Data Processing Agreement
Last updated July 16, 2026 · Version 1.0
This Data Processing Agreement (“DPA”) forms part of, and is subject to, the agreement for the provision of the SmartVault platform (the “Main Agreement” — for self-service accounts, the Terms of Use) between:
- The Customer — the operator entity that has accepted the Main Agreement (the “Controller”); and
- SmartVault Technologies LTD, a private company incorporated in the Republic of Cyprus, trading as SmartVault (the “Processor”). Company registration details are available on request from legal@smartvaultapp.io,
each a “Party” and together the “Parties”.
This DPA applies automatically to every operator account from acceptance of the Main Agreement; a countersigned copy is available for customers that require one. It reflects the Parties’ agreement on the processing of Personal Data in connection with the SmartVault platform (the “Service”) and gives effect to Article 28 of the UK GDPR and the EU GDPR. Where there is a conflict between this DPA and the Main Agreement on the subject of data protection, this DPA prevails.
1. Definitions
1.1 The terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, “Special Category Data” and “Supervisory Authority” have the meanings given in the Data Protection Laws.
1.2 “Data Protection Laws” means all laws applicable to the Processing of Personal Data under the Main Agreement, including: (a) the UK GDPR (as defined in the Data Protection Act 2018) and the Data Protection Act 2018; and (b) the EU GDPR (Regulation (EU) 2016/679) and any implementing national laws; in each case as amended or replaced.
1.3 “Sub-processor” means any third party engaged by the Processor to Process Personal Data on behalf of the Controller.
1.4 “Standard Contractual Clauses” or “SCCs” means (a) for EU/EEA transfers, the clauses in Commission Implementing Decision (EU) 2021/914; and (b) for UK transfers, the ICO’s International Data Transfer Addendum to the EU SCCs (the “UK Addendum”).
1.5 “Annex” means an annex to this DPA, each of which forms part of it.
2. Roles and scope of processing
2.1 The Parties agree that, for the Personal Data Processed under the Main Agreement, the Controller is the controller and the Processor is the processor (or, where the Controller is itself a processor for its own customers, the Processor is a sub-processor and the same terms apply mutatis mutandis).
2.2 The Processor shall Process Personal Data only for the purpose of providing the Service and only as described in Annex 1 (Details of Processing).
2.3 The Controller is responsible for the accuracy, quality and legality of the Personal Data and for the lawful basis on which it was collected and provided to the Processor.
3. Processor obligations
The Processor shall:
3.1 Documented instructions. Process the Personal Data only on the Controller’s documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case the Processor shall inform the Controller of that legal requirement before Processing, unless the law prohibits it). The Main Agreement, this DPA, and the Controller’s use and configuration of the Service constitute the Controller’s complete documented instructions. The Processor shall inform the Controller if, in its opinion, an instruction infringes the Data Protection Laws.
3.2 Confidentiality. Ensure that persons authorised to Process the Personal Data are bound by an appropriate obligation of confidentiality and Process the data only as instructed.
3.3 Security. Implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk, in accordance with Article 32 of the Data Protection Laws.
3.4 Sub-processors.
(a) The Controller grants the Processor general written authorisation to engage the Sub-processors listed in Annex 3.
(b) The Processor shall impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for each Sub-processor’s performance.
(c) The Processor shall give the Controller at least thirty (30) days’ prior notice (by updating the published sub-processor list in Annex 3 on this page and/or by email) of any intended addition or replacement of a Sub-processor. The Controller may object on reasonable data-protection grounds within that period; the Parties shall work in good faith to resolve the objection, failing which the Controller may terminate the affected part of the Service.
3.5 Assistance with data-subject rights. Taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, to fulfil the Controller’s obligation to respond to requests to exercise Data Subject rights (access, rectification, erasure, restriction, portability, objection). Where a Data Subject sends such a request directly to the Processor, the Processor shall promptly forward it to the Controller and not respond directly except on the Controller’s instruction.
3.6 Assistance with compliance. Taking into account the nature of Processing and the information available to it, assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the Data Protection Laws (security, Personal Data Breach notification, data protection impact assessments, and prior consultation).
3.7 Deletion or return. On termination of the Service, at the Controller’s choice, delete or return all Personal Data and delete existing copies, unless retention is required by law. See clause 7 (Deletion, retention and cryptographic records).
