In short
- This notice applies to the AVS Telematics apps (Android, iOS and web) and to the tracking platform behind them.
- We have two roles. For account, billing, security and support data, AVS is the controller. For vehicle and location data, the customer who owns the account is the controller, and AVS processes the data on the customer's behalf. A data processing agreement is available on request.
- We process account data, vehicle and tracker data (location history, speed, ignition, trips, device and SIM identifiers) and phone and app data (device model, operating system, app version, push notification token).
- Phone permissions, such as location and notifications, are optional. You grant them in your phone settings and can withdraw them at any time.
- While the subscription is active we keep your data. If it is not renewed, we keep the account and existing data for 90 days, then delete or anonymise them. We keep only what tax and accounting law requires.
- We do not sell personal data.
- You have rights under the General Data Protection Regulation (GDPR). Write to [email protected]. You can complain to the Hellenic Data Protection Authority (www.dpa.gr).
- If you are a driver or an employee, the owner of the account (for example your employer) is the controller of your vehicle and location data. Please contact them first.
Last updated: October 8, 2026
1. Who this notice is for and who we are
1.1 This notice applies to the AVS Telematics app for Android and iOS, the web app at avstelematics.app and the tracking platform behind them (together, the "Service"). It is for everyone whose personal data the Service processes: account holders, users added to an account (for example employees and drivers) and people who drive or use tracked vehicles.
1.2 The Service is provided by AUTONET VERITAS SERVICES AEBE, trading as AVS Telematics ("AVS", "we", "us"):
| Registered address | Eth. Antistaseos 174, Ag. Dimitrios, Attiki 17236, Greece |
| VAT ID | 099360608 |
| GEMI (General Commercial Registry) number | 085168202000 |
| Email for privacy questions | [email protected] |
| Phone | +30 210 975 0117 |
1.3 For our website, see the Website Privacy Policy. For the contract with our customers, see the Terms of Sale and Service.
2. Our role: controller or processor
2.1 Our role depends on the data:
| Data | Who decides why and how it is used | AVS role |
|---|---|---|
| Account data | AVS | Controller |
| Billing and contract data | AVS | Controller |
| Security and technical logs | AVS | Controller |
| Support and communication data | AVS | Controller |
| Phone and app data (technical data of the app on your phone, push notification token) | AVS | Controller |
| Vehicle and tracker data (positions, trips, speed, ignition, alerts, device and SIM identifiers) | The customer who owns the account | Processor, on behalf of the customer |
2.2 The customer decides which vehicles are tracked, who has access, which alert rules are used and which data is kept. The customer is the controller of vehicle and location data and is responsible for the lawfulness of the tracking (see section 10).
2.3 When we process data on behalf of a customer, we:
- process it only on the customer's documented instructions (the contract, the settings of the platform and written instructions);
- make sure that our staff and providers are bound to confidentiality;
- apply security measures (section 9);
- use other processors only under a contract that gives the same protection (categories in section 6);
- help the customer to answer requests from individuals and to deal with security incidents;
- delete or return the data at the end of the contract, as the customer instructs (section 8).
2.4 A data processing agreement under Article 28 GDPR is available on request at [email protected].
2.5 If you are a driver or an employee and the account holder is your employer, please contact your employer first about your vehicle and location data. We will help your employer to answer you.
3. The data we process
Which data we process depends on how the Service is used.
3.1 Account data (AVS is the controller)
- Name, email address and phone number (if provided).
- Login details (username and credentials).
- Role and permissions, language, and the organisation (domain) the account belongs to.
AVS creates accounts from the details that the customer gives us. There is no self-signup. On request, we add further users to an account.
3.2 Vehicle and tracker data (the customer is the controller, AVS is the processor)
- Position and movement: GPS position (coordinates), date and time, speed, altitude, direction (course), number of satellites, and the address looked up for a position.
- Route history and trips: the route of a vehicle for a date range, with trips (start, end, duration, distance).
