Privacy Notice

How Druma collects, uses, and protects personal data when you use the Druma TMS service.

Effective 19 August 2026 · Version 2026-08-19

The English version of this document is the legally binding version. Romanian, Dutch and Polish translations are provided for convenience only.

Who we are

The Druma TMS service ("Druma", "we", "us") is operated by WESLEY DATA CONSULTING S.R.L., registered in Romania, Trade Register no. J29/511/2024, CUI 49645204, with registered office at 19 Mărgaritarilor Street, Bărcănești Village, Prahova County, 107055, Romania.

For any question about this notice or about how we handle your personal data, contact us at privacy@druma.io.

Data protection contact. privacy@druma.io is the dedicated channel for all data-protection queries, requests and complaints. It is monitored within five business days and is the single point of contact for data subjects, customers and supervisory authorities.

On the appointment of a Data Protection Officer. Whether Article 37(1)(b) GDPR requires us to designate a DPO turns on whether our core activities consist of processing operations that, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale. We have assessed this against the specific facts of the Service — continuous vehicle position data from the telematics providers our customers connect, tachograph and driving-time records per driver, and a driver performance score derived from those records — and against the EDPB's guidance on DPOs (WP243). We are not asserting here that the answer is no. The assessment is documented, is being reviewed with qualified legal counsel, and we will designate and publish a DPO if the conclusion is that one is required. In the meantime the contact above performs the data-protection contact function in practice, and nothing about the presence or absence of a designated DPO limits your rights or the obligations described in this notice.

Data we process

Depending on your role, we process the following categories of personal data:

  • Account data — full name, email, phone, language, role, profile photo (if you upload one), company name, VAT number, billing address.
  • Operational data — orders, stops, pickup/delivery addresses, goods descriptions, references, internal notes.
  • Driver personal data — name, phone, status taps (assigned, at pickup, in transit, delivered), tachograph status and driving-time data sourced from the telematics provider your company connects, driver card number, licence / CPC / ADR / medical expiry dates as recorded by your employer, pre-trip and post-trip checklist completions, delay reports, waiting time and reason, photos uploaded with documents, and eCMR digital signatures.
  • Driver location data. This comes in three distinct forms and they are retained differently:
    • Live vehicle position from telematics — a single row per vehicle, overwritten on each update, with no history.
    • Driver-app position pings, and the coordinates recorded when a driver changes an order status (arrived, loaded, delivered) — retained 90 days, then deleted.
    • Romanian e-Transport GPS waypoints — retained 30 days.
  • Driver performance score — a score derived from records already held: on-time performance, fuel consumption against a benchmark, idling, incidents and compliance. See "Automated processing & AI" below; this is profiling, and we describe it as such.
  • Client and carrier contact data — names, phones, emails of your customers' and subcontractors' contact persons.
  • Communications — order messages between planners and drivers, attachments, optional chat with our AI assistant.
  • Document content — uploaded CMRs, PODs, eCMR signatures, invoices, fuel receipts, identity documents (where required by compliance flows).
  • Billing data — Stripe customer ID, subscription level, payment status, invoice amounts. We do not store card numbers; Stripe holds those.
  • Technical and security data — IP address (for authentication and rate limiting), app version, device type, error context (limited to what is needed to diagnose issues).
  • AI input data — content of documents you submit to Smart Import, content of messages translated by our auto-translate feature, context fed to the AI assistant. When the optional Ask Druma data assistant is enabled, this also includes the operational records (orders, fleet, finance, driver hours) and order notes returned by the questions a user asks — limited in each case to data that user's role already permits them to see.

Purposes and legal basis

We rely on the following legal bases under Article 6 GDPR:

