Data Processing Addendum

Version 2026-08-23

version: 2026-08-23 # Data Processing Addendum This addendum forms part of the Terms of Service for Taylor's Fleet Services and describes how we handle personal data that belongs to your business rather than to you. "We" and "us" mean TayTech Innovations LLC; "you" means the customer named on the fleet. ## 1. Roles For personal data concerning your renters and your contractors, you are the **controller** and we are the **processor**. We process it only on your documented instructions, which are: to provide the fleet-operations service described in the Terms. If we ever believe an instruction from you breaks applicable data-protection law, we will tell you rather than carry it out. ## 2. Subject matter and duration Processing lasts as long as your fleet exists in the service. The subject matter is the operation of a vehicle rental fleet; the nature and purpose of processing is storing, organising and presenting the records that operation produces. ## 3. Categories of data subject - Your renters — name, trip dates, vehicle, and where you supply it, delivery address and message content. - Your contractors — name, contact details, work assigned, and amounts paid. Where you enable payouts, Stripe additionally collects identity and bank details directly from them under its own agreement. We do not process special categories of personal data, and you should not enter any. ## 4. Subprocessors As listed in the Privacy Notice. We will give you at least 30 days' notice before adding one, and you may object; if we cannot resolve your objection, you may terminate and delete your fleet without further charge. Each subprocessor is bound by terms at least as protective as these, and we remain responsible to you for their performance. ## 5. Security - **Tenant isolation.** Every read is filtered and every write is stamped by the fleet it belongs to, enforced in a single database-layer guard rather than in each query — so a missing filter fails closed instead of leaking. - **Encryption.** All traffic to the service is encrypted in transit. Storage volumes are encrypted at rest by the hosting provider. - **Access control.** Roles inside a fleet are yours to grant and revoke. Provider-side access is limited to the operator of the service, is used only to support you or to keep the service running, and is recorded in the logs when it happens. - **Credentials.** Passwords are stored only as Argon2 hashes. Third-party tokens you connect are held as secrets outside the codebase. - **Backups.** Nightly, checksummed, stored off-site, and test-restored on a schedule so that "we have backups" is a measured claim rather than an assumption. ## 6. Assistance We will assist you in responding to a data subject request, and in any data protection impact assessment or consultation with a supervisory authority that relates to our processing. Export and deletion are available to you directly in the product, which covers most requests without needing us at all. ## 7. Breach notification We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your fleet. The notice will describe what we know at the time: the nature of the breach, the categories and approximate number of records involved, the likely consequences, and what we are doing about it — updated as we learn more rather than delayed until complete. ## 8. Deletion and return On deletion of your fleet, we delete its data from the live service immediately and it ages out of backups within 30 days, as described in the Privacy Notice. You may export it first, and should — deletion is permanent. ## 9. Audit You may ask us once in any twelve-month period for the information reasonably necessary to demonstrate compliance with this addendum, and we will answer a security questionnaire in the same period. We do not offer on-site audits or penetration testing of shared infrastructure; where you need assurance beyond what we can provide directly, our hosting provider publishes its own compliance documentation. ## 10. International transfers Data is stored and processed in the United States. If you are subject to a law that restricts transfers out of your jurisdiction, tell us before you sign up — we do not currently offer regional data residency, and it is better that you know that now than later. ## Contact Questions about this document go to the support address shown on the sign-in page and in the in-app guide.

Terms of Service · Privacy Notice · Data Processing Addendum