Data Processing Agreement
How we process personal data in your workspace on your behalf.
Last updated 9 October 2026
1. Purpose and roles
This Data Processing Agreement applies when Data BI ("we", "the processor") processes personal data for a customer ("you", "the controller") through FleetOne. It forms part of our Terms of Service and Subscription Agreement. It applies to the business records your team enters into your workspace. For account and website information that we decide how to use, we act as a controller, as described in the Privacy Policy.
2. What we process
Subject matter and purpose: providing the service, which is dispatch, fleet, customer, carrier, driver, document and billing records for trucking operations.
People whose data is involved: your staff and users, your drivers, contacts at your customers, contacts and owners of carriers you work with, and people named on documents you upload.
Kinds of data: names, phone numbers, email addresses, licence and medical certificate dates, insurance details, pay terms, locations and check-in times from driver links, signatures and signing records, documents you upload, and notes you write. You decide what you enter. Please do not enter data you do not need, and do not enter government ID numbers or health information beyond certificate expiry dates.
Duration: while your workspace is open, plus the retention period in section 9.
3. Our obligations
We process personal data only on your documented instructions, which are this agreement, the Terms of Service and what you do in the application. If we think an instruction breaks data protection law we will tell you.
Everyone at our company with access to the data is bound by confidentiality. Access is limited to what is needed for support, security and running the service.
We help you answer requests from people exercising their data protection rights, and with security, breach notification and impact assessments, taking into account what we know. We may charge a reasonable fee for help that goes beyond normal use of the product.
4. Security
Each company's records are kept apart and every request is checked against the signed-in person's role and company. Connections are encrypted. Passwords are stored as hashes. Private links for signing, tracking and driver updates are long random secrets of which only a fingerprint is stored. They expire and can be revoked, and they are left out of backups.
Our admin tools for support need a written reason, are limited to named staff, and are logged. If we look at your records to help you, you are told in your workspace.
Company owners can create and restore backups of their workspace data from Settings. We fix security problems as we find them. No system is completely secure, and you are responsible for keeping your own passwords and devices safe.
5. Sub-processors
You agree that we may use the providers listed in our Third-party Services page to process data for you. In summary: hosting in France, email delivery, payment processing, domain services, and AI processing only if your company owner turns the AI assistant on.
Providers that you connect yourself, such as accounting, telematics or text message services, act on your instructions and are your sub-processors, not ours.
We will add or replace a provider only if it gives a comparable level of protection. We will update the Third-party Services page and give you at least 14 days' notice by email or in the application. You may object on reasonable data protection grounds within that time, and if we cannot resolve it you may cancel without penalty.
6. Transfers
Data is stored on servers in France. We and our providers may access it from other countries. Where the law requires a transfer safeguard, such as the standard contractual clauses, we use one, and we will give you a copy on request.
7. Breaches
If we become aware of a breach of security that leads to the loss, alteration, disclosure of or access to your personal data, we will tell you without undue delay and where we can within 72 hours, by email to your workspace owner. We will say what happened, what data is affected, what we are doing and what we recommend you do. Questions: connect@databi.me.
8. Audits and information
On reasonable written request, and not more than once a year unless there has been a breach, we will give you the information needed to show we meet this agreement. You may not run your own security tests against our service without our written permission, because the service is shared with other customers.
9. Return and deletion
When your workspace ends you can retrieve your data for 30 days. After that we delete it from live systems, and it leaves backups on their normal cycle. We may keep data for longer only where the law requires it, and we will keep it protected and use it for nothing else.
10. Responsibilities and liability
You are responsible for having a lawful basis to enter the data you enter, for telling your drivers and other people how their data is used, and for getting their agreement where the law requires it, for example before you track a driver's location.
Each party's liability under this agreement is subject to the limits in the Terms of Service. If this agreement conflicts with the Terms of Service on the processing of personal data, this agreement wins.