1.1 This Data Processing Agreement ("DPA") is entered into between Axxon B.V., a company incorporated under the laws of Curaçao, registered under number 133383 with the Chamber of Commerce and Industry of Curaçao, with registered office at Bon Bini Business Center Unit 1-10, Curaçao, contracting for itself and on behalf of its affiliates that process Personal Data in connection with the Services (together, "Axxon"), and the entity identified as the customer in the Principal Agreement ("Customer").
1.2 "Principal Agreement" means the master services agreement, proposal, order form, quotation, or other written agreement between Axxon and the Customer governing the Customer's access to and use of Axxon's cloud-based fleet management, dashcam, video telematics, and related services (the "Services").
1.3 By executing a Principal Agreement that references this DPA, or by continuing to use the Services following notice of this DPA, the Customer agrees to be bound by it. This DPA forms an integral part of the Principal Agreement and is incorporated therein by reference. No separate signature is required.
1.4 This DPA applies where and to the extent that Axxon processes Personal Data on behalf of the Customer in connection with the provision of the Services.
1.5 Where the Services are provided in respect of processing carried out in the Republic of Colombia, the Colombia Addendum applies and "Axxon" is construed in accordance with paragraph A of that Addendum. Axxon B.V. enters into this DPA for itself and on behalf of Axxon LATAM S.A.S.
1.6 In the event of a conflict with respect to the processing of Personal Data: (i) an applicable Regional Addendum prevails over the body of this DPA in respect of processing carried out in the jurisdiction to which that Addendum applies; (ii) this DPA prevails over the Principal Agreement; and (iii) where the Standard Contractual Clauses apply, they prevail to the extent of any conflict, in accordance with Clause 5 thereof.
1.7 Axxon may update this DPA to reflect changes in Applicable Data Protection Law, the Services, or its subprocessors. Axxon shall give the Customer at least thirty (30) days' prior notice of any material change by email or by publishing an updated version at https://axxon.co/dpa. No update shall materially reduce the overall level of protection afforded to Personal Data under the version in force when the Customer entered into the Principal Agreement. Changes to Annex III are governed by Section 9.
1.8 All notices under this DPA shall be sent to Axxon at [email protected] and to the Customer at the contact details set out in the Principal Agreement.
2. DEFINITIONS
For the purposes of this Addendum:
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation performed on Personal Data.
"Controller" means the entity that determines the purposes and means of Processing.
"Processor" means the entity that Processes Personal Data on behalf of the Controller.
“Applicable Data Protection Law” means all applicable data protection, privacy, and information security laws and regulations in force from time to time that apply to the processing of Personal Data under this DPA, including without limitation: (i) the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and its national implementing legislation; (ii) the UK GDPR and the UK Data Protection Act 2018; (iii) the Swiss Federal Act on Data Protection (“FADP”) as revised; (iv) Colombian Law 1581 of 2012 and Decree 1074 of 2015 and their implementing regulations; (v) applicable United States federal and state privacy laws, including the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”); and (vi) any other data protection or privacy laws applicable to the relevant jurisdiction in which the Customer operates or in which Personal Data subjects are located.
3. ROLES OF THE PARTIES
The Customer acts as the Controller of Personal Data.
Axxon acts as the Processor and shall process Personal Data solely on behalf of the Customer and in accordance with the Customer’s documented instructions.
4. NATURE AND PURPOSE OF PROCESSING
Axxon processes Personal Data as necessary to provide the Services under the Agreement,including the provision of fleet tracking, video telematics, operational monitoring, and related analytics and reporting functionalities.
5. CATEGORIES OF PERSONAL DATA
Personal Data processed under this Addendum may include:
GPS location data of vehicles;
Driver identifiers, where enabled by the Customer;
Video recordings, including images of drivers and surroundings;
Audio recordings, where enabled by the Customer (disabled by default);
Vehicle and operational data;
User account and access data.
Axxon does not intentionally perform facial recognition or process biometric data.
6. CATEGORIES OF DATA SUBJECTS
Data subjects may include drivers, employees, contractors, and authorized users of the Customer.
7. PROCESSING INSTRUCTIONS
Axxon shall process Personal Data only as necessary to provide the Services and strictly in accordance with the documented instructions of the Customer, including as set out in this DPA and the Principal Agreement. The configuration and use of the Services by the Customer shall constitute documented instructions for the purposes of this DPA. If Axxon is required by Applicable Data Protection Law to process Personal Data beyond the scope of the Customer’s instructions, Axxon shall inform the Customer of such legal requirement prior to processing (unless prohibited by applicable law on grounds of public interest). If Axxon considers that any instruction from the Customer infringes Applicable Data Protection Law, Axxon shall promptly notify the Customer.
Axxon shall not process Personal Data for its own purposes.
8. RETENTION
Personal Data shall be retained in accordance with the Customer’s instructions and configuration of the Services.
GPS location data is retained for the duration of the Agreement unless otherwise configured bythe Customer.
Video recordings are retained for approximately thirty (30) days unless otherwise configured by the Customer.
Notwithstanding the foregoing, Axxon may retain Personal Data for longer periods where required to comply with applicable law, legal hold obligations, dispute resolution requirements, or legitimate evidentiary preservation needs.
9. SUBPROCESSORS
The Customer hereby provides general written authorization for Axxon to engage subprocessors to support the provision of the Services, subject to the conditions set forth in this Section 8. Axxon shall provide prior written notice to the Customer of any intended changes concerning the addition or replacement of subprocessors by updating the list set forth in Annex III or by notifying the Customer via email at least thirty (30) days in advance. The Customer may object to any such change on reasonable data protection grounds by notifying Axxon in writing within fifteen (15) days of receipt of such notice. If the parties are unable to resolve such objection within a reasonable time, either party may terminate the affected portion of the Services upon written notice, without penalty.
Axxon’s subprocessors include, without limitation:
Mapon (fleet management platform provider, European Union);
Lytx / Surfsight (video telematics provider, United States);
Hosting providers located within the European Union.
Axxon shall impose data protection obligations on each subprocessor that are no less protective than those set out in this DPA. Axxon shall remain fully liable to the Customer for the performance of the subprocessor’s obligations to the extent that the subprocessor fails to fulfil its data protection obligations. The current list of subprocessors is set out in Annex III.
10. SECURITY MEASURES
Axxon shall implement appropriate technical and organizational measures designed to protectPersonal Data against unauthorized or unlawful processing and against accidental loss,destruction, or damage.
Such measures shall be appropriate to the nature of the Personal Data processed, the risks involved, and the state of the art and include, at a minimum:
encryption of Personal Data in transit and at rest;
access controls and authentication mechanisms, including two-factor authentication where applicable;
role-based access restrictions;
logging and monitoring of system access and activity;
vulnerability management and periodic security assessments;
business continuity and disaster recovery procedures;
backup and restoration controls;
incident response and escalation procedures;
periodic personnel training on data protection and information security obligations;
periodic review and testing of security measures.
11. DATA SUBJECT RIGHTS
Axxon shall, taking into account the nature of the Processing, assist the Customer by appropriate technical and organizational measures in fulfilling the Customer’s obligations to respond to requests from data subjects.
Axxon shall not respond directly to such requests unless required to do so by applicable law.
12. PERSONAL DATA BREACH
Axxon shall notify the Customer without undue delay, and in any event without undue delay after becoming aware, of any Personal Data breach affecting Personal Data processed under this DPA. Such notification shall include, to the extent available at the time: (i) a description of the nature of the breach, including the categories and approximate number of data subjects and Personal Data records affected; (ii) the likely consequences of the breach; (iii) the measures taken or proposed to be taken by Axxon to address the breach, including mitigation measures; and (iv) the name and contact details of the Axxon data protection contact. Where full information is not available within seventy-two (72) hours, Axxon shall provide an initial notification followed by supplementary information as soon as reasonably practicable. Axxon shall cooperate with the Customer and take such reasonable steps as may be directed by the Customer to assist in the investigation, mitigation, and remediation of any such breach.
13. DELETION OR RETURN OF DATA
Upon termination or expiration of the Agreement, Axxon shall, at the Customer’s choice, delete or return Personal Data, unless retention is required by applicable law.
Axxon shall complete such deletion or return within thirty (30) days following the termination or expiration of the Agreement, and shall provide the Customer with written certification of such deletion upon request. Residual copies contained in backup systems shall be deleted in the ordinary course of Axxon’s backup rotation cycle, and shall not be accessible by Axxon personnel during that period except as required to maintain the integrity of the backup system.
Personal Data shall be deleted using commercially reasonable secure deletion methods designed to prevent unauthorized recovery or reconstruction of the data.
14. INTERNATIONAL DATA TRANSFERS
Where Personal Data is transferred to a country or territory outside the jurisdiction in which it was originally collected, Axxon shall ensure that such transfer is carried out in compliance with Applicable Data Protection Law and that appropriate safeguards are in place to protect the Personal Data, including without limitation: (i) for transfers from the EEA or UK: the Standard Contractual Clauses adopted by the European Commission or the equivalent UK International Data Transfer Agreement, as applicable; (ii) for transfers from Colombia: a data transmission agreement complying with Law 1581 of 2012; (iii) for transfers from other jurisdictions: such equivalent transfer mechanisms as may be required by Applicable Data Protection Law. Axxon shall provide the Customer with reasonable assistance in documenting and formalizing such transfer mechanisms upon request.
ANNEX I – DETAILS OF PROCESSING
Controller: Customer
Processor: Axxon
Subject Matter: Provision of cloud-based fleet management and video telematics services
Nature and Purpose: Processing necessary to deliver the Services
Categories of Data: As described in Section 4
Categories of Data Subjects: As described in Section 5
Retention: As described in Section 7
ANNEX II – TECHNICAL ANDORGANIZATIONAL MEASURES
As described in Section 9 of this Addendum.
