🇮🇹 IT

Privacy Policy

Last Updated: January 7, 2026

Compliant with GDPR (EU 2016/679), CCPA, UK GDPR, Australian Privacy Act, Canadian PIPEDA

Quick Navigation

Whoolt shpk (hereinafter "Whoolt", "we", "our") respects your privacy and is committed to protecting your personal data. This privacy policy describes how we collect, use, share, and protect your information when you use our platform for electric and hybrid vehicle repair assistance, including the WhatsApp Business API (Meta) notification system.

This policy complies with the European Union's General Data Protection Regulation (GDPR) (2016/679), as well as other applicable international data protection regulations.

1. Data Controller (Art. 13 GDPR)

Whoolt shpk

Address: Tirane Njesia Bashkiake nr.9, Rruga e Barrikadave

Galeria Tirana, zyra nr.49, Tirana 1001, Albania

NUIS: M51827022B

Website: network.whoolt.com

Privacy Email: info@whoolt.com

Legal Representative: Davide Licari

Data Protection Officer (DPO): dpo@whoolt.com

The Data Controller is responsible for determining the purposes and means of processing personal data in accordance with Art. 4(7) of the GDPR.

2. Personal Data Collected (Art. 13(1)(c) GDPR)

Whoolt collects the following categories of personal data:

2.1 Personal Identification Data

  • First and last name
  • Phone number (including WhatsApp)
  • Email address
  • Physical address (street, city, postal code, province/state)
  • Company name and VAT number (for business customers)

2.2 Vehicle Data

  • License plate and Vehicle Identification Number (VIN)
  • Make, model, and year of registration
  • Vehicle type (electric, hybrid, etc.)
  • Technical problem description
  • Vehicle photos and uploaded documents

2.3 Communication Data

  • Messages exchanged via web chat
  • WhatsApp message timestamps and read status
  • WhatsApp phone number and delivery metadata
  • Shared attachments (photos, PDF documents)

2.4 Payment Data

  • Billing information
  • Stripe transaction ID (we do not store card data)
  • Payment amounts and transaction history

2.5 Technical and Navigation Data

  • IP address
  • Browser type and version
  • Operating system
  • Access timestamps
  • Pages visited and session duration

2.6 Biometric Data (Digital Signature Only)

  • Digitized graphometric signature
  • Signature coordinates and timestamp

Note: Biometric signature data is processed only with your explicit consent (Art. 9 GDPR) for the legal validity of vehicle acceptance documents.

4. Processing Purposes (Art. 13(1)(c) GDPR)

Your personal data is used exclusively for the following purposes:

1
Assistance Ticket Management

Creating, assigning, tracking, and closing vehicle repair requests

2
Transactional WhatsApp Notifications

Sending repair status updates (NOT marketing or promotions)

3
Customer-Workshop Communication

Real-time web chat, document exchange, technical information requests

4
Quote Creation and Delivery

Processing personalized repair quotes with detailed costs and services

5
Payment Management

Processing payments via Stripe, issuing invoices, managing transactions

6
Digital Signature for Acceptance Documents

Collecting graphometric signature for legal validity of workshop vehicle acceptance

7
Security and Fraud Prevention

Platform protection, suspicious activity detection, dispute management

8
Service Improvement

Aggregated (anonymized) statistical analysis to optimize user experience

⚠️ Important

Your data is NEVER used for:

  • Aggressive marketing or unsolicited promotions
  • Sale or transfer to third parties for commercial purposes
  • Automated profiling producing legal effects (Art. 22 GDPR)

5. Data Recipients (Art. 13(1)(e) GDPR)

Your personal data may be shared with the following recipients, exclusively for the purposes described:

RecipientPurposeLocation
Whoolt Network WorkshopsRepair management, technical communication, quotesItaly/EU
Meta Platforms Ireland LimitedSending transactional WhatsApp Business API notificationsIreland (EU) + USA
Stripe Payments Europe LtdSecure online payment processingIreland (EU)
Supabase Inc.Database hosting and user authentication managementEU (Frankfurt servers)
Vercel Inc.Web application hosting and CDNEU + USA
Email SMTP/IMAP ProviderSending transactional emails (confirmations, quotes, invoices)Configurable

