Data Processing Addendum
Last updated August 2026
This Addendum forms part of the agreement between Equillis Intelligence ('Processor') and the customer ('Controller') for use of the Equillis platform. It reflects the requirements of the UK GDPR and, where the Controller is established in the EEA, Regulation (EU) 2016/679. Equillis will also sign a customer's own DPA where preferred — email Henry@equillis.com.
1. Subject matter and duration
The Processor is Equillis Ltd, a private limited company registered in England and Wales under company number 17383990, trading as Equillis Intelligence.
The Processor processes personal data on behalf of the Controller solely to provide the Equillis vehicle-crime intelligence service. Processing continues for the term of the subscription and for the deletion period set out in section 9.
2. Nature and purpose of processing
- Hosting and storing account and operational records supplied by the Controller.
- Scoring depots, stops, lanes and schedules against open police-recorded crime data.
- Generating briefings, exports, alerts and reports for the Controller's users.
- Providing support, billing administration and security monitoring.
3. Categories of data subject and personal data
- Data subjects — the Controller's authorised users (employees and contractors given access to the platform).
- Personal data — name, business email address, role within the organisation, authentication metadata and product usage logs.
- Excluded — the platform is not designed for driver names, vehicle registrations, telematics traces or special-category data, and the Controller agrees not to upload them. Site references should be used in place of personal identifiers.
4. Controller instructions
The Processor processes personal data only on the Controller's documented instructions, which are given by use of the platform and this Addendum, unless required otherwise by applicable law. The Processor will inform the Controller if, in its opinion, an instruction infringes data-protection law.
5. Confidentiality
Personnel authorised to process personal data are bound by written confidentiality obligations and access is granted on a least-privilege basis, reviewed on role change or departure.
6. Security measures
The Processor implements the technical and organisational measures described on the Security and Data Processing page, which form Annex II to this Addendum. These include encryption in transit and at rest, row-level tenant isolation, server-side authorisation on every write, multi-factor administrative access, daily backups with point-in-time recovery, and logging of privileged actions.
7. Sub-processors
The Controller grants general authorisation for the sub-processors listed on the sub-processor page. The Processor imposes data-protection obligations on each sub-processor no less protective than those in this Addendum and remains liable for their performance. The Controller will be given at least 30 days' notice of any intended addition or replacement and may object on reasonable data-protection grounds.
8. International transfers
Customer data is hosted in the United Kingdom and the European Union. Where a sub-processor requires a transfer outside the UK or EEA, that transfer is made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism, together with a transfer risk assessment.
9. Deletion and return
On termination, or on written request, the Processor deletes the Controller's personal data within 30 days, other than billing records retained to meet statutory accounting obligations. Export of saved sites, lanes and scored schedules to CSV is available in the product at any time before deletion.
10. Assistance to the Controller
- Data subject rights — the Processor assists with access, rectification, erasure, restriction, portability and objection requests, and will pass on any request received directly within five business days.
- DPIAs and consultation — reasonable assistance is provided with impact assessments and prior consultation, given the nature of processing and information available.
11. Personal data breach
The Processor notifies the Controller without undue delay and in any event within 72 hours of becoming aware of a personal-data breach affecting the Controller's data, including the nature of the breach, likely consequences and remedial measures taken.
12. Audit
The Processor makes available the information necessary to demonstrate compliance and allows for audits, including inspections, by the Controller or an auditor it mandates, on reasonable notice, no more than once per year unless required by a supervisory authority or following a breach. Completed security questionnaires and, once available, third-party assurance reports may be provided in satisfaction of routine audit requests.
13. Order of precedence
In the event of conflict, this Addendum prevails over the Terms of Service in respect of the processing of personal data. Everything else in the agreement remains in force.
Signature
To execute this Addendum, or to have Equillis sign the Controller's own template, email Henry@equillis.com with the legal entity name and registered address. Counter-signature is typically returned within two business days.
