1. Data Controller and Data Processor Roles
For most customer accounts, the customer organisation is the Data Controller because it decides why and how driver, employee, transporter, customer, shipment, cargo, expense, and document data is processed.
NIMRYX.AI / NimryxAi Technologies acts as a Data Processor or service provider when it processes data on behalf of the customer.
In some cases, NIMRYX.AI may act as an independent Data Controller for account administration, billing, platform security, fraud prevention, service improvement, legal compliance, and support operations.
2. Data We Collect
NIMRYX.AI may collect and process the following categories of data:
Account and User Data
- Name
- Email address
- Phone number
- WhatsApp number
- Company name
- Role and permissions
- Login activity
- Device and session information
- IP address
- Audit logs
Driver Data
- Driver name
- Driver phone number
- WhatsApp number
- Driver ID information, if provided
- Driver licence information, if provided
- Driver nationality, if provided
- Assigned trips
- Driver app activity
- Driver-submitted messages, documents, and expenses
Location and Movement Data
- Current live location
- Last known location
- GPS coordinates
- Road/highway name
- Speed, heading, and accuracy
- Origin arrival
- Origin departure
- Destination arrival
- Border, customs, port, checkpoint, and toll events
- Stop duration
- Route snapshots
- Movement timeline
- Ping count
- Device signal status
Vehicle and Transport Data
- Truck plate number
- Trailer number
- Container number
- Vehicle type
- Transporter name
- Vehicle documents
- Job assignment data
Shipment and Cargo Data
- Job number
- Origin and destination
- Pickup and delivery details
- Customer, shipper, consignee, and transporter information
- Cargo description
- HS code, quantity, weight, and package details
- Customs and border details
- Milestones and job status
Document and AI Data
- Uploaded documents
- Invoices
- Packing lists
- Bills of Entry
- Permits
- Receipts
- Proof of delivery
- Driver and vehicle documents
- AI-extracted fields
- AI classification results
- AI document naming results
Expense and Job Costing Data
- Fuel expenses
- Toll expenses
- Border fees
- Customs fees
- Port fees
- Parking expenses
- Driver allowance
- Loading/unloading charges
- Waiting/detention charges
- Repair/breakdown costs
- Fines and penalties
- Receipts and supporting files
- Approval status
- Billable/non-billable status
Communication Data
- Messages between office users, transporters, and drivers
- Attachments sent through chat
- System notifications
- Delivery/read status, where available
3. Purpose of Processing
NIMRYX.AI processes data for the following purposes:
- Creating and managing logistics jobs
- Assigning drivers, transporters, trucks, trailers, and containers
- Showing live driver/truck location during active trips
- Detecting arrival at origin and destination
- Detecting departure from origin
- Detecting border, customs, port, checkpoint, toll, and route events
- Building movement timelines
- Creating stop summaries instead of repeated duplicate events
- Calculating job costing and trip expenses
- Reading and classifying documents using AI/OCR
- Supporting customer shipment visibility
- Supporting proof of delivery and operational audit
- Enabling office, transporter, and driver communication
- Securing accounts and preventing unauthorised access
- Troubleshooting, support, and platform improvement
- Legal, tax, accounting, audit, and compliance purposes
4. Legal Basis for Processing
Depending on the country and user relationship, NIMRYX.AI and the customer organisation may rely on one or more of the following legal bases:
- Consent
- Performance of a contract
- Legitimate business interest
- Employment or contractor operational requirement
- Legal or regulatory obligation
- Safety, security, fraud prevention, or audit requirement
- Transport, customs, logistics, or commercial documentation requirement
Where consent is required, consent must be clear, specific, informed, recorded, and withdrawable.
5. Driver Location Consent
Before live or background location tracking is enabled, the driver must be shown a clear in-app disclosure.
The disclosure must explain:
- What location data is collected
- Why location data is collected
- When tracking starts
- When tracking stops
- Whether background location is used
- Who can see the location
- How long location data is kept
- How the driver can withdraw consent or contact support
- What features may not work if permission is declined
Location tracking must only be used for active logistics trips, assigned jobs, safety, operational visibility, arrival detection, route event detection, toll detection, and movement history.
Location tracking must not be used for personal surveillance outside active work/trip purposes.