  • Contract performance (Art. 6(1)(b)) — running your account, processing orders, generating invoices, eCMR creation, subscription billing through Stripe.
  • Legal obligation (Art. 6(1)(c)) — submitting Romanian e-Transport (UIT) and e-Factura declarations, Peppol EU e-invoicing, retaining accounting records (10 years per Romanian Accounting Law 82/1991 Art. 25), cabotage compliance, EU driving-hours monitoring (Reg. 561/2006), tachograph data requirements (Reg. 165/2014).
  • Legitimate interests (Art. 6(1)(f)) — we rely on this for the purposes below. For each one, the interest being pursued is named, because "legitimate interests" on its own tells you nothing:
    • Preventing fraud and abuse of the Service — our interest in protecting the Service, our customers and their counterparties from account takeover, fraudulent orders and payment fraud.
    • Information and network security — our interest, and that of every user, in keeping the Service available and uncompromised (rate limiting, IP-based abuse detection, error monitoring). This is expressly recognised as a legitimate interest by Recital 49 GDPR.
    • Audit logging of changes to sensitive records — our customers' interest in being able to reconstruct who changed what, which is also how a dispute between an operator, a client and a driver gets resolved.
    • Route calculation and ETA — the operator's and the consignee's interest in knowing when a load will arrive, which is the core function they are paying for.
    • Product improvement from aggregate usage patterns — our interest in understanding which features are used, using aggregated and non-identifying data.
    • Direct communication with business contacts — our interest in contacting the named business contacts at a prospective or existing customer about the Service.
    We have carried out a legitimate interests assessment (a balancing test) for each of these and concluded in each case that our interest is not overridden by your interests, rights and freedoms. A summary of each legitimate interests assessment is available on request from privacy@druma.io. You can object at any time under Article 21.
  • Consent (Art. 6(1)(a)) — where required and where consent can genuinely be freely given. We currently rely on it for nothing on the browser-storage side, because every entry we set is either strictly necessary or a preference you chose yourself. Where consent is used, you can withdraw it at any time. Note that we do not treat consent as a valid basis for monitoring employees at work: see "Automated processing & AI".

For drivers employed by an operator using Druma: the operator (your employer) is the data controller. Druma processes your data as a processor on their behalf, under contract. Your employer is responsible for providing you the full Article 13 information notice; this notice describes only what Druma itself does with your data.

On the in-app checkbox. When you first sign in — and again whenever this notice is materially revised — the app asks you to confirm you have received it. That single checkbox is an acknowledgement of notice under Article 13/14, nothing more: it is not consent, and it is not the legal basis for any processing described in this document. The basis for each purpose is set out above — principally contract performance, legal obligation, and legitimate interest — and does not depend on whether the checkbox is ticked. This applies identically whether you are a driver or a planner, dispatcher, fleet manager, customer service agent or administrator: everyone who holds an account is shown the notice and asked to acknowledge it.

Do you have to provide this data?

Article 13(2)(e) GDPR requires us to tell you whether providing personal data is a statutory or contractual requirement, whether you are obliged to provide it, and what happens if you do not.

If you work for an operator that uses Druma (planner, dispatcher, fleet manager, administrator): providing your name, work email and role is a contractual requirement — it is necessary for your employer's contract with Druma to be performed, because an account cannot exist without an identity to attach it to and permissions to attach to that identity. You are not obliged to provide it, but without it we cannot create an account and you cannot use the Service. A profile photo, a phone number and a preferred language are entirely optional; leaving them blank changes nothing except convenience.

If you are a driver: the position is mixed.

  • Partly contractual. Your name, phone and driver account are needed for your employer to assign you work through the Service. Without them you cannot be assigned an order in Druma — your employer would have to dispatch you by other means.
  • Partly statutory. Some of it your employer is legally obliged to record and keep, and Druma is the tool it uses to do that. Driving, rest and working-time records exist because of Regulation (EC) 561/2006; tachograph records and driver card data because of Regulation (EU) 165/2014; and, for journeys within Romania that fall in scope, vehicle and route data must be declared to ANAF under the e-Transport rules. For these, neither you nor your employer can opt out: the consequence of not providing them is that the journey cannot lawfully be operated, and your employer is exposed to enforcement action.
  • Optional. A profile photo, your interface language, and the driver app's screen-wake preference are optional and can be left unset.

If you are a contact person at a client, supplier or subcontracted carrier: your name, business email and phone are provided to us by the operator you deal with, so that transport documents and notifications can be addressed to a real person. It is a contractual requirement of that operator's relationship with its counterparty rather than of your own relationship with Druma. If it is not provided, communication falls back to a generic company address.

Nothing on this page requires you to provide special-category data (Article 9), and you should not put any into the Service.

Sub-processors and other recipients

The table below is the complete list of third parties that receive personal data from Druma, what each one is used for, what data it actually receives, where it processes that data, and whether the data leaves the EEA. It is generated from the same source as Annex III of our Data Processing Agreement, so the two documents can never say different things.

Entries marked "only if you connect it" receive nothing at all unless your company enables that specific integration. The telematics, reefer, e-invoicing, freight-marketplace and WhatsApp connectors are all in that group — none is on by default.