- Vehicle status: ignition on or off, idling, the voltage of the tracker's battery. On trackers that read the OBD port: engine values such as coolant temperature, engine speed, vehicle speed, throttle position, intake air temperature, and, where the vehicle supports them, fuel level and odometer.
- Events and alerts: events such as speeding, ignition, idling, power cut or unplug, towing, crash, harsh driving or after-hours use, depending on the alert rules that the customer sets and on how the tracker is configured, and the alerts list.
- Identifiers: the tracker's identifier (for example IMEI or serial number), SIM identifiers (for example the SIM card number and the phone number of the SIM) and the connectivity status of the SIM.
- Labels the customer enters: for example vehicle names, registration numbers and driver names, if the customer enters them.
This data comes mainly from the trackers, automatically, and from the customer. Location data can show where a person is and when, and so can reveal habits. Please handle it with care (section 10).
3.3 Phone and app data (AVS is the controller)
- Device model, operating system and its version, and app version.
- A random install identifier that the app creates itself. It is not taken from your phone's hardware identifiers.
- The push notification token of your installation, if notifications are enabled (section 4).
- A sign-in token and settings, which the app keeps on your phone in the phone's secure storage.
If your account has driver features, the app also processes the reports you file, such as a field alert: your phone's position at that moment, with time, altitude, direction, speed, number of satellites, the type of alert and any text you add. If there is no connection when you file it, the app keeps the report on your phone, in its secure storage, and sends it when the connection returns. The report goes to your fleet. The customer is the controller of it.
3.4 Billing and contract data (AVS is the controller)
Name or company name, billing address, VAT ID and tax office, details of orders and plans, invoices and payment records (for example the reference of a bank transfer). Payment is by bank transfer, so we do not receive payment card numbers.
3.5 Support and communication data (AVS is the controller)
Messages, emails and notes of phone calls with us, the details of the problem you report, and the service emails we send you (for example renewal reminders, notices of planned maintenance and security notices).
3.6 Security and technical logs (AVS is the controller)
Records of sign-ins and access to the Service, such as date and time, IP address, and app or browser type, and the records we need to detect abuse and to find and fix errors.
4. Phone permissions
4.1 The app asks your phone for permission only for specific features. You decide whether to grant it, and you can change your decision in your phone settings at any time.
- Location. If you grant location access, the app can show your current position on the map and, if your account has driver features, add your position to a field alert that you file. The app uses your phone's location only while you use such a feature and the app is open. If you do not grant it, the rest of the app works, but position-based features are not available.
- Notifications. If you allow notifications, and if push notifications are enabled for your account, your phone gives the app a push token, which we store so that we can send you notifications. Notifications are delivered through Google Firebase Cloud Messaging (Android) or the Apple Push Notification service (iOS). If you do not allow notifications, you get no push notifications, and alerts remain visible in the app.
- Internet access. The app needs an internet connection to communicate with the platform. It may also check whether a connection is available.
4.2 The app does not ask for access to your contacts, photos, camera, microphone or files.
4.3 To withdraw a permission, use your phone settings. You can sign out of the app or uninstall it at any time. To have data held on our servers deleted, see sections 8 and 11.
5. Why we use data and on what legal basis
5.1 For the data where we are the controller:
| Purpose | Data | Legal basis |
|---|---|---|
| Create and run your account, sign you in, apply roles | Account data, phone and app data | Performance of our contract with the customer (Article 6(1)(b) GDPR). For users added by a customer: our legitimate interest in providing the Service to the customer's organisation (Article 6(1)(f)) |
| Send push notifications | Push token, phone and app data | Your consent, given by allowing notifications on your phone (Article 6(1)(a)) |
| Billing, invoicing, accounting and tax | Billing and contract data | Performance of the contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c)) |
| Service messages: renewal reminders, planned maintenance, security notices | Account data | Performance of the contract (Article 6(1)(b)) and our legitimate interest (Article 6(1)(f)) |
| Support | Support and account data | Performance of the contract (Article 6(1)(b)) and our legitimate interest (Article 6(1)(f)) |
| Security, preventing abuse, fixing errors | Security logs, account data, phone and app data | Our legitimate interest in the security and proper working of the Service (Article 6(1)(f)) |
| Legal claims and legal obligations | All data concerned | Legal obligation (Article 6(1)(c)) and our legitimate interest (Article 6(1)(f)) |
5.2 For vehicle and location data, we process the data to provide the tracking features (collect, store and show positions, trips, reports and alerts) on the customer's instructions. The customer is responsible for having a legal basis for the tracking.
