Data Processing Agreement
Article 28 GDPR controller-to-processor agreement between Druma (processor) and the Customer (controller). Forms an annex to the Terms of Service.
Effective 19 August 2026 · Version 2026-08-19
The English version of this document is the legally binding version. Romanian, Dutch and Polish translations are provided for convenience only.
1. Roles
For the personal data processed through the Druma TMS service on behalf of the Customer, the Customer is the data controller and Druma is the data processor as those terms are defined in Article 4 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
For data Druma collects in its own right (Customer account data, billing records, marketing prospects), Druma is an independent controller; that processing is governed by Druma's Privacy Notice, not by this DPA.
2. Subject matter and duration
Druma processes personal data on the Customer's behalf solely for the purpose of providing the Service. This DPA takes effect on the Customer's subscription start date and remains in force for the duration of the subscription, plus the post-termination data export and purge periods set out in section 11.
3. Categories of data and data subjects
Data subjects:
- The Customer's employees, contractors, and drivers.
- The Customer's clients and their contact persons.
- The Customer's subcontracted carriers and their staff.
- Other identifiable individuals whose data the Customer enters into the Service (consignees, dock contacts, etc.).
Categories of personal data:
- Identification data (names, employee IDs, role).
- Contact data (email, phone, language).
- Location data, in three distinct forms:
- Live vehicle position from telematics — a single row per vehicle, overwritten on each update, with no history.
- Driver-app position pings, and the coordinates recorded when a driver changes an order status (arrived, loaded, delivered) — retained 90 days, then deleted.
- Romanian e-Transport GPS waypoints forwarded to ANAF — retained 30 days.
- Driver qualification and document data (licence, CPC, ADR and medical expiry dates, and the uploaded documents themselves) as recorded by the Customer.
- Derived data — the components and result of the driver performance score, which is profiling within the meaning of Article 4(4) GDPR but produces no legal or similarly significant effect and involves no automated decision-making under Article 22.
- Tachograph and driving-time data (remaining driving hours, working-state records sourced from telematics providers where connected; processed under EU Reg. 561/2006 and Reg. 165/2014 compliance obligations).
- Operational data (orders, status taps, waiting times, delays).
- Document content (CMR, POD, eCMR signatures, identity documents where required by compliance flows).
- Communication content (messages between planner and driver, AI assistant transcripts).
Druma does not knowingly process special-category data (Article 9 GDPR). The Customer must not upload health, biometric, religious, or other special-category data to the Service except where strictly required by an incident or insurance flow, in which case the Customer accepts the additional Article 9 obligations.
4. Processing instructions
Druma processes Customer Data only on the Customer's documented instructions, including with respect to international transfers, unless required by EU or member-state law to do otherwise (in which case Druma will notify the Customer unless the law prohibits notification).
The Customer's documented instructions include: (a) these Terms and the DPA, (b) configuration choices made within the Service, and (c) any additional written instructions from the Customer that Druma confirms in writing.
Druma will inform the Customer if it considers that an instruction infringes GDPR or another data-protection law.
5. Sub-processors
The Customer gives Druma general written authorisation to engage the sub-processors set out in Annex III to this DPA. Annex III is the complete and authoritative list — it is generated from the same source as the table in our Privacy Notice, so the two documents cannot state different things. There is no separate, shorter list anywhere.
Many of the entries in Annex III are marked "only if you connect it". Those recipients receive no data at all unless the Customer enables that specific integration — the telematics, reefer, e-invoicing, marketplace and messaging connectors are all in this group. A Customer that connects none of them shares data only with the core platform, email, routing, map-tile and AI recipients.
Druma will give the Customer at least 30 days' email notice of any new sub-processor before that sub-processor begins processing Customer Data. If the Customer reasonably objects to a new sub-processor on data-protection grounds, the Customer may terminate the affected portion of the Service on written notice.
Druma remains responsible for each sub-processor's compliance with this DPA and imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA.
6. Technical and organisational measures (Annex II)
- Encryption — TLS 1.2+ in transit; encryption at rest (AES-256) by default through our infrastructure providers.
- Access control — row-level security on every database table; tenant isolation by company; least-privilege role-based access for staff.
- Authentication — JWT, HMAC, or service-role tokens on every server endpoint; optional two-factor authentication available to all users.
- Secret management — credentials stored in a managed vault, never in source control.
- Audit logging — automatic mutation log on sensitive tables, retained 12 months.
- Backup and recovery — daily automated backups by our database provider, retained 7 days. Documented recovery objectives: a recovery point objective of 24 hours and a recovery time objective of 8 working hours, set out with their assumptions and known gaps in our business continuity and disaster recovery plan, which we make available on request. These are operating targets, not a service-level guarantee.
