Privacy Policy

Last Updated: 2026-09-25

This Privacy Policy describes how Triptomatic BV ('we', 'us', or 'our') collects, uses, and shares your personal information when you visit our websites or when your organisation uses the Triptomatic and Booqit platforms and the mobile app.

Who we are

Triptomatic BV, Ganzenkoor 8, 2570 Duffel, Belgium, enterprise number BE 0739.577.785, operates the websites triptomatic.com and booqit.be and the Triptomatic and Booqit platforms.

Booqit is a product of Triptomatic BV.

For questions about this Privacy Policy or about your data, contact our Data Protection Officer at dpo@triptomatic.com.

Our websites: what we collect, why, on what legal basis, for how long

On our websites, Triptomatic BV is the controller. We collect information that you provide directly to us, for example when you contact us through our website or request a demo. We use this information to respond to your inquiries, provide you with information about our services and improve our website and services. The table below lists what we collect, why, on what legal basis and for how long.

PurposeDataLegal basisRetention
Responding to inquiries and demo requestsContact details and message contentSteps prior to a contract and our legitimate interest in responding2 years after the last contact
B2B prospecting: individual outreach to relevant professional contacts at organisations that may need our servicesBusiness contact details (name, function, organisation, professional e-mail)Legitimate interest in making our services known to relevant professional contacts; you may object at any time2 years after the last contact, or immediately upon objection
Customer relationship, support and invoicingName, business contact details, support communications, invoicing data of customer contactsPerformance of the contract and legal obligations (accounting)Duration of the relationship plus 5 years; accounting data for the statutory period
RecruitmentCV, contact details, interview notesSteps prior to an employment contract1 year after the end of the procedure
Website operation and securityEssential cookies and technical logsLegitimate interest in a secure and working websiteSession, or the retention period of the related logs

Where we do not receive your details directly from you for prospecting – for example, a referral from an existing customer or details published on your employer's website – we obtain them from that source.

Cookies

We use only essential cookies on our website:

  • NEXT_LOCALE: This cookie is used to remember your language preference for the website.
  • _GRECAPTCHA: Set by Google reCAPTCHA Enterprise on our contact page to protect the contact form against spam and abuse. Google may set cookies or read similar identifiers for this purpose; this is strictly necessary to keep the form secure.

The Triptomatic and Booqit platforms and the mobile app

The Triptomatic and Booqit platforms are used by hospitals, care facilities, transport companies and other organisations to book, dispatch, execute, invoice and report on (medical) transports. Data entered in the platforms about patients, passengers, requesters, drivers and staff is processed by Triptomatic BV as processor, on the instructions of the customer organisation, which is the controller, under a data processing agreement.

If you want to exercise your rights on data in the platforms, contact the organisation that arranged your transport or gave you access. We assist that organisation.

Mobile App

Our mobile app is used by drivers, assistants and dispatchers to operate transport shifts on behalf of their employer (the customer organisation). The categories below summarise the data the app accesses or collects, and why.

Account and identity

Email address, profile (name, role, organisation, language) and authentication tokens — to sign you in securely and link you to your employer's account.

Location (precise, foreground and background)

Precise GPS coordinates collected only while a work shift is active, including in the background — to record the shift route, dispatch trips and provide proof-of-service. Tracking stops automatically when the shift ends.

Camera and photos

Pictures from the camera or photo library, scanned document barcodes and on-screen signatures — only when you choose to attach a document or sign a trip sheet.

Device and technical information

Device brand and model, operating system, app version and push notification token — to deliver notifications, inform you about app updates and support troubleshooting.

Diagnostic and crash data

Crash reports, error stack traces and technical logs (via Firebase Crashlytics) — to detect and fix bugs, crashes and stability issues.

Work activity data

Selected vehicle and crew, shift information, mileage, trip-sheet entries, attached images and signatures, and trip/passenger information needed to execute the transports assigned to you.

Data stored on your device

Authentication tokens, push token, app preferences, cached trip data and draft trip-sheet entries are stored in encrypted local storage. They are removed when you sign out or uninstall the app.

Sharing of mobile app data

App data is shared only with parties strictly needed to operate the service: your employer (the customer organisation), Google / Firebase (push notifications and crash diagnostics), and your device's operating system for biometric / passkey sign-in. Navigation apps and the phone dialer only receive data when you explicitly tap to use them. We do not sell your personal data and do not use it for advertising.

Data the app does not collect

The app does not access your microphone, contacts, calendar, SMS or health/fitness data. It does not track motion or activity sensors, does not read the advertising identifier, and does not use third-party analytics or behavioural tracking.

Retention of platform data

Retention of platform data follows the data processing agreement with the customer organisation: 5 years from the last use of a record, plus up to 12 months in backups.

Service providers and transfers

We do not sell your personal information. We share it only with the service providers below, who assist in operating our website, and with legal authorities when required by law. All providers act under a data processing agreement. We will not transfer your personal data to countries outside the European Economic Area, except to the extent an adequate level of protection is ensured, in particular through the European Commission's Standard Contractual Clauses or, where applicable, a provider's certification under the EU-US Data Privacy Framework.

  • Google Cloud Platform: Provides hosting services for our website (Cloud Run), in region europe-west1 (Belgium)
  • Google reCAPTCHA Enterprise: Protects our contact form against spam and abuse
  • Resend: Handles email communications from our contact form

How we protect your data

We apply appropriate technical and organisational measures to protect your personal data, including encryption of data in transit and at rest, access controls limited to staff who need the data for their role, and regular monitoring and testing of our systems. Our core infrastructure runs on Google Cloud Platform and Microsoft Azure, hosted in the European Economic Area; our sub-processors are bound by data processing agreements and hold ISO/IEC 27001 or SOC 2 certification, or an equivalent standard.

Your rights and complaints

Under GDPR, for data where Triptomatic BV is the controller, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Request restriction of processing
  • Object to data processing
  • Receive your data in a portable format

Where we contact you for prospecting purposes, you may object to this at any time and free of charge, without needing to give a reason, by writing to dpo@triptomatic.com; we will then no longer contact you for this purpose.

Send your request to our Data Protection Officer at dpo@triptomatic.com.

You also have the right to lodge a complaint with the supervisory authority: Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels, www.gegevensbeschermingsautoriteit.be.

For data in the Triptomatic and Booqit platforms or the mobile app, contact the organisation that arranged your transport or gave you access.

Changes to this notice

We may update this Privacy Policy from time to time. We will post the new version on this page and update the 'Last Updated' date above.

If you have any questions about this Privacy Policy, please contact us at dpo@triptomatic.com.

Start using Triptomatic today

Privacy Policy - Triptomatic