The controller of personal data is osaühing INDREKS REIS, registry code 10395867, registered address Peterburi tee 46, 11415 Tallinn. EURO TAKSO is a trademark, not a separate legal entity or controller. For privacy and data-subject rights matters, contact irtakso@gmail.com.
osaühing INDREKS REIS organises and intermediates taxi orders, connecting the customer with the transport service provider. The actual carrier for each ride is an independent sole trader (FIE) or company (OÜ), not osaühing INDREKS REIS. Driver users operate as independent service providers. The Driver account of a driver working through an OÜ is personal to the natural person specifically authorised in the cooperation arrangement; it must not be shared or used by another driver.
When EURO TAKSO Driver is used, we process driver account and login data, driver identity and contact details, vehicle data, a device identifier and technical information, and app connection and usage data. To intermediate and fulfil orders, we process order status and driver actions, customer pickup and destination locations, trip progress, meter and tariff data, fares, payment method and accounting data. An order assigned to a driver may include the customer's phone number, addresses, notes and order-related messages. When a receipt is printed, the order, trip, fare, driver and vehicle information needed to produce it is processed.
Technical, connection and security information and operational diagnostics may be processed where necessary for service operation and security, troubleshooting and dispute handling.
Active listening for GPS and other location services starts only after the driver has logged in successfully. A failed login does not start location listening. While the driver is logged in and working, precise location is also processed in the background to dispatch orders, arrange pickup, support fulfilment of the ride and show the progress of an active order.
Logout, forced logout by an administrator, login to the same account on another device, or termination of the Driver service stops active location listening. Late location callbacks received after logout are not used for order processing or location transmission.
Authorised dispatcher, operator and administrator systems may receive an active driver's current location within their assigned duties. A customer may see the current location of the driver assigned to that customer's active order. The driver's live location is not shown to other customers or other drivers.
Where a driver is personally the FIE contracting with osaühing INDREKS REIS, processing of their account, orders, trips and work-related location is based on Article 6(1)(b) GDPR only to the extent necessary to perform their own agreement. The necessary account, order, trip and working-time location data of a specifically authorised driver working through an OÜ is processed under Article 6(1)(f) for osaühing INDREKS REIS's legitimate interest in securely intermediating and organising orders, taking account of the driver's rights, limited visibility and the necessity of processing.
Processing necessary technical and security logs and data for specific dispute handling is based on Article 6(1)(f) only within the limits of the relevant purpose and necessity. Article 6(1)(c) applies to legally required accounting and other legal obligations and to handling data-subject rights requests. Granting device location permission is not, by itself, the GDPR legal basis for these activities.
Customers may pay in cash or using the service provider's separate physical card terminal. Driver uses payment-method and trip-accounting data, but the app itself does not process payment-card numbers, PAN or CVC.
An optional locally paired Bluetooth printer may receive the order or invoice number and date, trip times and addresses, tariff, distance, time and amount lines, where applicable minimum-fare and bonus or discount lines, and service-provider, driver and vehicle details needed to print a receipt. This function does not print the customer's phone number or order notes. The Bluetooth printer is a local device, not an internet-based external processor.
The map embedded in Driver uses Google Maps SDK, and location functionality uses Google Play Services Location. Android Geocoder may be used to convert between addresses and coordinates; its actual backend provider may depend on the device. If the driver chooses external navigation and opens Google Maps or Waze, the selected app receives destination coordinates or, if unavailable, an address. Subsequent processing by the external navigation app is governed by its provider's terms.
Authorised dispatchers, operators and administrators can access data within their assigned role and duties. A customer with an active assigned order may see the driver's current location. GPS history associated with an active or archived order may be available in an authenticated backend or administration order-map view. Access is restricted by role; this policy does not claim that location history is visible to all staff or to only one specifically named role. No user-facing historical GPS trajectory view was found in Driver or the customer app.
The technical service providers and infrastructure identified below may process data to the extent needed to operate the service. Data is not provided to others for purposes that are not justified by service delivery, a legal obligation, security or dispute handling.
The API, real-time and routing functions operate on infrastructure used by osaühing INDREKS REIS. The confirmed production hosting provider is Hetzner. Driver's primary API traffic and routing use HTTPS, while the primary real-time and GPS channels use WSS.
Google Maps SDK and Google Play Services Location are used as technical services within Driver. Android Geocoder may use a backend service selected by the device. Google Maps and Waze receive data only when the driver selects the relevant external navigation app.
Operational diagnostics may be generated for service reliability, security and troubleshooting. Release logging on the primary API, WebSocket, routing and Bluetooth communication paths is minimised, and sensitive request or response payloads are not intentionally included in those logs. This is not a claim that every legacy logging path in the app has been fully audited or completely eliminated.
Driver 2.223 disables Android app backup, and its backup and device-transfer rules exclude private app data. App-private local data is therefore not intended for Android cloud backup or device transfer. This setting does not describe server-backup retention.
Completed orders are archived and are not automatically deleted when an order ends. Older archived orders may be moved into year-specific archive tables. Detailed GPS and order logs may be associated with an order. Driver accounts use soft deletion on the server, so ending account access does not mean immediate physical deletion of all historical information.
Personal data is retained according to service operation, accounting, legal, security and dispute-handling needs. Different data categories may have different periods, which must be governed by the approved retention policy. This policy does not promise a uniform, automatic or immediate deletion period. No automatic deletion or rotation period for server backups or GPS and order logs is specified here.
Driver accounts are created outside the app. The app has no self-service account-creation or deletion feature. Blocking or ending account access is different from deleting personal data; history needed under a legal or other valid ground may remain. Uninstalling the app is not a deletion request and does not automatically delete data held on the server.
To request access, correction, deletion or restriction of your data, to object to processing based on legitimate interests, or to exercise other applicable rights, email irtakso@gmail.com. Requests are assessed under applicable rights and retention obligations; immediate deletion of all historical records cannot be promised. You may also contact the Estonian Data Protection Inspectorate.