← Privacy notice

Fleet data processing agreement

B2B fleet contracts · July 2026

This page sets out the data processing agreement schedule Hypernest Innovations Limited provides to fleet customers using EnforceIQ Labs. Use this document for procurement and legal review. A countersigned Word or PDF copy is available on request — this web summary supports UK GDPR Article 28 due diligence but is not a substitute for a signed contract where your organisation requires one.

1. Roles

The fleet customer is the controller for driver and employee personal data. Hypernest is the processor, processing data only on documented instructions via EnforceIQ Labs and associated support channels.

The controller remains responsible for lawful basis, driver privacy notices, and ICO notification where applicable. The processor implements security measures, assists with data subject requests where feasible, and notifies the controller of personal data breaches.

2. Subject matter & duration

Processing is limited to PCN compliance workflow: notice ingestion, deadline tracking, driver assignment, appeal preparation, fleet reporting, and audit logging. Duration matches the subscription term plus any agreed wind-down period.

Processing does not include legal representation, payment of PCNs on behalf of the controller, or automated driver disciplinary action.

3. Categories of data

Data subjects include fleet drivers, transport managers, and invited organisation members. Personal data includes names, email addresses, vehicle registrations, PCN references, contravention details, uploaded notice images, appeal draft text, and audit metadata.

Special category data is not intentionally processed. Controllers should not upload unnecessary special category information in notice images or appeal text.

4. Security measures

Measures include tenant isolation (PostgreSQL RLS), encryption in transit and at rest, RBAC via Clerk Organizations, audit events, rate limiting, private object storage for uploads, and incident response aligned with our breach response procedure. Detailed security architecture is provided at fleet onboarding.

5. Subprocessors

Subprocessors are listed in the subprocessor register (Vercel, Neon, Clerk, Stripe, Resend, AWS S3, Upstash, optional Sentry). Hypernest will notify controllers of material changes with at least 14 days notice and opportunity to object on reasonable data protection grounds.

6. International transfers

Where subprocessors process data outside the UK, Hypernest relies on UK IDTA, UK Addendum to EU SCCs, or adequacy decisions as applicable. Transfer impact assessments are maintained in the compliance documentation pack (GDPR-01).

7. Breach notification

Hypernest will notify the controller without undue delay and within 48 hours of becoming aware of a personal data breach affecting controller data.

8. Data subject assistance

Hypernest provides self-service export and erasure tools for individual users. For fleet-wide requests, the processor assists the controller within reasonable timeframes. See the privacy notice for API endpoints.

9. Deletion & return

On termination, Hypernest will delete or return personal data per controller instructions within 30 days, except where law requires retention. Encrypted backup copies may persist for up to 30 additional days before automatic purge.

10. Audit rights

Controllers may audit processor compliance once per calendar year on 30 days written notice, or rely on third-party certifications where available. On-site audits are subject to confidentiality and security requirements.

Signed DPA

For a countersigned Word or PDF copy, contact [email protected]. This web page is a transparency summary for Art 28 due diligence — not a substitute for a countersigned contract where your organisation requires one.

Hypernest Innovations Limited · EnforceIQ Labs