6. Background Location Disclosure for Android/iOS
NIMRYX.AI may collect background location during an active trip so the office can monitor route progress, detect arrival at origin/destination, detect tolls, detect border/customs/port/checkpoint events, calculate stop duration, and update the live Control Tower.
Background location must be disabled when:
- The trip is completed
- The trip is cancelled
- The driver is unassigned
- The driver logs out
- The customer organisation disables tracking
- The driver withdraws permission, subject to applicable operational/legal requirements
The app must show a persistent foreground service notification on Android while active trip tracking is running.
7. Data Subject Rights
Subject to applicable law, users, drivers, and other individuals may request:
- Access to their personal data
- Information about why their data is processed
- Correction of inaccurate data
- Completion or updating of incomplete data
- Deletion/destruction of personal data
- Restriction or stopping of certain processing
- Withdrawal of consent
- Objection to direct marketing
- Objection to certain automated processing
- A copy of personal data in a readable format, where applicable
- Complaint handling and escalation
Requests can be submitted through:
- In-app privacy request form
- Email to nimryxai@outlook.com
- Company support portal
- Written request to NimryxAi Technologies
8. Deletion Upon Request
NIMRYX.AI supports deletion requests.
When a valid deletion request is received, NIMRYX.AI will delete, anonymise, or restrict the relevant personal data unless retention is required for:
- Legal obligation
- Tax or accounting obligation
- Transport documentation obligation
- Customs or border documentation obligation
- Contract performance
- Dispute resolution
- Fraud prevention
- Security investigation
- Audit trail preservation
- Court, regulatory, or government request
Where full deletion is not legally or operationally possible, NIMRYX.AI may restrict access, anonymise data, pseudonymise data, or retain only the minimum necessary records.
Examples:
- Raw GPS pings may be deleted or anonymised after the retention period.
- Live location should be overwritten during active trips and not kept forever.
- Movement events linked to job proof may be retained as part of job history.
- Accounting and expense records may be retained according to tax/accounting requirements.
- Customs and transport documents may be retained according to logistics/legal requirements.
- Audit logs may be retained for security and fraud prevention.
9. Consent Withdrawal
Where processing is based on consent, the individual may withdraw consent at any time.
Withdrawal of consent does not affect processing that happened before withdrawal.
After withdrawal, NIMRYX.AI will stop consent-based processing unless another legal basis applies.
For driver location tracking, withdrawal may disable:
- Live tracking
- Automatic reached-origin detection
- Automatic reached-destination detection
- Toll detection
- Movement events
- Route snapshots
- Customer live shipment visibility
The app must clearly explain the operational impact before disabling tracking.
10. Retention Schedule
Suggested default retention rules:
Live Location
- Store only the latest live location per active job.
- Update using UPSERT.
- Do not permanently insert every GPS ping.
Raw GPS Pings
- Avoid storing raw pings unless needed.
- If stored, retain for 30 to 90 days only.
- Delete or anonymise after retention period.
Movement Events
- Retain as part of job history.
- Keep important events such as origin reached, destination reached, toll crossed, border reached, customs reached, port reached, checkpoint crossed, and long stops.
Stop Sessions
- Store one stop session per location.
- Update first_seen_at, last_seen_at, duration, and ping_count.
- Do not create repeated “vehicle stopped” events.
Documents
- Retain according to customer policy, customs requirements, legal requirements, and contract requirements.
Expenses and Job Costing
- Retain according to accounting, tax, customer, and audit requirements.
Messages
- Retain according to customer policy and operational/legal needs.
Audit Logs
- Retain for security, fraud prevention, and dispute investigation.
11. Security Measures
NIMRYX.AI must implement appropriate technical and organisational security controls, including:
- Encryption in transit
- Encryption at rest where supported
- Tenant isolation
- Role-based access control
- Least privilege access
- MFA for office/admin users where possible
- Strong password/session controls
- Audit logs for sensitive actions
- Access logs for document viewing/downloading
- API authentication and rate limiting
- Secure file upload validation
- Malware scanning where possible
- Secure backups
- Secret/API key management
- Database row-level security where possible
- Secure deletion/anonymisation workflow
- Periodic security review
- Incident response process
12. Cross-Border Data Transfers
NIMRYX.AI may use cloud, database, AI, messaging, geocoding, email, analytics, and support providers located outside the GCC or outside the customer’s country.
