Business plan
Data Processing Agreement (Business plan)
Last updated:
Document drawn up in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Guidelines 07/2020 of the European Data Protection Board.
This translation is provided for informational purposes only. Only the French version is legally binding.
Version 1.0. This agreement is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) between IT EXPERT SERVICES SAS, publisher of the WheelTrust service (“WheelTrust”, “we”), acting as processor, and the Organisation that has subscribed to the Business plan (“you”), acting as data controller. It forms an integral part of the Terms of Sale (Article 2 bis.6), and you accept it by subscribing to the Business plan. The terms “Organisation”, “Member” and “Role” have the meaning given to them by the Terms of Use; other terms have the meaning given to them by Article 4 of the GDPR.
1. Purpose
Under the Business plan, you keep the maintenance records for the vehicles in your fleet in WheelTrust. The data you enter there, or that your Members enter there on your behalf, is your data: you determine the purposes and means of processing it, and we process it on your behalf, on your instructions, under the terms of this agreement. We refer to this data as your fleet data.
2. What this agreement does not cover
We remain data controller, in our own name, for the following processing activities, described in our privacy policy: the creation and management of your Members' accounts, their authentication and the security of the service; the identification and invoicing of your Organisation (company name, SIRET number, EU VAT number, billing email address, payment data held by our payment provider); security logging; and audience measurement on our website. These processing activities are outside the scope of this agreement.
3. Duration
This agreement applies for the entire duration of your subscription to the Business plan and until your fleet data is returned or deleted under the terms of Article 10.
4. Description of processing
| Item | Content |
|---|---|
| Nature of processing | Hosting, storage, consultation, modification, making data available to your Members according to their Role, backup, export, and, when you use this feature, automatic reading of the documents you upload. |
| Purpose of processing | Keeping the maintenance records for the vehicles in your fleet, organising your Members' access to these records, and producing the reports offered by the service. No other purpose: we do not use your fleet data for our own purposes, to train a model, or for statistical or commercial purposes. |
| Categories of data | Vehicle data (make, model, registration number, serial number, mileage, photos); maintenance history (dates, work carried out, costs, garages, notes); documents and invoice photos uploaded to the records; upcoming actions; fleets, assignment of records to fleets and to Drivers; for each entry, the identity of its author (display name and Role) and its date. |
| Categories of data subjects | Your Members (employees, staff, contractors you invite) as authors of entries and assignees of records; individuals whose name appears in the documents you upload (garages, sellers, contacts). |
| Special data | The service is not designed for what is known as special category data (Article 9 of the GDPR) or for data relating to criminal offences (Article 10). You undertake not to upload any such data. |
5. Your instructions
Your instructions consist of the Terms of Use and Terms of Sale, this agreement, and the use you make of the service's features (creating records, inviting Members, assigning Roles, uploading documents, exporting, deleting). Any further instructions must be sent to us in writing at contact@wheeltrust.io. If we consider an instruction to be contrary to the GDPR or to any other provision of EU or French law, we will inform you without delay (Article 28.3, last paragraph).
6. Our obligations
In accordance with Article 28.3 of the GDPR, we undertake to:
- only process your fleet data on your documented instructions, including with regard to transfers to a third country, unless we are subject to a legal obligation to do otherwise, in which case we will inform you before processing unless the law prohibits us from doing so;
- ensure that persons authorised to process your fleet data undertake to keep it confidential: access by our staff is limited to authorised persons and to what is necessary to support and operate the service, and every administrative access is logged;
- take the security measures set out in Article 8;
- comply with the conditions of Article 7 when engaging another sub-processor;
- help you, through appropriate technical and organisational measures, to respond to requests to exercise data subject rights (Article 9);
- help you ensure compliance with the obligations relating to security, data breach notification and impact assessments (Articles 32 to 36 of the GDPR), taking into account the nature of the processing and the information available to us;
- at the end of the service, delete or return your fleet data, at your choice, under the terms of Article 10;
- make available to you the information necessary to demonstrate compliance with this agreement and to allow audits to be carried out under the terms of Article 11.
