Back
DATA PROTECTION
Version: 1.1.0 Effective date: 10 August 2026
Synegia Sàrl will process your personal data in order to operate the DailyFleetPro SaaS application and to manage the related contractual and user relationships, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation — "GDPR").
As a private company processing personal data, Synegia is required to comply with its obligations as controller for the processing activities described below.
Please find below Synegia's contact details:
Synegia Sàrl
21, rue Glesener
L-1631 Luxembourg
Grand Duchy of Luxembourg
Registered with the Luxembourg Trade and Companies Register under number B187706
E-mail: [email protected]
For any question regarding the processing of your personal data carried out by Synegia, please contact:
› By email: [email protected]
› By post: Synegia Sàrl — Data Protection, 21, rue Glesener, L-1631 Luxembourg
Synegia has not designated a Data Protection Officer within the meaning of Article 37 of the GDPR.
The personal data processing activities carried out by Synegia as controller are described below. For each processing activity, detailed information is available in the corresponding section (including information regarding the exercise of your rights).
This notice covers the processing operations carried out by Synegia as controller. The processing operations carried out by Synegia as processor on behalf of its Subscribers (in particular fleet management, exceptional activity tracking and payroll-data preparation relating to the Subscribers' Collaborators) are not covered by this notice; they are governed by the Data Processing Agreement (DPA) entered into between Synegia and each Subscriber, and the relevant Subscriber — as controller — is responsible for informing the data subjects concerned.
This notice is available in French and English. In the event of any discrepancy between the two versions, the French version shall prevail.
I. Customer relationship management
Management of Subscribers
Synegia enters into subscription agreements with companies and other professional entities (the "Subscribers") wishing to use the DailyFleetPro service. In this context, Synegia processes the personal data of the legal representatives and contact persons of the Subscribers, as well as of prospects who have expressed an interest in the service, in order to manage the contractual relationship, invoicing, support and the related legal obligations.
Further information
1. Purposes of the processing
Synegia (21, rue Glesener, L-1631 Luxembourg) processes personal data relating to the legal representatives, contact persons and billing contacts of the Subscribers and of the prospects of the DailyFleetPro service in order to:
› enter into and perform the subscription agreement for the Solo, Team, Business or Corporate offering with the Subscriber; › manage the Subscriber's account, the subscription plan and the lifecycle of the contract (creation, modification, renewal, termination); › invoice and collect the fees due under the subscription, including processing payments by credit card and managing unpaid invoices; › reply to pre-contractual requests and follow up commercially with prospects who have requested information about the service; › manage customer support, complaints and disputes; › keep accounting records and comply with the accounting, tax and anti-money-laundering obligations applicable to Synegia; › defend Synegia's rights in legal proceedings, where applicable.
2. Personal data processed
The following personal data are collected and accessible to Synegia staff members in charge of the customer relationship:
› Identification data of the Subscriber and of its legal representative or contact person: company name, legal form, registration number, VAT number, registered office, postal address, first name, surname, position, professional email address, professional telephone number. › Contractual data: subscription plan, number of Collaborators, start and end dates of the subscription, contractual history. › Billing and payment data: invoices, amounts, tokenised payment-card identifier (the full card number is not stored by Synegia and is processed exclusively by the payment service provider), payment history, unpaid invoices. › Commercial follow-up data: exchanges with the sales and support teams, content of support tickets, date and content of pre-contractual exchanges. › Data necessary for the keeping of accounting records, in accordance with the Luxembourg Commercial Code.
3. Legal basis for the processing
The processing of personal data carried out by Synegia in this context is based on:
› the performance of the contract to which the Subscriber is a party, or pre-contractual measures taken at its request [Article 6(1)(b) of the General Data Protection Regulation]; › compliance with a legal obligation to which Synegia is subject, in particular Luxembourg accounting, tax and anti-money-laundering legislation [Article 6(1)(c) of the General Data Protection Regulation]; › the legitimate interests pursued by Synegia, namely the management of its commercial relationships, the recovery of unpaid invoices and the defence of its rights in legal proceedings [Article 6(1)(f) of the General Data Protection Regulation].
4. Categories of recipients of the personal data
Within Synegia, the personal data mentioned above may be accessed by staff members in charge of the customer relationship, invoicing, support, accounting and, where applicable, the legal management of disputes.
