| Independent no-logs / navigation telemetry audit | ❌Not foundNo public independent audit of WeGo consumer location telemetry found; privacy claims rest on policy text (offline mode, random identifiers). | ⚠️PartialVendor claims journey location is not linked to accounts, not sold, and re-identifying data is erased within 24h after shutdown. No independent public no-logs audit PDF specific to GO Expert was found. |
|---|
| ISO 27001 | ⚠️Vendor claimedHERE certifications page asserts ISO/IEC 27001:2022 (and related 27017/27018) with Schellman certificate references. Confirm scope covers services you use. | ⚠️Vendor claimedTomTom safety page claims ISO/IEC 27001:2022 with downloadable registration certificate PDF. Confirm certificate scope vs GO Expert processing systems. |
|---|
| SOC 2 / SOC 3 | ⚠️Vendor claimedHERE states SOC 2 Type 2 for HERE Platform Foundation and Workspace—not clearly scoped to consumer WeGo alone. | ❌Not foundNo public SOC 2/3 report for the consumer GO Expert app found in this research pass. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedEU controller HERE Global B.V.; GDPR programme and Type 1 attestation described on certifications page. Consumer rights and lawful bases detailed in WeGo privacy supplement. | ⚠️Vendor claimedDutch EU controller; detailed GDPR privacy notices, DPO, data-subject rights, and consent for location/journey data. Not a legal compliance certification. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity / no known single US parent, but AWS and Azure listed with United States processing locations; US SaaS subprocessors and Intel shareholding add US nexus. Offline use reduces device telemetry to HERE. Indicative only—not legal advice. | ⚠️PartialEU entity / no known US parent, but public subprocessors include AWS EMEA SARL, Microsoft Ireland, and US-headquartered SaaS (Zendesk, Airship, Atlassian cloud) plus TomTom North America Inc. affiliate. Medium exposure. Not legal advice. |
|---|
| Data processing agreement (B2B) | ❌Not foundConsumer WeGo is under personal Service Terms; no public self-serve DPA for the free app located. Enterprise/platform customers should request HERE commercial DPA separately. | ⚠️PartialPrivacy pages reference DPAs/SCCs for transfers and processor arrangements; self-serve B2B DPA package for individual GO Expert consumers not found. Fleet/enterprise buyers should request terms via TomTom sales. |
|---|
| EU AI Act | —Not applicableConsumer navigation app; HERE separately markets ISO/IEC 42001 for corporate AI management—not treated as AI-system primary product here. | —Not applicableConsumer/professional GPS navigation app; not marketed as a high-risk AI system product in materials reviewed. |
|---|
| TISAX (automotive) | ⚠️Vendor claimedHERE claims TISAX AL3 assessment (Scope ID S0H13Y) on certifications page—relevant for automotive supply-chain trust more than consumer app downloaders. | ⚠️Vendor claimedTomTom states successful TISAX assessment for automotive-industry information security; details via ENX portal. |
|---|
| ISO 27018 (PII in public cloud) | No indicado | ⚠️Vendor claimedVendor claims ISO/IEC 27018:2019 with downloadable certificate for PII processor role in public clouds. |
|---|