Data Processing Agreement — Emaride and Fleet Partner
This Data Processing Agreement ("DPA") implements Art. 28 GDPR for the relationship between Emaride and a fleet partner. It is the document referred to in clause 15.2 of the Fleet Partner Agreement ("FPA"): "Where a Party processes Personal Data on behalf of and on the documented instructions of the other, the Data Processing Agreement in the GDPR Compliance Package applies and is incorporated by reference and prevails on data-protection matters."
It requires no separate acceptance. It becomes binding through the signed Fleet Partner Agreement, which incorporates it by reference. There is no tick box for it, and a tick box would add nothing to that.
On data protection matters this DPA prevails over the Fleet Partner Agreement (clause 15.2 FPA). In all other respects the Fleet Partner Agreement prevails.
1. Parties and Scope — When This DPA Applies at All
Parties are
- Emaride EU S.à r.l., société à responsabilité limitée under Luxembourg law, represented by its sole manager Ramez Mohamad Alkhalaf, Luxembourg ("Emaride"), and
- the fleet partner named in the Fleet Partner Agreement ("Fleet Partner").
This DPA applies only to processing in which one party actually processes personal data on behalf of and on the documented instructions of the other. For that processing, the party giving the instruction is the controller and the other is the processor. The roles are not attached to a party: either party can be the processor for a given operation.
That is the exception, not the rule. In the ordinary operation of the Platform both parties are separate controllers, each for its own purposes and on its own responsibility. Art. 28 GDPR does not apply to that processing, and neither do the obligations in clauses 3 to 12 below.
schedule-7 decides which case applies. It allocates, for each data category, who is
controller and who is processor (clause 15.2 FPA). Where the allocation of an individual category
is in doubt, schedule-7 prevails, and it also decides whether this DPA applies to that category
at all. schedule-7 additionally records that Art. 26 GDPR (joint controllership) is expressly
excluded: there is no joint determination of purposes and means.
Cases identified today in which this DPA does apply:
- Emaride as processor for the Fleet Partner — where Emaride stores or processes content that the Fleet Partner enters or uploads solely for the Fleet Partner's own purposes and to which Emaride attaches no purpose of its own, and where Emaride prepares an export or an evaluation on the Fleet Partner's instruction that Emaride does not need for its own purposes.
- The Fleet Partner as processor for Emaride — where the Fleet Partner collects, retains, or forwards data on Emaride's documented instruction without a purpose of its own, in particular where it retains records under clause 14.2 FPA solely as evidence for an Emaride audit or a supervisory-authority request.
This list is not a limitation. Where a further case arises, this DPA applies to it as soon as one
party instructs the other in documented form; the case is then added to schedule-7 at the next
version.
2. Subject-matter, Duration, Nature and Purpose of the Processing
| Item | Content |
|---|---|
| Subject-matter | Processing of personal data that one party carries out on the documented instruction of the other in connection with the Fleet Partner Agreement, within the scope in clause 1 |
| Duration | The term of the Fleet Partner Agreement; the obligations survive until the data has been deleted or returned under clause 10 |
| Nature of the processing | Storage, organisation, retrieval, use, transmission to the recipients named in the instruction, restriction, erasure — as automated processing in the Platform, and in the Fleet Partner's case also processing not carried out in the Platform |
| Purpose | Solely the purpose of the instructing controller as recorded in the instruction. There is no own purpose of the processor and no further use — no product development, no analytics, no training of models, no enrichment of the processor's data |
| Categories of data subjects | Passengers, drivers, contact persons of the Fleet Partner, authorised employees of corporate clients — as set out per category in schedule-7 clause 5 |
| Categories of personal data | Identity, contact, ride, location, transaction and settlement, record and eligibility, communication, and log data — as set out per category in schedule-7 clauses 3 and 5 |
| Special categories (Art. 9) | None. No instruction may extend to special categories of personal data. Should such processing become necessary, this DPA must be amended beforehand |
| Transfers to third countries | Only under clause 12 |
3. Instructions
The processor processes personal data only on the documented instructions of the controller, including as regards transfers to a third country or an international organisation. Instructions are given in text form and are documented; for Emaride the address for this is privacy@emaride.lu, and for the Fleet Partner the contact address recorded in the Fleet Partner Agreement. An oral instruction must be confirmed in text form without delay.
