Goliv Technologies

Privacy policy

Data controller

The data controller is Goliv Technologies. For any personal data request, contact contact@golivtechnologies.com.

For accounts attached to an organization, that organization may act as controller for professional, operational, route, employee, contractor, customer, parcel, document and tracking data entered or managed under its workspace. Goliv Technologies acts as processor where it processes that data only to provide, secure and support the service according to documented instructions.

Goliv Technologies may act as an independent controller for account administration, billing, fraud prevention, security, legal compliance, product analytics, support and commercial communications where legally permitted.

Data collected

Goliv Technologies collects only the data required to operate, secure, support and improve the service.

  • Identification data: name, email, phone number, technical identifiers.
  • Professional data: company, team, role, access rights, invitations and memberships.
  • Operational data: routes, addresses, parcels, files, contracts, messages, statistics and histories useful to the service.
  • Technical data: device, application, IP address, logs, errors and security events.
  • Location data when the feature is enabled and necessary for delivery or tracking.

Purposes

Data is processed to provide Goliv Technologies, authenticate users, synchronize information, assist customers, secure access, comply with legal obligations and improve the service.

  • Account creation, authentication and service delivery.
  • Organization, roles, invitations and access rights.
  • Routes, addresses, parcels, deliveries, documents, messages and operational history.
  • Geolocation, tracking and proof of delivery where the relevant feature is enabled.
  • Payments, invoices, subscriptions, refunds, chargebacks and tax records.
  • Security, fraud prevention, abuse detection, diagnostics and logs.
  • Support, service communications and product improvement.
  • Audience measurement and anonymous traffic statistics where configured.

Legal bases

Depending on the context, processing is based on contract performance, the legitimate interest of Goliv Technologies, user consent or a legal obligation.

Recipients, service providers and sub-processors

Data may be accessible to authorized Goliv Technologies teams, to your organization when the account is attached to it, and to technical providers strictly necessary for the service.

Depending on the feature, providers may act as processors, sub-processors, independent controllers or a combination of these roles under their own terms. The current configured list is:

Stripe: Payments, subscriptions, invoicing, fraud prevention and connected accounts. Role: Processor and/or independent controller depending on the payment service. Processing locations: European Economic Area, United States and other locations covered by Stripe transfer safeguards - privacy information.
Google Firebase / Google Cloud: Authentication, application infrastructure, data synchronization and push notifications. Role: Processor and/or independent controller depending on the service. Processing locations: European Economic Area, United States and other locations covered by Google transfer safeguards - privacy information.
Google Maps Platform: Maps, addresses, geocoding, routing and location-based features. Role: Processor and/or independent controller depending on the service. Processing locations: Global - privacy information.
Apple: Sign in with Apple, App Store subscriptions and mobile platform services. Role: Independent controller and service provider depending on the feature. Processing locations: Global - privacy information.
Google Play: Google sign-in, Android distribution and subscriptions. Role: Independent controller and service provider depending on the feature. Processing locations: Global - privacy information.

Goliv Technologies requires processors and sub-processors to provide appropriate data protection commitments and remains responsible for its processor obligations. Where required, professional customers may object to a new sub-processor for legitimate data protection reasons after receiving notice.

Personal data is not sold.

Cookies, SDKs and audience measurement

Goliv Technologies and related websites may use cookies, SDKs, local storage, mobile identifiers, pixels or similar technologies for authentication, security, sessions, fraud prevention, preferences, payments, maps, notifications, diagnostics and analytics.

  • Strictly necessary technologies are used to provide and secure the requested service.
  • Preference technologies remember interface, language or account choices.
  • Analytics technologies measure audience, performance, errors and feature usage.
  • Marketing or advertising technologies are used only where enabled and legally permitted.

Where consent is required, non-essential technologies must not be activated before a valid choice. Users may refuse or withdraw consent through the consent interface when available and through browser, device or application settings.

The planned Matomo audience-measurement configuration is intended to use anonymized traffic data. Anonymization alone does not automatically remove all consent or information obligations; the production configuration must satisfy the applicable exemption criteria before analytics is enabled without consent.

To seek a consent exemption for audience measurement in France, the configuration must remain strictly limited to audience measurement for Goliv Technologies, produce anonymous statistics, prevent cross-checking and global cross-site or cross-application tracking, avoid unauthorized third-party reuse, and apply limited tracker and data-retention periods.

Location data

Location data is processed only where the relevant feature is enabled, permitted by device settings and necessary for routing, delivery tracking, proof of service, safety, fraud prevention, customer visibility or operational coordination.

Background location requires a clear notice and device-level permission where applicable. Disabling location may prevent some features from working correctly.

Organizations using location features for employees, contractors or drivers are responsible for informing them, defining lawful purposes, respecting employment rules and avoiding excessive monitoring.

Retention

Data is kept for the period necessary for processing purposes, then archived or deleted according to legal, contractual and security obligations.

  • Account data: for the account duration, then deletion or archival after closure.
  • Organization, operational delivery and access data: for the service duration and the limited period needed for proof, disputes, accounting and customer obligations.
  • Location data: only for the period necessary for tracking, proof, dispute, security or contractual needs.
  • Payment, invoice and tax data: for the legally required accounting and tax retention period.
  • Support data and security logs: for a limited period proportionate to support, security and fraud-prevention needs.
  • Audience-measurement data: for the configured limited analytics retention period.

Security

Goliv Technologies applies technical and organizational measures to protect data: access control, authentication, logging, backups and rights limitation.

Goliv Technologies will notify the relevant controller without undue delay after becoming aware of a personal data breach affecting customer-controlled personal data. The controller remains responsible for notifications to authorities and data subjects unless mandatory law imposes a direct obligation on Goliv Technologies.

International transfers

Personal data may be processed in the European Economic Area and, where necessary, in other countries by Goliv Technologies or its service providers.

Where required, transfers outside the European Economic Area, United Kingdom or Switzerland rely on an adequacy decision, standard contractual clauses, supplementary safeguards or another valid transfer mechanism.

Users may request more information about applicable transfer safeguards by contacting contact@golivtechnologies.com.

Customer instructions, assistance and end of service

When acting as processor, Goliv Technologies processes customer-controlled personal data only on documented instructions, including configuration choices, user actions, API calls, support requests and accepted contractual terms.

Goliv Technologies assists controllers, taking into account the nature of processing and available information, with data subject requests, security obligations, impact assessments and audits where required by applicable law.

At the end of the service, and subject to legal retention, backup, security and accounting obligations, customer-controlled personal data is deleted, anonymized or returned according to the service features and applicable agreement. Backup copies may remain for a limited period with restricted access.

Automated features and minors

Goliv Technologies may provide routing suggestions, status updates, alerts, scoring, fraud signals or operational recommendations. Unless expressly stated otherwise, these are decision-support features and do not produce legal or similarly significant effects without human review.

Goliv Technologies is not intended for children. Users must meet the minimum legal age required in their country or use the service under valid authorization.

User rights

You may request access, rectification, erasure, restriction, objection or portability of your data when these rights apply.

Requests must be sent to contact@golivtechnologies.com. Identity verification may be requested before processing.

Contact and complaint

For any question, contact contact@golivtechnologies.com. Data protection contact: contact@golivtechnologies.com. You may also contact the competent supervisory authority if you believe your rights are not respected.