Data processing
This page describes the data-protection relationship between your agency and Narix Technologies when you run RentivoFleet. It exists because most agreements of this kind assume the vendor holds the data — and here, ordinarily, we do not.
Last updated 5 September 2026
RentivoFleet is installed on a server you rent, under a domain you own. Your customers' names, licences, contracts and invoices are written to a database on that machine. We have no copy of it, no live connection to it, and no ability to read it from where we sit.
In data-protection terms your agency is the controller and, for the ordinary running of your platform, there is no processor. That is unusual enough to say plainly rather than bury.
Support access. If you ask us to investigate a problem on your installation, you grant us access to that server for that purpose. While we are in there we may see whatever the fault touches. Access is granted by you, used only for the task you described, and ends when the task does.
Migration. If we import your existing records into a new installation, we handle that data for as long as the import takes and delete our working copies afterwards.
Your own account. The details you gave us to become a customer — your agency name, the person we deal with, the email and phone we answer, the domain your platform runs on, and the invoices between us. That is our own record of a commercial relationship, and we are the controller of it.
We do not hold a copy of your operational database. We do not aggregate across agencies. We do not use anything on your installation to train anything, sell anything, or build a product on top of it.
We do not have standing access to your server. Where access exists it is because you configured it, and you can withdraw it without asking us.
When we act on your data we act on your instruction — the request you sent us — and on nothing else. If an instruction seems to conflict with the law that applies to you, we will say so rather than carry it out quietly.
Everyone who touches your data is bound to confidentiality. Today that is a small, named team, and we will tell you who rather than describe them as "authorised personnel".
For the ordinary running of your platform there are none, because we are not processing anything. The infrastructure your installation sits on is a contract between you and your hosting provider, not between you and us.
For our own record of you as a customer we use an email provider and an invoicing tool. If that list changes in a way that matters, we will tell you before it does.
Your operational data lives wherever you chose to put your server. Most of our customers run in Tunisia or the EU. That choice is yours, and it is the choice that determines which transfer rules apply to your customers' data — not anything we do.
Our record of you as a customer is held in Tunisia and in the EU.
What we ship: TLS on every hostname, secrets held outside the code, role-separated accounts, an audit trail on the actions that change money or contracts, and a documented backup and restore procedure that we test rather than assume.
What is yours: the server itself. Patching the operating system, controlling who has SSH access, and keeping backups somewhere other than the machine they came from are decisions you make. We give you the runbook and will walk it with you; we cannot make them for you.
If we become aware of a breach affecting data we were processing for you, we will tell you without undue delay and in any case within 48 hours of confirming it, with what we know at that point rather than a polished account a week later.
If the breach is on your server and we notice it during support, we will tell you the same day. Notifying your authority and your customers is yours to do — it is your controller obligation, and we will give you whatever detail helps you do it.
Working copies from a migration are deleted once the import is verified. Support access notes are kept only as long as the ticket is useful.
Your operational data is not ours to return or delete — it is on your machine. If you stop being a customer, nothing about your platform changes: the licence is perpetual and the server is yours.
You may ask us what we hold about you and how we handled a specific support access, and we will answer with specifics. For a formal audit of our own record-keeping, write to us and we will arrange it — we are a small company and would rather have the conversation than send a certificate.
If your legal team needs this as an executed document rather than a web page — and a serious procurement process usually does — write to contact@rentivofleet.com and we will send one for signature, adapted to how you actually use the platform.