GDPR statement & data-protection notice

Version: 2026-08-09 Effective date: 2026-08-09 Controller: E. zona, MB (trading as "FabiRide"), Tvirtovės al. 88, Kaunas, Lithuania Data-protection contact: info@fabiride.com

This page is a concise complement to our Privacy Policy at https://my.fabiride.com/legal/privacy, focused on GDPR-specific rights and processes.

Lawful bases for processing

Processing purpose Article 6(1) basis
Create + maintain your account, pair your Display (b) Contract
Record which version of the Terms + Privacy Policy you accepted, and when (c) Legal obligation + (f) legitimate interest — evidence of consent
Sign in with Apple (verify identity, create/link account) (b) Contract
Send transactional emails (verify, reset, ownership transfer) (b) Contract
Store invoice + sales-chain rows (c) Legal obligation (LT Accounting Law)
GPS recording + live location on the map during a trip (a) Consent — toggle on, anytime off
Crew voice chat (live microphone audio) (a) Consent — you join a room by choice
Now-playing cover-art lookup (track/artist text only) (a) Consent / (f) legitimate interest
Emergency-contact storage (a) Consent
Sending a crash-SOS SMS to your contacts (d) Vital interests + (a) consent
Marketing emails / push (a) Consent — opt-in at signup, opt-out anytime
Firmware / OTA updates, support (b) Contract + (f) legitimate interest
Anti-fraud, tamper + source-code-extraction detection (f) Legitimate interest — protecting our hardware and other riders
Crash reports + bug telemetry (f) Legitimate interest — improving reliability
Sync your bike settings + rider-access caps across your devices (b) Contract
Disclose to law enforcement on lawful request (c) Legal obligation

We do not perform automated decision-making with legal effects on you.

Shared bikes — who controls what

Where a bike is shared, the owner decides what limits a rider gets and can see that rider's ride data, GPS trail and live location. For that monitoring the owner is the controller and FabiRide is the processor; the owner is responsible for having a lawful basis and for telling the rider before they ride. See §3 of the Privacy Policy and §15.3 of the Terms.

Your rights — how to exercise them

Right How
Access — copy of all your data In-app: Settings → My account → Export my data (JSON download). Or email info@fabiride.com.
Rectification — fix what's wrong In-app: Settings → My account → Edit. For data you can't edit (sales/invoice rows), email us.
Erasure — delete account In-app: Settings → My account → Delete account, or https://my.fabiride.com/legal/delete-account. We anonymise sales/invoice rows we must keep by law.
Restriction — pause processing Email info@fabiride.com with the reason; we acknowledge within 7 days.
Portability — machine-readable export Same as Access — the JSON export is portable.
Object — refuse processing on §6(1)(f) bases Email info@fabiride.com.
Withdraw consent In-app toggles for GPS / Voice / Marketing / Push.
Complaint LT data-protection authority: https://vdai.lrv.lt; or your country's DPA.

Response time: 30 days, extendable to 90 days for complex requests (with notice).

Sub-processors

We share the minimum data needed with the following sub-processors, each under a GDPR-compliant DPA. The canonical, current list is at https://my.fabiride.com/legal/subprocessors.

Vendor Purpose Region Personal data shared
Application hosting (EU VPS) App server + database hosting EU All app data
SMTP email-delivery provider Transactional email EU Email address + email body
LiveKit (self-hosted) Crew voice-chat media relay EU Live microphone audio (not recorded), room display name
Apple iTunes Search API Album-cover lookup US (DPF) Track title + artist text only (no account link)
Deezer API Album-cover fallback lookup US/EU Track title + artist text only (no account link)
Apple Maps (iOS) / Google Maps (Android) Map tile rendering US (DPF) Map region + approximate location viewed
Apple Push Notification Service iOS push US (DPF) Device token only, no PII in payload
Firebase Cloud Messaging Android push US (DPF) Device token only
App Store / Play Store App distribution + crash reports US App-store standard telemetry

Crash-SOS SMS is sent from your own device via your mobile carrier and is not routed through our sub-processors.

International transfers

All primary data storage is in the EU/EEA. US transfers are limited to app-store telemetry, push-token routing, cover-art lookup, and Android map tiles — covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses.

Data Protection Impact Assessment (DPIA)

A DPIA was performed for:

DPIA summary available on request.

Breach notification

We log all administrative actions to a tamper-evident audit trail. In the event of a personal-data breach we will notify:

Children

The Services are not intended for users under 16. If we learn we have collected data from a child, we delete it. Parents who believe their child has registered can email info@fabiride.com for immediate erasure.

Retention summary

Data Retention
Account profile Until account deletion
Invoice + sales-chain (legal) 10 years from sale
Telemetry / ride GPS Until device unpaired + 30 days
Voice chat audio Not retained (live relay only)
Emergency contacts Until removed or account deleted
Anonymised aggregated stats Indefinite
Diagnostic logs 90 days
Terms-acceptance record 10 years after account closure
Security / tamper event records 7 years
Email-server logs 30 days
Audit log 7 years (compliance)

Changes to this statement

We reserve the right to update this statement at any time. The current version always lives at https://my.fabiride.com/legal/gdpr and in the App under More ▸ Help & support ▸ Legal, and carries a version date at the top. Material changes are notified in-app or by email at least 30 days in advance.

Contact

info@fabiride.com · E. zona, MB (FabiRide) · Tvirtovės al. 88, Kaunas, Lithuania

Related documents: Terms & conditions · Privacy Policy · Sub-processors · Delete your account