The controller of the personal data processed within the mobile application and the associated digital services of the Talobox platform (hereinafter the “Application”) is the company mtech global s. r. o., with its registered office at J. Alexyho 2704/10, 955 03 Topoľčany, Slovak Republic, Company ID (IČO): 57635544, Tax ID (DIČ): 2122862841, registered in the Commercial Register maintained by the District Court Nitra, Section: Sro, Insert No.: 69769/N (hereinafter the “Operator”, the “Controller” or “mtech global s. r. o.”). This Privacy Policy constitutes a comprehensive legal framework describing in detail which categories of personal data we collect about you as users, for which specific and explicitly defined purposes we use them, how we ensure their maximum protection against misuse, to whom such data may be disclosed, and which guaranteed rights you have as data subjects directly under Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Slovak Act No. 18/2018 Coll. on Personal Data Protection, as amended.
1. Scope and categories of personal data processed
Our platform processes personal data to differing extents depending on the role you hold within the application and the functions you actively use. Without the provision of the data set out below, it is neither technically nor legally possible to ensure the performance of the contractual relationship and the provision of our services.
A. Data common to all registered users (both Senders and Drivers):
- E-mail address: serves as the unique user identifier (login), for unambiguous authentication during sign-in, for sending important operational and technical information about the application, and for primary communication between the Controller and the user.
- Telephone number: an essential contact detail used to ensure immediate coordination and verification of details between the Sender, the Driver and the Recipient of the shipment during the active delivery process.
- Geolocation data and device location: for the Sender, we process the GPS coordinates of addresses when an order is created (the pick-up and delivery locations). For the Driver, we process the location in real time during active transport (order statuses accepted, picked_up and in_transit), as well as upon confirmation of delivery and in selected functions (e.g. quick start, planned route). The live location enables the Sender to follow the progress of the transport on a map.
- FCM token (Firebase Cloud Messaging): a unique technical identifier assigned to your device, which enables the immediate generation and delivery of push notifications about changes in the order status, the assignment of a transport, or system messages.
- Internal chat messages: the textual content of the communication between the Sender and the Driver within an active order (specifying the meeting point, time and transport details), stored in the order database.
- Data on the Recipient of the shipment (a third party): the name and telephone number of the Recipient, entered by the Sender when creating an order. This data is necessary for delivery and for verification of the takeover (PIN). The Sender is obliged to have a legal basis for providing the Recipient’s data (e.g. consent or a contractual relationship with the Recipient).
B. Automatically collected technical data and network identifiers:
- IP address and network logs: recording of the network address assigned to your device on each access to our servers, for the purposes of ensuring cyber security, detecting fraudulent behaviour and preventing DDoS attacks.
- Unique device identifier (Device ID / Installation ID): a technical code of the hardware and of the application installation, used to pair the account with the device, to prevent repeated registrations and to detect fraud.
- Operating system and application metadata: data on the type and version of the operating system (Android/iOS), the device model and the version of the Talobox application, for the purposes of technical optimisation, force-update and error diagnostics.
- Firebase Analytics: telemetry of application usage (events, screens) used to improve the product and its stability.
- Firebase Crashlytics: technical reports on application crashes and errors, which may contain the user identifier (uid) and diagnostic device metadata, used to fix errors.
- Firebase App Check: technical verification of the integrity of the application / device (e.g. Play Integrity, App Attest) before sensitive server functions are called, in order to prevent API abuse.
C. Special and additional categories of data processed exclusively in respect of Drivers (Couriers):
- First name, surname and academic title: basic identification data necessary for the formation of contractual relationships, billing documentation and the unambiguous identification of the person.
- Identity verification (KYC) via Stripe: new Drivers undergo identity verification during the “Become a driver” registration process through Stripe Connect. Stripe (as a separate controller / payment service provider) verifies the identity document (typically an identity card or a passport) and the related data required for payouts. The operator of Talobox does not store scans of identity cards in its own database; the verification status (e.g. charges enabled) is recorded in the Driver’s profile.
- Data entered in the Driver profile in the application: e.g. document number (where required in the form), vehicle registration plate, vehicle data and an optional IBAN – for identification towards the Sender and for the internal administration of the profile. Bank details for payouts are processed primarily in Stripe Connect.
- Vehicle registration plate, make, model and colour of the vehicle: technical parameters of the motor vehicle, displayed to the Sender so that they can safely recognise the arriving Driver.
- Photographic documentation of the condition of the shipment (visual records): photographs taken by the Driver directly through the Talobox application interface at the moment of the physical takeover of the parcel from the Sender and subsequently at the moment of handover to the Recipient. These records serve as evidence of the condition of the goods for complaints and dispute resolution.