🔒 Protection Guarantees

All data recipients are bound by:

  • Data Processing Agreements (DPA) compliant with Art. 28 GDPR
  • Standard Contractual Clauses (SCC) approved by the European Commission
  • Security certifications ISO 27001, SOC 2 Type II
  • Adequate technical and organizational measures for data protection

6. International Data Transfers (Art. 44-50 GDPR)

Some of our service providers may process your data outside the European Economic Area (EEA). In these cases, we ensure an adequate level of protection through:

🇪🇺 EU-US Data Privacy Framework

Meta and other US providers are certified under the Data Privacy Framework (DPF) approved by the European Commission with Adequacy Decision 2023/1795.

Verify certifications: www.dataprivacyframework.gov

📄 Standard Contractual Clauses (SCC)

We use Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914) for transfers to countries without an adequacy decision.

🔐 Supplementary Safeguards

Beyond SCCs, we implement supplementary technical measures:

  • End-to-end encryption for WhatsApp messages
  • Pseudonymization of sensitive data
  • Limited data access by US providers
  • Periodic security practice audits

⚠️ Transfers to USA

Some features (WhatsApp Business API, CDN hosting) involve transfers to the United States. These transfers are protected by the safeguards described above. If you wish to exercise your rights regarding these transfers, contact us at info@whoolt.com.

7. Data Retention (Art. 13(2)(a) GDPR)

We retain your personal data only as long as necessary for the purposes for which it was collected:

Data CategoryRetention PeriodLegal Basis
Ticket and Communication Data12 months after ticket closureContract performance
Billing and Payment Data10 yearsLegal tax obligation
WhatsApp Metadata30 daysLegitimate interest (troubleshooting)
Vehicle Photos and Attachments5 years after ticket closureContractual rights protection
Digital Signature Data10 yearsDocument legal validity
Access Logs and IP12 monthsInformation security
Marketing Consent (if provided)Until withdrawalExplicit consent

🗑️ Automatic Deletion

At the end of retention periods, your data is automatically and securely deleted from our systems, except for legal obligations requiring longer retention (e.g., tax data).

8. Your Rights (Art. 15-22 GDPR)

Under the GDPR, you have the following rights regarding your personal data:

Right of Access (Art. 15)

You can request a copy of all personal data we process about you, including information about processing purposes and recipients.

Right to Rectification (Art. 16)

You can request correction of inaccurate data or completion of incomplete data concerning you.

Right to Erasure (Art. 17)

You can request deletion of your personal data ("right to be forgotten"), except for legal retention obligations (e.g., tax data).

Right to Restriction (Art. 18)

You can request restriction of processing of your data in certain circumstances (e.g., disputing data accuracy).

Right to Data Portability (Art. 20)

You can receive your data in a structured, machine-readable format (CSV, JSON) and transmit it to another controller.

Right to Object (Art. 21)

You can object to processing of your data based on legitimate interest or for direct marketing purposes.

🚫 Withdrawal of Consent

Where processing is based on consent (e.g., WhatsApp notifications), you can withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing.

⚖️ Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe the processing of your data violates the GDPR.

EU Supervisory Authorities: Find your authority

9. WhatsApp Business API Data Processing (Meta)

End-to-End Encryption

All WhatsApp messages are protected by end-to-end encryption (E2EE). This means only you and the workshop can read the message content. Neither Meta nor Whoolt can access encrypted content.

Data Collected by Meta (WhatsApp Business API)

Metadata Collected

Even with E2E encryption, Meta collects the following metadata:

  • Sender and recipient phone numbers
  • Message send and delivery timestamps
  • Delivery and read status (blue checkmarks)
  • Message type (text, image, document)
  • IP address and device information
Meta's Processing Purposes

Meta processes this metadata for:

  • Reliable message delivery
  • Spam and abuse prevention
  • WhatsApp platform security
  • Legal compliance obligations

Note: Meta does NOT use your WhatsApp Business message content for advertising. See WhatsApp Business Policy.

