Trust & compliance

A repair shop trusts us with its customers, cars and money. Here is a short, honest account of who we are, where the data lives and how we protect it. Technical detail is on the security page.

What we stand on

🇪🇪
An Estonian company

CarsEXP is built and operated by GBO Eesti OÜ. Contracts, invoices and liability follow European Union law.

🗄️
Data in the European Union

The platform and its backups live in EU data centres. Data is not transferred outside the EU.

🧱
Every shop isolated

Shop data is isolated at both the application and database level (row-level security). One shop never sees another shop’s customers.

🔐
Strong sign-in

Smart-ID, Mobiil-ID, passkeys (WebAuthn) and one-time codes. We do not build password-leak risk into the system.

📜
Audit trail

Significant changes — invoices, prices, permissions, customer data — stay in the log: who, what, when.

🧾
E-invoices and VAT

Invoices follow the European e-invoicing standard EN 16931 with Peppol readiness; multi-rate VAT and exact money arithmetic.

Personal data

Customer personal data (name, contacts, vehicle details) is encrypted in the database and processed only to deliver the shop’s service. The shop is the data controller and CarsEXP the processor; the terms are in the data processing agreement (DPA).

The AI inside the platform does not invent numbers: answers are built from the shop’s own data and cite their source.

If something happens

In case of a security incident we notify affected shops and the supervisory authority within GDPR deadlines. Security researchers: please report findings the way the security page describes.

Documents