5.3 We do not take decisions about you based solely on automated processing that have legal effects or similarly significantly affect you. Alerts come from rules that the customer builds, and the customer decides what to do with them.
6. Who receives data
6.1 We share data only with the categories of recipients below, where needed for the purposes above:
| Recipient | What they do | Data they may receive |
|---|---|---|
| Hosting and infrastructure providers | Run our servers, databases and backups | The data stored in the platform |
| Mobile connectivity provider | Provides the SIM and data connection of the trackers | SIM identifiers, connectivity and usage data, and the data the trackers send over its network |
| Map and address look-up providers (the app loads map images directly from the OpenStreetMap and OpenTopoMap servers) | Show maps and turn coordinates into addresses | The map area requested, the coordinates looked up and technical data such as the IP address |
| Push notification services (Google Firebase Cloud Messaging, Apple Push Notification service) | Deliver push notifications to phones | Push token, the content of the notification and technical data of the device |
| Email service providers | Send our emails, such as renewal reminders, maintenance notices and support replies | Name, email address and the content of the message |
| SMS gateway provider | Sends configuration commands by SMS to the SIM cards of the trackers | The phone number of the SIM and the text of the command |
| Professional advisers and banks (for example accountants, lawyers, banks) | Accounting, legal advice, bank transfers | Billing and contract data |
| Authorities and courts | Where the law requires | Only the data required |
| Other users of the same account | Use the Service for the same customer | The data their role allows them to see |
6.2 Providers that process data for us act under a contract and on our instructions. Where we act as a processor, these providers act as sub-processors, and we give customers an up-to-date list on request.
6.3 If our business is reorganised or transferred, data may pass to the successor, which must protect it as we do.
7. Transfers outside the European Economic Area
7.1 Some providers, for example Google and Apple for push notifications, may process data outside the European Economic Area, for example in the United States. Where this happens, we rely on the safeguards that the GDPR requires, such as an adequacy decision of the European Commission (for example for certified US companies under the EU-US Data Privacy Framework) or the standard contractual clauses. You can ask us about these safeguards at [email protected].
8. How long we keep data
8.1 In plain terms:
- While your subscription is active, we keep your account and your vehicle data in the platform, so that you can use route history, trips and reports.
- If your subscription is not renewed, it ends at the end date of the term, plus a short grace period that we state in the renewal reminder. After that, we pause your devices and no new data is recorded. We keep your account and the data already recorded for 90 days (the retention period), so that you can come back by renewing. At the end of the retention period, we delete or anonymise them.
- Billing and accounting records are kept for as long as tax and accounting law requires, also after your account is deleted.
- Support messages are kept as long as needed to handle the matter, and afterwards for a reasonable time in case we need to defend legal claims.
- Security logs are kept only as long as needed for security and troubleshooting.
- Push tokens are kept while your installation is registered. We remove them when they are no longer valid or when the account is deleted.
8.2 Where we act as a processor, the customer can instruct us to delete specific data earlier. At the end of the contract, we delete or return the customer's data as instructed, unless the law requires us to keep it.
