Privacy Policy
Last updated: 25 August 2026 · Version 1.0
Scope of this policy
This Privacy Policy applies to the processing of personal data in the European Union, the European Economic Area and Brazil.
It explains how TAKSUR Unipessoal Lda. ("TAKSUR", "we" or "our") processes personal data through the website https://taksur.pt, the SaaS platform, the iOS and Android mobile applications when made available, the Marketplace, contact channels and related services.
1. Who we are
The Services are operated by:
TAKSUR Unipessoal Lda.NIF: 519576268Avenida do Atlântico, N.º 16, 2.011990-019 Parque das NaçõesLisbon, PortugalWebsite: https://taksur.ptPrivacy and legal matters: legal@taksur.ptIn this document, "TAKSUR", "we" or "our" means TAKSUR Unipessoal Lda. As of this date there is no named Data Protection Officer (DPO) or LGPD officer with a separate contact. Privacy requests must be sent to legal@taksur.pt.
TAKSUR provides a SaaS technology platform for mobility and fleet management, operations, drivers, vehicles, documentation, contracts, finance, Marketplace and connection to a partner network. TAKSUR acts as a technology platform and not as an insurer, rental company, carrier, fuel station, charging operator or direct provider of services performed by third-party partners.
2. Scope of this Policy
This Policy applies to personal data processed through:
- the TAKSUR public website;
- user accounts and authenticated areas;
- the SaaS fleet and operations platform;
- TAKSUR iOS and Android mobile applications, when made available (not yet officially launched in the stores as of this version);
- the Marketplace, including listings, contact requests, favourites, moderation and reports;
- contact, support and ticket forms;
- communications sent by TAKSUR;
- subscription, invoicing and payment processes;
- the driver referral programme, when used;
- integrations, APIs and digital services operated by TAKSUR or on its behalf.
This Policy does not apply to websites, applications, insurers, workshops, rental companies, service providers or other third-party platforms that may be accessed through TAKSUR. Those third parties may have their own policies and act as independent controllers.
3. Controller and processor
TAKSUR's role depends on the service and the specific purpose of the processing.
TAKSUR as controller
TAKSUR generally acts as controller when it determines the purposes and means of processing for its own activities, including:
- management of the website and TAKSUR accounts;
- management of commercial and customer relationships;
- administration of subscriptions, invoicing and payments;
- customer service and support;
- service communications and, where permitted, marketing;
- security, fraud prevention and platform protection;
- Marketplace management, moderation and handling of reports;
- the driver referral programme;
- improvement and maintenance of the services;
- compliance with legal obligations and defence of rights.
TAKSUR as processor or operator
When a customer company uses the platform to enter and manage data of its drivers, workers, collaborators, providers, customers or other data subjects, the customer company may determine the purposes and means of processing. In that situation the customer company will normally be the controller, and TAKSUR will act as processor or operator, processing data on behalf of and according to the customer's documented instructions.
This relationship will be governed, where applicable, by a data processing agreement (DPA). The DPA for customer companies that process data of drivers, workers, customers or other data subjects through TAKSUR is available on request at legal@taksur.pt. The DPA defines, among other elements, the subject-matter and duration of processing, nature and purpose, categories of data and data subjects, customer instructions, confidentiality, security, subprocessors, international transfers, incidents, assistance with rights, audits and deletion or return of data.
When TAKSUR acts as processor or operator, data subjects should as a rule exercise their rights with the customer company that is the controller. TAKSUR will provide reasonable assistance to the customer under applicable law and the DPA.
4. Categories of data subjects
Depending on how you interact with TAKSUR, this Policy may cover:
- website visitors;
- people who create or use an account;
- representatives, administrators, directors and employees of customer companies;
- drivers and mobility professionals;
- owners, users or persons responsible for vehicles;
- investors and commercial partners;
- suppliers and service providers;
- advertisers and Marketplace users;
- people who contact support or TAKSUR;
- people whose data are entered on the platform by a customer company.
