard Contractual Clauses (SCC) under Chapter V GDPR in addition. Concluding these agreements with the respective providers is a precondition for the Platform going live.
In so far as Stripe performs the KYB, AML, and sanctions screening described in clause 5, it does not act on Emaride's instructions but in order to meet its own regulatory and anti-money-laundering obligations. For that processing, Stripe is a separate controller and not a processor of Emaride.
7. Transfers to Third Countries
In so far as data is transferred to countries outside the EEA (see the "Location" column in clause 6), this takes place only on the basis of appropriate safeguards under Chapter V GDPR, in particular the EU Standard Contractual Clauses or an adequacy decision of the European Commission. The data itself is hosted in the EU (Frankfurt).
8. Retention Periods
Principle: your data as a contact person is retained for the duration of your organisation's contractual relationship with Emaride, and beyond that in so far as a statutory retention obligation exists or claims are not yet time-barred. In detail:
| Data | Period |
|---|---|
| your account and contact data | for the duration of the contractual relationship; anonymisation on request |
| invoicing, settlement, and payout data | 10 years (commercial and tax retention) |
| tax and invoicing details (VAT ID, tax number) | for the duration of the contractual relationship, then within the 10-year retention of accounting records |
| support tickets and chat content | 24 months after the matter is closed, then removal of the content |
| notifications (email / in-app log) | 90 days |
| log data | 24 months |
| login attempts (IP) | 15-minute window, removed automatically thereafter |
| device and location data of a sign-in session | until that session ends, removed automatically thereafter |
| export file for a data subject access request (clause 10) | 8 days; the download link is valid for 7 days |
| application data (including rejected applications) | no automatic period — see below |
| bank details, organisation and status data, key metadata | no automatic period — see below |
| company records (clause 3) | no automatic period — see below |
| blocklist entry | 3 years from the entry being made, sooner upon revocation |
| logged registration attempts by blocked persons | 24 months |
The 10-year period is an obligation, not a discretion. We may not delete accounting and tax records before it expires, not even at your request. An erasure request therefore leads to restriction of processing under Art. 18 GDPR in that respect: the data is then kept solely to fulfil the retention obligation.
For application data, bank details, organisation and status data, and the metadata of technical access, we expressly promise no automatic deletion period, because none is implemented in the product. This data is retained for the duration of the contractual relationship and is deleted or anonymised on request (privacy@emaride.lu). A rejected or withdrawn application can be deleted in full and irreversibly; that is a case-by-case decision which only an authorised person at Emaride can trigger. We do not carry out automatic deletion for inactivity.
For company records, too, we promise no automatic deletion period, because none is implemented in the product. They are retained, including superseded versions, for the duration of the contractual relationship and are deleted on request (privacy@emaride.lu).
Retention hold in the event of litigation or a request from an authority. Where litigation, a request from an authority or other legal proceedings concern you personally, an authorised person at Emaride can suspend the automatic deletion of the following data: log data on operations you carried out, notifications to you, the support tickets you opened and the chat content you wrote, and the device and location data of your sign-in sessions (legal basis: Art. 6(1)(c) or (f) GDPR). This data is then retained beyond the period stated above until the hold is lifted, and is removed by the next deletion run thereafter. There is no such hold for the other data in this clause.
9. Role Mapping: Who Is Responsible for What
This clause is the heart of the relationship and is frequently confused.
Your fleet partner is a separate controller for the data of its employees and drivers within the meaning of Art. 4(7) GDPR — not a processor of Emaride. It processes that data for its own purposes and on its own responsibility: personnel file, employment or service contract, duty and shift planning, payroll, social security, working-time records, tax obligations. Emaride gives no instructions in that regard and cannot provide information about it (clauses D7.3 and D8.1).
The transfer between Emaride and the fleet partner is therefore a controller-to-controller transfer under Art. 6(1)(b) and (f) GDPR and not processing on behalf of a controller under Art. 28 GDPR. In practice that means:
- Each side is responsible for its own processing and its own legal basis.
- Access, rectification, and erasure requests go to the side that processes the data for its own purpose; we forward requests and name the right point of contact.
- A complaint about your fleet partner goes to the supervisory authority competent for it, not to the one competent for Emaride.
- Each side is liable for its own processing under Art. 82 GDPR; there is no chain of instructions that shifts that responsibility.
Where Emaride processes on instructions, a data processing agreement applies. In so far as
Emaride processes personal data on the instructions of the fleet partner, the data
processing agreement dpa-fleet-partner applies (clause D7.1). Conversely, it applies in so far
as the fleet partner processes on Emaride's instructions.
The complete allocation per data category is set out in schedule-7 (Data Processing
Particulars, clause 15.2 of the Fleet Partner Agreement). It determines, for each category —
passenger, driver, vehicle, contact, and billing data — who is controller and who is processor.
Where there is doubt about an individual category, schedule-7 prevails; this notice only
summarises.
The same pattern applies to corporate clients: the corporate client is a separate controller for its own processing — selecting and administering the authorised persons, internal travel-expense and billing processes (clause E5).
10. Your Rights
Under the GDPR you have the right to:
- access (Art. 15),
- rectification (Art. 16),
- erasure / anonymisation (Art. 17), within the limits of the retention obligations in clause 8,
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on legitimate interests (Art. 21).
