Route ZERO legal
RouteZero Data Processing Addendum
Between:
Dynamon Ltd, a company incorporated in England and Wales, company number 09633575 registered office at Kenneth Dibben House Enterprise Road, Southampton Science Park, Southampton, United Kingdom, SO16 7NS ("Dynamon", "Processor"); and
The customer organisation identified in the Subscription (the "Customer", "Controller").
(Each a "Party" and together the "Parties".)
This Data Processing Addendum (this "DPA") supplements and forms part of the Terms of Service between the Parties (the "Agreement") and governs the Processing of Personal Data carried out by Dynamon on behalf of the Customer in connection with the Service.
In the event of any conflict between this DPA and the Agreement in respect of Personal Data Processing, this DPA prevails.
1. Definitions
Capitalised terms not defined here have the meanings given in the Agreement or, if not defined there, in the UK GDPR.
"Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, as each may be updated, together with any successor legislation.
"Controller", "Processor", "Sub-processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach", "Special Category Data" and "Supervisory Authority" have the meanings given in Article 4 of the UK GDPR.
"Customer Personal Data" means Personal Data Processed by Dynamon on behalf of the Customer in connection with the Service.
"International Data Transfer" means a transfer of Personal Data to a country outside the United Kingdom that is not covered by an Adequacy Decision.
"Standard Contractual Clauses" or "SCCs" means the European Commission's standard contractual clauses approved under the EU GDPR; "UK IDTA" means the UK International Data Transfer Addendum to those clauses, issued by the Information Commissioner's Office.
2. Subject matter, duration and scope (Article 28(3) header)
| Item | Detail |
|---|---|
| Subject matter | Dynamon's Processing of Customer Personal Data as necessary to provide the Service to the Customer in accordance with the Agreement. |
| Duration | The term of the Agreement, plus any post-termination period reasonably necessary to comply with Clause 12 (Deletion / return). |
| Nature and purpose | Hosting, storing, transmitting, displaying, organising and otherwise Processing Customer Personal Data so that the Customer and its Users can use the Service for route planning, energy and charging simulation, fleet management and related analytical purposes. |
| Categories of Personal Data | As set out in Annex 1 of this DPA. |
| Categories of Data Subjects | As set out in Annex 1 of this DPA. |
| Special Category Data | None. The Customer is prohibited from uploading Special Category Data under Section 4 of the Terms of Service. |
| Frequency of transfer (where transfers occur) | Continuous, for the duration of the Agreement. |
| Retention | As set out in Annex 1 of this DPA. |
3. Customer obligations and warranties
The Customer warrants and undertakes that:
- It is and remains the Controller of the Customer Personal Data.
- It has a lawful basis under Applicable Data Protection Law for Processing the Customer Personal Data, including providing it to Dynamon for Processing in accordance with the Agreement.
- It has provided all necessary fair-processing information to, and obtained any required consents from, the relevant Data Subjects.
- Its instructions to Dynamon (including via its use of the Service's configuration options and APIs) comply with Applicable Data Protection Law.
- It has not uploaded any Special Category Data, Personal Data of children under 18, payment card data, or other prohibited content as set out in the Terms of Service.
The Customer indemnifies Dynamon against any third-party claim arising from breach of any of these warranties, subject to the liability allocation in the Agreement.
4. Dynamon's obligations as Processor (Article 28(3)(a)–(h))
Dynamon undertakes that it will:
4.1 Process only on documented instructions (Art 28(3)(a))
Process the Customer Personal Data only on the Customer's documented instructions, including transfers to a third country (where permitted by this DPA). The Agreement, this DPA, and the Customer's configuration of the Service constitute the Customer's documented instructions. If Dynamon believes any instruction infringes Applicable Data Protection Law, it will inform the Customer without undue delay (unless prohibited from doing so by law).
Dynamon may also Process Customer Personal Data where required by law to which Dynamon is subject, in which case Dynamon will (unless prohibited) inform the Customer of that requirement before Processing.
