Data Processing Terms
These Data Processing Terms form part of the Agreement between FleetMark and each customer, binding on sign-up. For processing matters they prevail over the main terms.
1. Definitions & hierarchy
Terms have their UK GDPR meanings. These Terms prevail over the main terms for processing matters.
2. Scope of processing (Annex I)
- Subject matter: provision of the FleetMark vehicle-compliance platform.
- Duration: the account lifetime plus the deletion window.
- Nature & purpose: recording daily walkaround checks, defects and rectifications; where the Driver Hub is active, driver qualification records, document acknowledgements and incident reports.
- Data subjects: the customer's drivers and staff.
- Categories: identity (name), authentication (hashed PIN), signatures, check/defect content including photos; Hub fleets add licence number & expiry, CPC/tacho/training expiries, training certificates and incident details.
- Explicit exclusions: no special-category data and no criminal-offence data (including penalty points) — the customer agrees not to input these.
3. Instructions
FleetMark processes only on documented instructions — providing the service per the documentation and the settings the customer configures — and flags instructions it believes unlawful.
4. Confidentiality
Persons authorised to process personal data are bound by confidentiality obligations.
5. Security (Annex II — technical & organisational measures)
- Encryption in transit (TLS) and at rest.
- Organisation-scoped access controls on every table and storage bucket.
- Hashed driver PINs; no driver passwords or emails.
- Immutable, SHA-256-sealed check records.
- UK/EU data residency [region to be confirmed]; daily backups with tested restore.
- Access logging, dependency and vulnerability management, incident response per clause 8.
6. Sub-processors
General written authorisation; the current list lives at /legal/subprocessors. 30 days' advance notice of additions by email; the customer may object and terminate the affected service with a pro-rata refund. Equivalent obligations flow down.
7. Data subject rights assistance
FleetMark provides the tools (driver self-view, export, deletion/anonymisation) and reasonable assistance; requests received directly from drivers are redirected to the customer.
8. Breach notification
FleetMark notifies the customer without undue delay after becoming aware of a personal data breach affecting their data (target: within 48 hours), with the Article 33(3) particulars as they become available. FleetMark does not notify the ICO on the customer's behalf.
9. Assistance with Articles 32–36
Reasonable cooperation on security, breach notification and DPIAs, given the nature of processing.
10. Deletion & return
Self-service export at all times (Pledge item 5). On account deletion, personal data is hard-deleted after the 14-day grace window; backups age out within 30 days.
11. Audit & information
FleetMark makes available the information necessary to demonstrate compliance; audits are satisfied first by documentation and the Security page; on-site audits on reasonable notice, at most annually, at the customer's cost.
12. International transfers
Processing in the UK/EEA only; no restricted transfers. If ever needed, a UK IDTA/Addendum would be put in place before any transfer.
13. Liability
Per the liability provisions of the main Agreement.