Data processing agreement
The Article 28 terms on which Oleks Tech OÜ processes personal data on behalf of a dealership using miraride. Forms part of the terms of service.
On this page
- 1. Scope and relationship to the terms
- 2. Subject matter, duration, nature, and purpose
- 3. Categories of personal data
- 4. Processing only on your instructions
- 5. Confidentiality of personnel
- 6. Security of processing
- 7. Sub-processors
- 8. Assisting you with data subject rights
- 9. Assisting you with security, impact assessments, and breaches
- 10. Return and deletion
- 11. Audits
- 12. International transfers
- 13. Liability
1. Scope and relationship to the terms
This data processing agreement forms part of the terms of service and applies whenever we process personal data on your behalf in the course of providing miraride. Where it conflicts with the terms of service on a matter of data protection, this agreement prevails.
You are the controller of that personal data. We are the processor. Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” carry the meanings given in the General Data Protection Regulation (EU) 2016/679.
You may request a copy signed on our behalf by writing to us. We do not require a negotiated agreement before you can start, and we do not charge for one.
2. Subject matter, duration, nature, and purpose
Subject matter and duration: processing personal data for the purpose of providing the miraride service, for as long as your agreement with us is in force and for the wind-down period described in section 10.
Nature and purpose: hosting, storage, retrieval, structuring, transmission by email at your instruction, rendering into documents, encryption, backup, and deletion — all in order to operate the storefront and workspace you use.
Categories of data subject:
- Your customers and prospective customers: vehicle buyers, renters, and people who submit an inquiry through your storefront.
- Named drivers on a rental booking, including additional drivers.
- The parties recorded on a document you issue.
- Your own team members, in their capacity as users of your workspace.
3. Categories of personal data
The service is designed to process the following, and you should not use it to store anything materially different:
- Identity data: names, and the party details recorded on a document.
- Contact data: email addresses, telephone numbers, messaging handles, and postal addresses.
- Rental and driver data: date of birth, driving licence number, issuing country, issue and expiry dates.
- Business identifiers: company names, tax identification numbers, and registration details.
- Transaction data: inquiries, bookings, prices, deposits, settlements, and issued documents.
- Free-text notes you write about a customer, a rental condition, or a cancellation.
4. Processing only on your instructions
We process personal data only on your documented instructions, including in relation to transfers to a third country. Your use of the service, together with the terms of service and this agreement, constitutes those instructions; anything beyond them requires a separate written instruction from you.
We may process personal data where European Union or Estonian law requires it. Where that happens we will tell you before processing, unless that law prohibits telling you.
If we consider an instruction to infringe data protection law, we will tell you, and we may suspend that instruction until it is resolved.
5. Confidentiality of personnel
Access to personal data processed on your behalf is limited to the people who need it to operate or support the service. Each of them is bound by a written duty of confidentiality that survives the end of their engagement, and each has access only to what their role requires.
6. Security of processing
Taking into account the state of the art, the cost of implementation, and the risks of the processing, we implement appropriate technical and organisational measures under Article 32 of the GDPR. These include:
- Authenticated encryption of personal data at rest, under a key derived for each individual value, with the ciphertext cryptographically bound to its field and to your dealership so that it cannot be relocated.
- Encryption in transit using current TLS.
- Tenant isolation: every query is scoped to the dealership resolved from the request host, and every related record is checked against that dealership independently.
- Access control: authenticated sessions that are host-only and HTTP-only, cross-site request forgery protection on every mutation, and an active membership requirement on every private endpoint.
- Exclusion of personal data from application logs and audit events.
- Encrypted backups with point-in-time recovery, and a documented restore procedure.
- A documented process for testing, evaluating, and improving these measures.
7. Sub-processors
You give us general authorisation to engage sub-processors. Those currently engaged are listed on our sub-processor page, which forms part of this agreement.
We will give you at least thirty days' notice by email before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate the affected part of the service without penalty for the remainder of the paid period.
Every sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this agreement. We remain fully liable to you for their performance.
8. Assisting you with data subject rights
The workspace gives you direct access to the personal data you hold, so you can answer most requests yourself. Where you cannot, we will assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests for access, rectification, erasure, restriction, portability, or objection.
If a data subject contacts us directly about data we process on your behalf, we will not respond to the substance ourselves. We will tell them to contact you and forward the request to you without undue delay.
The workspace and our support process provide export, correction, restriction, and erasure assistance. We provide additional reasonable assistance on written request within the statutory deadline.
9. Assisting you with security, impact assessments, and breaches
Taking into account the nature of the processing and the information available to us, we will assist you in complying with your obligations under Articles 32 to 36 of the GDPR — security of processing, breach notification to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation.
We will notify you of a personal data breach affecting personal data processed on your behalf without undue delay after becoming aware of it. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — providing whatever of this is known at the time and the rest as it becomes known, rather than delaying the first notification until everything is established.
10. Return and deletion
On termination of the service, we will, at your choice, return the personal data to you or delete it. Tell us which you want; if you tell us nothing, we keep the data available for thirty days so you can obtain it, and then delete it.
Active tenant data is deleted at the end of the thirty-day post-termination window, except where European Union or Estonian law requires us to retain something, in which case we retain only that and only for as long as required.
Personal data present in encrypted backups is removed as those backups rotate out of the retention window rather than being individually erased from each backup. Backups are not restored into the live service after a deletion request except to recover from a failure, and in that case the deletion is applied again.
11. Audits
We will make available to you all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In practice: we will answer a security questionnaire and provide our documentation on request. An on-site or system audit may be requested once in any twelve-month period, with at least thirty days' written notice, during business hours, under confidentiality, and conducted so that it does not access or disrupt any other dealership's data. Where a supervisory authority requires an audit, these limits do not apply.
You bear your own costs of an audit, and our reasonable costs where an audit goes beyond answering questions and providing documentation.
12. International transfers
Personal data processed on your behalf is stored in the European Union. Where a sub-processor is established outside the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses, on an adequacy decision where one applies, and on the supplementary measures described in our security documentation. The mechanism for each sub-processor is stated on the sub-processor page.
You instruct us to carry out those transfers for the purpose of providing the service. We enter the required transfer terms with each sub-processor in our own contracting chain and make information about those safeguards available on request.
13. Liability
The limitations of liability in the terms of service apply to this agreement. They do not limit or exclude either party's liability towards a data subject, or towards a supervisory authority, under Article 82 of the GDPR or under any other mandatory provision of data protection law.