emris
Product
AskPlain-language answers across trips, expenses and schedules
Dashboard & scorecardsSeven-day KPIs, AI advice and auditable 0–100 scores
What you can askSix questions fleets ask every week, answered in a sentence
How data gets inUpload the reports you already have, or connect the API
Answers you can checkEvery answer with the trips and rows behind it
IntegrationsRead-only, works with the telematics you already run
See the product →
How it works Integrations Insights About FAQ
FR Sign in Get in touch →
Home
Product
Ask
Dashboard & scorecards
What you can ask
How data gets in
Answers you can check
How it works
Integrations
Insights
About
FAQ
FR Sign in Get in touch

DPA · Effective 18 May 2026

Data Processing Agreement.

This Data Processing Agreement ("DPA") forms part of the agreement between Emris AI Ltd. ("Emris", "Processor") and the Customer ("Controller") for the use of the Service. It governs Emris's processing of personal data on behalf of the Customer.

1. Definitions

Capitalised terms used but not defined here have the meanings given in the GDPR. "Applicable Data Protection Law" means the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act (CCPA/CPRA), and other laws governing the processing of personal data that apply to the parties.

2. Roles and scope

The Customer is the Controller of personal data within Customer Data. Emris is the Processor (or Service Provider under the CCPA) and processes personal data only on documented instructions from the Customer, including as set out in this DPA, the Order, and the use of the Service.

3. Subject matter and details of processing

Subject matterProvision of the Emris Service to the Customer.
DurationFor the term of the subscription and any post-termination period required by these terms.
Nature and purposeHosting, processing, transmitting, displaying, and analysing Customer Data to deliver AI-powered fleet intelligence to the Customer.
Categories of data subjectsCustomer's drivers, dispatchers, fleet managers, administrators, and other authorised personnel.
Categories of personal dataIdentifiers (name, employee ID, contact details); operational data (engine events, GPS location, speed, fuel, idle); planning and expense data where connected (calendar entries, card-expense lines); product usage data (queries, settings).
Special category dataNot knowingly processed. The Customer must not submit special-category data without prior agreement.

4. Customer instructions

Emris will process personal data only on the Customer's documented instructions, including as configured through the Service, unless required to do otherwise by law. Emris will inform the Customer if it believes an instruction violates Applicable Data Protection Law.

5. Confidentiality

Emris ensures that personnel authorised to process personal data are bound by appropriate confidentiality obligations.

6. Security measures

Emris implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit (TLS 1.2+) and at rest.
  • Tenant isolation per Customer.
  • Role-based access control with least-privilege principles.
  • Centralised logging, monitoring, and alerting.
  • Regular vulnerability scanning and periodic penetration testing.
  • Documented incident response and business continuity procedures.
  • Personnel security training on an annual basis.

7. Sub-processors

The Customer authorises Emris to engage sub-processors to perform parts of the Service. A current list is available in the product and on request. Emris will notify the Customer of intended changes at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds, in which case the parties will work in good faith to resolve the objection or, failing that, the Customer may terminate the affected portion of the Service for a pro-rata refund of pre-paid fees.

Emris remains liable for the acts and omissions of its sub-processors as if they were its own.

8. International transfers

Where personal data is transferred outside the EEA, the UK, or Switzerland to a country not subject to an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor, as updated), and the UK International Data Transfer Addendum where applicable. The Customer's signature on the Order constitutes acceptance of these clauses.

9. Data subject rights

Emris will assist the Customer, by appropriate technical and organisational measures, in fulfilling the Customer's obligations to respond to data subject requests under Applicable Data Protection Law. Where Emris receives a request directly, it will forward it to the Customer without undue delay.

10. Personal data breaches

Emris will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data. The notification will include the information reasonably required by the Customer to comply with its own notification obligations.

11. Data protection impact assessments

On request, and taking into account the nature of processing and the information available to Emris, Emris will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities.

12. Audits

Emris will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports (such as SOC 2 or ISO 27001) where applicable. The Customer may conduct an audit no more than once per year, on at least 30 days' notice, at its own expense, subject to reasonable confidentiality and scope limits, except where required more frequently by a supervisory authority.

13. Return or deletion of data

Upon termination or expiry of the Service, and at the Customer's option, Emris will return or delete all personal data within 30 days, except to the extent retention is required by law. Backups containing personal data are deleted in accordance with the normal backup-rotation schedule.

14. Liability

The parties' liability under this DPA is subject to the limitations of liability set out in the main agreement. Nothing in this DPA limits a data subject's rights under Applicable Data Protection Law.

15. Order of precedence

In the event of a conflict between this DPA and the main agreement, this DPA prevails with respect to the processing of personal data.

16. Updates

Emris may update this DPA from time to time to reflect changes in law, regulator guidance, or the Service. Material changes will be notified to the Customer with at least 30 days' notice.

17. Contact

Emris AI Ltd.
Dublin, Ireland
privacy@emris.ai

emris

The AI layer on top of the telematics you already have. Ask anything, get a sourced answer.

Made in Dublin · © 2026 Emris AI Ltd

LinkedIn

Product

  • Ask
  • Dashboard
  • Integrations
  • Insights
  • About
  • FAQ
  • Become a partner

Legal

  • Privacy
  • Terms
  • DPA
Fleet intelligence.