





Version: September 2026
Contents
- Introduction & Definitions
- Data Processing Overview
- 1. Processing of Client Data
- 2. General Obligations of the Parties
- 3. Sub-Processing & Cross-Border Data Transfers
- 4. Security & Compliance
- 5. Access to Data and Assistance to Controller
- 6. Miscellaneous
- Appendix 1: Description of Processing
- Appendix 2: Sub-Processors
- Appendix 3: OEM & Third-Party Integrations Data Processing Terms
- Appendix 4: Technical & Organizational Measures
- Data Access Specification Sheet (under development)
Introduction & Definitions
- This Data Processing Addendum (including its appendices, collectively the
DPA
) supplements and is subject to the provisions of the agreement and any other terms and conditions binding the Controller and the Processor (collectively, theParties
, and, individually, eachParty
) in connection with Processor's provision of the WEBFLEET Service and Products to Controller (theAgreement
). For the purposes of this DPA, Client (as defined in the Agreement) shall be deemed the Controller, and Webfleet Solutions B.V. shall be deemed the Processor. - This DPA describes the Parties' obligations with respect to the processing and security of Client Data (defined below), including under applicable privacy, security, and data protection laws. This DPA constitutes an integral part of the Agreement and replaces any terms previously applicable to the processing and security of Client Data.
- Any capitalized term not defined herein shall have the meaning given to it in the Agreement and its schedules. To the extent the language in this DPA conflicts with the Agreement, this DPA shall control. For the purposes of this DPA:
Applicable Privacy Law(s)
means binding national, state, European Union, or provincial laws or regulations in force concerning privacy, security, or data protection and applicable to the processing of Client Data;Client Data
means all (personal) data generated, collected, provided, or otherwise processed by Processor on behalf of and under the instructions of Controller for the provision of the WEBFLEET Service and Products;GDPR
collectively means both the United Kingdom's and the European Union's GDPR Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;Processor Security Incident
means an event affecting Processor's security and leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Client Data on systems managed by or otherwise maintained by Processor;Sub-Processor
means a third party engaged by Processor to carry out a specific part of the Client Data processing activities necessary for the provision of the WEBFLEET Service and Products;Supervisory Authority
means a competent authority that is expressly vested with powers and authority to monitor compliance with and enforce any Applicable Privacy Laws; and- The terms
personal data
,data subject
,processing
,controller
,processor
,special categories of personal data
,personal data breach
, andanonymization
as used in this DPA have the meanings given by the Applicable Privacy Law or, absent any such meaning or law, by the GDPR.
Data Processing Overview
This DPA governs the Parties' commitments with respect to the processing of personal data in the WEBFLEET Service and Products. For a comprehensive overview of the WEBFLEET Service and Products, Appendix 1 (Description of Processing) includes information relating to the processing of all categories of Client Data, including non-personal data.
| Overview of Processing (Personal Data) | |
|---|---|
| Subject Matter | The subject matter of data processing under this DPA is personal data collected, generated or otherwise processed in the context of Controller's use of the WEBFLEET Service and Products. |
| Duration | Personal data will be processed for as long as the Agreement and this DPA remain in force. For the specific data points detailed in the Appendix 1 (Description of Processing), the granular retention periods indicated in the relevant table shall apply, also after termination of the Agreement for any reason. At Controller's express request and subject to the applicable commercial conditions, such retention periods may be extended, thereby superseding the relevant retention schedule defined in this DPA. Controller is also entitled to request erasure of (portions of) Client Data while this DPA remains in force. |
| Purposes | The purpose of the processing of personal data under this DPA is the provision of the WEBFLEET Service and Products as initiated by Controller, as further outlined in Section 1.2 of this DPA and in accordance with the Agreement. As between Controller and Processor, Controller's use of the WEBFLEET Service and Products may have, as the case may be and depending on the contracted scope under the Agreement, the essential purposes of carrying out (real-time) vehicle tracking, bi-directional communication between fleet managers and drivers, management of fleet workflows, maintenance, sustainability and costs, assessment of driver performance and behavior, driving time management and recording, and integration with third-party solutions selected by Controller. Processor shall also render data non-personal for the purposes of Processor's further processing of anonymized and aggregated System Data in accordance with the Agreement. The processing of personal data made available to Processor hereunder is intended to enable Controller to access strategic data to make informed decisions about productivity, maintenance, compliance, safety, sustainability, and cost-efficiency of its fleet operations. |
| Nature of Processing | Data recording, retrieval, collection, storage, organization, combination, analysis, disclosure, erasure and any such other activities and services as initiated by Controller, according to the descriptions in the documentation of the relevant WEBFLEET Service and Products. For the purposes of anonymization, Processor shall ensure Client Data de-identification (removal, transformation, aggregation of identifiers) so that it is no longer attributable to a data subject. |
| Categories of Data | The categories of personal data specified in Appendix 1 (Description of Processing). |
| Categories of Data Subjects | Personal data processed in the WEBFLEET Service and Products will generally relate to the following categories of individuals:
|
1. Processing of Client Data
1.1. Appointment of Processor. Controller appoints Processor to process Client Data on its behalf and under its documented instructions under the Agreement, this DPA and throughout Controller's deployment, configuration, and use of the WEBFLEET Service and Products. To the extent required by Applicable Privacy Laws, where the Processor processes Client Data that qualifies as personal data, the Controller shall be deemed the controller and the Processor the processor of such personal data.