- Vulnerability management — dependency upgrades, security review on each PR, error monitoring and alerting via Sentry, and a published vulnerability disclosure policy (security.txt, reports to security@druma.io) with stated acknowledgement and remediation timeframes.
- Personnel and confidentiality (Art. 28(3)(b)) — Druma ensures that every person authorised to process Customer Data, whether an employee, contractor or freelancer, has committed themselves to confidentiality or is under an appropriate statutory obligation of confidentiality. That commitment is contractual, binds each person individually, covers all Customer Data they may access, and survives the end of their engagement with Druma. Access is granted on a least-privilege, need-to-know basis and is revoked when the engagement ends or the need lapses. Every such person is also bound to process Customer Data only on Druma's documented instructions, which in turn follow the Customer's instructions under section 4.
- Sub-processor diligence — review of each sub-processor's security posture before onboarding, with reliance on their published certifications (SOC 2, ISO 27001, etc.) where available.
7. Assistance to the Customer (Art. 28(3)(e) and 28(3)(f))
7.1 Data subject rights (Art. 28(3)(e)).
The Service includes built-in tools (Settings → GDPR) that the Customer can use to fulfil access, rectification, erasure, and portability requests without contacting us. For requests that cannot be fulfilled through these tools, Druma will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, taking into account the nature of the processing and the information available to Druma. If a data subject contacts Druma directly about Customer Data, Druma will not respond substantively; it will forward the request to the Customer without undue delay and tell the data subject that it has done so.
7.2 Data protection impact assessments and prior consultation (Art. 28(3)(f), Art. 35 and Art. 36).
Taking into account the nature of the processing and the information available to Druma, Druma will assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR. In particular, on the Customer's reasonable written request to privacy@druma.io, Druma will:
- Provide the information the Customer needs to carry out a data protection impact assessment under Article 35 — the description of the processing operations Druma performs, the categories of data and data subjects, the data flows and recipients (Annex III), the retention periods, and the technical and organisational measures in Annex II, in a form the Customer can incorporate into its own DPIA.
- Make available Druma's own DPIA covering GPS tracking, tachograph data and driver performance scoring, which the Customer may use as an input to its own assessment. It does not replace the Customer's assessment: the Customer is the controller and must assess its own operational context, works-council position and national employment-law requirements.
- Answer follow-up questions on risks and mitigations within a reasonable period, and flag to the Customer any change in the Service that Druma believes may materially affect an existing DPIA.
- Provide reasonable assistance to the Customer in any prior consultation with a supervisory authority under Article 36, including supplying documentation and responding to the authority's technical questions about Druma's role as processor.
Druma provides this assistance at no additional charge where the request is proportionate to the processing carried out for the Customer. Druma does not determine whether a DPIA is required — that assessment is the Customer's, as controller.
8. Personal data breach notification
Druma will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will describe (so far as known): the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.
The Customer is responsible for any onward notification to data subjects and supervisory authorities under Articles 33 and 34 GDPR.
Security incidents that do not involve personal data. Druma will also notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a security incident that materially affects the availability or integrity of the Service or of Customer Data, even where no personal data breach has occurred. The notice will describe what is known of the cause, the services and data affected, the expected duration or extent, and the steps being taken. This commitment exists because a Customer that is itself an essential or important entity may have its own regulatory notification clock running from the moment it becomes aware, and it cannot start that clock from information it does not have.
9. Audit rights (Art. 28(3)(h))
Druma makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or by an auditor mandated by the Customer. The rest of this section describes how that is done — it does not restrict the right itself.
9.1 Information Druma provides on request. On reasonable written request to privacy@druma.io, Druma will provide:
- A current copy of this DPA, the Privacy Notice, and the sub-processor list (Annex III).
- A description of the technical and organisational measures in force (Annex II) in enough detail to demonstrate compliance with Article 32.
- A completed security questionnaire, using the Customer's own template where one is supplied and is of reasonable length.
- An architecture and data-flow walkthrough, including where Customer Data is stored, which sub-processors receive which categories of data, and the applicable transfer safeguards.
- Available certifications and attestation reports of sub-processors (SOC 2, ISO 27001 and equivalent) where Druma is permitted to share them, and Druma's own records of the sub-processor diligence in Annex II.
- Druma's most recent penetration-test or security-review summary, where one exists.
9.2 Remote audit is the default — because that is where the evidence is. Druma does not own or operate any data centre. The Service runs entirely on managed cloud infrastructure operated by the sub-processors in Annex III, and Druma's staff work from ordinary office and remote workplaces with no Customer Data held on local premises. Audits are therefore conducted remotely by default: questionnaires and evidence packs, screen-shared reviews of live configuration (access control, RLS policies, encryption, logging, retention jobs), architecture walkthroughs, and sub-processor certifications and attestations. A physical inspection of a sub-processor's data centre is governed by that sub-processor's own audit programme; Druma will forward and support such a request and will pass on any report it is entitled to share.
