This Data Processing Agreement forms part of the Master Agreement between Lucett Ltd and the business customer identified in that agreement. It takes effect when the Master Agreement takes effect and applies only to processing for which that customer acts as controller and Lucett acts as processor. The Controller’s contact details are those recorded in its account. Lucett’s contact is [email protected]. Private use of an Asset Owner Portfolio does not, by itself, make its user a controller. The parties’ recorded acceptance of the Master Agreement incorporates this DPA without a separate paper signature.
Background
1. The Controller and Processor entered into an agreement (the ‘Master Agreement’) that requires the Processor to Process Personal Data on behalf of the Controller. This DPA is incorporated into the Master Agreement, with effect from the date the Master Agreement takes effect.
2. This Data Processing Agreement (‘DPA’) sets out the additional terms, requirements and conditions on which the Processor will Process Personal Data when providing services under the Master Agreement.
Agreed Terms
1. DEFINITIONS AND INTERPRETATION
The following definitions and rules of interpretation apply in this DPA:
1.1 “Data Protection Legislation” means the UK GDPR, the Data Protection Act 2018, the EU GDPR where applicable, the Privacy and Electronic Communications (EC Directive) Regulations 2003 and all other applicable laws relating to personal data and privacy, in each case as amended or replaced from time to time.
1.2 Capitalised terms used and not defined in this Agreement shall bear the meanings given to them in the Data Protection Legislation.
1.3 A reference to writing or written includes email.
1.4 In the case of conflict or ambiguity between any provision contained in this Agreement and the Master Agreement, the terms of this Agreement will prevail.
2. DATA PROCESSING
2.1 Controller confirms it has the right to transfer, or provide access to, the Personal Data it shares with the Processor (including its personnel and subprocessors) for Processing (the ‘Data’) in accordance with the terms of the Master Agreement and this DPA. The Controller shall comply with the Data Protection Legislation in connection with the Personal Data it shares with the Processor.
2.2 The Controller instructs the Processor in accordance with this Agreement to Process the Data as reasonably necessary for the provision of the Master Agreement.
3. PROCESSOR'S MANDATORY OBLIGATIONS
3.1 Processor will Process the Data only for the purposes described in, and for the duration of, the Master Agreement. Where the Processor is legally required to Process the Data for other reasons, then where permitted, the Processor must first notify the Controller of this requirement. Both parties acknowledge that the Data which the Processor will Process for the Controller will usually consist of following:
Users full name, telephone numbers, email addresses, user names and passwords, physical company address(s), physical vehicle locations, asset details (including but limited to description, price, physical location and characteristics), operation scheduling, GPS location of drivers and vehicles, GPS coordinates of company address(s), region and countries.
3.2 Where the Processor is aware that the Controller’s instructions related to the Data infringes Data Protection Legislation or other applicable laws, the Processor must notify the Controller immediately (unless applicable laws prevents the Processor from doing so) and the Processor will not carry out that Processing.
3.3 The Processor will implement appropriate security measures (both technical and organisational) to ensure the Data is kept sufficiently secure. The Processor will also ensure that anyone is allows to Process the Data on behalf of the Controller is subject to confidentiality commitments as required by Data Protection Legislation.
3.4 At the cost of the Controller, the Processor will provide the Controller with reasonable assistance to demonstrate compliance with the Data Protection Legislation, including but not limited to: (i) ensuring compliance with security, breach notification, impact assessments and prior consultation obligations; (ii) submitting to audits requested by the Controller (subject to reasonable advance notice and terms to be agreed between the parties which protect the Processor’s ability to run its business and the confidentiality of its other clients); and (iii) responding to: (a) any Data Subject request to exercise their rights under Data Protection Legislation; and (b) any other correspondence, enquiry or complaint received in connection with the Processor’s Processing of the Data.
3.5 If the Processor becomes aware of a Personal Data Breach in relation to the Data, the Processor will inform the Controller without undue delay and help the Controller to fulfil any data breach reporting obligations they may have under Data Protection Legislation. The Processor will not inform any third party of any Personal Data Breach in relation to the Data without first obtaining the Controller's prior written consent, except when required to do so by law.
