Data Processing Agreement (GDPR)

Standard DPA under Article 28 GDPR  ·  Version 1.0, 26 July 2026  ·  cloudGPS fleet telematics platform

✍️

How to execute this DPA: print this page (or save as PDF), fill in the Controller details and signature blocks, sign, and email a scan to info@cloudgps.online — we will return a countersigned copy. This DPA is also deemed incorporated by reference into the Service Agreement between the parties.

All customer data is hosted exclusively in the EU — Hetzner Online GmbH, Falkenstein, Germany. See our Privacy Policy.

This Data Processing Agreement ("DPA") is entered into between:

the Controller: the customer identified in the signature block below and/or in the Service Agreement (the "Controller"), and

the Processor: Private Entrepreneur Oleksandr Oliinyk, operating the cloudGPS platform, registration no. 3137207472, Zaporizhzhia, Ukraine ("cloudGPS" or the "Processor"),

together the "Parties", and supplements the agreement under which cloudGPS provides the fleet telematics service to the Controller (the "Service Agreement").

1. Definitions

"GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Sub-processor" means a processor engaged by the Processor to process personal data on behalf of the Controller.

2. Scope and roles

2.1. The Processor processes personal data on behalf of the Controller as described in Annex I, solely to provide the services under the Service Agreement.

2.2. In respect of such data, the Controller acts as controller and the Processor acts as processor. This DPA prevails over the Service Agreement in data protection matters.

2.3. Partner / white-label scenario. Where the party identified as Controller uses the platform to provide services to its own clients (including under the cloudGPS partner programme, on its own domain and brand), it may itself act as a processor on behalf of those clients. In that case this DPA applies mutatis mutandis as a sub-processing agreement: cloudGPS acts as sub-processor, the documented instructions of that party are deemed to include the instructions of its clients acting as controllers, and for the purposes of Clause 11.2 Module Three (processor to processor) of the Standard Contractual Clauses applies. That party warrants that its own data processing agreements with its clients permit the engagement of cloudGPS on the terms of this DPA.

3. Instructions

3.1. The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do otherwise by EU or Member State law; in that case the Processor informs the Controller before processing, unless the law prohibits it on important grounds of public interest.

3.2. The Service Agreement, this DPA, and the Controller's configuration and use of the platform (including its settings, API calls and user actions) constitute the Controller's documented instructions.

3.3. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.

4. Confidentiality

The Processor ensures that all persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and access data strictly on a need-to-know basis under role-based access control.

5. Security

The Processor implements and maintains the technical and organisational measures set out in Annex II, in accordance with Article 32 GDPR. The Processor may update these measures from time to time, provided the updates do not materially lower the overall level of protection.

6. Sub-processors

6.1. The Controller grants a general authorisation to engage the sub-processors listed in Annex III.

6.2. The Processor gives the Controller at least 30 days' prior notice (by email or via the platform) of any intended addition or replacement of a sub-processor. The Controller may object on reasonable data protection grounds; if the Parties cannot resolve the objection, the Controller may terminate the affected services.

6.3. The Processor imposes on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the sub-processor's performance.

7. Assistance with data subject rights

Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures (including export, correction and deletion functions of the platform) in fulfilling the Controller's obligation to respond to data subject requests under Chapter III GDPR. The Processor forwards to the Controller, without undue delay, any request it receives directly from a data subject, and does not respond to it except on the Controller's instruction.

8. Personal data breach

The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's personal data, providing the information required by Article 33(3) GDPR as it becomes available, and documents all breaches, their effects and remedial action taken.

9. Impact assessments

The Processor provides reasonable assistance to the Controller with data protection impact assessments and prior consultations under Articles 35–36 GDPR, insofar as they relate to the processing under this DPA.

10. Audits

10.1. The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, in the first instance through security documentation and completed questionnaires.

10.2. The Processor allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller: no more than once per 12 months (except after a personal data breach), with at least 30 days' written notice, during business hours, under confidentiality, without access to data of other customers, and at the Controller's expense.

11. International transfers

11.1. All personal data at rest is stored exclusively within the European Union — on dedicated servers operated by Hetzner Online GmbH, Falkenstein, Germany, including database replicas, file storage and backups.

