Privacy Notice for the Movemar Platform
Last updated: 01 July 2026
Promotino Ltd. (“Promotino”, “we”, “us” or “our”) respects privacy and protects personal data processed through the Movemar Platform.
This notice explains how personal data is processed when the Movemar web Platform and mobile applications are used for account administration, field work, visits, routes and mileage, tasks, forms, photographs, analytics, diagnostics, security and support.
1. Who This Notice Applies To
This notice applies to natural persons who use Movemar on behalf of a client organisation, including:
- client-organisation administrators;
- managers and supervisors;
- field representatives and other end users;
- the initial administrator Account created during client onboarding.
2. Roles of the Client and Promotino
Where a client organisation uses Movemar to manage its employees, contractors, visits, routes, tasks, forms, photographs, notes and operational records, that organisation generally acts as the controller of such data.
In this context, Promotino processes the data on behalf of the Client in order to provide Movemar. The processing is governed by a separate Data Processing Agreement (DPA) or another binding contractual arrangement.
Promotino acts as an independent controller for limited activities for which it independently determines the purposes and essential means, including security, authentication, prevention of misuse, diagnostics, reliability, product analytics and service improvement.
3. Controller Details
For processing for which Promotino acts as controller: Promotino Ltd., UIC 203755878, Mladost District, Mladost 1A Residential Complex, Block 537, Floor 1, Apartment 2A, Sofia 1729, Bulgaria; email: info@movemar.com. No Data Protection Officer has been appointed.
4. Categories of Personal Data
Account and Identity Data
- name and business email address;
- Account identifier;
- Role, permissions and Account status.
Operational Data and Work Activity
- working days, routes, mileage, visits and timestamps;
- tasks, statuses, forms, surveys and responses;
- notes, comments, files and visit photographs.
Location Data
- precise coordinates used to verify presence at a site;
- precise coordinates and route points used to calculate mileage during an active working day;
- background location while working-day tracking is active and permitted by device settings and applicable law;
- pause and resume status.
Technical, Diagnostic and Security Data
- IP address, device type, operating system, browser, application version and user agent;
- login, access, security and technical-event logs;
- application, installation or device identifiers and push token;
- crash, error, performance, usage and diagnostic data.
5. How Data Is Collected
Data is collected when Accounts are created and managed, Users log in and use the Platform, start, pause or end a working day, perform visits and routes, complete tasks and forms, upload files and photographs, receive notifications, and when technical, analytics, diagnostic or security events are recorded automatically.
6. Location and Google Maps
Movemar may process precise location, including background location, to calculate mileage, track a route during an active working day and verify whether a User is present at a particular site. Tracking starts when the User activates the working day, may be paused and ends when the working day is stopped.
Location data may be visible to the Client’s authorised administrators and managers according to the configuration and permissions in the Platform.
Google Maps is used as a separate location and mapping-content service. When a map is loaded and displayed, Google may receive the request, IP address and the coordinates of the displayed site or the device’s current location. Movemar does not send employee or site names to Google Maps as parameters.
7. Purposes and Legal Bases
A. Processing on Behalf of the Client
The Client determines the purposes and legal basis for user administration, working days, routes, mileage, visits, tasks, forms, photographs, files, reports and related field activity. Promotino processes such data on the Client’s documented instructions and in accordance with the DPA.
B. Independent Processing by Promotino
Provision, maintenance and security of the Platform. We process technical and Account-related data to manage access, reliability, security, prevent misuse and investigate incidents. Legal basis: performance of a contract, where applicable, and legitimate interests in providing a secure and reliable service.
Diagnostics and performance. We use Firebase Crashlytics and Performance Monitoring for crashes and performance, and Sentry only to monitor and diagnose errors in the back-office interface. Legal basis: legitimate interests in troubleshooting and improving reliability.
