When we decide
TRAKARIA LLC is responsible for its website, direct relationships, individual accounts, service administration and its own security and communications.
Privacy policy · Effective 28 September 2026
This policy explains what happens to personal data when you visit our website, use TrakarIA, appear in a vehicle record, or open a presentation shared through the service. It also explains when we make a decision about that data and when a customer organisation does.
The short version: personal data should serve a defined purpose, access to private records is contextual, and publication is a separate decision. The detail, including your choices and rights, is below.
Read the policyTRAKARIA LLC is responsible for its website, direct relationships, individual accounts, service administration and its own security and communications.
For personal data placed in a customer's operational workspace, the customer usually determines why it is used; TrakarIA provides the service under its instructions.
A customer or authorised user chooses whether a supported vehicle presentation is published and which information or files it includes.
TRAKARIA LLC ('TrakarIA', 'we', 'us') operates the TrakarIA website and vehicle-centred software. For questions about this policy or personal data for which we are responsible, write to contact@trakaria.com. Please put 'Privacy' in the subject line.
Our role depends on the activity, not simply on the fact that data is stored in our systems. We are a controller when we determine a purpose such as answering a website enquiry, managing an individual account, securing the service or sending our own communications. An organisation using TrakarIA normally remains the controller of the personal data it enters about staff, customers, drivers and vehicles; TrakarIA then acts on its documented instructions for that customer content. We may separately be a controller for limited account, security and business-relationship data.
If an organisation controls the record about you, it decides what to enter, who can access it, whether to share it and how long it is needed, subject to law and its agreement with us.
If you use a personal account rather than an organisation-controlled workspace, TrakarIA generally determines the purposes needed to deliver and administer that direct service.
This policy covers our institutional website and forms, the private TrakarIA application, support and service communications, and public vehicle pages, reports or links served through TrakarIA. It applies to visitors, prospects, account holders, customer-team members and people whose information is included in a vehicle workflow or shared output.
A customer's own website, another company's service or a third-party destination reached through a link may have its own privacy notice. Where a customer has provided your information, its notice and its choices about the vehicle record also matter. This policy does not replace an organisation's duties to inform its drivers, customers or employees.
A vehicle record, its photos, documents, signatures and operational history are not made public merely because they exist in the application.
An authorised publication may create a separate buyer-facing or recipient-facing view. Anyone who receives an accessible link may be able to pass it on, save what they see or capture a copy; disabling the source later cannot recall copies already made by others.
We obtain data directly from you, from the organisation that invites you or manages a vehicle, from people who submit a request or public-page enquiry, and from your use of the website or application. Some fields are required to provide a requested service; optional fields are identified where they are collected. Please avoid uploading information that is unnecessary for the task, especially sensitive information about another person.
Vehicle information is not always personal data. It becomes personal data when it identifies or can reasonably be linked to an owner, driver, renter, employee or another person. Customer-uploaded files can contain information we did not ask for and cannot reliably classify in advance.
Contact and demo forms can include your name, work email, optional phone and company, country, preferred language, role, operation size, area of interest, message, request route and submission details. Website requests and server logs can also involve IP address, device or browser information and timestamps.
Depending on the account and permissions: name, contact details, organisation, role, access scope, login and session information, preferences, support requests, technical identifiers and records of actions performed.
Depending on the workflow: vehicle identity and registration, plate or VIN, mileage, availability, plans, maintenance, costs, inspections, condition and damage evidence, photos, videos, documents, attachments, reports, history, annotations, dates and the person who performed an action.
Rental handovers, sales enquiries, documents or inspections may contain customer and driver contact details, correspondence, signatures, uploaded evidence, or other information supplied by a customer. A photo can incidentally show a person or identifying surroundings.
If a feature is used, we may process image-analysis results, extracted vehicle values, AI suggestions, diagnostics, usage events and limited service-performance information. A suggestion or detected imperfection is an inference to be reviewed, not an independently verified fact.
