Data Processing Agreement
Version 2026-07-26 · In effect from 26 July 2026
These are the Article 28 GDPR terms between your depot (the "Controller") and Oxus Technologies Limited (the "Processor"). They form part of the Terms of Service and are accepted by the depot owner, who alone can bind the depot.
1.Roles
The Controller determines the purposes and means of processing the personal data it puts into DepotIQ - principally its drivers' and employees' data. The Processor processes that data only to provide the platform, and only on the Controller's documented instructions. Use of the platform's features constitutes the Controller's instructions; anything beyond them requires a written request.
If the Processor is required by EU or Member State law to process data beyond those instructions, it will inform the Controller before doing so unless that law prohibits it.
2.Subject matter and scope of processing
| Subject matter | Provision of the DepotIQ delivery depot management platform |
| Duration | For the term of the subscription, plus the deletion period in section 9 |
| Nature and purpose | Storage, structuring, calculation, analysis, retrieval and erasure of depot operational data |
| Categories of data subject | Delivery drivers, depot employees, and depot staff users |
| Categories of personal data | Identity and contact details; employment type; work, attendance and performance records; compliance document details; pay, deduction and commission figures; and - where the Controller chooses to store them - financial and tax identifiers (PPS, IBAN, BIC, VAT) |
| Special category data | None. The Controller must not upload special category data (Art. 9) to the platform |
3.Processor obligations
- Process personal data only on the Controller's documented instructions, including on transfers.
- Ensure everyone authorised to process the data is bound by confidentiality obligations.
- Implement the technical and organisational measures in section 5.
- Respect the conditions in section 4 for engaging subprocessors.
- Assist the Controller, so far as possible, in responding to data subject requests.
- Assist the Controller with data protection impact assessments and with prior consultation of the supervisory authority.
- Delete or return the data at the end of the service, per section 9.
- Make available the information needed to demonstrate compliance, and allow and contribute to audits under section 8.
- Immediately inform the Controller if, in its opinion, an instruction infringes data protection law.
4.Subprocessors
The Controller gives general authorisation for the Processor to engage the subprocessors listed below. The Processor imposes the same data protection obligations on each of them by contract and remains fully liable to the Controller for their performance. The Processor will give at least 30 days' notice before adding or replacing a subprocessor, during which the Controller may object on reasonable data protection grounds; if the objection cannot be resolved, the Controller may terminate the affected service without penalty.
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting and delivery | Dublin, Ireland (dub1) with US parent; EU Standard Contractual Clauses in place |
| Supabase | PostgreSQL database and encrypted file storage | AWS eu-west-1 (Ireland) |
| Google Ireland Limited | Single sign-on (OAuth), Google Sheets/Forms sync, and outbound email via Gmail where enabled | European Union |
| Sentry (Functional Software, Inc.) | Application error monitoring | EU region (Germany) with US parent; EU Standard Contractual Clauses in place |
| Amazon Web Services (Anthropic Claude via Amazon Bedrock) | Marshal, the optional AI assistant. Processes a depot's operational data to answer that depot's questions. Not used to train the model, and only where a depot has the feature enabled. | AWS eu-west-1 (Ireland) |
5.Technical and organisational measures
The Processor maintains, at minimum, the following measures (GDPR Art. 32):
- Encryption in transit (TLS everywhere, HSTS enforced) and at rest (database and object storage).
- Tenant isolation: every record carries a depot identifier and every query is scoped to the caller's depot server-side. Cross-depot access is possible only for the platform master admin.
- Role-based access control enforced on the server for every page, action and API route - never by hiding UI alone. Commission and profit/loss data is restricted to the Depot Owner role; sensitive identifiers (PPS, IBAN, BIC, VAT) are further restricted and their access is logged.
- Authentication via Google SSO with optional domain restriction, or password with bcrypt hashing; per-account and per-IP brute-force throttling; 12-hour session expiry; no self-registration.
- Audit logging of sign-ins, uploads, stop edits (with mandatory reason, old and new value), rate changes, payout entries, sensitive-data access, and administrative actions.
- Uploaded files validated by type and size, stored privately, never served directly or executed, and delivered only through authenticated, tenancy-checked requests.
- Security headers on every response: Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
- Encrypted daily backups with point-in-time recovery, held in the same EU region.
- Separate staging and production environments; production credentials never stored in source control; dependencies monitored and patched.
- Application error monitoring with personal data scrubbed from reports.
6.International transfers
All personal data is stored and processed within the European Union. Where a subprocessor has a parent company outside the EEA and incidental access could occur (for example for support), EU Standard Contractual Clauses and supplementary measures are in place. The Processor will not transfer personal data outside the EEA without a valid transfer mechanism.
7.Personal data breaches
The Processor will notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. The Processor will assist the Controller in meeting its own notification obligations to the Data Protection Commission and to affected data subjects. Notifying the supervisory authority within 72 hours remains the Controller's duty.
8.Audits
On reasonable written notice, and no more than once in any twelve months (unless required by a supervisory authority or following a breach), the Processor will make available the information necessary to demonstrate compliance with this agreement and will submit to audits conducted by the Controller or an independent auditor it mandates. Audits must not unreasonably disrupt the Processor's business or compromise the confidentiality of other customers' data.
9.Return and deletion
On termination the Controller may export its data through the platform's export features for 30 days. After that the Processor will delete all personal data, including from backups within the normal backup rotation, within a further 60 days - except where EU or Member State law requires continued storage, in which case the Processor will store it securely and process it no further.
10.Data subject requests
Requests from drivers or employees are for the Controller to answer. The platform provides per-driver export (access and portability) and per-driver anonymisation (erasure, while preserving the financial ledger the law requires be kept). Where a data subject contacts the Processor directly, it will not respond substantively but will forward the request to the Controller without undue delay.
11.Liability and precedence
This agreement takes precedence over any conflicting term in the Terms of Service in respect of the processing of personal data. It is governed by the laws of Ireland.
Contacting us
Oxus Technologies Limited, registered in Ireland, company number 818468.
Registered address: Greenhills Road, Walkinstown, Dublin 12, D12 DX80
Privacy and data protection enquiries: info@oxus.ie
General support: info@oxus.ie
Web: https://oxus.ie
See also the full set of DepotIQ legal documents.