3.8 Records and audits. Make available to the Controller all information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to clause 5.
4. Controller obligations
4.1 The Controller shall: (a) comply with the Data Protection Laws in respect of its Processing and its instructions; (b) have a valid lawful basis for the Personal Data it provides to, or generates within, the Service; (c) provide all required privacy notices to its own Data Subjects; and (d) not upload or input Special Category Data or other unusually sensitive data except as strictly necessary, and in particular shall ensure that photographs and documents uploaded to the Service are of vehicles and their condition and do not intentionally capture Data Subjects or their Special Category Data.
5. Audit
5.1 The Processor shall, on reasonable written request and no more than once in any twelve-month period (unless a Supervisory Authority requires otherwise or following a Personal Data Breach affecting the Controller’s data), make available its then-current security documentation, sub-processor list and, where held, third-party audit reports or certifications, to demonstrate compliance.
5.2 Where the documentation under 5.1 is insufficient, the Controller may conduct, or mandate an independent auditor (bound by confidentiality) to conduct, an audit. Any such audit shall: be on at least thirty (30) days’ notice; take place during business hours; not unreasonably disrupt the Processor’s operations; respect the confidentiality and security of other customers’ data; and be at the Controller’s cost.
6. Personal Data Breach
6.1 The Processor shall implement measures to detect Personal Data Breaches.
6.2 The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting the Controller’s Personal Data.
6.3 The notification shall, to the extent known, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information cannot be provided at once, it may be provided in phases without undue further delay.
6.4 The Processor shall reasonably assist the Controller in meeting the Controller’s own breach-notification and communication obligations to Supervisory Authorities and Data Subjects. Notification of a breach is not an acknowledgement of fault or liability.
7. Deletion, retention and cryptographic records
7.1 On expiry or termination of the Main Agreement, the Processor shall, at the Controller’s written election within thirty (30) days, delete or return the Personal Data, and delete remaining copies, save to the extent (and for as long as) retention is required by applicable law.
7.2 The Controller acknowledges the following features of the Service, which it has instructed the Processor to provide:
(a) Audit trail. The Service maintains an append-only, tamper-evident audit log. Erasure of Personal Data from this log is supported through a controlled, logged maintenance process and will be carried out where required to honour a valid erasure request.
(b) Custody Passports and cryptographic anchoring. The Service commits finished records (sealed Custody Passports, and official copies of inspection and intake documents) and a daily digest of live custody records to a public timestamping network (Bitcoin, via OpenTimestamps). Only a cryptographic hash (or blinded hash) is committed to that network — no Personal Data is placed on any public blockchain, and the hash does not reveal, and cannot feasibly be reversed to obtain, any Personal Data. Accordingly there is nothing to erase from, and no Personal Data is disclosed by, the public network.
(c) Records delivered to Data Subjects. Sealed records (e.g. a Custody Passport PDF and its proof file) may be delivered to the relevant Data Subject and held by that person outside the Processor’s control. Deletion by the Processor does not extend to copies already delivered to and held by Data Subjects.
7.3 On deletion of the underlying Personal Data, the Processor shall cease to serve that Personal Data through any public verification page.
8. International transfers
8.1 The Processor Processes and stores Personal Data primarily within the European Economic Area (Republic of Ireland). Details of hosting and processing locations are in Annex 4.
8.2 Where Processing by the Processor or a Sub-processor involves a transfer of Personal Data to a country outside the UK/EEA that is not subject to an adequacy decision, the Processor shall ensure an appropriate safeguard under Article 46 is in place, being (as applicable) the SCCs and/or the UK Addendum, which are incorporated into this DPA by reference and completed as set out in Annex 4. Where the relevant importer is certified under an applicable adequacy framework, that framework may additionally be relied upon.
8.3 For the purposes of the SCCs between the Parties, the Controller is the “data exporter” and the Processor is the “data importer”; Module Two (Controller-to-Processor) applies; the docking clause applies; and the Annexes to this DPA populate the corresponding appendices.
9. Liability
9.1 Each Party’s liability arising out of or related to this DPA, whether in contract, tort or otherwise, is subject to the exclusions and limitations of liability set out in the Main Agreement, and any reference in the Main Agreement to the liability of a Party means the aggregate liability of that Party under the Main Agreement and this DPA.
