Data protection
Privacy policy
Last updated:
Document drawn up in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR), Act No. 78-17 of 6 January 1978, as amended (French Data Protection Act, loi Informatique et Libertés), and the guidelines of the European Data Protection Board (EDPB).
This translation is provided for informational purposes only. Only the French version is legally binding.
1. Preamble and commitment
WheelTrust is a digital vehicle maintenance record service (for cars and motorcycles), offered by IT EXPERT SERVICES SAS. Protecting your personal data is at the heart of how we design the service, in line with the principle of data protection by design (GDPR, Art. 25).
The purpose of this policy is to inform you, in a clear and accessible way, of the personal data processing we carry out when you use WheelTrust (the website wheeltrust.io and its subdomains), in accordance with Articles 12 to 14 of the GDPR.
Your data is hosted in France, in accordance with our guiding principle of European data sovereignty.
2. Data controller
The controller for the processing of your personal data is:
- IT EXPERT SERVICES SAS
- Registered office: 9 Allée Saint-Éloi, 77144 Chalifert, France
- SIREN: 908 633 100
- Legal representative: Patricia Pereira
- E-mail: contact@wheeltrust.io
3. Data protection officer
IT EXPERT SERVICES SAS has not appointed a data protection officer within the meaning of Article 37 of the GDPR. This appointment is not mandatory for WheelTrust: our processing involves neither regular and systematic monitoring on a large scale, nor large-scale processing of special category data within the meaning of Article 9 of the GDPR.
The data controller, IT EXPERT SERVICES SAS represented by its president Patricia Pereira, directly acts as the point of contact for any question relating to your personal data, at contact@wheeltrust.io.
No data protection officer declaration is made to the CNIL (Art. 37.7 of the GDPR), as this obligation is tied to an appointment. This position will be reassessed if WheelTrust crosses thresholds involving large-scale monitoring or large-scale processing of special category data.
4. Definitions
For the purposes of this policy:
- Personal data: any information relating to an identified or identifiable natural person (GDPR, Art. 4.1).
- Processing: any operation performed on personal data (collection, recording, consultation, use, storage, erasure, etc.; GDPR, Art. 4.2).
- Data controller: IT EXPERT SERVICES SAS, which determines the purposes and means of processing (GDPR, Art. 4.7); for the fleet data of a client organisation, this status belongs to the organisation, and we act on its behalf (see 5.12).
- Processor: any natural or legal person who processes data on behalf of the data controller (GDPR, Art. 4.8).
- User: any natural person holding a WheelTrust Account, on the Free, Premium or Business plan.
- Organisation: the structure (company, association, public body) holding a Business plan, owner of the records for its fleet.
- Member: the natural person linked to an organisation.
- Role: a member's title within their organisation, which determines what they can see and do: Fleet Manager, Fleet Administrator or Driver.
5. Data collected and purposes
We collect and process the following categories of data, depending on the purpose pursued.
5.1 Creating and managing your Account
- Data: surname, first name, e-mail address, account creation date, preferred language, time zone. Sign-in is by secure link sent by e-mail: no password is collected or stored.
- Purpose: creating, authenticating and managing your account.
- Legal basis: performance of the contract (GDPR, Art. 6.1.b).
5.2 Managing your subscription and billing
- Data: plan subscribed to, subscription history, renewal dates, amount paid, payment method used (with no card number stored by WheelTrust, see section 8), invoice history.
- Purpose: performance of the contract, invoicing, management of the business relationship, fraud prevention.
- Legal basis: performance of the contract (Art. 6.1.b); statutory accounting obligations (Art. 6.1.c; French Commercial Code, Art. L123-22); legitimate interest in fraud prevention (Art. 6.1.f).
5.3 Vehicle records and maintenance history
- Data: make, model, year, mileage, registration plate (optional), serial number (optional), photos of the vehicle, maintenance history (date, operation, mileage, cost, garage), invoice photos, free-text notes, upcoming actions (what you note as needing to be done on the vehicle: free-text label, planned date, target mileage and estimated cost, all optional except the label), and the files you attach to these upcoming actions (up to five photos or files per action: a garage's quote, a photo of a worn part).
- These files are never read automatically : we do not send the attachments to your upcoming actions to any document-reading service, whether our own or a processor's. They are stored encrypted and are only ever served to you, and, if you create a report sharing link, to the people you send that link to.
