1. Parties and background
This data processing agreement (the "DPA") applies between the customer (the taxi company, the "Controller") and Naxdor, Linjegatan 3D, 302 50 Halmstad, Sweden (the "Processor"), and forms part of the agreement governing use of the Manecab service. The business registration number is provided when entering into an agreement. The DPA is intended to satisfy the requirements of Article 28 GDPR and applies in the version indicated by the date at the top of this page. Earlier versions are retained, and the version in force at a given point in time is provided on request. Material changes are notified to account holders in writing at least 30 days in advance.
2. Subject matter, duration, nature and purpose
The Processor processes personal data on the Controller's behalf in order to provide Manecab: administration of vehicles, drivers and employees, shift reporting, analytics, scheduling, booking requests, customer register and invoicing, expenses and receipts, payroll records, vehicle and equipment register, price quotations, internal communication, leave, employment contracts and document management. Processing continues for the duration of the agreement and ends in accordance with Section 10.
3. Categories of data subjects and personal data
- Users (owners, administrators, drivers):name, email address, phone number, taxi driver licence number, employment terms (e.g. salary or commission in employment contracts), absence records (including sick leave and VAB), shift and financial records (shifts, trips, expenses, fuel), and uploaded documents (e.g. copies of driving licences and identity documents, including taxi driver licences). The service has no dedicated personal identity number field for users. Swedish personal identity numbers nevertheless occur: first in the field for the company's business registration number — for a sole trader (enskild firma) that number is the owner's personal identity number, and it is printed on the regulated price quotation certificate (bevis om prisuppgift) under TSFS 2013:41 — and second, routinely, in uploaded documents (e.g. copies of driving licences, identity documents and employment contracts) that the Controller itself chooses to upload and which the Processor therefore processes as file content. The Controller is responsible for ensuring that such processing is clearly justified in view of the purpose under Chapter 3, Section 10 of the Swedish Data Protection Act (2018:218).
- The Controller's end customers (passengers): name, phone number, email address and address details in booking requests.
- Per-trip location dataoccurs only if the Controller has enabled trip logging (off by default). Pickup and drop-off locations can then be recorded partly as free text entered by the driver and partly — if the driver grants location access in their browser — as an exact coordinate (latitude/longitude) read from the device's positioning service at the start and end of the individual trip. The service does not track vehicles continuously, has no taximeter or vehicle integration and is not a mileage log. Location access can always be declined by the driver, and a trip can be recorded without coordinates.
- The Controller's contract and invoicing customers (customer register): company details and contact persons' names, email addresses, phone numbers and address details, notes, customer agreements, price information, invoices and payment reminders. This data is stored until further notice and is not covered by the automatic scrub in Section 8, which applies to booking records only — it is deleted in accordance with Section 10.
- Payroll records: salary specifications with gross pay, deductions, preliminary tax and net pay.
- Internal communication: messages and attachments between users within the company.
- Special categories of personal data:absence records concerning sick leave and care of a sick child (VAB) constitute data concerning health within the meaning of Article 9(1) GDPR. The Controller is responsible for the legal basis under Article 9(2)(b) GDPR read with Chapter 3, Section 2 of the Swedish Data Protection Act (2018:218). The categories of data subjects also include the employee's children, to the extent VAB records are entered.
4. Instructions
The Processor processes personal data only on documented instructions from the Controller — primarily through the service's features — including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Swedish law. In such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Processor informs the Controller immediately if, in the Processor's view, an instruction infringes the GDPR or other Union or Swedish data protection provisions (e.g. Chapter 3, Section 10 or Chapter 5, Section 2 of the Swedish Data Protection Act (2018:218)). The Processor notifies the Controller of any binding request from a third-country authority for disclosure of personal data, to the extent legally permitted, and challenges such a request where it lacks a legal basis.
5. Confidentiality
Persons authorized to process the data are bound by confidentiality. Access is granted only to the extent required to provide and support the service. Every action a system administrator takes inside the Customer's account is recorded in the Customer's own audit log, as are the start and end of a support session in the account. A system administrator's reading of the platform overview itself — the organisation's name and registration number, subscription details, and members' names and email addresses — is not logged.
6. Security measures
- All traffic is encrypted (HTTPS/TLS); passwords are stored hashed.
- File storage is accessed only via time-limited signed URLs with server-generated, organization-prefixed keys.
- Multi-tenant isolation: all database access is scoped per organization.
- Role-based access control and audit logging of sensitive actions.
- Rate limiting on authentication and invitation flows.
- All regular processing takes place within the EU (see Sections 7 and 12).
- The database can be restored to any point within the last seven days (point-in-time restore at the database provider). The restore procedure is documented and rehearsed at least once a year and after every change of the database provider's plan. Uploaded files (receipts and documents) are not covered by point-in-time restore: a deleted file is gone, while the database record referring to it can be restored.
- The Processor evaluates the technical and organisational measures at least once a year (Art. 32(1)(d) GDPR).
