PRIVACY POLICY

NorthTracker respects your personal privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, process, and share your personal data when you use our products and services, visit our website, subscribe to our newsletter, communicate, or otherwise interact with us. The policy also describes your rights regarding the protection of your personal data.


Who is the Data Controller?

The data controller for processing carried out under this Privacy Policy is:

NorthTracker AB
Company registration number: 556826-4674
Gustavslundsvägen 139
167 51 Bromma
Sweden

If you have any questions regarding this Privacy Policy or our processing of your personal data, please contact us at:
dataskydd@northtracker.com

For personal data collected to fulfill agreements with our customers, it is often the customer who determines the purposes and means of processing. In such cases, the customer is the data controller, and NorthTracker acts as a data processor. A Data Processing Agreement (DPA) is entered into between NorthTracker and the customer in these situations.


Data We Collect and How We Collect It

We may collect, use, store, and transfer different types of personal data. Below we describe the categories of personal data we collect and how we collect them.


Contact Data

  • Name

  • Personal identity number (where applicable)

  • Phone number

  • Email address

  • Postal address

  • Contact person details (name, email, phone number)

  • Billing and payment information

This data may relate to customers, partners, or suppliers.


Transaction Data

  • Details of agreements entered into with us

  • Information about products and services purchased

  • Payment information to and from you


User Data

Automatically Generated Data

When using our services, we may automatically collect:

  • GPS position data

  • Date and time of trip start and stop

  • Route data, including start and stop addresses/coordinates

  • Current speed and direction

  • Trip duration and distance

  • Engine status (on/off)

  • Raw accelerometer data used to generate driving scores and identify events such as harsh acceleration, hard braking, sharp turns, or idling

Data Provided by the Customer

Customers may also provide:

Vehicle Information, including:

  • Registration number

  • Make and model

  • First registration date

  • Emission data

  • Category

  • Color

  • Vehicle name

  • Vehicle type

  • Fuel type

  • Assigned driver

  • Original and updated odometer readings

Leasing Information, including:

  • Leasing company

  • Contract number

  • Contract start date

  • Mileage limits

  • Contract duration

  • Initial odometer reading

Insurance Information, including:

  • Insurance company

  • Insurance policy number

  • Policy start date

  • Mileage limits

  • Policy duration

  • Odometer reading at policy start

Service Information, including:

  • Latest service date

  • Odometer reading at last service

  • Service intervals (distance or time-based)

  • Contact details for service provider

Hardware Diagnostic Data, including:

  • GPS satellite data

  • Installation angle

  • Operational hours


Technical Data

  • IP address

  • Login credentials

  • Browser type and version

  • Time zone setting and location

  • Browser plug-ins and versions

  • Operating system and platform

  • Device information

  • Website interaction data

When you interact with our website or services, we may automatically collect technical data about your device, browsing behavior, and usage patterns through cookies and similar technologies.

We may also collect technical data if you visit other websites or social media platforms using our cookies. Except for strictly necessary cookies, we will only use cookies with your consent.


Marketing & Communication Data

  • Your preferences for receiving marketing from us or our partners

  • Your communication preferences

If you have been in contact with NorthTracker, we may ask you to participate in a customer satisfaction survey. Participation is voluntary. Your feedback helps us improve our products and services.


Recruitment Data

If you apply for a position at NorthTracker, we collect and process:

  • Information from your application

  • CV/resumé

  • Certificates

  • References

  • Name

  • Email address

  • Phone number


Purpose and Legal Basis for Processing

We will only process your personal data when we have a lawful basis under applicable data protection legislation, including the General Data Protection Regulation (GDPR).

We typically process personal data based on:

a) Contractual necessity (Article 6(1)(b) GDPR)
When processing is necessary to perform a contract with you or to take steps prior to entering into a contract.

b) Legal obligation (Article 6(1)(c) GDPR)
When processing is necessary to comply with a legal obligation.

c) Consent (Article 6(1)(a) GDPR)
When you have given explicit consent.

d) Legitimate interests (Article 6(1)(f) GDPR)
When processing is necessary for our legitimate interests (or those of a third party), provided your interests and fundamental rights do not override those interests.

Below, we describe the situations in which we process personal data and the legal basis we rely upon, including any legitimate interests pursued.

Purpose
Types of data processed
Legal basis

To manage and fulfil agreements with you

This includes:

  • Registering you as a new customer, partner, or supplier
  • Enabling you to purchase and subscribe to our products and services
  • Conducting credit assessments
  • Delivering products and services
  • Managing and receiving payments
  • Sending invoices and payment reminders
  • Providing customer support and service, including complaint handling
  • Otherwise fulfilling our contractual obligations

Contact Data

Transaction Data

Performance of a contract (Article 6(1)(b) GDPR)

Legal obligation (accounting and tax laws) (Article 6(1)(c) GDPR)

To analyse and improve our business

This includes:

  • Improving our website
  • Developing business operations
  • Improving sales channels, products and services

Contact Data

Transaction Data

Legitimate interest (Article 6(1)(f) GDPR)
(Our legitimate interest in analysing and improving our operations, products and services.)

To provide access to and enable use of our website

Technical Data

Legitimate interest (Article 6(1)(f) GDPR)
(Necessary for us to provide access to our website.)

To communicate with you

This includes:

  • Responding to inquiries
  • Communicating via website, email, phone, or social media
  • Allowing participation in surveys and questionnaires

Contact Data

Marketing & Communication Data

Legitimate interest (Article 6(1)(f) GDPR)
(Our legitimate interest in communicating with you and improving our services.)

To send newsletters or marketing communications

Contact Data

Marketing & Communication Data

  • Legitimate interest (Article 6(1)(f) GDPR), where applicable
  • Consent (Article 6(1)(a) GDPR), where required

We will only send marketing emails or electronic communications if:

  • You have given your consent; or
  • We are legally permitted to do so under applicable marketing legislation.

To administer and protect our business

This includes:

  • IT administration
  • System maintenance
  • Troubleshooting
  • Data analysis
  • Network security
  • Fraud prevention

Contact Data

Technical Data

Legitimate interest (Article 6(1)(f) GDPR)
(Necessary for our legitimate interests in running our business, providing IT services, ensuring network security and preventing fraud.)

To improve our website, products/services, marketing, customer relationships and user experience

Technical Data

Legitimate interest (Article 6(1)(f) GDPR)
(Necessary to analyse how customers use our products and services, define customer segments, keep our website updated and relevant, develop our business and improve our marketing strategy.)

Cookies:
We will only use cookies – except strictly necessary cookies – if you have provided your consent.

To deliver relevant and targeted marketing

This includes:

  • Personalised website content

  • Relevant advertising

  • Measuring advertising effectiveness

Contact Data

Technical Data

Marketing & Communication Data

Legitimate interest (Article 6(1)(f) GDPR)
(Necessary for our marketing strategy and to tailor communications to your preferences.)

Consent (Article 6(1)(a) GDPR), where required

Cookies:
We will only use non-essential cookies if you have given your consent.

To manage and complete recruitment processes

Recruitment Data

Consent (Article 6(1)(a) GDPR)
and/or

Legitimate interest (Article 6(1)(f) GDPR)
(Necessary to evaluate candidates and manage recruitment processes.)

To the extent that we rely on our legitimate interest as a legal basis for processing, we have carried out a balancing assessment between our interests and need to process the data and your interest in the protection of your personal data. Please contact us by email at dataskydd@northtracker.com if you would like more information about these balancing assessments.


Data Retention

We retain personal data that we collect when it is necessary for the purposes of the processing. When it is no longer necessary, we will either delete or anonymise the personal data.

Contact Data and User Data are retained to maintain documentation of the agreement we have or have had and for accounting and tax purposes for seven full financial years after the end of the year in which the transaction took place. If you are a customer and it is deemed necessary for our legitimate interest in administering our customer relationship, the data may be retained for up to ten full financial years after the end of the year in which you terminated your customer relationship with us. Information about partners and suppliers is stored during the contract term and for five years thereafter.

Marketing & Communication Data will be retained as long as necessary for the purposes of the processing. If you have consented to receive marketing, we will retain proof of your consent for five years after the most recent date on which we had evidence of your consent to send marketing. We will stop sending electronic marketing when you withdraw your consent.

Technical Data will primarily be retained as long as necessary or as long as your consent remains valid.

Recruitment Data will be retained for 12 months after the recruitment process has ended in order to consider you for future positions.

Data may be stored for a longer period if we are legally required to do so, or if retention is necessary to establish, exercise or defend legal claims.


Who May Receive Your Personal Data?

In order to provide our goods and services to you, we may transfer or share your information with selected third parties:

  • Banks in connection with payment administration

  • Debt collection and credit reference agencies where loans/credits/claims have fallen due and in connection with credit checks when entering into agreements

  • The Swedish Tax Agency, the Police and other authorities in connection with statutory reporting or other legal obligations

  • External service providers within accounting, support and IT

  • External service providers within customer service, marketing and CRM systems

  • Professional advisors and other data processors under data processing agreements

  • Insurance companies

  • Third parties where necessary due to a legal obligation. If we are required to disclose your personal data due to a court order or similar, we will inform you to the extent we are not legally prevented from doing so.

NorthTracker strives to process your personal data within the EU/EEA. If personal data is transferred to a data processor outside the EU/EEA, we use Standard Contractual Clauses approved by the European Commission, which provide the personal data with essentially equivalent protection as if it were processed within the EU/EEA.


Security Measures and Information Security

NorthTracker strives to protect your personal data and maintains appropriate technical and organisational security measures to prevent improper or accidental disclosure, use, unauthorised access, loss, alteration or damage to your personal data.

We follow the information security management standard ISO 27001:2017.
We apply network segmentation in all our production environments to reduce risks.
Our infrastructure is continuously updated with the latest security patches provided by our service providers.
We apply a recognised access control method known as the Principle of Least Privilege (PoLP) to ensure that only necessary access is granted in order to maintain infrastructure security.

For more detailed information about our security measures, please visit our website:
www.northtracker.com/dk


Your Rights and How to Exercise Them

Under applicable data protection legislation, you have several rights in relation to our processing of your personal data. More information about each of your rights and any limitations can also be found on the website of the Swedish Authority for Privacy Protection (IMY):
https://www.imy.se/verksamhet/dataskydd/det-har-galler-enligt-gdpr/de-registrerades-rattigheter/

You have the right to:

  • Be informed about our processing of your personal data, including when we process your data, why and for how long we store it.

  • Access your personal data (data extract), enabling you to receive a copy of the personal data we hold about you.

  • Request rectification of personal data we hold about you, allowing you to have incomplete or inaccurate information corrected.

  • Request erasure of your personal data (“the right to be forgotten”). This primarily applies where (a) the data is no longer necessary for the purposes for which it was collected, (b) you withdraw consent where processing is based solely on consent, or (c) processing is carried out for marketing purposes and you object to it. In certain cases, we may not be able to delete some or all of your personal data, for example where we are legally required to retain it.

  • Object to our processing where it is based on a legitimate interest assessment. You always have the right to object to processing for direct marketing purposes.

  • Request restriction of processing, for example if you believe that the data we hold is inaccurate and have requested correction.

  • Request data portability, meaning you may receive your personal data in a transferable format under certain conditions.

  • Withdraw your consent at any time where processing is based solely on your consent. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

  • Lodge a complaint with the supervisory authority. If you are not satisfied with how we process your personal data, you have the right to submit a complaint to the Swedish Authority for Privacy Protection (IMY). Contact details are available at imy.se.

If you wish to exercise any of your rights, please send your request by email to dataskydd@northtracker.com, and we will handle your request in accordance with applicable data protection legislation.

When we process data on behalf of our customers in connection with providing our services, any request for extended access, correction or deletion must be submitted to us by our customer. If you use our services through employment or other affiliation with our customer, you must contact the relevant person within that organisation, who can make the necessary decisions, including submitting a request to us.


Data Protection Officer

If you have any questions regarding this privacy policy, concerns about how we handle your personal data, or wish to submit a complaint, please contact us at:

dataskydd@northtracker.com


Changes to this Privacy Policy

This privacy policy may be updated from time to time. The latest version is available on our website:
www.northtracker.com/uk

 
 

Subscribe to our newsletter

Don’t miss the latest updates, news or offers from us!
Your subscription could not be saved. Please try again.
Your subscription has been successful.

Get a price quote

Fill in your details and we'll get back to you

By filling in this form, you agree to us processing your data. Read more about how we handle your data here: Link to privacy policy

Get more info or a free price quote on the driving log

Fill in your details and we'll get back to you

By filling in this form, you agree to us processing your data. Read more about how we handle your data here: Link to privacy policy