- What a sharing link shows : the shared report attaches the files for the upcoming actions it already displays, just as it already attaches your service invoices. Access to these files goes exclusively through that link's address : revoking it closes off the files at the same instant, and no other address can reach them.
- Purpose: provision of the core maintenance record service.
- Legal basis: performance of the contract (Art. 6.1.b).
5.4 Official documents (special category)
- Data, on your initiative alone: photo or scan of the vehicle registration certificate, driving licence, roadworthiness test certificate, insurance certificate, and vehicle purchase invoice.
- Purpose: centralising the official documents for your vehicles.
- Legal basis: explicit consent (Art. 6.1.a and 9.2.a). You may withdraw your consent at any time, which results in the permanent deletion of these documents.
- Security: these documents are protected by bank-grade encryption through a self-hosted secrets vault on our infrastructure in France, in accordance with our Data Protection Impact Assessment (DPIA).
5.5 Vehicle record transfers between users
- Data: e-mail addresses of the transferor and the recipient, date of the transfer, confirmation of both parties' consent.
- Purpose: passing on a vehicle's history in the event of a sale or change of owner.
- Legal basis: performance of the contract (Art. 6.1.b) with the explicit consent of both parties.
- Special feature: the transferor's identification documents (vehicle registration certificate, driving licence, purchase invoice) are not transferred to the recipient; they are deleted from the transferred record.
- What follows the vehicle: the transferred record includes your upcoming actions and the files attached to them, because they describe the vehicle's future maintenance and not you personally, exactly like your invoices. The transfer screen reminds you of this before sending: you may delete any you do not wish to pass on. The link then disappears along with the action; the file itself remains in the vehicle's documents, where you may delete it before the transfer like any other file.
- Ongoing sharing ends: if you had opened your record to other people, all of that access is withdrawn at the time of transfer. The buyer receives the record, not the people you had granted access to it.
- Retention period for the recipient's address : the duration of the transfer. It is erased immediately as soon as the transfer ends, whether it is accepted, refused, cancelled by you, or the link expires with no response. Any reason you may have given is erased at the same time. What remains is the record of the operation in our log, without the address in clear text.
5.5 bis Sharing a record with another person
- Data: e-mail address of the person you invite, level of rights you grant them, dates of invitation, acceptance and withdrawal, and, for each service entry added by that person, the record that they are its author.
- Purpose: allowing you to open your record on an ongoing basis to someone you trust (your mechanic, your spouse, your child), so they can view it and log what they have done.
- Legal basis: performance of the contract (Art. 6.1.b) for you and for the person who accepts; legitimate interest (Art. 6.1.f) for sending the invitation to a person who does not yet have an account, whose address is used only for this purpose and is never reused.
- What the invited person can never do: delete a service entry, photo or document from your record, transfer your vehicle, share your record in turn, create a public report link, or see your personal notes or your account's documents.
- The only thing they can remove: a supporting document they have just uploaded themselves and have not yet attached to a service entry. As soon as a document joins your record, it stays there - they can no longer remove it, even if they had uploaded it.
- Retention period for the address: the duration of the sharing. It is erased immediately as soon as the sharing ends, whether you withdraw it, the person declines or leaves it, the invitation expires, the vehicle is transferred or deleted, or either of your two accounts is deleted.
- What remains after withdrawal: the service entries that person added remain in your record, because they belong to the vehicle. Withdrawal of access, however, is immediate.
5.6 Referral programme and partner programme (affiliation)
- Data (referral): referral code, link between the referrer's account and that of the referred person, linking date, conversion status, free months granted.
- Data (partner programme): for registered partners: legal or business identity (legal form, company name, SIRET number or equivalent identifier, EU VAT number or exemption statement), billing address and e-mail address, bank details (IBAN), partner code, registrations and subscriptions linked to this code, commissions calculated and paid.
- Purpose: operating the referral programme and the partner contract, paying commissions and preparing the corresponding accounting records, fraud prevention (one code per account, one reward per referred person).
- Legal basis: performance of the contract (Art. 6.1.b), including the partner contract for billing and payment data; statutory obligation (Art. 6.1.c) for retaining accounting records; legitimate interest in fraud prevention (Art. 6.1.f).
- Security: partners' bank details are stored encrypted by WheelTrust and are never displayed again in clear text.
- Retention: accounting records relating to commissions are kept for 10 years under our accounting and tax obligations; bank details are deleted at the end of the partnership.