We use personal data only for identified purposes connected to operating TrakarIA and the relationships around it. The exact processing depends on the features used, the settings chosen by the account or customer, and whether a record is private or deliberately published.
A website request is used to respond to that request, not to enrol the sender automatically in a mailing list. Existing users may receive essential service messages. Product news or offers are treated separately from those essential messages, with the choices and objection or unsubscribe route required by applicable law.
Create and administer accounts, authenticate users, manage organisation and vehicle access, save work, generate requested reports and deliver supported Sales, Rental and Fleet workflows.
Prepare and serve a public vehicle presentation, report, link or authorised file access only when a supported publication or sharing action is taken.
Respond to enquiries, arrange demonstrations, handle support and privacy requests, diagnose problems and communicate service changes.
Limit abuse, investigate incidents, maintain service reliability and evaluate usage or quality with data minimisation and applicable tracking choices.
Comply with valid legal requests and recordkeeping duties, resolve disputes, and establish or defend legal claims where necessary.
Where TrakarIA is the controller and the GDPR applies, the basis depends on the specific purpose. The rows below connect the activity, relevant data and basis; a required website-form acknowledgement that lets us answer you is not permission to send unrelated marketing. Consent, where used, can be withdrawn without affecting earlier lawful processing.
For customer-directed vehicle records where TrakarIA acts as a processor, the customer determines and communicates its lawful basis. Our processing follows that customer's instructions and the applicable processing agreement, except for our separate controller purposes described in this policy.
| Answer a request or prepare a demo | Data: contact details, request content and relevant business context. Basis: steps requested before a contract where applicable, or our legitimate interest in replying to a general business enquiry. |
|---|---|
| Provide and administer a direct account | Data: account identity, access and usage needed to deliver the service. Basis: performance of a contract with an individual account holder, or legitimate interests in administering a customer relationship and authorised users. |
| Security and abuse prevention | Data: session and access logs, technical identifiers and relevant incident records. Basis: our legitimate interests in protecting the service and its users, and legal obligations where applicable. |
| Communicate about the service | Data: account or contact details and communication preferences. Basis: contract or legitimate interests for essential operational messages; consent or another permitted basis, with applicable opt-out rights, for promotional communications. |
| Measure use and diagnose issues | Data: controlled website or product events and, if enabled, limited usage and diagnostic data. Basis: legitimate interests where lawful, or consent where a non-essential tracker or local rule requires it. Any exemption must be assessed for the actual tool and configuration. |
| Train TrakarIA models on identifiable customer content | Data: only categories specifically described at the point of choice. Basis: a separate, recorded authorisation and an appropriate legal basis before such use; ordinary use of an AI feature is not, by itself, permission to train our own models. |
| Compliance and legal claims | Data: relevant account, correspondence, transaction or incident records. Basis: legal obligation, or legitimate interests in establishing, exercising or defending rights as applicable. |
Access within TrakarIA is limited by function and need. Authorised staff and contractors may handle data for support, operations, security or legal matters. The organisation controlling a workspace decides which of its authorised users can see its records. We do not treat a private vehicle record as a public listing by default.
We use service providers for hosting, communications, analytics, AI-assisted processing and media services where required. Their access depends on the services enabled and the information needed to deliver them. You can ask contact@trakaria.com for information about providers relevant to your use of TrakarIA.
An organisation's authorised team can access data according to its permissions. If that team publishes a presentation, the selected information becomes available to the intended audience or anyone with an accessible public link, subject to the sharing controls used.
An AI-assisted feature may send relevant images, prompts or vehicle context to a provider to complete your request. Analytics and media services may receive information needed for their respective functions. The data and recipients depend on the features in use.
We may disclose relevant data to competent authorities when lawfully required, to protect rights or safety, or as part of a business transaction with appropriate confidentiality and legal safeguards. This is not unrestricted permission to disclose customer records.
