Privacy policy
Draft of 2 October 2026 — to be read by an accountant and a lawyer; not yet in force.
This policy says what data FieldWake processes, why, who else receives it and how long it is kept. It covers the app at app.fieldwake.net, this site and mail sent to our addresses. It is a translation; the Bulgarian text binds.
1. Who is responsible for the data
„Парсинг“ ООД (Parsing Ltd), UIC 205338328, registered office Elite Lodge, Peshterite 6, Bansko 2770, Bulgaria — “Parsing” below. Questions and requests about personal data go to the address below. No data protection officer has been appointed.
2. Two roles
Parsing is the controller of the data about its customers and their users as such — the accounts, signing in, the invoices and payments — and of mail sent to our addresses.
For the fleet's data — where the vehicles and machines have been, who drove or operated them, the alerts, the fuel and the costs — the controller is the customer: the business that uses FieldWake. Parsing processes it on the customer's behalf, under the terms of service. A driver or operator who wants to know what is kept about them asks their employer; a request that reaches us is passed on to the customer.
3. What data
- About users: name, email, role, language and settings, the password — only as a hash — and when and from which IP address they signed in; for a failed sign-in, the email typed and the IP address.
- About the customer: the company's legal name, UIC, VAT number, registered address and invoice email; the invoices and payments — of the bank account, only its last four characters and the mandate's reference.
- About the fleet: the trackers, by IMEI; the vehicles and machines — names, plates, models; every position a tracker sends — time, place, speed, heading, ignition and the sensors' readings, fuel and CAN bus data included; the trips, stops and alerts made from them; the operators and drivers — their names, their reference (a payroll number, or whatever the business files them by) if one is entered, the ID of their card or key, and who drove or operated what and when; the working hours and the “Private” and “Business” marks with their reasons; fuel receipts, repairs and costs; the places, fields and zones users draw.
- The audit trail: who did what in the account, when, and from which IP address.
- Server logs: the app's web server records every request — the IP address, the page asked for and the browser — and the app's own log records, for every request, the IP address beside the account's number and role. They serve security and finding faults.
- Mail sent to our addresses: the sender and its content.
The fieldwake.net site collects nothing: there is no form, no analytics and no record of visitors.
4. Why, and on what basis
- To provide the service under the contract with the customer — the accounts, signing in, the map, the reports, the alerts and the emails about them (Article 6(1)(b) GDPR).
- To issue invoices and keep the accounts, as the law requires (Article 6(1)(c) GDPR).
- For the security of the service and a clear record of who changed what — the audit trail, the server logs and the error reports — on the basis of our legitimate interest (Article 6(1)(f) GDPR).
- The fleet's data — on the customer's behalf and on its basis, as a processor (Article 28 GDPR).
5. Who receives data
The data is processed on our server. These providers receive some of it as well — each only what is described beside it:
- netcup
- The server FieldWake runs on, in netcup's data centre in Nuremberg, Germany, under a data processing agreement. All the data above is stored there.
- Scaleway
- Backups: every night a full copy of the database is sent to Scaleway storage in Amsterdam, the Netherlands, where it is kept encrypted, with keys held by Scaleway.
- Brevo
- Sending FieldWake's emails — invitations, password resets, alerts, the daily digest, invoices and the payment emails: the recipient's address and the message itself. Brevo records whether a message is opened and routes the links in it through an address of its own to count clicks; on this account that cannot be switched off.
- Stripe
- Payments by SEPA Direct Debit. Our server sends Stripe the company's legal name, invoice email and FieldWake account number, and with every payment the amount, the invoice number and the account number again. In Stripe's form the owner enters the bank account, which only Stripe receives and keeps, and the page also passes Stripe the company's registered address. Stripe also sends the customer its own debit notifications.
- The map of a fleet that has chosen Google's map, and the search for places on it. The map's tiles pass through our server: Google sees its address and which area is being viewed, at what zoom, and for the credit line, the bounds of the part of the map in view. A place search sends Google the text typed and the centre of the map. No position, machine, user or account is sent, and a fleet on CARTO's map sends Google nothing. Mail sent to our addresses arrives in a mailbox at Google's Gmail.
- Esri
- Satellite imagery, while somebody has it switched on: our server asks Esri for the tiles of the area being viewed, at its zoom — and nothing else.