3.6 At the end of the relevant processing services, the Processor shall, at the Controller’s choice, return or delete all Personal Data processed on the Controller’s behalf and delete existing copies, unless applicable law requires storage. The obligation covers Data generated during the services as well as Data originally supplied by the Controller. Any legally required retention shall remain protected and limited to its lawful purpose. Data temporarily remaining in backups shall be isolated from ordinary use pending secure deletion under a documented expiry schedule. Required erasures shall be reapplied before restored backup data is returned to operational use. Account deactivation, a plan restriction or recoverable soft deletion does not, by itself, fulfil these obligations. The Processor shall provide reasonable evidence of compliance on request.
4. INTERNATIONAL TRANSFERS OF PERSONAL DATA
4.1 The Processor and its subprocessors may Process the Data in countries that are outside of the United Kingdom and the European Economic Area (‘UK and EEA’).
4.2 The Processor shall ensure that transfers of the Data outside of the UK and EEA are subject to the appropriate safeguards as required by the Data Protection Legislation (such as adequacy regulations or standard contractual clauses approved under the Data Protection Legislation).
5. SUBCONTRACTORS
5.1 The Controller gives general written authorisation for the Processor to appoint the sub-processors listed in clause 5.2 for the relevant processing services. Before a sub-processor processes Data, the Processor shall enter into a binding written agreement imposing data protection obligations which meet the requirements of Data Protection Legislation and provide the required level of protection for that processing. The Processor remains responsible to the Controller for the performance of its sub-processors’ data protection obligations.
5.2 The subcontractors used at the date of this DPA are
- DigitalOcean Holdings, Inc (Cloud Services Provider)
- Amazon Web Services (Cloud Service Provider)
- Google Cloud (Cloud Service Provider)
- Pusher.com (Bird formally MessageBird)
- Stripe Inc. (Payment Processing Gateway)
- Krank Ltd. (INSPEQ)
The Processor shall notify the Controller in advance of any intended addition or replacement of a sub-processor, identifying the provider and the processing concerned and allowing a reasonable opportunity to object on data protection grounds before the change takes effect. The parties shall seek a practicable resolution to a substantiated objection. If no compliant resolution is available, the Processor shall not transfer the affected Data to that proposed sub-processor and the parties may end the affected processing services without overriding required return or deletion obligations.
6. INDEMNIFICATION
6.1 The Data Controller shall be liable for, and shall indemnify (and keep indemnified) the Data Processor in respect of any and all action, proceeding, liability, cost, claim, loss, expense (including reasonable legal fees and payments on a solicitor and client basis), or demand suffered or incurred by, awarded against, or agreed to be paid by, the Data Processor arising directly or in connection with:
6.1.1 any non-compliance by the Data Controller with the Data Protection Legislation;
6.1.2 any Personal Data processing carried out by the Data Processor in accordance with instructions given by the Data Controller that infringe the Data Protection Legislation; or
6.1.3 any breach by the Data Controller of its obligations under this DPA,
except to the extent that the Data Processor is liable under sub-Clause 6.2.
6.2 The Data Processor shall be liable for, and shall indemnify (and keep indemnified) the Data Controller in respect of any and all action, proceeding, liability, cost, claim, loss, expense (including reasonable legal fees and payments on a solicitor and client basis), or demand suffered or incurred by, awarded against, or agreed to be paid by, the Data Controller arising directly or in connection with the Data Processor’s Personal Data processing activities that are subject to this DPA:
6.2.1 only to the extent that the same results from the Data Processor’s breach of this DPA; and
6.2.2 not to the extent that the same is or are contributed to by any breach of this DPA by the Data Controller.
6.3 The Data Controller shall not be entitled to claim back from the Data Processor any sums paid in compensation by the Data Controller in respect of any damage to the extent that the Data Controller is liable to indemnify the Data Processor under sub-Clause 6.1.
6.4 Nothing in this DPA (and in particular, this Clause 6) shall relieve either Party of, or otherwise affect, the liability of either Party to any data subject, or for any other breach of that Party’s direct obligations under the Data Protection Legislation.
7. NOTICE
7.1 Any notice or other communication given to a party under or in connection with this DPA must be in writing and delivered to:
7.1.1 For the Controller: the contact details recorded in its account
7.1.2 For the Processor: [email protected] LUCETT LTD.
7.2 This clause does not apply to the service of any proceedings or other documents in any legal action or, where applicable, any arbitration or other method of dispute resolution.
7.3 A notice given under this DPA is valid if sent by email.