This Data Processing Agreement ("DPA") forms part of the agreement between Emris AI Ltd. ("Emris", "Processor") and the Customer ("Controller") for the use of the Service. It governs Emris's processing of personal data on behalf of the Customer.
Capitalised terms used but not defined here have the meanings given in the GDPR. "Applicable Data Protection Law" means the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act (CCPA/CPRA), and other laws governing the processing of personal data that apply to the parties.
The Customer is the Controller of personal data within Customer Data. Emris is the Processor (or Service Provider under the CCPA) and processes personal data only on documented instructions from the Customer, including as set out in this DPA, the Order, and the use of the Service.
| Subject matter | Provision of the Emris Service to the Customer. |
|---|---|
| Duration | For the term of the subscription and any post-termination period required by these terms. |
| Nature and purpose | Hosting, processing, transmitting, displaying, and analysing Customer Data to deliver AI-powered fleet intelligence to the Customer. |
| Categories of data subjects | Customer's drivers, dispatchers, fleet managers, administrators, and other authorised personnel. |
| Categories of personal data | Identifiers (name, employee ID, contact details); operational data (engine events, GPS location, speed, fuel, idle); planning and expense data where connected (calendar entries, card-expense lines); product usage data (queries, settings). |
| Special category data | Not knowingly processed. The Customer must not submit special-category data without prior agreement. |
Emris will process personal data only on the Customer's documented instructions, including as configured through the Service, unless required to do otherwise by law. Emris will inform the Customer if it believes an instruction violates Applicable Data Protection Law.
Emris ensures that personnel authorised to process personal data are bound by appropriate confidentiality obligations.
Emris implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
The Customer authorises Emris to engage sub-processors to perform parts of the Service. A current list is available in the product and on request. Emris will notify the Customer of intended changes at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds, in which case the parties will work in good faith to resolve the objection or, failing that, the Customer may terminate the affected portion of the Service for a pro-rata refund of pre-paid fees.
Emris remains liable for the acts and omissions of its sub-processors as if they were its own.
Where personal data is transferred outside the EEA, the UK, or Switzerland to a country not subject to an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor, as updated), and the UK International Data Transfer Addendum where applicable. The Customer's signature on the Order constitutes acceptance of these clauses.
Emris will assist the Customer, by appropriate technical and organisational measures, in fulfilling the Customer's obligations to respond to data subject requests under Applicable Data Protection Law. Where Emris receives a request directly, it will forward it to the Customer without undue delay.
Emris will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data. The notification will include the information reasonably required by the Customer to comply with its own notification obligations.
On request, and taking into account the nature of processing and the information available to Emris, Emris will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities.
Emris will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports (such as SOC 2 or ISO 27001) where applicable. The Customer may conduct an audit no more than once per year, on at least 30 days' notice, at its own expense, subject to reasonable confidentiality and scope limits, except where required more frequently by a supervisory authority.
Upon termination or expiry of the Service, and at the Customer's option, Emris will return or delete all personal data within 30 days, except to the extent retention is required by law. Backups containing personal data are deleted in accordance with the normal backup-rotation schedule.
The parties' liability under this DPA is subject to the limitations of liability set out in the main agreement. Nothing in this DPA limits a data subject's rights under Applicable Data Protection Law.
In the event of a conflict between this DPA and the main agreement, this DPA prevails with respect to the processing of personal data.
Emris may update this DPA from time to time to reflect changes in law, regulator guidance, or the Service. Material changes will be notified to the Customer with at least 30 days' notice.
Emris AI Ltd.
Dublin, Ireland
privacy@emris.ai