9.3 On-site inspection of Druma's own premises and systems. The Customer, or an independent auditor mandated by the Customer who is not a competitor of Druma, may inspect Druma's own premises, equipment, records and systems. Such an inspection takes place on 30 days' prior written notice, during normal business hours, subject to the auditor signing a reasonable confidentiality undertaking and to proportionate measures protecting other customers' data, Druma's security and any third-party confidentiality obligation. Druma will make competent personnel available for the inspection and will respond to findings in writing. The notice period and the frequency limit in 9.4 do not apply, and Druma will cooperate promptly and without additional conditions, where an inspection or the production of information is required by a competent supervisory authority, or where it follows a personal data breach affecting Customer Data.
9.4 Frequency. Other than in the cases described at the end of 9.3, audits and inspections are limited to once per calendar year, so that they remain proportionate to the processing.
9.5 Costs. Druma bears its own costs of responding to audit requests, including the information listed in 9.1 and the personnel time spent on a remote or on-site audit; Druma makes no charge for meeting its Article 28(3)(h) obligation. The Customer bears the fees of any third-party auditor it mandates and its own costs of attendance. Where the Customer requests audits beyond the frequency in 9.4 for reasons other than those in 9.3, the parties will agree in advance a reasonable charge for Druma's additional time.
10. International transfers (Chapter V GDPR)
10.1 The Customer-to-Druma leg needs no transfer safeguard. Druma is established in Romania and its central administration is in Romania. Customer Data is hosted in the European Union by default. A transfer from the Customer (controller) to Druma (processor) is therefore an intra-EEA transfer and does not engage Chapter V. No Standard Contractual Clauses are required, or entered into, for that leg — and this DPA does not purport to make the Customer a party to any SCCs.
10.2 Druma is the exporter for the onward leg. Where a sub-processor in Annex III is established outside the EEA, or processes Customer Data outside the EEA, the transfer is made by Druma as data exporter to that sub-processor as data importer. Druma has entered into the European Commission's 2021 Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with each such recipient, using Module Three (processor to processor), with the docking clause enabled, the optional Clause 7 included, and Romania designated as the Member State whose law governs the clauses and whose courts have jurisdiction, consistent with section 13 of this DPA. Where a recipient is certified under the EU-US Data Privacy Framework, Druma may rely on the adequacy decision of 10 July 2023 instead of, or in addition to, the SCCs.
10.3 Transfer impact assessment. Druma has carried out a transfer impact assessment for each non-EEA recipient, considering the categories of data transferred, the laws and practices of the destination country relevant to public-authority access, the recipient's own transparency and challenge commitments, and the supplementary measures in place — encryption in transit and at rest, minimisation of what is sent to each recipient, and pseudonymisation where the recipient does not need identifying data. Druma re-runs that assessment when a recipient's circumstances or the legal environment materially change.
10.4 Copies. Copies of the executed Standard Contractual Clauses (with commercial terms redacted), and of the transfer impact assessments, are available to the Customer on request to privacy@druma.io. The Customer, as controller, may rely on them as evidence of the safeguards applying to the onward transfers of its data.
10.5 Recipients outside the EEA. The following recipients in Annex III receive, or may receive, personal data outside the EEA. The safeguard for each is stated alongside it:
- Supabase (Supabase, Inc.) (may leave the EEA) — Data is stored in the EU. The vendor is US-established, so remote support access is covered by the 2021 SCCs in the Supabase DPA.
- Cloudflare, Inc. (leaves the EEA) — 2021 SCCs in the Cloudflare DPA; EU-US Data Privacy Framework where applicable.
- Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.) (leaves the EEA) — 2021 SCCs in the Stripe DPA; EU-US Data Privacy Framework.
- Sentry (Functional Software, Inc.) (may leave the EEA) — Data is stored in the Sentry EU region. The vendor is US-established, so support access is covered by the 2021 SCCs in the Sentry DPA.
- Resend, Inc. (leaves the EEA) — 2021 SCCs in the Resend DPA. Migration to an EU-resident email provider is on the roadmap.
- CARTO (may leave the EEA) — Tiles are served from a global CDN, so the serving edge is not guaranteed to be in the EEA. Only IP and tile coordinates are exposed; no Customer Data is transmitted.
- OpenStreetMap Foundation (leaves the EEA) — The United Kingdom is covered by the European Commission’s adequacy decision of 28 June 2021 (as extended).
- Google Cloud Translation API (leaves the EEA) — 2021 SCCs in the Google Cloud DPA. Message auto-translation can be switched off per user in profile settings.
- Google LLC — Firebase Cloud Messaging (leaves the EEA) — 2021 SCCs in the Google Cloud DPA; EU-US Data Privacy Framework.