1.2. Purpose Limitation. The processing of Client Data is granularly detailed in Appendix 1 (Description of Processing), including all the types of personal data involved, as well as the duration and context of such processing in connection with each portion of the WEBFLEET Service and Products. Except as otherwise expressly agreed upon in the Agreement, Processor will only process personal data in the Client Data as described in this DPA as strictly necessary to provide the WEBFLEET Service and Products. The following groups of activities are considered strictly necessary to that end:
- Enabling and delivering the requested functional capabilities of the WEBFLEET Service and Products as licensed to, configured, and used by Controller and its users;
- Troubleshooting (preventing, detecting, investigating, mitigating, and repairing problems, including Processor Security Incidents and issues identified in the WEBFLEET Service and Products), providing customer (technical) support, advice on deployment and usability of the WEBFLEET Service and Products; and
- Keeping the WEBFLEET Service and Products up to date and performant, and enhancing user productivity, reliability, efficacy, quality, and security.
1.3. Anonymization of Client Data. Controller authorizes Processor to anonymize Client Data processed under this DPA with a view to enable its further processing as permitted under the Agreement and Applicable Privacy Law. Anonymized data does not constitute personal data, shall not be deemed Client Data, and is not subject to this DPA. Processor may process anonymized data in the form of System Data, as governed by the Agreement.
1.4. No Automated Decision-Making. To the extent that Controller's contracted scope for WEBFLEET's Service and Products include automated processing as specified in Appendix 1 (Description of Processing), the Parties hereby acknowledge that Processor (by means of the WEBFLEET's Service and Products or otherwise) is incapable of making decisions that produce legal effects concerning individuals. Controller is solely responsible for interpreting the Client Data generated throughout the use of the WEBFLEET's Service and Products by its authorized users as well as for making and documenting its own independent decisions.
1.5. Engagement of Third Parties. Controller acknowledges and agrees that the processing of Client Data relies on Sub-Processors providing services that are necessary for the WEBFLEET Service, as set forth in Section 3 below and further detailed in Appendix 2 (Sub-Processors). Furthermore, and to the extent that Controller elects to connect either (a) Vehicles to the WEBFLEET Service by means of an OEM Onboard Unit; or (b) the WEBFLEET Service and Products to technologies provided by other independent service providers with the intention to establish shared processing of Client Data between Processor and those independent service providers for purposes defined by Controller in agreement with such service providers, then the provisions of Appendix 3 (OEM & Third-Party Integrations Data Processing Terms) will apply.
1.6. This DPA is incorporated by reference into the Agreement and will take effect on the date in which the Parties entered into the Agreement. If an Agreement was already in place upon receipt of this DPA by Controller, then this DPA will take effect as of the date communicated by Processor in its notice to Controller.
2. General Obligations of the Parties
2.1. Controller's Obligations. In addition to its other obligations under the Agreement and this DPA, the Controller shall comply with the Applicable Privacy Laws and:
- Ensure that the processing of Client Data is lawful and that the processing of personal data is grounded on a valid legal basis under Applicable Privacy Law;
- Be transparent about the processing of personal data towards data subjects and provide the necessary information about such processing and data subjects rights as required under Applicable Privacy Laws;
- Ensure the security of Client Data when using the WEBFLEET Service and Products and when storing or otherwise using Client Data outside Processor's or Sub-Processors' systems, including by: (1) using adequate controls to ensure a level of security appropriate to the risk to the Client Data, (2) securing account authentication credentials, systems and devices Controller uses to access the WEBFLEET Service and Products, and (3) backing up or retaining copies of Client Data as appropriate;
- Provide adequate training on privacy, data protection and information security to its staff and contractors with respect to the processing and adequate protection of Client Data;
- To the extent required under Applicable Privacy Laws, ensure that Controller's accountability obligations relating to the processing and protection of Client Data are met, including keeping accurate and up-to-date records about the decisions made relating to its own activities; and
- Make lawful use of the WEBFLEET Service and Products and only provide instructions for the processing of Client Data in compliance with Applicable Privacy Laws.
2.2. Processor's Obligations. In addition to its other obligations under the Agreement and this DPA, the Processor shall comply with the Applicable Privacy Laws and:
- Process personal data only on documented instructions from the Controller, unless required to do so by force of a binding legal obligation for the Processor, in which case Processor shall inform the Controller of that legal requirement before processing, unless applicable law prohibits Processor from disclosing such information;
- Subject to the product- and service-specific conditions on data retention laid out in Appendix 1 (Description of Processing), and unless Applicable Privacy Laws prevent Processor from doing so, irreversibly anonymize or delete personal data in the Client Data at the end of the applicable retention periods, as well as allow Controller to export, retrieve or otherwise access Client Data in accordance with the provisions of Section 5 below while this DPA remains in force;
- Only engage Sub-Processors and transfer Client Data across jurisdictions in accordance with the requirements set forth in Section 3 below;
- Provide adequate training on privacy, data protection and information security to its staff and contractors with respect to the processing and adequate protection of Client Data;
- Maintain an appropriate level of security for Client Data in accordance with the provisions of Section 4 below by implementing appropriate technical and organizational measures to that effect and ensure that Sub-Processors, employees and other persons authorized to process the Client Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- To the extent required under Applicable Privacy Laws, ensure that accurate and up-to-date records of the activities it carries out involving the processing of Client Data are maintained; and
- Where Processor becomes aware that an instruction clearly infringes Applicable Privacy Laws, it shall immediately notify Controller, who may then withdraw or modify its instructions accordingly. For the avoidance of doubt, and in particular due to the nature of Controller's instructions to Processor as referred to in Section 1.1 above, Controller understands and agrees that (1) it is unlikely that Processor can form an opinion on whether instructions from Controller infringe Applicable Privacy Laws; (2) Processor is under no obligation to actively monitor or audit Controller's instructions or deployment decisions; and (3) Processor is not responsible for providing legal advice to Controller.