2. Specific and legitimate purposes of processing personal data
The Controller strictly observes the principle of data minimisation. Your personal data are processed exclusively for the following legitimate purposes:
- Provision of platform services and intermediation of transport: registration of the user profile, real-time matching of Senders’ demand with Drivers’ supply, order administration and the overall technical operation of the Talobox infrastructure.
- Identity verification and community safety (KYC): verification of the identity of new Drivers in the “Become a driver” process via Stripe Connect (including verification of the identity card / identity document on the Stripe side) and approval of access to payouts, with the aim of minimising the risks associated with transport.
- Payment processing and clearing: secure processing of card transactions on the Sender’s side, holding of funds in escrow and the subsequent distribution and payout of net financial remuneration to Drivers’ IBAN accounts through the integrated payment gateway.
- Sending system messages and operational communication: dispatch of push notifications, SMS messages or e-mails concerning the immediate status of the transport (e.g. “The Driver has picked up the parcel”, “The shipment has been delivered”), as well as technical announcements about planned maintenance or security risks. Commercial communications are sent only within the limits of applicable e-privacy and electronic commerce legislation.
- Resolution of disputes, arbitration and complaints procedures: assessment of submissions from users in the event of non-delivery, damage, loss or theft of a shipment, where system logs, GPS routes and uploaded photographic documentation are used as the principal evidence.
- Compliance with strict legislative and tax obligations (DAC7 and accounting): collection, recording and automated reporting of Drivers’ financial income and identification data to the competent tax authorities pursuant to European Directive DAC7 on digital platforms (Council Directive (EU) 2021/514, implemented in the Slovak Republic by Act No. 442/2012 Coll. on International Assistance and Cooperation in Tax Administration), as well as the proper maintenance of the accounting and tax records of mtech global s. r. o. pursuant to Act No. 431/2002 Coll. on Accounting.
- Defence of legal claims and crime prevention: detection of fraud (e.g. fictitious rides, misuse of payment cards), securing evidence for potential civil court proceedings, enforcement proceedings or criminal prosecutions.
3. Legal bases on which the processing is founded
Every operation involving the processing of your personal data has a legislative foundation and is carried out exclusively in accordance with Article 6 of the GDPR. We rely on the following legal bases:
- Performance of a contract under Article 6(1)(b) GDPR: the processing is necessary in order for us to be able to perform what we have undertaken in the Terms and Conditions – i.e. to create an account for you, to enable you to submit a transport request, to match you with a driver and to safely complete the delivery of the parcel.
- Compliance with a legal obligation under Article 6(1)(c) GDPR: the Controller is bound by the legislation of the Slovak Republic and of the EU. The processing of data on payments, invoicing and the income of operators in the sharing economy (Directive DAC7) is directly imposed on us by Act No. 442/2012 Coll. on International Assistance and Cooperation in Tax Administration and by Act No. 431/2002 Coll. on Accounting.
- Legitimate interests of the controller or of third parties under Article 6(1)(f) GDPR: processing of data for the purposes of maintaining cyber security, protecting senders’ property, preventing serious fraud, technical monitoring of application errors and defending our legitimate legal claims before the courts.
- Consent of the data subject under Article 6(1)(a) GDPR: freely given consent is used in specific situations, for example if we decide to send marketing offers not directly related to the operation of Talobox. You may withdraw such consent at any time free of charge.
4. Recipients of data and categories of third parties
Your personal data are kept secure to the greatest possible extent. However, in order to maintain a functional application ecosystem and to deliver the shipment, a limited amount of data is necessarily shared with the following parties:
- Mutual sharing between Users (contracting parties): after accepting an order, the Driver sees the Sender’s name, telephone number, pick-up address and handover address, including the name and telephone number of the Recipient. Conversely, the Sender sees the Driver’s name, their rating and the vehicle parameters (including the registration plate) and can follow the live location during the transport. Both participants may use the internal chat within the order.
- Stripe Payments Europe, Limited / Stripe Connect: a payment gateway with PCI DSS certification. Stripe processes payment card data, Apple Pay / Google Pay data and, in the case of Drivers, also the KYC identity verification (identity card / passport) and the data required for payouts (including the bank account). The operator of Talobox never sees or stores complete payment card numbers.
- Google Ireland Limited (Firebase, Google Cloud, Google Maps Platform): cloud hosting, database, authentication, Storage, Cloud Functions, FCM, Analytics, Crashlytics, App Check, as well as mapping and address services (Maps, Places, Geocoding, Directions). Primary processing takes place in the EU; certain supporting processing operations may involve transfers outside the EEA – see section 4a.
