Data Processing Addendum
This Data Processing Addendum (“DPA”) is part of the Terms of Service (or a signed Service Agreement) between RT Express (“Processor”, “we”) and the Customer (“Controller”, “you”). It applies to Customer Data we process to provide RT Track. If you need a signed copy, email dan@rtohio.com — checking “I agree” at onboarding also accepts this DPA.
1. Roles
You determine the purposes of your fleet and account-user data. We process that Customer Data only as your service provider / processor, to provide, secure, and support RT Track, and as described in the Privacy Policy.
We act as an independent business / controller for our own account records, security logs, demo-request leads, and similar data we collect for our business, as described in the Privacy Policy. This DPA does not cover that controller-side processing.
RT Track is offered to U.S. businesses. This DPA is written for U.S. state privacy laws (including the California Consumer Privacy Act as amended, the “CCPA”) and ordinary contract law. It is not a GDPR Article 28 agreement. If you later need EU/UK terms, ask us in writing before sending EU personal data.
2. Customer Data we process
| Category | Examples | Typical data subjects |
|---|---|---|
| Account users | Name, work email, phone, role, login timestamps | Your employees and contractors who use the portal |
| Asset registry | Unit number, type, notes, assignment to a tracker | Usually none (equipment). A name you type in a note could identify a person — you control that. |
| Telemetry | GPS time/lat/lon, speed, heading, voltage, battery, engine/ACC bit, signal, raw frames | Typically equipment. Location of a vehicle can sometimes be linked to a driver by you, not by us. |
| Alerts & geofences | Event records, zone names, recipient addresses/numbers | People you designate to receive alerts |
| Support | Tickets and emails you send us about the account | Your staff |
We do not process Social Security numbers, payment-card PAN (invoices are the default), driver license photos, or biometric data. We do not want you to paste those into notes.
3. Instructions and limitations
You instruct us to process Customer Data to provide RT Track as configured in the portal (including alerts you enable). We will not:
- sell Customer Data or share it for cross-context behavioral advertising;
- use it to build profiles for our own marketing to your drivers;
- retain, use, or disclose it except as needed to provide the service, as permitted by the Terms, as required by law, or as otherwise permitted of a “service provider” / “processor” under U.S. state privacy laws (including CCPA § 1798.140).
We certify that we understand those restrictions. If we can no longer meet them we will notify you and stop processing or allow you to take back the data.
You are responsible for the lawfulness of your instructions — including that you have the right to track the equipment, and that any employee notice your policies require is your job, not ours.
4. Your obligations
- Use RT Track only for equipment you are authorized to monitor (see Acceptable Use).
- Do not submit special categories of data we do not need.
- Configure users and recipients correctly; we will send alerts to the addresses and numbers you enter after they are verified where the product requires it.
- Handle data-subject requests that come to you; we will reasonably assist (see §7).
5. Security
We implement reasonable administrative, technical, and physical safeguards appropriate to a small B2B SaaS holding location history, including: TLS in transit; access control and tenant isolation; hashed passwords; least-privilege database roles; session controls; staff access only as needed; encrypted off-site backups; and logging of security-relevant events. No safeguard is perfect. Details may change as we improve the service; we will not materially weaken the overall posture without a compensating control.
6. Subprocessors
You authorize us to use the subprocessors listed at /subprocessors to process Customer Data as needed for the service. We remain responsible for their performance to the extent required by this DPA. We will post material changes to that list and notify account administrators. If you object to a new subprocessor for a legitimate data-protection reason, your remedy is to cancel under the Refunds & billing policy before the change takes effect.
7. Assistance, requests, and deletion
Taking into account the nature of the service, we will reasonably assist you with:
- access, correction, or deletion requests from your users that you cannot complete in the portal;
- information you need for your own security or privacy assessments, via a written summary of our practices (we do not host on-site audits of a shared production server as a default — we will discuss a reasonable alternative if a large customer requires it);
- deletion or return of Customer Data when the service ends, as described in the Terms and Privacy Policy (live data within a commercially reasonable period after a written request; backups expire on rotation).
If a data-subject request comes to us directly and we can tell it relates to you, we will point the person to you unless law requires us to handle it.
8. Breach notice
If we confirm unauthorized access to Customer Data on our systems, we will notify you without undue delay (and in any event as required by applicable U.S. law), with the facts we know: what happened, what data was involved, and what we are doing. We will cooperate reasonably on your own notification duties. We do not notify your drivers or the public except as law requires or as you direct in writing.
9. International transfers
We host Customer Data in the United States. Some subprocessors (for example map tiles in the browser, SMS delivery) may handle limited data outside the U.S. as described on the subprocessor list. You instruct us to make those transfers as needed to provide the service.
10. Term and order of documents
This DPA lasts as long as we process Customer Data for you. On conflict about data protection, this DPA controls over the Terms; a signed Service Agreement can modify this DPA only in writing. Liability remains subject to the limitation of liability in the Terms, except where law says that limitation cannot apply to a data-protection claim.