3. Sub-Processing & Cross-Border Data Transfers
3.1. Authorization to Engage Sub-Processors. Controller acknowledges that the provision of the WEBFLEET Service and Products requires Processor to put in place complex technical and organizational arrangements for the adequate processing and protection of Client Data, including with specific Sub-Processors providing specialized services. Controller therefore gives general authorization for Processor to engage Sub-Processors under the terms of this DPA. The entities listed in Appendix 2 (Sub-Processors) are the Sub-Processors engaged by Processor for the provision of the WEBFLEET Service and Products to Controller. Controller further authorizes Processor's engagement of other third parties as Sub-Processors provided that such engagement is strictly necessary for the adequate provision of the WEBFLEET Service and Products. Processor shall notify Controller of intended changes to Appendix 2 (Sub-Processors) in accordance with Sections 3.2 and 6.4 below.
3.2. Controller's Objection to Sub-Processors. When Processor engages any new Sub-Processor not listed in Appendix 2 (Sub-Processors), Processor will, at least 30 days before the new Sub-Processor starts processing any Client Data, update Appendix 2 (Sub-Processors) accordingly, including the name, location and activities of the new Sub-Processor. Controller may, within 15 days after the publication of the updated Appendix 2 (Sub-Processors), object to the appointment of the new Sub-Processor(s) by notifying Processor in writing. When objecting to new Sub-Processors, Controller will include a documented explanation of the grounds for non-approval together with the termination notice to permit Processor to re-evaluate any such new Sub-Processor based on the concerns expressed by Controller. Upon receipt of such an objection by Processor, the Parties shall discuss in good faith and attempt to find a commercially reasonable resolution. If after such discussion Controller does not approve the new Sub-Processor, then Processor may, at its sole discretion, either (a) refrain from appointing the objected Sub-Processor; or (b) allow Controller to (partially) terminate any subscription for the affected portion of the WEBFLEET Service and Products which would otherwise rely on that Sub-Processor, without liability to either Party.
3.3. Conditions Applicable to Sub-Processors. Where a Sub-Processor fails to fulfill its data protection obligations, Processor shall remain liable to Controller for the performance of that Sub-Processor's obligations. Processor shall ensure that, as between Processor and each Sub-Processor, a written contract is in place whereby:
- Sub-Processor undertakes to process personal data in the Client Data only to the extent required to perform the specific obligations subcontracted to it; and
- To the extent required under the Applicable Privacy Laws, Sub-Processor abides to data protection obligations in a manner that is substantially consistent with Processor's obligations under this DPA. This shall include, in particular, Sub-Processor's obligations to implement appropriate technical and organizational measures to ensure the security of Client Data.
3.4. Cross-Border Processing of Client Data. Controller is solely responsible for defining where the WEBFLEET Service and Products will be used by authorized users, including the geographic locations where Controller's vehicles managed with the WEBFLEET Service and Products will be moved through. Controller acknowledges that the provision of the WEBFLEET Service and Products requires Processor to process Client Data in different jurisdictions, because of the physical location of the processing facilities used by Processor and Sub-Processors. Data processing activities carried out by Processor will generally take place within the European Economic Area. Other jurisdictions on which Client Data will be processed, as well as the specific conditions applicable to such cross-border processing under Applicable Privacy Laws, if any, are laid out in Appendix 2 (Sub-Processors). Controller shall inform Processor in advance in case it intends to use the WEBFLEET Service and Products in a jurisdiction that imposes privacy obligations that add to or conflict with those considered in this DPA. If additional or conflicting obligations are communicated by Controller, then the Parties shall engage in good faith negotiations about (1) the necessary amendments to this DPA to address said obligations, and (2) the potential impacts to the commercial conditions applicable to the WEBFLEET Service and Products as a result of such amendments in a way that meets Controller's requirements and maintains the commercial balance of the Agreement.
3.5. Non-EEA/UK Processing of Personal Data. Where Processor engages a Sub-Processor hereunder for carrying out personal data processing activities on behalf of Controller which entail transfers of personal data outside the European Economic Area and the United Kingdom, Processor will only transfer personal data outside the European Economic Area and the United Kingdom if the appropriate GDPR requirements are met. Processor will only engage Sub-Processors to process personal data in the Client Data outside the European Economic Area or the United Kingdom if either (a) an adequacy decision in the meaning of Article 45 GDPR is in place to cover the geography where processing by the relevant Sub-Processor is set to take place; or (b) standard contractual clauses adopted by the European Commission (EEA) or the Information Commissioner's Office (UK) in accordance with of Article 46(2) GDPR are in place between Processor and Sub-Processor, provided that the conditions for the use of those standard contractual clauses are met. Specific information applicable to the processing of personal data carried out by each Sub-Processor is laid out in Appendix 2 (Sub-Processors).
