Data Processing Agreement (DPA)

Addendum to the Terms of Service   |   Last Updated: Sep 08, 2026

Plain-English Summary (Not Part of the Legal Terms)

This box is just here to help you understand the document below — it has no legal effect and does not change the actual terms.

When a Driver’s data passes through FuelaFleet (names, routes, logbook entries, receipts), GDPR treats your business as the “Controller” — you decide why that data is collected and what it’s used for — and treats FuelaFleet as the “Processor” — we just handle the data on your instructions, to provide the Service. Whenever a Processor handles personal data on behalf of a Controller, GDPR requires that relationship to be written down in a contract. That is what this document is.

In short, it covers: what FuelaFleet can and can’t do with your data; which other companies (called “sub-processors” — here, Zonercloud, Stripe, make.com, iDoklad, Google, Google Gemini AI, Brevo, Telegram, Hotjar by Contentsquare, and Meta) also touch the data, and why; what happens if there’s a data breach; how you can check up on us; and what happens to your data when you leave. You, as the Controller, remain responsible for having a lawful reason to collect your Drivers’ data in the first place (e.g., telling them what is tracked and why) — this DPA only covers FuelaFleet’s side of that relationship.

Preamble

This Data Processing Agreement (“DPA”) is entered into between Mgr. Ján Kubiš, operator of the FuelaFleet application (“Processor,” “Provider,” “we,” “us”), and the business entity that has registered for a FuelaFleet account (“Controller,” “Customer,” “you”). This DPA forms part of, and is incorporated by reference into, the Terms of Use between the parties (the “Main Agreement”), and applies automatically whenever Controller uses the FuelaFleet application (the “Service”) to process personal data of Drivers or other individuals. This DPA reflects the parties’ respective obligations under Articles 28 and 29 of Regulation (EU) 2016/679 (“GDPR”).

Where Controller requires a separately countersigned copy of this DPA for its own vendor-compliance records, it may request one using the contact details in Section 16.

1. Definitions

1.1 “GDPR” means Regulation (EU) 2016/679 (General Data Protection Regulation), as amended or replaced from time to time.

1.2 “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” “Personal Data Breach,” and “Supervisory Authority” have the meanings given to them in Article 4 GDPR.

1.3 “Sub-processor” means any processor engaged by Processor to assist in processing Customer Personal Data on behalf of Controller, as listed in Annex III.

1.4 “Customer Personal Data” means personal data processed by Processor on behalf of Controller through the Service, as described in Annex I.

1.5 “Main Agreement” means the FuelaFleet Terms of Service in effect between the parties.

2. Roles of the Parties

The parties acknowledge that, with respect to Customer Personal Data, Controller is the Data Controller and Processor is the Data Processor, as those terms are defined in the GDPR. Annex I describes the subject matter, duration, nature, and purpose of the processing, the categories of Data Subjects, and the categories of Customer Personal Data.

3. Controller’s Instructions

Processor shall process Customer Personal Data only on the documented instructions of Controller, including with regard to international transfers, unless required to do otherwise by EU or Member State law; in that case, Processor shall inform Controller of that legal requirement before processing, unless the law prohibits Processor from doing so.

The Main Agreement, this DPA, and Controller’s use of the standard features and configuration options of the Service constitute Controller’s complete documented instructions to Processor as of the date of this DPA. Any additional or alternative instructions require the parties’ written agreement and may be subject to additional fees if they require material changes to the Service.

Processor shall promptly inform Controller if, in Processor’s reasonable opinion, an instruction infringes the GDPR or other applicable data protection law.

4. Confidentiality

Processor shall ensure that any person it authorizes to process Customer Personal Data is subject to a binding obligation of confidentiality, whether contractual or statutory, and processes such data only as necessary for the purposes of the Main Agreement.

5. Security of Processing

Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, consistent with Article 32 GDPR.

Processor may update the measures described in Annex II from time to time to reflect technical progress, provided that any such update does not materially decrease the overall level of protection.

6. Sub-processors

Controller grants Processor general written authorization to engage the Sub-processors listed in Annex III to assist in providing the Service.

Processor shall impose data protection obligations on each Sub-processor that are substantially equivalent to those set out in this DPA, and remains fully liable to Controller for the performance of each Sub-processor’s obligations.

Processor shall give Controller at least 14 days’ prior notice (by email or in-app notice) of any intended addition or replacement of a Sub-processor, giving Controller a reasonable opportunity to object on reasonable data-protection grounds. If the parties cannot resolve such an objection, Controller’s sole remedy is to terminate the Main Agreement with respect to the affected part of the Service.

