MotoDoc MotoDoc
Home FAQ For Garages
About Us Contact Us
Login Join the Waitlist
MotoDoc
MotoDoc
Home For Garages FAQ About Us Contact Us
Login Join the Waitlist
Legal

Privacy Policy

MotoDoc Oy · Last updated: February 7, 2026

This Privacy Policy explains how MotoDoc Oy (\\\"MotoDoc\\\", \\\"we\\\", \\\"us\\\", or \\\"our\\\") collects, uses, stores, shares, and protects your personal data when you use the MotoDoc platform, including our mobile application, web application, and related services (the \\\"Platform\\\"). We are committed to protecting your privacy in compliance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the Finnish Data Protection Act (Tietosuojalaki 1050/2018), and other applicable data protection laws.

1. Data Controller

The data controller responsible for your personal data is:

MotoDoc Oy
Business ID: 3599168-4
Peltokatu, 33100 Tampere, Finland
Email: info@motodoc.app
Website: www.motodoc.app

2. What Personal Data We Collect

2.1 Data You Provide

When you create an account and use the Platform, you provide us with:

  • Account information: name, email address, phone number, password
  • Vehicle information: make, model, year, registration plate number, mileage
  • Communications: messages you send to Service Providers through in-app chat
  • Payment information: payment method details (processed and stored by our payment processor, not by MotoDoc directly)
  • Uploaded content: photos, documents, notes related to your vehicles or services
  • Feedback and support: any information you provide when contacting our support team

2.2 Data We Collect Automatically

When you use the Platform, we automatically collect:

  • Device information: device type, operating system, browser type, unique device identifiers
  • Usage data: features used, pages viewed, actions taken, time and date of access
  • Log data: IP address, access times, error logs, referring URLs
  • Location data: general location based on IP address (we do not collect precise GPS location unless you explicitly enable it)

2.3 Data from Third Parties

We may receive data about you from:

  • Traficom (Finnish Transport and Communications Agency): vehicle registration data, inspection (katsastus) dates, and vehicle specifications, retrieved using your registration plate number
  • Service Providers: service records, invoices, and appointment information created when they service your vehicle
  • Payment processors: transaction confirmation data (not full payment card details)

3. How and Why We Use Your Data

Purpose Data Used Legal Basis (GDPR)
Provide the Platform Account info, vehicle data, usage data Contract (Art. 6(1)(b))
Process bookings & repair requests Account info, vehicle data, communications Contract (Art. 6(1)(b))
Process payments Payment data, transaction details Contract (Art. 6(1)(b))
Facilitate Memberships Account info, payment data, membership status Contract (Art. 6(1)(b))
Service reminders & recommendations Vehicle data, service history, inspection dates Legitimate interest (Art. 6(1)(f))
Improve the Platform Usage data, aggregated analytics Legitimate interest (Art. 6(1)(f))
Partner recommendations Vehicle data, service history, preferences Consent (Art. 6(1)(a))
Customer support Account info, communications, device data Legitimate interest (Art. 6(1)(f))
Security & fraud prevention IP address, device info, usage patterns Legitimate interest (Art. 6(1)(f))
Legal compliance Any data as required Legal obligation (Art. 6(1)(c))
Marketing communications Name, email Consent (Art. 6(1)(a))

4. Personalized Recommendations

4.1 Automatic Recommendations

We use your vehicle data and service history to proactively recommend services, alert you to upcoming maintenance needs, and remind you of important dates (e.g., katsastus, oil change intervals). This is a core function of the Platform and is processed under our legitimate interest in providing a useful and relevant service to you.

4.2 Right to Object

You have the right to object to processing based on legitimate interest at any time. You can disable automatic recommendations in your account settings. Note that disabling recommendations may reduce the usefulness of certain Platform features.

4.3 Partner Offers (Consent-Based)

With your explicit opt-in consent, we may recommend third-party products such as insurance, parts, or cashback offers based on your vehicle and service data. You can withdraw consent at any time in your account settings. Withdrawal does not affect the lawfulness of processing performed before withdrawal.

5. Who We Share Your Data With

We share your personal data only in the following circumstances:

  • 5.1 Service Providers You Connect With. When you join a garage, book a service, or send a message, we share relevant data (your name, contact details, vehicle information) with that Service Provider so they can serve you. This sharing is necessary to perform the contract between you and the Service Provider.
  • 5.2 Payment Processors. We use third-party payment processors (e.g., Stripe) to handle payments. Your payment information is transmitted directly to the processor and is subject to their privacy policy. MotoDoc does not store full payment card details.
  • 5.3 Hosting & Infrastructure Providers. We use cloud hosting services to store and process data. Our infrastructure providers process data on our behalf under Data Processing Agreements compliant with GDPR Article 28.
  • 5.4 Public Registries. We query Traficom to retrieve vehicle data based on your registration plate number. We transmit only the plate number; Traficom returns publicly available vehicle data.
  • 5.5 Legal Requirements. We may disclose personal data if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or property of MotoDoc, our Users, or the public.
  • 5.6 Business Transfers. In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you of any such transfer and any choices you may have regarding your data.
  • 5.7 With Your Consent. We may share your data with other third parties when you have given explicit consent to do so.

We do not sell your personal data. We do not share your personal data with advertisers, data brokers, or any third party for their own marketing purposes without your explicit consent.