4. Security & Compliance
4.1. Confidentiality of Client Data. Processor will not access, use, or disclose to any third party, any Client Data, except as (a) directed by Controller, (b) described in this DPA, or as (c) necessary to comply with the law or a valid and binding order of a governmental body (such as a subpoena or court order). If a competent (government) authority requests access to Client Data, the Processor will, where legally permitted and reasonably practicable, seek to redirect the authority to request the data directly from the Controller. If the Processor is legally required to disclose Client Data, it will provide the Controller with prompt notice of the request and await instructions, unless prohibited to do so by law.
4.2. Processor's Security Measures. Processor will implement and maintain technical, organizational, and physical measures to protect Client Data against Processor Security Incidents in a manner consistent with its obligations under Applicable Privacy Laws as described in Appendix 4 (Technical & Organizational Measures). Processor may update such measures from time to time provided that such updates do not result in a material reduction of the security of the Client Data processed within the WEBFLEET Service and Products.
4.3. Controller's Security Assessment. Controller is solely responsible for making an independent determination as to whether the technical and organizational measures for the security of the WEBFLEET Service and Products meet Controller's requirements, including any of its security obligations under Applicable Privacy Laws. By entering into this DPA, Controller agrees that the WEBFLEET Service and Products and in particular the security practices and policies implemented and maintained by Processor provide a level of security appropriate to the risk to Client Data, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing of Client Data as well as the risks to individuals.
4.4. Security Incidents. Processor will notify Controller promptly and without undue delay after becoming aware of a Processor Security Incident, take reasonable steps to minimize harm and secure Client Data, and continue to provide reasonable assistance to Controller to that effect. Processor may provide information about a Processor Security Incident in phases in so far as more information about the Security Incident becomes available. To enable Controller to notify a Processor Security Incident to a Supervisory Authority and/or data subjects, Processor will cooperate with and assist Controller by including in the notification under this Section 4.4 such information about the Processor Security Incident as Processor is able to disclose to Controller, taking into account the nature of the processing and the information available to Processor. Processor's notification of or response to a Processor Security Incident to Controller hereunder will not be construed as an acknowledgement by Processor of any fault or liability with respect to the Processor Security Incident. Controller must notify Processor promptly about any possible misuse of its accounts or authentication credentials or any other security incident, breach or adverse event related to the WEBFLEET Service and Products.
5. Access to Data and Assistance to Controller
5.1. Data Access. At all times during the term of the Agreement and this DPA, Processor will enable Controller, in a manner consistent with the functionalities of the WEBFLEET Service and Products, to access and to export Client Data, including where necessary for further use of Client Data by Controller outside the WEBFLEET Service and Products. Processor keeps a Data Access Specification Sheet up to date with the purpose of transparently informing Controller about the different data points generated by Processor throughout the Agreement, as well as the means available for Controller to access and export such data. This can be consulted at webfleet.com/dpa.
5.2. Control and Responsibility Over Client Data. Notwithstanding the specifications of the processing of Client Data for the purposes of the adequate provision of the WEBFLEET Service and Products under this DPA, Controller retains exclusive responsibility for assessing whether the processing of Client Data commissioned to Processor as described in this DPA and Agreement fulfills the legal, technical, and operational requirements of the Controller. This includes the specific retention periods applicable to the different categories of Client Data outlined in Appendix 1 (Description of Processing) and Controller's obligations and potential interests in keeping Client Data for periods that differ from those laid out in this DPA. During the term of this DPA, Controller retains control over Client Data, including where necessary to rectify, update, export, make copies of, and erase Client Data. Processor shall reasonably cooperate and assist Controller to that extent in accordance with the provisions of this DPA.
5.3. Data Subject Requests. Should Processor receive a request from a data subject that relates to Client Data, Processor will (1) advise the data subject to submit their request to Controller, (2) notify Controller without undue delay, and (3) refrain from responding to the request without authorization from Controller. Controller will be responsible for responding to any such request including by using the functionality of the WEBFLEET Service. Processor will (taking into account the nature of the processing of Client Data) assist Controller in fulfilling its obligations under Applicable Privacy Law to respond to requests for exercising the data subject's rights by either instructing Controller on how to use the WEBFLEET Service to that end or, if that proves insufficient, and upon Controller's express request, by providing Controller with additional reasonable cooperation and assistance.
5.4. Assistance for Compliance. Upon Controller's express request, Processor will (taking into account the nature of the processing and the information available to Processor) reasonably assist Controller where necessary in ensuring compliance with its obligations relating to data protection impact assessments, prior regulatory consultations with Supervisory Authority(ies) or equivalent procedures under Applicable Privacy Law. Processor will provide such cooperation and assistance by providing the requested information, which shall never be construed by Controller as legal advice, related to the processing activities and technical and organizational measures relevant to the WEBFLEET Service and Products, unless the requested information is otherwise already available to Controller. To the extent that Controller requests assistance, support or cooperation that materially exceeds the scope of Processor's obligations under this DPA or Applicable Privacy Laws, Processor may charge Controller for its reasonable and demonstrable costs incurred in providing such additional assistance. Controller shall reimburse Processor for all such reasonable and demonstrable costs and expenditures, provided that Processor notifies Controller in advance and obtains Controller's prior written approval for such costs.
