Kocheras Business Privacy Policy

Last updated: 1 August 2026 Processor: The Kilite SL, tax ID B66873118, registered at C/ Modolell 29B, 08021 Barcelona, Spain. Contact: hello@kocheras.app.

This document applies to Kocheras Business. For household use there is the Kocheras Home privacy policy, which is different.

Who answers for what

There are two distinct roles here and it pays not to mix them up:

Who For what
Controller Your company Its employees' data: why it processes it, for how long, and informing them
Processor The Kilite SL Processing it only as your company tells us, and protecting it
Controller The Kilite SL The data of our relationship with you: who signed up, billing and support

The annex at the end is the data processing contract required by article 28 GDPR. It is accepted on signing up to Kocheras Business and forms part of the terms.

What data is in Kocheras Business

Data Whose What for
Name, email and phone Employees Identifying who books, and letting them reach each other
Profile photo Employees Recognising who the vehicle is being left with. Optional
That they declare their licence is valid, and its class Employees Warning if a vehicle needs a class they do not hold
Bookings, mileage and hours Employees The service
Expenses and receipts Employees Splitting and allocating cost
Incidents, with photo Employees Recording damage
Location on return Employees So the next person finds the vehicle
Ratings, if the company enables them Employees Internal reputation. Can be switched off
Who did what and when Employees The account's audit trail
Tax and billing details The company Charging and invoicing

We do not store ID card or driving licence numbers, nor any photo of the document. Of the licence, only what the person declares and its class.

There is no real-time tracking. Location is recorded at a single moment — on return — and nowhere else. Kocheras is not a system for monitoring people and is not going to be one.

What the company has to do

Two things, and they are the company's, not ours:

  1. Tell its employees their data is processed in Kocheras, what for and on what legal basis. Usually that will be the employment relationship and the legitimate interest of organising the company's assets.
  2. Decide what to switch on. Peer ratings, for instance, are optional: if the company thinks they are unnecessary, it turns them off in Settings.

Who it is shared with

Only with whoever is needed for the service to work, all under a processor contract:

Who What for Where
Supabase Database and storage European Union (Frankfurt)
ZeptoMail (Zoho) Sending email notices European Union
Stripe Charging and invoicing EU, with standard contractual clauses for the US
Firebase Cloud Messaging (Google) Mobile notifications USA, with standard clauses
The Help assistant's provider Generating the Help assistant's answers Stated here once the assistant is switched on
Google Analytics (Google Ireland Ltd.) Measuring anonymously how the public website is used, only if accepted EU, with transfer to the USA under standard contractual clauses
Metricool (Metricool SL) Measuring anonymously the public website's traffic, only if accepted European Union (Spain)

We do not sell data, there is no advertising and there is no profiling. There is no tracker inside the application.

The Help assistant

An employee who asks the assistant sends their question, and the account data that employee can see, to the model provider. This is processing on behalf of the Company as Controller, with the same obligations as the rest of the annex. Three things the Company should know:

How long it is kept

Guest loans

If a company car is lent to someone without a Kocheras account (a one-off external driver), we keep their name and email to record who had the vehicle and let them complete the return from a link, without creating an account. This data is automatically deleted after 18 months from the loan if that person doesn't create an account; they can request earlier deletion at hello@kocheras.app. The loan record may be kept in anonymised form as proof of the vehicle's use.

Employees' rights

An employee exercises their rights — access, rectification, erasure, objection, portability and restriction — with their company, which is the controller. If they write to us directly, we pass it to the company and tell them so, without deciding it ourselves.

From within the app, anyone can download everything we hold about them in one file.

If something goes unresolved, they can complain to the Spanish Data Protection Agency (aepd.es).


Annex · Data processing contract

Article 28 of Regulation (EU) 2016/679. Between the client company ("the Controller") and The Kilite SL ("the Processor").

1. Subject matter

The Processor processes personal data on the Controller's behalf for the sole purpose of providing Kocheras Business under the terms contracted.

2. What is processed

3. The Processor's obligations

  1. Process the data only on documented instructions from the Controller. These terms and normal use of the application are those instructions.
  2. Not use it for any purpose of its own, nor to train models, nor for advertising.
  3. Ensure that anyone with access is under a duty of confidentiality.
  4. Apply the security measures of article 32: encryption in transit and at rest, row-level access control in the database, access logging and backups.
  5. Not subcontract without authorisation. Current sub-processors are in the table above; if they change we give 30 days' notice and the Controller may object and terminate.
  6. Assist the Controller in meeting data subject rights, using the export and deletion features the application already has.
  7. Notify a breach without undue delay and within 24 hours at most of becoming aware of it, with whatever is known at that point, following an internal breach-notification procedure.
  8. Help the Controller with impact assessments, if it carries any out.
  9. On termination, at the Controller's choice, return or delete the data. By default it is deleted after 30 days. Anything a legal obligation requires is kept blocked.
  10. Make available to the Controller the information needed to demonstrate all of the above and allow audits, one a year with 30 days' notice, or any imposed by an authority.

4. Transfers outside the European Union

Data is hosted in the European Union. The only possible transfer is Stripe's, for payment, covered by standard contractual clauses. The Processor will make no other without informing the Controller.

5. Liability

Each party answers for its own infringements. The cap on liability agreed in the service terms applies to this annex too, except where data protection law declares otherwise.

↑ Arriba