REGIONAL ADDENDUMS
A. EUROPEAN ECONOMIC AREA (GDPR)
This Addendum incorporates the requirements of Article 28 of the GDPR.
Where applicable, the Standard Contractual Clauses (Controller-to-Processor) shall apply to transfers of Personal Data outside the EEA.
B. COLOMBIA
This Addendum supplements, develops, and forms an integral part of this DPA and shall apply exclusively with respect to the data processing carried out in the Republic of Colombia.
In the event of any conflict, inconsistency, or contradiction between the general terms of the DPA and this Colombia Addendum, the provisions of the latter shall prevail exclusively with respect to data processing carried out in Colombia.
For purposes of the data processing carried out in Colombia, the following deviations apply to the terms of the DPA:
The Customer shall be solely responsible for determining whether the use of audio and video recording functionalities complies with applicable employment, labor, privacy, surveillance, and data protection laws in the jurisdictions where the Services are used, including obtaining any required notices, authorizations, or consents from data subjects.
The Customer shall also be solely responsible for defining the purposes and conditions under which such functionalities are used. Axxon does not verify, monitor, or guarantee the legal validity of such notices, authorizations, consents, or Processing activities conducted by the Customer.
Axxon shall reasonably cooperate with the Customer in connection with any notification obligations before the Colombian Superintendencia de Industria y Comercio (SIC) or any other competent authority arising from a Personal Data breach.
Axxon shall maintain appropriate records relating to any such security incident and preserve relevant evidence reasonably necessary for investigation and remediation purposes.
The Customer shall be responsible for obtaining any authorizations, consents, or legal bases required under applicable Colombian law for such international transfers or transmissions of Personal Data.
The parties agree that any international transmission or transfer of Personal Data shall be carried out in accordance with the principle of restricted circulation and subject to the safeguards required under Law 1581 of 2012 and its implementing regulations.
The parties acknowledge that the Services are not intended for the intentional collection or processing of sensitive Personal Data, including biometric data, health data, or other categories of sensitive data under applicable law.
To the extent any sensitive Personal Data is incidentally captured through the use of the Services, the Customer shall be responsible for ensuring that an appropriate legal basis exists for such Processing and that all applicable legal requirements are satisfied.
16. CONFIDENTIALITY OF PROCESSING
Axxon shall ensure that any person authorized to process Personal Data on its behalf is subject to appropriate obligations of confidentiality, whether by contract or professional duty, and that access to Personal Data is limited to those personnel who require access to perform the Services.
17. LIMITATION OF LIABILITY
Each party’s liability under or in connection with this DPA, whether arising in contract, tort (including negligence), breach of statutory duty, or otherwise, shall be subject to the limitations and exclusions of liability set forth in the Principal Agreement. Nothing in this DPA shall limit either party’s liability for fraud, gross negligence, or willful misconduct, or any liability that cannot be excluded or limited by applicable law.
L. A section 18 is added, as follows:
18. GENERAL PROVISIONS
18.1 Entire Agreement. This DPA, together with the Principal Agreement and its annexes, constitutes the entire agreement between the parties with respect to the processing of Personal Data and supersedes all prior agreements and understandings relating to the same subject matter.
18.2 Amendments and Updates. (a) Axxon may update this DPA from time to time where reasonably necessary to reflect changes in Applicable Data Protection Law, the Services, Axxon's subprocessors, or Axxon's technical and organizational measures.
(b) Axxon shall notify the Customer of any material update at least thirty (30) days before it takes effect, by email to the Customer's contact address or by publishing the updated version at https://axxon.co/dpa and notifying the Customer that it has done so. Non-material updates, including corrections of clerical errors, take effect on publication. Where an update is required to comply with Applicable Data Protection Law or a binding order of a competent authority on a shorter timeline, the update takes effect on the date required by that law or order, and Axxon shall notify the Customer as promptly as reasonably practicable.
(c) No update made under this Section shall materially reduce the overall level of protection afforded to Personal Data compared to the version of this DPA in force when the Customer most recently entered into or renewed the Principal Agreement.
(d) Subject to paragraph (c), the version of this DPA published at https://axxon.co/dpa as at the date of any given Processing governs that Processing.
(e) Changes to Annex III (Subprocessors) are governed exclusively by Section 9, and paragraphs (b) and (c) of this Section do not apply to them.
(f) Where Axxon and the Customer have agreed in writing, signed by authorized representatives of both parties, to terms that vary from this DPA, those agreed terms prevail over any subsequent update made under this Section for the duration of the Principal Agreement, and may only be amended by a further written instrument signed by both parties.
18.3 Severability. If any provision of this DPA is found to be unenforceable, the remaining provisions shall continue in full force and effect.
C. UNITED STATES
To the extent applicable, Axxon shall act as a "Service Provider" or "Processor" under applicableUnited States privacy laws, including the California Consumer Privacy Act (CCPA) and CaliforniaPrivacy Rights Act (CPRA).
Axxon shall not sell Personal Data and shall not retain, use, or disclose Personal Data for any purpose other than for the specific purpose of performing the Services in accordance with the Agreement.