Customer companies are responsible for adequately informing their workers, drivers and other data subjects when they enter their data on the platform, whenever that obligation applies to them.
5. Personal data we may process
We process only the data necessary for specific, legitimate and informed purposes. The concrete categories depend on the profile, the service and the features used.
5.1. Identification and contact data
We may process full name, username, email address, telephone number, country, city, professional or business address and communication preferences.
5.2. Account and authentication data
We may process login email, protected credentials, role or profile, account status, permissions, language preferences, account settings, authentication logs, email confirmation, password recovery, multi-factor authentication (TOTP app, email or SMS code) and security logs.
TAKSUR does not request or intend to store passwords in plain text. Credentials are processed through appropriate technical authentication and security mechanisms.
5.3. Professional and business profile
Depending on the option chosen at registration, we may process the user's professional or business category, including TVDE company, Driver, Investor, Insurance Broker, Rent-a-Car, Workshop, Commercial Partner, Equipment Supplier, Consultant or Other.
We may also process company name, business registration information, tax identification number, business address and contact, authorised representative, relationship with the company, role, permissions and data needed to manage the business account.
5.4. Identification and compliance documents
Where necessary to create, validate or manage an account, a company, a driver, a vehicle or a professional relationship, we may process documents provided by the user or the customer company, including:
- identity document;
- identification or representation documents of directors;
- official documents proving the existence of the company;
- driving licence;
- professional licence;
- TVDE licence;
- insurance policy or proof of insurance;
- contracts, certificates, authorisations and other necessary compliance documents.
These documents may contain name, photograph, signature, document number, issue and expiry dates, address, company data, vehicle data and other information on the document itself. They should be sent only when needed for the stated purpose and should not contain excessive or irrelevant information.
Validation of these documents is carried out by authorised people at TAKSUR (including the Master team) and, where applicable, by reviewers at the customer company. We do not use an external automatic validator for this purpose.
5.5. Vehicle and fleet data
We may process registration plate, vehicle identification, vehicle type, documents, insurance, inspection, maintenance, costs, mileage, operational status, availability, assignment to a driver, contracts and other fleet-management records. Where these data allow a natural person to be identified directly or indirectly, they will be processed as personal data.
5.6. Driver and operations data
We may process professional and operational driver data, including identification, contact, driving licence, licences, TVDE licence, compliance documentation, contracts, internal payments, assigned vehicle, status of the relationship with the company, operational activity and service-related communications.
When the customer company uses these data for its own purposes, the customer company is responsible for ensuring the legal basis, transparency and the other requirements applicable to the processing.
5.7. Financial, subscription and invoicing data
We may process contracted plan, trial period, add-ons, subscription status, invoices, amounts, currency, billing address, transaction identifiers, payment status, refunds, payment references and type of payment method.
Platform and Marketplace subscription payments are processed by Stripe. TAKSUR does not store full card numbers. It stores only identifiers and the status of the transaction or subscription (for example Stripe customer and subscription identifiers).
Payment records for drivers and investors on the platform are internal management ledger entries. In this version they are not automatic bank transfers or payouts through Stripe Connect.
5.8. Marketplace and user content
We may process account data, business data, listings, photographs, descriptions, categories, favourites, contact requests (a form, not a continuous chat), reports, moderation responses and data relating to providers or partners.
Published content may be seen by other users according to the feature settings and rules. The user must ensure they have authorisation to publish data, photographs, names, brands or documents of third parties. This version does not provide Marketplace messaging chat or a reviews and ratings system.
5.9. Referral programme
When a driver uses the referral programme, we may process the referral code, the relationship between referrer and referred person, activation status and associated rewards, including the administrative status of reward payment.
5.10. Support and communications
When you contact TAKSUR, we may process name, email, telephone, company, message, attachments, account data, support request, ticket, response, request status, technical information and communication history.
