How to execute this DPA: print this page (or save as PDF), fill in the Controller details and signature blocks, sign, and email a scan to info@cloudgps.online — we will return a countersigned copy. This DPA is also deemed incorporated by reference into the Service Agreement between the parties.
All customer data is hosted exclusively in the EU — Hetzner Online GmbH, Falkenstein, Germany. See our Privacy Policy.
This Data Processing Agreement ("DPA") is entered into between:
the Controller: the customer identified in the signature block below and/or in the Service Agreement (the "Controller"), and
the Processor: Private Entrepreneur Oleksandr Oliinyk, operating the cloudGPS platform, registration no. 3137207472, Zaporizhzhia, Ukraine ("cloudGPS" or the "Processor"),
together the "Parties", and supplements the agreement under which cloudGPS provides the fleet telematics service to the Controller (the "Service Agreement").
1. Definitions
"GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Sub-processor" means a processor engaged by the Processor to process personal data on behalf of the Controller.
2. Scope and roles
2.1. The Processor processes personal data on behalf of the Controller as described in Annex I, solely to provide the services under the Service Agreement.
2.2. In respect of such data, the Controller acts as controller and the Processor acts as processor. This DPA prevails over the Service Agreement in data protection matters.
2.3. Partner / white-label scenario. Where the party identified as Controller uses the platform to provide services to its own clients (including under the cloudGPS partner programme, on its own domain and brand), it may itself act as a processor on behalf of those clients. In that case this DPA applies mutatis mutandis as a sub-processing agreement: cloudGPS acts as sub-processor, the documented instructions of that party are deemed to include the instructions of its clients acting as controllers, and for the purposes of Clause 11.2 Module Three (processor to processor) of the Standard Contractual Clauses applies. That party warrants that its own data processing agreements with its clients permit the engagement of cloudGPS on the terms of this DPA.
3. Instructions
3.1. The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do otherwise by EU or Member State law; in that case the Processor informs the Controller before processing, unless the law prohibits it on important grounds of public interest.
3.2. The Service Agreement, this DPA, and the Controller's configuration and use of the platform (including its settings, API calls and user actions) constitute the Controller's documented instructions.
3.3. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
4. Confidentiality
The Processor ensures that all persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and access data strictly on a need-to-know basis under role-based access control.
5. Security
The Processor implements and maintains the technical and organisational measures set out in Annex II, in accordance with Article 32 GDPR. The Processor may update these measures from time to time, provided the updates do not materially lower the overall level of protection.
6. Sub-processors
6.1. The Controller grants a general authorisation to engage the sub-processors listed in Annex III.
6.2. The Processor gives the Controller at least 30 days' prior notice (by email or via the platform) of any intended addition or replacement of a sub-processor. The Controller may object on reasonable data protection grounds; if the Parties cannot resolve the objection, the Controller may terminate the affected services.
6.3. The Processor imposes on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the sub-processor's performance.
7. Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures (including export, correction and deletion functions of the platform) in fulfilling the Controller's obligation to respond to data subject requests under Chapter III GDPR. The Processor forwards to the Controller, without undue delay, any request it receives directly from a data subject, and does not respond to it except on the Controller's instruction.
8. Personal data breach
The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's personal data, providing the information required by Article 33(3) GDPR as it becomes available, and documents all breaches, their effects and remedial action taken.
9. Impact assessments
The Processor provides reasonable assistance to the Controller with data protection impact assessments and prior consultations under Articles 35–36 GDPR, insofar as they relate to the processing under this DPA.
10. Audits
10.1. The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, in the first instance through security documentation and completed questionnaires.
10.2. The Processor allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller: no more than once per 12 months (except after a personal data breach), with at least 30 days' written notice, during business hours, under confidentiality, without access to data of other customers, and at the Controller's expense.
11. International transfers
11.1. All personal data at rest is stored exclusively within the European Union — on dedicated servers operated by Hetzner Online GmbH, Falkenstein, Germany, including database replicas, file storage and backups.
11.2. The Processor's personnel may access the platform remotely from Ukraine for administration and support. For this remote access the Parties incorporate by reference the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module Two: controller to processor), with the Controller as data exporter and the Processor as data importer; Annexes I and II of this DPA serve as Annexes I and II of the Clauses; the competent supervisory authority is that of the Controller's Member State.
11.3. Transfers to sub-processors outside the EU/EEA take place only under the safeguards listed in Annex III (EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses).
