Data Processing Addendum (DPA)
For customers who require a formal controller–processor agreement
1. Introduction
This Data Processing Addendum ("DPA") forms part of the agreement between Fleetmio ("Processor") and the Customer ("Controller") regarding the provision of fleet management and telematics services ("Services"). This DPA governs Fleetmio's processing of Personal Data on behalf of the Customer.
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on Personal Data, including collection, storage, transmission, or deletion.
- Controller: The entity determining the purposes and means of processing Personal Data.
- Processor: The entity processing Personal Data on behalf of the Controller.
- Sub-processor: A third party engaged by Fleetmio to process Personal Data.
3. Roles and Responsibilities
- The Customer acts as the Controller.
- Fleetmio acts as the Processor and will process Personal Data only on documented instructions from the Customer.
4. Types of Data Processed
Fleetmio may process the following categories of data on behalf of the Customer:
- Driver identification information
- Vehicle and asset identifiers
- GPS location and telematics data
- Maintenance, inspection, and operational records
- User account information
5. Purpose of Processing
Fleetmio processes Personal Data solely to:
- Provide and maintain the Services
- Support analytics, reporting, and operational insights
- Ensure security, fraud prevention, and service reliability
- Comply with legal obligations
Fleetmio will not process Personal Data for any purpose other than those documented by the Customer.
6. Sub-processors
Fleetmio may engage Sub-processors for:
- Cloud hosting
- Data storage
- Analytics
- Customer support
- Payment processing
Fleetmio ensures all Sub-processors are bound by written agreements providing data protection obligations no less protective than this DPA.
7. Security Measures
Fleetmio implements industry-standard security controls, including:
- Encryption in transit and at rest
- Role-based access controls
- Multi-factor authentication
- Network monitoring and logging
- Regular vulnerability assessments
8. International Transfers
If Personal Data is transferred outside the Customer's jurisdiction, Fleetmio will implement appropriate safeguards such as:
- Standard contractual clauses
- Contractual protections
- Industry-standard security measures
9. Data Subject Rights
Fleetmio will assist the Customer in responding to requests from data subjects, including:
- Access
- Correction
- Deletion
- Restriction
- Portability
Requests from Authorized Users will be directed to the Customer.
10. Data Breach Notification
Fleetmio will notify the Customer without undue delay upon becoming aware of a Personal Data breach affecting Customer data.
11. Data Retention & Deletion
Upon termination of the Services, Fleetmio will:
- Delete or return Personal Data at the Customer's request
- Retain data only where legally required
12. Audit Rights
Fleetmio will make available documentation necessary to demonstrate compliance and allow audits by the Customer or an independent auditor.
13. Term
This DPA remains in effect for the duration of the Customer's use of the Services.