5.11. Technical and usage data
We may process IP address, browser, operating system, device type, technical identifiers, application version, language, time zone, referral URLs, date and time of access, logs, errors, security events, features used, interactions, session data and performance information.
5.12. Location and GPS
Location or GPS will only be processed if a concrete feature uses them, if they are necessary for the stated purpose and if the user has granted the applicable device permission where required.
In the Android operations application, location (approximate and precise) may be used for driver presence and journey management, including coordinates, accuracy and timestamp. The iOS Copilot application, in this version, does not request GPS; it may request camera and photo library access for assisted reading of ride offers. On the website we use Google maps and geocoding services for addresses and, where applicable, freight tracking through a public tracking link. Refusing a permission may prevent features that depend on it.
5.13. Special categories of data
TAKSUR does not intend to request special categories of personal data, such as health, biometric, racial or ethnic origin, religious or political beliefs, sex life or trade-union membership data, except where there is a specific need, an adequate legal basis and authorisation permitted by applicable law.
Documents uploaded by the user or by a customer company may contain additional information or special categories of data. Users should avoid including unnecessary data. When the customer company determines the purpose of processing, it is for that company to assess the legal basis, necessity and measures applicable to those data.
6. How we obtain data
We may obtain data:
- directly from the user, at registration, in the profile, in forms or in support;
- from the customer company, fleet managers and authorised administrators;
- from drivers, representatives, partners and suppliers;
- from payment, authentication, maps or other integrated service providers;
- through use of the website, platform or application;
- through content published on the Marketplace;
- through the referral programme, when used;
- from public sources, where legally permitted.
Where data are not obtained directly from the data subject, the applicable information must be provided by the controller, by TAKSUR or by both, according to the context and applicable law.
7. Purposes of processing
We process personal data for the following purposes:
- to create, authenticate, administer and protect accounts;
- to confirm email addresses and allow access recovery;
- to personalise the experience according to the chosen profile;
- to provide and maintain the platform and contracted services;
- to manage companies, drivers, vehicles, documentation, contracts, operations and finance;
- to receive, organise, verify and make available compliance documents;
- to manage subscriptions, trial periods, invoicing and payments;
- to provide the Marketplace, listings, contact requests, favourites, reports and moderation;
- to operate the driver referral programme;
- to provide customer service, technical support and ticket management;
- to send service, security, authentication, invoicing and operational communications;
- to send commercial communications where legally permitted and, where necessary, with consent;
- to provide multi-factor authentication, when enabled;
- to prevent fraud, abuse, unauthorised access and unlawful use;
- to monitor, diagnose and improve security, performance, stability and usability;
- to make backups and recover data;
- to comply with legal, tax, accounting and regulatory obligations;
- to establish, exercise or defend rights in proceedings or claims;
- to manage relationships with partners, suppliers and providers;
- to analyse platform use in a proportionate way and, where possible, in aggregated or pseudonymised form;
- to pursue other compatible purposes informed at the time of collection or permitted by law.
8. Legal bases in the European Economic Area
Where the GDPR applies, we process personal data on one or more of the following legal bases:
- Performance of a contract or pre-contractual steps — creating an account, providing the platform, managing a subscription, providing support and performing requested features.
- Compliance with a legal obligation — invoicing, accounting, retention of mandatory records, responses to authorities and documentary compliance.
- Legitimate interest — security, fraud prevention, platform protection, business management, support, technical improvement and defence of rights, after balancing the rights of data subjects.
- Consent — non-essential cookies, marketing where required, certain device permissions, optional location and other situations that legally require it.
- Vital interest — exceptional situations where processing is necessary to protect vital interests, as legally permitted.
Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before that withdrawal.
When TAKSUR acts as processor, the legal basis for processing carried out on behalf of the customer company must be determined by the customer controller.
9. Legal bases and transparency in Brazil
Where the LGPD applies, TAKSUR will process personal data on the legal bases provided for in Brazilian law according to the concrete purpose, including performance of a contract, compliance with a legal or regulatory obligation, regular exercise of rights, credit protection, fraud prevention and security, legitimate interest where applicable and consent where necessary.