12. Return and deletion
Upon termination of the Service Agreement, the Processor, at the choice of the Controller, deletes or returns (in a structured, commonly used, machine-readable format) all personal data processed on the Controller's behalf, and deletes existing copies within 90 days, unless EU or Member State law requires further storage. Upon request, the Processor confirms deletion in writing.
13. Liability
The liability of each Party under this DPA is subject to the limitations and exclusions of liability set out in the Service Agreement, and each Party is liable towards data subjects in accordance with Article 82 GDPR.
14. Term and governing law
14.1. This DPA takes effect on the date of the last signature (or, where incorporated by reference, on the effective date of the Service Agreement) and remains in force until all personal data has been deleted or returned under Clause 12.
14.2. This DPA is governed by the law governing the Service Agreement; in the absence of such a choice, by the law of the EU Member State in which the Controller is established.
Signatures
Controller
Company name / reg. no.
Registered address
Name, title
Date, signature
Processor
PE Oleksandr Oliinyk (cloudGPS)
Registration no. 3137207472
Zaporizhzhia, Ukraine
info@cloudgps.online
Name, title
Date, signature
A. Parties
Data exporter (Controller): the customer identified in the signature block / Service Agreement.
Data importer (Processor): PE Oleksandr Oliinyk (cloudGPS), reg. no. 3137207472, Zaporizhzhia, Ukraine, info@cloudgps.online.
B. Processing details
| Subject matter | Provision of the cloudGPS fleet telematics platform (SaaS): GPS tracking, fuel monitoring, geofencing, reports, alerts, maintenance and driver management. |
|---|---|
| Duration | The term of the Service Agreement, plus the deletion period under Clause 12. |
| Nature and purpose | Collection (from tracking devices and user input), storage, structuring, retrieval, display, analysis and erasure of vehicle telemetry and related data, to provide fleet monitoring services to the Controller. |
| Categories of data subjects | Drivers and other employees or contractors of the Controller; users authorised by the Controller; the Controller's contact persons. Where the Controller resells the service (partner / white-label programme, Clause 2.3) — the corresponding persons on the side of the Controller's clients. |
| Categories of personal data | Vehicle location data (GPS coordinates, speed, heading, routes, mileage, engine hours); telemetry and sensor readings (ignition, fuel, temperature, CAN-bus); device identifiers (IMEI, serial, SIM); driver identification events (iButton / RFID); driver names, phone numbers, email addresses and photos where entered by the Controller; vehicle registration plates; login and usage logs. |
| Special categories | None intended. The Controller undertakes not to submit special categories of personal data (Art. 9 GDPR) to the platform. |
| Frequency | Continuous, for the duration of the Service Agreement. |
- Hosting: all production data on dedicated servers operated by Hetzner Online GmbH in Falkenstein, Germany (EU); physical security provided by ISO 27001-certified data centers; no storage of customer data outside the EU.
- Encryption in transit: TLS for all web, mobile and API traffic; private network (VLAN) isolation for inter-node traffic.
- Access control: role-based access control (RBAC), per-tenant data isolation, least-privilege access for personnel.
- Authentication: multi-factor authentication for administrative access; password strength enforcement; automated protection against brute-force and credential-stuffing attacks with automatic blocking.
- Infrastructure hardening: SSH access by cryptographic keys only; host firewalls and network segmentation; application servers reachable only via dedicated load balancers (origin isolation).
- Resilience: replicated three-node database cluster with automated failover; regular backups stored within the EU; 24/7 availability monitoring and alerting.
- Logging and monitoring: centralised security and authentication logging; audit logging of administrative operations.
- Organisational measures: confidentiality obligations for all personnel; need-to-know access; defined incident response process; sub-processors bound by written data protection agreements.
| Sub-processor | Processing / role | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Dedicated servers, storage and backups for all production data | Germany (EU) | Not required (EU) |
| Functional Software, Inc. (Sentry) | Application error monitoring | EU data region (Germany) | EU data residency; DPF for support access |
| Anthropic | AI support assistant — support conversation text and relevant device context, only when the support chat is used; API data not used for model training | USA | DPF / SCC |
| ADM.tools | Transactional email delivery (service notifications) | Ukraine | SCC |
| Cloudflare, Inc. | DNS for platform domains; application traffic and customer data do not pass through Cloudflare | Global | DPF / SCC |
The Processor notifies the Controller at least 30 days before adding or replacing a sub-processor (Clause 6). The current list is also published at cloudgps.online/dpa/.
White-label tenants may configure their own SMTP server for outgoing notifications. In that case email for that tenant is delivered by the provider chosen by the partner (as the partner's own processor) instead of the email sub-processor listed above.