- Meta Platforms (WhatsApp Business Cloud API) (leaves the EEA) — 2021 SCCs. Off unless the company enables the WhatsApp driver channel.
- Transporeon GmbH (Germany, Trimble group) (may leave the EEA) — Processing is in the EU; the parent group is US-established, so group-level access is covered by the 2021 SCCs in the Transporeon DPA.
- Geotab Inc. (may leave the EEA) — Druma connects to whichever Geotab database host the Customer’s own Geotab account resolves to. Where that host is outside the EEA the Customer’s own agreement with Geotab governs the transfer.
- Samsara Inc. (may leave the EEA) — Druma connects to Samsara’s EU shard by default. The vendor is US-established, so vendor-side access is covered by the 2021 SCCs in the Samsara DPA; a Customer that overrides the endpoint to a non-EU shard makes that transfer under its own agreement.
- ORBCOMM Inc. (leaves the EEA) — 2021 SCCs in the ORBCOMM agreement.
- Thermo King TracKing (Trane Technologies) (leaves the EEA) — 2021 SCCs in the Thermo King agreement.
- Carrier — Lynx Fleet (Carrier Global Corporation) (leaves the EEA) — 2021 SCCs in the Carrier agreement.
- CHEP (Brambles Limited) (may leave the EEA) — No personal data is transmitted. Where CHEP processing takes place outside the EEA it is covered by the Customer’s own CHEP account terms.
17 of the 34 recipients in Annex III fall into this group; the remainder process Customer Data exclusively within the EEA.
11. Return or deletion at the end of processing (Art. 28(3)(g))
At the end of the provision of services relating to processing, Druma will, at the Customer's choice, either return all Customer Data to the Customer or delete it, and will delete existing copies — unless Union or Member State law to which Druma is subject requires continued storage. The choice is the Customer's; Druma does not decide it.
11.1 The default, if the Customer says nothing. Customer Data is retained for 90 days from the effective date of termination or suspension. Throughout that window the Customer can export a complete copy at any time from Settings → GDPR (machine-readable JSON and CSV plus the stored documents), and the account can be reactivated with its data intact. At the end of the 90 days Druma deletes Customer Data from its live systems. The same 90-day period is stated in section 13 of the Terms of Service and in the retention table of the Privacy Notice.
11.2 Return, or earlier deletion, on instruction. The Customer may instruct Druma in writing at any time — during the subscription or during the 90-day window — to return Customer Data, to delete it, or both. Druma will act on the instruction within 30 days of receiving it and will confirm completion in writing. Return is provided in the same machine-readable export format, by a secure transfer method agreed with the Customer.
11.3 Existing copies, including backups. Deletion extends to existing copies of Customer Data. Encrypted database backups and point-in-time-recovery snapshots held by our database provider are immutable and cannot be selectively edited without destroying their integrity as a recovery mechanism. Customer Data still present in a backup is therefore not individually erased at the moment of deletion from the live systems: it is overwritten as that backup ages out of the normal rotation, and in any event no later than 35 days after deletion from the live systems. During that period the backups remain encrypted at rest and access-controlled, and are used only for disaster recovery — never to restore, serve, or otherwise process data that has been deleted. Deletion also covers copies held by sub-processors, on the deletion timelines in their own agreements with Druma.
11.4 Where law requires Druma to keep the data. Druma retains, and does not delete, data whose storage is required by Union or Member State law to which Druma is subject: invoices and accounting records (10 years from issue date — Romanian Accounting Law 82/1991 Art. 25 and EU VAT Directive Art. 244); eCMR and eFTI consignment documents (7 years, covering the CMR Convention Art. 32 limitation period and the eFTI authority-access requirements of Regulation (EU) 2020/1056); and the audit log (12 months). Those records remain isolated and access-controlled, are processed for no purpose other than the legal obligation that requires them, and are deleted when the retention period expires.
11.5 Certification of deletion. On written request, Druma will confirm in writing that deletion has been completed, and will identify any category of data retained under 11.4 together with the legal basis and the date its retention period expires.
12. eFTI authority access
Druma has implemented readiness for the EU eFTI Regulation (EU) 2020/1056. From 9 July 2027, competent transport-enforcement authorities may access transport consignment data linked to an eFTI unique link (UIL) during roadside inspections. Where a transport order managed through the Service is linked to a UIL, the corresponding consignment data — cargo description, route, and consignment parties — may be accessed by authorised authorities via the eFTI platform.
This access is mandated by law (Art. 6(1)(c) GDPR). Druma logs each authority-access event in the eFTI operation log as required by the Regulation and makes those logs available to the Customer on request. The Customer, as operator-controller, is responsible for informing affected data subjects of this possibility in their Article 13 notice.
13. Miscellaneous
- Order of precedence — in case of conflict between this DPA and the Terms of Service, this DPA prevails for matters concerning personal data.
- Liability — claims between the parties under this DPA are subject to the liability cap in section 11 of the Terms of Service. That cap does not apply to liability for death or personal injury, to fraud, or to any liability that cannot be limited under applicable law — including liability to data subjects for damage caused by processing in breach of the GDPR under Article 82 GDPR. Nothing in this DPA or in the Terms restricts a data subject's rights or remedies against either party, or alters the allocation of responsibility between controller and processor under Articles 82(1) to 82(3) GDPR.
- Changes — Druma may update this DPA to reflect changes in law, sub-processors, or security measures, on 30 days' email notice.
- Governing law — Romanian law; Bucharest courts.
- Contact — privacy@druma.io.
- Annexes — Annex I (parties and description of processing), Annex II (technical and organisational measures — section 6 above) and Annex III (sub-processors) form an integral part of this DPA and of the Standard Contractual Clauses referred to in section 10.
Annex I — Parties and description of the processing
A. The parties
| Controller | The Customer — the company that subscribes to the Service. Its identity, address, contact person and role are those recorded in its Druma company profile and on its subscription record. The Customer determines the purposes and means of the processing of the personal data it puts into the Service. |
| Processor | WESLEY DATA CONSULTING S.R.L., Trade Register no. J29/511/2024, CUI 49645204, 19 Mărgaritarilor Street, Bărcănești Village, Prahova County, 107055, Romania. Contact: privacy@druma.io. Activities relevant to the transfer: provision of the Druma TMS software-as-a-service. |
| Role for onward transfers | For transfers to non-EEA sub-processors, Druma is the data exporter and the sub-processor is the data importer, under Module Three of the 2021 Standard Contractual Clauses (see section 10). |
| Competent supervisory authority | ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, Romania, as the authority of Druma's single establishment and central administration. The Customer's own lead authority is determined by the Customer's establishment. |
B. Description of the processing
| Categories of data subjects | The Customer's employees, contractors and drivers; the Customer's clients and their contact persons; the Customer's subcontracted carriers and their staff and drivers; consignees, dock and site contacts, and other individuals whose details the Customer enters into the Service. |
| Categories of personal data | Identification data (name, employee identifier, role); contact data (email, phone, language); location data (live vehicle position, driver-app position pings, coordinates recorded at order status changes, e-Transport GPS waypoints); tachograph and driving-time data including driver card numbers; driver qualification data (licence, CPC, ADR and medical expiry dates as recorded by the Customer); operational data (orders, stops, status changes, waiting times, delays); document content (CMR, POD, eCMR and the signatures captured on them, invoices, receipts); communication content (planner-driver messages and attachments, AI assistant transcripts); derived data (driver performance score components); and technical and security data (IP address, device and app version, error context). |
| Sensitive data | None is intended or required. Druma does not knowingly process Article 9 data. See section 3 for the Customer's obligation not to upload it. |
| Nature and purpose | Hosting, storage, structuring, retrieval, transmission and deletion of transport-management records, for the sole purpose of providing the Service to the Customer: order and trip management, planning and dispatch, the driver application, fleet and driving-time compliance, document issuance including eCMR, invoicing and finance, analytics, and the integrations the Customer chooses to enable. |
| Frequency | Continuous, for the duration of the subscription. Telematics and position data are ingested on a recurring automated schedule where the Customer has connected a provider. |
| Duration | For the duration of the subscription, then per section 11 (90-day window, then deletion) subject to the statutory retention periods listed there. Category-level retention periods that apply during the subscription are set out in the retention table of the Privacy Notice. |
| Sub-processor processing | As set out per recipient in Annex III, for the duration of the subscription or, for an optional integration, for as long as the Customer keeps it connected. |
Annex II (technical and organisational measures, including the measures relied on as supplementary measures for transfers) is section 6 of this DPA.
Annex III — Sub-processors
The complete list of sub-processors and other third-party recipients Druma engages, what each is used for, the personal data each actually receives, where it processes that data, and whether the data leaves the EEA. This table and the sub-processor table in the Privacy Notice are generated from one shared source, so they are always identical.
Entries marked "only if you connect it" receive no data unless the Customer enables that integration. Druma gives the Customer at least 30 days' email notice before a new sub-processor begins processing Customer Data, and the Customer may object as described in section 5.
Core platform and infrastructure
| Recipient | Purpose | Personal data received | Location | Certifications | Leaves the EEA? |
|---|---|---|---|---|---|
| Supabase (Supabase, Inc.) | Managed Postgres database, authentication, file storage, Edge Functions — the primary store for all Customer Data. | All personal data held in the Service: account and contact data, orders and stops, driver data, documents and PODs, messages, audit records. | EU — Ireland (eu-west-1) | SOC 2 Type II · HIPAA | May leave the EEAData is stored in the EU. The vendor is US-established, so remote support access is covered by the 2021 SCCs in the Supabase DPA. |
| Cloudflare, Inc. | CDN, static hosting for the web app and marketing site, TLS termination, DDoS and bot protection. | IP address and request metadata (URL, user agent, timestamp) of every visitor; the content of requests in transit. | Global edge network, EU termination preferred | ISO 27001 · SOC 2 Type II · PCI DSS | Leaves the EEA2021 SCCs in the Cloudflare DPA; EU-US Data Privacy Framework where applicable. |
| Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.) | Subscription billing, seat metering, payment processing. | Billing contact name and email, company name, VAT number, billing address, subscription level and payment status. Druma never receives or stores card numbers. | EU (Ireland) and US | PCI DSS Level 1 · SOC 1 & SOC 2 | Leaves the EEA2021 SCCs in the Stripe DPA; EU-US Data Privacy Framework. |
| Sentry (Functional Software, Inc.) | Application error monitoring and crash reporting. | User ID, IP address, browser and app version, and the error context attached to a crash — which can incidentally include record identifiers. | EU (Sentry EU region) | SOC 2 Type II | May leave the EEAData is stored in the Sentry EU region. The vendor is US-established, so support access is covered by the 2021 SCCs in the Sentry DPA. |
Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.
| Recipient | Purpose | Personal data received | Location | Certifications | Leaves the EEA? |
|---|---|---|---|---|---|
| Resend, Inc. | Both directions of email. Outbound: all transactional email (invitations, notifications, document delivery, dunning). Inbound: Druma retrieves messages sent to your Druma email aliases from Resend’s receiving API — including the full message body and the raw attachment bytes — for the order, carrier/supplier invoice, payment and CRM ingestion pipelines. | Sender and recipient names and email addresses; the full text and HTML body of inbound and outbound messages; and the content of attachments (transport orders, invoices, PODs, remittance advices), which routinely contain names, addresses, VAT numbers and bank details. | US | — | Leaves the EEA2021 SCCs in the Resend DPA. Migration to an EU-resident email provider is on the roadmap. |
Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.
Routing, geocoding and map tiles
| Recipient | Purpose | Personal data received | Location | Certifications | Leaves the EEA? |
|---|---|---|---|---|---|
| PTV Logistics GmbH | Primary truck-routing, distance-matrix and ETA engine. | Pickup and delivery coordinates and addresses, vehicle profile parameters. No name is sent. | EU (Germany) | — | Stays in the EEA |
| HERE Global B.V. | Geocoding, address autosuggest, reverse geocoding, fallback routing and ETA. | Pickup and delivery addresses and coordinates; address fragments typed into search boxes; vehicle positions used to compute an ETA. | EU (Netherlands / EU endpoints) | — | Stays in the EEA |
| CARTO | Basemap tiles for the map views in the planner and operations screens. | Your browser requests tiles directly from CARTO’s CDN, so CARTO receives your IP address, user agent, and the tile coordinates — which reveal the geographic area you are looking at. No account or order data is sent. | Global CDN edge | — | May leave the EEATiles are served from a global CDN, so the serving edge is not guaranteed to be in the EEA. Only IP and tile coordinates are exposed; no Customer Data is transmitted. |
| OpenStreetMap Foundation | Basemap tiles for a small number of secondary map views. | Your browser requests tiles directly from the OSM tile servers, so the Foundation receives your IP address, user agent, and the tile coordinates. No account or order data is sent. | United Kingdom | — | Leaves the EEAThe United Kingdom is covered by the European Commission’s adequacy decision of 28 June 2021 (as extended). |
Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.
AI, translation and messaging
| Recipient | Purpose | Personal data received | Location | Certifications | Leaves the EEA? |
|---|---|---|---|---|---|
| Google Cloud — Vertex AI (Google Cloud EMEA Limited) | Document extraction (Smart Import, inbound order and invoice ingestion) and the Ask Druma assistant. | The content of documents you submit — which typically includes consignor, consignee and driver names, addresses, signatures and reference numbers — and the text of questions asked in Ask Druma together with the operational records returned to answer them. | EU — pinned to the europe-west1 region | ISO 27001 · ISO 27017 · ISO 27018 · SOC 1/2/3 | Stays in the EEAVertex AI Enterprise terms; customer data is not used to train Google’s foundation models. |
| Google Cloud Translation API | Automatic translation of messages between drivers and planners. | The text of the message being translated, which can contain names, places and free-text operational detail. | Google Cloud infrastructure — no EU-residency pin on this API | ISO 27001 · ISO 27017 · ISO 27018 · SOC 1/2/3 | Leaves the EEA2021 SCCs in the Google Cloud DPA. Message auto-translation can be switched off per user in profile settings. |
| Google LLC — Firebase Cloud Messaging | Delivery of push notifications to driver and planner devices. | Device push token and the notification title and body, which can contain an order reference, a place name or a person’s name. Notification content is transient and is not stored by Druma at Google. | Google infrastructure | — | Leaves the EEA2021 SCCs in the Google Cloud DPA; EU-US Data Privacy Framework. |
| Meta Platforms (WhatsApp Business Cloud API)Only if you connect it | Driver messaging over WhatsApp. | Driver phone number and the content of messages exchanged over the WhatsApp channel. | US | — | Leaves the EEA2021 SCCs. Off unless the company enables the WhatsApp driver channel. |
Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.
