Data processing agreement

The agreement under Article 28 of the GDPR for the personal data EasyFleet B.V. processes on behalf of its customers.

Last updated 28 September 2026 · EasyFleet B.V.

1Parties and roles

This data processing agreement ("DPA") is part of the agreement between EasyFleet B.V., Zichtenburglaan 31, 2544 EA Den Haag ("EasyFleet", the processor) and the customer that uses the EasyFleet platform ("Customer", the controller). Terms not defined here have the meaning given in our Terms and conditions.

For the personal data in the platform, the Customer decides why and how it is processed and is the controller. EasyFleet processes it only on the Customer’s behalf. If this DPA and the Terms conflict on data protection, this DPA prevails.

2Subject, purpose and duration

EasyFleet processes personal data only to provide, support, secure and maintain the EasyFleet platform for the Customer. The types of personal data and the people concerned are described in Annex 1. This DPA runs for as long as EasyFleet processes personal data for the Customer.

3Instructions

EasyFleet processes personal data only on the Customer’s documented instructions. The agreement, this DPA and the Customer’s settings and use of the platform are the Customer’s instructions. EasyFleet informs the Customer if it believes an instruction breaks the GDPR, and may then suspend that instruction. EasyFleet may process data without instructions only where EU or Dutch law requires it, and then informs the Customer unless the law forbids this.

4The Customer’s responsibilities

The Customer is responsible for the lawfulness of the processing, including:

  • having a legal basis for each processing activity and informing the people concerned, such as drivers and staff;
  • obtaining any required approval, for example from its works council, and carrying out a data protection impact assessment where required, in particular before using location tracking or cabin-facing cameras;
  • setting retention periods and access rights in the platform that fit its purposes;
  • not entering special categories of personal data or citizen service numbers (BSN), unless agreed in writing.

5Confidentiality

EasyFleet ensures that everyone who has access to the personal data is bound by confidentiality and only has the access needed for their work.

6Security

EasyFleet takes appropriate technical and organisational measures to protect the personal data, as required by Article 32 of the GDPR. The main measures are listed in Annex 2. EasyFleet may update these measures, as long as the level of protection does not go down.

7Sub-processors

The Customer gives general permission for EasyFleet to use sub-processors, such as hosting providers. The current list is available on request at info@easyfleet.org. EasyFleet informs the Customer in advance of new sub-processors. The Customer may object on reasonable grounds within 14 days; if the parties cannot resolve the objection, the Customer may end the agreement as its sole remedy.

EasyFleet imposes the same data protection obligations on each sub-processor by contract and remains responsible to the Customer for their performance, as required by the GDPR.

8Location and transfers

Personal data is processed and stored within the European Union. A transfer outside the European Economic Area only takes place with appropriate safeguards under Chapter V of the GDPR, such as an adequacy decision or the standard contractual clauses.

9Assistance

Taking into account the nature of the processing and the information available to it, EasyFleet helps the Customer:

  • respond to requests from people exercising their GDPR rights; most requests can be handled with the platform’s own tools;
  • carry out data protection impact assessments and prior consultations with the supervisory authority where needed.

EasyFleet may charge reasonable costs for assistance beyond normal support.

10Personal data breaches

EasyFleet notifies the Customer without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting the Customer’s data. EasyFleet gives the information it has and supports the Customer in taking measures. The Customer decides whether to notify the supervisory authority and the people concerned.

11Information and audits

EasyFleet makes available the information needed to show that it meets this DPA. If that information is not enough, the Customer may have an audit carried out by an independent auditor bound by confidentiality, at most once a year, with at least 30 days’ notice, at the Customer’s expense and without disrupting EasyFleet’s operations.

12End of processing

When the agreement ends, the Customer receives a full export of its data on request. EasyFleet then deletes the personal data within 90 days, including from backups in their normal cycle, unless EU or Dutch law requires EasyFleet to keep it. Records the Customer must keep itself, such as its mileage registration, should be kept from the export.

13Liability

The limitations of liability in our Terms and conditions also apply to this DPA, to the extent permitted by law.

14Governing law

This DPA is governed by Dutch law. Disputes are submitted exclusively to the competent court in The Hague, the Netherlands.

Annex 1 · Processing details

People concernedThe Customer’s drivers, operators, administrators and other Users; people who appear in photos, video or accident reports
Personal dataName and contact details; employee and assignment details; driving licence details and images; vehicle handover records, signatures and signed contracts; location, trip and vehicle data; driving behaviour and scores; photos and video, including dash-cam footage; fines, parking, fuel, maintenance and cost records; payment status of fines
PurposeProviding, supporting, securing and maintaining the EasyFleet platform for the Customer
DurationFor the duration of the agreement and until deletion under this DPA
LocationEuropean Union

Annex 2 · Security measures

  • Hosting and storage within the European Union
  • Role-based access, so each User and staff member sees only what they need
  • Encrypted connections between the apps, the admin panel and our servers
  • Regular backups and procedures to restore data
  • Logging of access to the platform
  • Confidentiality obligations for all staff
  • Procedures to detect, report and handle personal data breaches