• contact@getedelivery.com
  • +216 52 838 318
  • Lun - Ven, 9h - 18h (GMT+1)

GDPR / Compliance

Last updated: January 1, 2025

GDPR Principles We Follow

Lawfulness & Transparency

We process data only on lawful grounds and are fully transparent about how your data is used.

Purpose Limitation

Data is collected for specific, explicit purposes and not processed in ways incompatible with those purposes.

Data Minimisation

We collect only the data that is strictly necessary to provide the Service.

Accuracy

We take reasonable steps to ensure personal data is accurate and kept up to date.

Storage Limitation

Data is retained only for as long as necessary, then securely deleted.

Security

We apply technical and organisational measures to protect data against unauthorised access or loss.

Your Rights Under GDPR

Right of Access

You can request a copy of all personal data we hold about you at any time.

Right to Rectification

You can ask us to correct inaccurate or incomplete personal data.

Right to Erasure

You can request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.

Right to Restriction

You can ask us to temporarily restrict processing of your data in certain circumstances.

Right to Portability

You can request your data in a structured, machine-readable format (JSON/CSV).

Right to Object

You can object to processing based on legitimate interests or for direct marketing.

Our Role Under GDPR

E-Delivery acts as a Data Processor on behalf of its customers (delivery companies), who are the Data Controllers. We process personal data (sender details, recipient details, driver information) strictly according to the instructions of our customers and the terms of our Data Processing Agreement (DPA). For data relating to our own users (account holders, admins), E-Delivery acts as a Data Controller.

Legal Basis for Processing

We process personal data on the following legal bases: • Contract performance: processing necessary to provide the Service you have subscribed to. • Legitimate interests: improving the Service, security monitoring, fraud prevention. • Legal obligation: retaining invoices and financial records as required by law. • Consent: analytics cookies and marketing communications (where applicable).

Data Processing Agreement

As a Data Processor, we offer a Data Processing Agreement (DPA) to all customers. The DPA defines the scope of processing, the obligations of both parties, and the sub-processors we use. To request a signed DPA, contact us at contact@getedelivery.com.

Sub-Processors

We use the following categories of sub-processors: • Cloud infrastructure: OVH Cloud • Transactional email: third-party SMTP provider • Payment processing: third-party payment gateway All sub-processors are bound by GDPR-compliant data processing agreements.

International Data Transfers

Your data is primarily stored in OVH's EU data centers. Where data is transferred outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission.

Data Breach Notification

In the event of a personal data breach that poses a risk to individuals, we will notify affected customers within 72 hours of becoming aware of the breach, as required by GDPR Article 33. We will also provide guidance on steps to take.

Contact & Complaints

To exercise your GDPR rights or raise a concern, contact us at: contact@getedelivery.com If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.