Product analytics. We use Google Analytics, including Firebase Analytics, to analyse use of the web Platform and mobile applications. Microsoft Clarity is used only in the authenticated web part of the Platform and not on the public website or in the mobile applications. Strict masking is enabled; for Users in the EEA, the United Kingdom and Switzerland, the integration transmits the required consent signal through Microsoft Clarity Consent Mode. Legal basis: consent where required and, in other applicable cases, legitimate interests in understanding and improving the product.
Notifications and configuration. Firebase Cloud Messaging is used for push notifications and Firebase Remote Config for remote application configuration. Legal basis: performance of a contract, where applicable, and legitimate interests in providing and maintaining the functionality.
The Firebase services used are Firebase Crashlytics, Firebase Analytics, Firebase Cloud Messaging, Firebase Remote Config and Firebase Performance Monitoring.
Legal obligations and protection of rights. We may process and retain data where necessary to comply with a legal obligation, respond to a lawful request, enforce contractual terms or protect our rights and security.
8. Whether Data Must Be Provided
Some data is necessary for the Platform to function. A name and business email address are required for an Account; technical data is required for login and security; location may be required for Client-enabled features such as mileage or presence verification. If required data is not provided, the relevant function may not operate or be available.
9. Recipients and External Services
Depending on the relevant processing, data may be accessible to:
- the Client and its authorised administrators, managers and Users;
- authorised Promotino personnel where necessary for support, security and administration;
- UAB Interneto Vizija, company No. 126350731, Lithuania, the legal entity behind the Time4VPS service — VPS and infrastructure hosting;
- UAB Rakrėjus, company No. 303126701, Lithuania — a downstream subprocessor through UAB Interneto Vizija, where applicable to backup infrastructure and storage;
- Microsoft Azure — storage of photographs and other files in the West Europe region;
- Cloudflare — proxy, CDN, WAF and DNS;
- Google/Firebase — Firebase Crashlytics, Analytics, Cloud Messaging, Remote Config and Performance Monitoring;
- Microsoft Clarity — product analytics only in the authenticated web part of the Platform;
- Functional Software, Inc. d/b/a Sentry — error diagnostics only for the back-office interface;
- Google Maps — a separate location service through which Google receives the request, IP address and coordinates, but not employee or site names as parameters;
- competent authorities, professional advisers or other parties where disclosure is required by law or necessary to protect rights and security.
We do not sell personal data.
10. International Transfers
Some providers may process personal data outside the European Economic Area. Where this occurs, an applicable lawful mechanism is used, including an adequacy decision, Standard Contractual Clauses, the EU–U.S. Data Privacy Framework where applicable, or another lawful transfer mechanism used by the relevant provider.
11. Retention
- Accounts may be archived by the Client rather than immediately deleted;
- operational data may be retained while the Client has an active contract and uses the Platform;
- security, technical, crash and diagnostic logs are retained according to operational need, settings and the applicable rules of the relevant service;
- analytics data is retained according to the settings and applicable rules of the relevant provider;
- a Backup is generated on each calendar day except Sunday and retained on a rolling basis for up to 7 calendar days, with each new Backup overwriting the oldest;
- after termination, active data, export and deletion are managed in accordance with the General Terms and Conditions and the DPA.
12. Rights of Individuals
Where data is processed by an employer or another client organisation for operational purposes, that organisation is generally responsible for requests for access, rectification, erasure, restriction, objection and portability. Promotino assists the Client in accordance with the DPA.
For data for which Promotino acts as controller, a request may be sent to info@movemar.com. We may request reasonable verification of identity. Where processing is based on consent, consent may be withdrawn for the future.
13. Complaints
You have the right to lodge a complaint with a competent supervisory authority. The competent authority for Promotino in Bulgaria is the Commission for Personal Data Protection.
14. Automated Decision-Making
Promotino does not use personal data in Movemar to make decisions based solely on automated processing that produce legal or similarly significant effects for Users.
15. Children
Movemar is intended for business use by organisations and is not directed to children under 16.
16. Changes
We may update this notice from time to time. When we do, we publish the updated version and change the last-updated date.
