Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between {COMPANY_LEGAL_NAME} ("Processor", "we") and the garage business using {PRODUCT_NAME} ("Controller", "you"). It applies whenever we process personal data of your customers on your behalf. Terms not defined here have the meaning given in UK GDPR.
1. Roles
You are the controller of your customers' personal data. We are the processor, acting only on your documented instructions as set out in this DPA and the Terms of Service, including instructions given through your use of the Service's features (e.g. uploading a customer list, approving a campaign).
2. Subject matter, duration, and purpose
- Subject matter: processing of your customers' personal data to generate vehicle service/advisory insights and to send SMS/email campaigns to those customers on your behalf and under your brand.
- Duration: for as long as your {PRODUCT_NAME} subscription is active, plus any retention period agreed in Section 9.
- Nature and purpose: collection, storage, lookup against DVSA/DVLA vehicle records, insight generation, and message sending (SMS/email), all solely to provide the Service to you.
3. Categories of data and data subjects
- Data subjects: your customers (individuals whose vehicles you service).
- Categories of data: name, phone number, email address, vehicle registration number, vehicle MOT/advisory history retrieved via DVSA/DVLA, campaign message content, and delivery/opt-out status (including permanent suppression records for "STOP" requests).
We do not knowingly process special category data through the Service. You must not upload special category data (e.g. health data) into customer records.
4. Our obligations
We will:
- process personal data only on your documented instructions, including instructions reflected in the Service's features, unless required otherwise by law (in which case we will tell you before processing, unless the law prohibits this);
- ensure our staff and contractors who access the data are bound by confidentiality obligations;
- implement the security measures in Section 5;
- assist you in responding to data subject requests and in meeting your own UK GDPR obligations (Section 6);
- notify you of a personal data breach without undue delay (Section 7);
- delete or return data on termination (Section 9);
- make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits (Section 10).
5. Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- encryption of personal data in transit (TLS) and at rest;
- role-based access controls limiting internal access to customer data on a need-to-know basis;
- permanent suppression lists so opted-out contacts cannot be re-contacted;
- logging and monitoring of access to production data;
- regular review of sub-processor security as part of onboarding (Section 8).
6. Data subject requests
If we receive a request from one of your customers relating to their personal data (e.g. an access or deletion request), we will promptly forward it to you and will not respond directly except to confirm receipt and redirect the requester to you, unless you instruct us otherwise. We will provide reasonable assistance to help you respond within the statutory timeframe.
7. Personal data breaches
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your customers' data. The notification will include, to the extent known: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address it. We will cooperate with you in any resulting notification to the ICO or affected individuals, which remains your responsibility as controller.
8. Sub-processors
You give general authorisation for us to engage the sub-processors listed in our Sub-processors page, which is incorporated by reference. We will:
- keep that list current and flag it as indicative where sub-processors may change;
- give you at least {14} days' notice of any new sub-processor or replacement, during which you may object on reasonable data protection grounds;
- impose data protection obligations on each sub-processor no less protective than this DPA;
- remain liable for each sub-processor's performance.
9. Deletion and return on termination
On termination or expiry of your subscription, we will delete all personal data of your customers within {30} days, unless we are required by law to retain it, or unless you request return of the data in an exportable format before deletion (which we will provide on reasonable request made before the deletion deadline). This mirrors the account closure deletion commitment in our Privacy Policy.
10. Audit rights
On reasonable written notice (at least {30} days), and no more than once per 12-month period (unless required by a regulator or following a breach), you may audit our compliance with this DPA, or request a summary of a recent third-party audit/ certification in lieu of a direct audit. Reasonable costs of an on-site or direct audit are borne by you, except where the audit identifies a material breach of this DPA, in which case we bear our own costs.
11. International transfers
Where personal data is transferred outside the UK, the parties will enter into the UK International Data Transfer Agreement (IDTA) or rely on the UK Addendum to the EU Standard Contractual Clauses, as applicable, the terms of which are incorporated by reference and will be annexed to this DPA as Annex 3 once finalised.
12. Liability
Liability under this DPA is subject to the limitation of liability in the Terms of Service.
Last updated: {DATE}