- External subcontractors and professional advisers: companies providing mtech global s. r. o. with external accounting, legal advisory, audit or technical IT support services, all of whom are bound by confidentiality and by data processing agreements (DPAs) pursuant to Article 28 GDPR.
- State authorities and institutions: the Financial Administration of the Slovak Republic (in connection with DAC7 reporting), courts, the Office for Personal Data Protection of the Slovak Republic, law enforcement authorities (the Police Force of the Slovak Republic, the public prosecutor’s office) or the Slovak Trade Inspection, on the basis of an official, lawful and duly reasoned request.
4a. Transfers of personal data outside the European Economic Area
The Controller prefers to store and process data within the EU. Certain providers (in particular Google / Firebase and Stripe) may, within their global infrastructure, transfer personal data to third countries as well (e.g. the USA). Such transfers take place exclusively subject to appropriate safeguards under Chapter V of the GDPR, in particular by means of the European Commission’s standard contractual clauses (SCCs), or another valid mechanism (e.g. an adequacy decision / the Data Privacy Framework, where applicable). Details of the transfers carried out by individual providers are set out in their own privacy policies.
5. Retention periods for personal data
The Controller retains your personal data only for the period strictly necessary to achieve the purposes for which they were collected, or for the period required by the relevant legal regulations of the Slovak Republic. The criteria for determining the retention period are set strictly as follows:
- Data of an active user account: all identification, contact and profile data are processed and retained for the entire duration of your contractual relationship with the platform, i.e. during the active use of the Talobox application until the moment you request the cancellation and deletion of your account.
- Transaction, financial and accounting records: data on completed orders, transports, billing data, payments and remuneration paid out must be retained pursuant to Act No. 431/2002 Coll. on Accounting in conjunction with the tax regulations of the Slovak Republic for a period of 10 years from the end of the accounting year in which the transaction took place. This data cannot be deleted earlier, not even on the basis of a request to cancel an account.
- Data for the purposes of Directive DAC7: information collected about Drivers for the purposes of complying with obligations in the field of international assistance in tax administration (Act No. 442/2012 Coll.) is retained in accordance with the tax regulations for the period required for inspection by the state authorities, as a rule for a period of 10 years.
- Photographic documentation of the condition of shipments: visual records produced by the Driver upon the takeover and handover of a parcel are retained in the system for a period of 6 months from the successful delivery of the shipment. This period is set having regard to the limitation periods for asserting claims for compensation for damage and to the definitive closure of any complaints.
- Operational logs and IP addresses: technical network records and security-related logs are retained for a period of 12 months from their creation, for the purposes of the retrospective analysis of cyber security incidents and the protection of the server infrastructure.
6. Your guaranteed rights as a data subject
As a data subject you have, under the GDPR, a broad range of rights which you may exercise against the Controller at any time free of charge. Upon your request, we will provide you with cooperation and with information on the measures taken without undue delay, and no later than within 30 days of receipt of the request. Your rights include:
- Right of access to data (Article 15 GDPR): you have the right to request confirmation from us as to whether we process your personal data and, if so, you have the right to obtain access to that data and detailed information about the manner of its processing, the purpose and the recipients.
- Right to rectification (Article 16 GDPR): if you find that your personal data recorded in the Talobox application are inaccurate, incomplete or out of date, you have the right to request their immediate correction, rectification or completion.
- Right to erasure / right to be forgotten (Article 17 GDPR): you have the right to request that we erase your personal data without undue delay where they are no longer necessary for the purposes for which they were collected, where you withdraw your consent, or where you object to processing based on legitimate interests and there are no overriding legal grounds for their further retention.
- Right to restriction of processing (Article 18 GDPR): you have the right to request that we restrict the processing of your data (i.e. that we merely store the data without actively working with it), for example during the period in which you contest the accuracy of the data, or where the processing is unlawful but you refuse its complete erasure.
- Right to data portability (Article 20 GDPR): you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format (e.g. JSON), and you have the right to transmit that data to another controller, where the processing is based on a contract or on consent.
- Right to object (Article 21 GDPR): you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of our legitimate interest (Article 6(1)(f) GDPR). In such a case we may no longer process the data unless we demonstrate compelling legitimate grounds which override your interests and rights.
- Right to withdraw consent (Article 7(3) GDPR): in cases where we process your data solely on the basis of consent given by you, you have the right to withdraw that consent at any time, in a manner as simple as that in which it was given. Withdrawal does not affect the lawfulness of processing carried out before its withdrawal.
- Right to lodge a complaint with a supervisory authority (Article 77 GDPR): you have the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic, or with the supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement.
