Fleet data processing agreement
B2B fleet contracts · July 2026
This page sets out the data processing agreement schedule Hypernest Innovations Limited provides to fleet customers using EnforceIQ Labs. Use this document for procurement and legal review. A countersigned Word or PDF copy is available on request — this web summary supports UK GDPR Article 28 due diligence but is not a substitute for a signed contract where your organisation requires one.
1. Roles
The fleet customer is the controller for driver and employee personal data. Hypernest is the processor, processing data only on documented instructions via EnforceIQ Labs and associated support channels.
The controller remains responsible for lawful basis, driver privacy notices, and ICO notification where applicable. The processor implements security measures, assists with data subject requests where feasible, and notifies the controller of personal data breaches.
2. Subject matter & duration
Processing is limited to PCN compliance workflow: notice ingestion, deadline tracking, driver assignment, appeal preparation, fleet reporting, and audit logging. Duration matches the subscription term plus any agreed wind-down period.
Processing does not include legal representation, payment of PCNs on behalf of the controller, or automated driver disciplinary action.
3. Categories of data
Data subjects include fleet drivers, transport managers, and invited organisation members. Personal data includes names, email addresses, vehicle registrations, PCN references, contravention details, uploaded notice images, appeal draft text, and audit metadata.
Special category data is not intentionally processed. Controllers should not upload unnecessary special category information in notice images or appeal text.
4. Security measures
Measures include tenant isolation (PostgreSQL RLS), encryption in transit and at rest, RBAC via Clerk Organizations, audit events, rate limiting, private object storage for uploads, and incident response aligned with our breach response procedure. Detailed security architecture is provided at fleet onboarding.
5. Subprocessors
Subprocessors are listed in the subprocessor register (Vercel, Neon, Clerk, Stripe, Resend, AWS S3, Upstash, optional Sentry). Hypernest will notify controllers of material changes with at least 14 days notice and opportunity to object on reasonable data protection grounds.
6. International transfers
Where subprocessors process data outside the UK, Hypernest relies on UK IDTA, UK Addendum to EU SCCs, or adequacy decisions as applicable. Transfer impact assessments are maintained in the compliance documentation pack (GDPR-01).
7. Breach notification
Hypernest will notify the controller without undue delay and within 48 hours of becoming aware of a personal data breach affecting controller data.
8. Data subject assistance
Hypernest provides self-service export and erasure tools for individual users. For fleet-wide requests, the processor assists the controller within reasonable timeframes. See the privacy notice for API endpoints.
9. Deletion & return
On termination, Hypernest will delete or return personal data per controller instructions within 30 days, except where law requires retention. Encrypted backup copies may persist for up to 30 additional days before automatic purge.
10. Audit rights
Controllers may audit processor compliance once per calendar year on 30 days written notice, or rely on third-party certifications where available. On-site audits are subject to confidentiality and security requirements.
Signed DPA
For a countersigned Word or PDF copy, contact [email protected]. This web page is a transparency summary for Art 28 due diligence — not a substitute for a countersigned contract where your organisation requires one.
Hypernest Innovations Limited · EnforceIQ Labs