Article 28 EU GDPR / UK GDPR agreement between Naviuma (processor) and business users (controller).
The business user ("Controller") and Naviuma Platform GmbH ("Processor") enter into this DPA to govern processing of personal data on the Controller's behalf.
Subject matter: operation of the Naviuma B2B marketplace including matching, offer exchange, booking, driver dispatch, and settlement.
Duration: for as long as the Controller uses the Platform.
Nature and purpose: hosting, matching, communication, and payment settlement services.
Data subjects: Controller's staff, drivers, and passengers.
Data: identity, contact, licence, vehicle, itinerary, and payment metadata.
The Controller consents to the sub-processors listed in the Subprocessor List. Changes are announced 30 days in advance with a right to object on legitimate data-protection grounds.
Transfers from the EEA rely on the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) with supplementary measures where required.
Transfers from the United Kingdom rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs issued by the ICO, together with a transfer risk assessment where required.
The Processor makes available all information necessary to demonstrate compliance and permits audits, subject to reasonable confidentiality and cost-allocation arrangements.
On termination the Processor deletes or returns personal data at the Controller's choice, subject to statutory retention obligations.
See sections 2 and 3 above. Additional context is documented in the Platform product documentation.
See the Security & Compliance document for the current TOMs.
Questions about this document may be sent to legal@naviuma.com.
Naviuma Platform GmbH [Company Legal Address, Munich, Germany]