Core platform and infrastructure

RecipientPurposePersonal data receivedLocationCertificationsLeaves the EEA?
Supabase (Supabase, Inc.)Managed Postgres database, authentication, file storage, Edge Functions — the primary store for all Customer Data.All personal data held in the Service: account and contact data, orders and stops, driver data, documents and PODs, messages, audit records.EU — Ireland (eu-west-1)SOC 2 Type II · HIPAAMay leave the EEAData is stored in the EU. The vendor is US-established, so remote support access is covered by the 2021 SCCs in the Supabase DPA.
Cloudflare, Inc.CDN, static hosting for the web app and marketing site, TLS termination, DDoS and bot protection.IP address and request metadata (URL, user agent, timestamp) of every visitor; the content of requests in transit.Global edge network, EU termination preferredISO 27001 · SOC 2 Type II · PCI DSSLeaves the EEA2021 SCCs in the Cloudflare DPA; EU-US Data Privacy Framework where applicable.
Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.)Subscription billing, seat metering, payment processing.Billing contact name and email, company name, VAT number, billing address, subscription level and payment status. Druma never receives or stores card numbers.EU (Ireland) and USPCI DSS Level 1 · SOC 1 & SOC 2Leaves the EEA2021 SCCs in the Stripe DPA; EU-US Data Privacy Framework.
Sentry (Functional Software, Inc.)Application error monitoring and crash reporting.User ID, IP address, browser and app version, and the error context attached to a crash — which can incidentally include record identifiers.EU (Sentry EU region)SOC 2 Type IIMay leave the EEAData is stored in the Sentry EU region. The vendor is US-established, so support access is covered by the 2021 SCCs in the Sentry DPA.

Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.

Email

RecipientPurposePersonal data receivedLocationCertificationsLeaves the EEA?
Resend, Inc.Both directions of email. Outbound: all transactional email (invitations, notifications, document delivery, dunning). Inbound: Druma retrieves messages sent to your Druma email aliases from Resend’s receiving API — including the full message body and the raw attachment bytes — for the order, carrier/supplier invoice, payment and CRM ingestion pipelines.Sender and recipient names and email addresses; the full text and HTML body of inbound and outbound messages; and the content of attachments (transport orders, invoices, PODs, remittance advices), which routinely contain names, addresses, VAT numbers and bank details.USLeaves the EEA2021 SCCs in the Resend DPA. Migration to an EU-resident email provider is on the roadmap.

Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.

Routing, geocoding and map tiles

RecipientPurposePersonal data receivedLocationCertificationsLeaves the EEA?
PTV Logistics GmbHPrimary truck-routing, distance-matrix and ETA engine.Pickup and delivery coordinates and addresses, vehicle profile parameters. No name is sent.EU (Germany)Stays in the EEA
HERE Global B.V.Geocoding, address autosuggest, reverse geocoding, fallback routing and ETA.Pickup and delivery addresses and coordinates; address fragments typed into search boxes; vehicle positions used to compute an ETA.EU (Netherlands / EU endpoints)Stays in the EEA
CARTOBasemap tiles for the map views in the planner and operations screens.Your browser requests tiles directly from CARTO’s CDN, so CARTO receives your IP address, user agent, and the tile coordinates — which reveal the geographic area you are looking at. No account or order data is sent.Global CDN edgeMay leave the EEATiles are served from a global CDN, so the serving edge is not guaranteed to be in the EEA. Only IP and tile coordinates are exposed; no Customer Data is transmitted.
OpenStreetMap FoundationBasemap tiles for a small number of secondary map views.Your browser requests tiles directly from the OSM tile servers, so the Foundation receives your IP address, user agent, and the tile coordinates. No account or order data is sent.United KingdomLeaves the EEAThe United Kingdom is covered by the European Commission’s adequacy decision of 28 June 2021 (as extended).

Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.

AI, translation and messaging

RecipientPurposePersonal data receivedLocationCertificationsLeaves the EEA?
Google Cloud — Vertex AI (Google Cloud EMEA Limited)Document extraction (Smart Import, inbound order and invoice ingestion) and the Ask Druma assistant.The content of documents you submit — which typically includes consignor, consignee and driver names, addresses, signatures and reference numbers — and the text of questions asked in Ask Druma together with the operational records returned to answer them.EU — pinned to the europe-west1 regionISO 27001 · ISO 27017 · ISO 27018 · SOC 1/2/3Stays in the EEAVertex AI Enterprise terms; customer data is not used to train Google’s foundation models.
Google Cloud Translation APIAutomatic translation of messages between drivers and planners.The text of the message being translated, which can contain names, places and free-text operational detail.Google Cloud infrastructure — no EU-residency pin on this APIISO 27001 · ISO 27017 · ISO 27018 · SOC 1/2/3Leaves the EEA2021 SCCs in the Google Cloud DPA. Message auto-translation can be switched off per user in profile settings.
Google LLC — Firebase Cloud MessagingDelivery of push notifications to driver and planner devices.Device push token and the notification title and body, which can contain an order reference, a place name or a person’s name. Notification content is transient and is not stored by Druma at Google.Google infrastructureLeaves the EEA2021 SCCs in the Google Cloud DPA; EU-US Data Privacy Framework.
Meta Platforms (WhatsApp Business Cloud API)Only if you connect itDriver messaging over WhatsApp.Driver phone number and the content of messages exchanged over the WhatsApp channel.USLeaves the EEA2021 SCCs. Off unless the company enables the WhatsApp driver channel.

Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.

Regulatory, e-invoicing and transport-document recipients

Government systems in this group are statutory recipients rather than commercial sub-processors: submission is a legal obligation under Art. 6(1)(c) GDPR and cannot be switched off for the flows that require it.

RecipientPurposePersonal data receivedLocationCertificationsLeaves the EEA?
ANAF — Agenția Națională de Administrare Fiscală (Romania)Romanian e-Transport (UIT) declarations and e-Factura invoice submission.Consignor and consignee names and addresses, driver name, vehicle registration, goods description and weights, GPS waypoints for the declared journey, and the full content of the invoice.EU (Romania)Stays in the EEA
KSeF — Ministerstwo Finansów (Poland)Only if you connect itPolish national e-invoicing: submission of the structured FA(3) invoice.The complete invoice: seller and buyer NIP (Polish tax identifier), legal name and full address, plus all line items and amounts. Where the buyer or seller is a sole trader, the NIP and name are personal data.EU (Poland)Stays in the EEA
Recommand (Peppol Access Point, Belgium)Only if you connect itSending and receiving e-invoices over the Peppol network.Buyer and seller legal name, address, VAT number, contact details, and the full invoice content.EU (Belgium)Stays in the EEA
SmartBill (Romania)Only if you connect itPushing issued invoices into the operator’s Romanian accounting suite.Client name, VAT code, address and country, plus invoice lines, amounts, dates and notes.EU (Romania)Stays in the EEA
VIES — European Commission (DG TAXUD)Validating a counterparty’s EU VAT number and retrieving its registered name and address.The VAT number being checked is sent. For sole traders and one-person businesses a VAT number is personal data, and the response returns the registered name and address of that person.EU (European Commission)Stays in the EEA
TransFollow B.V. (Netherlands)Only if you connect itLegacy eCMR issuance and signature capture. Druma now issues and seals eCMRs in-house as its primary provider; TransFollow only receives data for companies whose eCMR configuration still points at it.Driver full name, vehicle registration, consignor and consignee name, address and email, cargo description and ADR particulars, declared value and charges, and the captured signature images together with the identifier of the person who signed.EU (Netherlands)Stays in the EEA

Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.

Freight marketplaces and TMS integrations

RecipientPurposePersonal data receivedLocationCertificationsLeaves the EEA?
Transporeon GmbH (Germany, Trimble group)Only if you connect itAccepting and declining tenders, and pushing transport status events to shippers using Transporeon.Order and tender references, order status changes and timestamps, and the free-text reason given when a tender is declined. Inbound tender payloads received from Transporeon can contain consignment addresses and site contact details.EU (Germany)May leave the EEAProcessing is in the EU; the parent group is US-established, so group-level access is covered by the 2021 SCCs in the Transporeon DPA.
TIMOCOM GmbH (Germany)Only if you connect itFreight-price insights for lane pricing.Lane-level query parameters only (origin and destination areas, vehicle type, date). No personal data is forwarded.EU (Germany)Stays in the EEA
Trans.eu Group S.A. (Poland)Only if you connect itMarket price API for lane pricing.Lane-level query parameters, plus the OAuth identity of the user account that authorised the connection.EU (Poland)Stays in the EEA

Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.

Telematics and tachograph providers

Only the provider a company actually connects receives any data. Connecting one of these is optional; none is active by default.