5.5. Audits. Processor uses independent third-party auditors to verify the adequacy of its security measures according to ISO 27001 standards. At Controller's written request, and under appropriate confidentiality covenants, Processor will provide Controller with as much information and records as reasonably necessary so that Controller can verify Processor's compliance with its obligations under this DPA, including by providing access to relevant third-party audit reports, certifications, and summaries thereof. Controller agrees to use such reports and certifications as the primary means of verifying Processor's compliance. To the extent that Applicable Privacy Laws provides for audit rights and Controller reasonably determines that the information provided is insufficient to verify Processor's compliance with its obligations under this DPA, Processor will allow Controller (or a demonstrably independent auditor appointed by Controller) to verify Processor's compliance with its obligations under this DPA. During an audit, Processor will reasonably cooperate with Controller or its auditor, including by providing any relevant documents relating to Processor's measures applied by Processor to comply with this DPA. Controller remains responsible for any fees charged by an auditor appointed by Controller or otherwise incurred for the carrying out of any such audit. Following an audit request hereunder, the Parties will discuss and mutually agree in advance on:
- the reasonable start date, scope and duration of the audit; and
- each Party's security and confidentiality obligations, controls, and covenants applicable to the audit and to any related evidence or other documents, as well as any ensuing reports and agreements.
6. Miscellaneous
6.1. Termination of this DPA. This DPA shall remain in force for the duration of the Agreement and for so long thereafter as the Processor continues to process Client Data on behalf of the Controller during the applicable retention periods specified in Appendix 1 (Description of Processing). This DPA shall automatically terminate upon the Processor's cessation of all processing activities involving personal data in the Client Data.
6.2. Severability. If any provision of these DPA is at any time held by a competent court to be invalid or unenforceable, it shall be ineffective only to the extent of such invalidation or unenforceability without invalidating the remaining portions hereof, and such remaining portions of this DPA shall continue to be in full force and effect. In the event that any provision of this DPA shall be determined to be invalid or unenforceable, the Parties will negotiate in good faith to replace such provision with another provision that will be valid or enforceable and that is as close as practicable to the provisions held invalid or unenforceable.
6.3. Return or Deletion of Client Data. In addition to Controller's right to retrieve/obtain access to Client Data under Section 5.1 above, Processor will further enable Controller, at all times during the term of this DPA, to delete Client Data in a manner consistent with the functionalities of the WEBFLEET Service and Products. If Controller is technically unable to access or delete Client Data via the dedicated functionalities provided in the WEBFLEET Service and Products, Controller may submit a request in writing to that effect and Processor will enable Controller to access or irreversibly delete Client Data following such request.
6.4. Notices & Communication. Except where expressly stated otherwise, all notices from Processor to Controller under this DPA will be delivered to one or more of Controller's administrators, either by dedicated notifications via the WEBFLEET Service interface or email. Notice is given as of the date it is made available by Processor. It is Controller's sole responsibility to ensure Controller's administrators maintain accurate contact information on the WEBFLEET Service's management console and secure transmission at all times. Notices and other communications from Controller to Processor referring to the subject matter of this DPA will be delivered by Controller's authorized representatives to digitaltrust@bridgestone.com.
6.5. Updates. This DPA may be updated from time to time by Processor, including as needed to comply with updates to applicable laws and reflect the release of improvements or other material changes to the WEBFLEET Service and Products. The most up-to-date version of this DPA can be consulted at webfleet.com/dpa.
6.6. Governing Laws & Dispute Resolution. The provisions relating to the choice of applicable laws and dispute resolution contained in the Agreement shall apply in full to this DPA.
Appendices
- Appendix 1: Description of Processing
- Appendix 2: Sub-Processors
- Appendix 3: OEM & Third-Party Integrations Data Processing Terms
- Appendix 4: Technical & Organizational Measures
The most up-to-date version of this DPA as well as of each of the documents above can be found on webfleet.com/dpa.
Appendix 1
Description of Processing
Throughout Client's use of the WEBFLEET Service and Products, the following categories of data may be generated and further processed by Webfleet Solutions:
- User-Managed Data and Created Content: Data created or otherwise (manually) inserted into and/or edited in the Webfleet Telematics Service Platform.
- Transactional Data: Data automatically generated by Client's use of the WEBFLEET Service and Products.
- Aggregated Data: Data derived by applying statistical analysis as part of the WEBFLEET Service.
In the tables below, a detailed description of the different data points processed by Webfleet Solutions is presented. These tables include: (1) a general reference to each data category, (2) a description of the (more granular) data contained in each such data category, and (3) a reference to the retention period that Webfleet Solutions applies by default to the data points in each such data category.
Product- or Service-Specific Processing. Certain components and modules of the WEBFLEET Service and Products have specific data processing capabilities that apply only to them. Individual tables are set out below to describe this where applicable. To jump straight to the product- and service-specific data tables, please refer to the links below:
- Webfleet Services:
- Webfleet Mobile Applications:
The entirety of Client Data listed in this Appendix 1 is processed and made available to Client via the Webfleet Telematics Service Platform. To the extent that Client does not use certain components or modules of the WEBFLEET Service or Products, the data processing specifications that apply only to those unused components or modules will not apply to Client.
General Data Processing Overview
The tables below describe the general data processing capabilities that are enabled with the use of core features of the Webfleet Telematics Service Platform, as well as with most functionalities from the LINK and PRO devices.