5.7 Audience measurement and service improvement
- Data: pages visited, visit duration, device type, browser, language, anonymised IP address (last two octets removed), date and time.
- Purpose: anonymised audience measurement, improving usability and performance.
- Legal basis: legitimate interest (Art. 6.1.f), processing exempted from consent in accordance with the CNIL (the French data protection authority) deliberation of 17 March 2022 (Matomo configured with no cookies, no cross-referencing, anonymised IP).
5.8 Security and fraud prevention
- Data: sign-in history, IP addresses (by /24 block for detecting multiple accounts), suspicious behaviour, timestamped history of mileage readings and changes.
- Purpose: service security, fraud prevention (multiple accounts, mileage tampering, referral abuse).
- Legal basis: legitimate interest (Art. 6.1.f); the data controller's security obligations (Art. 32).
5.9 Support and communication
- Data: content of your messages to support, e-mail address, ticket identifier, history of exchanges.
- Purpose: handling your support requests.
- Legal basis: performance of the contract (Art. 6.1.b).
5.10 Notifications and transactional e-mails
- Data: e-mail address, notification preferences.
- Purpose: deadline reminders (roadworthiness test, insurance, etc.), service notifications (invoices, subscription changes), security communications (secure sign-in links, alerts in the event of unusual sign-in activity).
- Legal basis: performance of the contract (Art. 6.1.b).
5.11 Marketing communications (optional)
- Data: e-mail address, communication preferences.
- Purpose: information about new service features, maintenance tips, occasional offers.
- Legal basis: explicit consent (Art. 6.1.a). You may withdraw your consent at any time via the unsubscribe link included in every message or via your account settings.
5.12 Organisation accounts (Business plan)
Some maintenance records do not belong to a person but to a company, an association or a public body that has subscribed to the Business plan. We call this structure your organisation. If you have been invited to join an organisation, this subsection describes what we process about you in this capacity, what your organisation sees of your activity, and what happens to this information when you leave it.
- Who answers for what: your organisation decides what it puts in its records, who accesses them and what it does with them. For this fleet data, it is the data controller, and we act on its behalf, on its instructions (GDPR, Art. 28). We remain data controller for what we control ourselves: your account, your authentication, the security of the service, the organisation's invoicing, and the technical record of who wrote what. In practice: a question about the content of your employer's fleet is a matter for your employer; a question about your account or your activity record is a matter for us. The commitments we make to your organisation in this respect are described in the data processing agreement (wheeltrust.io/dpa-entreprise).
- Data: your membership of the organisation: the link between your account and the organisation, your role (Fleet Manager, Fleet Administrator or Driver), the status of this link (invitation pending, active, withdrawn, left, expired), the dates of invitation, acceptance and withdrawal, and the identity of the person at the organisation who invited you.
- Data: your assignments: the records assigned to you, the fleets you manage where applicable, the date of each assignment and withdrawal, and the person at the organisation who decided them.
- Data: the record of what you write: every service entry, document and upcoming action you add to an organisation record carries a mark that you are its author, with its date. This mark is an internal technical identifier, never your name or your address copied into the record.
- Purpose: allowing an organisation to assign its maintenance records to the people who look after them and to withdraw that access; knowing who wrote what on an organisation asset, because a record kept by several hands is only valid as proof of maintenance if the author of each line is known; and allowing you to obtain a record of your own activity if you ask us for it.
- Legal basis: for sending the invitation to a person who does not yet have an account, our legitimate interest (Art. 6.1.f) in allowing a customer to open its fleet to its staff, the address being used only for this purpose and never reused or transferred. For your membership, your role and your assignments once your account has been created, performance of the contract you entered into with us by accepting our terms of use (Art. 6.1.b), supplemented by the organisation's legitimate interest in administering its own access rights. For retaining the record of your entries beyond your departure, our legitimate interest (Art. 6.1.f) in the integrity of the record, which is the very value of the service.
- How you are invited, and what happens to your address: a Fleet Manager or Fleet Administrator at the organisation enters your e-mail address to invite you. We send you a single message, telling you who is inviting you, why, how long we keep your address, and where to read this policy. The invitation link is valid for 7 days and can only be used once. Your address is erased at the same time as the invitation ends, in the three possible cases: you accept, the organisation revokes the invitation, or the period expires with no response. All that remains is a truncated fingerprint, which allows two lines of our log to be matched without reconstructing your address.
