Data Processing Agreement (DPA)
Between TransportHQ (Processor) and the Customer (Controller)
Version / last updated: [DATE]
1. Parties and roles
This Agreement is made between:
- The Processor: Michelle Sharpe, trading as TransportHQ (“TransportHQ”, “we”, “us”); and
- The Controller: [CUSTOMER NAME] (“the Customer”, “you”).
For the personal data processed through the TransportHQ application, you are the data controller and we are your data processor. This Agreement governs that processing and is entered into in accordance with Article 28 of the UK GDPR.
Where terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” are used, they have the meanings given in the UK GDPR and the Data Protection Act 2018.
2. Subject matter, duration, nature and purpose
- Subject matter: the provision of the TransportHQ school transport management application.
- Duration: for as long as you have an active account with us, plus any short period afterwards needed to return or delete data (see section 10).
- Nature and purpose: storing and processing personal data so that you can manage school transport operations — including passengers, drivers, passenger assistants, schools, vehicles, runs, holidays, cancellations, notes, and the sharing of relevant information with your clients or councils.
3. Categories of data subject and personal data
Categories of data subject:
- Passengers (children using school transport)
- Drivers and passenger assistants
- Client and council contacts
- Your own staff / managers who use the app
Categories of personal data:
- Passengers: name, address, town, postcode, associated school, and yes/no flags for wheelchair access and passenger-assistant need
- Drivers and passenger assistants: name, phone number, email address, and role
- Client and council contacts: name and email address
- Operational records: runs, holidays, cancellations, notes, and cancellation photos (intended to show only a location such as a door)
- Account/login data: email addresses used to log in
Special category data: the wheelchair-access and passenger-assistant flags may indicate information about a passenger's health or disability. You are responsible for ensuring you have a valid lawful basis and an appropriate Article 9 condition for this data. We process it only on your instructions and apply appropriate protection to it.
4. Our obligations as processor
We will:
- Process only on your documented instructions. We will process the personal data only to provide the service and as instructed by you, unless required otherwise by law (in which case we will tell you, unless the law prohibits it).
- Confidentiality. Ensure that anyone authorised to process the data is bound by an appropriate duty of confidentiality.
- Security. Implement appropriate technical and organisational measures to protect the data (see Annex A).
- Sub-processors. Only engage sub-processors as set out in section 5.
- Assist with data subject rights. Taking into account the nature of the processing, help you respond to requests from data subjects (such as access, correction or deletion) as far as we reasonably can.
- Assist with your obligations. Help you, where relevant, with data protection impact assessments, security, and breach notification.
- Breach notification. Notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own reporting duties.
- Deletion or return. At the end of the service, delete or return the personal data as set out in section 10.
- Records and audits. Make available the information reasonably needed to demonstrate compliance with Article 28, and allow for and contribute to reasonable audits.
- Tell you if an instruction is unlawful. Inform you if, in our opinion, an instruction from you would breach data protection law.
5. Sub-processors
You give general authorisation for us to use the following sub-processor:
- Google (Firebase / Google Cloud) — provides the Firestore database (data stored in the europe-west2 / London region) and Firebase Authentication (which processes login email addresses in the United States under Standard Contractual Clauses and the UK Addendum).
Our app code is served through GitHub Pages (the app) and Firebase Hosting (the landing page). These deliver the application's website files only and are not used to store your personal data.
If we intend to add or change a sub-processor that processes your personal data, we will give you reasonable prior notice and an opportunity to object.
6. International transfers
Your operational data is stored in the United Kingdom (europe-west2, London). Login email addresses are processed in the United States by Firebase Authentication. Where personal data is transferred outside the UK, appropriate safeguards are in place (Standard Contractual Clauses together with the UK Addendum, as provided under Google's data processing terms). We will not otherwise transfer your personal data outside the UK without an appropriate safeguard in place.
7. Your obligations as controller
You confirm that you will:
- have a valid lawful basis (and, for any special category data, an appropriate Article 9 condition) for the personal data you process through the app;
- provide the people whose data you hold — including parents/passengers, drivers, assistants and client/council contacts — with the privacy information they are entitled to;
- give us lawful and reasonable instructions; and
- be responsible for the accuracy of the data you enter and for how you share it with your clients and councils.
8. Data subject requests
If we receive a request from a data subject relating to your data, we will not respond directly (unless legally required) but will inform you promptly and help you respond.
9. Personal data breaches
We will notify you without undue delay once we become aware of a breach affecting your personal data, and will provide reasonable assistance and information so you can meet any obligation to notify the ICO or affected individuals.
10. Deletion and return of data
On termination of the service, or on your written request, we will delete your personal data within 30 days, unless we are required by law to keep it. On request during that period, we will make the data available to you for export. This aligns with the TransportHQ Data Retention Policy.
11. General
- This Agreement forms part of, and is subject to, the TransportHQ Terms of Service.
- It is governed by the laws of England and Wales.
- If any part of it conflicts with the Terms of Service on the subject of data protection, this Agreement prevails.
Annex A — Security measures
We apply measures appropriate to the risk, including:
- data encrypted in transit (HTTPS) and at rest, as provided by Google Firebase;
- access to the application controlled by individual email/password login;
- access to customer data restricted so that each customer, and each client/council user, can see only the data relevant to them;
- use of a reputable cloud infrastructure provider (Google) with recognised security certifications;
- data hosted in the UK (europe-west2) for the database, with login authentication handled under appropriate international transfer safeguards.
Signatures
Processor: Michelle Sharpe, trading as TransportHQ
Signature: ...................................... Date: ..................
Controller: [CUSTOMER NAME]
Name / position: ......................................
Signature: ...................................... Date: ..................