DispHub / Legal documents
Privacy Policy
How the DispHub website handles visitor information, transport company contacts and demonstration requests.
Scope and responsible party
This policy concerns the DispHub marketing website, business enquiries and demonstration requests. The responsible party’s legal name, registration details, address and email must be entered in the effective version before the form is launched. This policy also covers enquiries from potential investors.
Passenger and driver data, location information and trip records in the operational platform require separate allocation of the transport company’s and provider’s roles, a data processing agreement and notices in the relevant applications. This page does not replace those documents.
Information in a request
The form requires a name, email, country, city and business stage. Optional fields include phone, company, fleet size, area of interest and a message. Existing services may also provide order volume and current software. The separate investor form requires a name, email address and message; the language, time and acknowledgement of the policy version are also recorded.
Do not enter card details, passwords, identity documents or passenger and driver personal data in the message. They are not needed for a demonstration. The selected language and acknowledgements of the documents may also be recorded with the request.
Purposes and legal basis
Request details are used to respond, arrange a demonstration, understand the service’s needs and prepare a proposal. Where the GDPR applies, steps requested by an individual before entering a contract may rely on Article 6(1)(b), while communication with a company representative may rely on the legitimate interest in answering business enquiries under Article 6(1)(f). The appropriate basis must match the actual process. Investor enquiry data is used to respond and discuss a possible partnership.
Submitting a request does not itself subscribe you to advertising or conclude a paid agreement. Acknowledging the policy is separate from optional marketing consent.
Request storage and access
Once intake is enabled, a request will be stored in a private WordPress area accessible to administrators. A notification to the configured email address will contain a link to the record. Access must be limited to people who need it to handle the enquiry.
Acknowledgement records will include time, language and document versions. Retention periods for enquiries, acknowledgements, backups and technical logs must be agreed and published before launch. This policy does not authorise storage without a defined purpose and retention period.
Technical information and form protection
Website hosting and email services may produce technical logs. The actual providers, processing countries, logged information and retention periods must be identified in the final version.
Form protection uses request verification, a hidden anti-bot field and repeated-attempt limits. A derived IP identifier is used for an hourly limit; the request record does not contain the raw IP address. This does not exclude separate hosting logs.
Recipients and international transfers
Necessary provider categories include website hosting, email delivery and technical maintenance. Their identities and processing locations must be checked before launch. Access must be limited to the service purpose and covered by appropriate contractual obligations.
Transfers to another country require the safeguards applicable under the relevant law. Specific mechanisms depend on the parties and processing locations; this draft does not represent them as already implemented.
Mailing lists and personalised advertising
Marketing mailings and personalised advertising are not enabled. They are not included in the required request acknowledgements. Introducing them requires a separate clear choice, recipient information and a way to withdraw consent.
Declining marketing must not prevent a business response to an enquiry. This website version does not use form data for advertising audiences or automated decisions with significant legal effects.
Rights and requests
Depending on applicable law, you may request access, correction, deletion, restriction or portability, object to processing and withdraw consent where consent is the basis. Legal retention obligations for particular records may prevent immediate deletion.
A working contact email and the responsible party’s details must be published before requests are collected. Where the GDPR applies, you may also complain to a competent data protection authority. Identity checks and responses must comply with applicable law.
Policy updates
The approved policy will carry a date and version identifier. Changes to processing purposes, recipients or optional tools must be reflected before use and communicated appropriately. Previous acknowledgement records retain a reference to the version applicable at that time.