Skip to Content

Data Protection Notice

Last updated (latest save date): 2026-06-22

1. Who We Are

Legal Entity: Comoo NV,  and linked companies in the group

Registered address: Schaarbeeklei 485, 1800 Vilvoorde

Company number: BE0725.425.683

General contact: https://www.comoo.be/en_GB/contactus

Contact DPO contact email: dpo@comoo.be

Main Company Telephone: +32 2 255 82 20

Comoo NV (also referred to “we”, “us”, or “our” in the text below) is processing personal data as described in this notice.

Comoo NV (also referred to “we”, “us”, or “our” in the text below) is processing personal data as described in this notice.


2. Version

Latest update: June 2026

This notice applies to the data processing activities described below and is updated on a regular basis via the website. Target audience is expected to regularly check this website for updates.

In contracts with 3rd parties like customers and suppliers, a data protection clause is included in the contractual requirements, covered in mutual data processing agreements.


2. 1  Scope of This Data Protection Notice

This data protection notices is meant to inform you in a general way about our data protection practices.

More information can be provided on request, see contact details mentioned above.

Comoo NV (also referred to “the company”, “we”, “us”, or “our” in the text below) acts in 2 roles for the personal data described in this notice,

  1. As data controller for a limited number of internal activities, contractual and regulatory requirements (eg HR, contracting suppliers, …)
  2. As data processor on behalf of our clients

This Data Protection Notice explains how we collect, use, share, and protect personal data when providing:

  • Fleet management services
  • Vehicle leasing or rental services
  • Telematics and driver behaviour monitoring
  • Maintenance, insurance, and incident management
  • Digital platforms, mobile applications, and websites to support the core Comoo business activities


2.1. Our services as data controller

Comoo NV acts as data controller for the purpose of managing the following categories of processes and/or subjects, but not limited to

  • HR, employee and staff management, incl.

    • Prospect staff, hiring candidates
    • Outsource Payrol management with a supplier
  • Payroll, Financial management and bookkeeping
  • Supply chain management
  • Customer Relation Management (CRM), including:

    • Prospecting and prospect data, incl. but not limited to prospect customers, …
  • Visitor management
  • Building management and logistics
  • Legal requirements, contracting, legal and regulatory compliance
  • Safety requirements, incl. vital or public interests, where applicable
  • Communication and contact management (mail, …)
  • IT & Cloud infrastructure for office management

In the chapters below you’ll find more details about the data categories processed per process or subject.


2.2. Our services as Data processor

Most, if not all of our commercial business activities of fleet management is conducted on behalf of and instructed by our customers.

In that case we process personal data as data processor on behalf of our customers (who are data controllers), our customers are acting as data controller, with all relevant data controller responsibilities.

In fleet management we process data for the following services:

  • Contract management
  • Car Fleet management
  • Driver management
  • Car repair and damage management
  • Driver services


4. Categories of Personal Data We Process

4.1. Comoo as data controller

We may process the following categories of personal data.


4.1.1. Identification and contact data

Applies to:

  • Employee and staff
  • Customer


Data categories processed

  • Name data (First name, Lastname, …)
  • Business or private address
  • Professional and/or personal Email address
  • Telephone numbers, mobile number, office number
  • Driver or employee ID

For staff only

  • Essential Social security data for payroll processing, like family situation


4.1.2. IT infrastructure & Digital Interaction data

Applies to:

  • IT and network users

Data categories processed, incl.

  • IP address
  • Access control data and logging
  • Device and browser information
  • Log files and platform usage data
  • Cookies (see Section 10)


4.2. Comoo as data processor

4.2.1. Vehicle and usage data

Applies to:

  • Customer
  • End users

We process personal data categories that (can) identify persons, like

  • Car identification

    • Vehicle identification number (VIN)
    • Registration number
    • Carpass data
  • Car performance

    • Mileage
    • Fuel or energy consumption
    • Maintenance and inspection data


4.2.2. End user & driver management

  • Personal name

    • First and last name
  • Address data

    • Pickup and drop-of locations
  • Contact data

    • Mobile Phone
    • Company Mail address
    • Personal mail address


4.2.3. Car telematics and location Data

  • GPS location (real-time or historical)
  • Trip start/end locations
  • Driving style data (e.g. braking, acceleration, speed)
  • Time, distance, and route data


4.2.4. End user Employment-related Data

Contains but not limited to (if applicable):

  • Employer name (customer)
  • End user job function
  • Vehicle assignment data

4.2.5. Incident and Claims Data

Contains but not limited to:

  • Accident reports
  • Damage images or videos
  • Insurance claim references
  • Insurer data


4.2.6. Safety data & Camera

Our premises for car fleet management are protect by camera systems to guarantee safety and security on the sites.


4.3. Data we do not process

We do not process any sensitive data (as defined under GDPR Art.9 and 10), like

  • Biometrics
  • DNA
  • Personal background data (financial, criminal record, …)


5. Purposes and legal bases of processing

By default, we process personal data for following reasons, in order of priority

  1. Contract
  2. Legal obligations
  3. Vital interest (safety reasons to protect the subject)
  4. Public interest
  5. Consent
  6. Legitimate interests

Please check GDPR Art. 6 for the explanation of these categories.

In case of legitimate interest the data controller collects and processes subject data without prior consent.

Comoo avoids the use of legitimate interest as much as possible, as mostly consent or mutual or contractual agreements can be put in place.