7. Procedure for exercising the rights of a data subject
You may exercise all of the above rights in official electronic form by sending a detailed request to our dedicated e-mail address for privacy matters: gdpr@talobox.com. Your request must contain identification data (the e-mail address associated with the account) so that we can reliably verify your identity and prevent unauthorised access to your data by third parties. If we do not respond to your request within the statutory period of 30 days, or if you believe that we are handling your data contrary to the GDPR and to Act No. 18/2018 Coll. on Personal Data Protection, you have the right to lodge an official complaint or a motion to commence proceedings with the supervisory authority, which for the Slovak Republic is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), with its registered office at Hraničná 12, 820 07 Bratislava 27, Slovak Republic, web: dataprotection.gov.sk.
7a. Automated and earlier deletion of data directly in the application
The Controller has implemented a function for the direct administration and disposal of a user account into the application interface. If you decide to stop using the platform, you may do so in the section Profile → Delete account (GDPR). After confirming this option, your profile will be blocked / anonymised according to the configuration of the deleteAccount server function. Please note that personal data and records subject to statutory archiving obligations (transaction records of deliveries, tax and accounting documents, DAC7 reports, etc.) will not be completely erased on the basis of this step and will remain stored in a segregated / restricted regime until the expiry of the relevant statutory period (as a rule 10 years), with access to them strictly limited. Deletion is not possible if you have an active order.
8. Technical, organisational and security measures
The protection of your data is our highest priority. The Controller, mtech global s. r. o., declares that, in accordance with Article 32 of the GDPR, it has implemented appropriate technical and organisational security measures with the aim of ensuring the integrity, confidentiality and availability of the data processed:
- Encryption of transmission: all network communication between the Talobox application on your smartphone and our cloud infrastructure takes place exclusively via the securely encrypted HTTPS protocol using modern TLS/SSL ciphers.
- Access control and authorisation: access to the databases on the Firebase / Google Cloud platform is strictly limited and governed by comprehensive rules (Firebase Security Rules). Every data query is verified by an authentication token. An ordinary Driver never has access to the sensitive data of other Drivers.
- Segregation of sensitive data: the most sensitive data relating to KYC and to Driver payouts is processed primarily by Stripe Connect. Data in the Driver profile in the application (e.g. the vehicle registration plate, the optional IBAN) is accessible, under the Firebase Security Rules, only to authorised parties.
- Absolute payment security: the processing of card payments and bank clearing is fully delegated to the global processor Stripe. The infrastructure of the Talobox platform does not process, does not store and has no access to full payment card numbers or to CVC/CVV codes. The entire process is subject to the most stringent security standard, PCI DSS Level 1.
9. Protection of the privacy of persons under 16 years of age
The mobile application and the services of the Talobox platform are aimed at and intended exclusively for natural persons of full legal age, or for persons who have reached the age of at least 16 years (Article 8 GDPR in conjunction with Section 15 of Act No. 18/2018 Coll. on Personal Data Protection). The Controller does not intentionally or knowingly collect, process or record personal data from persons under 16 years of age. If, in the course of our monitoring activity, we find that an account has been registered by a person under 16 years of age without the demonstrable consent of their legal guardian, we will delete such account, including all associated data, from our systems without undue delay and without any prior notice.
10. Unilateral changes and updates to this Policy
The Controller reserves the full right to unilaterally amend, supplement or change this Privacy Policy at any time, in particular in view of the implementation of new application functions, legislative changes in the field of privacy protection, or adjustments to contractual relationships with external subcontractors. All registered users will be transparently informed in advance of every material and legislatively significant change to this Policy, by means of a push notification directly in the Talobox application interface, by a system e-mail, or by the display of a mandatory information screen at the next launch of the application. If you continue to actively use the application and our services after the updated wording of the Policy takes effect, you are deemed to have acquainted yourself with the new wording of the Policy and to have taken note of it.
11. Contact details and supervision
Should you have any questions, uncertainties or comments regarding the processing of your data, or should you wish to exercise your rights as a data subject, you may contact us at any time through the following communication channels:
Company name: mtech global s. r. o.
Registered office: J. Alexyho 2704/10, 955 03 Topoľčany, Slovak Republic
Company ID (IČO): 57635544
Tax ID (DIČ): 2122862841
Commercial Register: District Court Nitra, Section: Sro, Insert No.: 69769/N
E-mail address: gdpr@talobox.com
Competent supervisory authority for the Slovak Republic:
Office for Personal Data Protection of the Slovak Republic
(Úrad na ochranu osobných údajov Slovenskej republiky)
Hraničná 12, 820 07 Bratislava 27
Slovak Republic
Website: www.dataprotection.gov.sk
mtech global s. r. o. | Talobox 2026