Privacy Policy

Version 1.0 · Effective August 11, 2026

1. Introduction and scope

This Privacy Policy («Policy») describes how GRUPO AMX LOGÍSTICA COMERCIO Y SERVICIOS («the Provider») processes personal information in connection with KontrolFleet («Platform»).

This Policy applies to the website https://kontrolfleet.com, administrative interfaces, mobile applications, APIs, support, and related services offered by the Provider.

By using the Platform, data subjects acknowledge that they have read this Policy. When the Customer incorporates third-party data, it is responsible for informing them and obtaining required authorizations.

2. Roles in data processing

The Provider acts as controller for registration data, membership billing, support, platform security, aggregated service analytics, and the Provider's own communications.

For data the Customer enters about its operations, personnel, drivers, end customers, and third parties, the Customer acts as controller and the Provider acts as processor, handling such data under documented Customer instructions and this Policy.

Where law requires a data processing agreement, the parties will formalize it on terms consistent with this Policy.

3. Personal information processed

Identification and contact data: name, email, phone, job title, account identifiers, and access credentials.

Organization data: legal name, trade name, tax identifiers, business address, billing configuration, and service preferences.

Operational data entered by the Customer: fleet information, trips, routes, maintenance, documents, incidents, hours of service, telemetry, geolocation, media captured in operations, and other records uploaded or generated in the Platform.

Technical data: IP address, device identifiers, activity logs, cookies or similar technologies, usage metrics, and security logs.

Payment data: card or other payment information is processed by specialized providers; the Provider does not store full card numbers when the processor assumes that function.

4. Purposes and legal bases

Provide, administer, and improve the Platform, including authentication, authorization, support, maintenance, and feature development.

Manage subscriptions, payments, membership billing, renewals, taxes, and service accounting compliance.

Protect security, prevent fraud, investigate incidents, and ensure service integrity.

Send operational communications, service notices, product updates and, with adequate legal basis, commercial communications from the Provider.

Comply with legal obligations, respond to authority requests, and enforce rights in applicable proceedings.

Prepare aggregated or anonymized statistics that do not identify individuals.

Legal bases include, as applicable: contract performance, consent, the Provider's legitimate interests (balanced against data subject rights), legal compliance and, where applicable, vital or public interest.

5. Security

The Provider implements reasonable technical, administrative, and organizational measures to protect personal information against unauthorized access, loss, alteration, or improper disclosure.

Among other measures, the Provider applies access controls, encryption in transit where appropriate, logical segregation between customers, periodic backups, security monitoring, and incident response procedures.

No system is completely infallible; the Customer must also adopt internal good practices, manage user permissions, and protect its credentials.

6. Sharing and international transfers

The Provider may share personal information with vendors that provide services on its behalf (for example, hosting, email, payment processing, maps, messaging, analytics, or support), subject to contractual confidentiality and data protection obligations.

Information may also be disclosed when required by law, competent authority, or to protect rights, safety, and integrity of the Provider, Customer, or third parties.

In corporate transactions (merger, acquisition, or asset sale), personal information may be transferred under this Policy and applicable safeguards.

Information may be processed in countries other than the data subject's country. Where required by law, the Provider will implement recognized transfer mechanisms (such as standard contractual clauses or other valid instruments).

7. Retention

The Provider retains personal information while an active relationship exists, while necessary for described purposes, or while required by law.

After service termination, the Provider may retain certain records for additional periods for backups, audit, dispute resolution, or legal compliance, and will then delete or anonymize them under internal policies.

The Customer may export Customer Data during the service term through available features.

8. Data subject rights

Under applicable law, data subjects may request access, rectification, erasure, objection, restriction of processing, portability, or withdrawal of consent, where applicable.

Requests relating to data processed as processor should preferably be directed to the responsible Customer; the Provider will assist the Customer to a reasonable extent.

Direct requests to the Provider regarding data for which it is controller may be sent to the email in section 13. The Provider may request information to verify identity before responding.

9. Regional provisions

9.1. European Union and United Kingdom

When the General Data Protection Regulation (GDPR) applies, data subjects have the rights provided therein, including the right to lodge a complaint with a supervisory authority.

The Provider will handle EU/UK data subject requests under GDPR timelines and requirements, to the extent applicable to its role.

9.2. California (USA)

When the California Consumer Privacy Act (CCPA/CPRA) applies, California residents may exercise rights to know, delete, and correct personal information, and to opt out of certain sales or sharing, where applicable.

The Provider does not sell personal information within the meaning of CPRA. Requests may be sent to the contact email in this Policy.

9.3. Mexico

When Mexico's Federal Law on Protection of Personal Data Held by Private Parties applies, data subjects may exercise ARCO rights and revoke consent under that law and its regulations.

The comprehensive privacy notice for Mexican data subjects is reflected in this Policy.

10. Cookies, automated decisions, and minors

The Provider uses cookies and similar technologies for authentication, preferences, security, and service analytics. Data subjects may manage cookies through browser settings, although some features may be affected.

The Platform may generate alerts or operational classifications based on configurable rules; exclusively automated decisions with significant legal effects on data subjects without human involvement are not adopted by the Provider, unless the Customer configures its own workflows to that effect.

The Platform is not directed to minors. The Customer must not register minors as users except where labor or transport law permits and an adequate legal basis exists.

11. Customer obligations

The Customer must provide clear privacy notices to employees, drivers, and other data subjects whose data it processes in the Platform, obtain consent when required, and respond to rights requests in its capacity as controller.

The Customer will configure access permissions under least privilege and notify the Provider of security incidents affecting data processed in the Platform.

12. Policy updates

The Provider may update this Policy to reflect legal, technical, or operational changes. The current version is identified by version number and effective date.

When changes are material, the Provider will seek to notify the Customer through reasonable means. Continued use of the Platform after the effective date implies acknowledgment of the updated version, unless law requires additional consent.

13. Contact

GRUPO AMX LOGÍSTICA COMERCIO Y SERVICIOS

Privacy / Data protection

Email: [email protected]

Website: https://kontrolfleet.com