RecipientPurposePersonal data receivedLocationCertificationsLeaves the EEA?
Webfleet (Bridgestone Mobility Solutions)Only if you connect itVehicle GPS positions and tachograph / driving-time data.Vehicle identifiers and GPS position, speed and heading; tachograph working state, driving and rest times, and the tachograph driver card number used to match the record to a driver.EUStays in the EEA
Geotab Inc.Only if you connect itVehicle GPS positions.Vehicle identifiers and GPS position, speed and heading.Depends on the customer’s own Geotab database hostMay leave the EEADruma connects to whichever Geotab database host the Customer’s own Geotab account resolves to. Where that host is outside the EEA the Customer’s own agreement with Geotab governs the transfer.
Continental VDO (Continental Automotive, Germany)Only if you connect itVehicle GPS positions and tachograph / driving-time data.Vehicle identifiers and GPS position; tachograph working state, driving and rest times, driver card number.EU (Germany)Stays in the EEA
Frotcom International (Portugal)Only if you connect itVehicle GPS positions and tachograph / driving-time data.Vehicle identifiers and GPS position; tachograph working state, driving and rest times, driver card number.EU (Portugal)Stays in the EEA
Webeye / Eurowag (W.A.G. payment solutions)Only if you connect itVehicle GPS positions and tachograph / driving-time data.Vehicle identifiers and GPS position; tachograph working state, driving and rest times, driver card number.EU (Czechia)Stays in the EEA
Samsara Inc.Only if you connect itVehicle GPS positions.Vehicle identifiers and GPS position, speed and heading.EU shard (api.eu.samsara.com) by default; a non-EU shard can be configuredMay leave the EEADruma connects to Samsara’s EU shard by default. The vendor is US-established, so vendor-side access is covered by the 2021 SCCs in the Samsara DPA; a Customer that overrides the endpoint to a non-EU shard makes that transfer under its own agreement.
Vehicle-manufacturer rFMS endpoints — Scania CV AB (SE), Volvo Trucks / Volvo Group (SE), Renault Trucks (via the Volvo Group endpoint), DAF Trucks N.V. / PACCAR (NL), MAN Truck & Bus / TRATON “RIO” (DE), Mercedes-Benz Trucks / Daimler Truck AG (DE), IVECO S.p.A. (IT)Only if you connect itVehicle GPS positions and tachograph / driving-time data pulled straight from the truck manufacturer’s fleet-management interface (rFMS).Vehicle identifiers, GPS position, speed, heading and odometer; tachograph working state and remaining daily driving time, matched to a driver by tachograph driver card number.EU (Sweden, Netherlands, Germany, Italy depending on manufacturer)Stays in the EEA

Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.

Reefer telematics providers

Only the provider a company actually connects receives any data.

RecipientPurposePersonal data receivedLocationCertificationsLeaves the EEA?
Mapon (Latvia)Only if you connect itReefer temperature and trailer telemetry.Trailer and reefer unit telemetry — temperature, set point, door and engine state, alarms — linked to a trailer, and therefore indirectly to whichever driver is assigned to it.EU (Latvia)Stays in the EEA
ORBCOMM Inc.Only if you connect itReefer temperature and trailer telemetry.Trailer and reefer unit telemetry, linked to a trailer and therefore indirectly to the assigned driver.USLeaves the EEA2021 SCCs in the ORBCOMM agreement.
Thermo King TracKing (Trane Technologies)Only if you connect itReefer temperature and trailer telemetry.Trailer and reefer unit telemetry, linked to a trailer and therefore indirectly to the assigned driver.US / globalLeaves the EEA2021 SCCs in the Thermo King agreement.
Carrier — Lynx Fleet (Carrier Global Corporation)Only if you connect itReefer temperature and trailer telemetry.Trailer and reefer unit telemetry — temperature, humidity, door and engine state, fuel level, alarms — linked to a trailer and therefore indirectly to the assigned driver.US / globalLeaves the EEA2021 SCCs in the Carrier agreement.

Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.

Pallet-pool accounts

RecipientPurposePersonal data receivedLocationCertificationsLeaves the EEA?
CHEP (Brambles Limited)Only if you connect itReading the operator’s pallet account balance and posting pallet movements.No personal data has been identified in this data flow: the payload carries the operator’s own CHEP account number, pallet type, quantity and movement date. Listed here for completeness because the connection is made from Customer records.Not determinable from the endpoint; confirmed at connectionMay leave the EEANo personal data is transmitted. Where CHEP processing takes place outside the EEA it is covered by the Customer’s own CHEP account terms.

Certifications are those the recipient publishes for itself, shown so you can verify them at source. They are not an audit Druma has performed, and a blank means we have not found a published certification — not that none exists.

We will give you at least 30 days' advance notice by email before a new sub-processor begins processing your data.

Optional Druma Copilot (bring your own AI): if a company administrator enables the opt-in, default-off Druma Copilot and connects their own OpenAI, Anthropic, or Google API key, the questions and operational data that user chooses to send are processed by that provider directly under the operator's own agreement with them — not under this Privacy Notice or our sub-processor list, and possibly outside the EU. See our AI Disclosure for detail.

International transfers

Druma is established in Romania and your data is hosted in the European Union by default. Where a recipient in the list above processes personal data outside the EEA, Druma is the exporter for that transfer, and it is covered by the European Commission's 2021 Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supported by a transfer impact assessment — or, where the destination benefits from an adequacy decision, by that decision.