- What your organisation sees: this depends on the person's role, and on nothing else. A Fleet Manager sees all of the organisation's records and the directory of its members. A Fleet Administrator sees the records of the fleets they manage and the member directory. A Driver sees only the records assigned to them, and does not see the directory. On an organisation record, the people who have access to it also see who entered each line, and when.
- Who can write on an organisation record: all three roles, each within their scope of visibility. A Fleet Manager may log a service entry on any of the organisation's records; a Fleet Administrator, on the records of the fleets they manage; a Driver, on the records assigned to them. Every line bears the name of its author, whatever their role: an entry logged by a manager is identified as such, exactly like one made by a driver.
- What your organisation does not see: your personal records. A record created on a personal account never becomes visible to an organisation, and the records you owned before joining an organisation remain yours. However, any record you create from your account while you are a member of an organisation belongs to that organisation, never to you: if you want to track your personal vehicle, use a separate account, with your personal address. We do not pass on to your organisation your sign-in data, your browsing history, or any information about your use of the service outside its own records.
- Moving a personal record to the organisation: this is an explicit action, which only you can take on a record you own. It is final: the record, its history and its documents become the organisation's, including what you had entered there before. Any sharing you had granted on this record is closed at the same instant, and any pending transfer requests are cancelled.
- When you leave the organisation: your access stops immediately. The records assigned to you are withdrawn, as are the fleets you managed. What you wrote remains in the records, because those records belong to the organisation: this is the same rule as for a personal record opened to a third party. The record that you are its author remains attached to those lines.
- When you delete your account: you automatically leave all of your organisations, your assignments and your fleet management roles lapse, and your account is pseudonymised within 30 days at most. The record of your entries then remains in a form that no longer allows you to be identified. Only one situation delays deletion: if you are the last active Fleet Manager of an organisation that is still open, we ask you to first appoint another Fleet Manager or close the organisation, failing which its records would be left with no one to administer them. The message tells you which one, and the operation takes you a minute.
- Your rights in this context: your rights under Articles 15 to 22 of the GDPR are exercised as described in section 12. Two clarifications specific to organisations. Your data export contains your organisations, your roles, your dates, your assignments and the list of your contributions (what, when, on which vehicle); it does not contain the content of the organisation's records, even for vehicles assigned to you, because this information describes the organisation's activity and not yours, and the right of access must not adversely affect the rights of others (Art. 15.4). To obtain the content of the fleet itself, contact your organisation. The right to portability (Art. 20) does not cover these contributions: you provided them under your organisation's contract, not your own.
- No rating, no ranking: we do not count, rate, rank or compare the members of an organisation. We produce no score, no leaderboard and no inactivity alert. No decision concerning you is made in an automated way based on your activity within an organisation (Art. 22).
- Organisation invoicing: when a Fleet Manager subscribes to the Business plan, we collect the organisation's company name, legal form, SIRET number and, where applicable, EU VAT number, together with a billing e-mail address. The billing postal address and payment method are entered directly with our payment provider Stripe (section 8), which issues invoices and sends them to the billing e-mail address; WheelTrust never keeps a card number. Online subscription is reserved for organisations established in France. The VAT number and SIRET number are recorded as declared: we do not verify them with a third party and draw no automated decision from them; a late payment does not close access to the fleet. We keep a record of the person who committed the organisation. This information describes the organisation, not its members: it is visible only to its Fleet Managers and our authorised staff. The organisation's subscription is separate from any personal subscription you may hold elsewhere: two contracts, two invoices, never combined. If the organisation is a sole trader, this information concerns you directly and you may obtain it, have it corrected and exercise your rights as described in section 12; the billing e-mail address may be replaced at any time with a generic address. Legal basis: for the sole trader, performance of the contract entered into with you (Art. 6.1.b); for issuing and retaining invoices, our accounting and tax obligations (Art. 6.1.c); for the named billing e-mail address and the record of the person who committed the organisation, our legitimate interest (Art. 6.1.f) in performing and invoicing the organisation's contract. Retention: the duration of the contract, then ten years under our accounting obligations (French Commercial Code, Art. L123-22); invoices issued by Stripe follow the same period.
- Retention periods: your invitation e-mail address, for the duration of the invitation and not an hour longer (7 days at most, erased on acceptance, revocation or expiry). Your membership and your roles, for the duration of the organisation's contract: a withdrawal does not delete the line, it marks it as ended, and this is what allows the record of your entries to remain legible. Your assignments, until they are withdrawn. The record of your entries, for the lifetime of the record, and therefore of the organisation.
6. Legal bases for processing
In accordance with Article 6 of the GDPR, we process your data on the following bases:
| Legal basis | GDPR reference | Use case at WheelTrust |
|---|---|---|
| Performance of the contract | Art. 6.1.b | Account creation, subscription, vehicle records, support, organisation membership |
| Statutory obligation | Art. 6.1.c | Accounting retention (French Commercial Code, Art. L123-22), responses to judicial requisitions |
| Explicit consent | Art. 6.1.a and 9.2.a | Sensitive official documents, marketing |
| Legitimate interest | Art. 6.1.f | Audience measurement, security, fraud prevention, inviting a member, retaining the record of organisation entries |
No processing is carried out on any basis other than those listed above.
7. Retention periods
In accordance with the storage limitation principle (GDPR, Art. 5.1.e), we keep your data for the period strictly necessary for the purpose pursued:
| Data / category | Retention period | Reference |
|---|---|---|
| Active user account | Lifetime of the account | Performance of the contract |
| Account deleted at your request | Pseudonymised within 30 days; technical logs kept for 3 years | GDPR Art. 17 and 32 |
| Accounting data and invoices | 10 years from the close of the financial year | French Commercial Code, Art. L123-22 |
| Audit logs | 5 years (level 1) / 3 years (level 2) | Security, Art. 32, and statutory obligations |
| Partner programme data (affiliation) | 3 years after the last activity; bank details deleted at the end of the partnership | Performance of the partner contract and legitimate interest |
| Technical and session cookies | Duration of the session or 13 months maximum | CNIL, cookie guidelines |
| Matomo audience measurement | 13 months | CNIL, deliberation of 17/03/2022 |
| Support requests | 3 years after the ticket is closed | Legitimate interest |
| Marketing messages (with consent) | 3 years after the last contact | CNIL, recommendation |
| E-mail address of a person invited to a record sharing | Duration of the sharing; erased immediately on its withdrawal, refusal, expiry, or the deletion of either account | Legitimate interest and GDPR Art. 5.1.e |
| E-mail address of a person invited to join an organisation | Duration of the invitation, 7 days at most; erased immediately on acceptance, revocation or expiry | Legitimate interest and GDPR Art. 5.1.e |
| Membership of an organisation (role, dates, status) | Duration of the organisation's contract; a withdrawal marks the line as ended, it does not delete it | Performance of the contract and GDPR Art. 5.1.d |
| Assignment of a record or fleet to a member | Until the assignment is withdrawn or the member leaves | Performance of the contract |
| Record of the author of an entry on an organisation record | Lifetime of the record; after the author's account is deleted, the record remains in a form that no longer allows them to be identified | Legitimate interest, integrity of the record |
| Identification and billing data of a client organisation | Duration of the contract, then 10 years from the close of the financial year | Performance of the contract, accounting obligation (French Commercial Code, Art. L123-22) |
At the end of these periods, data is either permanently deleted or pseudonymised. At your request, your account is pseudonymised within 30 days at most; statutory retention obligations (in particular accounting obligations) are kept separately and securely.
If your account is deleted, the mileage history of your vehicles (date, mileage, source of the reading) remains attached to the vehicle in a form that no longer allows you to be identified, under our legitimate interest in preventing odometer fraud. Any free-text comments you entered are erased.
8. Recipients and processors
Your data is never transferred to third parties for commercial purposes. It is only disclosed, to the strict extent necessary, to the following recipients.
You may also decide to open the record of one of your vehicles to a person you designate by their e-mail address (see 5.5 bis). That person then becomes a recipient of that record's data, within the limits you have chosen, and until you withdraw access.
If you are a member of an organisation, the people at that organisation who hold the relevant role are recipients of its records' data, including the record of what you have written there: a Fleet Manager for the entire fleet, a Fleet Administrator for the fleets they manage (see 5.12). It is the organisation that decides on these roles, not us.
8.1 Authorised staff of IT EXPERT SERVICES SAS
Only authorised staff (technical team, support, finance), bound by confidentiality and trained in data protection, access the data necessary for their duties, under an audited access rights policy.