- CARTO
- The default map: its style, tiles and the fonts of its labels are loaded by the user's browser straight from CARTO's servers, which see its IP address and which area is being viewed, at what zoom. With Google's map the browser loads only the labels' fonts from CARTO, which carry no place.
- Copernicus
- Crop health: for each field, our server sends the European Union's Copernicus Data Space Ecosystem the field's outline and the dates it is looking for a satellite picture of — without the field's name and without the account.
- Open-Meteo
- The spray window: our server asks Open-Meteo for the forecast at the middle of each field, rounded to about a kilometre, at most once an hour — with no field, machine or account.
- VIES
- Checking a VAT number: with every invoice for a business in another EU member state, our server sends the European Commission's VIES system the customer's VAT number and Parsing's own.
- Sentry
- Error reports: when the server or the app meets an error, Sentry receives its description, the page's address, the browser, and the account's number and role — no email, no name; after a failed place search, the text typed as well. Sentry keeps no IP addresses, and the data is in its EU region, in Germany.
- Cloudflare
- Our domains: Cloudflare answers the DNS queries for fieldwake.net and forwards the mail sent to our addresses, seeing its sender and content. Visits to the site and the app do not pass through Cloudflare.
- Parsing's accountant
- Every month: the invoices and the customers' details on them — legal name, UIC, VAT number, registered address and amounts.
- The partner who fitted the trackers
- Every month: a statement of what was paid for the trackers he fitted — the customer's legal name, the number and IMEIs of the trackers, the amounts and his share.
The trackers send their data to our server over the mobile network of their SIM card's operator.
6. Outside the European Economic Area
Stripe, Google, Esri, CARTO, Cloudflare and Sentry are US companies or have affiliates there, to whom data may be transferred. Such a transfer is made under the safeguards in their own terms — the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
7. How long it is kept
The detailed history of the vehicles and machines — every position their trackers send, and the trips, routes, driving events and alerts made from it — is kept for 13 months, and then deleted a whole day at a time. After that, one line per vehicle or machine per day is kept for as long as the account exists: how far it went, how long it moved and ran, the fuel it used, its top speed and its number of trips and stops — never where it was.
The record of which operator drove or operated which machine, and when, is also kept for as long as the account exists, so such a daily line beside it describes one driver's day. When the operator is erased, their name is taken off that record, and the day becomes the machine's alone again. Operators themselves are kept until erased on request.
Refuels and fuel receipts are kept with the account, as fuel records, and repairs and costs for as long as the account exists. The record of who did what in the account is kept for 24 months, and failed sign-ins for 90 days. Deletion is suspended for an account under a legal hold — during a dispute, for example, or when the law requires the data to be kept — and resumes when the hold is released.
Invoices, credit notes and payments are kept for at least 6 years — the tax and accounting periods.
A user is kept until erased on request; their name and email are then removed, and their actions in the audit trail stay under a pseudonym.
What is deleted from the database stays in the backups on the server for up to 35 days, and in the copies kept off it for up to 70 days, because their storage keeps earlier versions as well.
No period has been decided for the server logs yet; until it is, they are rotated automatically.
When a subscription ends, the data stays under the same periods; at the customer's written request it is deleted earlier, within one month.
8. Cookies and data in the browser
This site sets no cookie and loads no script.
The app sets no cookie of its own. In the browser's local storage it keeps the user's sign-in key, their email and role, the machines and fields they opened last, and their settings — language, theme, units, where the map was. Signing out deletes the key, the email and role, the machines and fields opened last, and where the map was.
On the page for setting up the SEPA mandate, the app loads Stripe's script from js.stripe.com — the one outside script in it. Against fraud, it sets two cookies on the app's own domain, __stripe_mid for a year and __stripe_sid for half an hour, and Stripe's form sets cookies of its own on the domains of Stripe and of hCaptcha, which Stripe uses against abuse.
9. Your rights
Anyone whose personal data we process may ask for access to it, for it to be corrected or erased, for its processing to be restricted, or to receive it in a machine-readable form, and may object to its processing (Articles 15–22 GDPR). Requests go to the address below and are answered within one month.
A complaint may be made to the Commission for Personal Data Protection:
10. Changes
The version of this policy in force is the one published at this address, with its date. A change that affects customers is emailed to them in advance.