These are the recipients for which data leaves, or may leave, the EEA:

  • Supabase (Supabase, Inc.) (may leave the EEA) — Data is stored in the EU. The vendor is US-established, so remote support access is covered by the 2021 SCCs in the Supabase DPA.
  • Cloudflare, Inc. (leaves the EEA) — 2021 SCCs in the Cloudflare DPA; EU-US Data Privacy Framework where applicable.
  • Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.) (leaves the EEA) — 2021 SCCs in the Stripe DPA; EU-US Data Privacy Framework.
  • Sentry (Functional Software, Inc.) (may leave the EEA) — Data is stored in the Sentry EU region. The vendor is US-established, so support access is covered by the 2021 SCCs in the Sentry DPA.
  • Resend, Inc. (leaves the EEA) — 2021 SCCs in the Resend DPA. Migration to an EU-resident email provider is on the roadmap.
  • CARTO (may leave the EEA) — Tiles are served from a global CDN, so the serving edge is not guaranteed to be in the EEA. Only IP and tile coordinates are exposed; no Customer Data is transmitted.
  • OpenStreetMap Foundation (leaves the EEA) — The United Kingdom is covered by the European Commission’s adequacy decision of 28 June 2021 (as extended).
  • Google Cloud Translation API (leaves the EEA) — 2021 SCCs in the Google Cloud DPA. Message auto-translation can be switched off per user in profile settings.
  • Google LLC — Firebase Cloud Messaging (leaves the EEA) — 2021 SCCs in the Google Cloud DPA; EU-US Data Privacy Framework.
  • Meta Platforms (WhatsApp Business Cloud API) (leaves the EEA) — 2021 SCCs. Off unless the company enables the WhatsApp driver channel.
  • Transporeon GmbH (Germany, Trimble group) (may leave the EEA) — Processing is in the EU; the parent group is US-established, so group-level access is covered by the 2021 SCCs in the Transporeon DPA.
  • Geotab Inc. (may leave the EEA) — Druma connects to whichever Geotab database host the Customer’s own Geotab account resolves to. Where that host is outside the EEA the Customer’s own agreement with Geotab governs the transfer.
  • Samsara Inc. (may leave the EEA) — Druma connects to Samsara’s EU shard by default. The vendor is US-established, so vendor-side access is covered by the 2021 SCCs in the Samsara DPA; a Customer that overrides the endpoint to a non-EU shard makes that transfer under its own agreement.
  • ORBCOMM Inc. (leaves the EEA) — 2021 SCCs in the ORBCOMM agreement.
  • Thermo King TracKing (Trane Technologies) (leaves the EEA) — 2021 SCCs in the Thermo King agreement.
  • Carrier — Lynx Fleet (Carrier Global Corporation) (leaves the EEA) — 2021 SCCs in the Carrier agreement.
  • CHEP (Brambles Limited) (may leave the EEA) — No personal data is transmitted. Where CHEP processing takes place outside the EEA it is covered by the Customer’s own CHEP account terms.

Copies of the Standard Contractual Clauses, with commercial terms redacted, and of the transfer impact assessments are available on request from privacy@druma.io.

Note that the map-tile providers are a slightly different case: your browser contacts them directly when you open a map view, so what reaches them is your IP address and the coordinates of the tiles you are looking at — not your account or order data. See our Cookie Policy.

Retention periods

We keep personal data only as long as we need it for the purposes above. Each period below is enforced by an automated deletion job, except where the row says otherwise.

Location data

  • Live vehicle position from telematics — a single row per vehicle, overwritten on each update, with no history.
  • Driver-app position pings, and the coordinates recorded when a driver changes an order status (arrived, loaded, delivered) — 90 days, then deleted.
  • Romanian e-Transport GPS waypoints30 days.

Driver and compliance records

  • Tachograph and driving-hours records24 months. Regulation (EU) 165/2014 Art. 36 requires an operator to be able to produce at least the preceding 12 months; we keep 24 so that a record is still available during an enforcement or audit window that reaches back beyond the statutory minimum.
  • Driver licence, CPC, ADR and medical details, and the documents behind them — these are your employer's employment records, held in Druma on its behalf. We do not delete them on a timer, because it is not our decision when an employment record stops being needed. They are removed when your employer deletes your driver record, and in any event when the company's data is purged under the 90-day rule below.
  • Driver performance score — the monthly score snapshots are kept for the life of the account and are removed with it. The score is recomputed from underlying records, so it fades as those records reach their own retention limits.

