Data Processing Addendum (DPA)

For customers who require a formal controller–processor agreement

1. Introduction

This Data Processing Addendum ("DPA") forms part of the agreement between Fleetmio ("Processor") and the Customer ("Controller") regarding the provision of fleet management and telematics services ("Services"). This DPA governs Fleetmio's processing of Personal Data on behalf of the Customer.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation performed on Personal Data, including collection, storage, transmission, or deletion.
  • Controller: The entity determining the purposes and means of processing Personal Data.
  • Processor: The entity processing Personal Data on behalf of the Controller.
  • Sub-processor: A third party engaged by Fleetmio to process Personal Data.

3. Roles and Responsibilities

  • The Customer acts as the Controller.
  • Fleetmio acts as the Processor and will process Personal Data only on documented instructions from the Customer.

4. Types of Data Processed

Fleetmio may process the following categories of data on behalf of the Customer:

  • Driver identification information
  • Vehicle and asset identifiers
  • GPS location and telematics data
  • Maintenance, inspection, and operational records
  • User account information

5. Purpose of Processing

Fleetmio processes Personal Data solely to:

  • Provide and maintain the Services
  • Support analytics, reporting, and operational insights
  • Ensure security, fraud prevention, and service reliability
  • Comply with legal obligations

Fleetmio will not process Personal Data for any purpose other than those documented by the Customer.

6. Sub-processors

Fleetmio may engage Sub-processors for:

  • Cloud hosting
  • Data storage
  • Analytics
  • Customer support
  • Payment processing

Fleetmio ensures all Sub-processors are bound by written agreements providing data protection obligations no less protective than this DPA.

7. Security Measures

Fleetmio implements industry-standard security controls, including:

  • Encryption in transit and at rest
  • Role-based access controls
  • Multi-factor authentication
  • Network monitoring and logging
  • Regular vulnerability assessments

8. International Transfers

If Personal Data is transferred outside the Customer's jurisdiction, Fleetmio will implement appropriate safeguards such as:

  • Standard contractual clauses
  • Contractual protections
  • Industry-standard security measures

9. Data Subject Rights

Fleetmio will assist the Customer in responding to requests from data subjects, including:

  • Access
  • Correction
  • Deletion
  • Restriction
  • Portability

Requests from Authorized Users will be directed to the Customer.

10. Data Breach Notification

Fleetmio will notify the Customer without undue delay upon becoming aware of a Personal Data breach affecting Customer data.

11. Data Retention & Deletion

Upon termination of the Services, Fleetmio will:

  • Delete or return Personal Data at the Customer's request
  • Retain data only where legally required

12. Audit Rights

Fleetmio will make available documentation necessary to demonstrate compliance and allow audits by the Customer or an independent auditor.

13. Term

This DPA remains in effect for the duration of the Customer's use of the Services.