7. International Data Transfers

Where Processor or a Sub-processor transfers Customer Personal Data outside the European Economic Area (“EEA”), Processor shall ensure the transfer is subject to appropriate safeguards under Chapter V GDPR, such as: (a) an applicable European Commission adequacy decision; (b) the Standard Contractual Clauses adopted under European Commission Implementing Decision (EU) 2021/914; or (c) a Sub-processor’s self-certification under the EU-U.S. Data Privacy Framework or a successor mechanism, where applicable.

As of the date of this DPA, the Sub-processor most likely to process Customer Personal Data outside the EEA is Google (Google Gemini AI, used for receipt OCR). Processor relies on the transfer safeguards incorporated into Google’s own customer and data-processing terms, as updated by Google from time to time. Controller may request a copy of the relevant transfer documentation for this and any other Sub-processor.

8. Assistance with Data Subject Rights

Taking into account the nature of the processing, Processor shall provide reasonable assistance to Controller, through appropriate technical and organizational measures, to help Controller fulfil its obligation to respond to Data Subject requests (e.g., access, rectification, erasure, restriction, portability, or objection) under Chapter III GDPR.

If Processor receives a request directly from a Data Subject (for example, a Driver) concerning Customer Personal Data, Processor shall not respond to it substantively, beyond acknowledging receipt, and shall promptly forward the request to Controller, who remains responsible for responding to it.

9. Assistance with Compliance, Security, and Impact Assessments

Processor shall provide Controller with information reasonably requested about its processing activities and security measures, to the extent necessary for Controller to comply with its own obligations under Articles 32 to 36 GDPR, including carrying out data protection impact assessments and any required prior consultation with a Supervisory Authority.

10. Personal Data Breach Notification

Processor shall notify Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notification shall describe, to the extent then known: the nature of the breach; the categories and approximate number of Data Subjects and records concerned; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. Processor shall provide further information as it becomes available, without undue delay.

Processor’s notification of, or response to, a Personal Data Breach shall not be construed as an admission of fault or liability by Processor.

11. Audits and Inspections

Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by Controller or an independent auditor mandated by Controller, subject to: (a) at least 30 days’ prior written notice; (b) audits taking place no more than once per 12-month period, unless required by a Supervisory Authority or following a Personal Data Breach; (c) audits being conducted during normal business hours in a manner that minimizes disruption to Processor’s operations, and subject to confidentiality; and (d) Controller bearing its own costs, and any reasonable costs incurred by Processor in supporting an on-site audit.

In place of an on-site audit, Processor may satisfy this obligation by providing a written description of its security measures, completing a reasonable security questionnaire, or providing a relevant third-party audit or certification report, where one is available.

12. Return and Deletion of Customer Personal Data

Following termination or expiry of the Main Agreement, Processor shall, at Controller’s choice, make Customer Personal Data available for export and thereafter delete it, in accordance with the data export and retention provisions of the Terms of Service.

Unless applicable law requires Processor to retain copies, Processor shall delete all remaining Customer Personal Data, including from routine backups, within a commercially reasonable period following the retention period described in the Terms of Service, in line with its standard deletion and backup-rotation schedules.

13. Liability

Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Limitation of Liability section of the Terms of Service, which apply equally to this DPA as if set out in full, except where applicable law prohibits such a limitation.

14. Term and Termination

This DPA takes effect on the date Controller first uses the Service to process Customer Personal Data, and remains in effect for as long as Processor processes Customer Personal Data on Controller’s behalf under the Main Agreement. Termination of the Main Agreement automatically terminates this DPA, without prejudice to any obligation that by its nature survives termination (for example, post-termination deletion and confidentiality).

15. Order of Precedence and Governing Law

In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of personal data; the Terms of Service prevail on all other matters. This DPA is governed by the laws of the Slovak Republic, consistent with the Governing Law and Jurisdiction section of the Terms of Service.

16. Contact

Questions about this DPA, requests for a countersigned copy, or Sub-processor transfer documentation, can be sent to Questions about DPA

Annex I — Details of Processing

  • Subject matter: Processor’s provision of the FuelaFleet fleet-management SaaS to Controller.
  • Duration: For the term of the Main Agreement, plus the post-termination retention period described in the Terms of Service.
  • Nature and purpose of processing: hosting, storage, and processing of fleet, logbook, and receipt data to enable Controller to track vehicles and fuel use, manage driver logbooks, generate PDF/CSV reports, send notifications and email alerts, and process subscription payments.
  • Categories of Data Subjects: Controller’s Drivers and other personnel invited to the workspace; Controller’s Admin users.
  • Categories of Customer Personal Data: name; email address; post address; hire date; birthday; personal ID; vehicle assignment; logbook entries (dates, times, distances, routes, purpose); fuel receipt images and data extracted from them (cost, VAT, liters, merchant details); Telegram account identifiers (where a Driver or Admin opts in); technical/usage data (IP address, browser type, session logs).
  • Special categories of data: None are required by the Service. Controller shall not submit special categories of personal data (Article 9 GDPR) or criminal-offense data through the Service.
  • Frequency of processing: Continuous, for the duration of the Main Agreement.

