This Privacy Policy explains how Autofid ("we," "us," or "our") collects, uses, processes, and protects your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable EU data protection laws. Autofid is a multi-tenant SaaS platform designed for vehicle dealerships and garages to manage their business operations. We are committed to protecting your privacy and ensuring transparency in our data processing activities.
2. Data Controller
The data controller responsible for your personal data is:
We process your personal data based on the following legal grounds:
Contract Performance: Processing is necessary to provide our dealership management services, process subscriptions, and fulfill our contractual obligations
Consent: You have given explicit consent for specific processing activities such as marketing communications, data processing consent, and optional features
Legal Obligation: We must process data to comply with VAT regulations, tax laws, financial reporting requirements, and other legal obligations
Legitimate Interest: Processing is necessary for fraud prevention, security monitoring, system optimization, and improving our services
5. How We Use Your Data
We use your personal data for the following purposes:
To provide and maintain our vehicle dealership management platform
To process subscriptions and manage billing through Stripe
To authenticate users and maintain account security
To store and manage vehicle inventory, documents, and photos
To generate invoices, financial reports, and VAT returns
To facilitate job management and service tracking
To provide customer support through our ticketing and chat system
To send transactional emails (account verification, password resets, notifications)
To monitor system performance and prevent fraud
To comply with legal and regulatory requirements
To send marketing communications (with your consent)
To improve our services and develop new features
6. Data Sharing and Transfers
We may share your personal data with the following third parties:
6.1 Service Providers
Stripe: Payment processing and subscription management
Cloudinary: Image storage and optimization for vehicle photos
Vercel Blob: Document and file storage
Neon: Database hosting (PostgreSQL)
Email Service Providers: Transactional and notification emails
Car Registration API: Vehicle data lookup and enrichment
6.2 Legal Authorities
We may disclose data when required by law, court order, or to protect our rights and safety.
6.3 Business Transfers
In connection with mergers, acquisitions, or asset sales, your data may be transferred to the acquiring entity.
International Data Transfers: When transferring data outside the EU/EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission. Our service providers (Stripe, Cloudinary, Vercel) maintain GDPR-compliant data processing agreements.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
Right of Access: Request a copy of your personal data through your account settings or by contacting us
Right to Rectification: Correct inaccurate or incomplete data through your account settings
Right to Erasure:Request deletion of your data ("right to be forgotten") through our account deletion feature with a 30-day grace period
Right to Restriction: Limit how we process your data
Right to Data Portability: Receive your data in CSV, Excel, or PDF format through our export features
Right to Object: Object to processing based on legitimate interests, including marketing communications
Right to Withdraw Consent: Withdraw consent at any time through your account settings
Right to Lodge a Complaint: File a complaint with your supervisory authority
To exercise these rights, please contact us at privacy@autofid.com or use the account management features in your dashboard.
8. Data Retention
We retain your personal data as follows:
Account Data: Retained while your account is active and for 30 days after deletion request
Financial Records: Retained for 7 years to comply with tax and accounting regulations
Vehicle and Transaction Data: Retained for the duration of your subscription and 7 years thereafter for legal compliance
Audit Logs: Retained for 2 years for security and compliance purposes
Support Communications: Retained for 3 years for quality assurance
Marketing Consent: Retained until consent is withdrawn
9. Data Security
We implement comprehensive technical and organizational measures to protect your personal data:
Encryption: All data is encrypted in transit (TLS/SSL) and at rest
Authentication: JWT-based authentication with refresh tokens and optional two-factor authentication (2FA)
Access Controls: Role-based access control with 22+ granular permissions
IP Filtering: Configurable IP whitelist and blocklist
Session Management: Secure session handling with session approval features
Password Security: Password hashing, expiration policies, and password history tracking
Audit Logging: Comprehensive audit trail for all data access and modifications
Multi-Tenant Isolation: Complete data isolation between dealership accounts
Regular Security Assessments: Ongoing monitoring and security updates
10. Cookies and Tracking
We use cookies and similar tracking technologies to enhance your experience, maintain sessions, and analyze usage patterns. For detailed information about our use of cookies, please refer to our Cookies Policy.
11. GDPR Compliance
For a detailed overview of our GDPR obligations, your rights as a data subject, our lawful bases for processing, sub-processor list, and Data Processing Agreement, please visit our dedicated GDPR Compliance page.
12. Children's Privacy
Our services are designed for business use and are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at privacy@autofid.com.
13. Data Processing for Customers
When you use Autofid to manage your dealership, you may process personal data of your customers (vehicle buyers, service customers). In this relationship:
You are the Data Controller for your customer data
Autofid acts as a Data Processor on your behalf
You are responsible for obtaining necessary consents from your customers
You must comply with GDPR and data protection laws in your use of the platform
We provide tools to help you manage consent, data exports, and deletion requests
Our Data Processing Agreement (DPA) is available upon request and outlines our responsibilities as a data processor.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of significant changes by email and by posting the new policy on this page with an updated "Last Updated" date. We encourage you to review this policy periodically.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your personal data appropriately. For EU residents, you can find your supervisory authority at https://edpb.europa.eu/about-edpb/board/members_en.
Ready when you are
Put the whole operation on Autofid.
Start with stock and invoices, then bring in workshop jobs, VAT reports, warranties, team permissions, and support as your process grows.