4.2 Confidentiality (Art 28(3)(b))
Ensure that persons authorised to Process the Customer Personal Data are bound by an obligation of confidentiality (whether contractual or statutory) and have received appropriate training.
4.3 Security (Art 28(3)(c) and Art 32)
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk to Customer Personal Data, as set out in Annex 2 of this DPA.
4.4 Sub-processors (Art 28(3)(d), 28(2), 28(4))
Engage Sub-processors only in accordance with Clause 5.
4.5 Assistance with Data Subject requests (Art 28(3)(e))
Taking into account the nature of the Processing, assist the Customer by appropriate technical and organisational measures, in so far as possible, to respond to requests from Data Subjects exercising their rights under Chapter III of the UK GDPR.
Dynamon provides standard tooling within the Service for Customers to perform many of these actions directly (e.g. update, export and delete Customer Personal Data). Where the Customer requires additional assistance, Dynamon will provide it on the basis of reasonable cost recovery.
4.6 Assistance with security, breach notification, DPIA, consultation (Art 28(3)(f) and Art 32–36)
Assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of the Processing and the information available to Dynamon. In particular:
- Personal Data Breaches: Dynamon will notify the Customer without undue delay (and in any event within [72] hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing the information set out in Clause 7.
- DPIAs: Dynamon will provide reasonable assistance to the Customer in conducting any Data Protection Impact Assessment that the Customer is required to perform in respect of the Service.
4.7 Deletion or return (Art 28(3)(g))
Delete or return Customer Personal Data at the end of the provision of the Service in accordance with Clause 12.
4.8 Demonstration of compliance and audit (Art 28(3)(h))
Make available to the Customer all information necessary to demonstrate compliance with the obligations in this Clause 4 and allow for and contribute to audits in accordance with Clause 9.
5. Sub-processors
5.1 General authorisation
The Customer grants Dynamon a general authorisation to engage Sub-processors to Process the Customer Personal Data, subject to this Clause 5.
5.2 Current Sub-processors
The Sub-processors currently engaged are listed at Route ZERO Sub-processors. By signing this DPA, the Customer specifically authorises the engagement of these Sub-processors.
5.3 New Sub-processors
Dynamon will give the Customer reasonable prior notice, normally at least 14 days, of the appointment of any new Sub-processor or the replacement of any existing Sub-processor, via:
- update to the published Sub-processor list, with an updated effective date; and
- notification by email to the privacy contact recorded for the Customer.
5.4 Right to object
The Customer may, on reasonable grounds related to data protection, object to a proposed new Sub-processor by notice in writing to support@dynamon.co.uk within [15] days of the notice. If the Customer objects:
- Dynamon will use reasonable efforts to make available a change in the Service or recommend a commercially reasonable change to the Customer's configuration of the Service to avoid Processing of Customer Personal Data by the proposed Sub-processor.
- If Dynamon is unable to make available such change within a reasonable period (which will not exceed [30] days), the Customer may terminate the Agreement (in respect of the Service only) on [15] days' notice. Termination on this basis is the Customer's sole remedy.
5.5 Sub-processor contracts
Dynamon will impose on each Sub-processor data protection obligations no less protective than those imposed on Dynamon by this DPA. Dynamon remains liable to the Customer for the performance of each Sub-processor's obligations.
6. International data transfers
6.1 Primary location
Customer Personal Data is hosted in AWS region eu-west-2 (London), United Kingdom.
6.2 Transfers to Sub-processors
Where a Sub-processor's normal operations involve an International Data Transfer, the transfer is governed by the mechanism stated for that Sub-processor in the Sub-processors list (typically the UK IDTA).
6.3 Standard mechanism
Where no Adequacy Decision applies and no other transfer mechanism in Article 46 of the UK GDPR applies, the Parties agree that the UK IDTA is incorporated into this DPA by reference, with the following selections:
- Module: Controller-to-Processor (Module 2).
- Docking clause: included.
- Optional clauses: as set out in Annex 3.