User Managed Data and Created Content
Data created by users of the WEBFLEET Service and Products
| Data Category | Description | Retention Period |
|---|---|---|
| Addresses | Geolocation data, shipping addresses, way points and EV charging station locations | Throughout the Agreement, then during the remainder of the current calendar year + 2 full calendar years |
| Administrator and other Authorized Webfleet User Data | User name, address, and contact data as phone, email, identification numbers | |
| Areas | Geo-zone definitions to determine areas of wanted or unwanted vehicle position | |
| Driver Data | Driver name, address, and contact data as phone, email, driving license information, identification numbers | |
| Other User-Managed Vehicle Data | Other user content, such as individual vehicle specifications, additional telematics data (manually) provided by users, such as registration, VIN or license plate | |
| Fleet and Vehicle Departure Time | Planned departure time on a fleet or vehicle level | |
| Routes | Pre-defined driving routes, order destinations, planned routes on driver terminals | |
| VIN (Vehicle Identification Number) | 17-character unique identifier for a vehicle which displays the car's unique features, specifications and manufacturer which can be used to track recalls, registrations, warranty claims, thefts and insurance coverage as well as map a vehicle to a particular owner or data subject | |
| Checklists | Regular vehicle inspection and maintenance by drivers | 24 months |
| Orders and Order States | Job data for drivers, attachments, electronic proof of delivery, and order status | 90 days (France: 60 days) |
| Text Messages | Messages exchanged between fleet manager and driver through driver terminals |
Transactional Data
Data generated by using the WEBFLEET Service and Products
| Data Category | Description | Retention Period |
|---|---|---|
| (Lateral) Acceleration | Events of harsh breaking, cornering, and acceleration | 90 days (France: 60 days) |
| CAN/OBD Data | Signals from a vehicle's Controller Area Network (CAN) or on-board diagnostics (OBD) interface as malfunction indicators, maintenance prediction, door monitoring, fuel level etc. | |
| Detailed Position Messages | Current/historical location of a vehicle with a LINK device | |
| Ignition Changes | If and when ignition is switched on and off | |
| Momentary Odometer and Fuel Level | The current odometer and fuel levels | |
| Tracks | Sequence of coherent positions | |
| Tracking Device Monitoring | Vehicle movements with ignition off (towing, theft), power disconnection, shielding of tracking device | |
| Trouble Codes | Malfunction indicators taken from FMS bus of heavy goods vehicles or OBD | |
| Other Observed Vehicle Data | Other sensor data including driving time, time of day, vehicle and engine speed, engine load and temperature, trailer data, battery voltage, accident data protocols for 45 seconds before and 15 seconds after an accident, vehicle connected devices, sensors, and service-related diagnostic data | |
| Trips and Trip Position Data including time stamp | Registration of trip start and trip end location and time only – no detailed route | Current calendar year + 2 full calendar years |
| Trip Fuel and Energy Consumption | Fuel and/or energy consumption during a trip | |
| Trip Odometer | Distance driven during a trip |
Aggregated Data
Data derived by applying statistical analysis as part of the WEBFLEET Service
| Data Category | Description | Retention Period |
|---|---|---|
| Asset Statistics | Coupling events, activities and maintenance for assets | Current calendar year + 2 full calendar years |
| Driver Statistics | Driver behavior aggregated over time | |
| Driving Events | Driving behavior above pre-defined thresholds of normal driving | 90 days (France: 60 days) |
| Driving KPIs and OptiDrive Scores | Aggregated driving behavior indicators (speeding, driving events, idling, fuel, constant speed, coasting, green speed, gear shift) and resulting OptiDrive scores | Current calendar year + 2 full calendar years |
| Reports | Configurable reports with the ability to combine all data mentioned above, which needs to be set up by the account administrator | Between 30 days and 36 months depending on Client's chosen setup |
| Speed and Speeding Events | Current speed compared with local speed limit from map data | 90 days |
| Vehicle Statistics | Driving events, carbon footprint data, engine hours etc. aggregated over time | Current calendar year + 2 full calendar years |
| Work Time Statistics | Driver/co-driver check in/out |
Product- and Service-Specific Processing
The tables below describe product- and service-specific data processing specifications. To the extent that Client does not use (a portion of) the following products or services, the corresponding data processing specifications will not apply.
Cold Chain
Webfleet Cold Chain gives you complete visibility of your refrigerated fleet for worry-free cold chain logistics. With real-time temperature monitoring and control, this adaptable solution helps you both protect temperature sensitive products and achieve cold chain compliance. Learn more about Cold Chain here.
