Data Processing Agreement
Last updated September 15, 2026 · v1.1
This agreement governs how Fuel Relay processes personal data on behalf of its customers. It forms part of the Terms of Service and applies wherever data protection law such as the GDPR requires a processing agreement.
1. Parties and scope
This Data Processing Agreement ("DPA") is between the customer identified on the account (the "Controller") and [COMPANY_LEGAL_NAME], [BUSINESS_ADDRESS] (the "Processor", "we").
It is incorporated into the Terms of Service and is accepted by click-through when the admin account is created. Enterprise customers can request a countersigned copy at privacy@fuelrelay.net. This DPA applies to the extent we process personal data on the Controller's behalf and data protection law, including the GDPR and UK GDPR, applies to that processing.
2. Subject matter and duration
The subject matter is the processing of personal data needed to provide the Fuel Relay service: the mobile app, the admin dashboard, and the APIs behind them.
The duration is the term of the Controller's subscription plus the retention window described in the Privacy Policy: 90 days of export availability after cancellation, then scheduled deletion, or 30 days after the Controller requests account deletion. Signing in before the scheduled date cancels the deletion.
3. Nature and purpose of processing
We collect, store, sync, and display data submitted through the service; generate reports and exports the Controller runs; send service email; and maintain security records such as the audit log. The sole purpose is providing the service. We do not process Controller personal data for advertising, profiling, or model training.
4. Personal data and data subjects
Categories of personal data:
- Admins: email address, hashed password, company name.
- Fuelers: operator name, truck number, a device identifier, and fueling entries (date, time, contractor, truck or equipment code, fuel type, gallons). Voice entry is transcribed on the device by its platform speech service; we receive only confirmed text, never audio.
- Device data attached to crash reports: app version, OS version, device model, locale, screen size, free memory, battery level.
- Security records: the IP address and user agent of each audited action, kept in the audit log.
Categories of data subjects: the Controller's admins, employees, and contractors who use the service. No special categories of data are processed, and the service is not intended for data about children.
5. Obligations of the processor
We will:
- Process personal data only on the Controller's documented instructions, which are: these terms, the DPA, and the Controller's use of the service's features. We will inform the Controller if we believe an instruction violates data protection law.
- Ensure everyone we authorize to process the data is bound by confidentiality.
- Apply appropriate technical and organizational measures, including encryption in transit and at rest, per-tenant row-level security, least-privilege access, re-authentication for sensitive admin actions, and an append-only audit log. Our published summary is at fuelrelay.net/security.
- Assist the Controller with data subject requests and with security obligations.
- Delete or return all personal data at the end of the service term, on the schedule in the Privacy Policy (90 days after cancellation, 30 days after a deletion request), unless law requires longer storage. Audit log entries are anonymized (actor, IP address, and user agent cleared) and retained as security evidence.
6. Obligations of the controller
The Controller will:
- Have a lawful basis for the personal data it submits, and inform its fuelers and staff about the processing.
- Keep the data it enters accurate, and use the dashboard to correct or delete it.
- Issue and revoke fueler access codes responsibly.
- Give only instructions that comply with data protection law.
7. Sub-processors
The Controller gives general authorization for the sub-processors listed at fuelrelay.net/sub-processors. We impose data protection obligations on each sub-processor equivalent to this DPA and remain responsible for their performance.
We will notify admins by email before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within 30 days; if we cannot resolve the objection, the Controller may cancel the affected service.
8. Data subject rights
Taking into account the nature of the processing, we assist the Controller in fulfilling requests to access, export, correct, delete, or restrict processing of personal data. The dashboard's export and deletion tools cover most requests directly. If a data subject contacts us directly, we forward the request to the Controller without undue delay.
9. Personal data breaches
We notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data. The notice describes the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We document breaches and our response to them.
10. Audits
On request, we make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security measures and third-party assessments when available. The Controller may audit no more than once per year, on at least 30 days' written notice, during business hours, under confidentiality, at its own cost, and without access to other customers' data.
11. International transfers
Personal data is hosted in the United States (AWS us-west-1, Northern California). Where the Controller's personal data originates in the EEA, the UK, or Switzerland, the transfer is governed by the Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this DPA by reference and completed as set out in section 13, or by another lawful transfer mechanism.
12. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service, except where data protection law does not permit such limits. Questions about this DPA: privacy@fuelrelay.net or our data protection officer at dpo@fuelrelay.net.
13. Annexes and transfer terms
The Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two) are completed by reference to this DPA rather than by separate annexes:
- Annex I.A (parties) and Annex I.B (description of the transfer): the parties in section 1; the data subjects, categories of personal data, purpose, nature, and duration in sections 2 to 4. No sensitive data is transferred. Data is transferred continuously for the duration in section 2.
- Annex I.C (competent supervisory authority): the authority of the EU member state in which the Controller is established.
- Annex II (technical and organizational measures): section 5 and the published summary at fuelrelay.net/security.
- Annex III (sub-processors): the list at fuelrelay.net/sub-processors, authorized under section 7.
Clause selections. Clause 7 (docking clause) applies. Clause 9, Option 2 (general written authorization) applies, with the notice period in section 7. The optional language in Clause 11 (independent dispute resolution body) is not included. Clause 13: the supervisory authority is the one identified in Annex I.C above. Clause 17, Option 1: the Clauses are governed by the law of Ireland. Clause 18: disputes are resolved by the courts of Ireland.
United Kingdom. For transfers subject to the UK GDPR, the Clauses apply as amended by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner (version B1.0, in force 21 March 2022). Its tables are completed with the information above; for Table 4, neither party may end the Addendum under its section 19.
Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, references in the Clauses to the GDPR and to a member state are read as references to that Act and to Switzerland, and the Federal Data Protection and Information Commissioner is the competent authority.