Data Processing Agreement

Controller-to-processor terms for the personal data contained in the business data you upload. Forms part of the Terms of Service.

Version
1.0
Effective
EFFECTIVE DATE

1.Parties and roles

This Data Processing Agreement (“DPA”) is entered into between the Customer as controller and COMPANY LEGAL NAME, trading as Metimo Auto, as processor, and forms part of the Terms of Service. Capitalised terms not defined here have the meaning in the Terms; “Customer Personal Data”, “processing”, “controller”, “processor” and “data subject” carry their meanings under applicable data protection law (UK GDPR, EU GDPR and equivalents).

2.Subject-matter and details of processing

  • Subject-matter: provision of the Metimo Auto platform.
  • Duration: the term of the subscription plus the retention window in section 9.
  • Nature and purpose: hosting, storage and processing of uploaded data to produce emissions calculations and reports.
  • Types of personal data: business-contact and employee-related data incidentally present in uploads (e.g. names/emails on invoices, FTE figures, supplier contacts) and platform user account data. No special-category data is intended.
  • Categories of data subject: the Customer’s personnel, and individuals named in the Customer’s supplier or provider records.

3.Our obligations as processor

  • Process Customer Personal Data only on the Customer’s documented instructions, including as to international transfers, unless required otherwise by law (in which case we notify you unless the law forbids it).
  • Ensure personnel authorised to process are bound by confidentiality.
  • Implement the technical and organisational measures in section 6.
  • Assist the Customer, taking account of the nature of processing, with data-subject requests and with security, breach-notification and impact-assessment obligations.
  • Not sell Customer Personal Data or process it for our own purposes; where US state law applies, we act as a “service provider” and certify we will not retain, use or disclose it outside the direct business relationship.

4.Controller obligations

The Customer warrants it has a lawful basis and all necessary notices and consents to provide Customer Personal Data to us and to instruct the processing described here, and that its instructions comply with applicable law.

5.Sub-processing

The Customer grants general authorisation for us to engage the sub-processors listed at /legal/subprocessors. We impose data-protection terms on each sub-processor no less protective than this DPA and remain liable for their performance. We will give at least N days’ notice of any intended addition or replacement, during which you may object on reasonable data-protection grounds.

6.Security measures

Taking account of the state of the art and the risk, we maintain measures including:

  • encryption of data in transit (TLS) and at rest;
  • role-based access control, least-privilege internal access and multi-factor authentication for administrative access;
  • network isolation, logging and monitoring;
  • regular backups and a tested restoration process;
  • secure software-development and change-management practices;
  • staff confidentiality obligations and security awareness.

7.Personal-data breaches

We will notify the Customer without undue delay, and in any event within N hours, after becoming aware of a personal-data breach affecting Customer Personal Data, with the information reasonably available to help the Customer meet its own notification duties.

8.Data-subject requests and assistance

Where a data subject contacts us directly about Customer Personal Data, we will refer them to the Customer and, taking account of the nature of processing, assist the Customer to respond, including through the export, correction and deletion tools in the platform.

9.Return and deletion

On termination or expiry, at the Customer’s choice we will return or delete Customer Personal Data. The Customer may export its data during the subscription and for N days after; we will then delete it within N days, save for copies in routine backups which are deleted on their normal cycle and copies we must keep by law.

10.Audits

We will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, by the Customer or an appointed auditor on reasonable notice, no more than once a year except where required by a regulator or following a breach, subject to confidentiality and to minimising disruption. We may satisfy audit requests by providing current third-party certifications or reports.

11.International transfers

Where processing involves transfer of Customer Personal Data outside the UK, EEA or Switzerland, the parties agree that the relevant Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum are incorporated by reference and completed with the details in this DPA and the sub-processor list, with the Customer as data exporter and Metimo (or the sub-processor) as data importer.

12.Liability and precedence

Each party’s liability under this DPA is subject to the limitations in the Terms of Service. If there is a conflict between this DPA and the Terms on the processing of Customer Personal Data, this DPA prevails. Contact: dpo@YOUR-DOMAIN.