Data processing addendum

Controller and processor terms.

This DPA applies automatically when Trackely processes personal data for a business customer.

Effective

25 July 2026

This Data Processing Addendum (DPA) forms part of the contract between the customer identified in an order form, checkout or account (Customer) and Trackely Ltd, company number 16551892, of 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE (Trackely). It is effective when Customer accepts the Terms or otherwise enters a contract that incorporates it. No separate signature is required. A separately signed DPA prevails if it expressly replaces this version.

1. Definitions

Applicable Data Protection Law means the UK GDPR, Data Protection Act 2018, retained or amended UK privacy law (including the Data (Use and Access) Act 2025), and where directly applicable the EU GDPR and relevant EEA law. Customer Personal Data means personal data processed by Trackely as processor for Customer. Data Protection Laws and the terms controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have their statutory meanings.

2. Roles, scope and instructions

Customer is controller and Trackely is processor for Customer Personal Data. If Customer acts for another controller, Customer is its authorised processor and appoints Trackely as subprocessor. Each party will comply with its own legal obligations.

Trackely will process Customer Personal Data only to provide, secure, maintain and support the service, follow Customer's documented configuration and requests, and comply with the contract and Schedule 1. The contract and Customer's authorised use are documented instructions. Trackely will tell Customer before processing required by law unless that law prohibits notice.

Trackely will promptly tell Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may pause the affected processing while the parties resolve it. Trackely is a controller for the limited independent processing described in its Privacy Notice.

3. Confidentiality and access

Trackely will ensure people authorised to process Customer Personal Data are bound by confidentiality and receive access only as needed for their role. Access is removed or adjusted when no longer required.

4. Security

Taking account of the state of the art, implementation cost, scope and risks, Trackely will maintain appropriate technical and organisational measures under Article 32, including the measures in Schedule 2. Customer is responsible for secure configuration, authorised users, endpoint devices, lawful data, least-privilege roles and reviewing available security settings.

5. Personal data breaches

Trackely will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As information becomes available, notice will describe the nature and likely consequences, affected data and people, contact point, and mitigation taken or proposed. Trackely will reasonably cooperate with Customer's investigation and notifications. Notice is not an admission of fault.

6. Data-subject requests

Taking account of the processing, Trackely will provide reasonable technical and organisational assistance for Customer to respond to requests. If Trackely receives a request relating to Customer Personal Data, it will direct the person to Customer or notify Customer and will not respond substantively unless instructed or required by law.

7. DPIAs, regulators and compliance

Trackely will provide information reasonably necessary for Customer's data protection impact assessment or prior consultation, having regard to the processing and information available to Trackely. Each party will reasonably cooperate with a competent supervisory authority.

8. Subprocessors

Customer gives general written authorisation for Trackely to appoint subprocessors. Current subprocessors and purposes are listed in the Subprocessor Register. Trackely will impose materially equivalent data-protection obligations and remains responsible for their performance to the extent required by law.

Trackely will give active customers at least 30 days' notice by service notice or email before a new subprocessor processes Customer Personal Data, where practicable. Customer may object during that period on reasonable data-protection grounds. The parties will try in good faith to find a reasonable alternative. If none is available, either party may terminate only the affected service on written notice before the change, and Trackely will refund prepaid fees for the unused affected period.

9. International transfers

Customer authorises processing in the UK and in other locations used by authorised subprocessors. Trackely will not make a restricted transfer without a lawful mechanism. Where required, the parties incorporate the ICO's then-current International Data Transfer Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement, using the information in this DPA, and Trackely will complete an appropriate transfer risk assessment. An applicable adequacy regulation takes priority while valid.

10. Return and deletion

During the subscription Customer may use available exports. On termination, and at Customer's choice communicated before the account is purged, Trackely will return available Customer Personal Data in a standard format or delete it. Unless the contract says otherwise, account erasure is normally queued for 30 days. Trackely may retain data required by law or preserved in limited rolling backups until expiry, provided it remains protected and is not used for another purpose.

11. Information and audits

Trackely will make available information reasonably necessary to demonstrate Article 28 compliance. Customer may audit once in any 12-month period and after a confirmed material breach, on at least 30 days' notice, during business hours and without disrupting or exposing other customers. The parties will first use current security documents and independent reports if available. Customer bears reasonable audit costs unless the audit identifies a material Trackely breach. Auditors must be independent, competent, non-competitive and bound by confidentiality.

12. Liability, conflict and law

Liability under this DPA is subject to the liability provisions of the contract. If this DPA conflicts with the contract on processing Customer Personal Data, this DPA prevails. It is governed by the law and jurisdiction specified in the contract.

Schedule 1 — Processing details

Subject matterHosted logistics, route, dispatch, driver workflow, tracking, proof, reporting, communications, integrations and support services.
DurationThe contract term plus the export, deletion and backup-expiry periods described above.
Nature and purposeCollecting, recording, organising, storing, retrieving, transmitting, displaying, analysing, securing, supporting, exporting and deleting data to provide the Customer-configured service.
FrequencyContinuous or as initiated by Customer and authorised users during the contract.
Data subjectsCustomer users and contacts; drivers, employees and contractors; recipients and end customers; suppliers, depot and site contacts; support correspondents; other people whose data Customer submits.
Personal dataIdentity, business contact and account data; delivery addresses and instructions; orders and references; route, assignment, location and activity data; vehicle and customer-uploaded compliance data; signatures, photos, notes and timestamps; communications and notification data; device, session, IP, API, audit, diagnostic and security events; integration data selected by Customer.
Sensitive dataNot intentionally required. Customer must not submit special-category or criminal-offence data unless agreed in writing and processed with a lawful basis and appropriate safeguards. Signatures are delivery evidence and are not used by Trackely for biometric identification.
Customer obligationsLawful, fair and transparent instructions; data minimisation and accuracy; notices and lawful bases; rights handling; retention and access configuration; special safeguards for worker monitoring.

Schedule 2 — Technical and organisational measures

  • TLS for browser and API traffic and provider storage encryption where supplied by the hosting platform.
  • Password hashing, managed sessions, optional MFA, hashed revocable API keys and secret handling controls.
  • Tenant-scoped application access, role permissions, authentication checks and separation of production from development practices.
  • Rate limiting, validation, security-relevant audit events, error handling and operational monitoring where configured.
  • Durable object storage for production uploads and access-controlled proof assets.
  • Dependency maintenance, change review, restricted administrative access and incident investigation procedures.
  • Retention, export, erasure and anonymisation workflows, subject to configured scope and provider backup expiry.
  • Confidentiality obligations and access removal for people with service access.

Measures may evolve to address risk and technology, but Trackely will not materially reduce overall protection during a subscription. No ISO, SOC or other certification is claimed unless expressly evidenced in writing.

Schedule 3 — Contact

Data-protection notices and requests: support@trackely.co.uk. Include the Customer legal name and tenant or billing reference.