FleetVerified
Privacy & Legal Centre / Data Processing Agreement

Data Processing Agreement

Version 1.0.0 · In effect from 7 August 2026 · Forms part of the agreement

The Article 28 agreement between the operator as controller and the platform provider as processor, including the processing schedule and sub-processor schedule.

Contents

  1. 1. Scope and order of precedence
  2. 2. Roles of the parties
  3. 3. Processing instructions
  4. 4. Confidentiality of personnel
  5. 5. Security measures
  6. 6. Sub-processors
  7. 7. International transfers
  8. 8. Data subject requests
  9. 9. Personal data breach
  10. 10. DPIAs and prior consultation
  11. 11. Deletion and return on termination
  12. 12. Audit and information rights
  13. Schedule 1 — Details of the processing
  14. Schedule 2 — Sub-processors
  15. Acceptance

1. Scope and order of precedence

This agreement is made between the operator ("Controller") and FleetVerified ("Processor") and forms part of the Terms of Service for FleetVerified. It applies whenever the Processor processes personal data on the Controller's behalf. In the event of conflict about the processing of personal data, this agreement prevails over the Terms of Service.

"Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR, in each case as amended or replaced. Terms such as controller, processor, personal data, processing, personal data breach and data subject have the meanings given in that law.

2. Roles of the parties

The Controller determines the purposes and means of processing the personal data it and its authorised users place in the service, and warrants that it has a lawful basis for doing so and has given the required information to the individuals concerned. The Processor processes that personal data only on the Controller's behalf.

The Processor acts as an independent controller for a limited set of data it decides about itself — account identity, security and abuse-prevention records, billing records and service communications with administrators. That processing is governed by the Processor's privacy notice, not by this agreement.

3. Processing instructions

The Processor will process personal data only on the Controller's documented instructions, including on international transfers, unless required to do otherwise by law — in which case it will inform the Controller first, unless that law prohibits it on important grounds of public interest.

The Controller's documented instructions consist of this agreement, the Terms of Service, the configuration the Controller sets in the service (roles, access, retention settings, inspection regimes, notification settings), and the actions its authorised users take in the service. Further instructions outside this scope may attract a reasonable charge, and the Processor will say so before acting.

The Processor will tell the Controller promptly if, in its opinion, an instruction infringes Data Protection Law, and may suspend that instruction until it is resolved.

4. Confidentiality of personnel

The Processor ensures that everyone it authorises to process the personal data is subject to a binding duty of confidence, is trained appropriately, has access strictly limited to what their role requires, and has that access logged and reviewed. Access is removed promptly when it is no longer required.

5. Security measures

Taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to individuals, the Processor implements appropriate technical and organisational measures, including at least:

  • encryption of personal data in transit (TLS) and at rest;
  • tenant isolation enforced at database level by row-level security, so that one operator's queries cannot reach another operator's rows;
  • role-based access control evaluated on the server on every request, never trusted from the browser;
  • mandatory two-step verification for privileged roles, sign-in throttling and account lockout;
  • short-lived signed URLs for evidence and document downloads, with no public object storage;
  • an append-only audit trail that records who changed what, when and why, and which administrators cannot alter;
  • separation of production from development environments, and least-privilege service credentials;
  • backups with tested restoration, and monitored scheduled processing with watchdog alerting;
  • vulnerability management, dependency scanning and prompt patching;
  • documented incident response and business continuity procedures.

The Processor may update these measures provided the level of protection is not reduced. The current position is described in the published security overview.

6. Sub-processors

The Controller gives general written authorisation for the Processor to engage sub-processors. The current schedule (version 2026-08-01) is published in the legal centre and is maintained centrally so it is always current.

The Processor will give at least 30 days' notice before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds within that period; the parties will work in good faith to find a solution and, failing one, the Controller may terminate the affected part of the service without penalty for the remainder of the paid period.

Each sub-processor is engaged under a written contract imposing data protection obligations equivalent to those in this agreement, and the Processor remains fully liable to the Controller for the sub-processor's performance.

7. International transfers

Personal data is hosted at rest in the European Union (Ireland). Where personal data is transferred outside the UK, the Processor ensures a lawful transfer mechanism is in place — UK adequacy regulations, or the EU Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum — supported by a transfer risk assessment and supplementary technical measures. The mechanism for each sub-processor is stated in the schedule.