6.4 Onward transfers
Where Dynamon transfers Customer Personal Data to a Sub-processor that itself onward-transfers to a third country, Dynamon ensures that the onward transfer is subject to an equivalent safeguard.
7. Personal Data Breach notification
7.1 Notification timeline
Dynamon will notify the Customer without undue delay (and in any event within [72] hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2 Contents of notification
Each notification will, to the extent the information is then available to Dynamon, include:
- a description of the nature of the breach, including (where possible) the categories and approximate number of Data Subjects affected and the categories and approximate number of records affected;
- the name and contact details of the Dynamon contact (typically support@dynamon.co.uk) from whom further information can be obtained;
- a description of the likely consequences of the breach; and
- a description of the measures taken or proposed to be taken to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
Dynamon will provide updates and further information as soon as reasonably practicable.
7.3 No supervisory authority notification by Dynamon
Notification to a Supervisory Authority or to Data Subjects is the responsibility of the Customer as Controller. Dynamon will provide reasonable assistance.
7.4 No admission of liability
A notification under this Clause 7 is not an admission by Dynamon of liability, breach, or fault.
8. Data Subject requests
Dynamon will, without undue delay, notify the Customer of any request received directly from a Data Subject in respect of Customer Personal Data. Dynamon will not respond to such a request itself except on the Customer's documented instructions or as required by law.
Where the Customer requires Dynamon's assistance to respond to a Data Subject request, Dynamon will provide it as set out in Clause 4.5.
9. Audit rights
Dynamon will make available to the Customer, on reasonable written request, the information necessary to demonstrate Dynamon's compliance with this DPA. Reasonable requests include requests for copies of:
- current ISO 27001, SOC 2 Type II, or equivalent third-party certification reports, where Dynamon holds them;
- Cyber Essentials Plus certification;
- Dynamon's information security policy summary; and
- the published Sub-processor list and any change history.
A Supervisory Authority's exercise of its statutory powers is not subject to this Clause 9.
10. Liability
The liability of each Party under this DPA is subject to, and counts towards, the liability provisions in the Agreement. Nothing in this DPA excludes or limits liability for matters that cannot lawfully be excluded or limited.
11. Term
This DPA takes effect on the date the Customer accepts it (at Checkout, on first acceptance of the Service, or by executed counterpart) and continues for the term of the Agreement.
12. Deletion or return on termination
On termination of the Agreement, the Customer may export Customer Personal Data from the Service for a period of [30] days from the effective date of termination. After that period:
- Dynamon will delete Customer Personal Data from primary systems within [30] days.
- Dynamon will delete Customer Personal Data from backups in accordance with its backup rotation, and in any event within [90] days.
- Billing records and tax records will be retained for the statutory retention period (6 years from the end of the relevant accounting period, under HMRC requirements), with access restricted to tax, audit and legal purposes only.
- Personal Data subject to a legal hold will be retained for the duration of the hold.
Dynamon will, on reasonable request and at the Customer's cost, provide a written certification of deletion.
13. Order of precedence
If there is any conflict between the documents that form this agreement, the following order of precedence applies (highest first):
- The UK IDTA (where applicable).
- This DPA.
- The Agreement (Terms of Service).
- Any other policy or document referenced from the Agreement.
14. Governing law and jurisdiction
This DPA is governed by the laws of England and Wales. The English courts have exclusive jurisdiction, subject to any provisions in the UK IDTA where it applies.
15. Miscellaneous
The general provisions in the Agreement (entire agreement, assignment, severability, waiver, force majeure, third-party rights, notices) apply equally to this DPA.
Annex 1 — Description of Processing
Subject matter, nature and purpose
Provision of the RouteZero Service to the Customer, including hosting, storage, transmission, organisation, retrieval and analytical processing of Customer Personal Data as necessary for the Service.