- Performance of a contract or pre-contractual steps — creating an account, providing the platform, managing a subscription, providing support and performing requested features.
- Compliance with a legal obligation — invoicing, accounting, retention of mandatory records, responses to authorities and documentary compliance.
- Legitimate interest — security, fraud prevention, platform protection, business management, support, technical improvement and defence of rights, after balancing the rights of data subjects.
- Consent — non-essential cookies, marketing where required, certain device permissions, optional location and other situations that legally require it.
- Vital interest — exceptional situations where processing is necessary to protect vital interests, as legally permitted.
The concrete legal basis may vary according to the service, the data subject, the origin of the data, TAKSUR's role and the customer company's instructions. Use of legitimate interest will be subject to necessity, proportionality and protection of the data subject's rights.
10. Sharing of personal data
We may share personal data, only where necessary and in accordance with applicable law, with:
- customer companies and authorised users;
- administrators, managers and authorised representatives;
- hosting, database, storage and infrastructure providers;
- authentication and security providers;
- payment and invoicing providers;
- email, SMS, notification and communication providers;
- support and ticket-management providers;
- maps and location providers, where applicable;
- Marketplace partners and providers, according to the requested interaction;
- professional advisers, auditors and insurers, where necessary;
- public authorities, regulators, courts and law-enforcement authorities, where legally required;
- acquirers, successors or entities involved in a reorganisation, merger or corporate transaction, subject to applicable safeguards.
TAKSUR does not sell personal data.
Marketplace partners and providers may process personal data as independent controllers when they determine their own purposes. The user should consult those third parties' policies before completing an interaction or transaction.
11. Processors and suppliers
TAKSUR uses specialised suppliers to operate the Services. As of this version, the main processors and suppliers relevant to personal-data processing are:
- Vercel — hosting, content delivery and execution of the website and web application;
- Supabase — authentication, database, file storage, realtime and server functions;
- Stripe — processing of platform and Marketplace subscription payments;
- Google Maps Platform — maps, geocoding and address search;
- Twilio — sending SMS for multi-factor authentication;
- SMTP mail service and authentication email infrastructure — transactional and account messages (including no-reply@taksur.pt).
Where a supplier processes data on behalf of TAKSUR, contractual obligations and appropriate measures will be adopted under applicable law. Suppliers should process data only according to authorised instructions, for defined purposes and with confidentiality and security measures.
12. International transfers
TAKSUR may use suppliers located outside Portugal, the European Economic Area or Brazil. Where this results in an international transfer of personal data, TAKSUR will adopt the legal mechanism appropriate to the concrete flow.
Under the GDPR, those mechanisms may include an adequacy decision, standard contractual clauses, applicable binding corporate rules or another safeguard recognised in Chapter V of the GDPR. Under the LGPD, transfers will be carried out in accordance with Brazilian law and applicable ANPD regulations.
In particular, web-application hosting on Vercel may involve processing in the United States of America. Stripe, Google and Twilio may also process data outside Portugal and the EEA, according to their respective policies and contractual clauses. Supabase processes data in cloud infrastructure, with any support access subject to applicable safeguards.
The data subject may request additional information about the countries or regions involved and the applicable safeguards, except for legal or security limitations, at legal@taksur.pt.
13. Cookies, local storage and similar technologies
TAKSUR may use cookies, local storage, session identifiers and similar technologies for:
- essential operation;
- authentication and session maintenance;
- security and fraud prevention;
- language and interface preferences;
- performance, diagnostics and stability.
Strictly necessary technologies may be used where indispensable to provide the service. Non-essential technologies, including usage analytics and marketing, will be used in accordance with applicable law and, where necessary, only after consent.
Use of a local identifier during onboarding, such as professional-profile selection, may be necessary to complete registration and maintain the user experience. The user may delete locally stored data through browser or device settings, although this may reset preferences or affect features.
