Data Processing Addendum
Last updated: 16 September 2026
Document Reference: TCH-UK-DPA-2026-V1
Pursuant to Article 28 of the UK General Data Protection Regulation (UK GDPR).
Parties: Tachyo LTD ("Data Processor") and the Contracting Fleet Operator ("Data Controller").
1. Scope, subject matter & statutory roles
1.1 Regulatory Scope: This Addendum governs the processing of personal data by Tachyo LTD on behalf of the Customer in connection with the provision of the Tachyo fleet telematics, compliance, and yield platform pursuant to Article 28(3) of the UK GDPR.
1.2 Designation of Roles:
- (a) The Customer is and shall remain the Data Controller in respect of all fleet operational data, including driver location data, shifts, tachograph advisory calculations, walkaround defect images, and fuel receipts.
- (b) Tachyo LTD is and shall act strictly as the Data Processor acting solely under the documented instructions of the Customer.
1.3 Details of Processing Activities:
- (a) Subject Matter: Automated ingestion, calculation, display, and storage of commercial vehicle fleet telematics, driver duty timestamps, vehicle roadworthiness logs, and delivery remittance reconciliation.
- (b) Duration: The duration of the Customer's commercial subscription plus the mandatory 14-day data export and retention window.
- (c) Categories of Data Subjects: Commercial HGV drivers (employed under PAYE, engaged as self-employed subcontractors, or supplied via third-party driver recruitment agencies), Transport Managers, and logistics dispatchers.
- (d) Types of Personal Data: Driver full names, internal identification numbers, mobile GPS coordinates, vehicle registration mark (VRM) linkage, shift hours, photographs of defect walkaround inspections, and fuel pump receipt images.
2. Processor obligations & documented instructions
2.1 Processing Instructions: Tachyo LTD shall process personal data only on documented instructions from the Customer (including via the configuration settings and user interactions within the SaaS dashboard), unless required to do so by the laws of England and Wales or statutory UK public authority orders.
2.2 Staff Confidentiality: Tachyo LTD guarantees that all software engineers, support specialists, and personnel authorized to access production databases have committed themselves to strict statutory obligations of confidentiality.
2.3 Technical & Organizational Measures (Security): Tachyo LTD shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- (a) Storage of database records strictly within AWS London (eu-west-2);
- (b) Cryptographic encryption of database storage volumes and backups using Advanced Encryption Standard (AES-256);
- (c) Enforced end-to-end transport layer encryption (TLS 1.3) across all API communications;
- (d) Automated daily database snapshot backups retained in an encrypted state.
3. Sub-processors & infrastructure authorisation
3.1 General Written Authorisation: The Customer hereby grants Tachyo LTD general written authorisation to engage the third-party sub-processors specified below:
- (a) Supabase Inc. — Managed PostgreSQL Database Engine & Authentication (hosted in AWS London, UK);
- (b) Amazon Web Services EMEA SARL — S3 Object Storage for defect images and fuel dockets (AWS London eu-west-2, UK);
- (c) Stripe Payments UK, Ltd. — Subscription payment processing and billing infrastructure (London, UK);
- (d) Twilio Ireland Limited / SendGrid UK — SMS VOR safety alerts and critical two-factor notifications.
3.2 Sub-Processor Flow-Down: Tachyo LTD warrants that it imposes statutory data protection obligations no less onerous than those set out in this DPA upon every sub-processor via formal contract.
3.3 Notification of Sub-Processor Alterations: Tachyo LTD shall provide the Customer with at least thirty (30) calendar days' electronic notice prior to appointing any new sub-processor, providing the Customer with the commercial opportunity to object on reasonable data protection grounds.
4. The driver employment tribunal & surveillance shield (total indemnity)
Draft — pending qualified legal review
This is the highest-risk clause in the whole portal and needs a solicitor's eyes before it's relied on. A contractual indemnity between Tachyo and the Customer cannot stop a driver bringing their own claim directly against Tachyo, and "full indemnity solicitor-and-own-client basis" costs recovery is a specific, technical costs-law term that needs to be drafted correctly to actually work.
4.1 Customer Warranty on Driver Transparency: The Customer expressly warrants and covenants that:
- (a) Prior to requiring or requesting any driver (whether direct employee, agency driver, or self-employed sub-contractor) to download, log into, or use the Tachyo mobile endpoint, the Customer has provided said driver with a statutory Article 13/14 UK GDPR Employee Privacy Notice;
- (b) The Customer possesses an audited lawful basis under Article 6 of the UK GDPR (such as Legitimate Interests supported by an LIA, or statutory compliance with the Goods Vehicles Act 1995) to conduct GPS tracking and duty-time verification;
- (c) The Customer maintains sole responsibility for complying with the Information Commissioner's Employment Practices Code regarding electronic monitoring at work.
4.2 Full Indemnification by Customer:
- (a) The Customer shall indemnify, defend, and hold harmless Tachyo LTD, its directors, and officers against all liabilities, losses, damages, legal costs (calculated on a full indemnity solicitor-and-own-client basis), fines, and settlements arising from:
- (i) Any claim, grievance, or Employment Tribunal action brought by a driver alleging unlawful workplace surveillance, constructive dismissal, or infringement of privacy rights under Article 8 of the European Convention on Human Rights (ECHR);
- (ii) Any enforcement action or administrative monetary penalty issued by the Information Commissioner's Office (ICO) resulting from the Customer's failure to establish a lawful basis for monitoring its transport workforce.
5. Data subject rights & regulatory assistance
5.1 Assistance via In-Product Utilities: Taking into account the nature of the processing, Tachyo LTD shall assist the Customer by appropriate technical measures, insofar as this is commercially possible, to respond to drivers exercising statutory rights under Chapter III of the UK GDPR (including Subject Access Requests and Rectification).
5.2 Driver Request Routing: Where a driver submits a Subject Access Request (SAR) directly to Tachyo LTD, Tachyo shall not disclose any Customer records directly, but shall notify the Customer's designated Transport Manager within three (3) business days.
5.3 Exclusion of Unilateral Erasure: Tachyo LTD shall not alter, redact, or erase any historical defect inspections, maintenance confirmations, or duty hours records upon direct driver request, recognizing that such records represent statutory property of the Customer mandated for retention under the Goods Vehicles (Licensing of Operators) Act 1995.
6. Audit rights & regulatory inspections
6.1 Provision of Compliance Proof: Tachyo LTD shall make available to the Customer all information reasonably necessary to demonstrate compliance with the statutory obligations laid down in Article 28 UK GDPR.
6.2 Audit Parameters:
- (a) Any physical or electronic audit by the Customer or its appointed independent auditor shall occur no more than once in any twelve-month period;
- (b) Audits mandate at least thirty (30) business days' prior written notice;
- (c) Audits shall be conducted during normal UK business hours without disrupting operational SaaS infrastructure;
- (d) Audits shall not grant access to proprietary source code, underlying intellectual property, or data belonging to other multi-tenant fleet subscribers.
7. Termination, 14-day export window & irreversible hard purge
7.1 Cessation of Processing: Upon termination or expiration of the Customer's SaaS subscription, Tachyo LTD shall immediately halt all active telematics processing, driver check-in ingestions, and OCR parsing.
7.2 Mandatory 14-Day Self-Service Export: The Customer shall maintain self-service access to the read-only reporting portal for exactly fourteen (14) calendar days post-termination to export all historical fleet compliance logs, inspection dockets, and settlement records in structured .csv format.
7.3 Automated Cryptographic Purge:
- (a) At 23:59 BST on the fourteenth (14th) calendar day following subscription termination, Tachyo LTD's automated database routines shall execute an irreversible, cryptographic hard deletion of all Customer personal data across active database tables, object storage buckets (receipts and defect photos), and temporary session logs within AWS London (eu-west-2).
- (b) Backup archives shall be overwritten and eradicated in accordance with standard disaster recovery rotation cycles (not to exceed thirty (30) days).
7.4 Certification of Destruction: Upon written request received prior to the expiration of the 14-day window, Tachyo LTD shall issue an electronic Certificate of Data Destruction confirming compliance with this Clause.