8. Data subject requests

The Processor will not respond to a data subject request relating to the Controller's data itself, except to direct the individual to the Controller. Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, so far as possible, in fulfilling requests for access, rectification, erasure, restriction, portability and objection.

In practice the service itself provides much of this assistance: authorised administrators can search and correct records, end a person's access while preserving attributable history, and run a full operator-scoped export without contacting the Processor. Where a request cannot be satisfied in-product, the Processor will assist within a reasonable time and will forward any request it receives directly to the Controller without undue delay.

9. Personal data breach

The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's personal data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — provided in stages if not all of it is known at once.

The Processor will assist the Controller with its own obligations to notify the ICO and affected individuals, and will not make a public statement identifying the Controller without the Controller's prior written agreement unless legally required.

10. DPIAs and prior consultation

The Processor provides reasonable assistance to the Controller with data protection impact assessments and any prior consultation with the ICO, taking into account the nature of the processing and the information available to the Processor. A standard information pack describing the processing, security measures and sub-processors is available on request to support a DPIA.

11. Deletion and return on termination

The Controller may export a complete, machine-readable copy of its data at any time using the self-service export. On termination the export remains available for at least 30 days, and the account closure workflow includes a 30-day cooling-off period during which closure can be cancelled.

After that period the Processor deletes or anonymises the personal data in accordance with the published retention matrix, and procures that its sub-processors do the same, except to the extent that UK law requires storage to continue — which includes compliance evidence, audit trails and security records held for the periods stated in the matrix. Data retained on that basis remains subject to the security and confidentiality obligations of this agreement and is not processed for any other purpose. Backups age out on their ordinary cycle.

The Processor will confirm completion of deletion or anonymisation in writing on request.

12. Audit and information rights

The Processor makes available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates.

Audits are limited to once in any 12-month period unless a personal data breach or a regulator requires otherwise, require at least 30 days' written notice, take place during business hours, must not unreasonably disrupt the Processor's business, must not compromise other customers' confidentiality or the security of the service, and are subject to confidentiality. The Processor may satisfy an audit request in the first instance by providing current security documentation, penetration test summaries and independent certifications where held.

The service additionally gives the Controller a permanent audit trail of activity within its own workspace, which the Controller may inspect at any time without notice to the Processor.

Schedule 1 — Details of the processing

ItemDetail
Subject matterProvision of the FleetVerified fleet compliance platform to the Controller
DurationFor the term of the Terms of Service, plus the retention periods in the retention matrix
Nature of processingCollection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission to authorised users, restriction, erasure and destruction, all by automated means
PurposesRecording and evidencing fleet compliance: driver walkaround checks, defect reporting and rectification, vehicle and trailer records, documents and expiries, preventative maintenance and inspection planning, workshop job cards and repairs, quality control and return-to-service decisions, alerts and reminders, evidence packs for DVSA or a Traffic Commissioner, and administration of users and access
Categories of data subjectThe Controller's employees, workers and contractors, including drivers, technicians, workshop staff, Transport Managers, compliance staff and administrators; staff of external maintenance providers the Controller invites; named contacts recorded on documents and job cards
Categories of personal dataIdentity and contact data (name, work email, phone, job title); employment and role data (role, permissions, operating centre, membership dates); activity data (checks completed, defects raised, repairs carried out, labour time, declarations and sign-offs); free-text notes entered by users; images and signatures (defect and repair photographs, signature captures); technical and security data (IP address, device and browser information, sign-in and two-step verification events)
Special category dataNone requested or required. The Controller must not enter special category data and is responsible if its users do so contrary to this agreement
Criminal offence dataNone requested or required
Frequency of transferContinuous, for the duration of the agreement
RetentionAs set out in the published retention matrix, which distinguishes operational records, statutory compliance evidence, security records, audit trails and operator-configurable periods

Schedule 2 — Sub-processors

The authorised sub-processor list is published and maintained centrally in the legal centre (schedule version 2026-08-01). That published list forms Schedule 2 to this agreement and is updated in accordance with clause 6.

Acceptance

This agreement is accepted electronically when an authorised person accepts the Terms of Service on behalf of the operator. The acceptance record — user, operator, document versions, date, time and originating address — is stored permanently and cannot be altered. A countersigned paper copy is available on request from privacy@fleetverified.co.uk.

Other documents

  • Privacy Notice
  • Terms of Service
  • Cookie and On-Device Storage Notice
  • Sub-processors
  • Security Overview
  • Data Retention Overview