9.2 Nothing in this DPA limits either Party’s liability to the extent it cannot lawfully be limited, including liability under the SCCs to Data Subjects.
10. Term
10.1 This DPA takes effect on the effective date of the Main Agreement and continues while the Processor Processes Personal Data on the Controller’s behalf, notwithstanding termination of the Main Agreement, until all such Personal Data is deleted or returned under clause 7.
11. General
11.1 In the event of a conflict, the order of precedence is: (1) the SCCs/UK Addendum; (2) this DPA; (3) the Main Agreement.
11.2 Any variation to this DPA must be in writing. The Processor may update Annex 2 (measures) and Annex 3 (sub-processors) in accordance with clauses 3.3–3.4, provided the changes do not materially reduce the protection of Personal Data.
11.3 Notices under this DPA shall be sent to the Processor at legal@smartvaultapp.io and to the Controller at the contact associated with its account.
12. Governing law and jurisdiction
12.1 This DPA is governed by the laws of the Republic of Cyprus, and the courts of the Republic of Cyprus have exclusive jurisdiction, save that this clause does not override the governing-law and forum provisions mandated by the SCCs or the UK Addendum in respect of transfers to which they apply.
Execution
This DPA applies automatically to each operator account from the effective date of the Main Agreement — no signature is required for it to bind the Parties. Customers that require a countersigned copy for their records can request one at legal@smartvaultapp.io.
Annex 1 — Details of Processing
| Subject matter | Provision of the SmartVault vehicle-custody management platform. |
| Duration | The term of the Main Agreement, plus the deletion/return period in clause 7. |
| Nature and purpose | Hosting, storage, structured record-keeping, retrieval, display, transmission, generation of documents (invoices, condition reports, Custody Passports), automated condition/summary analysis, email delivery, billing, and cryptographic timestamping — all to operate the Service for the Controller. |
| Frequency | Continuous, for the duration of the Controller’s use of the Service. |
Categories of Data Subjects
- The Controller’s authorised users and personnel (operator staff).
- The Controller’s clients (vehicle owners) and their authorised contacts.
- Prospective clients / leads / waitlist entries.
- Third-party service providers engaged through the Service.
Categories of Personal Data
- Identity & contact: names, email addresses, telephone numbers, postal/facility addresses.
- Account & authentication: usernames, hashed passwords, role, facility access, session and login metadata, IP addresses.
- Client & asset records: vehicle identifiers (VIN, registration), make/model, custody status, and associated records (inspections, movements, key custody, services, documents, messages, visits).
- Images: photographs of vehicles and their condition (which may incidentally contain Personal Data such as a registration plate).
- Financial: invoice data, amounts, payment references and status. (Payment card data is handled by the payment Sub-processor and is not stored by the Processor.)
- Communications: messages exchanged between operator and client within the Service.
Special Category Data: None intended or required. The Controller is instructed not to input Special Category Data (see clause 4.1).
Annex 2 — Technical and Organisational Measures (Article 32)
The Processor maintains the following measures, kept under review and appropriate to the risk:
Tenant isolation & access control
- Every customer’s data is logically segregated. All application data access is automatically scoped to the owning organisation at the data-access layer, with a fail-closed safeguard that blocks any query lacking a valid tenant scope.
- Row-Level Security is enabled at the database on application tables as defence in depth.
- Role-based access control (owner / admin / operator / viewer / client) with a granular permission model, and per-facility access scoping for staff.
- Cross-tenant isolation is verified by an automated test suite executed on every release.
Authentication
- Credential-based authentication with passwords stored using a strong one-way hash (bcrypt); optional two-factor authentication (TOTP) with second-factor secrets encrypted at rest and single-use recovery codes.
- Session tokens with enforced timeouts, and invalidation of other active sessions on security-sensitive account changes; rate limiting on login attempts by account and by IP; single-use, time-limited, hashed password-reset tokens.
Encryption
- Personal Data encrypted in transit (TLS/HTTPS) and at rest (provider-managed AES encryption at the hosting and storage layer).
- Private file storage served only via short-lived signed URLs; no public object access.
Integrity & auditability
- Append-only, hash-chained audit log, enforced at the database (write-once) so changes are tamper-evident and cannot be silently altered — including by the Processor’s own application.
