X3 DOT Audit
Privacy Policy

Privacy Policy

X3 DOT Audit · Effective August 13, 2026 · Operated by X3 Fleet Safety LLC

X3 Fleet Safety LLC ("X3," "we," "us") provides fleet-safety and U.S. Department of Transportation (DOT) compliance software, including X3 Compass and the related X3 products (the "Services"). This Policy explains how we handle personal information in connection with the Services and our websites.

Because our customers are motor carriers and employers, most personal information we process is driver and applicant data that a customer submits to run its own compliance program. For that data the customer is the controller (or "business"), and X3 acts as a processor / service provider under the customer's instructions and our Data Processing Addendum (DPA). For account, billing, and website data, X3 is the controller.

1. Scope and roles

2. Information we collect

Account and billing: name, business email, company, role, and payment information (processed by our payment processor; we do not store full card numbers).

Regulated driver / applicant data submitted by customers, which may include: identifiers (name, date of birth, Social Security number, driver-license number, state, and class); background and consumer-report information governed by the Fair Credit Reporting Act (FCRA); motor-vehicle-record (MVR) data governed by the Driver's Privacy Protection Act (DPPA); DOT drug-and-alcohol testing information governed by 49 CFR Part 40 Subpart P; medical-examiner certification status; hours-of-service (HOS) and electronic-logging-device (ELD) records; and driver-qualification (DQ) file documents.

Integration data: records X3 receives, at the customer's direction, from third-party ELD, applicant-tracking, screening, and MVR providers connected by the customer.

Website and usage data: privacy-focused, cookieless analytics and server logs; support communications.

3. How we use information

We do not sell personal information. We do not use customer, driver, or applicant data to train artificial-intelligence models, and we contractually require the same of our AI sub-processor.

4. Artificial-intelligence processing

Certain features use a third-party large-language-model provider to extract, classify, and analyze documents (for example, background and MVR review). We are implementing data-minimization so that regulated identifiers and Part 40 testing content are minimized or redacted before any external processing, and we process regulated data with this provider only under a written agreement providing zero data retention with the G4 determination (redaction-first Option A/B/C).]

5. Sub-processors and disclosure

We share personal information with vetted service providers who process it on our behalf under written contracts. Categories include cloud hosting and storage, database and vector storage, the AI provider described above, background and MVR providers, carrier-data providers, payment processing, and privacy-focused analytics, plus the ELD / applicant-tracking / screening integrations a customer connects. Our current Sub-processor List is maintained in, and incorporated by reference from, our DPA.

6. Regulated-data commitments

FCRA. Background information is consumer-report data used only for permissible purposes; the customer is responsible for obtaining the standalone disclosure and written authorization and for following adverse-action procedures.

DPPA. MVR data is used only for a permitted use under 18 U.S.C. 2721(b); we maintain records of redisclosure as required by 2721(c).

49 CFR Part 40 Subpart P. DOT testing information is treated as confidential and released only to authorized recipients consistent with specific written consent requirements.

7. Retention and disposal

We retain personal information only as long as necessary to provide the Services and to meet legal obligations. Where the FTC Safeguards Rule applies, we securely dispose of customer information no later than two years after the last date it was used, unless a longer period is required by law (for example, DQ-file and testing-record retention rules) or reasonably necessary for a legitimate business purpose. bases.]

8. Security

We maintain administrative, technical, and physical safeguards including encryption in transit and at rest, access controls, multi-factor authentication, logging and monitoring, and vendor oversight. See our Trust & Security Overview for detail.

9. Your choices and rights

Driver and applicant requests to access, correct, or delete regulated data are generally directed to the customer that submitted it (the controller); we assist customers in responding. Depending on your state, you may have rights under laws such as the CCPA/CPRA and other U.S. state privacy laws. We do not sell or share personal information for analysis and any required "Do Not Sell or Share" mechanism; state-law rights matrix (TX, VA, CO, and others).]

10. International transfers

The Services are intended for U.S. motor carriers and their data. 27 representative and named transfer mechanism (EU SCCs 2021 / UK IDTA).]

11. Children

The Services are for business use and are not directed to children under 13, and we do not knowingly collect their personal information.

12. Changes

We may update this Policy and will revise the "last updated" date; material changes will be communicated through the Services.

13. Contact

Not legal advice · Not an FMCSA determination. X3 DOT Audit is compliance decision-support software provided by X3 Fleet Safety LLC. It is not a law firm, does not provide legal advice, and is not affiliated with FMCSA, USDOT, or any government agency. Always verify against the current, controlling regulation.

← Back to X3 DOT Audit  ·  Questions? joshua@x3fleetsafety.com