GDPR / Compliance
- Accueil
- /
- GDPR / Compliance
Last updated: January 1, 2025
GDPR Principles We Follow
Lawfulness & Transparency
We process data only on lawful grounds and are fully transparent about how your data is used.
Purpose Limitation
Data is collected for specific, explicit purposes and not processed in ways incompatible with those purposes.
Data Minimisation
We collect only the data that is strictly necessary to provide the Service.
Accuracy
We take reasonable steps to ensure personal data is accurate and kept up to date.
Storage Limitation
Data is retained only for as long as necessary, then securely deleted.
Security
We apply technical and organisational measures to protect data against unauthorised access or loss.
Your Rights Under GDPR
You can request a copy of all personal data we hold about you at any time.
You can ask us to correct inaccurate or incomplete personal data.
You can request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
You can ask us to temporarily restrict processing of your data in certain circumstances.
You can request your data in a structured, machine-readable format (JSON/CSV).
You can object to processing based on legitimate interests or for direct marketing.
Our Role Under GDPR
E-Delivery acts as a Data Processor on behalf of its customers (delivery companies), who are the Data Controllers. We process personal data (sender details, recipient details, driver information) strictly according to the instructions of our customers and the terms of our Data Processing Agreement (DPA). For data relating to our own users (account holders, admins), E-Delivery acts as a Data Controller.
Legal Basis for Processing
We process personal data on the following legal bases: • Contract performance: processing necessary to provide the Service you have subscribed to. • Legitimate interests: improving the Service, security monitoring, fraud prevention. • Legal obligation: retaining invoices and financial records as required by law. • Consent: analytics cookies and marketing communications (where applicable).
Data Processing Agreement
As a Data Processor, we offer a Data Processing Agreement (DPA) to all customers. The DPA defines the scope of processing, the obligations of both parties, and the sub-processors we use. To request a signed DPA, contact us at contact@getedelivery.com.
Sub-Processors
We use the following categories of sub-processors: • Cloud infrastructure: OVH Cloud • Transactional email: third-party SMTP provider • Payment processing: third-party payment gateway All sub-processors are bound by GDPR-compliant data processing agreements.
International Data Transfers
Your data is primarily stored in OVH's EU data centers. Where data is transferred outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission.
Data Breach Notification
In the event of a personal data breach that poses a risk to individuals, we will notify affected customers within 72 hours of becoming aware of the breach, as required by GDPR Article 33. We will also provide guidance on steps to take.
Contact & Complaints
To exercise your GDPR rights or raise a concern, contact us at: contact@getedelivery.com If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.