Document

Data Processing Agreement

In force from 1 September 2026 · version 1

This is an English translation provided for convenience. The Polish version is legally binding. In case of any discrepancy, the Polish version prevails. Read the Polish version.

Contents · 10 sections
In short
  • You are the controller of your drivers’ and business partners’ data. We only process it — on your instructions.
  • We do nothing with it beyond what the service needs to work.
  • Our subcontractors are listed by name. We give 30 days’ notice of any change.
  • When the agreement ends, we return the data or delete it — you decide.

This summary makes the document easier to read but does not replace it. The full document is binding — in its Polish version.

1What this document is

This document is an agreement on the processing of personal data within the meaning of Art. 28 of the General Data Protection Regulation (GDPR). You conclude it with MOVGRANTO Sp. z o.o. at the moment you conclude the agreement for the provision of the BusiKM service. It forms an integral part of the Terms of Service and does not require a separate signature.

Controller
— the Client, that is, the business that uses the service and enters data into it.
Processor
— MOVGRANTO Sp. z o.o., that is, us.
Subprocessor
— a further processor that we use to provide the service. The list of subprocessors is in the Subprocessors document.

If your organisation requires a separate data processing agreement to be signed on its own template, write to us — we will agree its content individually.

2Subject matter, nature and purpose of processing

You entrust us with the processing of personal data solely for the purpose of providing the BusiKM service: managing orders, routes, working time, costs, documents and billing, and making them available to the persons to whom you have granted access.

Processing consists of performing the following operations on the data:

  1. collection and recording — through the application’s forms and the driver app;
  2. storage — on the servers of the subprocessors indicated on the list;
  3. organisation, viewing and retrieval — for display and reporting purposes;
  4. transmission — to recipients indicated by you, including clients and accounting;
  5. erasure — on your instructions and after the agreement ends.

We do not use the entrusted data for our own purposes, including marketing and analytics, and we do not sell it.

3Duration

We process the data for the term of the service agreement and for 30 days after it ends — so that you have time to download the data. After that period, we proceed in accordance with section 9.

4Type of data and categories of data subjects

Category of data subjectsWhat dataWhere it comes from
Driversfirst name and surname, e-mail address, driving licence number and medical examination dates, vehicle position during an order, driving and break times, photos of documents; phone number, if you enter itentered by you when sending the invitation, or by the driver in the app
Office stafffirst name and surname, e-mail address, role in the accountentered by you
Contact persons at business partnersfirst name and surname, e-mail address, phone number, company detailsentered by you or taken from documents

You do not entrust us with special categories of data (Art. 9 GDPR) or data relating to criminal convictions. If you enter such data nonetheless, you do so at your own risk.

5Our obligations

We undertake that we:

  1. process the data only on your documented instructions — your use of the application’s functions also constitutes an instruction;
  2. will inform you before processing if the law imposes an obligation to process on us, unless the law prohibits this;
  3. ensure that persons authorised to access the data are bound by confidentiality;
  4. apply the security measures described in section 6;
  5. assist you in fulfilling your obligation to respond to requests from data subjects;
  6. assist you with data protection impact assessments and prior consultations with the supervisory authority, to the extent of the information available to us;
  7. return or delete the data after the agreement ends, in accordance with section 9;
  8. make available to you the information necessary to demonstrate compliance and allow audits under the terms of section 8.

If we consider that your instruction infringes the GDPR or other data protection provisions, we will inform you immediately.

6Security

We apply technical and organisational measures appropriate to the risk, in particular:

  1. encryption of data in transit (TLS) and at rest;
  2. role-based access control and two-factor authentication for administrative access;
  3. separation of individual clients’ data;
  4. backups made daily, stored in Europe and tested for restorability;
  5. logging of access to production data and periodic review of permissions;
  6. a procedure for handling personal data breaches.

7Subprocessors

You give us general authorisation to engage subprocessors. We keep their current list — with the name, scope and country of processing — in the Subprocessors document.

We notify you by e-mail at least 30 days in advance of any intended addition or replacement of a subprocessor. During that time, you may raise a reasoned objection. If we cannot find a solution, you may terminate the agreement with effect from the date the change takes effect, at no cost.

We impose on each subprocessor the same data protection obligations that apply to us. We are liable to you for the actions of subprocessors as for our own.

8Breaches and audits

We notify you of a breach of the entrusted data without undue delay, and no later than 24 hours after becoming aware of it. We provide a description of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures we have taken.

You have the right to audit the processing, including inspections, carried out by you or by an auditor mandated by you. You announce an audit 14 days in advance and carry it out during business hours, no more than once a year — unless the reason is an identified breach. Instead of an audit, we may present a current audit report from an independent party.

9What happens after the agreement ends

For 30 days after the agreement ends, you can access and download the data. After that period, we delete the data from production systems. The data disappears from backups as they are rotated, no later than after 90 days.

If you would rather receive the data than have it deleted, or you want us to delete it earlier — write to us, and we will do so and confirm that it has been done.

We may retain the data for longer only where required by law. In that case, we inform you of the legal basis and scope.

10Liability and contact

Each party is liable for damage caused by processing under the rules set out in Art. 82 GDPR.

Please send matters concerning data processing to kontakt@busikm.pl. The subject line “data processing agreement” is enough.

Last updated: 1 September 2026

Other documents:Terms of ServicePrivacy PolicySubprocessors

Have a question about this document? Write to: kontakt@busikm.pl