8.2 Processors (GDPR, Art. 28)
We use the following processors, each bound to WheelTrust by a data processing agreement compliant with Article 28 of the GDPR:
| Processor | Purpose | Location |
|---|---|---|
| O2Switch (FR) (FR) | Hosting | France |
| Stripe Payments Europe (IE) (IE) | Payment and invoicing | European Union (Ireland) + United States (standard contractual clauses) |
| Brevo (FR) (FR) | Transactional and marketing e-mails | France |
| Cloudflare (US) (US) | DNS, CDN, web application firewall | United States (standard contractual clauses) |
| Google (US) (US) | Sign-in via Google (when you enable it) | United States (standard contractual clauses) |
| Mistral AI (FR) (FR) | Automatic reading of documents | European Union |
Automatic reading of documents: when you use the add-entry-by-invoice-scan feature, the document you submit is sent to our provider Mistral AI (a French company, hosted in the European Union) for the time needed to extract its content. Your documents are not used to train models and are not used for any other purpose.
Audience measurement relies on Matomo software, self-hosted on our own infrastructure in France: no data is sent to the publisher of this software.
Each processor is contractually required to comply with the GDPR and to provide sufficient guarantees (Art. 28.1 GDPR).
9. Transfers outside the European Union
In accordance with our principle of European sovereignty, hosting and most processing take place within the European Union, mainly in France.
Some limited processing nonetheless involves a transfer outside the EU:
- Cloudflare (United States): DNS, CDN and web application firewall services.
- Google (United States): sign-in via Google, when you enable it.
These transfers are governed by the standard contractual clauses adopted by the European Commission (Decision 2021/914 of 4 June 2021), in accordance with Article 46.2.c of the GDPR, supplemented by additional measures (encryption, segregation) in line with EDPB Recommendations 01/2020.
No data is transferred to a country that has neither an adequacy decision nor appropriate safeguards.
10. Cookies and trackers
WheelTrust is designed to respect your privacy by default.
10.1 Strictly necessary cookies (no consent required)
In accordance with Article 82 of the French Data Protection Act and the CNIL's guidelines, we set the following without prior consent:
- a security cookie (
__Host-authjs.csrf-token), which protects the site's forms against forged submissions from another site (so-called anti-CSRF protection); set by WheelTrust (Auth.js), inaccessible to page scripts, kept for the duration of your browsing session and erased when you close your browser; - a sign-in return cookie (
__Secure-authjs.callback-url), which remembers the address of the page to take you back to after signing in; it contains only the site's address, no data about you; set by WheelTrust (Auth.js), inaccessible to page scripts, kept for the duration of your browsing session and erased when you close your browser; - a session cookie (authentication), set once you are signed in to your account;
- a language preference cookie;
- a cookie recording acceptance of the terms of use;
- a referral cookie (
wt_ref), set only when you follow a referral link, kept for 30 days at most, inaccessible to page scripts and deleted as soon as your account is created; - an invitation cookie (
wt_invite), set only when you follow an invitation link, on the same terms; - a first-name cookie (
wt_prenom), set only when you enter your first name in the account creation form, to remember it between that form and the creation of your account via the magic link; kept for 30 days at most, inaccessible to page scripts and deleted as soon as your account is created, strictly necessary for the service you have requested, it is exempt from consent; - where applicable, a cookie recording your objection to audience measurement (see section 10.2), it contains no identifying data.
The first two cookies in this list, security and sign-in return, are set from the very first page you visit, including if you do not have an account and never sign in. They are strictly necessary for the secure operation of the site: your consent is not required.
10.2 Exempted audience measurement (no consent required)
Our Matomo solution is configured to be exempt from consent, in accordance with the CNIL deliberation of 17 March 2022: no-cookie configuration, anonymised IP address, no cross-referencing with other processing, no disclosure to third parties, self-hosted in France. Visit data is deleted after 13 months; only aggregated and anonymous statistics, which do not allow anyone to be identified, are kept beyond that.
Audience measurement is active only on our public pages; it is never active in your personal space or on record sharing pages.
You may object to it at any time, without justification, directly from this page: your choice is recorded in your browser (see section 10.1) and taken into account immediately.
Opt out of audience measurement
Reading your preference…
We also honour the “Do Not Track” signal: if your browser sends it, no visit data is collected, with no action needed on your part.
10.3 No advertising cookies
WheelTrust uses no advertising cookies, no behavioural trackers, no social media pixels and no third-party marketing tools. No consent banner is therefore necessary.
11. Data security
In accordance with Article 32 of the GDPR, IT EXPERT SERVICES SAS implements technical and organisational measures appropriate to the risk:
- Sovereign hosting in France, compliant with the CNIL's recommendations.
