EATIN MONACO — DRIVER APP
Version 1.0 — 8 June 2026
1. Introduction
This Privacy Policy describes how EATIN SARL collects, uses, stores and protects the personal data of employees using the EATIN MONACO driver application.
The driver application is a professional tool reserved for authorised EATIN employees.
Data is processed in connection with the organisation of work, the management of deliveries, the security of the service, the protection of customers and the proper performance of the duties entrusted to employees.
2. Data Controller
The data controller is:
EATIN SARL
RCI Monaco: 19S08113
Registered office: 47 Avenue Hector Otto, 98000 Monaco
Contact:
Email: info@eatin.mc
Telephone: +377 97 77 12 32
3. Data Collected
EATIN may collect and process the following data concerning salaried drivers.
3.1 Professional identification data
- last name
- first name
- employee ID
- professional or personal email address used for the service
- telephone number
- login credentials
- role or function
3.2 Application usage data
- login times
- logout times
- availability statuses
- orders assigned
- orders accepted or handled
- delivery statuses
- pickup confirmations
- delivery confirmations
- reported incidents
- exchanges with support
3.3 Professional geolocation data
When the application is used during working hours, EATIN may process geolocation data to enable the proper functioning of the service.
This data may include:
- approximate or precise position during service
- operational route
- position at the time an order is assigned
- position at pickup
- position at delivery
- data required to manage an incident or dispute
3.4 Technical data
- IP address
- device type
- operating system
- application version
- technical identifiers
- connection logs
- error reports
- security data
3.5 Incident-related data
- accidents
- significant delays
- customer disputes
- delivery problems
- reports
- internal declarations
- information required for disciplinary or legal management where applicable
4. Purposes of Processing
The data is used to:
- enable access to the application
- assign orders
- organise deliveries
- track the performance of duties
- optimise routes
- ensure the safety of drivers
- ensure the safety of customers
- handle incidents
- prevent fraud
- protect customer data
- monitor compliance with internal procedures
- manage disputes
- document the proper performance of the service
- provide technical maintenance
- comply with EATIN’s legal and social obligations
5. Legal Bases
Processing may rely on:
- performance of the employment contract
- EATIN’s legitimate interest in organising, securing and monitoring its activity
- compliance with legal obligations
- the need to protect the rights, safety and interests of EATIN, its employees, its customers and third parties
Where consent is required by applicable regulations, it will be obtained separately.
6. Driver Geolocation
Geolocation is used exclusively in a professional context.
Its purposes are:
- efficient assignment of orders
- optimisation of the service
- driver safety
- management of delays
- management of incidents
- proof of delivery
- protection against fraud
- improvement of operational organisation
Geolocation must not be used for any purpose unrelated to the service.
Except where specifically necessary — incident, dispute, safety or legal obligation — geolocation is not intended to be used outside working hours or when the employee is not connected to the driver application.
The employee must log out of the application at the end of their service, unless otherwise justified by instruction.
7. Customer Data Visible to Drivers
To carry out their duties, the driver may access certain customer data necessary for delivery.
This data may include:
- first name
- delivery address
- delivery instructions
- telephone number if necessary
- order information useful for handover
This information must be used only for the relevant delivery.
It must never be copied, retained, transmitted, photographed, published, reused or used for personal purposes.
Any misuse of customer data may lead to disciplinary measures and legal proceedings.
8. Confidentiality and Security
EATIN implements measures designed to protect the data processed through the driver application.
Employees must themselves contribute to this security, in particular by complying with the following rules:
- do not share login credentials
- lock their phone
- do not leave the application open and unattended
- do not take screenshots of customer data
- do not transmit information via personal messaging
- immediately report any loss, theft or suspicious access
- comply with internal security instructions
- use only the channels authorised by EATIN
9. Data Recipients
Data may be accessible, as needed, to the following persons or departments:
- EATIN management
- operational managers
- support
- technical department
- HR department
- technical service providers
- hosting providers
- competent authorities where required by law
- legal counsel, insurers or experts in the event of a dispute or incident
Data is disclosed only to persons who need access in the course of their duties.
10. Technical Service Providers
The application may use technical service providers for hosting, maintenance, security, notifications, technical analytics or incident management.
These providers act on EATIN’s instructions and must implement appropriate security measures.
11. International Transfers
Some data may be processed outside Monaco or outside the European Union by technical service providers.
Where such transfers occur, EATIN implements the appropriate safeguards provided for by applicable regulations.
12. Retention Periods
Data is retained for a period proportionate to the purposes pursued.
By way of indication:
- employee account data: duration of the employment contract, then archiving in accordance with legal obligations
- operational delivery data: up to 24 months, except in the event of a dispute or specific obligation
- operational geolocation data: a limited period necessary for organising the service and managing disputes
- technical and security logs: up to 24 months
- data related to an incident, dispute, accident, fraud or disciplinary procedure: the period necessary to handle the matter and defend EATIN’s rights
Some data may be retained longer where required by law or where a dispute is ongoing.
13. Employee Rights
In accordance with applicable regulations, the employee may exercise their rights over their personal data, in particular:
- right of access
- right of rectification
- right of erasure where applicable
- right to restriction
- right to object where applicable
- right to information
Any request may be sent to: info@eatin.mc
EATIN may request identity verification before responding to a request.
Certain requests may be limited where the data is necessary for the performance of the employment contract, compliance with a legal obligation, safety, fraud prevention or the defence of EATIN’s rights.
14. Data Breach
In the event of a security incident likely to affect personal data, EATIN will take the necessary measures in accordance with applicable regulations.
The employee must immediately report any actual or suspected incident, in particular:
- lost or stolen phone
- unauthorised access
- accidental screenshot
- sending information to the wrong recipient
- unintentional disclosure
- a bug exposing data
- a hacking attempt
15. Changes to the Policy
EATIN may amend this Policy to reflect changes in the application, its tools, its organisation or applicable regulations.
Employees will be informed of changes by any appropriate means.
16. Governing Law
This Policy is governed by Monegasque law, subject to any applicable mandatory rules.