| Data Category | Description | Retention Period |
|---|---|---|
| Temperature | Temperature value in Celsius degrees coming from temperature sensor (up to 6 sensors) | 1 year |
| Door status | Open / Close state of the doors for refrigerated vehicle/truck/trailer (up to 3 doors) | |
| Reefer unit status | On / Off state of the reefer unit | |
| Operational mode | Current mode of the refrigeration machine (continuous or start/stop) | |
| Fuel level | Remaining fuel for the diesel engine | |
| Operating hours total | Total running hours of the reefer unit | |
| Operating diesel hours total | Total running hours of the diesel engine of the reefer unit | |
| Operating electric hours total | Total running hours of the electric engine of the reefer unit | |
| Power mode | It tells if reefer unit is using diesel or electric engine when running | |
| Zone: Set Point | Temperature set in the reefer unit for a certain zone (up to 3 zones) | |
| Zone: Supply Air | The temperature of the air leaving the refrigeration unit for a certain zone (up to 3 zones) | |
| Zone: Return Air | The temperature of the air returning to the reefer unit for a certain zone (up to 3 zones) | |
| Zone: Operational mode | Current state of the refrigeration machine (cooling, heating or defrosting) for a certain zone (up to 3 zones) |
EV Charger Monitoring & Optimization
Gain comprehensive insights into your EV charging routine by connecting your private chargers to the Webfleet EV monitoring system. Effortlessly monitor your chargers across multiple sites without the need for additional hardware. Stay on top of charging costs and occupancy to improve operational reliability. Chargers must comply with OCPP 1.6 and be connected to the internet. Learn more about EV Charger Monitoring & Optimization here.
| Data Category | Description | Retention Period |
|---|---|---|
| Charger data | Charger identifier, Maximum power, Connector type, Charger status, Number of sockets | Throughout the Agreement, then during the remainder of the current calendar year + 2 full calendar years Charger and charge session data are automatically deleted when the relevant third party from which that data originated either removes the charger or deletes the data themselves. |
| Charge session data | Charger identifier + socket number, Start/end time, Current charging power, Energy charged, Cost, Expected remaining charging time, Charge session authorization token | |
| Vehicle data | Vehicle connection status, Expected time until fully charged, Vehicle identifier / name, Battery level |
Fleet Advisor
Webfleet Fleet Advisor is an advanced AI fleet management feature designed to help fleet managers make data-driven decisions with ease and precision. Learn more about Fleet Advisor here.
| Data Category | Description | Retention Period |
|---|---|---|
| User prompts, responses given, and conversation history | Requests sent by the Webfleet user to generate insights based on existing data from Client's Webfleet environment, responses provided by Fleet Advisor in response to user prompts and the resulting conversation history | 90 days per interaction (each single prompt + response context) |
Fleet Insights
Webfleet Fleet Insights helps fleet managers transform complex fleet data into practical action. Fleet benchmarks, trends, and a recommendations dashboard allows for faster, actionable understanding of fleet performance. By unifying key aggregated metrics from your fleet, benchmarking against similar fleets, surfacing trends, and with seamless link to Fleet Advisor for tailored recommendations and deeper analysis, you get to make faster, more confident decisions that reduce costs, improve efficiency, and elevate safety and operational performance. Learn more about Fleet Insights here.
| Data Category | Description | Retention Period |
|---|---|---|
| Aggregated sustainability, safety, and productivity data from Client's fleet | Includes fuel consumption, wasted fuel while idling, driving events, video events, vehicle mileage, trailer mileage, vehicle utilization, and trailer utilization. This feature uses fleet-level, non-personal aggregated data to show trends and enable unidentified peer benchmarking. Identifiers are removed, transformed or aggregated so data is no longer attributable to an individual. This enables Client to act on what matters most to improve performance with a holistic dashboard, KPI benchmarking, and interplay with Webfleet Fleet Advisor for recommendations and deep-dive follow-up actions. | Granular input data (e.g., from each fleet data point) follows the retention period applicable to its usual feature-based processing under this DPA Aggregated data generated for the purposes of Fleet Insights remain available in Client's environment for up to 15 months and are then replaced with newer indicators |
In-App Translation Service
In-App Translations enables authorized users to request translations of text messages and order descriptions exchanged through Webfleet, Webfleet Mobile, and the Work App. When a user selects the translation function, the relevant text and requested target language are processed using an AI-powered translation service, and the translated text is returned for display alongside the original content. Translations may be temporarily cached within the Client's account to improve performance and avoid repeated translation of identical content.
| Data Category | Description | Retention Period |
|---|---|---|
| Translation inputs and outputs | Text messages and free-text order descriptions submitted for translation within the Webfleet Service, together with the requested target language and the resulting translated text. Content may contain personal data entered by users in free-text fields. Translated content is cached separately for each Client account to improve performance and avoid repeated translations. | Cached translations: up to 90 days, after which they are automatically removed. The cache may also be cleared earlier upon request. Original text messages and order data remain subject to the retention periods otherwise applicable under this DPA. |
Tachograph Manager
Webfleet Tachograph Manager is the reliable all-in-one software solution for downloading, analyzing and archiving tachograph data for your HGVs and LCVs. Learn more about Tachograph Manager here.
| Data Category | Description | Retention Period |
|---|---|---|
| Driver card data | Tachograph records from the driver, including driver unique identification, trip start/end events and timestamps | 37 months (Data from vehicles with a terminated contract are retained only for 90 days post-contract termination) |
| Tachograph mass storage data | Tachograph records from the vehicle, including driver unique identification, trip start/end events and timestamps |
TachoShare
Webfleet TachoShare is a Remote Download Module that downloads tachograph data from vehicles on the road and offers connectivity to 3rd party analysis software. You get complete control of how you use your data and who you share it with, from a secure, accessible archive. Learn more about TachoShare here.
