Privacy Policy
Last updated: 2026-07-20
1. Introduction
This privacy policy explains how Torek (“we”, “us”) collects, uses, and protects your personal data when you use our fleet management platform at torek.eu.
Torek is registered in Lithuania, EU. For the personal data of our direct customers (such as account and billing contacts), Torek is the data controller under the EU General Data Protection Regulation (GDPR). For operational and fleet data that a customer organization enters about its own staff and contacts, that organization is the controller and Torek acts as a data processor on its behalf. This controller/processor split is formalized in the Data Processing Agreement (DPA) signed with each customer.
2. Data We Collect
Account data: name, email address, phone number, organization name.
Usage data: login times, IP address, browser type, page views.
Fleet data: vehicle information, maintenance records, work orders, and other data you enter into the platform.
Payment data: processed by a certified external payment processor and not stored on our servers.
Website inquiry form data: name, email address and the content of your message when you submit an inquiry on torek.eu. This data is used only to respond to your inquiry and is retained for no longer than 180 days.
3. How We Use Your Data and Legal Bases
We use your data to: provide and improve the service, manage your account, process billing and payments, provide technical support, comply with legal requirements.
Legal bases for processing (GDPR Art. 6): performance of a contract — to provide the service and manage your account; legal obligation — for accounting and tax requirements; legitimate interest — to secure the service, prevent fraud and improve the product; consent — where we ask for it separately (e.g. marketing communications).
We NEVER sell your personal data to third parties.
4. Data Storage and Security
Your primary data (database and file storage) is held on servers located in the European Union. Data is transmitted only over encrypted connections (TLS 1.2+). We apply layered security measures: row-level security (RLS) ensuring complete data isolation between customers, role-based access control, audit logging and continuous infrastructure monitoring.
We retain your data as long as you have an active account. After account deletion, data is permanently removed within 30 days, unless longer retention is required by law. Regular encrypted backups are stored in the EU; in tamper-protected backups, deleted data may persist until the end of the backup retention cycle and is then removed automatically.
5. Your Rights (GDPR)
Under GDPR, you have the right to: access your data, request data correction, request data deletion ('right to be forgotten'), restrict data processing, data portability, object to data processing.
To exercise your rights, contact us at info@torek.eu. We will respond within 30 days.
You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt).
7. Categories of Data Processors
To provide the service we rely on carefully selected service providers (data processors). We publicly disclose them by category:
Payment processing service — payment card data is never stored on our servers (US).
Transactional email delivery service (EU).
Content delivery network (CDN), firewall and DNS (US).
Application error monitoring service (US).
Mobile push notification service (US).
AI language-model service — used only for customers and their designated users who have enabled the AI feature (US).
File and attachment storage (EU, own infrastructure).
TLS certificate authority (no personal data is shared).
All processors are bound by data processing agreements under GDPR Article 28 and process data only on our documented instructions. We provide the full named list of processors to business customers in the Data Processing Agreement (DPA) and notify them of changes; the list is also available on justified request at info@torek.eu.
8. International Data Transfers
Our primary data location is the European Union. Where processors in the categories listed in Section 7 process limited personal data outside the EU/EEA (e.g. the US), transfers take place only with appropriate safeguards in place: the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework (DPF).
9. Data Breach Notification
If we identify a personal data breach likely to put your rights and freedoms at risk, we will notify the Lithuanian State Data Protection Inspectorate within 72 hours (GDPR Art. 33) and, in high-risk cases, inform you directly without undue delay (GDPR Art. 34).
10. Automated Decision-Making
We do not make solely automated decisions that produce legal effects concerning you or similarly significantly affect you (GDPR Art. 22). The platform's AI features are assistive only — final decisions are always made by a human.
11. Children's Data
The service is intended for business customers and is not directed at individuals under 16. We do not knowingly collect personal data of minors.
12. Contact Information
For data protection inquiries, contact us at: info@torek.eu.
At present, Torek has not appointed a separate Data Protection Officer (DPO); data protection inquiries are handled via the contact above.
Torek, Lithuania, EU.
13. Policy Changes
We will notify you of any material changes to this privacy policy via email or platform notification at least 30 days before the changes take effect.
14. Employees and Other Individuals Whose Data Is Entered by an Organization
If your employer or another organization uses Torek, they may enter your personal data into the platform. For that data the organization is the data controller and Torek acts as a data processor on its behalf.
Categories of data: name and contact details, job role, and records linked to vehicles, work orders, maintenance and time entries assigned to you.
Source of the data: it is provided by your employer or the organization operating the account, not collected from you directly.
Purpose: to provide the fleet maintenance and management service to that organization.
Your rights: you have the GDPR rights described in Section 5. Because we act as a processor for this data, please direct requests to your employer (the controller); we will assist and forward requests where appropriate.
The legal basis for processing this data (e.g. legitimate interest or the employment relationship) is determined by the data controller — your employer or the organization administering the account. Data is retained while the account is active and deleted within 30 days of account closure, as described in Section 4, unless the controller instructs otherwise or longer retention is required by law.