Privacy policy
Last updated: 2026-09-13
This policy explains which personal data we process in the TahoRis service, on what legal basis, and for how long we keep it. Processing follows the General Data Protection Regulation (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).
Controller
The controller is the company named below. For any question about the processing of personal data, contact us at the email address given.
DAVID MARN, razvoj sodobnih tehnologij, d.o.o.
Maistrova ulica 13
2000 Maribor, Slovenija
- Registration number
- 9740384000
- VAT number
- SI38419386
- Share capital
- 7.500,00 EUR
- Registration authority
- Okrožno sodišče v Mariboru
What we process
- Account data: your identifier (the OIDC subject), email address and name as supplied by the Charon sign-in provider, the time you signed up and the time you were last seen.
- The contents of uploaded .ddd files: data from a driver card or vehicle unit, including the driver's name, card number, minute-by-minute activity, distance driven and vehicle identification. This data concerns drivers who are typically employed by the user of the service.
- Technical data: the session cookie, the chosen language, and access logs needed to operate and secure the service.
Roles: controller and processor
For your account data we act as the controller. For the contents of uploaded .ddd files, which concern your drivers, we act as a processor and you, as the employer, are the controller: you determine the purpose and legal basis for processing your drivers' data and are responsible for informing them.
Purposes and legal basis
- Performance of a contract (Article 6(1)(b) GDPR): providing the working-time analysis, storing uploaded files and producing exports.
- Compliance with a legal obligation (Article 6(1)(c) GDPR): retention of original files to the extent required by article 3 of the Slovenian rules on transferring working-time data from recording equipment (PRAV7249).
- Legitimate interest (Article 6(1)(f) GDPR): service security, abuse prevention and keeping an audit trail of administrator access.
Retention
Original .ddd files and the records derived from them are kept until you delete them or until your account ends. Note that article 3 of PRAV7249 requires an employer to keep original files for two years; meeting that duty is your responsibility. Account data is kept for the life of the account and access logs for at most 12 months.
Sharing
We do not sell personal data and do not pass it to third parties for their own purposes. Data is processed on servers in the European Union. Sign-in uses the Charon service, which receives only what authentication requires. We do not transfer data outside the European Economic Area.
Security
Access is limited to the signed-in user: each user sees only their own files, drivers and vehicles. Connections are protected with TLS. Every administrator view of another user's data is written to an audit trail.
Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Send requests to the email address above. If you believe the processing breaches the rules, you may lodge a complaint with the Slovenian Information Commissioner, Dunajska cesta 22, 1000 Ljubljana (gp.ip@ip-rs.si).
Cookies
We use strictly necessary cookies only: a session cookie for sign-in and a cookie holding your chosen language. We use no analytics or advertising cookies, and therefore do not ask for consent.
← Back to the home page