Effective date: April 9, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between you (the “Customer”) and A group of entrepreneurs (“Processor”) governing use of CarGest (the “Services”) where the Customer acts as a controller (or processor on behalf of a controller) of personal data processed in the Services under applicable data protection law (including the GDPR as defined in those laws).
1. Definitions
“Applicable Data Protection Law” means data protection laws binding on the parties. “Personal Data,” “Controller,” “Processor,” “Processing,” and “Data Subject” have the meanings under Applicable Data Protection Law. “Subprocessor” means a third party engaged by Processor to process Personal Data.
2. Scope & roles
The Customer is the Controller of Personal Data it instructs Processor to process to provide the Services. Processor processes such data only on documented instructions from the Customer (including these Terms/DPA and use of the Services), unless otherwise required by law—in which case Processor will inform the Customer unless prohibited.
3. Details of processing
- Subject-matter: provision of the CarGest platform.
- Duration: for the term of the Services and as needed afterward per the Privacy Policy and backup/disaster recovery practices.
- Nature & purpose: hosting, storage, retrieval, support, security, and Service features the Customer enables.
- Categories of data subjects: Workspace Users and End-Customers (as defined in the Privacy Policy), as submitted by the Customer.
- Categories of personal data: identification and contact data, account data, transaction and vehicle/rental-related data, and other categories the Customer elects to input.
- Sensitive data: the Services are not intended for special categories of data unless the Customer has configured lawful bases and safeguards; the Customer is responsible for compliance.
4. Processor obligations
Processor will:
- process Personal Data only on documented instructions;
- ensure persons authorized to process Personal Data are bound by confidentiality;
- implement appropriate technical and organizational measures per Article 32 GDPR (or equivalent);
- assist the Customer—with regard to cost and feasibility—in responding to Data Subject requests and in complying with security, breach notification, and impact assessment obligations where required;
- delete or return Personal Data at the Customer’s choice at the end of the Services, unless law requires retention;
- make available information necessary to demonstrate compliance and allow audits on reasonable notice.
5. Subprocessors
The Customer authorizes Processor to engage Subprocessors. Processor will impose data protection terms on Subprocessors materially no less protective than this DPA. Processor remains liable for Subprocessor performance. A mechanism to object to new Subprocessors may be described in the main agreement or notified in advance where we add material vendors.
6. International transfers
Transfers from restricted jurisdictions will be subject to appropriate safeguards (e.g. Standard Contractual Clauses) unless another valid transfer tool applies.
7. Security incidents
Processor will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information needed for the Customer’s reporting obligations, in line with Applicable Data Protection Law.
8. Conflict
If this DPA conflicts with the Terms of Service, this DPA prevails solely with respect to processing of Personal Data covered here.