Data Processing Agreement
The Article 28 terms on which we process personal data for an operator using Truckzly — what we may do with it, who else touches it, and what we owe you if something goes wrong.
In effect from
Contents
- 1. Scope and roles
- 2. Subject matter, duration, nature and purpose
- 3. Categories of data subject and personal data
- 4. Truckzly's obligations
- 5. Security measures
- 6. Sub-processors
- 7. International transfers
- 8. Assisting with data subject rights
- 9. Personal data breaches
- 10. Impact assessments and prior consultation
- 11. Return and deletion
- 12. Information and audit
- 13. Liability and contact
1. Scope and roles
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Truckzly Solutions SRL(“Truckzly”) and the organisation using the service (“the Customer”). It applies whenever Truckzly processes personal data on the Customer's behalf, and it gives effect to Article 28(3) of Regulation (EU) 2016/679 (“GDPR”).
The Customer is the controller. It determines the purposes and means of processing the personal data it puts into the service, and is responsible for having a lawful basis for it, for informing data subjects, and for the accuracy and lawfulness of the instructions it gives.
Truckzly is the processor.It processes that personal data only as set out here and on the Customer's documented instructions.
If this DPA conflicts with the Terms of Service on the subject of personal data, this DPA prevails.
2. Subject matter, duration, nature and purpose
Subject matter and purpose. Providing the Truckzly transport management service, as described in the Terms of Service and as configured by the Customer.
Duration. For as long as the Customer has an account, and thereafter only for the limited period described under Return and deletion.
Nature of the processing.Collection, recording, organisation, storage, retrieval, transmission, display, analysis and erasure, carried out by automated means, in order to operate order and dispatch planning, vehicle telemetry and mapping, tachograph data collection and review, document management, maintenance records, messaging, and an assistant that answers questions from the Customer's own records.
3. Categories of data subject and personal data
Categories of data subject:
- drivers employed or engaged by the Customer
- other employees of the Customer — dispatchers, mechanics, administrators, accounting staff
- individual contacts at the Customer's own clients, suppliers and partners
- individuals who are themselves the Customer's client, where that client is a sole trader
Categories of personal data:
- identification and contact data — name, employee reference, work email address and telephone number
- employment data — role, assignments, and which vehicles a person is associated with
- driver credential data — driving licence and driver card details, and their expiry dates
- tachograph driver activity — driving, rest, availability and other work recorded by the vehicle unit and the driver card, which reveals in detail where a person was and what they were doing over time
- location data — the position of vehicles, and therefore in practice the position of the driver operating them
- documents uploaded by the Customer, and whatever personal data those documents happen to contain
- messages exchanged between the Customer's staff within the service
- audit and access records showing which user took which action
Special category data.The service is not designed to process special categories of personal data under Article 9, and the Customer should not upload it. Where a document the Customer uploads nonetheless contains such data, it remains the Customer's responsibility to have an Article 9 condition for it.
4. Truckzly's obligations
Truckzly shall:
- process personal data only on the Customer's documented instructions, including as to transfers, unless required to do otherwise by EU or Member State law — in which case it will inform the Customer first, unless that law prohibits it. The Terms of Service, this DPA, and the Customer's use and configuration of the service together constitute those instructions
- immediately inform the Customer if it considers an instruction infringes the GDPR or other data protection law
- not use the personal data for its own purposes, and in particular not for training artificial intelligence models, for advertising, or for sale or disclosure to any third party except as set out in this DPA
- ensure that people authorised to process the personal data are bound by an appropriate duty of confidentiality and are trained accordingly
- keep a record of processing carried out on behalf of the Customer, as required by Article 30(2)
5. Security measures
Truckzly implements appropriate technical and organisational measures under Article 32, including:
- authorisation enforced at the database layer. Access rules are applied by the database itself rather than only by the application, so a request for data an account is not entitled to returns nothing regardless of what the application asks
- tenant isolation— each organisation's data is segregated from every other organisation's
- encryption of personal data in transit
- role-based access control, with multi-factor authentication available to all users
- an immutable audit record of privileged and security-relevant actions
- restricted, least-privilege access to production systems for Truckzly personnel
- backups, and a process for restoring availability after an incident
Measures may be updated as the service develops, provided the level of security is not reduced. Truckzly holds no security certification such as ISO 27001 or SOC 2, and does not represent otherwise.
6. Sub-processors
The Customer gives general written authorisation for Truckzly to engage sub-processors. Truckzly uses sub-processors for hosting and infrastructure, payment processing, transactional email, mapping and routing, push notification delivery, and artificial intelligence inference.
A current list naming each sub-processor, what it receives and where it is located is available to the Customer on request at contact@truckzly.com.
Truckzly will impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customerfor a sub-processor's performance.
Truckzly will email the account's administrators at least 30 days before a new sub-processor begins processing personal data. The Customer may object on reasonable data protection grounds within that period. If the parties cannot agree a resolution, the Customer may terminate the affected part of the service without penalty for the remainder of the term.
7. International transfers
The service is hosted in the European Union. Where personal data is transferred to a sub-processor outside the EEA, Truckzly ensures an appropriate safeguard under Chapter V of the GDPR is in place — the European Commission's Standard Contractual Clauses, or the recipient's certification under the EU–US Data Privacy Framework where it holds one — together with any supplementary measures required by a transfer impact assessment. Details of the relevant transfers are available to the Customer on request.
8. Assisting with data subject rights
The service gives the Customer direct access to the personal data it holds, so that it can respond to access, rectification, erasure, restriction and portability requests itself. Lists export to CSV and tachograph files download in their original format.
Where the Customer cannot respond using the service alone, Truckzly will provide reasonable assistance taking into account the nature of the processing.
If a data subject contacts Truckzly directly about data processed on a Customer's behalf, Truckzly will not respond substantively. It will tell the data subject to contact the controller and, where it can identify the Customer, forward the request without undue delay.
9. Personal data breaches
Truckzly will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and in any event in time to allow the Customer to meet its own 72-hour obligation under Article 33. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact — providing information in stages where it is not all available at once. Truckzly will not notify a supervisory authority or data subjects on the Customer's behalf unless the Customer instructs it to.
10. Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to it, Truckzly will provide reasonable assistance to the Customer with data protection impact assessments under Article 35 and with prior consultation of a supervisory authority under Article 36. Continuous vehicle location and tachograph driver activity are the kind of processing for which an impact assessment is commonly required, and the Customer should assume it needs to consider one.
11. Return and deletion
On termination, and at the Customer's choice, Truckzly will delete or return the personal data it processes on the Customer's behalf. The Customer may export data at any time while the account is active, and for a limited period afterwards, after which the data is deleted. Copies held in backups are removed as those backups age out on their normal cycle. Truckzly may retain personal data where EU or Member State law requires it to, and in that case will continue to protect it under this DPA and process it for no other purpose.
12. Information and audit
Truckzly will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits shall take place on reasonable prior written notice, during business hours, no more than once in any twelve-month period unless a supervisory authority requires otherwise or there has been a personal data breach, shall not unreasonably disrupt the service or compromise the confidentiality of other customers' data, and shall be subject to confidentiality obligations.
13. Liability and contact
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the extent permitted by law.
Data protection enquiries, including requests to execute this DPA as a signed document for procurement purposes, go to contact@truckzly.com.