The detailed inventory of cookies, suppliers, durations and opt-out mechanisms is described in the Cookie Policy at https://taksur.pt/cookies, which will be updated as the technical inventory is published.
14. Communications, email, SMS and notifications
We may send communications necessary to operate the account, including email confirmation, password recovery, multi-factor authentication, security, service changes, subscription, invoicing, payments, support and operational notifications.
Marketing communications will be sent only where permitted by applicable law and, where necessary, after prior consent. The user may withdraw consent or unsubscribe from commercial communications through the unsubscribe link or by contacting legal@taksur.pt.
Communications strictly necessary for security, authentication and account operation may continue to be sent even after marketing is cancelled.
If TAKSUR uses SMS, the telephone number will be processed for the corresponding purpose, including authentication, security, alerts or notifications. Mobile-operator charges may apply.
15. iOS and Android mobile applications
The TAKSUR iOS and Android mobile applications have not yet been officially launched in the respective stores as of this version. When they are made available, they will be covered by this Policy and may have complementary notices at the time of installation or use. This version does not publish store URLs or package identifiers.
The applications may process the account and platform data needed to provide the requested features. Any access to the camera, photographs, location, notifications or other device functions will depend on a concrete feature, the corresponding need and the operating-system permissions.
In the current preparation: the iOS application (TAKSUR Copilot) may request camera and photo library; the Android application may request location, camera, notifications and screen overlay for operational functions. TAKSUR will not request permissions unnecessary for the feature used. The user may manage or withdraw permissions in the device settings, without prejudice to the fact that withdrawal may limit features that depend on that permission.
The applications will be distributed through stores operated by third parties. Apple and Google may process data according to their own policies and terms. TAKSUR does not control processing carried out by the stores outside the services it provides.
16. Security
TAKSUR adopts technical and organisational measures that are reasonable and appropriate to the risk, the nature of the data and the purposes of processing. Those measures may include:
- access control by role and by organisation;
- segregation of accounts and data between companies;
- authentication and multi-factor authentication, when enabled;
- encryption in transit and, where applicable, at rest;
- protection of documents and private storage;
- temporary URLs or equivalent mechanisms for files;
- access, activity, audit and security logs;
- backups and recovery procedures;
- monitoring, vulnerability management and system updates;
- confidentiality obligations for authorised persons;
- incident-response procedures.
No system connected to the Internet can be guaranteed as completely secure. The user must keep credentials confidential, use secure devices and immediately report any unauthorised use.
17. Incidents and data breaches
TAKSUR will maintain procedures to identify, assess, contain, investigate and remedy security incidents that may involve personal data.
Where the law requires communication to an authority, to the data subject or to the customer controller, TAKSUR will make that communication within the applicable legal time limits, including, where the GDPR requires it, notification of the competent supervisory authority. When acting as processor or operator, it will notify the customer controller in accordance with the DPA and applicable law.
18. Retention of data
Personal data are retained for as long as the TAKSUR account and services remain active.
After cancellation or closure of the account, personal data must be retained for a period of up to 6 months.
After that period, the data must be deleted, anonymised or otherwise securely disposed of, as applicable.
Certain data may be retained for a longer period where that is necessary or permitted by applicable law, in particular to comply with legal, tax, accounting or regulatory obligations, for fraud prevention, security, dispute resolution, or to establish, exercise or defend rights.
19. Rights of data subjects in the European Union
Where the GDPR applies, the data subject may, under the terms and limits of the law:
- request confirmation of processing and access to the data;
- ask for inaccurate or incomplete data to be corrected;
- request erasure of the data;
- ask for restriction of processing;
- object to processing based on legitimate interest or to direct marketing;
- request portability, where applicable;
- withdraw consent at any time, where processing is based on consent;
- not be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects, except for legal exceptions;
- lodge a complaint with the competent supervisory authority.
