Personal data

Privacy notice.

Version of 14 August 2026

This notice describes how Emovanti processes personal data on the public site and in the application during the beta phase, in accordance with the GDPR (Regulation (EU) 2016/679). It is written from the product's actual behavior and will be updated as the product evolves.

Who we are

Emovanti is published and operated by Mohammed Hamdoune during the launch phase. The final identifiers of the controller company (legal name, SIREN, registered office) will be completed here after legal validation.

For any question about personal data, write to support@emovanti.com.

Two distinct roles

Depending on the data concerned, Emovanti acts either as a controller or as a processor.

Emovanti as controller
For account holders' data (identity, credentials, sessions, security logs) and for early-access requests sent from the site.
Emovanti as processor
For business data the customer organization enters about its own people: fleet members, drivers, assignment attribution. The customer organization is the controller for that processing; Emovanti carries it out on its behalf under the signed beta agreement. If you are concerned by that data, direct rights requests to your employer; Emovanti relays the requests it receives.

Data we process

The following categories reflect the product's actual behavior.

Account data
Identity, email address, password (stored as a hash), sessions, login history, and two-factor authentication settings.
Early-access requests
Name, work email, organization, fleet size, and expressed need, submitted with your explicit consent through the site form, then relayed to the API without logging personal data.
Business data entered by the customer organization
Fleet records that can include employees' personal data (fleet members, drivers, vehicle assignments), together with legal-entity data.
Audit records
Internal, protected, redacted records kept for security and for tracing sensitive actions.
Documents and files
Files uploaded to the application, stored in private storage spaces.

Purposes and legal bases

Each processing activity relies on an identified legal basis.

Contract performance
Creating and managing accounts, sessions, and workspaces relies on the performance of the contract with the account holder.
Consent
The early-access form relies on your explicit consent, which you can withdraw at any time by requesting deletion of your request.
Legitimate interest
Security and audit records rely on our legitimate interest in securing the service and tracing sensitive actions.
Customer instructions
Business data entered by the customer organization is processed on its instructions, under the beta agreement.

Sub-processors

Emovanti relies on the following providers. Each is governed by a data processing agreement (DPA).

ProviderServiceLocationSafeguardsDPA
Google Cloud (contracting entity: Google Cloud France)Application execution, file storage, and events (Cloud Run, Cloud Storage, Eventarc)Region europe-west1 (Belgium)Commitment to keep data at rest in the region; this is not a commitment to processing exclusively in the EUGoogle Cloud DPA
Neon (a Databricks group company)Managed Postgres databaseProject in AWS eu-central-1 (Frankfurt)Neon's DPA reserves the possibility of processing in the United States; transfers are governed by the EU Standard Contractual Clauses and the EU-US Data Privacy FrameworkNeon DPA
Cloudflare, Inc. (USA)Site and application delivery (Pages, Pages Functions)Global network, not limited to the EUInternational transfer governed by the EU Standard Contractual Clauses (2021/914) and the EU-US Data Privacy FrameworkCloudflare DPA
Sendinblue SAS (trading as Brevo), French company, SIREN 498 019 298Transactional emailEU (OVH France and Germany, Google Cloud Belgium)Processing in the EUBrevo DPA (annexed to the terms of use)

International transfers

Application data stored on Google Cloud benefits from a commitment to keep data at rest in the europe-west1 region (Belgium). The database is located in Frankfurt, but Neon's DPA reserves the possibility of processing in the United States.

Site and application delivery by Cloudflare, as well as Neon processing involving the United States, are governed by the EU Standard Contractual Clauses (Decision 2021/914) and the EU-US Data Privacy Framework.

Retention periods

Personal data is kept for the duration of the contractual relationship, then for the applicable legal retention periods — for example ten years for accounting evidence.

A purpose-specific retention matrix is under legal validation; this notice does not promise shorter windows until it is validated.

Closing an account leads to deletion of the associated data, subject to those legal obligations.

Your rights

You have the rights of access, rectification, erasure, portability, objection, and restriction over the data for which Emovanti is the controller.

An export of your account data (profile, sessions, login history, audit summaries, invitations, recovery metadata) is available directly in the application.

To exercise a right, write to support@emovanti.com. For business data entered by your organization, contact your employer first, as the controller of that processing; Emovanti relays the requests it receives.

You can also lodge a complaint with the CNIL (cnil.fr), the French supervisory authority.

Cookies

The public site sets no advertising cookies or trackers. Audience measurement is disabled by default; if it is ever enabled, it relies on a cookieless solution (Plausible or Umami).

The application uses a session cookie strictly necessary for authentication, which is exempt from consent; no consent banner is therefore required as things stand.

Updates to this notice

The version in force is dated at the top of the page. Any significant change to the processing will lead to a dated update of this notice.