The processor processes no data beyond the instruction and for no purpose of its own. Where Union or Member State law to which the processor is subject requires the processing, the processor informs the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
Duty to inform where an instruction is unlawful (Art. 28(3), second sentence, GDPR). Where the processor is of the opinion that an instruction infringes the GDPR or another data protection provision, it informs the controller without delay. The processor is entitled to suspend the execution of that instruction until the controller confirms or amends it in text form. The processor is not obliged to execute an instruction that is manifestly unlawful.
4. Confidentiality
The processor ensures that the persons authorised to process the data have undertaken to observe confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process the data only in accordance with the instruction. Access is granted on the principle of least privilege and only to persons who need it for the instructed processing. The obligation of confidentiality survives the end of the Fleet Partner Agreement and the end of the employment or engagement of the individual person.
5. Security of Processing (Art. 32 GDPR)
The processor takes appropriate technical and organisational measures. These are, specifically:
- Encryption in transit — transport encryption (TLS) for all connections between apps, web dashboard, interfaces, and the database.
- Encryption at rest — encryption of the stored data and of the record files at the hosting provider.
- Access control and least privilege — access restricted by role and country, enforced in the database access rules, not merely in the user interface. Particularly sensitive fields are ring-fenced separately: bank details are accessible only to the owner role and to authorised Emaride staff, and the ride verification code is held in a separate table that is not readable by any app role.
- Authentication — passwords stored only as hashes; support for a second factor and for passkeys; interface keys stored only as hashes with prefix and last four characters kept for identification.
- Logging — security- and settlement-relevant operations are recorded in a change log (who triggered which change and when); login attempts are recorded with the IP address for a short window.
- Pseudonymisation where practicable — internal identifiers instead of names in interfaces to processors; the payment service provider receives an internal identifier of the organisation, not its records.
- Backup, resilience, and restoration — regular backups with the ability to restore availability and access to the data in a timely manner after an incident.
- Secure development — separated environments, review before deployment, automated tests and guards for access rules and data flows.
- Management of processors — sub-processors only under clause 6; Emaride's processor register records for each provider the appointment check, the agreement, the sub-processor chain, and the objection period.
- Incident response — a defined route for reporting, assessing, and notifying personal data breaches (clause 8).
- Awareness — instruction of the persons authorised to process data before they are granted access.
These measures describe the state that the parties owe. A change is permitted, provided it does not lower the level of protection. No certification is asserted: Emaride holds no security certification of its own; the measures are its own documented ones. Obtaining a certification is an open item and is not claimed here in advance.
6. Sub-processors
The controller grants a general authorisation for the engagement of sub-processors that are
listed in schedule-7 clause 7 at the time this DPA is concluded. Any further engagement
requires authorisation.
- Timely information about intended changes. The processor informs the controller in text form of any intended addition or replacement of a sub-processor at least 30 days in advance, stating the service, the place of processing, the categories of data concerned, and the basis for any transfer to a third country.
- Right to object. The controller may object within 30 days of that information, stating reasons. Where it objects, the parties seek a solution; until one is found, the processing affected does not take place through the sub-processor concerned. Where no solution is found within a reasonable period, either party may terminate the service affected without cost to the objecting party.
- Equivalent obligations and continuing liability. The processor imposes on every sub-processor, by contract, data protection obligations equivalent to those under this DPA, and remains fully liable to the controller for the sub-processor's performance.
The state of conclusion for each provider — appointment check, agreement, sub-processor list, objection period — is recorded in Emaride's processor register. It is not repeated here, so that there is a single place to maintain. Open item before go-live: as at the date of this DPA, none of the agreements recorded there is marked as concluded. A general authorisation does not cure a missing Art. 28 agreement with the provider in question.
7. Assistance with Data Subject Rights
The processor assists the controller, taking into account the nature of the processing, in fulfilling requests from data subjects under Arts. 12 to 23 GDPR.
- A request that reaches the processor but concerns the controller's processing is forwarded without undue delay, and at the latest within five business days, together with everything needed to answer it.
- The processor does not itself answer requests concerning the controller's processing, unless the controller instructs it to do so. It informs the data subject of the responsible point of contact.
- On instruction, the processor rectifies, restricts, or erases data, or provides it in a structured, commonly used, machine-readable format.
8. Personal Data Breaches
The processor notifies the controller of a personal data breach without undue delay, and in any event within 48 hours of becoming aware of it. The notification contains, as far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Where the information is not available in full, it is provided in stages without further undue delay.
The 48-hour period is deliberately shorter than the controller's own period: the controller must notify the supervisory authority within 72 hours under Art. 33(1) GDPR, and this period is what keeps that possible.
The processor takes no notification to a supervisory authority or to the controller's data subjects on its own initiative and does not communicate publicly about the incident, unless it is itself legally obliged to do so. Where it is, it informs the controller beforehand and coordinates the wording as far as legally possible.
9. Data Protection Impact Assessments and Prior Consultation
The processor assists the controller in carrying out a data protection impact assessment (Art. 35 GDPR) and in a prior consultation of the supervisory authority (Art. 36 GDPR), by providing the information on the processing, the measures under clause 5, and the sub-processors that the controller needs and cannot obtain otherwise.
10. Deletion or Return at the End of the Processing
On termination of the instructed processing, and at the latest on termination of the Fleet Partner Agreement, the processor, at the controller's choice, deletes or returns all personal data processed on the instruction, and deletes existing copies. The controller exercises the choice in text form; the processor performs it within 30 days and confirms it in text form.
Exception, retention obligations. Where Union or Member State law requires the data to be retained — in particular the ten-year retention of accounting and tax records — the data is not deleted. In that case the processor restricts the processing to the retention purpose, blocks any other use, and deletes the data when the period expires. It informs the controller which data is affected and for how long.
11. Audits and Demonstration of Compliance
The processor makes available to the controller the information necessary to demonstrate compliance with Art. 28 GDPR and allows audits, including inspections, by the controller or by an auditor mandated by it.
- Not more than once per calendar year, and additionally after a personal data breach or at the request of a supervisory authority.
- On at least 14 days' notice in text form, during normal business hours, and under confidentiality.
- With minimal disruption to the operation of the audited party, and in compliance with data protection law — this is the standard already agreed in clause 14.3 FPA and it applies to audits under this clause as well. The costs are borne in accordance with clause 14.3 FPA.
- Recognised certifications, external audit reports, and the processor's own documentation may be used to demonstrate compliance; an on-site inspection takes place where they are not sufficient in the individual case.
Emaride's audit rights under clause 14 FPA — authorisations, insurance, driver eligibility, vehicle standards, anti-circumvention — are separate from this clause and remain unaffected. This clause concerns only the demonstration of data protection compliance.
12. Transfers to Third Countries
Personal data is processed within the EEA; the data region is the EU (Frankfurt).
A transfer to a country outside the EEA takes place only on the documented instruction of the controller and only where
- an adequacy decision of the European Commission under Art. 45 GDPR covers the recipient country, or
- appropriate safeguards under Art. 46 GDPR are in place, in particular the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supplemented by an assessment of the legal situation in the recipient country and by any additional measures required.
This mirrors clause 15.4 FPA. The providers concerned and the basis applying to each are set
out in schedule-7 clause 7; the state of conclusion is recorded in
Emaride's processor register. Onward transfer by a sub-processor to a further third country
follows the same conditions.
13. Liability, Precedence, Term, Amendments
Liability is subject to the limitations in the Fleet Partner Agreement, save for liability that may not be limited under applicable law, in particular liability towards data subjects under Art. 82 GDPR. Each party bears the liability for its own processing; there is no chain of instructions that shifts that liability.
Precedence. On data protection matters this DPA prevails over the Fleet Partner Agreement
(clause 15.2 FPA). For the allocation of roles per data category, schedule-7 prevails over this
DPA.
Term. This DPA runs for the term of the Fleet Partner Agreement and survives until the data has been deleted or returned under clause 10.
Amendments are made in text form. Where a change in the law, a decision of a supervisory authority, or a court ruling makes an adjustment necessary, either party may require it; until it is made, the parties process the data in the manner that complies with the law.
14. Contact
Emaride EU S.à r.l. — privacy@emaride.lu (instructions, data subject requests, notification of a personal data breach, information about sub-processors).
Fleet Partner — the contact address recorded in the Fleet Partner Agreement. The Fleet Partner keeps that address current; a notification under clause 8 is deemed to have been given when it is sent to the last address notified.
A data protection officer has not been appointed at present. Assessing whether an appointment is required under Art. 37 GDPR, and the appointment itself, are open items before go-live.
15. Deviations from the V2.1 Legal Package
This DPA follows Part C of the GDPR Compliance Package and clause 15 of the Fleet Partner Agreement. Where it deviates, it does so for the reason stated:
| V2.1 Part | Our clause | Deviation and reason |
|---|---|---|
| C.1 — roles and scope | clause 1 | Made specific. The package leaves open which processing is actually carried out on instructions. We state that this is the exception and that in the ordinary case both parties are separate controllers under schedule-7. A DPA that read as if all Platform processing were Art. 28 processing would misstate the roles and shift liability to the wrong party. |
| C.1 — documented instructions | clause 3 | Adopted, and extended by a named address, text form, and the right to suspend a manifestly unlawful instruction. |
| C.2 — Art. 28(3) obligations | clauses 3–11 | Adopted in full and broken down into individual clauses, so that each obligation has an addressee and a period. |
| C.3 — objection period of 14 days | clause 6 | Extended to 30 days, and the information period is set at 30 days in advance. Reason: Emaride's processor register already operates a 30-day objection period for Emaride's own providers. One period for both directions is easier to keep than two, and the longer period favours the objecting party. |
| C.4 — breach notification within 48 hours | clause 8 | Adopted verbatim, with the reason stated: the controller's own period under Art. 33(1) GDPR is 72 hours. |
| C.5 — transfers | clause 12 | Adopted and aligned with clause 15.4 FPA; the data region and the requirement of a transfer assessment are named. |
| C.6 — audit once per year | clause 11 | Adopted, and tied to clause 14.3 FPA (minimal disruption, allocation of costs), so that one standard applies to audits under the Agreement and under this DPA. Emaride's audit rights under clause 14 FPA are expressly kept separate. |
| C.7 — liability | clause 13 | Adopted. |
| C.8 — duration | clause 13 | Adopted. |
| Annex C-1 — processing details with blanks | clause 2 | Blanks filled. Subject-matter, nature, and purpose are named; data subjects and data categories refer to schedule-7 rather than being duplicated. Special categories are expressly excluded from the scope of any instruction. |
| Annex C-2 — security measures | clause 5 | Made specific against the product instead of listing keywords: which measures exist, where they are enforced, and which fields are ring-fenced separately. No certification is asserted, because there is none; obtaining one is named as an open item. |
| Part K — sub-processor register | clause 6 | Not duplicated. The list of providers sits in schedule-7 clause 7 and the state of conclusion in Emaride's processor register. A third copy would only create a third place to fall out of date. Expressly stated: as at today none of the agreements is marked as concluded, and a general authorisation does not cure that. |
| Part C — parties | clause 1 | The package writes the DPA for any principal agreement. This version is written for the Fleet Partner Agreement only; the corporate client relationship gets its own annex when a corporate client agreement is signed. |
Part A.1 — contact addresses at @emaride.com |
clause 14 | Changed to @emaride.lu. |