Documents, messages and AI

  • eCMR documents and eFTI consignment data7 years, covering the CMR Convention Art. 32 limitation period and the eFTI authority-access requirements of Regulation (EU) 2020/1056.
  • Other transport documents and PODs (CMR scans, delivery notes, weighbridge tickets, damage reports, photos) — kept for as long as the order they belong to is kept, and removed with the account under the 90-day rule below. They are not deleted on a separate timer.
  • Voice notes attached to messages7 days, then the audio is deleted.
  • Order messages — kept for the life of the order. A deleted message is purged 90 days after deletion.
  • Other chat and direct messages — kept for the life of the account and removed with it.
  • AI inputs — for document and message extraction, Druma does not keep a separate copy of what is sent to an AI provider. The document or message itself is retained under its own rule above, and the extracted result becomes an ordinary record. Two exceptions: the CMR validation log, where the raw AI request and response are blanked at 18 months while the validation verdict and confidence score are kept, so the decision remains auditable without keeping the source text; and assistant conversations, covered by the next entry.
  • Ask Druma assistant conversations90 days from the last message in the conversation, then deleted automatically. This covers the Assistant tab (the optional data assistant and Druma Copilot), where the conversation is saved so you can pick it up again later. A saved conversation is visible only to the user who created it — not to colleagues and not to a company administrator. You can delete any of your conversations at any time from the assistant panel, and they are included in a data export and removed with your account. Help-mode chat is not saved at all: it stays in the browser tab and is discarded when you close or reload the page. The one exception is if you escalate a help chat with "Talk to a human" — the transcript is then attached to that support conversation so the support agent can see the context, and the whole support conversation is deleted 90 days after its last activity.

Operational, technical and financial records

  • Audit log12 months, then purged automatically.
  • Notification log (record of emails, push and in-app notifications sent) — 180 days.
  • ETA history180 days.
  • Webhook event log (used to avoid processing the same event twice) — 30 days.
  • Technical and security data (IP address, device and app version, error context) — kept only as long as needed to diagnose and secure the Service, and removed with the account. Crash and error reports held by our error-monitoring provider follow that provider's own retention schedule.
  • Invoices and accounting records10 years from issue date, to comply with Romanian Accounting Law 82/1991 Art. 25 and EU VAT Directive Art. 244. They are archived out of the working views after 3 years.
  • Quotes — expire on the validity date set by the operator; the record then follows the accounting retention above.

Account and company data

  • Account data — kept for the duration of the subscription. After termination, suspension or a deletion request, a single 90-day window applies: the data can be exported and the account can be restored throughout, and at the end of the 90 days it is purged. The only exceptions are records subject to the legal retention periods above (invoices, eCMR/eFTI, audit log), which stay isolated and access-controlled until their own period expires.

The same 90-day period appears in section 13 of our Terms of Service and in section 11 of our DPA. Deletion also reaches encrypted backups: they are not selectively editable, so data still present in a backup is overwritten as that backup rotates out, no later than 35 days after deletion from the live systems.

Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you (Art. 15) — see "How to make an access request" immediately below.
  • Rectification of inaccurate data (Art. 16) — your own name, contact details, language and photo are directly editable in your profile. Operational records entered about you by your employer are corrected by your employer.
  • Erasure (Art. 17) — request via privacy@druma.io, or ask your employer, who can delete your user account from the Service. Subject to the legal retention exceptions in the retention table.
  • Restriction of processing (Art. 18) — request via privacy@druma.io.
  • Data portability (Art. 20) — we provide the data in machine-readable JSON and CSV.
  • Object to processing based on legitimate interests (Art. 21) — including to the driver performance score.
  • Information about automated decision-making and profiling (Art. 22 and Art. 13(2)(f)) — see "Automated processing & AI" below.

How to make an access request. Send it to privacy@druma.io. We will identify the personal data held about you across the Service and provide it, together with the Article 15(1) information, within one month. This is the route for every individual — planner, driver, client contact or carrier contact — and it costs you nothing.

A note on the in-app export, so there is no misunderstanding. The Service does contain a GDPR export tool at Settings → GDPR, but it is not an individual access mechanism: it is available only to administrators of a company, and it exports that company's entire dataset rather than one person's data. It exists so an operator can meet its own obligations as controller. If you are a driver or an employee, do not rely on it to exercise your own Article 15 right — email us instead, and we will produce a response scoped to you. We are building a per-subject export; when it ships we will say so here and describe both routes.

Where Druma acts as processor for your employer, we may need to route your request through them as the controller. If we do, we will tell you promptly and pass the request on without delay, so nothing is lost.

We respond within one month. We may extend by up to two further months for complex requests; we will tell you within the first month if so. We do not charge a fee, unless requests are manifestly unfounded or excessive.