Regulatory, e-invoicing and transport-document recipients
Government systems in this group are statutory recipients rather than commercial sub-processors: submission is a legal obligation under Art. 6(1)(c) GDPR and cannot be switched off for the flows that require it.
| Recipient | Purpose | Personal data received | Location | Certifications | Leaves the EEA? |
|---|---|---|---|---|---|
| ANAF — Agenția Națională de Administrare Fiscală (Romania) | Romanian e-Transport (UIT) declarations and e-Factura invoice submission. | Consignor and consignee names and addresses, driver name, vehicle registration, goods description and weights, GPS waypoints for the declared journey, and the full content of the invoice. | EU (Romania) | — | Stays in the EEA |
| KSeF — Ministerstwo Finansów (Poland)Only if you connect it | Polish national e-invoicing: submission of the structured FA(3) invoice. | The complete invoice: seller and buyer NIP (Polish tax identifier), legal name and full address, plus all line items and amounts. Where the buyer or seller is a sole trader, the NIP and name are personal data. | EU (Poland) | — | Stays in the EEA |
| Recommand (Peppol Access Point, Belgium)Only if you connect it | Sending and receiving e-invoices over the Peppol network. | Buyer and seller legal name, address, VAT number, contact details, and the full invoice content. | EU (Belgium) | — | Stays in the EEA |
| SmartBill (Romania)Only if you connect it | Pushing issued invoices into the operator’s Romanian accounting suite. | Client name, VAT code, address and country, plus invoice lines, amounts, dates and notes. | EU (Romania) | — | Stays in the EEA |
| VIES — European Commission (DG TAXUD) | Validating a counterparty’s EU VAT number and retrieving its registered name and address. | The VAT number being checked is sent. For sole traders and one-person businesses a VAT number is personal data, and the response returns the registered name and address of that person. | EU (European Commission) | — | Stays in the EEA |
| TransFollow B.V. (Netherlands)Only if you connect it | Legacy eCMR issuance and signature capture. Druma now issues and seals eCMRs in-house as its primary provider; TransFollow only receives data for companies whose eCMR configuration still points at it. | Driver full name, vehicle registration, consignor and consignee name, address and email, cargo description and ADR particulars, declared value and charges, and the captured signature images together with the identifier of the person who signed. | EU (Netherlands) | — | Stays in the EEA |
Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.
Freight marketplaces and TMS integrations
| Recipient | Purpose | Personal data received | Location | Certifications | Leaves the EEA? |
|---|---|---|---|---|---|
| Transporeon GmbH (Germany, Trimble group)Only if you connect it | Accepting and declining tenders, and pushing transport status events to shippers using Transporeon. | Order and tender references, order status changes and timestamps, and the free-text reason given when a tender is declined. Inbound tender payloads received from Transporeon can contain consignment addresses and site contact details. | EU (Germany) | — | May leave the EEAProcessing is in the EU; the parent group is US-established, so group-level access is covered by the 2021 SCCs in the Transporeon DPA. |
| TIMOCOM GmbH (Germany)Only if you connect it | Freight-price insights for lane pricing. | Lane-level query parameters only (origin and destination areas, vehicle type, date). No personal data is forwarded. | EU (Germany) | — | Stays in the EEA |
| Trans.eu Group S.A. (Poland)Only if you connect it | Market price API for lane pricing. | Lane-level query parameters, plus the OAuth identity of the user account that authorised the connection. | EU (Poland) | — | Stays in the EEA |
Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.