7. Sub-processors
The Controller approves the sub-processors listed below. Where changes to sub-processors are planned, the Processor notifies the Controller in writing by email to the registered account holder at least 30 days in advance. Publication on this page does not replace that notification. The Controller has the right to object within 14 days of the notification. Where an objection cannot be accommodated, the Controller has the right to terminate the agreement with immediate effect, free of charge and with the right to an export under Section 10.
| Sub-processor | Service | Processing location | Transfer mechanism |
|---|---|---|---|
| Vercel Inc. | Hosting and operations | EU (Frankfurt, fra1) | EU processing; DPF/SCCs for any US access |
| Neon Inc. | Database | EU (Frankfurt) | EU processing; DPF/SCCs for any US access |
| Cloudflare Inc. (R2) | File storage (receipts, documents) | EU jurisdiction | EU processing; DPF/SCCs for any US access |
| Cloudflare Inc. (Turnstile) | Bot protection on the public booking form (visitor's IP address) | Cloudflare's global network (incl. USA) | EU-U.S. DPF and SCCs |
| Resend (Plus Five Five Inc.) | Transactional email | USA (email content and logs) | EU-U.S. DPF and SCCs |
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Subscription and payment (billing details, payment status). Takes effect when the billing function is activated — it is not in operation yet. | EU/Ireland; group access from the United States may occur | EU-U.S. DPF and SCCs |
| Functional Software Inc. (Sentry) | Error monitoring | EU (Sentry EU region); contracting entity Functional Software Inc., USA | EU processing; DPF/SCCs for any US access |
The Processor engages sub-processors only on condition that the Processor, by written contract, imposes on the sub-processor the same data protection obligations as set out in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organizational measures. Where a sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Controller for the performance of that sub-processor's obligations. The Processor makes the relevant contract terms available to the Controller on request (trade secrets may be redacted). Each sub-processor in turn engages its own sub-processors; current lists are maintained by each vendor and are provided on request.
When the paid service launches, a payment provider will be added (planned: Stripe); the list will be updated beforehand.
8. Assistance to the Controller
The Processor assists with technical and organizational measures for responding to data subject requests under Chapter III GDPR (including access, rectification, erasure, restriction of processing, objection and data portability) and with data protection impact assessments and supervisory authority contacts.
- Driver erasure is performed as pseudonymization:in small fleets, remaining shift data with registration numbers and timestamps is trivially re-identifiable, and financial records must be retained under the Controller's statutory archiving obligations. Identity data is removed or replaced; erasure of the financial records themselves falls under the exemption in Article 17(3)(b) GDPR. Timing is controlled by the Controller: immediate deactivation with identity scrubbing after a chosen delay (default 12 months), or immediate scrubbing.
- Passenger data in bookingsis scrubbed automatically 90 days after the booking's pickup time. The scrub applies to data in booking records. Data about contract and invoicing customers in the customer register is not covered by the scrub.
9. Personal data breaches
The Processor notifies the Controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach, providing the information required for the Controller's notification under Article 33 GDPR and, where applicable, for communication to data subjects under Article 34 GDPR.
10. Deletion and return at the end of the agreement
Upon termination the Controller chooses, no later than 30 days after termination, whether the personal data shall be (a) returned by way of a complete export (JSON, CSV and all uploaded files) and thereafter deleted, or (b) deleted without a prior export. Deletion is carried out within 30 days of the Customer's instruction, and no later than 90 days after termination if no instruction is given; a deletion requested in the service is executed after a 30-day grace period. Data is not deleted to the extent Union or Swedish law requires continued storage; in that case the Processor states which provision is relied on and limits the processing to the storage purpose alone. Section 8 concerns erasure during the term of the agreement. Archiving duties under Chapter 7 of the Swedish Bookkeeping Act (1999:1078) rest with the Controller, not the Processor; the export constitutes source material, and the Controller is itself responsible for thereafter preserving the accounting information in a durable and easily accessible form throughout the retention period. The Processor gives no undertaking that the export in itself satisfies the requirements of the Bookkeeping Act. A deletion certificate is provided on request.
11. Audits
The Processor makes available the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits conducted by the Controller or an auditor mandated by the Controller, with reasonable notice.
12. Third-country transfers
Regular processing takes place within the EU. There are two exceptions: transactional email via Resend, where email content and logs are stored in the United States, and the Cloudflare Turnstile bot protection on the public booking form, where the visitor's IP address is checked against Cloudflare's global network. Both rely on the EU-U.S. Data Privacy Framework and standard contractual clauses. Email content is deliberately kept data-light: no licence numbers, amounts or free text in notification emails. Booking confirmations sent to the passenger contain the recipient's email address, the taxi company's name and the time of the ride.
Annex: Receipts and accounting information
Following a legislative amendment in force since 1 July 2024, accounting information in paper form may be destroyed once it has been transferred to electronic form. The preservation duty in Chapter 7, Section 2 of the Swedish Bookkeeping Act (1999:1078) nevertheless applies unchanged: the information must be preserved in a durable and easily accessible form until the end of the seventh year after the end of the calendar year in which the financial year ended. Uploaded receipt files are stored within the EU (Cloudflare R2, EU jurisdiction), and the end-of-agreement export includes all receipt files. Manecab is not an archive for accounting information and should not be used as the sole place of preservation — data is deleted in accordance with Section 10 after the agreement ends. The Controller is responsible for continuously securing its own copies. The Processor gives no advice on the application of the Bookkeeping Act; check with your accounting consultant before destroying paper source documents. Questions: kontakt@manecab.se.