Trust & compliance
A repair shop trusts us with its customers, cars and money. Here is a short, honest account of who we are, where the data lives and how we protect it. Technical detail is on the security page.
What we stand on
CarsEXP is built and operated by GBO Eesti OÜ. Contracts, invoices and liability follow European Union law.
The platform and its backups live in EU data centres. Data is not transferred outside the EU.
Shop data is isolated at both the application and database level (row-level security). One shop never sees another shop’s customers.
Smart-ID, Mobiil-ID, passkeys (WebAuthn) and one-time codes. We do not build password-leak risk into the system.
Significant changes — invoices, prices, permissions, customer data — stay in the log: who, what, when.
Invoices follow the European e-invoicing standard EN 16931 with Peppol readiness; multi-rate VAT and exact money arithmetic.
Personal data
Customer personal data (name, contacts, vehicle details) is encrypted in the database and processed only to deliver the shop’s service. The shop is the data controller and CarsEXP the processor; the terms are in the data processing agreement (DPA).
The AI inside the platform does not invent numbers: answers are built from the shop’s own data and cite their source.
If something happens
In case of a security incident we notify affected shops and the supervisory authority within GDPR deadlines. Security researchers: please report findings the way the security page describes.