Before transferring personal data across borders, NIMRYX.AI should:
- Identify the country where data is stored or processed
- Identify subprocessors
- Use contracts with data protection obligations
- Use adequate safeguards where required
- Limit transferred data to what is necessary
- Inform customers and users in the privacy policy
- Obtain consent or other lawful basis where required
- Maintain a subprocessor list
13. Subprocessors and Vendors
NIMRYX.AI may use third-party providers for:
- Cloud hosting
- Database hosting
- File storage
- AI/OCR processing
- Maps and geocoding
- WhatsApp/SMS messaging
- Email
- Push notifications
- Analytics
- Support and error monitoring
- Payment/billing if applicable
Each vendor should be reviewed for:
- Data location
- Security controls
- Privacy terms
- Data processing agreement
- Deletion support
- Breach notification obligations
- Access controls
- Audit availability
14. AI Governance
NIMRYX.AI may use AI to extract, classify, rename, summarise, and structure documents.
AI output must be treated as assistance only.
Users must verify AI output before using it for:
- Customs
- Border clearance
- Invoicing
- Tax
- Legal decisions
- Customer billing
- Driver reimbursement
- Compliance reporting
NIMRYX.AI should keep an audit trail showing:
- Original document
- AI-extracted fields
- Confidence score
- Manual edits
- User who approved the extracted data
- Time of approval
AI should not make final legal, customs, financial, or disciplinary decisions without human review.
15. Job Costing and Toll Data
Auto-detected tolls, fuel expenses, border costs, customs costs, port costs, and route expenses are operational estimates unless approved by an authorised user.
The system must show:
- Source of expense
- Auto/manual status
- Currency
- Country
- Receipt if available
- Approval status
- Billable/non-billable status
- User who approved or edited the expense
Do not automatically bill customers based only on AI or GPS detection without office approval.
16. Breach and Incident Response
NIMRYX.AI must maintain an incident response process for:
- Unauthorised access
- Data leak
- Wrong tenant access
- Lost/stolen credentials
- Cloud/storage exposure
- Misconfigured database
- Unauthorised document access
- Location data exposure
- AI/vendor data leak
The incident process should include:
- Detection
- Containment
- Investigation
- Internal escalation
- Customer notification where required
- Authority notification where required
- User notification where required
- Corrective action
- Evidence preservation
- Post-incident review
17. Privacy by Design
NIMRYX.AI should follow privacy-by-design principles:
- Collect only necessary data
- Use live location upsert instead of storing every ping
- Hide raw logs by default
- Use stop sessions instead of repeated stopped events
- Use access roles for office, transporter, driver, admin, and customer
- Show only required data to each role
- Mask sensitive IDs where possible
- Keep raw GPS only for limited time
- Keep audit logs for accountability
- Provide privacy settings and deletion request workflow
- Maintain data maps and retention rules
18. Driver Consent Text
Shown in the Android/iOS driver app before asking for location permission:
NIMRYX.AI collects your location during active assigned trips to help your company manage transport operations.
Your location may be used to:
- Show your current truck location to authorised office users
- Confirm when you reach pickup/origin
- Confirm when you leave pickup/origin
- Confirm when you reach destination
- Detect route events such as tolls, checkpoints, ports, borders, and customs areas
- Create trip movement history
- Calculate stop duration and route progress
- Support job costing and trip expenses
When a trip is active, NIMRYX.AI may collect location in the background so the office can receive accurate movement updates even if the app is not open.
NIMRYX.AI does not use your location for advertising.
You may decline or withdraw location permission, but live tracking, automatic arrival detection, route events, and customer shipment visibility may not work.
I Agree
Decline
19. Delete My Data Request
Shown in the app and website:
You may request access, correction, deletion, restriction, or withdrawal of consent for your personal data.
To submit a request, contact:
- Privacy Email: nimryxai@outlook.com
- Support Email: nimryxai@outlook.com
- Company: NimryxAi Technologies
We will review your request and respond according to applicable law.
Some data may not be deleted immediately if it is required for legal, customs, tax, accounting, security, audit, contract, dispute, or regulatory purposes. Where deletion is not possible, we may restrict, anonymise, or retain only the minimum required data.