1. Lawful basis
Processing is based on contract performance, legitimate interest, compliance obligations, fraud prevention, support delivery and explicit acceptance of platform legal documents where required.
2. Consent records
Acceptance of the Privacy Policy, Terms of Service and GDPR notice is stored in the audit log together with timestamp and network metadata. This allows administrators to demonstrate who accepted which active version.
3. Data minimization
Only the minimum data required for identity, workspace access, ownership workflows, vehicle history, billing support and service operations should be introduced into the platform.
4. Access control
Platform access is role-based. Workspaces are isolated and shared visibility is granted only through explicit workflow permissions, approvals or ownership relationships supported by the business process.
5. Administrative oversight
Platform administrators may review audit events, consent evidence, security incidents and support escalations strictly for operational continuity, legal compliance and incident investigation.
6. Processor and document scanning
When configured, uploaded documents may be processed by Azure Document Intelligence as part of the document-analysis workflow. Parsed results should be reviewed by the responsible user before final confirmation into the permanent history.