Supervisory authority

You have the right to lodge a complaint with a supervisory authority — in particular in the EU country where you live, work, or where the alleged infringement took place:

Security

We protect your data with measures including:

  • Encryption in transit (TLS 1.2+) and at rest (managed by Supabase).
  • Row-level security on every database table — strict tenant isolation by company.
  • JWT, HMAC, or service-role authentication on every server endpoint.
  • Secrets stored in a managed vault, never in source code.
  • Rate limiting on user-facing APIs that call paid third-party services.
  • Comprehensive audit log of changes to sensitive records.
  • Regular review of sub-processor security posture.

If a personal data breach affects you, we will notify the operator who controls your data within 72 hours of becoming aware, and where applicable we will notify you directly without undue delay.

Cookies

Druma's own code sets no cookies at all. What it uses is browser storage — localStorage and sessionStorage for sign-in state, your active company, and your interface preferences, plus an IndexedDB store on a driver's phone that holds documents queued for upload while offline. The only true cookie in play is the bot-management cookie set by our CDN provider. We set nothing for analytics or marketing.

Two things do reach a third party directly from your browser: our CDN provider sees request metadata for every page load, and the map views fetch basemap tiles from CARTO and the OpenStreetMap Foundation, which therefore see your IP address and the area of the map you are viewing. Our Cookie Policy has the full inventory grouped by purpose, covering the application, the driver app and the public website.

Automated processing & AI

Druma's core AI features — document extraction (Smart Import, inbound invoice ingestion), driver-planner message translation, and the in-app AI assistant — run on Google Vertex AI in the EU (europe-west1); Vertex AI Enterprise terms prohibit using customer data to train Google's models.

Separately, a company administrator can opt in to the Druma Copilot (bring your own AI) — off by default. Once enabled and configured with the company's own OpenAI, Anthropic, or Google API key, the operational data a user chooses to query is sent to that provider under the operator's own agreement with them, and may leave the EU.

Every AI output is treated as a draft. A human user must review and confirm before any data is created, modified, or sent. There are no fully automated decisions producing legal or similarly significant effects (Art. 22). You can opt out of message auto-translation in your profile settings.

Profiling: the driver performance score. Druma calculates a driver performance score, and we want to be precise about what it is rather than hide it behind the fact that it is not "AI".

  • It is profiling within the meaning of Article 4(4) GDPR: it is automated processing of personal data used to evaluate aspects relating to a person, in particular performance at work and reliability. We disclose it as such.
  • It is not artificial intelligence and not machine learning. It is a fixed, published weighted average of five components — on-time performance (35%), fuel consumption against a benchmark (20%), idling (15%), incidents (15%) and compliance with driving-time rules (15%). No model is trained or applied, and no data is sent to an AI provider to produce it.
  • It does not produce legal or similarly significant effects and is not an automated decision under Article 22. Nothing in Druma acts on the score by itself: it is a figure shown to a fleet manager, who decides what, if anything, to do with it.
  • Missing data does not count against you. A component with no data is excluded and the remaining weights are rescaled, rather than the component being scored zero. Where the sample is too small to be meaningful, the component and the overall score are flagged as low-confidence.
  • Your rights. You can ask for the components behind your score and how each was calculated, contest a figure you believe is wrong, and object to the profiling under Article 21 — email privacy@druma.io, or raise it with your employer, who decides whether to use the feature at all.

Continuous position data, tachograph records and a performance score together amount to monitoring of people at work. Your employer, not Druma, decides whether to switch these on and on what legal basis — and, importantly, consent is not a valid basis for monitoring employees, because of the imbalance of power in an employment relationship. We publish a data protection impact assessment covering driver monitoring, which operators can use as an input to their own assessment; ask us for a copy.

See our separate AI Disclosure for technical detail.

eFTI authority access

Druma has implemented readiness for the EU eFTI Regulation (EU) 2020/1056, which enables competent authorities (customs officers, transport enforcement) to access transport consignment data electronically from 9 July 2027. Where an eCMR or transport order is linked to an eFTI unique link (UIL), the consignment data corresponding to that UIL — including cargo description, route, and consignment parties — may be accessed by authorised authorities via the eFTI platform during a roadside inspection or port check.

This access is based on Article 6(1)(c) GDPR (legal obligation). No additional consent is required. Druma logs each authority-access event in the eFTI operation log as required by the Regulation.

Changes to this notice

We may update this notice from time to time. The version number and effective date at the top will be revised. For material changes we will notify registered users by email at least 30 days before the new version takes effect, and will request re-acceptance on next sign-in.

Contact

For privacy questions: privacy@druma.io. For general support: support@druma.io.