Annex II — Technical and Organizational Security Measures

At FuelaFleet, the security, privacy, and integrity of your fleet data is our highest priority. We employ industry-standard security protocols and a strict “security-by-design” architecture to ensure your data is protected at all times.

1. Hosting, Infrastructure & Data Sovereignty

  • Tier III European Infrastructure: Our primary databases and application servers are hosted on Enterprise-Grade Virtual Private Servers (VPS) within a proprietary Tier III Data Center located in the Czech Republic (EU).
  • DDoS Protection & Network Security: Our infrastructure is protected by advanced DDoS mitigation protocols and is a proud participant in the FENIX security initiative—a project uniting cybersecurity experts to create robust infrastructure resistant to severe cyber threats and network attacks.
  • EU-Bound AI Processing: All advanced Artificial Intelligence features (Voice Agent and Receipt Scanner) are processed exclusively via Google Cloud servers geographically restricted to the European Union (europe-west3).
  • GDPR Compliance: No personal or fleet data is transferred outside the European Economic Area (EEA), ensuring absolute strict compliance with the General Data Protection Regulation (GDPR).

2. Encryption (In Transit & At Rest)

  • Encryption in Transit: All data transmitted between the user’s device (browser/mobile) and our servers is encrypted using strict TLS 1.2 / TLS 1.3 (HTTPS) protocols. Downgrade attacks are prevented, ensuring no data can be intercepted over public networks.
  • Encryption at Rest: All sensitive fleet data, databases, and uploaded documents (receipts, contracts) are stored on secure storage volumes utilizing OS-level encryption.
  • Payment Security: We do not store or process credit card information on our servers. All billing is handled directly by Stripe (PCI-DSS Level 1 Compliant).

3. Logical Multi-Tenant Isolation & Access Control

  • Strict Data Isolation: FuelaFleet operates on a secure multi-tenant architecture. Every single database query strictly enforces a dual-verification check (user_id and account_id). It is mathematically impossible for one company to access, view, or modify the data of another company (BOLA/IDOR protection).
  • Role-Based Access Control (RBAC): We enforce strict hierarchical access at the server routing level:
    • Admins: Full access to billing, company settings, and all data.
    • Team Managers: Isolated access restricted exclusively to vehicles and drivers within their assigned Department.
    • Drivers: Strict isolation allowing access only to assigned vehicles and their personal logs.
    • Accountants: Global read-only access. The server physically blocks HTTP POST/Write requests for this role.

4. Authentication & Session Security

  • Password Hashing: User passwords are never stored in plain text. They are cryptographically hashed and salted using the industry-standard PBKDF2-SHA256 algorithm.
  • Password Complexity: The system strictly enforces password policies requiring a minimum of 8 characters, containing both letters and numbers.
  • Secure Sessions: Authentication is maintained via cryptographically signed, HTTP-only session cookies protected by a secure, randomly generated 32-byte hexadecimal key.
  • Anti-Brute Force Protection: Login endpoints are protected by an aggressive Rate Limiter, automatically blocking IP addresses that attempt more than 5 failed login guesses per minute.
  • Open Redirect Protection: Authentication workflows strictly verify the netloc (network location) to prevent Open Redirect phishing attacks.


5. Application-Level Defenses

  • SQL Injection (SQLi) Prevention: 100% of database interactions utilize parameterized queries, completely neutralizing SQL injection attacks.
  • Cross-Site Scripting (XSS) Prevention: Our templating engine (Jinja2) automatically sanitizes and escapes all user-generated input before it is rendered on the screen.
  • Malicious File & DoS Protection: All file uploads (receipts, photos) are scanned and processed in-memory using the Pillow imaging library. Corrupted files, executables (.exe, .php), or disguised payload files are instantly rejected and destroyed before they can be written to the server disk.
  • Mathematical Integrity: All financial inputs (fuel costs, hourly rates) are scrubbed and absolute-valued at the server level to prevent “Negative Math” exploitation or logical corruption of accounting data.

6. Dual-Layer Backups & Disaster Recovery

We employ a comprehensive, two-tiered backup strategy to guarantee data integrity and business continuity:

  • Infrastructure-Level Backups: Our data center automatically captures a full operational image (IMG) backup of the entire virtual server every night to protect against catastrophic hardware failures.
  • Application-Level Database Backups: The FuelaFleet application independently clones the fleet database every night at 03:00 AM using secure Write-Ahead Logging (WAL) protocols. This ensures databases are backed up safely without interrupting live users or causing data corruption.
  • Retention Period: Application-level database backups are securely retained in an isolated server directory for exactly 14 days. Older backups are automatically purged to adhere to GDPR data minimization principles.

7. Logging & Monitoring

  • Immutable Action Logs: Critical compliance actions (e.g., Driver Digital Signatures, Manager Payroll Approvals, Trip Authorizations) are permanently time-stamped and logged within the database.
  • System Alerts: The server automatically monitors fleet health and compliance deadlines, dispatching automated security and notification alerts via encrypted Telegram webhooks and authenticated SMTP relays.

Annex III — Authorized Sub-processors

Controller authorizes Processor to engage the following Sub-processors. Processor will update this list and notify Controller in accordance with Section 6 above.

Sub-processorZonercloud.cz (ZONER a.s.)
PurposePrimary cloud infrastructure, application hosting, and encrypted database storage.
Processing LocationEuropean Union (Czech Republic)
International Transfer MechanismNone (Processed entirely within the EU/EEA).
Technical Solutions
Sub-processorStripe
PurposeSubscription payment processing
Processing LocationFor European users, Stripe’s primary data processing and contracting location is in the EU/EEA (handled via entities like Stripe Payments Europe, Limited and Stripe Technology Europe, Limited based in Ireland).
International Transfer MechanismStripe’s current Data Processing Agreement:
Stripe Privacy Center | Data Processing Agreement
Sub-processorMake.com (Celonis Inc.)
PurposeAPI integration, data routing, and workflow automation (connecting payment gateways to invoicing software).
Processing LocationEuropean Union (Primary Servers), with potential processing globally (e.g., United States)
International Transfer MechanismEU Standard Contractual Clauses (SCCs) and/or reliance on Adequacy Decisions (e.g., the EU-U.S. Data Privacy Framework), ensuring an adequate level of protection for onward transfers outside the EEA.
Celonis Privacy Notice for Make | Celonis Data Processing Agreement for Make (PDF)
Sub-processoriDoklad (Seyfor, a. s.)
PurposeGeneration of tax-compliant invoices, automated billing communication, and accounting records.
Processing LocationEuropean Union (Hosted on Microsoft Azure cloud data centers within the EU, with parallel synchronization across multiple EU centers for high availability).
International Transfer MechanismNone (Processed and synchronized entirely within the EU/EEA).
Bezpečnosť a zálohovanie dát v iDoklade
Sub-processorGoogle (Vertex AI Gemini API, Gemini 2.5 Flash)
PurposeOCR / data extraction from fuel receipts and Speech-to-Text transcription
Processing LocationRegion(s) where Google processes Gemini API requests: Frankfurt
(europe-west3)
International Transfer MechanismGoogle’s current data processing / transfer terms :
Deployments and endpoints | Gemini API Additional Terms of Service | Data Processing Addendum
Sub-processorBrevo
PurposeTransactional email delivery (alerts, PDF logbooks)/td>
Processing LocationBrevo’s processing region: European Union (Belgium and France)
International Transfer MechanismBrevo’s current Data Processing Agreement:
Terms of Service | Data Storage Location
Sub-processorTelegram
PurposeOptional push notifications (opt-in only)
Processing LocationTelegram’s processing region: If you signed up for Telegram from the UK or the EEA, your data is stored in data centers in the Netherlands.
International Transfer MechanismTelegram’s standard terms and transfer mechanism:
Privacy Policy | User guidance for the EU Digital Services Act
Sub-processorGoogle Ireland Limited (Google Analytics, Ads & Tag Manager)
PurposePublic website traffic analysis, performance monitoring, and advertising conversion tracking (Public website only; NOT used inside the SaaS application).
Processing LocationEuropean Union (Ireland) / Global.
International Transfer MechanismEU Standard Contractual Clauses (SCCs) / Data Privacy Framework.
Sub-processorHotjar (Contentsquare Group)
PurposePublic website user experience analysis and heatmapping (Public website only; NOT used inside the SaaS application).
Processing LocationEuropean Union (e.g., Germany, Netherlands, Portugal, Spain), the United Kingdom, and globally as necessary for the performance of the service.
International Transfer MechanismEuropean Commission Adequacy Decisions (e.g., for data transferred to the UK) and Intercompany Standard Contractual Clauses (SCCs) for transfers to other Third Countries outside the EEA/UK.
Contentsquare Sub-processors List Data Processing Agreement
Sub-processorMeta Platforms Ireland Limited
PurposeAdvertising conversion tracking and marketing analytics (Public website only; NOT used inside the SaaS application).
Processing LocationEuropean Union (Ireland) / Global (United States).
International Transfer MechanismEU Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework.