Introduction
To make your fleet-management work even simpler, Avrios includes intelligent, AI-supported features. They help you process documents automatically and structure your data better.
Because protecting your data is our top priority, this document explains openly which features are used, how they work technically, which data they process, and how we keep your data safe.
This document covers the following AI-supported features:
Post Office
Automated invoice capture
Digital fines desk
Smart driver's licence check
1. AI-supported features in the product
Our features work like a smart assistant that takes manual steps off your hands. Every result created by AI is clearly marked as such in the interface. Section 4.1 explains the details.
1.1 Post Office — receiving, structuring and filing documents
What it does
The Post Office is the central inbox for documents in Avrios. It receives documents,
automatically detects what type each one is, and suggests a structured name and a suitable
place to file it. The goal is to replace the manual sorting, naming and assigning of incoming
documents. You can reach the digital mail room through the upload interface in the web app, or
through the receiving email addresses we provide.
How it works
Receiving documents: documents can be uploaded through the web interface, the driver app, or a customer-specific email upload address ("Post Office").
Automated document processing: the system automatically reads relevant information such as document type, date and identification numbers (e.g. licence plates, invoice numbers, claim numbers).
Smart filing: based on the data it reads, the tool creates structured suggestions for sensible file names and categories, and for where the document belongs in your records.
Integrated claims management: new documents are checked against existing ones to avoid duplicates. The system also suggests creating new damage claims.
Human oversight: all results are only suggestions and must be actively confirmed by you before anything is saved.
Data processed
Document and metadata: document type, document date, file name, identification numbers (e.g. invoice, claim or case numbers).
Vehicle and assignment data: licence plate, vehicle identification number (VIN),
internal cost centre.
Contact information: name, address, email address, phone number, role — where they appear in the uploaded document and are needed to classify it.
Categories of data subjects: drivers, fleet managers, business partners
Post Office: the uploaded file is read by AI and the fields (document name, category) are pre-filled.
Post Office overview: uploaded documents with their AI categorization status.
1.2 Automated invoice reading — AI categorization in the mail room
What it does
This feature recognises uploaded invoices as invoices, categorises them, and files them under a clear name in the right place. It also reads the invoice contents and presents them as a suggestion for review. The invoice is only booked after the fleet manager confirms it.
How it works
Recognition and categorization: invoices uploaded to the mail room are recognised and categorised by AI. The automated invoice capture identifies the document as an invoice and files it, so it appears under a sensible name in the right place.
No automatic import of invoice data: the information in an invoice is not automatically taken into the system. The AI's suggestions for line items, amounts and the assignment to a vehicle or cost centre must be reviewed and confirmed by the fleet manager.
Human oversight: your team confirms the categorization and filing suggestion before anything is saved.
Data processed
Contact information: name, address, email address, phone number, role, other master and contact data.
Vehicle and assignment data: licence plate, VIN, personnel number, internal cost centre, invoice number.
Invoice information: amount, service/item.
Categories of data subjects: drivers, fleet managers, business partners
Starting invoice capture: choosing the import type in the "Add invoice" dialog.
Uploading an invoice as a PDF or image. The AI icon shows the AI support; alternatively, invoices can be sent to the customer-specific email upload address.
1.3 Digital fine reading — processing penalty notices
What it does
The digital fines desk turns incoming penalty notices into a structured fine record in the system.
The relevant fields are pre-filled, so you no longer have to type the details of the notice by hand.
Based on the identifiers provided (e.g. licence plate), the system also suggests the matching vehicle to make further handling easier.
How it works
Extraction and pre-filling: the system reads, extracts and structures data from penalty notices (e.g. offence, amount, date, licence plate, VIN) and pre-fills the matching fields of the fine record.
Manual driver assignment: the system does not work out who was driving. After the data is extracted, the responsible driver must be added manually by your team.
No transmission to authorities: no data can be sent to the issuing authority through Avrios. Communication with the authority happens outside the application. (The only exception is fleets in France, if the ANTAI connection has been enabled.)
Human oversight: the extracted data is only a suggestion. A fleet manager must review, complete and confirm it, and every field can be adjusted or overwritten.
Data processed
Document data: the penalty notice as an uploaded file (image or PDF).
Offence data: type of offence, date/time, location, fine amount, reference number, issuing authority.
Vehicle and assignment data: licence plate, VIN, internal cost centre.
Personal details in the notice: keeper and, where applicable, driver details (e.g. name, address), as listed in the notice.
Categories of data subjects: drivers, fleet managers
Uploading a penalty notice: the notice is uploaded as a PDF, JPG or PNG and assigned to an organisation.
Fines overview: for each uploaded fine, the status shows that the data has been read ("Data extracted").
Fine detail: the AI reads the uploaded document and pre-fills the fields. The note asks you to check the results (fictional sample document).
1.4 Smart driver's licence check
What it does
The smart driver's licence check reads the licence data directly from a photo of the licence. This means the driver no longer has to type the data in by hand during the check.
How it works
Reading from the photo: when the driver runs the check, Avrios reads the licence data (licence number, issue date, validity, country) directly from the photo taken.
Different technology: unlike the document-processing features above, the licence check uses an AI model that Avrios has developed and runs itself. For this, the licence photos are not sent to an external AI provider (see Section 2).
Consent and free choice: the reading only happens with the driver's explicit consent, which can be withdrawn at any time. If the driver does not give consent, entering the data manually is always available. The check can be completed either way.
Human oversight: the driver reviews and confirms the data that was read. The fleet manager then checks the images against a checklist and accepts or rejects the check. There is no automated decision about whether the licence is valid.
Data processed
Image data: photo of the driver's licence (front and, if needed, back).
Licence data: licence number, issue date, expiry date, country of issue.
Assignment data: linking the check to the driver profile in your customer account.
Categories of data subjects: drivers
Retention period: the licence files are only kept until the check is finished and are then deleted immediately (see Section 3).
2. Technology used
All the AI features described in Section 1 use the same technical method.
They use the large language model Gemini through a direct API connection. Specifically, the model Gemini 2.5 Flash is used. The model in use is, however, reviewed and adjusted regularly, so it may change in the future. Our direct contractual partner for providing this technology is Google Ireland Limited.
Processing and storage of the transmitted data for this service generally take place within the European Union. You can find more information in our list of sub-processors at shiftmove.com/legal/subprocessors.
3. Data flow: encryption, retention and output control
In line with our product standards, data transfers are encrypted with TLS 1.2+, and stored data is encrypted with AES-256. Whether you upload documents through the web interface, the driver app or by email, the original files are stored securely in our own cloud infrastructure (AWS S3 bucket — Frankfurt am Main).
For data extraction, the information needed is passed to the Gemini API through a secure interface. The exchange happens only as a short-lived "request-response" process (a request and a direct answer). The AI model does not store your data or documents after processing. The instructions we give the AI for processing (called prompts) also stay entirely in our hands and are documented in our internal system.
3.1 Zero data retention — no data kept at the AI provider
The connection to the external language model runs in a mode without data retention ("zero data retention"). The content sent — the instruction (prompt), the document content to be analysed, and the model's answer — is processed only for the length of that request and is deleted once the answer is delivered. It is not stored.
In concrete terms, this means:
No persistence: the content is neither stored permanently nor cached for logging, analysis or training.
No inspection: the provider's staff do not view the content that is sent.
Statelessness: each request is handled on its own, with no link to earlier requests (stateless).
The processing therefore ends with the answer. The original documents are stored permanently only in our own infrastructure described above, and they stay under your control.
3.2 Strict checking of the model output by our systems
The language model is not run as a freely chatting component. It is used only as a clearly limited extraction step with an output format that is fixed in advance ("structured output"). For each use case, a schema defines exactly which fields are allowed and what data types they have (for example document type, date, licence plate or amount).
Every answer from the model is checked against this schema by our systems before it is used further. Answers that do not match the schema, or that contain fields outside the defined allow-list, are discarded and never reach the application. Free text outside the intended fields is
not accepted.
This gives an important security benefit: there is no channel through which the model could be used as a general query tool. Even if an uploaded document contains manipulated instructions (prompt injection, see Section 4), the model cannot leave the set output structure. This effectively blocks any targeted query for arbitrary information through the model's answer; at most, a successful attack could influence the values inside the fields that are intended anyway, and those are then checked during the human review.
4. Protecting personal data (privacy by design)
To protect data proactively, we have built in wide-reaching safeguards. For example, the document-processing model is told to actively ignore and leave out personal data while reading, whenever that data is not needed for the specific file.
On top of that, every use of AI features follows the "human-in-the-loop" principle: the AI only acts as an assistant and makes no decisions on its own. All suggestions for file names, folder structures, damage claims or licence data must always be confirmed manually by you before any action is carried out in our system. The AI model has no write access to our databases and is technically prevented from changing content stored in Avrios on its own.
4.1 Transparency by labelling AI-generated results
Another part of the privacy-by-design approach is labelling machine-generated content consistently. Every result created by AI is clearly marked in the interface — with the AI icon ("magic sparkle") and a short text note. This lets you see at any time which field values come from automated reading and which were entered by hand.
AI icon:
This transparency is also what makes an effective human review possible: only when you can see that a value was suggested by a model can you check it properly. The labelling happens whether the suggestion is then accepted, adjusted or discarded.
4.2 Protection against prompt injection
When processing documents that come from third parties, we have to consider so-called indirect prompt injections. Here, hidden instructions are placed inside a document's content to try to manipulate how the language model behaves. We are aware of this risk and address it directly when designing and running the AI features. Several measures work together to guard against it:
The provider's protection mechanisms: we use the protection and filtering that Google provides at the platform level for the Gemini API, especially the safety filters and the hardening of the system instructions against incoming content.
Separating instruction from content: the processing instructions are defined,
versioned and documented only by Avrios. Document contents are given to the model as data to be analysed, not as instructions to be carried out.
Limiting the output: because of the schema-bound output format (see Section 3.2), a successful injection could at most influence individual field values. Leaking extra information through the model's answer is not possible.
Minimal permissions: the model has no access to databases, user accounts or other system functions and cannot trigger any actions in the application. It only processes the content handed to it for that specific request.
Human control: because every result must be confirmed before it is accepted, unlikely or unusual extraction results are caught and corrected during the review step.
We assess how well these measures work on an ongoing basis, as part of the regular review of the models and prompts we use, and adjust them where needed.
5. Using your data: no AI training, error fixing only with your consent
We guarantee that no "fine-tuning" or training of the AI models takes place with your customer data. To make sure the AI gives correct, high-quality results, we internally use a strictly separate, standardised set of reference data for quality control.
5.1 Error analysis during operation (live deployment improvement)
This is different from fixing specific errors during operation. If you report an error or a faulty processing result to us, reproducing and analysing it usually requires knowing the exact request involved. The data of that specific request — the document concerned and the related model output — may therefore be used, after your error report, to prepare, analyse and fix the reported error.
6. Full control and opt-out options
You keep full control over your processes at all times. If you wish, the AI features can be switched off for your system, so you can also use the filing function purely manually as before. The only current exception is fines and invoices, which are processed purely on an AI basis. For quality assurance and to speed up processing time, these features have been fully switched to AI-supported methods.
7. Further legal information
We place great value on transparency. You can find more details about how we process data, and
a complete overview of our service providers, at any time in our legal documents:
Overview of our sub-processors: https://www.shiftmove.com/legal/subprocessors
Our full privacy policy: https://www.shiftmove.com/legal/datenschutzerklarung