Categories of Personal Data
Personal Data Processed in the course of providing the Service includes, where the Customer uploads or generates it:
- business contact information for the Customer's Users (name, work email, work phone, job title, role within the Organisation);
- depot, customer, and destination addresses entered by the Customer for route planning;
- vehicle metadata not tied to a named driver (model, configuration, battery capacity, registration date — this does not include the registration plate of a vehicle linked to an identifiable driver, which is prohibited under the Terms of Service);
- route and operational parameters entered by the Customer; and
- usage and account metadata about the Customer's Users (login timestamps, activity logs, IP addresses).
Where the Customer breaches the Terms of Service and uploads other categories of Personal Data, the Customer is responsible — see Clause 3.
Categories of Data Subjects
- The Customer's Users.
- Other natural persons whose Personal Data the Customer chooses to upload to the Service in compliance with the Terms of Service (typically business contacts at depots, customer sites, or partner organisations).
Retention
As set out in Clause 12 (Deletion or return on termination) and in the Terms of Service and Privacy Notice. In summary:
- Service data: retained while the Account is active; 30-day primary deletion + 90-day backup expiry on request or termination.
- Billing records: 6 years (HMRC).
- Inactive Trial accounts: 24-month auto-deletion with warning.
Annex 2 — Technical and Organisational Security Measures
Dynamon implements the following measures to ensure a level of security appropriate to the risk to Customer Personal Data, in accordance with Article 32 of the UK GDPR.
Access control and authentication
- Customer authentication via AWS Cognito with support for multi-factor authentication.
- Dynamon staff access to production systems via individually-named accounts with the principle of least privilege.
- No shared credentials. All administrative access logged.
- Periodic review of staff access rights.
Network and infrastructure security
- All Customer Personal Data hosted in AWS region eu-west-2 (London).
- Encryption in transit using TLS 1.2+ for all customer-facing endpoints.
- Encryption at rest for the primary database (AWS RDS) and object storage (AWS S3).
- Network isolation via AWS VPC; production resources accessible only via documented paths.
- Credentials and secrets stored in AWS Secrets Manager; never committed to source control.
Application security
- Secure software development lifecycle including code review.
- Dependency vulnerability monitoring.
- Cyber Essentials Plus certification.
Operational security
- Monitoring of system availability and security-relevant events.
- Backup procedures with regular testing of restore capability.
- Incident response procedure (see internal Breach Response SOP).
- Documented Data Subject request handling procedure (see internal DSAR SOP).
- Personal data processed in accordance with the principle of data minimisation.
Personnel
- Confidentiality obligations in employment and contractor agreements.
- Data protection awareness training on onboarding and periodically thereafter.
Resilience
- Multi-availability-zone deployment within the primary region for database resilience.
- Documented disaster recovery procedure for major incident scenarios.
Periodic review
- Annual review of these security measures.
- Review on any material change to the Service architecture, the Sub-processor list, or the applicable legal framework.
Annex 3 — International Transfer Clauses (UK IDTA)
Where a transfer of Customer Personal Data outside the UK takes place under Clause 6.3, the following selections apply.
- Module. Module 2 (Controller to Processor).
- Docking clause. The optional docking clause is included.
- Clause 7 — option of audits. The Customer may request compliance information subject to Clause 9 of this DPA. On-site audits are not offered.
- Clause 9 — appointment of Sub-processors. Option 2 (general written authorisation) applies. The minimum notice period for new Sub-processors is normally 14 days, consistent with Clause 5.3.
- Clause 11 — dispute resolution. The optional independent dispute resolution body is not selected.
- Clause 17 — governing law. The laws of England and Wales.
- Clause 18 — choice of forum and jurisdiction. The courts of England and Wales.
Annex I of the UK IDTA
- Data exporter: the Customer as Controller (details as in the Subscription record).
- Data importer: Dynamon Ltd, as Processor (details as in this DPA header).
- Description of transfer: as set out in Annex 1 of this DPA.
Annex II of the UK IDTA
Technical and organisational measures: as set out in Annex 2 of this DPA.
Annex III of the UK IDTA
Sub-processors: as set out at Route ZERO Sub-processors, updated from time to time in accordance with Clause 5.