11.2. The Processor's personnel may access the platform remotely from Ukraine for administration and support. For this remote access the Parties incorporate by reference the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module Two: controller to processor), with the Controller as data exporter and the Processor as data importer; Annexes I and II of this DPA serve as Annexes I and II of the Clauses; the competent supervisory authority is that of the Controller's Member State.

11.3. Transfers to sub-processors outside the EU/EEA take place only under the safeguards listed in Annex III (EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses).

12. Return and deletion

Upon termination of the Service Agreement, the Processor, at the choice of the Controller, deletes or returns (in a structured, commonly used, machine-readable format) all personal data processed on the Controller's behalf, and deletes existing copies within 90 days, unless EU or Member State law requires further storage. Upon request, the Processor confirms deletion in writing.

13. Liability

The liability of each Party under this DPA is subject to the limitations and exclusions of liability set out in the Service Agreement, and each Party is liable towards data subjects in accordance with Article 82 GDPR.

14. Term and governing law

14.1. This DPA takes effect on the date of the last signature (or, where incorporated by reference, on the effective date of the Service Agreement) and remains in force until all personal data has been deleted or returned under Clause 12.

14.2. This DPA is governed by the law governing the Service Agreement; in the absence of such a choice, by the law of the EU Member State in which the Controller is established.

Signatures

Controller

Company name / reg. no.

Registered address

Name, title

Date, signature

Processor

PE Oleksandr Oliinyk (cloudGPS)
Registration no. 3137207472
Zaporizhzhia, Ukraine
info@cloudgps.online

Name, title

Date, signature

Annex I — Description of the processing

A. Parties

Data exporter (Controller): the customer identified in the signature block / Service Agreement.
Data importer (Processor): PE Oleksandr Oliinyk (cloudGPS), reg. no. 3137207472, Zaporizhzhia, Ukraine, info@cloudgps.online.

B. Processing details

Subject matterProvision of the cloudGPS fleet telematics platform (SaaS): GPS tracking, fuel monitoring, geofencing, reports, alerts, maintenance and driver management.
DurationThe term of the Service Agreement, plus the deletion period under Clause 12.
Nature and purposeCollection (from tracking devices and user input), storage, structuring, retrieval, display, analysis and erasure of vehicle telemetry and related data, to provide fleet monitoring services to the Controller.
Categories of data subjectsDrivers and other employees or contractors of the Controller; users authorised by the Controller; the Controller's contact persons. Where the Controller resells the service (partner / white-label programme, Clause 2.3) — the corresponding persons on the side of the Controller's clients.
Categories of personal dataVehicle location data (GPS coordinates, speed, heading, routes, mileage, engine hours); telemetry and sensor readings (ignition, fuel, temperature, CAN-bus); device identifiers (IMEI, serial, SIM); driver identification events (iButton / RFID); driver names, phone numbers, email addresses and photos where entered by the Controller; vehicle registration plates; login and usage logs.
Special categoriesNone intended. The Controller undertakes not to submit special categories of personal data (Art. 9 GDPR) to the platform.
FrequencyContinuous, for the duration of the Service Agreement.
Annex II — Technical and organisational measures
Annex III — Authorised sub-processors
Sub-processorProcessing / roleLocationTransfer safeguard
Hetzner Online GmbHDedicated servers, storage and backups for all production dataGermany (EU)Not required (EU)
Functional Software, Inc. (Sentry)Application error monitoringEU data region (Germany)EU data residency; DPF for support access
AnthropicAI support assistant — support conversation text and relevant device context, only when the support chat is used; API data not used for model trainingUSADPF / SCC
ADM.toolsTransactional email delivery (service notifications)UkraineSCC
Cloudflare, Inc.DNS for platform domains; application traffic and customer data do not pass through CloudflareGlobalDPF / SCC

The Processor notifies the Controller at least 30 days before adding or replacing a sub-processor (Clause 6). The current list is also published at cloudgps.online/dpa/.

White-label tenants may configure their own SMTP server for outgoing notifications. In that case email for that tenant is delivered by the provider chosen by the partner (as the partner's own processor) instead of the email sub-processor listed above.