The personal data processed may also be accessed by the following processors acting on behalf of Synegia:
› the cloud-hosting and infrastructure provider of the DailyFleetPro service; › the transactional email provider used for service-related communications; › the payment service provider used to process payments by credit card; › the customer-support tool provider; › Synegia's accounting service provider.
The personal data may also be disclosed to the competent administrative or judicial authorities where Synegia is required to do so by a legal obligation or a duly motivated request, and, where applicable, to external legal counsel and debt-collection agencies.
In the event of a merger, acquisition, transfer of business or restructuring, the data may be transferred to the acquirer or successor of Synegia, subject to prior notification of the Subscriber.
The personal data are not sold, rented or transferred to third parties for advertising or marketing purposes.
5. Retention period
› Data relating to the active customer relationship: throughout the duration of the subscription. › Contractual and accounting data (contracts, invoices): 10 years from the end of the financial year concerned, in accordance with the obligations laid down in the Luxembourg Commercial Code. › Commercial-prospecting data (prospects who have not become customers): 3 years from the last contact initiated by the data subject. › Support tickets and commercial correspondence: 3 years from the closure of the ticket or the end of the contractual relationship. › Data necessary to defend Synegia's rights in legal proceedings: throughout the applicable limitation periods.
6. Rights of the data subject
You have the right to access your personal data and to obtain a copy of them (Article 15 of the General Data Protection Regulation), to obtain the rectification of inaccurate or incomplete personal data (Article 16 of the General Data Protection Regulation), to obtain the erasure of your personal data (Article 17 of the General Data Protection Regulation), to obtain the restriction of the processing under the conditions laid down in Article 18 of the General Data Protection Regulation, to data portability (Article 20 of the General Data Protection Regulation) and to object to the processing of your personal data carried out on the basis of Synegia's legitimate interests, on grounds relating to your particular situation (Article 21 of the General Data Protection Regulation).
For any questions regarding the processing of your personal data carried out by Synegia, and for any queries regarding the exercise of your rights, please contact [email protected].
7. Complaint
If you consider that the processing of your personal data by Synegia infringes the General Data Protection Regulation, you may lodge a complaint with the Commission nationale pour la protection des données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Grand Duchy of Luxembourg.
II. User account management
Management of Users of the DailyFleetPro service
Synegia provides access to the DailyFleetPro service to the natural persons authorised by the Subscriber (the "Users"), in their capacity as Owner, Manager, Gestionnaire or Intervenant. In this context, Synegia processes the personal data necessary for the creation and administration of user accounts, for the authentication of Users and for the security of the service.
Further information
1. Purposes of the processing
Synegia (21, rue Glesener, L-1631 Luxembourg) processes personal data relating to the Users of the DailyFleetPro service in order to:
› create and administer the user accounts of Owners, Managers, Gestionnaires and Intervenants; › authenticate and identify Users and manage their access rights and Roles within their Organisation; › send service-related communications (account creation, invitation to join an Organisation, password reset, security notices, changes to the Terms of Use or to this notice); › ensure the security, integrity and availability of the service, prevent fraud and detect misuse; › keep logs of connections and significant actions for security and audit purposes.
2. Personal data processed
The following personal data are collected and accessible to Synegia staff members in charge of the operation of the service:
› Identification data: first name, surname, professional email address. › Authentication data: hashed password, multi-factor authentication tokens where applicable, password reset tokens. › Account data: Organisation to which the User is attached, Role (Owner, Manager, Gestionnaire, Intervenant), assigned scope, date of creation of the account, date of last connection, account status (active, suspended, deleted). › Technical and connection data: IP address, browser and operating-system data, mobile-device identifiers strictly necessary for the operation of the iOS and Android applications, connection and event logs. › Communication data: language preferences, notification preferences, content of service-related emails sent by Synegia to the User.
The data relating to a User invited to join an Organisation (first name, surname, professional email address) are collected from the Owner or the Administrator issuing the invitation, in accordance with Article 14 of the General Data Protection Regulation.