7. Sub-processors
You give us general authorisation to use the following sub-processors to process your fleet data:
| Sub-processor | Role | Location of processing | Safeguards |
|---|---|---|---|
| O2Switch (France) | Hosting of servers and backups | France | Sub-processing agreement, hosting in the European Union |
| Cloudflare (United States) | DNS, content delivery network and web application firewall services: sees the encrypted traffic between your Members and our servers | United States | Standard contractual clauses (SCCs) of the European Commission (Decision 2021/914), supplementary measures (encryption in transit) |
| Brevo (France) | Sending invitation and notification emails to your Members | France | Sub-processing agreement (Brevo's data protection addendum), hosting in the European Union |
| Mistral AI (France) | Automatic reading of the documents you upload, only when you use this feature, for the time needed to extract their content | European Union | Sub-processing agreement; your documents are not used to train a model |
We will inform you by email, at your Organisation's billing address and to the Fleet Manager(s), of any plan to add or replace a sub-processor, at least 30 days before it takes effect. You may object in writing, for a legitimate reason, within this period; failing agreement on a solution, you may terminate your subscription free of charge, with a pro-rata refund for the unused period. We contractually impose on each sub-processor the same data protection obligations as those set out in this agreement, and we remain fully liable to you for the performance of its obligations (Article 28.4). Our payment provider does not have access to your fleet data and is not a sub-processor under this agreement.
8. Security
We implement the technical and organisational measures described in the “Security” section of our privacy policy, including: hosting in France; encryption of exchanges between your Members and our servers; access control by Role, within your Organisation, according to the matrix described in Article 2 bis.1 of the Terms of Sale; account authentication, with two-step verification offered to each Member; logging of administrative actions; encrypted daily backups, kept on separate storage; strict separation between your Organisation's records, your Members' personal records, and other customers' records. We review these measures regularly and adapt them to changing risks (Article 32).
9. Assistance: data subject rights, impact assessment
Your Members exercise with you the rights they hold under the GDPR over the fleet data (access, rectification, erasure, restriction, objection). If we receive such a request directly regarding your fleet data, we forward it to your Fleet Manager(s) without responding to it on the merits, unless you instruct us in writing to do so, and we provide you with the reasonable assistance needed (extraction, correction, deletion) within a timeframe consistent with the one-month period set out in Article 12.3. On written request, we provide you with the information we hold that is necessary for a data protection impact assessment or for a prior consultation with the CNIL (the French data protection authority). The rights your Members exercise over their own account (account data, authentication) are exercised with us, as described in our privacy policy.
10. End of contract: return and deletion
At the end of your subscription to the Business plan (termination, non-renewal, closure of the Organisation), you choose between returning and deleting your fleet data. Return: on written request made before the end of the subscription or within the 90 days that follow, we provide you with a copy of your fleet data in a structured, commonly used format (data files and uploaded documents). Deletion: on written request, or if no request for return is made within the 90-day period, we delete your fleet data within 30 days, along with any copies, except for data whose retention is required by law and technical logs, which are kept for the period stated in our privacy policy and then deleted. We confirm deletion in writing on request.
11. Documentation and audits
We make available to you the documentation necessary to demonstrate compliance with this agreement: this agreement, our privacy policy, the description of our security measures, and the extract of our record of processing activities that concerns you. No more than once a year, you may send us a written questionnaire on these points, to which we will respond within a reasonable time. If this is not sufficient, you may have an audit carried out, by yourself or by an independent third party bound by confidentiality, with 30 days' written notice, during business hours, without disrupting the service or accessing other customers' data, and at your expense. The audit findings are confidential.
12. Data breach
If we become aware of a personal data breach affecting your fleet data, we will inform you as soon as possible and no later than 48 hours after becoming aware of it, at your Organisation's billing address and to the Fleet Manager(s), with, to the extent available to us, the information required under Article 33.3 of the GDPR: the nature of the breach, the categories and approximate number of data subjects and data records concerned, the likely consequences, and the measures taken or proposed. We will supplement this information as it becomes available. It is your responsibility, as data controller, to notify the CNIL and, where applicable, the data subjects concerned (Articles 33 and 34); we will help you do so.
13. Your obligations, records, miscellaneous provisions
You are responsible for the lawfulness of your fleet data, for informing your Members about the processing you carry out (see our page “Organisation record: what you owe your staff”), for assigning Roles and withdrawing them when a Member leaves your Organisation, and for the security of your Members' accounts to the extent it depends on them. You keep your own record of processing activities (Article 30.1); we keep ours, as processor, for the processing carried out on your behalf (Article 30.2). In the event of any conflict between this agreement and the Terms of Use or Terms of Sale on a data protection matter, this agreement prevails. We may amend it to comply with the law or to reflect changes to the service, with 30 days' notice given by email, except where the law requires immediate entry into force; an amendment that would reduce your safeguards gives you the right to terminate free of charge. This agreement is governed by French law. Our contact for any question relating to data protection: contact@wheeltrust.io.