Data Processing Agreement with Meta

Whoolt has signed a Data Processing Agreement (DPA) with Meta Platforms Ireland Limited in compliance with Art. 28 GDPR. Meta acts as a data processor for WhatsApp metadata.

Meta Platforms Ireland Limited
4 Grand Canal Square, Grand Canal Harbour
Dublin 2, Ireland

🔔 Opt-Out from WhatsApp Notifications

You can disable WhatsApp notifications at any time:

  • Reply "STOP" to any WhatsApp message from Whoolt
  • Contact us via email: info@whoolt.com
  • Through your Whoolt account settings (if available)

Even after opt-out, you'll continue receiving email notifications for ticket management.

📱 Whoolt WhatsApp Number

Whoolt WhatsApp Business Number: +39 333 123 4567

This number is used ONLY for transactional notifications (ticket updates). We will never send unsolicited promotional or marketing messages.

10. Compliance with International Regulations

In addition to GDPR (EU), we comply with the following international data protection regulations:

🇺🇸CCPA - California Consumer Privacy Act

For California (USA) residents, we guarantee the following rights under CCPA:

Right to Know (Sec. 1798.100): You have the right to know what personal data we collect, use, share, and sell (if applicable).
Right to Delete (Sec. 1798.105): You can request deletion of your personal data, subject to legal exceptions.
Right to Opt-Out of Sale (Sec. 1798.120): Whoolt does NOT sell personal data to third parties, so this right is not applicable.
Non-Discrimination (Sec. 1798.125): We will not discriminate against you for exercising your CCPA rights.

To exercise your CCPA rights, contact us at: info@whoolt.com

🇬🇧UK GDPR - United Kingdom (Post-Brexit)

For UK residents, we comply with UK GDPR and the Data Protection Act 2018.

ICO Registration: Whoolt complies with UK data protection requirements for processing UK residents' data.
UK Representative: In accordance with Art. 27 UK GDPR, Whoolt has appointed a UK representative (details available upon request).
Data Subject Rights: All GDPR rights also apply under UK GDPR (access, rectification, erasure, restriction, portability, objection).

For UK complaints: Information Commissioner's Office (ICO)

🇦🇺Australian Privacy Act 1988

For Australian residents, we comply with the Australian Privacy Principles (APP).

APP 1 - Open and Transparent Management: This privacy policy is easily accessible and clearly explains how we manage personal data.
APP 6 - Use or Disclosure: We use your data only for stated purposes or directly related purposes.
APP 8 - Cross-Border Disclosure: When transferring data abroad (e.g., USA), we ensure adequate protections through SCCs and DPF.
APP 12 - Access and Correction: You can request access to and correction of your personal data by contacting us.

For Australian complaints: Office of the Australian Information Commissioner (OAIC)

🇨🇦Canadian PIPEDA - Personal Information Protection

For Canadian residents, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA).

Consent: We obtain your explicit consent before collecting, using, or disclosing personal data (except for legal exceptions).
Purpose Limitation: We collect data only for identified purposes communicated at the time of collection.
Right to Withdraw Consent: You can withdraw consent at any time, with possible legal or contractual limitations.
Right to Access: You can request information about the existence, use, and disclosure of your personal data.

For Canadian complaints: Office of the Privacy Commissioner of Canada

11. Data Security Measures (Art. 32 GDPR)

Whoolt implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk:

Encryption

  • TLS 1.3 for all HTTPS communications
  • End-to-end encryption for WhatsApp messages
  • AES-256 for data-at-rest on databases
  • Bcrypt/Argon2 for user passwords

Access Control

  • Role-Based Access Control (RBAC)
  • Two-factor authentication (2FA) for admins
  • Least privilege access principle
  • Automatic session timeout

Infrastructure Protection

  • EU-based servers (Frankfurt, Germany)
  • Firewalls and network segmentation
  • Encrypted daily backups
  • Tested disaster recovery plan