Our providers, authorised support personnel or recipients of a deliberately shared public link may be located outside the European Economic Area. The countries involved depend on the services and sharing choices in use.
Transfers subject to GDPR restrictions require an applicable legal mechanism, which may include an adequacy decision or safeguards such as standard contractual clauses. You may ask contact@trakaria.com about transfers relevant to your use of the service and how to obtain a copy of applicable safeguards.
A customer can choose to share a presentation with recipients outside the country where the underlying private record is hosted. Those recipients may retain their own copies of what they access.
There is no single maximum retention period for all personal data. We use the shortest period compatible with the purpose, the customer relationship, applicable legal duties, and the need to establish or defend claims. A customer acting as controller determines the active-life retention of the content it enters, subject to its agreement with us and technical deletion processes.
Deleting an active record does not necessarily remove every backup or legally restricted copy at once. Such copies are limited to their applicable lifecycle or preservation requirement and are not returned to ordinary use. The criteria below are not a promise that every category is stored for the longest possible period.
| Website enquiries and prospects | Keep while a request is being handled and for a proportionate follow-up period tied to the last meaningful interaction; retain longer only where a legal obligation or specific dispute requires it. Marketing preferences remain relevant until withdrawal or their lawful purpose ends. |
|---|---|
| Accounts and business relationship | Keep while the account or customer relationship is active, then for the period needed for closure, export, billing, compliance and relevant limitation periods. Revoke live access according to the account lifecycle. |
| Vehicle records, images and documents | Keep under the customer's retention and deletion instructions while the workspace operates; after termination, allow the agreed export or deletion window, subject to legal holds and backup expiry. For a direct individual account, apply the account lifecycle and applicable legal duties. |
| Communications and support | Keep until the request or incident is resolved, then only as long as needed to document the outcome, handle follow-up or defend a claim. |
| Security and analytics | Keep only for the relevant diagnostic, security or analytics period. The period for an enabled external service depends on its settings and contract; you may ask us for details relevant to your use of the service. |
| Privacy-rights requests | Keep the request and outcome for the period necessary to demonstrate that it was handled and to address a related complaint or claim, while limiting any identity evidence collected for verification. |
| Backups and legal preservation | Backups expire according to the applicable system lifecycle. A relevant record may be preserved longer when law, a valid hold or a live dispute requires it, with access restricted for that purpose. |
Depending on the law and our role, you may ask to access, correct, erase or receive your personal data, restrict or object to processing, or withdraw consent. Portability applies in its legal conditions. You can object to direct marketing at any time. Rights are not absolute: an exception may apply, for example when records must be kept by law or for a legal claim.
Send a request to contact@trakaria.com and describe the account, request or vehicle context that helps locate the data. We may ask for proportionate additional information only where reasonably needed to confirm identity or authority. We will explain our response and applicable time frame. Under the GDPR, the normal response period is one month, with a permitted extension for complex or numerous requests.
If an organisation controls the record, contact that organisation for decisions about its content. We will direct the request appropriately where we can and assist the organisation in meeting its duties. A request to us does not automatically override a customer's independent legal obligations.
You may withdraw a separate AI-training authorisation or marketing consent through the mechanism provided for it, or contact us. Withdrawal does not make earlier lawful processing unlawful; information already irreversibly anonymised cannot be linked back to you for removal.
The website uses browser storage for a chosen light or dark theme and can keep non-identifying form choices in session storage so a request can be resumed. Names, email addresses and messages are not saved in that form draft. Restricted editorial preview can use a preview cookie. The private application uses session and security technologies needed for login and account protection; optional push notifications and product analytics depend on activation and settings.
On the institutional website, Cookiebot manages preferences and Google Analytics 4 (GA4) measures visits under Google Consent Mode v2. In the European Economic Area, the United Kingdom and Switzerland, analytics storage starts denied and is enabled only after a positive Cookiebot choice. Outside those regions, analytics storage uses a granted general default and can be withdrawn at any time. Advertising storage, ad-user-data and ad-personalisation remain denied everywhere in this integration.
