FLEET COMPLY
Loading Fleet Comply
Legal

Data Processing Agreement

Version 1.0 — Last updated: 15 June 2026

1. Parties and Scope

This Data Processing Agreement (“DPA”) is entered into between Aurel Paraschiv (Sole Trader), trading as Fleet Comply (“Fleet Comply”, the “Processor”) and the workspace owner accepting this DPA on behalf of the customer organisation (the “Controller”). It applies whenever Fleet Comply processes personal data uploaded or generated within the Controller's workspace (drivers, vehicles, compliance records, documents, infringements, DVSA events and related data subjects).

This DPA forms part of, and is incorporated into, the Fleet Comply Terms & Conditions and Privacy Policy. Capitalised terms not defined here have the meaning given in UK GDPR.

2. Subject-Matter and Duration

Subject-matter: hosted compliance management, reminders, document storage, reporting and audit preparation for the Controller's fleet.

Duration: for the term of the Controller's use of the platform and until deletion or return of the data in accordance with Section 9.

Nature and purpose: storage, access control, scheduled processing, notification and generation of compliance reports on the Controller's instructions through configuration of the platform.

3. Categories of Data and Data Subjects

Data subjects: the Controller's drivers, employees, transport managers, contractors and authorised users.

Categories of personal data: identity and contact data, driver licence references and renewal dates, vehicle and tachograph data, compliance and infringement records, uploaded compliance documents, audit and login events.

No special category data is required by the platform; the Controller must not upload it without a separate lawful basis.

4. Processor Obligations

Fleet Comply will:

  • process personal data only on documented instructions from the Controller (the platform configuration, in-app actions and this DPA);
  • ensure persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational measures, including encryption in transit and at rest, role-based access control, tenant isolation enforced by Row-Level Security, audit logging and least-privilege administrative access;
  • assist the Controller, taking into account the nature of processing, in responding to data-subject requests and in meeting Articles 32–36 obligations;
  • notify the Controller without undue delay (and within 72 hours where feasible) on becoming aware of a personal-data breach affecting the Controller's data;
  • make available all information necessary to demonstrate compliance and allow for, and contribute to, audits as set out in Section 8.

5. Sub-Processors

The Controller provides general authorisation for the following sub-processors:

  • Lovable Cloud — application hosting, managed database, authentication, storage and transactional email delivery.
  • Cloudflare — content delivery, edge security and encrypted off-platform R2 backups.
  • Google (Gmail API) — outbound transactional email transport for operational notifications.

Fleet Comply will give at least 30 days' prior notice of any new or replacement sub-processor via in-app broadcast or email. The Controller may object on reasonable data-protection grounds within that period; if the parties cannot agree on a remedy, the Controller may terminate the affected service.

6. International Transfers

Processing is configured for UK or EEA hosting where available. Any restricted transfer outside the UK is made under either UK adequacy regulations or the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), supported by supplier due diligence, encryption in transit and at rest, and least-privilege access controls.

7. Data-Subject Requests and Breach Assistance

The platform provides self-service access, portability, rectification, restriction and erasure tooling in Settings → Privacy & Data Rights. Where the Controller receives a data-subject request that requires action on Fleet Comply's side, Fleet Comply will assist within reasonable timescales and in any event in time for the Controller to meet its statutory deadline. Breach notifications include the nature of the breach, categories and approximate number of records affected, likely consequences and measures taken or proposed.

8. Audit Rights

Fleet Comply will make available, on request and not more than once per twelve-month period, information reasonably required to demonstrate compliance with Article 28 UK GDPR, including the Record of Processing Activities at fleetcomply.co.uk/ropa, the public security and retention documentation, and answers to a reasonable security questionnaire. On-site audits are by mutual agreement and may be coordinated through an independent auditor under confidentiality.

9. Deletion or Return on Termination

On termination of the Controller's use of the platform, Fleet Comply will, at the Controller's choice, return or delete all personal data within 30 days, save for copies retained in encrypted off-platform R2 backups for up to 52 weeks and any records the platform is legally required to retain (for example security audit logs for 7 years and compliance records for 6 years). Backup residue is encrypted, access- controlled and automatically pruned on the published schedule.

10. Liability and Governing Law

Each party's liability under this DPA is subject to the limitation-of-liability provisions of the Terms & Conditions. This DPA is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales.

11. Acceptance

Workspace owners accept this DPA in Settings → Data Processing Agreement. Acceptance is recorded with a timestamp, the IP address and user-agent of the accepting user and the DPA version number, and is included in the Controller's data export.

12. Contact

For DPA enquiries, sub-processor objections, audit requests or breach correspondence, contact notify@fleetcomply.co.uk.