Compliance Policy

Privacy Policy.
Last Updated: March 13, 2026

1. Introduction

This Privacy Policy explains how Autofid ("we," "us," or "our") collects, uses, processes, and protects your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable EU data protection laws. Autofid is a multi-tenant SaaS platform designed for vehicle dealerships and garages to manage their business operations. We are committed to protecting your privacy and ensuring transparency in our data processing activities.

2. Data Controller

The data controller responsible for your personal data is:
Autofid
Address: Autofid HQ, Tech Hub District, Dublin-Cavan, Ireland
Data Protection Officer: dpo@autofid.com
Phone:

3. Personal Data We Collect

We collect and process the following categories of personal data depending on your role and usage:

3.1 Account and Identity Data

  • Name (first name, last name)
  • Email address
  • Phone number
  • Password (encrypted)
  • Language preference
  • User role (Super Admin, Dealer Admin, Accountant, Auditor, Technician)

3.2 Business Information

  • Business name and trading name
  • Business address
  • VAT number and tax identification
  • Company registration number
  • Business contact details

3.3 Vehicle and Inventory Data

  • Vehicle registration numbers and VIN
  • Vehicle specifications (make, model, year, mileage)
  • Vehicle photos and documents
  • Purchase and sale information
  • Service history and maintenance records

3.4 Customer Data (Processed on Your Behalf)

  • Customer names and contact information
  • Customer addresses
  • Vehicle ownership information
  • Transaction history

3.5 Financial and Transaction Data

  • Subscription package and billing cycle
  • Payment method information (processed by Stripe)
  • Invoice and payment history
  • VAT information and tax records

3.6 Technical and Usage Data

  • IP address and device information
  • Browser type and version
  • Login timestamps and session data
  • Feature usage and interaction patterns
  • API call logs and system performance data

3.7 Security and Authentication Data

  • Two-factor authentication settings
  • Backup codes and recovery email
  • Login attempt history
  • Session tokens and refresh tokens
  • IP filtering rules (whitelist/blocklist)

3.8 Communication Data

  • Support ticket content and chat messages
  • Email correspondence
  • Notification preferences

4. Legal Basis for Processing

We process your personal data based on the following legal grounds:
  • Contract Performance: Processing is necessary to provide our dealership management services, process subscriptions, and fulfill our contractual obligations
  • Consent: You have given explicit consent for specific processing activities such as marketing communications, data processing consent, and optional features
  • Legal Obligation: We must process data to comply with VAT regulations, tax laws, financial reporting requirements, and other legal obligations
  • Legitimate Interest: Processing is necessary for fraud prevention, security monitoring, system optimization, and improving our services

5. How We Use Your Data

We use your personal data for the following purposes:
  • To provide and maintain our vehicle dealership management platform
  • To process subscriptions and manage billing through Stripe
  • To authenticate users and maintain account security
  • To store and manage vehicle inventory, documents, and photos
  • To generate invoices, financial reports, and VAT returns
  • To facilitate job management and service tracking
  • To provide customer support through our ticketing and chat system
  • To send transactional emails (account verification, password resets, notifications)
  • To monitor system performance and prevent fraud
  • To comply with legal and regulatory requirements
  • To send marketing communications (with your consent)
  • To improve our services and develop new features

6. Data Sharing and Transfers

We may share your personal data with the following third parties:

6.1 Service Providers

  • Stripe: Payment processing and subscription management
  • Cloudinary: Image storage and optimization for vehicle photos
  • Vercel Blob: Document and file storage
  • Neon: Database hosting (PostgreSQL)
  • Email Service Providers: Transactional and notification emails
  • Car Registration API: Vehicle data lookup and enrichment

6.2 Legal Authorities

We may disclose data when required by law, court order, or to protect our rights and safety.

6.3 Business Transfers

In connection with mergers, acquisitions, or asset sales, your data may be transferred to the acquiring entity.
International Data Transfers: When transferring data outside the EU/EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission. Our service providers (Stripe, Cloudinary, Vercel) maintain GDPR-compliant data processing agreements.

7. Your Rights Under GDPR

You have the following rights regarding your personal data:
  • Right of Access: Request a copy of your personal data through your account settings or by contacting us
  • Right to Rectification: Correct inaccurate or incomplete data through your account settings
  • Right to Erasure:Request deletion of your data ("right to be forgotten") through our account deletion feature with a 30-day grace period
  • Right to Restriction: Limit how we process your data
  • Right to Data Portability: Receive your data in CSV, Excel, or PDF format through our export features
  • Right to Object: Object to processing based on legitimate interests, including marketing communications
  • Right to Withdraw Consent: Withdraw consent at any time through your account settings
  • Right to Lodge a Complaint: File a complaint with your supervisory authority
To exercise these rights, please contact us at privacy@autofid.com or use the account management features in your dashboard.

8. Data Retention

We retain your personal data as follows:
  • Account Data: Retained while your account is active and for 30 days after deletion request
  • Financial Records: Retained for 7 years to comply with tax and accounting regulations
  • Vehicle and Transaction Data: Retained for the duration of your subscription and 7 years thereafter for legal compliance
  • Audit Logs: Retained for 2 years for security and compliance purposes
  • Support Communications: Retained for 3 years for quality assurance
  • Marketing Consent: Retained until consent is withdrawn

9. Data Security

We implement comprehensive technical and organizational measures to protect your personal data:
  • Encryption: All data is encrypted in transit (TLS/SSL) and at rest
  • Authentication: JWT-based authentication with refresh tokens and optional two-factor authentication (2FA)
  • Access Controls: Role-based access control with 22+ granular permissions
  • IP Filtering: Configurable IP whitelist and blocklist
  • Session Management: Secure session handling with session approval features
  • Password Security: Password hashing, expiration policies, and password history tracking
  • Audit Logging: Comprehensive audit trail for all data access and modifications
  • Multi-Tenant Isolation: Complete data isolation between dealership accounts
  • Regular Security Assessments: Ongoing monitoring and security updates

10. Cookies and Tracking

We use cookies and similar tracking technologies to enhance your experience, maintain sessions, and analyze usage patterns. For detailed information about our use of cookies, please refer to our Cookies Policy.

11. GDPR Compliance

For a detailed overview of our GDPR obligations, your rights as a data subject, our lawful bases for processing, sub-processor list, and Data Processing Agreement, please visit our dedicated GDPR Compliance page.

12. Children's Privacy

Our services are designed for business use and are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at privacy@autofid.com.

13. Data Processing for Customers

When you use Autofid to manage your dealership, you may process personal data of your customers (vehicle buyers, service customers). In this relationship:
  • You are the Data Controller for your customer data
  • Autofid acts as a Data Processor on your behalf
  • You are responsible for obtaining necessary consents from your customers
  • You must comply with GDPR and data protection laws in your use of the platform
  • We provide tools to help you manage consent, data exports, and deletion requests
Our Data Processing Agreement (DPA) is available upon request and outlines our responsibilities as a data processor.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of significant changes by email and by posting the new policy on this page with an updated "Last Updated" date. We encourage you to review this policy periodically.

15. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
Autofid
Data Protection Officer: dpo@autofid.com
Phone:
Address: Autofid HQ, Tech Hub District, Dublin-Cavan, Ireland

16. Supervisory Authority

You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your personal data appropriately. For EU residents, you can find your supervisory authority at https://edpb.europa.eu/about-edpb/board/members_en.
Ready when you are

Put the whole
operation on Autofid.

Start with stock and invoices, then bring in workshop jobs, VAT reports, warranties, team permissions, and support as your process grows.

Try Autofid free

No credit card required.