1. Scope and roles
This Data Processing Addendum applies when a business customer uses InvoiceTrucker to process personal data for which that customer is a controller and InvoiceTrucker acts as its processor. It supplements the applicable service agreement. Each party remains responsible for its own obligations under applicable data-protection law.
The customer determines the purpose and lawful basis for customer data and must provide any required notices. InvoiceTrucker processes that data to provide, secure, maintain, and support the service.
2. Instructions and processing details
The customer instructs InvoiceTrucker to process personal data as reasonably necessary to provide the service and as further directed through documented, lawful instructions. If an instruction appears to violate applicable data-protection law, InvoiceTrucker may notify the customer and pause the affected processing where permitted.
Expected data may include business contact, customer, driver, vehicle, invoice, expense, and document-reference information. The actual account-enabled product and any file-upload processing must be confirmed before this DPA is signed.
3. Confidentiality and security
People authorized to process customer personal data will be subject to appropriate confidentiality obligations. InvoiceTrucker will use reasonable technical and organizational safeguards designed to protect personal data, taking account of the nature of processing and the risks involved.
4. Subprocessors
The customer authorizes use of the providers listed on the Subprocessors page. InvoiceTrucker will require subprocessors to protect customer personal data through appropriate contractual terms. Material changes to the provider list will be communicated in a reasonable way before they take effect where required.
5. Assistance
Taking account of the nature of processing and information available, InvoiceTrucker will provide reasonable assistance with data-subject requests, data-protection impact assessments, regulator consultations, and other compliance duties that relate to the service. The customer remains responsible for responding to requests as controller.
6. Security incidents
InvoiceTrucker will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer data and will provide information reasonably available to support the customer's response. Notice is not an admission of fault or liability.
7. Return and deletion
Following termination and on the customer's request, InvoiceTrucker will return or delete customer personal data within a reasonable period, unless retention is required by law or maintained temporarily in protected backups. Product-level export and deletion workflows, timeframes, and backup behavior must be finalized before paid launch.
8. International transfers
Where customer personal data is transferred across borders, the parties and relevant subprocessors will use a legally recognized transfer mechanism when required. The applicable mechanism and any supplementary measures depend on the locations and services involved.
9. Audit and cooperation
On reasonable request, InvoiceTrucker will provide information needed to demonstrate compliance with this DPA. If that information is not sufficient, the parties may agree to a proportionate audit that protects security, confidentiality, other customers, and service availability. The customer bears reasonable audit costs unless the audit identifies a material breach by InvoiceTrucker.
10. Contact and effectiveness
Contact info@invoicetrucker.com to discuss or execute a DPA. This online framework is not a signed agreement by itself; party details, jurisdiction, processing scope, and signature terms must be completed for an executable DPA.