AI Disclosure

How Druma uses AI, what data the AI sees, and what controls you have over it.

Effective 7 August 2026 · Version 2026-08-07

This document is available in English only. The English version is the legally binding version.

Overview

Druma uses AI to assist with two kinds of work: (1) extracting structured data from documents and emails, and (2) translating short messages between drivers and planners. We do not use AI to make legal decisions, regulatory filings, or any decision that produces a significant effect on a person without human review.

Where AI is used

  • Smart Import — bulk onboarding of trucks, drivers, clients, and insurance from existing documents (PDF / images / spreadsheets). Output is shown in a review table; you confirm before anything is saved.
  • Inbound order email — when a shipper emails a transport request to your Druma alias, AI extracts the lane, dates, and goods into a draft order. The order stays in draft until a planner accepts it.
  • Inbound carrier and supplier invoices — when invoices arrive at the dedicated email alias, AI extracts amount, VAT, dates, and reference numbers. The result is queued for human approval before it touches the books.
  • Driver-planner message translation — when a driver and planner have different default languages, messages are auto-translated so each side reads in their own language. The original is always shown alongside the translation.
  • Ask Druma — an in-app assistant with two modes. By default it answers questions about how to use Druma from our product documentation. When an administrator enables the optional data assistant, it can also answer questions about your own operational records — orders, fleet status, finance, driver hours, and order notes — by querying your database on your behalf. It is strictly read-only and never modifies data. Every query runs under the asking user's own permissions, so the assistant can only surface data that user is already allowed to see in the app (a driver sees only their own trips; a user without financial access cannot retrieve prices or margins, and so on). Order notes and other free-text fields may contain personal data such as names, which is sent to the AI provider to compose an answer.

Models and providers

Druma's own AI features run on a single core provider:

  • Google Gemini (via Vertex AI) — document extraction, Smart Import, the Ask Druma assistant. Pinned to the europe-west1 region in code; requests are sent to the regional endpoint and the data does not leave the EU during processing.
  • Google Cloud Translation API — driver-planner message translation. Runs on Google Cloud infrastructure; this API does not carry the same europe-west1 residency configuration as Vertex AI, so translated content may be processed outside the EU.

We do not use OpenAI, Anthropic, or Meta for any core Druma AI feature. The one exception is the optional, opt-in Druma Copilotdescribed below, where the company itself — not Druma — chooses and pays for the provider.

Druma Copilot (bring your own AI)

Druma Copilot is a separate, optional feature that lets a company administrator connect the company's own API key for OpenAI, Anthropic (Claude), or Google Gemini, and chat with an AI agent that can read (and, with explicit confirmation, propose changes to) the company's operational data.

  • Off by default. A company must explicitly enable it and connect a provider before any data is sent.
  • Own provider, own terms. Once enabled, the prompts and operational data (orders, fleet, finance, driver hours, and similar records within that user's normal permissions) that Copilot queries on the user's behalf are sent directly to the company's chosen provider — api.openai.com, api.anthropic.com, or Google's public Gemini API — and processed under that provider's own terms and data-processing agreement with the company, not under Druma's agreements with Google Vertex AI.
  • May leave the EU. Unlike the europe-west1-configured Vertex AI used for Druma's own features, the public OpenAI and Anthropic APIs, and the public Gemini API, do not carry the same EU-residency guarantee. Data sent to Druma Copilot may be processed outside the EU/EEA.
  • API key custody. The key itself is encrypted at rest in a managed vault and used only server-side to call the chosen provider on the company's behalf; Druma never displays it again after it is saved.
  • Requires explicit consent. Before a company can save Copilot credentials, an administrator must acknowledge this data-flow and record that acknowledgement.

If your company has not enabled Druma Copilot, none of your data is ever sent to OpenAI, Anthropic, or the public Gemini API.

Conversation history

Ask Druma has two tabs, and they keep conversations differently — on purpose.

  • Help mode is not saved. Questions about how to use Druma are answered from our product documentation. The conversation lives only in your browser tab and is discarded when you close the panel or reload the page. Nothing is written to our database, and there is nothing to retrieve later — including by us.
  • The one exception is escalation. If you click "Talk to a human", the help conversation up to that point is attached to the support conversation so the person helping you can see the context. That support conversation, transcript included, is deleted 90 days after its last activity.
  • Assistant mode is saved, for you. The optional data assistant and Druma Copilot answer questions about your own operational records, and those conversations are saved so you can reopen them later, ask a follow-up, and see what you already asked. This is the tab your company pays for, and the history is part of what it pays for.

Who can read a saved conversation. Only the user who created it. Not colleagues, and not a company administrator. We took that position deliberately: what a planner asks the assistant reveals what they were worried about, and making that readable by their employer would be workplace monitoring rather than data ownership. An operator that needs oversight of assistant use has it in the audit log, which records which user ran which query and when — what was queried, not what was asked.

How long, and how to remove it. A saved conversation is deleted automatically 90 days after its last message. You can delete any conversation yourself at any time from the assistant panel. Saved conversations are included in a personal-data export, and are removed when your user account or the company account is deleted.

