Privacy Policy

SaverOne 2014 Ltd. — SaverOne management dashboard

Draft — demo text. This is a provisional privacy policy pending final review by our data-protection officer. The wording, contact details and dates are not yet final.

1. Who this policy is for

This policy explains how SaverOne 2014 Ltd.("SaverOne", "we") processes personal data through the SaverOne management dashboard (the web application you log in to). Two roles apply, and they affect your rights:

  • For dashboard users (fleet managers, administrators, technicians and other staff who log in), SaverOne is the data controller of your account and usage data.
  • For driver-safety monitoring data(data about vehicles, devices and drivers' in-vehicle phone use), SaverOne generally acts as a data processor on behalf of your organization (the fleet operator / employer), which is the controllerof that data. Where SaverOne is a processor, that organization's own privacy notice and lawful basis govern.

2. What personal data we process

Dashboard account data (as controller):

  • Identity & contact: first name, last name, email address, profile avatar (optional).
  • Account settings: language/locale, timezone, date-time format, role and permissions, organization membership.
  • Authentication & security: hashed password, two-factor status and "remember this device" token, and session/login records including IP address and user-agent.

Fleet / driver-safety data (as processor, on behalf of your organization):

  • Vehicle records: license plate, internal/unit number, make/model/year, notes.
  • Device records: device identifiers, installation details and installer name, and on-site installation photos.
  • In-vehicle phone-use & driving-behavior telemetry, keyed to device/phone identifiers and optional labels: safe-mode activations, Bluetooth-off and notification events, app-permission status, driving/idling time, and connected vehicles.
  • Where an ELD/telematics integration is enabled by your organization: driver name/ID, vehicle identifiers and trip/driving-period data received from the provider.

We do not intentionally collect special-category data, and we do not use the data for advertising.

3. Why we process it, and our legal basis

  • Providing and securing dashboard access (login, 2FA, sessions) — contract / legitimate interests (security).
  • Fleet & device management and driver-safety compliance — on behalf of the controlling organization (typically its legitimate interests or legal obligation; employee monitoring is subject to the controller's balancing test and any required employee consultation).
  • Transactional emails (verification, password reset, alerts) — contract / legitimate interests.
  • Push notifications to keep devices in sync — legitimate interests.
  • Audit logging and abuse prevention — legitimate interests / legal obligation.

4. Who we share data with

We do not sell personal data. We share it only with service providers acting on our behalf under data-processing agreements, and with your organization:

  • Microsoft Azure — cloud hosting (compute, database, storage) in the West Europe (EEA) region.
  • Microsoft (Microsoft Graph) — sending transactional email.
  • Google (Firebase Cloud Messaging) — delivering push notifications to devices.
  • ELD / telematics providers enabled by your organization — as the source of driver/vehicle telematics.
  • Your organization — dashboard users within your organization can see fleet and driver-safety data scoped to that organization.

5. International transfers

Core hosting and data storage are located in the EEA (Azure West Europe). Some sub-processors (for example Google Firebase and certain US-based ELD providers) may process data outside the EEA; where that happens, transfers are safeguarded by appropriate mechanisms such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.

6. How long we keep it

  • Account data: while your account is active; deleted or anonymized after closure, subject to legal retention needs.
  • Audit / activity logs: up to 24 months.
  • Device history logs: approximately 6 months.
  • Driver-safety telemetry: retained per your organization's configuration and the underlying data source.

7. Your rights

Subject to applicable law, you have the right to access, rectify, erase, restrict or object to processing, and to data portability; where processing is based on consent, you may withdraw it at any time.

  • Dashboard users: view and correct much of your profile in-app under Settings, or contact us at privacy@saver.one.
  • Drivers and other monitoring data subjects: because your employer / fleet operator is the controller of that data, please direct requests to them; we will support them in fulfilling your request.

You also have the right to lodge a complaint with your data-protection supervisory authority.

8. How we protect your data

We apply appropriate technical and organizational measures, including encryption in transit (TLS), passwords stored only as salted hashes, role- and organization-scoped access control, two-factor authentication, secrets held in a managed key vault, and hosting on access-controlled EEA infrastructure.

9. Cookies

The dashboard uses only strictly necessary cookies required to operate the service: a session/authentication cookie to keep you logged in, and an optional "remember this device" cookie set only if you choose it during two-factor authentication. We do not use analytics, advertising, or tracking cookies.

10. Changes & contact

We may update this policy from time to time; material changes will be notified through the dashboard or by email. Questions or requests: privacy@saver.one — SaverOne 2014 Ltd.

This policy is provisional and being finalized by our data-protection officer; it will be updated and localized. Nothing here is legal advice.