Exercise of a right may be subject to conditions, exceptions and limitations provided for by law. Erasure, for example, may be refused where retention is necessary to comply with a legal obligation or to exercise and defend rights.
In Portugal, the supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD). The data subject may also contact the supervisory authority of the EU country where they reside, work or consider that a breach occurred.
20. Rights of data subjects in Brazil
Where the LGPD applies, the data subject may, under the terms and limits of the law, request:
- confirmation that processing exists;
- access to personal data;
- correction of incomplete, inaccurate or outdated data;
- anonymisation, blocking or deletion of unnecessary, excessive or unlawfully processed data;
- portability, subject to applicable regulations;
- deletion of data processed on the basis of consent, except for legal exceptions;
- information about public and private entities with which the data have been shared;
- information about the possibility of not providing consent and the consequences;
- revocation of consent;
- objection to processing in the cases provided for by law;
- review of decisions taken solely on the basis of automated processing, where applicable;
- a petition before the Autoridade Nacional de Proteção de Dados (ANPD), where applicable.
When TAKSUR processes data on behalf of a customer company that is the controller, the request may have to be submitted to that customer company. TAKSUR will cooperate under the contract and applicable law.
21. How to exercise rights or contact TAKSUR
Requests relating to privacy and personal data must be sent to legal@taksur.pt.
The request should, wherever possible, state the name, email associated with the account, nature of the request and sufficient information to allow it to be assessed. TAKSUR may request reasonable information to confirm identity and prevent improper access to personal data.
TAKSUR will respond within the time limits provided for by applicable law, including, where the GDPR applies, the one-month period, extendable as provided by law. Where the request concerns data processed on behalf of a customer company, TAKSUR may refer the data subject to that company or assist the controller customer.
22. Automated decisions and profiling
TAKSUR may use automated technical processes for security, fraud prevention, monitoring, network protection, diagnostics and service optimisation.
TAKSUR does not intend to take solely automated decisions that produce legal effects or similarly significant effects on natural persons, except where such processing is specifically informed, legally permitted and accompanied by the required safeguards. This version does not operate a risk-scoring system or automatic account suspension with that effect.
Selecting a professional profile at onboarding serves to configure the account experience and does not in itself constitute an automated decision with legal effect.
23. Children's data
The Services are intended primarily for companies, professionals, drivers, partners and persons with capacity to enter into applicable contracts. In line with the Terms and Conditions, the Services are intended for users who are at least 13 years of age. Users who are minors in the jurisdiction in which they reside must obtain the permission of their parents or legal representatives and use the Services under their supervision, where required by applicable law.
TAKSUR does not knowingly seek to collect data from children in situations prohibited by applicable law. If TAKSUR becomes aware that it has collected a child's data in circumstances where that was not permitted, it will take reasonable steps to delete or correct the processing, without prejudice to legal obligations.
24. Third-party links and services
The Services may contain links, integrations, advertisements, content or services provided by third parties. Those third parties may include application stores, payment providers, insurers, workshops, rental companies, transport companies, maps providers, technology partners and Marketplace providers.
Use of those services may be subject to the terms and policies of the respective third parties. TAKSUR is not responsible for the privacy practices of services it does not control.
25. Changes to this Policy
TAKSUR may update this Policy to reflect changes in the Services, new features, technologies, suppliers, processing, legal requirements or business operations.
Where a change is material, TAKSUR may provide additional notice, request new consent where necessary or apply any other mechanism required by applicable law.
The latest version will be available at https://taksur.pt/politicas. The update date indicated at the beginning of the document identifies the applicable version.
26. Applicable law
This Policy must be interpreted in accordance with the data-protection legislation applicable to the data subject and the concrete processing, including, where applicable, the EU General Data Protection Regulation, Portuguese data-protection law, the Brazilian General Personal Data Protection Law and ANPD regulations.
Application of a local law may confer additional rights or impose additional obligations that prevail over any general provision of this Policy.