- Automated cryptographic timestamping of finished records to a public network using hashes only (no Personal Data on-chain).
Application security & data minimisation
- Input validation on write operations; defences against prompt-injection on AI features; rate limiting on sensitive and third-party-proxying endpoints (durable, cross-instance limits on public data pages).
- Sensitive fields (e.g. password hashes, large binary image payloads) excluded from routine queries.
- Secrets held in a managed secrets store with access restricted to authorised personnel.
Availability & resilience
- Hosting on enterprise cloud infrastructure with regular automated backups provided by the database platform.
- Error and performance monitoring, plus a daily automated data-integrity health check with alerting.
Organisational
- Personnel authorised to Process Personal Data are bound by confidentiality.
- Least-privilege access to production systems; changes deployed through version control and automated checks.
- Sub-processor obligations flowed down by contract.
Annex 3 — Approved Sub-processors
| Sub-processor | Service provided | Personal Data processed | Primary location |
|---|---|---|---|
| Supabase (database & object storage) | Managed PostgreSQL database and private file storage | All categories in Annex 1 | EU — Ireland (AWS eu-west-1) |
| Vercel | Application hosting and serverless compute | All categories, transiently, during request processing | Compute in EU — Dublin (dub1); provider is US-headquartered |
| Resend | Transactional email delivery | Recipient name, email address, and message content (e.g. invoices, reports, notifications) | United States |
| Anthropic (Claude) | AI-assisted condition analysis, summaries, service recommendations, and import mapping | Vehicle/inspection data and any Personal Data contained in Controller-submitted content and import files, transiently for processing | United States |
| Stripe | Subscription billing and payment processing | Billing contact details, payment references and status (card data handled by Stripe as processor/controller for payments) | United States / Ireland |
| Sentry | Application error and performance monitoring | Diagnostic data that may incidentally include identifiers (e.g. a user email) present in error context | United States |
| Upstash | Durable rate-limiting and security counters (serverless key/value store) | IP addresses and account identifiers used as short-lived rate-limit and security keys | United States (provider); data held in the configured hosting region |
| Cloudflare (Turnstile) | Bot protection on the sign-in and sign-up forms | Visitor IP address and a browser challenge token, submitted for the bot check | United States |
| OpenStreetMap Foundation (Nominatim) | Address geocoding for facility/location mapping | Address strings submitted for lookup | United Kingdom / EU |
Notes.
- OpenTimestamps / Bitcoin are used for cryptographic timestamping. They receive only a hash and process no Personal Data; they are therefore not sub-processors of Personal Data.
- Satellite map tiles (Esri/ArcGIS) receive only map coordinates and no Personal Data.
- “Get directions” links open the Data Subject’s own map application; this is a user-initiated action, not a transfer by the Processor.
This page is the current authoritative sub-processor list, updated in accordance with clause 3.4.
Annex 4 — International Transfer Mechanisms
Primary location of Processing. The database and file storage are hosted in the Republic of Ireland (EEA); application compute is executed in Dublin, Ireland. Requests are routed via the hosting provider’s global edge network for TLS termination and routing; application compute and data storage remain in the EEA as described above.
Transfers outside the UK/EEA. Certain Sub-processors (Annex 3) Process Personal Data in the United States. For those transfers the following safeguards apply:
- EU/EEA exporters: the EU Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (Controller-to-Processor) between the Parties, and Module Three (Processor-to-Sub-processor) or equivalent between the Processor and each relevant Sub-processor.
- UK exporters: the same SCCs as varied by the ICO UK Addendum.
- Where a Sub-processor is certified under an applicable data-protection adequacy framework, that certification may additionally be relied upon.
SCC operative selections (between the Parties):
- Clause 7 (docking clause): applies.
- Clause 9 (sub-processors): Option 2 (general written authorisation); notice period per clause 3.4 of this DPA.
- Clause 11 (independent dispute resolution): not selected.
- Clause 17 (governing law) and Clause 18 (forum): as required by the SCCs for the relevant exporter; otherwise the law and courts of the Republic of Cyprus.
- Annex I (parties, description of transfer): populated by this DPA and Annex 1.
- Annex II (technical and organisational measures): Annex 2 of this DPA.
- Annex III (list of sub-processors): Annex 3 of this DPA.
End of Agreement.