6. Subprocessors

We use the following categories of subprocessors to deliver the Platform. A current list of specific subprocessors is available upon request at info@motodoc.app.

Category Purpose Data Processed
Cloud hosting (e.g., AWS, GCP) Data storage & processing All Platform data
Payment processor (e.g., Stripe) Payment processing Payment & transaction data
Email service (e.g., SendGrid) Transactional emails Name, email address
Analytics (e.g., Mixpanel) Platform usage analytics Anonymized usage data
Push notifications (e.g., Firebase) Mobile notifications Device tokens, notification content
Traficom API Vehicle data retrieval Registration plate number

All subprocessors are bound by Data Processing Agreements that comply with GDPR Article 28 and ensure appropriate technical and organizational security measures.

7. International Data Transfers

  • Your data is primarily stored and processed within the European Economic Area (EEA).
  • If data is transferred outside the EEA (for example, to a cloud provider with servers outside Europe), we ensure appropriate safeguards are in place, including: (a) EU Standard Contractual Clauses (SCCs); (b) adequacy decisions by the European Commission; or (c) other approved transfer mechanisms under GDPR Chapter V.
  • You may request information about the specific safeguards in place for any international transfer by contacting us at info@motodoc.app.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law.

Data Category Retention Period Reason
Account data Duration of account + 30 days Service delivery
Vehicle data Duration of account + 30 days Service delivery
Service history Duration of account + 5 years Legal obligations, consumer rights
Payment records 6 years after transaction Finnish accounting law (Kirjanpitolaki)
Chat messages Duration of account + 1 year Dispute resolution
Usage analytics 2 years (anonymized) Platform improvement
Marketing consent Until withdrawn + 1 year Proof of consent

After the retention period, data is permanently deleted or irreversibly anonymized.

9. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

  • Right of Access (Art. 15): You can request a copy of all personal data we hold about you.
  • Right to Rectification (Art. 16): You can request correction of inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): You can request deletion of your personal data (\\\"right to be forgotten\\\"), subject to legal retention obligations.
  • Right to Restriction (Art. 18): You can request that we limit the processing of your personal data in certain circumstances.
  • Right to Data Portability (Art. 20): You can request your personal data in a structured, commonly used, machine-readable format (e.g., JSON, CSV).
  • Right to Object (Art. 21): You can object to processing based on legitimate interest, including automated recommendations.
  • Right to Withdraw Consent (Art. 7): Where processing is based on consent (e.g., partner recommendations, marketing), you can withdraw consent at any time.
  • Right Not to be Subject to Automated Decisions (Art. 22): You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. MotoDoc does not make such decisions.

How to Exercise Your Rights: Contact us at info@motodoc.app. We will respond within one (1) month, extendable by two (2) months for complex requests. We may ask for identity verification before processing your request. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.

Right to Complain: You have the right to file a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) or with the supervisory authority in your country of residence.
Finnish Data Protection Ombudsman: www.tietosuoja.fi
Address: Lintulahdenkuja 4, 00530 Helsinki, Finland

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Access controls and role-based permissions
  • Regular security assessments and vulnerability scanning
  • Secure development practices
  • Employee and contractor confidentiality obligations
  • Regular backups with encrypted storage

No system is completely secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.

11. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within seventy-two (72) hours of becoming aware of the breach, as required by GDPR Article 33
  • Notify affected Users without undue delay if the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34
  • Document the breach, its effects, and the remedial actions taken

12. Cookies and Tracking Technologies

Our web application uses cookies and similar technologies. Cookies are small text files stored on your device when you visit our website.

We use the following categories of cookies:

  • Strictly necessary cookies: Required for the Platform to function (e.g., session management, authentication). These do not require consent.
  • Analytics cookies: Help us understand how Users interact with the Platform. Used only with your consent.
  • Preference cookies: Remember your settings and preferences. Used only with your consent.

You can manage cookie preferences through the cookie banner displayed on first visit, or through your browser settings. Disabling certain cookies may affect Platform functionality.

We do not use tracking cookies for advertising purposes.

13. Children's Privacy

The Platform is not directed at individuals under eighteen (18) years of age. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete such data promptly. If you believe a child under 18 has provided us with personal data, please contact us at info@motodoc.app.

14. Changes to This Privacy Policy

  • We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
  • We will notify you of material changes by email and/or through the Platform at least thirty (30) days before the changes take effect.
  • We will maintain an archive of previous versions of this Privacy Policy, accessible through the Platform or upon request.
  • Your continued use of the Platform after the effective date of an updated Privacy Policy constitutes your acknowledgment of the changes. If you do not agree, you should stop using the Platform and delete your account.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:

MotoDoc Oy
Data Protection Contact
Business ID: 3599168-4
Peltokatu, 33100 Tampere, Finland
Email: info@motodoc.app
Website: www.motodoc.app

For data protection inquiries, we aim to respond within five (5) business days. For formal GDPR requests, we will respond within one (1) month as required by law.

MotoDoc MotoDoc

Find. Connect. Save.

Your car care, simplified.

Business ID: 3599168-4

For Drivers
How It Works FAQ Download App
For Garages
Garage Platform FAQ Register Your Garage
Company
About Us Contact Help Center
Get In Touch

info@motodoc.app

+358 45 316 7977

Peltokuja 33, 33100 Tampere

© 2025 - 2026 MotoDoc Oy. Registered in Tampere, Finland.

Privacy Policy Terms of Service