Version 1.2
Effective date: 19 September 2026
1. General Provisions
1.1. We respect your privacy and are committed to protecting your personal data.
1.2. This Privacy Policy (the “Policy”) applies when you use:
1.2.1. the Prufio mobile application (the “App”);
1.2.2. the web dashboard available at www.prufio.com (the “Dashboard”);
1.2.3. all related services, infrastructure and functionality (collectively, the “Platform”).
1.3. “Personal Data” means any information relating to an identified or identifiable natural person.
1.4. Other capitalised terms used in this Policy have the meanings given to them in the Prufio Terms and Conditions (the “Terms”).
1.5. We process Personal Data in accordance with the General Data Protection Regulation (GDPR) and applicable laws of the Republic of Lithuania. The principal legal bases on which we process Personal Data are:
- performance of a contract – administering Accounts, creating and fulfilling Inspection Requests, conducting Inspection Sessions, generating Inspection Reports and administering payments;
- legitimate interests – ensuring the security of the Platform; confirming and evidencing the authenticity and integrity of inspections; preventing and detecting fraud, data falsification and manipulation; handling complaints, claims and disputes; protecting the rights and legitimate interests of Users and other persons connected with a vehicle; developing, testing and improving automated systems used on the Platform; delivering an Inspection Request to an Intended Recipient whose contact details were provided by the requesting User; and using xwinspection materials for training, research, product demonstration, communications and marketing purposes;
- legal obligation – complying with accounting, tax and other legal requirements;
- consent – where we specifically request it, for example, for direct marketing communications where consent is required by law.
1.6. Where we process Personal Data on the basis of legitimate interests, we assess whether the processing is necessary and seek to ensure that the interests, rights and freedoms of the data subject do not override our or a third party’s legitimate interests.
2. Data Controller
Prufio, UAB
Company code: 307496139
VAT number: LT100019259918
Senasis Ukmergės kel. 4, Užubalių k., LT-14302 Vilnius district, Lithuania
Contact: info@prufio.ravendev.lt
3. How We Collect Personal Data
We collect Personal Data:
- directly from you when you create an Account, purchase a service with or without an Account, create an Inspection Request, initiate an inspection of your own vehicle, enter an Inspection Code, conduct an Inspection Session or make a payment;
- automatically when you use the Platform, including technical and session data;
- from another User, for example, when the requesting User provides information about the vehicle being inspected or, where this option is available, the Intended Recipient’s contact details;
- from payment service providers for payment confirmation and administration purposes;
- from third-party authentication service providers when you choose a sign-in method offered by them.
You are responsible for ensuring that the information you provide is accurate and lawful and, where you provide another person’s data, that you are entitled to provide it to Prufio for the purposes set out in this Policy.
4. Personal Data We Collect
4.1. Account Data
We collect:
- email address;
- name, where you provide it on the Platform or we receive it from your chosen authentication service provider
- login and authentication data;
- information about Account activity;
- the IP address used when signing in.
- the unique User identifier assigned by the Platform (User ID)
We may also receive an email address and a unique User identifier assigned by a third-party authentication service provider, such as Apple or Google, depending on your chosen sign-in method and the permissions you grant.
Purpose: to create and manage your Account, provide access to the Platform and ensure the security of the Account and the Platform.
Legal basis: performance of a contract and Prufio’s legitimate interest in ensuring the security of the Account and the Platform.
Retention period: for the period during which the Account is used and for up to 3 years after the last activity. If the Account is deleted, related Personal Data is deleted unless it must be retained to comply with legal obligations, resolve disputes or for the periods specified for particular categories of data in this Section 4.
4.2. Inspection Request and Inspection Code Data
When you create an Inspection Request, we process:
- information you provide about the vehicle or other object to be inspected;
- the status of the Inspection Request and related timestamps;
- the Inspection Code generated by the Platform for the Inspection Request;
- the Intended Recipient’s telephone number or email address where the requesting User elects to provide such information.
When an Inspection Code is entered in the App, we record the time it was used and the Account and device through which it was used, and we link the Inspection Session, the User conducting it and the generated Inspection Report to the relevant Inspection Request.
The Inspection Code is usually provided to the Intended Recipient by the requesting User outside the Platform through communication channels selected by that User, such as messaging applications, email or SMS. We do not process the content of such communications taking place outside the Platform.
If the requesting User provides the Intended Recipient’s telephone number or email address, we may use it to attempt to deliver the Inspection Request or Inspection Code by SMS or email through our messaging service providers and to link the Inspection Request to an existing Account. Delivery is not guaranteed, and the primary delivery method remains the User’s own sharing of the Inspection Code. The Intended Recipient is informed why they received the message and is provided with a link to this Policy.
Purpose: to link Inspection Requests with Inspection Sessions and Inspection Reports, operate the Inspection Request flow, ensure session integrity and prevent unauthorised use of Inspection Codes.
Legal basis: performance of a contract and the legitimate interests of Prufio and the requesting User in properly delivering and fulfilling the Inspection Request, ensuring its security and preventing unauthorised use of the Inspection Code.
Retention period: Inspection Request data is retained together with the related Account and Inspection Session data. The Inspection Code remains valid until it is used or until the Inspection Request ends in the circumstances set out in the Terms; records of its use and the linking of the Inspection Request are retained for up to 2 years. Contact details of the Intended Recipient provided by the requesting User are retained for up to 3 months after the Inspection Request ends.
4.3. Inspection Session Data
An Inspection Session is generally conducted not by the requesting User but by the Intended Recipient, usually the seller or another person with access to the vehicle or other object being inspected, acting on the basis of the Inspection Code shared with them or another access method supported by the Platform. The data described in this section primarily relates to the User conducting the Inspection Session and to persons incidentally captured during the session.
A seller may also initiate and conduct an Inspection Session for their own vehicle without receiving an Inspection Request from a buyer. The data processing provisions set out in this section also apply to such inspections.
During an Inspection Session, we process:
- continuous video recording;
- audio recorded during the Inspection Session;
- photographs captured directly through the App during the Inspection Session;
- GPS location data collected during the active Inspection Session;
- device sensor, status and integrity signals to the extent captured during the Inspection Session;
- Inspection Session timestamps and other session metadata;
- questionnaire responses and other data provided by the User during the inspection;
- identifiers and data relating to the vehicle or other inspected object that may appear during the Inspection Session, such as vehicle registration plates, VINs, mileage and dashboard readings, visible documents or other identifiers.
GPS location tracking is activated only when the User starts an Inspection Session. Location data is collected only during an active Inspection Session and is not tracked when the App is used for browsing or other activities unrelated to an Inspection Session. Tracking stops immediately when the Inspection Session ends.
By starting an Inspection Session, the User expressly initiates the recording of video, audio and location data for the duration of the Inspection Session. Other persons, their voices, vehicle registration plates or environmental elements at the inspection location may be incidentally captured in the inspection materials. The User conducting the Inspection Session must avoid capturing persons unrelated to the inspection and Personal Data that is not required for the inspection and is responsible for having the necessary legal basis to record and share the inspected object, its surroundings and related materials.
Purposes:
- to generate remote vehicle inspection reports;
- to confirm and evidence the authenticity and integrity of the inspection;
- to prevent and detect fraud, data falsification and manipulation;
- to use location data to assess whether the inspection is being conducted at the declared location of the vehicle and to prevent fraudulent manipulation;
- to handle complaints, claims and disputes;
- to protect the rights and legitimate interests of Users and other persons connected with the vehicle;
- to develop, test and improve automated inspection, fraud and risk detection, analytical and other systems used on the Platform.
Legal basis: performance of a contract and the legitimate interests of Prufio, the requesting User and other persons connected with the inspected vehicle or object in ensuring the reliability of the inspection, preventing fraud, resolving disputes, protecting their rights and improving systems used on the Platform.
Retention periods:
-
The Inspection Report and captured materials are available through a shared Report link to persons who have the link for 30 calendar days from the inspection submission date where the inspection is conducted in response to a buyer’s Inspection Request, or for 60 calendar days from the inspection submission date where the seller initiates an inspection of their own vehicle.
- Inspection Session data, including video and audio recordings, photographs, location data, device signals, vehicle identifiers, mileage, submitted responses, session metadata and the Inspection Report, may be retained for the purposes set out above for up to 10 years after the end of the Inspection Session. This maximum period has been determined, among other things, taking into account the general 10-year limitation period under the laws of the Republic of Lithuania.
Individual categories of data may be deleted or irreversibly anonymised earlier when they are no longer required for the purposes set out in this Policy or in accordance with Prufio’s internal data retention periods. Data may be retained for longer where necessary to comply with legal requirements, resolve a dispute, conduct an investigation, or establish, exercise or defend legal claims. Deleted media files cannot be restored.
Fully anonymised or aggregated data from which a natural person can no longer reasonably be identified, either directly or indirectly, may be retained for longer for analytics, security improvement and the development, testing and improvement of automated systems used on the Platform.
Use of inspection materials outside the Platform: we may use inspection materials for training, research, product demonstration, communications and marketing purposes only after taking measures to ensure that a natural person cannot reasonably be identified, either directly or indirectly. Depending on the materials, such measures include masking vehicle registration plates and other vehicle identifiers, blurring faces, removing or altering voices, removing visible documents and other identifying elements, and removing metadata. Original materials may be retained in our internal systems for the periods and purposes set out above.
4.4. Technical and Security Data
We process limited technical information, such as:
- IP address;
- device type;
- notification delivery identifiers assigned to the App on a particular device (push tokens);
- operating system version;
- App version;
- session duration;
- the App’s activity status during inspection recording;
- security, error and performance log data.
We use notification delivery identifiers to send service-related notifications to your device. These identifiers are linked to the relevant User.
Purpose: to ensure the security and functionality of the Platform, identify technical errors and prevent fraud, including by detecting abnormal session interruptions.
Legal basis: performance of a contract and Prufio’s legitimate interest in ensuring the security, integrity and proper operation of the Platform.
Retention period: technical and security logs may be retained for up to 2 years. The retention period for notification delivery identifiers depends on their validity and the need to deliver notifications.
4.5. Payment Data
Payments are processed by the payment service providers identified on the Platform, including Neopay. We receive:
- payment confirmation;
- transaction identifier (ID);
- payment amount;
- payer’s email address;
- other information necessary for accounting and payment administration.
We do not store full payment card numbers.
You may purchase services without creating an Account. In that case, you must provide an email address, which we collect and process to administer your purchase, provide the service and send related information. The legal basis for this processing is performance of a contract and, where the data is necessary to meet accounting or other legal requirements, compliance with legal obligations.
The email address is retained together with the related purchase and service data for the periods specified in this Policy for the relevant categories of data. You may exercise the rights described in Section 8 of this Policy even if you do not have an Account.
Purpose: to administer payments, purchases, invoices and refunds and to comply with accounting and tax requirements.
Legal basis: performance of a contract and compliance with legal obligations applicable to Prufio.
Retention period: payment and accounting data is retained for the period required by law, generally for up to 10 years, or longer where required by applicable law.
5. Sharing Personal Data
We may share Personal Data with:
- cloud hosting service providers, including Amazon Web Services (AWS);
- payment service providers, including Neopay;
- authentication service providers, including Apple and Google, when you use their sign-in methods;
- SMS and email delivery service providers where contact details are provided to deliver an Inspection Request or Inspection Code;
- technical infrastructure, analytics, security and fraud prevention service providers supporting the Platform;
- public authorities, courts, law enforcement authorities or other persons where disclosure is required by law or is necessary to establish, exercise or defend our or another person’s rights and legitimate interests.
- push notification delivery service providers, which receive notification delivery identifiers and the data necessary to deliver a notification
Service providers may process Personal Data only in accordance with our instructions, the agreements entered into with them and the purposes described in this Policy, except where they act as independent data controllers under applicable law.
The Inspection Report, including materials captured during the Inspection Session, is accessible to the requesting User or the User who initiated the inspection of their own vehicle and, during the Report availability period, to persons with whom its link is shared. Users may share Inspection Reports using links generated by the Platform and are responsible for deciding to whom they provide such links.
We do not sell Personal Data to third parties.
6. Automated Decision-Making
The Platform may perform automated analysis of Inspection Session data and generate inspection, location reliability, fraud or risk indicators. These indicators are informational. We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning Users or similarly significantly affect them.
7. International Data Transfers
Data is primarily processed within the European Union and the European Economic Area (EU / EEA). Where Personal Data is transferred to service providers or other recipients outside the EU / EEA, we apply appropriate safeguards under the GDPR, such as standard contractual clauses approved by the European Commission, an adequacy decision or other measures provided for by law.
8. Your Rights
Subject to applicable conditions and exceptions, you have the right to:
- access your Personal Data;
- request correction of inaccurate or incomplete data;
- request deletion of Personal Data where there is a legal basis to do so;
- request restriction of the processing of Personal Data;
- object, on grounds relating to your particular situation, to the processing of Personal Data based on legitimate interests;
- receive Personal Data you have provided in a structured, commonly used and machine-readable format and, where applicable, transmit it to another data controller;
- withdraw your consent at any time where data is processed on the basis of consent, without affecting the lawfulness of processing carried out before consent was withdrawn;
- lodge a complaint with a supervisory authority.
To exercise your rights, contact us at info@prufio.ravendev.lt. Before acting on your request, we may ask you to provide information necessary to verify your identity.
You also have the right to lodge a complaint with the State Data Protection Inspectorate: L. Sapiegos str. 17, LT-10312 Vilnius, Lithuania; email ada@ada.lt; website vdai.lrv.lt.
9. Data Security
We apply appropriate technical and organisational measures to protect Personal Data against unauthorised access, disclosure, alteration, loss, destruction or other improper use. However, no electronic system can guarantee absolute security.
10. Cookies
The Dashboard may use strictly necessary cookies required for the proper operation and security of the Platform. Analytics, tracking or marketing cookies are not used without the User’s consent where such consent is required by law.
11. Eligibility and Use by Minors
The Platform is intended for persons who are legally capable of entering into binding contracts under the laws applicable in their jurisdiction. By using the Platform, you confirm that you meet the age requirements applicable to you.
We do not knowingly collect Personal Data from persons who are not legally permitted to use the Platform. If we become aware that data relating to such a person has been collected, we will take appropriate steps to delete it.
12. Updates to this Policy
We may update this Policy. The updated Policy will state a new version number and effective date. Updates take effect when published on the Platform or on a later date specified in the Policy.