Telematics and tachograph providers
Only the provider a company actually connects receives any data. Connecting one of these is optional; none is active by default.
| Recipient | Purpose | Personal data received | Location | Certifications | Leaves the EEA? |
|---|---|---|---|---|---|
| Webfleet (Bridgestone Mobility Solutions)Only if you connect it | Vehicle GPS positions and tachograph / driving-time data. | Vehicle identifiers and GPS position, speed and heading; tachograph working state, driving and rest times, and the tachograph driver card number used to match the record to a driver. | EU | — | Stays in the EEA |
| Geotab Inc.Only if you connect it | Vehicle GPS positions. | Vehicle identifiers and GPS position, speed and heading. | Depends on the customer’s own Geotab database host | — | May leave the EEADruma connects to whichever Geotab database host the Customer’s own Geotab account resolves to. Where that host is outside the EEA the Customer’s own agreement with Geotab governs the transfer. |
| Continental VDO (Continental Automotive, Germany)Only if you connect it | Vehicle GPS positions and tachograph / driving-time data. | Vehicle identifiers and GPS position; tachograph working state, driving and rest times, driver card number. | EU (Germany) | — | Stays in the EEA |
| Frotcom International (Portugal)Only if you connect it | Vehicle GPS positions and tachograph / driving-time data. | Vehicle identifiers and GPS position; tachograph working state, driving and rest times, driver card number. | EU (Portugal) | — | Stays in the EEA |
| Webeye / Eurowag (W.A.G. payment solutions)Only if you connect it | Vehicle GPS positions and tachograph / driving-time data. | Vehicle identifiers and GPS position; tachograph working state, driving and rest times, driver card number. | EU (Czechia) | — | Stays in the EEA |
| Samsara Inc.Only if you connect it | Vehicle GPS positions. | Vehicle identifiers and GPS position, speed and heading. | EU shard (api.eu.samsara.com) by default; a non-EU shard can be configured | — | May leave the EEADruma connects to Samsara’s EU shard by default. The vendor is US-established, so vendor-side access is covered by the 2021 SCCs in the Samsara DPA; a Customer that overrides the endpoint to a non-EU shard makes that transfer under its own agreement. |
| Vehicle-manufacturer rFMS endpoints — Scania CV AB (SE), Volvo Trucks / Volvo Group (SE), Renault Trucks (via the Volvo Group endpoint), DAF Trucks N.V. / PACCAR (NL), MAN Truck & Bus / TRATON “RIO” (DE), Mercedes-Benz Trucks / Daimler Truck AG (DE), IVECO S.p.A. (IT)Only if you connect it | Vehicle GPS positions and tachograph / driving-time data pulled straight from the truck manufacturer’s fleet-management interface (rFMS). | Vehicle identifiers, GPS position, speed, heading and odometer; tachograph working state and remaining daily driving time, matched to a driver by tachograph driver card number. | EU (Sweden, Netherlands, Germany, Italy depending on manufacturer) | — | Stays in the EEA |
Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.
Reefer telematics providers
Only the provider a company actually connects receives any data.
| Recipient | Purpose | Personal data received | Location | Certifications | Leaves the EEA? |
|---|---|---|---|---|---|
| Mapon (Latvia)Only if you connect it | Reefer temperature and trailer telemetry. | Trailer and reefer unit telemetry — temperature, set point, door and engine state, alarms — linked to a trailer, and therefore indirectly to whichever driver is assigned to it. | EU (Latvia) | — | Stays in the EEA |
| ORBCOMM Inc.Only if you connect it | Reefer temperature and trailer telemetry. | Trailer and reefer unit telemetry, linked to a trailer and therefore indirectly to the assigned driver. | US | — | Leaves the EEA2021 SCCs in the ORBCOMM agreement. |
| Thermo King TracKing (Trane Technologies)Only if you connect it | Reefer temperature and trailer telemetry. | Trailer and reefer unit telemetry, linked to a trailer and therefore indirectly to the assigned driver. | US / global | — | Leaves the EEA2021 SCCs in the Thermo King agreement. |
| Carrier — Lynx Fleet (Carrier Global Corporation)Only if you connect it | Reefer temperature and trailer telemetry. | Trailer and reefer unit telemetry — temperature, humidity, door and engine state, fuel level, alarms — linked to a trailer and therefore indirectly to the assigned driver. | US / global | — | Leaves the EEA2021 SCCs in the Carrier agreement. |
Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.
Pallet-pool accounts
| Recipient | Purpose | Personal data received | Location | Certifications | Leaves the EEA? |
|---|---|---|---|---|---|
| CHEP (Brambles Limited)Only if you connect it | Reading the operator’s pallet account balance and posting pallet movements. | No personal data has been identified in this data flow: the payload carries the operator’s own CHEP account number, pallet type, quantity and movement date. Listed here for completeness because the connection is made from Customer records. | Not determinable from the endpoint; confirmed at connection | — | May leave the EEANo personal data is transmitted. Where CHEP processing takes place outside the EEA it is covered by the Customer’s own CHEP account terms. |
Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.
The optional Druma Copilot feature is deliberately absent from this list. If a company administrator connects the company's own OpenAI, Anthropic or Google API key, the data sent through Copilot is processed by that provider under the Customer's own agreement with them. That provider is a sub-processor of the Customer, not of Druma, and Druma gives no transfer safeguard for it.