Monitoring and Auditing

  • Audit logging of all sensitive operations
  • Intrusion detection system (IDS)
  • Periodic vulnerability scanning
  • Quarterly security audits

Data Breach Notification Procedure

In case of a personal data breach, Whoolt:

  • Notifies the supervisory authority within 72 hours of discovery (Art. 33 GDPR)
  • Notifies affected individuals without undue delay if there is a high risk to their rights (Art. 34 GDPR)
  • Documents the breach, measures taken, and consequences in an internal register
  • Implements immediate corrective measures to prevent further breaches

🏆 Certifications and Compliance

Our service providers are certified according to:

  • ISO/IEC 27001:2013 - Information Security Management
  • SOC 2 Type II - Security, Availability, Confidentiality
  • PCI DSS Level 1 - Payment Card Industry (Stripe)
  • GDPR Compliance - All EU-based providers or with SCCs

12. How to Exercise Your Rights

To exercise any of your rights under GDPR and international regulations:

📧 Privacy Contacts

Privacy Email:

info@whoolt.com

Data Protection Officer:

dpo@whoolt.com

Postal Address:

Whoolt shpk - Privacy Office
Tirane Njesia Bashkiake nr.9, Rruga e Barrikadave
Galeria Tirana, zyra nr.49, Tirana 1001, Albania

Request Procedure

1
Send Request

Email info@whoolt.com specifying which right you want to exercise (access, rectification, deletion, etc.) and providing sufficient details to identify yourself.

2
Identity Verification

To protect your data, we may request a copy of valid ID (ID card, passport) to verify your identity.

3
Response Within 30 Days

We will respond within 30 days of receiving the complete request, as required by Art. 12(3) GDPR. In complex cases, we may extend the deadline by an additional 60 days, informing you of the reasons.

4
Free of Charge

Exercising your rights is always free. We may charge a reasonable fee only for manifestly unfounded or excessive requests (Art. 12(5) GDPR).

📝 Request Forms

To facilitate exercising your rights, you can use our standard forms:

Forms will be available soon. In the meantime, you can send a free-form request via email.

13. Complaints and Supervisory Authorities

If you believe the processing of your personal data violates GDPR or other privacy regulations, you have the right to lodge a complaint with a supervisory authority.

🇪🇺 EU Supervisory Authorities

You can contact the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.

Find your EU authority: EDPB Members List

Selected Supervisory Authorities

🇮🇹 Italy (Garante Privacy)

www.garanteprivacy.it

🇩🇪 Germany (BfDI)

www.bfdi.bund.de

🇫🇷 France (CNIL)

www.cnil.fr

🇬🇧 United Kingdom (ICO)

www.ico.org.uk

Note: We encourage you to contact us before lodging a formal complaint, so we can resolve any issues directly and quickly.

14. Changes to This Policy

Whoolt reserves the right to modify this privacy policy at any time. Changes will take effect immediately upon posting the updated version on the website.

In case of substantial changes affecting your rights, we will inform you through:

  • Email to the address provided during registration
  • Visible notification on the Whoolt platform at next login
  • WhatsApp message (if you have enabled notifications)

We recommend periodically consulting this page to stay updated on our data protection practices.

Current version: 1.0
Last modified: January 7, 2026
Next scheduled review: July 7, 2026

Questions or Concerns About Privacy?

If you have questions, concerns, or need clarifications about this privacy policy or our data processing practices, please don't hesitate to contact us:

📧 Privacy Email

info@whoolt.com

📧 Data Protection Officer

dpo@whoolt.com

🌐 Website

network.whoolt.com

📍 Address

Tirana 1001, Albania

Our privacy team responds within 48 business hours. For urgent requests, please mark your email as urgent.

© 2026 Whoolt shpk - NUIS M51827022B - All rights reserved

This policy complies with GDPR (EU 2016/679), CCPA, UK GDPR, Australian Privacy Act, Canadian PIPEDA