1. Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between the garage/workshop ("Controller", "you") and Torq'd Ltd ("Processor", "we", "us") for the processing of personal data through the Torq'd platform.
This DPA applies where you, as a data controller, instruct Torq'd to process personal data on your behalf as part of using the Service.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined in UK GDPR Article 4(1).
- "Processing" means any operation performed on personal data, including collection, storage, retrieval, use, disclosure, and deletion.
- "Data Subject" means the individual to whom the personal data relates.
- "Subprocessor" means any third party engaged by the Processor to assist in processing personal data.
- "Supervisory Authority" means the Information Commissioner's Office (ICO).
3. Roles and Responsibilities
3.1 Controller (You)
As the data controller, you are responsible for:
- Determining the purposes and means of processing customer personal data.
- Ensuring you have a lawful basis for processing (e.g., consent, contract, legitimate interests).
- Providing appropriate privacy notices to your customers.
- Responding to data subject rights requests from your customers.
- Ensuring data entered into Torq'd is accurate and up to date.
3.2 Processor (Torq'd)
As the data processor, Torq'd will:
- Process personal data only on your documented instructions (which are deemed given through your use of platform features).
- Not process personal data for any purpose other than providing the Service.
- Implement appropriate technical and organisational security measures.
- Assist you in responding to data subject rights requests.
- Delete or return personal data upon termination of the agreement.
- Make available all information necessary to demonstrate compliance.
4. Categories of Data Processed
| Category | Data Types | Data Subjects |
|---|---|---|
| Customer records | Names, addresses, phone numbers, email addresses | Garage customers |
| Vehicle data | Registration numbers, make, model, mileage, MOT/service history | Vehicle owners |
| Booking data | Appointment dates, service descriptions, assigned staff | Garage customers |
| Financial data | Invoice amounts, payment status, quote details | Garage customers |
| Communications | SMS/email content, delivery status, timestamps | Garage customers |
5. Security Measures
Torq'd implements the following technical and organisational measures:
5.1 Technical Measures
- Encryption in transit using TLS 1.2 or higher for all data transmission.
- Encryption at rest for stored data.
- Row-level security (RLS) enforcing tenant isolation at the database layer.
- Principle of least privilege for all system and employee access.
- Automated vulnerability scanning and dependency monitoring.
- Regular security patching and updates.
- Secure authentication with support for multi-factor authentication.
5.2 Organisational Measures
- Staff access limited to those with a business need.
- Confidentiality agreements for all personnel with access to personal data.
- Security awareness practices for development and operations.
- Incident response procedures (see Section 8).
6. Subprocessors
You provide general authorisation for Torq'd to engage subprocessors for the purposes of delivering the Service. Our current subprocessors are:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting, authentication, and storage | EU/UK region (AWS infrastructure) |
| Stripe | Payment processing and subscription management | United States (with UK IDTA) |
| Twilio | SMS and WhatsApp message delivery | United States (with UK IDTA) |
| Vercel | Application hosting and CDN | Global (with UK IDTA) |
We will notify you of any intended changes to subprocessors with at least 14 days' notice. You may object to a new subprocessor within that period. If we cannot reasonably accommodate your objection, you may terminate the agreement.
7. International Transfers
Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place in accordance with UK GDPR Chapter V, including:
- UK International Data Transfer Agreements (IDTAs) with relevant subprocessors.
- Reliance on adequacy decisions where applicable.
- Assessment of the legal framework in the recipient country.
8. Data Breach Notification
- Torq'd will notify you of any confirmed personal data breach without undue delay and in any event within 48 hours of becoming aware.
- Notification will include: nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed to mitigate.
- We will cooperate fully with your investigation and provide ongoing updates.
- You remain responsible for determining whether notification to the ICO or affected data subjects is required under UK GDPR Articles 33 and 34.
9. Data Subject Rights
Where Torq'd receives a request directly from one of your customers exercising their data subject rights, we will:
- Promptly redirect the request to you (unless legally required to respond directly).
- Provide reasonable technical assistance to help you fulfil the request.
- Support data export, rectification, or deletion requests within the platform's capabilities.
10. Audits
You have the right to audit Torq'd's compliance with this DPA. Audits shall be:
- Conducted with at least 30 days' written notice.
- Limited to once per 12-month period (unless a breach has occurred).
- Conducted during normal business hours with minimal disruption.
- At your cost (unless the audit reveals material non-compliance by Torq'd).
Torq'd may satisfy audit requests by providing relevant certifications, security reports, or third-party audit summaries where available.
11. Data Retention and Deletion
- Personal data is processed for the duration of your subscription.
- Upon termination or cancellation, we will delete all personal data within 90 days, unless retention is required by law.
- You may request a data export before deletion takes effect.
- Backup copies are purged within 30 days of primary data deletion.
12. Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. The Processor's liability for breaches of this DPA shall not exceed the limitation of liability agreed in the main Terms.
13. Term and Termination
This DPA remains in effect for as long as Torq'd processes personal data on your behalf. It terminates automatically when all personal data has been deleted or returned following the end of the Service agreement.
14. Governing Law
This DPA is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales.
15. Contact
For DPA-related queries, contact:
Torq'd Ltd
Email: privacy@torqd.uk
