MV Fleet ComplianceMV Fleet Compliance
TermsPrivacyCookiesData ProcessingSub-processorsData complaint
Controller / processor terms

Data Processing Addendum

Processor terms for personal data that customer operators control inside MV Fleet Compliance.

1. Parties and status

This Data Processing Addendum (“DPA”) forms part of the agreement between the Customer (controller) and trading as (processor) where MV processes personal data on the Customer’s behalf through MV Fleet Compliance. DPA version: .

2. Documented instructions

MV will process Customer Personal Data only on the Customer’s documented instructions, including those inherent in the Customer’s configuration and authorised users’ use of the service, unless UK law requires other processing. If law requires processing beyond those instructions, MV will inform the Customer before processing unless legally prohibited.

3. Confidentiality

MV will ensure that people authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and access information only to the extent necessary for their role.

4. Security

Taking account of the state of the art, costs, nature/scope/context/purposes and risks, MV will maintain appropriate technical and organisational measures. Current measures include authenticated accounts, company separation, role controls, database row-level security, private document storage, encryption in transit, protected server-side secrets, audit/history controls, backups/restore arrangements provided through the platform’s infrastructure, and procedures for security incidents.

5. Sub-processors

The Customer gives general authorisation for MV to appoint sub-processors necessary to provide and secure the service. MV will maintain a current public list at subprocessors.html and will require data-protection obligations appropriate to the processing. Where reasonably practicable, material new sub-processors will be notified through the platform or registered customer contact.

6. Data-subject requests

Taking account of the nature of processing, MV will provide reasonable assistance to enable the Customer to respond to requests to exercise data-protection rights. If MV receives a request relating to data controlled by the Customer, MV may refer the requester to the Customer and notify the Customer where appropriate.

7. Security incidents and personal-data breaches

MV will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide information reasonably available to assist the Customer with its legal assessment, notification and remediation duties. The Customer remains responsible for deciding whether notification to the ICO or affected people is legally required.

8. DPIAs and regulatory consultation

MV will provide reasonable information and assistance, taking account of the nature of processing and information available to MV, for the Customer’s data-protection impact assessments and any legally required prior consultation with the ICO.

9. Deletion and return

At the end of the services, MV will delete or return Customer Personal Data in accordance with the Customer’s documented instructions and the applicable exit process, unless law requires retention. Deletion from active systems may be followed by expiry through protected backup cycles rather than instantaneous removal from every backup copy.

10. Audit information

MV will make available information reasonably necessary to demonstrate compliance with applicable processor obligations and will allow reasonable audits or inspections where required by UK data-protection law, subject to appropriate confidentiality, security, scope, timing and cost controls. Existing security documentation and independent/provider evidence may be used first where it reasonably addresses the request.

11. International transfers

MV will not knowingly transfer Customer Personal Data outside the UK in breach of UK data-protection law. Where a sub-processor involves restricted transfers, MV will rely on an applicable adequacy regulation, UK International Data Transfer Agreement/Addendum or another lawful transfer mechanism as appropriate.

Annex 1 — Processing details

Subject matter and purpose

Hosting and operating a fleet-compliance SaaS platform; authentication; storage; reminders/notifications; driver/operator workflows; maintenance, defect and evidence management; support and security.

Duration

For the duration of the Customer’s account/agreement plus agreed/legal exit, backup and retention periods.

Data subjects

Customer account users, directors/owners, Transport Managers, employees, drivers, agency/casual drivers, contractors and other individuals whose information the Customer lawfully records.

Types of personal data

  • Identity, contact, employment and account information.
  • Driving licence identifiers/details and verification records, including NI number/postcode where the Customer stores these to support licence-check workflows.
  • DQC and tachograph-card details and expiries.
  • Medical/health declarations and eyesight information where used (special-category data).
  • Training, onboarding, signatures, policies/handbook acknowledgements.
  • Timesheets, holidays, expenses, fuel information where used.
  • Optional payroll payment details provided for the Customer’s payroll/payment administration, including account-holder name, bank/building society, sort code and account number.
  • Walkaround/defect records, photographs and evidence associated with a driver.
  • Audit, device/session and security information.
  • Limited Stripe billing metadata associated with the Customer account, such as Stripe customer/subscription identifiers, invoice status and payment-status events. Full card and bank account details are handled within Stripe and are not stored in the MV Fleet Compliance application.

Customer instructions

The Customer’s use/configuration of the platform, authorised-user actions, support requests and any written instructions consistent with the agreement.

Annex 2 — Security measures

  • HTTPS/TLS for data in transit.
  • Supabase authentication and company membership controls for operator accounts.
  • Database Row Level Security for customer separation.
  • Private storage buckets and signed/authorised file access.
  • Separate restricted server secrets outside public web files.
  • Role separation between platform admin, operator users and drivers.
  • Reduced driver data payloads so drivers do not receive unrelated workforce records.
  • Revision/conflict controls to reduce stale browser overwrites.
  • Audit/history records for key operational changes.
  • Infrastructure backups and controlled restore arrangements according to provider/account capabilities.
Legal and data protection enquiries: