Flotaryx← Back to Flotaryx
Legal information

Data Processing Agreement

Last updated: 11 October 2026

1. Parties and precedence

This Data Processing Addendum (DPA) forms part of the Flotaryx B2B Terms between the Customer company (Controller) and ELVA LTD, company 10715768 (Processor), in relation to personal data submitted to the Customer’s Flotaryx workspace. For matters concerning that processing, this DPA prevails over conflicting general terms. For ELVA LTD’s independent account and billing controller activities, the Privacy Notice applies.

2. Processing details and duration

Subject: hosting, organizing, displaying, updating, exporting and protecting company fleet-management records. Duration: the agreement and a limited wind-down/deletion period. Purposes: provision of the subscribed service on documented Customer instructions. Data subjects may include Customer staff, drivers, mechanics, contacts and other individuals recorded in fleet operations. Data may include contact identifiers, vehicle assignments, inspection/repair notes, related documents, issue records and usage history. The Customer should not upload special-category or criminal-offence data unless separately agreed and legally justified.

3. Instructions and compliance

The Processor shall process Customer personal data only on documented Controller instructions, including those embodied in service configuration and authorized user actions, unless required by applicable law; in that case it shall notify the Controller before processing unless prohibited. The Processor shall promptly inform the Controller if an instruction appears to infringe applicable data-protection law. The Controller remains responsible for lawful collection, notice, permissions and data quality.

4. Confidentiality and personnel

The Processor shall ensure persons authorized to process Customer personal data are subject to an appropriate duty of confidentiality, receive relevant security instructions and access data only for legitimate service or support needs.

5. Technical and organizational security

The Processor shall apply measures proportionate to risk under UK GDPR/EU GDPR Article 32, including role-based authorization, authentication, encrypted transmission where supported, protected service credentials, logging where appropriate, access limitation, backup/recovery arrangements and incident response procedures. Measures may evolve, provided the overall protection is not materially reduced. Neither party treats general software availability as an absolute security guarantee.

6. Approved sub-processors

The Controller grants general authorization for relevant sub-processors, which may include Supabase (database/authentication), Stripe (billing where acting as a processor), Resend (transactional notifications), Namecheap (email) and relevant hosting providers. The Processor shall impose substantially equivalent data-protection duties on them where required and remains responsible for its processing obligations. Planned additions or replacements that materially affect Customer personal data will be notified with a reasonable opportunity to object on data-protection grounds before use.

7. International transfers

Where personal data is transferred internationally in a restricted transfer, the parties shall use an applicable valid mechanism (such as adequacy, the UK IDTA/addendum or EU standard contractual clauses, as required) and supporting measures where necessary. The Processor shall make relevant transfer arrangements reasonably available to the Controller on request. This DPA alone is not a substitute for any mandatory transfer instrument.

8. Data-subject requests and assistance

Taking account of the nature of processing, the Processor shall reasonably assist the Controller with data-subject requests, security assessments, breach notifications and data-protection impact assessments, and with consultations with supervisory authorities where required. The Controller is responsible for responding directly to data subjects unless otherwise agreed.

9. Personal-data breaches

The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer data, with information then reasonably available and subsequent updates as appropriate. The Controller remains responsible for deciding whether notice to individuals or authorities is required. Incident reports: support@flotaryx.com.

10. Return, deletion and backup data

At termination of the service, the Controller may request export/return or deletion of Customer personal data, subject to applicable law and technical limitations. The Processor shall delete or return data in accordance with Controller instructions within a reasonable agreed period; backup copies will be protected and expire through normal retention cycles unless legally required to preserve them. We will not retain usable workspace copies for unrelated purposes.

11. Demonstrating compliance and audits

The Processor shall make information reasonably necessary to demonstrate compliance with Article 28 obligations available to the Controller and allow appropriate audits by an independent qualified auditor under reasonable notice, confidentiality, security and proportionality constraints. Audits must avoid disrupting services or compromising other customers’ information; the parties will agree practical arrangements and reasonable costs. Contact: support@flotaryx.com.

ELVA LTD · Company number 10715768 · Registered in England and Wales · 23–27 King Street, Luton, LU1 2DW, England · support@flotaryx.com