A saved conversation contains what you asked and what the assistant answered — which, in Assistant mode, restates records you were already entitled to see when you asked. It does not grant any new access: the assistant queries your database under your own permissions every time, and a saved answer is a record of that moment, not a live view.

Training and data use

Under Google's Vertex AI service terms, customer data submitted to Vertex AI is not used to train Google's foundation models and is not retained for model improvement. Requests are processed in the europe-west1 region.

What we can and cannot evidence about Google's retention. Google applies abuse monitoring to Vertex AI requests, and its published default is that prompts and responses may be cached for up to 30 days for that purpose, unless zero-data-retention is contractually enabled for the account. We have not yet confirmed in writing that zero-data-retention applies to Druma's account. Until we have, assume the default caching window applies — we would rather state the weaker claim we can evidence than a stronger one we cannot. We will update this section once the position is confirmed with Google.

Druma itself does not train AI models on your data. We do not sell or share your data with model providers for any purpose other than serving the requested inference.

Driver performance scoring is not AI. Druma's driver scorecard is a fixed, published weighted average of five operational components — on-time performance (35%), fuel efficiency against a benchmark (20%), idling (15%), incidents (15%) and compliance (15%). It is ordinary arithmetic on records Druma already holds. No model is trained, no model is applied, and no data is sent to any AI provider to produce it. Components with no data are excluded and the remaining weights renormalise, rather than the driver being scored zero. Small samples are flagged as low-confidence. The score is nevertheless profiling in the GDPR sense and is described as such in our Privacy Notice.

Human oversight

Every AI output is treated as a draft. A user must review and confirm before:

  • An imported record is saved (Smart Import).
  • A draft order is converted to an active order.
  • An extracted invoice is matched and posted.
  • A translated message is sent (the original is sent regardless; translation is shown alongside).

For Ask Druma, the assistant can read but never write. If you ask it to take an action, it will give you the steps to take in the planner, not perform them itself.

Opt-out

  • Message auto-translation — toggle in your Profile settings. Off by default for any user whose default language matches the counterparty.
  • Smart Import — entirely optional; never required to use the rest of the platform.
  • Ask Druma — only triggered when you open the assistant panel; nothing is sent until you ask a question. The optional data assistant mode, which queries your operational records, is off by default and must be switched on by a company administrator before any account data is sent to the AI. Help-mode chat is never saved; Assistant-mode conversations are saved for you and can be deleted at any time — see Conversation history.
  • Druma Copilot (bring your own AI)off by default. A company administrator must enable it, connect a provider API key, and acknowledge that data sent through Copilot goes to that provider under the company's own terms and may leave the EU, before any data is sent.
  • Inbound email AI — disabled by default. Enable per-feature in Settings → Integrations once you have configured your incoming alias.

EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages:

  • 2 February 2025 — the prohibited-practices rules (Chapter II) and the AI-literacy obligation (Art. 4) began to apply.
  • 2 August 2025 — obligations for providers of general-purpose AI models, together with the governance, notified-body and penalty provisions.
  • 2 August 2026 — the bulk of the Regulation, including the Article 50 transparency obligations and the Annex III high-risk regime.
  • 2 August 2027 — the remaining provisions, including high-risk AI embedded in products regulated under the Union harmonisation legislation in Annex I, and the transition rules for GPAI models placed on the market before 2 August 2025.

Our classification. Druma is a deployer of third-party AI models, and for the Ask Druma and Druma Copilot chat surfaces also the provider of the AI system the user interacts with. Our AI uses fall within the limited-risk / transparency tier — assistive tools with mandatory human review. We do not operate a prohibited practice under Chapter II, and we do not operate a high-risk AI system under Annex III: we do not score creditworthiness, determine access to essential services, or use AI to recruit, allocate work, evaluate performance, or make any decision about a worker's employment relationship.

Note in particular that Druma's driver performance score is not an AI system. It is a fixed, published arithmetic formula computed from operational records — no model is trained, inferred from, or applied. It is nevertheless profiling under Article 4(4) GDPR, and is described as such in our Privacy Notice.

Article 50(1) — you are interacting with an AI system. Where an AI system is intended to interact directly with natural persons, those persons must be informed that they are interacting with an AI unless it is obvious from the circumstances. This obligation applies to Ask Druma and Druma Copilot, and we state it here rather than deferring it: when you use Ask Druma or Druma Copilot, you are talking to an AI system, not to a member of Druma's staff. The one exception is the live-support hand-off inside the same panel, which is labelled Live Support and connects you to a human. The panels themselves carry an AI indicator (an assistant icon and a provider badge such as "Powered by Gemini", "Druma AI · read-only", or "Using your provider key").

Article 50(2) and (4) — labelling of AI output. Druma does not generate synthetic image, audio, or video content. AI-extracted fields are labelled as AI output in the review screens before a human confirms them, and AI-translated messages are shown alongside the untranslated original.