Data Processing Agreement (DPA)

Between TransportHQ (Processor) and the Customer (Controller)
Version / last updated: [DATE]

1. Parties and roles

This Agreement is made between:

For the personal data processed through the TransportHQ application, you are the data controller and we are your data processor. This Agreement governs that processing and is entered into in accordance with Article 28 of the UK GDPR.

Where terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” are used, they have the meanings given in the UK GDPR and the Data Protection Act 2018.

2. Subject matter, duration, nature and purpose

3. Categories of data subject and personal data

Categories of data subject:

Categories of personal data:

Special category data: the wheelchair-access and passenger-assistant flags may indicate information about a passenger's health or disability. You are responsible for ensuring you have a valid lawful basis and an appropriate Article 9 condition for this data. We process it only on your instructions and apply appropriate protection to it.

4. Our obligations as processor

We will:

  1. Process only on your documented instructions. We will process the personal data only to provide the service and as instructed by you, unless required otherwise by law (in which case we will tell you, unless the law prohibits it).
  2. Confidentiality. Ensure that anyone authorised to process the data is bound by an appropriate duty of confidentiality.
  3. Security. Implement appropriate technical and organisational measures to protect the data (see Annex A).
  4. Sub-processors. Only engage sub-processors as set out in section 5.
  5. Assist with data subject rights. Taking into account the nature of the processing, help you respond to requests from data subjects (such as access, correction or deletion) as far as we reasonably can.
  6. Assist with your obligations. Help you, where relevant, with data protection impact assessments, security, and breach notification.
  7. Breach notification. Notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own reporting duties.
  8. Deletion or return. At the end of the service, delete or return the personal data as set out in section 10.
  9. Records and audits. Make available the information reasonably needed to demonstrate compliance with Article 28, and allow for and contribute to reasonable audits.
  10. Tell you if an instruction is unlawful. Inform you if, in our opinion, an instruction from you would breach data protection law.

5. Sub-processors

You give general authorisation for us to use the following sub-processor:

Our app code is served through GitHub Pages (the app) and Firebase Hosting (the landing page). These deliver the application's website files only and are not used to store your personal data.

If we intend to add or change a sub-processor that processes your personal data, we will give you reasonable prior notice and an opportunity to object.

6. International transfers

Your operational data is stored in the United Kingdom (europe-west2, London). Login email addresses are processed in the United States by Firebase Authentication. Where personal data is transferred outside the UK, appropriate safeguards are in place (Standard Contractual Clauses together with the UK Addendum, as provided under Google's data processing terms). We will not otherwise transfer your personal data outside the UK without an appropriate safeguard in place.

7. Your obligations as controller

You confirm that you will:

8. Data subject requests

If we receive a request from a data subject relating to your data, we will not respond directly (unless legally required) but will inform you promptly and help you respond.

9. Personal data breaches

We will notify you without undue delay once we become aware of a breach affecting your personal data, and will provide reasonable assistance and information so you can meet any obligation to notify the ICO or affected individuals.

10. Deletion and return of data

On termination of the service, or on your written request, we will delete your personal data within 30 days, unless we are required by law to keep it. On request during that period, we will make the data available to you for export. This aligns with the TransportHQ Data Retention Policy.

11. General

Annex A — Security measures

We apply measures appropriate to the risk, including:

Signatures

Processor: Michelle Sharpe, trading as TransportHQ
Signature: ......................................  Date: ..................

Controller: [CUSTOMER NAME]
Name / position: ......................................
Signature: ......................................  Date: ..................