Data Processing Addendum

1. Roles

You determine the purposes of your fleet and account-user data. We process that Customer Data only as your service provider / processor, to provide, secure, and support RT Track, and as described in the Privacy Policy.

We act as an independent business / controller for our own account records, security logs, demo-request leads, and similar data we collect for our business, as described in the Privacy Policy. This DPA does not cover that controller-side processing.

RT Track is offered to U.S. businesses. This DPA is written for U.S. state privacy laws (including the California Consumer Privacy Act as amended, the “CCPA”) and ordinary contract law. It is not a GDPR Article 28 agreement. If you later need EU/UK terms, ask us in writing before sending EU personal data.

2. Customer Data we process

We do not process Social Security numbers, payment-card PAN (invoices are the default), driver license photos, or biometric data. We do not want you to paste those into notes.

3. Instructions and limitations

You instruct us to process Customer Data to provide RT Track as configured in the portal (including alerts you enable). We will not:

We certify that we understand those restrictions. If we can no longer meet them we will notify you and stop processing or allow you to take back the data.

You are responsible for the lawfulness of your instructions — including that you have the right to track the equipment, and that any employee notice your policies require is your job, not ours.

4. Your obligations

5. Security

We implement reasonable administrative, technical, and physical safeguards appropriate to a small B2B SaaS holding location history, including: TLS in transit; access control and tenant isolation; hashed passwords; least-privilege database roles; session controls; staff access only as needed; encrypted off-site backups; and logging of security-relevant events. No safeguard is perfect. Details may change as we improve the service; we will not materially weaken the overall posture without a compensating control.

6. Subprocessors

You authorize us to use the subprocessors listed at /subprocessors to process Customer Data as needed for the service. We remain responsible for their performance to the extent required by this DPA. We will post material changes to that list and notify account administrators. If you object to a new subprocessor for a legitimate data-protection reason, your remedy is to cancel under the Refunds & billing policy before the change takes effect.

7. Assistance, requests, and deletion

Taking into account the nature of the service, we will reasonably assist you with:

If a data-subject request comes to us directly and we can tell it relates to you, we will point the person to you unless law requires us to handle it.

8. Breach notice

If we confirm unauthorized access to Customer Data on our systems, we will notify you without undue delay (and in any event as required by applicable U.S. law), with the facts we know: what happened, what data was involved, and what we are doing. We will cooperate reasonably on your own notification duties. We do not notify your drivers or the public except as law requires or as you direct in writing.

9. International transfers

We host Customer Data in the United States. Some subprocessors (for example map tiles in the browser, SMS delivery) may handle limited data outside the U.S. as described on the subprocessor list. You instruct us to make those transfers as needed to provide the service.

10. Term and order of documents

This DPA lasts as long as we process Customer Data for you. On conflict about data protection, this DPA controls over the Terms; a signed Service Agreement can modify this DPA only in writing. Liability remains subject to the limitation of liability in the Terms, except where law says that limitation cannot apply to a data-protection claim.