3. Legal basis for the processing
The processing of personal data carried out by Synegia in this context is based on:
› the performance of the contract entered into between Synegia and the Subscriber, of which the User is a beneficiary, it being specified that the User's access to the service is necessary for the performance of that contract [Article 6(1)(b) of the General Data Protection Regulation]; › the legitimate interests pursued by Synegia, namely securing the service, preventing unauthorised access and fraud, and maintaining the integrity of accounts and logs [Article 6(1)(f) of the General Data Protection Regulation]; › compliance with a legal obligation to which Synegia is subject, as regards the retention of certain technical logs [Article 6(1)(c) of the General Data Protection Regulation].
4. Categories of recipients of the personal data
Within Synegia, the personal data mentioned above may be accessed by staff members in charge of the technical operation of the service, customer support and security.
The personal data processed may also be accessed by the following processors acting on behalf of Synegia:
› the cloud-hosting and infrastructure provider of the DailyFleetPro service; › the transactional email provider used for service-related communications; › the customer-support tool provider; › the security and monitoring tool providers used to ensure the integrity and availability of the service.
Within the Subscriber's Organisation, the Owner and the Administrators have access to the data of the Users of their Organisation for the purposes of administering that Organisation in the service.
The personal data may also be disclosed to the competent administrative or judicial authorities where Synegia is required to do so by a legal obligation or a duly motivated request.
The personal data are not sold, rented or transferred to third parties for advertising or marketing purposes.
5. Retention period
› Active account data: throughout the duration of the User's account within the Organisation. › At the end of the subscription or of the User's account, the data are kept for the 30-day recovery period provided for in the Terms of Use, then deleted. › Connection logs and technical security logs: 12 months from their generation. › Data necessary to evidence the existence of a right or contract or to defend Synegia's rights in legal proceedings: throughout the applicable limitation periods.
6. Rights of the data subject
You have the right to access your personal data and to obtain a copy of them (Article 15 of the General Data Protection Regulation), to obtain the rectification of inaccurate or incomplete personal data (Article 16 of the General Data Protection Regulation), to obtain the erasure of your personal data (Article 17 of the General Data Protection Regulation), to obtain the restriction of the processing under the conditions laid down in Article 18 of the General Data Protection Regulation, to data portability (Article 20 of the General Data Protection Regulation) and to object to the processing of your personal data carried out on the basis of Synegia's legitimate interests, on grounds relating to your particular situation (Article 21 of the General Data Protection Regulation).
Where the request relates to data processed by Synegia on behalf of a Subscriber, Synegia will forward the request to the Subscriber concerned, which is the controller of those data, and will inform the data subject accordingly.
For any questions regarding the processing of your personal data carried out by Synegia, and for any queries regarding the exercise of your rights, please contact [email protected].
7. Complaint
If you consider that the processing of your personal data by Synegia infringes the General Data Protection Regulation, you may lodge a complaint with the Commission nationale pour la protection des données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Grand Duchy of Luxembourg.
III. Website and subscription-interface audience measurement
Synegia processes, as data controller, data relating to the use of the website and subscription interface to measure product audience, understand navigation journeys, measure calls to action and payment-flow starts, improve the service and, where you have consented, link the web journey to your account and the mobile application.
The data may include the page path, URL parameters useful for attribution (utm_*, gclid, fbclid), the referrer, navigation and conversion events, and the user and organisation identifiers when you are logged in and have accepted audience measurement. After consent, download links may also contain ph_distinct_id, the browser's PostHog identifier, to allow a potential link with the mobile application. This parameter may be sent to Apple or Google when you open their store.
Audience measurement is provided by PostHog Inc. through its European instance (eu.i.posthog.com). After consent, PostHog may use cookies and first-party storage to retain the measurement identifier and receive the permitted identification functions. If you refuse, cookieless measurement based on a privacy-preserving hash is used, without identify or group.
The legal basis is Article 6(1)(a) GDPR for analytics cookies and identification after consent. Cookieless measurement after refusal must only be implemented after a legitimate-interest assessment has been validated and documented under Article 6(1)(f) GDPR. This measurement uses an identifier or a privacy-preserving server-side pseudonymous hash and must not be presented as fully anonymous. You may withdraw your consent through the banner or object to any cookieless measurement implemented on the basis of legitimate interest by contacting [email protected].
Retention is carried out according to the applicable PostHog configuration and the DPA concluded with PostHog. The data are not used for advertising profiling, are not resold, and global autocapture and session recording are disabled. The list of subprocessors is available in the dedicated document.
Last update: 11 August 2026
DailyFleetPro
Legal information
Language: