Compliance Policy

GDPR Compliance.
Last Updated: April 14, 2026

1. Introduction

Autofid ("we," "us," or "our") is committed to full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page explains how we meet our obligations under the GDPR, the rights available to you as a data subject, and how you can exercise those rights.This document should be read alongside our Privacy Policy and Cookies Policy, which provide further detail on how we collect and process personal data.

2. Data Controller & Data Protection Officer

Autofid acts as the Data Controllerfor personal data collected directly from users of our platform. When you use Autofid to manage your dealership's customer data, you act as the Data Controller for that customer data and Autofid acts as your Data Processor.
Autofid
Data Protection Officer (DPO): dpo@autofid.com
Phone:
Address: Autofid HQ, Tech Hub District, Dublin-Cavan, Ireland

3. Lawful Bases for Processing

Under Article 6 of the GDPR, we rely on the following lawful bases to process personal data:
Lawful BasisWhen We Use It
Contract Performance (Art. 6(1)(b))Providing the platform, processing subscriptions, managing billing, and fulfilling our service obligations
Legal Obligation (Art. 6(1)(c))VAT reporting, tax compliance, financial record-keeping, and responding to lawful authority requests
Legitimate Interests (Art. 6(1)(f))Fraud prevention, security monitoring, system performance optimisation, and improving our services
Consent (Art. 6(1)(a))Marketing communications, non-essential cookies, and optional analytics features

4. Your Rights Under the GDPR

As a data subject, you have the following rights under the GDPR. You can exercise any of these rights by contacting us at privacy@autofid.com or through your account settings. We will respond within 30 days.

4.1 Right of Access (Art. 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data along with information about how it is processed. You can request a data export directly from your account dashboard or by emailing us.

4.2 Right to Rectification (Art. 16)

You have the right to have inaccurate or incomplete personal data corrected. You can update most of your account information directly in your profile settings. For data you cannot update yourself, contact us and we will correct it promptly.

4.3 Right to Erasure / "Right to be Forgotten" (Art. 17)

You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent. Account deletion requests are processed with a 30-day grace period. Note that certain data (e.g., financial records) must be retained to comply with legal obligations.

4.4 Right to Restriction of Processing (Art. 18)

You have the right to request that we restrict the processing of your personal data in certain circumstances — for example, while we verify the accuracy of data you have contested, or while we assess an objection you have raised.

4.5 Right to Data Portability (Art. 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format (CSV, Excel, or PDF) and to transmit it to another controller. You can export your data at any time from your account dashboard.

4.6 Right to Object (Art. 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes. If you object to marketing, we will stop processing your data for that purpose immediately. For other objections, we will assess whether our legitimate interests override your rights.

4.7 Rights Related to Automated Decision-Making (Art. 22)

Autofid does not make solely automated decisions that produce legal or similarly significant effects on individuals. All significant decisions involving your data involve human review.

4.8 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. You can manage your consent preferences in your account settings or by contacting us.

5. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law:
Data CategoryRetention PeriodReason
Account & Identity DataDuration of account + 30 daysGrace period for account recovery
Financial & Transaction Records7 yearsTax and accounting legal obligation
Vehicle & Inventory DataSubscription duration + 7 yearsLegal compliance
Audit Logs2 yearsSecurity and compliance
Support Communications3 yearsQuality assurance
Marketing Consent RecordsUntil consent withdrawnProof of consent

6. International Data Transfers

Some of our service providers are located outside the EU/EEA. Where we transfer personal data internationally, we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR:
  • Standard Contractual Clauses (SCCs): We use EU-approved SCCs with all third-party processors that operate outside the EU/EEA.
  • Adequacy Decisions: Where the European Commission has issued an adequacy decision for the destination country, we rely on that decision.
  • Processor Agreements: All third-party processors (Stripe, Cloudinary, Vercel, Neon) have signed Data Processing Agreements (DPAs) confirming GDPR compliance.

7. Data Security Measures

We implement appropriate technical and organisational measures under Article 32 of the GDPR to ensure a level of security appropriate to the risk:
  • Encryption in transit and at rest — TLS/SSL for all data in transit; encrypted storage for sensitive data at rest
  • Role-based access control (RBAC) — 22+ granular permissions ensuring users only access data relevant to their role
  • Two-factor authentication (2FA) — optional but strongly recommended for all accounts
  • IP filtering — configurable IP whitelist and blocklist per tenant
  • Comprehensive audit logging — all data access and modifications are logged with timestamps and user attribution
  • Multi-tenant data isolation — complete separation of data between dealership accounts at the database level
  • Session management — secure JWT-based sessions with refresh token rotation and session approval features
  • Regular security assessments — ongoing monitoring and vulnerability management

8. Data Breach Notification

In the event of a personal data breach, we will comply with our obligations under Articles 33 and 34 of the GDPR:
  • We will notify the relevant supervisory authority within 72 hoursof becoming aware of a breach that is likely to result in a risk to individuals' rights and freedoms.
  • Where the breach is likely to result in a high risk to individuals, we will notify affected data subjects without undue delay.
  • We maintain an internal breach register to document all breaches, their effects, and the remedial actions taken.

9. Autofid as a Data Processor

When you use Autofid to manage your dealership's customer records, vehicle transactions, and job cards, you are the Data Controller for that customer data. Autofid acts as your Data Processor under Article 28 of the GDPR. In this capacity:
  • We process customer data only on your documented instructions
  • We ensure all staff with access to customer data are bound by confidentiality obligations
  • We implement the security measures described in Section 7 above
  • We assist you in responding to data subject rights requests from your customers
  • We delete or return all customer data upon termination of the service, at your choice
  • We provide all information necessary to demonstrate compliance with Article 28
A full Data Processing Agreement (DPA) is available upon request. Contact us at dpo@autofid.com to request a copy.

10. Sub-Processors

We use the following sub-processors to deliver our services. All sub-processors are bound by GDPR-compliant DPAs:
Sub-ProcessorPurposeLocation
StripePayment processing & subscription managementUSA (SCCs in place)
CloudinaryVehicle image storage & optimisationUSA (SCCs in place)
VercelHosting, CDN & file storageUSA / EU (SCCs in place)
NeonPostgreSQL database hostingEU / USA (SCCs in place)
We will notify you of any intended changes to sub-processors, giving you the opportunity to object before the change takes effect.

11. Supervisory Authority & Complaints

You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your personal data in accordance with the GDPR. You can find your supervisory authority at:https://edpb.europa.eu/about-edpb/board/members_enWe would, however, appreciate the opportunity to address your concerns before you approach the supervisory authority. Please contact us first at privacy@autofid.com.

12. Updates to This Page

We review and update this GDPR compliance page regularly to reflect changes in our practices or applicable law. We will notify you of material changes by email and by updating the "Last Updated" date above.

13. Contact Us

For any GDPR-related queries, to exercise your rights, or to request our Data Processing Agreement, please contact:
Data Protection Officer
General privacy queries: privacy@autofid.com
Phone:
Address: Autofid HQ, Tech Hub District, Dublin-Cavan, Ireland
Ready when you are

Put the whole
operation on Autofid.

Start with stock and invoices, then bring in workshop jobs, VAT reports, warranties, team permissions, and support as your process grows.

Try Autofid free

No credit card required.