- Encryption in transit: TLS 1.3 protocol across the entire service.
- Encryption at rest: official documents (vehicle registration certificate, driving licence, purchase invoice) are protected by bank-grade encryption through a self-hosted secrets vault. Two-factor authentication recovery codes are hashed using Argon2id with a unique salt.
- Strengthened authentication: two-factor authentication (2FA) mandatory for administration accounts, and offered to all users.
- Logging of sensitive operations in append-only mode (level 1: 5 years; level 2: 3 years).
- Role-based access control, following the principle of least privilege.
- Fraud prevention mechanisms: every mileage reading and change is dated and kept in the vehicle's history (an append-only register), visible to you and to a future buyer; no-stacking of promotional codes where the Publisher offers them, anti-abuse rules for referrals (one code per account, one reward per referred person).
- Encrypted backups, redundant and located in France.
- Regular security testing and mandatory code reviews.
- Incident management: notification to the CNIL within 72 hours in the event of a breach (Art. 33) and individual notification in the event of high risk (Art. 34).
A Data Protection Impact Assessment (DPIA) has been carried out in accordance with Article 35 of the GDPR and is updated periodically.
12. Your rights and how to exercise them
In accordance with Articles 15 to 22 of the GDPR and the French Data Protection Act, you have the following rights:
- Right of access (Art. 15): obtain confirmation that data concerning you is being processed, together with a copy of that data.
- Right to rectification (Art. 16): have inaccurate or incomplete data corrected.
- Right to erasure (Art. 17): request the erasure of your data, subject to statutory retention obligations. Deleting your account results in pseudonymisation within 30 days at most.
- Right to restriction (Art. 18): request the restriction of processing in certain cases.
- Right to portability (Art. 20): retrieve your data in a structured, machine-readable format. A ZIP / JSON export is available to all users; a presentable PDF export is planned from version 1.5.
- Right to object (Art. 21): object to processing based on legitimate interest, as well as to any direct marketing.
- Right to withdraw your consent (Art. 7.3): for processing based on consent (official documents, marketing), at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Post-mortem directives (French Data Protection Act, Art. 85): decide what happens to your data after your death.
If you are a member of an organisation: your data export contains your organisations, your roles, your dates, your assignments and the list of your contributions, but not the content of the organisation's records, which describe its activity and not yours (Art. 15.4). Your right to portability (Art. 20) does not extend to these contributions. To obtain data on the fleet itself, or request its rectification, contact your organisation: it is the one that decides, and we assist it on request. Lastly, if you are the last active Fleet Manager of an organisation that is still open, deleting your account first requires you to appoint another Fleet Manager or close the organisation; we tell you which one, and the operation is immediate.
Automated decisions (Art. 22): WheelTrust does not use fully automated decisions producing legal effects. Automated anti-fraud checks are systematically reviewed by a person before any restrictive measure.
To exercise your rights: directly from your personal space (“My data” section), by e-mail at contact@wheeltrust.io, or by post to IT EXPERT SERVICES SAS, 9 Allée Saint-Éloi, 77144 Chalifert. We will respond within one month, extendable by two months in complex cases (Art. 12.3). Reasonable proof of identity may be requested. No fee is charged to you, except for manifestly unfounded or excessive requests (Art. 12.5).
13. Data relating to minors
WheelTrust is not intended for minors under the age of 16. In accordance with Article 8 of the GDPR and Article 45 of the French Data Protection Act, we set the minimum age for registration at 16.
All registration is conditional on a declaration of age. If we discover that an account belongs to a minor under the age of 16, we delete it after notifying the account holder and, where applicable, their legal representative.
14. Changes to this policy
This policy may change over time. Any substantial change will be notified to you:
- by e-mail to the address associated with your account, at least 30 days before it takes effect;
- via a notification within the service;
- by publishing an updated version on this page, with its date.
If a change reduces your rights or significantly increases our prerogatives, your explicit consent will be requested.
15. Complaints to the CNIL
If you believe, after contacting us, that your rights are not being respected, you may lodge a complaint with the French supervisory authority:
- Commission Nationale de l'Informatique et des Libertés (CNIL)
- Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
- Phone: 01 53 73 22 22
- Website: www.cnil.fr
If you reside in another State of the European Union, you may also refer the matter to the supervisory authority of your State of residence (GDPR, Art. 77).
See also: Legal notice · Terms of Use · Terms of Sale.