8.3 Anonymised data is no longer personal data.
9. Security
9.1 We use technical and organisational measures that are appropriate to the risk. They include: role-based access, so that each user sees only what the role allows; encrypted connections (HTTPS) between the apps, the website and the platform; storing the sign-in token in the phone's secure storage; restricting access to our systems to authorised people and providers who are bound to confidentiality; and regular updates, with urgent security fixes applied immediately.
9.2 No system is completely secure. If a personal data breach affects you, we will tell the customer concerned without undue delay and, where we are the controller, we notify the authority and the individuals as the law requires.
10. What customers must do when they track drivers or employees
10.1 If you are a customer and you track drivers, employees or any other person, you are the controller of their vehicle and location data. Please make sure that you meet the following:
- Lawful basis. Have a legal basis under Article 6 GDPR, and respect Greek and EU rules, including Law 4624/2019 and employment law. Track only what is necessary and proportionate for a clear purpose, such as fleet management, safety or protection of property.
- Information. Tell drivers and employees clearly, before the tracking starts, that the vehicle is tracked: by whom, for which purposes, which data, who can see it, for how long it is kept and what their rights are. Do not track people secretly.
- Private use. Be careful with vehicles that people also use privately. The Hellenic Data Protection Authority has found in its decisions that tracking employees' vehicles is lawful only under conditions, such as necessity, proportionality and prior information, and that using location data outside working hours or for other purposes than those told to employees can be unlawful.
- Access and retention. Use roles so that only people who need the data can see it. Keep the data no longer than necessary, and ask us to delete data you no longer need.
- Rights. Answer the requests of drivers and employees about their data. We will help you.
- Assessment and consultation. Carry out a data protection impact assessment where the law requires it, and involve employee representatives where the law or a collective agreement requires it.
- Agreement. Sign the data processing agreement with us (section 2.4).
10.2 If you use the Service only for personal or household purposes, for example for your own car, these employer rules do not apply to you. Please still tell other people who drive the vehicle that it is tracked, and respect their privacy.
10.3 Please read section 13 of our Terms of Sale and Service as well. We may suspend the Service if it is used unlawfully.
11. Your rights and how to exercise them
11.1 Under the GDPR you have the right to: access your data and get a copy; have inaccurate data corrected; have your data erased, in the cases the law provides; restrict the processing; object to processing based on legitimate interests; receive the data you gave us in a structured, commonly used and machine-readable format (data portability), where it applies; and withdraw your consent at any time, without affecting the processing done before.
11.2 Data where we are the controller (sections 3.1 and 3.3 to 3.6): write to [email protected]. We may ask you to prove your identity. We reply within one month. In complex cases the law allows us to extend this period, and we will tell you. Exercising your rights is free of charge.
11.3 Vehicle and location data: the controller is the customer who owns the account, for example your employer. Please send your request to the customer. If you write to us, we will pass your request to the customer without undue delay and help the customer to answer.
11.4 You can withdraw consent to location or notifications in your phone settings at any time.
12. Complaints
12.1 If you think that your data is processed unlawfully, please contact us or the customer concerned first. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr), or with the supervisory authority of the country where you live or work.
13. We do not sell personal data
13.1 We do not sell personal data. We do not use vehicle and location data for advertising.
14. Children
14.1 The Service is meant for adults and businesses. To enter into a contract with us, you must be of legal age. We do not knowingly collect personal data directly from children. If a customer tracks a vehicle that a minor drives, for example a family car, the customer is responsible for this as the controller. If you believe that data of a child was given to us improperly, write to [email protected].
15. Changes to this notice
15.1 We may update this notice, for example when the Service changes. The date of the latest update is at the top of the page. If a change is significant, we will tell you in advance, by email, in the app or on the website.
16. Contact
- AUTONET VERITAS SERVICES AEBE, trading as AVS Telematics
- Eth. Antistaseos 174, Ag. Dimitrios, Attiki 17236, Greece
- Email: [email protected]
- Phone: +30 210 975 0117
For all privacy questions and requests, write to [email protected]. See also the Cookie Policy for the website.