Currently none of the activities of Comoo is based on legitimate interest.


5.1. Overview of legal bases


Purpose

Legal basis

Fleet operation and vehicle allocation

Contractual requirement

Vehicle tracking and optimisation

Contractual requirement

Maintenance, safety, and compliance

Legal obligation / Contractual requirement

Incident, insurance, and claims handling

Legal obligation / Contractual requirement

Billing and account management

Contractual requirement

IT security and fraud prevention

Legal obligation / Contractual requirement

Customer support and communication

Contractual requirement

Legal defence and audits

Legal obligation

Optional analytics or service improvements in website and CRM

Consent (where required)


If and where processing is based on legitimate interests, we carry out a balancing test to ensure our interests do not override individual rights.


6. Sources of personal data

6.1. Data controller

Data is collected from the subject directly, like

  • Employees & Staff
  • Prospect staff
  • Suppliers
  • Client corporate data, client contact persons


6.2. Data processor

For fleet management activies We collect personal data directly from the contractual party, like:

  • Customer or Client organisations (e.g. employers)
  • Drivers or users (employees of clients)
  • Vehicles and embedded telematics systems
  • Mobile applications and online platforms


7. Sharing and Disclosure of Personal Data

We only share personal data via contractual agreements with:

  • Client organisations (fleet owners or employers)
  • Insurance companies and claims handlers
  • Vehicle manufacturers and maintenance partners
  • IT, hosting, and telematics service providers
  • Public authorities when legally required

All processors and partners are subject to contractual data protection obligations, with a mutual data processing agreement.

We do not sell personal or marketing information to any third party.


8. International data transfers

If personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards such as:

  • EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Equivalent legal safeguards 

9. Data retention

We retain personal data only as long as necessary for the purposes described:

Data type

Retention period

Fleet and usage data

Contract duration + 5 years (ref. legal and tax requirements)

Telematics data

Contract duration

Incident and claims data

Legal limitation periods

Financial data

Statutory accounting periods defined by law

Camera

As defined by law

Data is securely deleted or anonymised once no longer required.


10. Your rights

According to applicable data protection laws (including GDPR), you have the right to:

  • Access your personal data
  • Rectification of inaccurate data
  • Data erasure (“right to be forgotten”)
  • Restriction of processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time

Please be informed that these subject rights are not absolute, but bound to legal and regulatory legislations, limitations and contractual obligations.

Our long-term system backups are excluded from data subject access requests, as they are solely serving business continuity services, with a high level of security, therefore data recovery for other reasons than business continuity is not reasonably feasible, because of the complexity and the effort to recover subject specific data.


10.1. Contact Comoo as data controller

Data subject access request and information requests must be sent to this mailbox: dpo@comoo.be

Alternatively, the contact form on the Comoo website can be used: https://www.comoo.be/contactus


10.2. Comoo as processor

If Comoo acts as data processor on behalf of customers (data controllers), you can exercise your subject rights with the relevant data controller.

In case you contact Comoo for inquiries related to data processor activities, we will forward your request to the relevant data controller.


11. Cookies and similar technologies

Our websites and platforms use cookies and similar technologies to:

  • Ensure technical operation
  • Enhance user experience
  • Collect analytics (where consent is given)

For more information, please consult our Cookie notice.


12. Data security

Comoo is committed to implement state-of-the art (modern) security measures, as long as they are relevant and reasonable.

Therefore, we manage our security measures with a full scale ISMS (information security management system) based on ISO 27001.

We implement organizational, procedural, technical and physical security measures, including:

  • Security lifecycles
  • Access controls and authentication
  • Encryption of data in transit and at rest
  • Logging and monitoring
  • Staff confidentiality obligations
  • Regular security assessments
  • Continuous monitoring
  • Rapid incident response


12. Geselecteerde leveranciers

We have implemented an ISMS (Information Security Management system) ourselves and also require that our suppliers and subcontractor in the supply change match the same requirements, like customers expect from us.

As supplier Comoo is subject to GDPR requirements, NIS2 and DORA.


13. Automated Decision-Making and AI (Artificial Intelligence)

We do not make decisions producing legal or similarly significant effects solely based on automated processing, unless explicitly communicated and legally permitted.


14. Changes to this notice

We may update this notice from time to time. The current version will always be available via our website or platforms.


15. Complaints and supervisory authority

15.1. First contact us

If you have any question or if you believe your data protection rights have been infringed, please contact us first. It’s our duty to help you out and make sure to answer all your relevant questions first.

See contact details in last section.

We will work with you to solve your questions and issues to the best of our capabilities.


15.2. Next option: data protection authority

If you still believe we could not handle your data protection rights as data controller correctly, you may lodge a complaint with your local Data Protection Authority (DPA).

As our HQ is located in Belgium, you can contact the: Gegevensbeschermingsautoriteit (GBA/APD) via www.gegevensbeschermingsautoriteit.be

For the list of EU data protection authorities, to contact a data protection authority in your region, please check this list: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en


16. Contact details

16.1. Please contact your direct Comoo contact person first

If you have any questions about our data processing, please contact your direct liaison person at Comoo, they are the best to know your personal situation and help you out.


16.2. Contact our DPO

For questions regarding this notice or our data protection practices, you can contact our Data Protection Officer (DPO).

Email: dpo@comoo.be