For your organisation's data we provide the owner role with a data export in the Platform: it contains the fleet partner's drivers, vehicles, invoices, and change log as files in an archive. The export file is deleted after 8 days; the download link is valid for 7 days.
For everything else, please contact privacy@emaride.lu. We respond within one month (extendable under Art. 12(3) GDPR). If your request concerns details held by the payment service provider (clause 5), we will name the responsible point of contact there.
11. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority in Luxembourg is the
Commission nationale pour la protection des données (CNPD) 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg <https://cnpd.public.lu>
As the controller is established in Luxembourg, the CNPD is the lead supervisory authority (one-stop shop, Art. 56 GDPR). Data subjects resident in Germany may in addition contact their locally competent state data protection authority at any time (Art. 77 GDPR). Complaints about your fleet partner or your corporate client as separate controllers go to the authority competent for them (clause 9).
12. Data Security
We apply appropriate technical and organisational measures (including encryption in transit, access controls by role and country, hashed passwords, separately restricted access to bank details, hashed-only storage of interface keys, and logging of changes) to protect your data (Art. 32 GDPR).
13. Changes to This Notice
We may adapt this notice to reflect changes in the law or in functionality. The current version is available on the website; it carries a version number and an effective date. Changes to the contractual terms are additionally communicated to fleet partners and corporate clients at least 15 days in advance on a durable medium (clauses D6 and E4).
14. Deviations from the V2.1 Legal Package
This notice follows Part A of the GDPR Compliance Package and clause 15 of the Fleet Partner Agreement. Where it deviates, it does so because it may only describe what the product actually does:
| V2.1 Part | Our clause | Deviation and reason |
|---|---|---|
| Part A.2 — scope ("Fleet Partner contacts, Corporate Client users") | clause 2 | Split. The package covers passengers, drivers, and organisation contacts in a single document. We separate them into three notices, because otherwise nobody can tell which statements apply to them. Expressly clarified: a ride booked for business purposes falls under datenschutz, not under this notice. |
| Part A.1 / Part N — data protection officer | clause 1 | A data protection officer has not yet been appointed; privacy@emaride.lu is given as the contact. The appointment is an open item before go-live and is not asserted in advance here. |
Part A.1 — contact addresses at @emaride.com |
clauses 1, 10 | Changed to @emaride.lu. |
| Part A.3 — data categories | clause 3 | Made specific against the code, limited to the fields actually held. Extended by application data, tax and invoicing details, and the metadata of interface access, which the package does not mention. |
| FPA clause 4.3 / Schedule 3 — register extracts, licences, insurance certificates, beneficial-ownership information | clause 3 | Described as collected. The upload for company records is implemented; clause 3 names the document types, the data stored, and who has access, clause 4 the purpose, clause 8 the retention. The Platform does not collect beneficial-ownership information or signatories' identity documents in fields of its own; they are present only in so far as they appear on an uploaded record. The KYB check itself remains with the payment service provider (clause 5). |
| FPA clause 4.3 — KYB, AML, sanctions lists | clause 5 | Made specific as to who screens. The legal basis is Art. 6(1)(c). The screening takes place at the payment service provider, which is a separate controller for it; Emaride receives only the account identifier and the payout status. We do not claim a sanctions screening of Emaride's own, because there is none. |
| Part A.4 — legal bases table | clause 4 | Adopted and broken down per purpose. Fraud prevention expressly placed on point (f). |
| Part A.4 / Part F — marketing consent | clause 4 | Not applicable. There is no marketing dispatch to contact persons and no consent mechanism. All notifications are transactional. |
| Part D — cookie policy | — | Not in this notice. The cookie section sits in datenschutz; it is visitor-related and not role-specific, and a duplicate would only create a second place to maintain. |
| Part A.5 — recipients | clause 6 | Adopted and extended by tax advisers, auditors, and legal advisers. Clarified that contact data is not disclosed to passengers and that the manager role has no access to bank details. |
| Part A.9 / Part M — automated decision-making | clause 5 | Not applicable to contact persons. The Platform takes no automated individual decision about them. The Platform's automated systems concern drivers and are described in datenschutz-fahrer. |
| Part E — retention periods | clause 8 | Adopted in so far as implemented. For application, bank, organisation, and status data, for company records, and for key metadata, no automatic period is promised, because no job enforces one; deletion is on request. Promising a period that no job enforces would be an inaccurate statement. |
| Part E — inactive account / litigation hold | clause 8 | Inactive account: not promised, because no inactivity detection exists. Litigation hold: adopted with limits. The retention hold is described only for the log, notification, ticket and session data named in clause 8, because only their deletion run observes a hold. It is not promised for any other data. |
| FPA clause 15.2 — role mapping via Schedule 7 | clause 9 | Adopted and set out in substance rather than merely referenced: the fleet partner is a separate controller, the transfer is controller-to-controller, and what that means for access, erasure, complaints, and liability. For the complete allocation per category, schedule-7 remains authoritative. |
| FPA clause 15.3 — transparency towards drivers | clause 9 | Not repeated but located: the obligation lies with the fleet partner and is described towards drivers in datenschutz-fahrer. |
| Part A.11 — children under 16 | — | Not applicable. Contact persons of an organisation act in a business capacity; an age criterion has no use case here. |