The GA4 tag can send cookieless consent and measurement pings while analytics storage is denied. When analytics storage is granted, GA4 may set or read analytics identifiers. Google Signals and ad-personalisation signals are disabled. A permanent cookie-preferences control in the footer reopens Cookiebot so you can review or withdraw your choice.
Theme choice, temporary form selections, authentication and anti-abuse measures support the requested experience or protect the account.
Cookiebot records the categories you accept or reject and sends the resulting Consent Mode updates. Rejecting optional analytics does not prevent access to the public website.
GA4 is configured for page-view measurement with Google Signals and ad-personalisation signals disabled. Provider-console retention, access and domain settings require separate production review.
TrakarIA uses access controls, organisational and vehicle context, permission checks, private-file handling, monitoring and recovery preparation appropriate to the service. Supported public presentations are separate from private records; supported file access can depend on a deliberate sharing choice and time-limited access links. Authorised users should still review a public output before making it available.
No website or service can promise absolute security or immediate recovery in every circumstance. Our safeguards evolve with the service and are reviewed as our systems, providers and workflows change. We assess incidents and make notifications where applicable law requires. If you suspect unauthorised access, contact us promptly at contact@trakaria.com.
Customer administrators are responsible for assigning suitable access, limiting unnecessary uploads, choosing what to publish, and revoking access when it is no longer appropriate.
When you use an AI-assisted feature, TrakarIA can process the information needed for that request: for example a vehicle image, prompt, relevant vehicle attributes or document-derived values. Depending on the feature and active configuration, some input can be sent to an external AI provider. The service can return extracted values, edited imagery, suggested text or condition findings; those outputs may be wrong and should be reviewed before an operational or public decision.
Using a feature to analyse or prepare a vehicle is distinct from using customer content to train TrakarIA's own models. Identifiable customer photos, documents or records will be used for our own training only after a separate, recorded authorisation describing the data and purpose. If data is truly anonymised so no person is reasonably identifiable, it is no longer treated as personal data; merely removing obvious names does not automatically achieve that standard.
An AI suggestion does not replace human review for decisions with legal or similarly significant effects. If a future feature makes such decisions, we will provide the information and safeguards required by applicable law. Ask us about the providers relevant to an AI-assisted feature before supplying sensitive content.
A person or authorised customer team remains responsible for checking suggestions, selecting publication content and deciding how an AI-assisted result is used.
TrakarIA is designed for people who can independently use a vehicle-related business or personal service, not for children. We do not intentionally invite children to open accounts or submit information through the website.
A customer-controlled photo, document or report might incidentally include information about a minor. The customer should avoid collecting it unless necessary and lawful, and should provide any notice or permission it is responsible for. If you believe a child has provided us data directly without appropriate authorisation, contact us so we can assess and act on the request.
We may update this policy when the service, providers, legal requirements or our processing changes. The effective date at the top will change when a revised version is published. For material changes affecting your choices or the way personal data is used, we will provide additional notice or seek a new authorisation where required.
An updated policy does not retroactively turn a past website request into marketing consent or a past use of an AI feature into authorisation for model training. Earlier versions and the relevant choice records should be retained where needed to explain the notice and permissions that applied at the time.
For privacy questions, access requests or concerns about TrakarIA's own processing, email contact@trakaria.com with 'Privacy' in the subject line. If your concern is about a record entered or published by a customer organisation, that organisation may be the controller able to make the substantive decision; we can help route or assist with your request where appropriate.
If the GDPR applies, you may also complain to the supervisory authority in the EU or EEA country of your habitual residence, place of work or the alleged infringement. Contacting us first can help resolve a question, but it is not a condition for making a complaint. For other jurisdictions, available rights and complaint routes depend on applicable law.
The European Data Protection Board publishes a directory of national data-protection authorities.
Find an EU authority