| Data Category | Description | Retention Period |
|---|---|---|
| Driver card data | Tachograph records from the driver, including driver unique identification, trip start/end events and timestamps | 37 months |
| Tachograph mass storage data | Tachograph records from the vehicle, including driver unique identification, trip start/end events and timestamps |
Tire Pressure Monitoring
Webfleet Tire Pressure Monitoring System (TPMS) checks your tire pressure and temperature in real-time. With predictive tire management, problems are detected before they lead to costly repairs or downtime. Whether you are transporting passengers or cargo – TPMS helps you ensure you get to your destination safely and on time. Learn more about TPMS here.
| Data Category | Description | Retention Period |
|---|---|---|
| Tire pressure current readings | Signals from tire pressure sensors' last reading: pressure, temperature, TPMS sensor battery level (valve mounted sensor) | Undefined (data follows object lifecycle) |
| Tire pressure historical readings | Signals from tire pressure sensors' readings: pressure, temperature | 90 days |
| Tire-related configuration | Vehicle/asset chassis layout, recommended axle pressure | Undefined (data follows object lifecycle) |
Webfleet Video
Combined with Webfleet Video, fleet cameras provide comprehensive insights into road incidents and driving events. AI technology detects risky driving behavior like mobile phone use and tailgating, then notifies drivers so they can immediately adjust their driving style. Learn more about Webfleet Video here.
CAM 50 (Legacy Solution)
| Data Category | Description | Retention Period |
|---|---|---|
| Raw video footage | Road-facing video footage: cannot be disabled. Driver-facing video footage: can be disabled via the Webfleet UI. Lens cover accessories available for users to avoid driver-facing video recordings. Raw footage is only processed outside the camera device itself when either the fleet manager toggles | Server storage: 90 days (France: 60 days) On-device storage: Data retention on SD card storage configurable on the Webfleet UI from 4 minutes to unlimited. |
| Video events | Video footage based on event triggers is transferred to the Webfleet backend and then made available in Webfleet UI. All event triggers can be enabled/disabled per camera or vehicle. Event triggers are automatically flagged using computer vision algorithms, G-sensors and accelerometers. Events include:
Videos are only uploaded to Webfleet if one of the events listed above is triggered, with footage of specific durations of 10 to 20 seconds by default. | |
| Activity log | System- and user-generated audit trail that logs event usage and camera lifecycle per camera, allowing authorized users to keep track of how event-related data is used within Webfleet as well as to keep track of relevant camera-related activities. Activity info contains:
Activity types – Event log:
Activity types – Camera log:
| Event log: 90 days* (France: 60 days*) *The log entries for a specific event is deleted when the corresponding event is deleted by an authorized user and gets replaced by an Event deletedentry Camera log: Undefined (data follows device lifecycle) |
CAM Lite & Pro
| Data Category | Description | Retention Period |
|---|---|---|
| Raw video footage | Recording to local microSD card of road-facing lens and any connected outward-, cargo-facing or other in-cabin auxiliary camera: always enabled during trip and, by default, continuously recording for 10 mins after trip end/ignition off. This can be managed in the Webfleet UI. Fleet managers can also Recording to local microSD card of driver-facing lens: Disabled by default. Can be enabled/disabled via the Webfleet UI, the Installer App, or with lens covering accessory. 3 Minute video blocks stored on encrypted video files in the microSD cards. Authorized Client users can decrypt the video files in the Webfleet UI. Raw footage is only processed outside the camera device itself when either the fleet manager toggles | Encrypted footage is retained in the microSD card until it is overwritten. The standard microSD card stores 128 GB, which corresponds to ~100 hours recording with default resolution and without auxiliary cameras. Oldest content is overwritten when saving new footage in 3-minute segments. MicroSD card can be upgraded to maximum 1 TB in CAM Lite and maximum 2*1 TB in CAM Pro. |
| Video events | Video footage based on event triggers is transferred to the Webfleet backend and then made available in Webfleet UI. All event triggers can be enabled/disabled per camera or vehicle and the creation of events and in-cabin driver alerts can be enabled/disabled separately—all using the Webfleet UI. Event triggers are automatically flagged using computer vision algorithms, G-sensors and accelerometers. Events include:
Videos are only uploaded to Webfleet if one of the events listed above is triggered, with footage of specific durations of 10 to 30 seconds by default depending on event type (extendable on request). | Event footage and events transmitted to backend: 90 days (France: 60 days) |
| Activity log | System- and user-generated audit trail that logs event usage and camera lifecycle per camera, allowing authorized users to keep track of how event-related data is used within Webfleet as well as to keep track of relevant camera-related activities. Activity info contains:
Activity types – Event log:
Activity types – Camera log:
| Event log: 90 days* (France: 60 days*) *The log entries for a specific event is deleted when the corresponding event is deleted by an authorized user and gets replaced by an Event deletedentry Camera log: Undefined (data follows device lifecycle) |
| Enhanced Road Safety (CAM Pro Only) | The enablement of the Enhanced Road Safety feature allows CAM Pro to detect critical situations – such as speed sign violations, red-light violations, difficult road or weather conditions, and truck size or weight restrictions. Based on this, drivers may receive in-cabin alerts, and customers may receive related events and metadata in the Webfleet platform. The data processed for this feature includes:
The Enhanced Road Safety feature uses an AI model, running on the CAM Pro camera itself, to analyze footage and related data to generate event metadata, risk classifications, scores, ratings, and alerts to drivers, and transmit the data to the Webfleet backends. The feature may also involve AI model improvement, either using anonymized data or non-anonymized data where the customer has opted in. | Event footage and events transmitted to backend: 90 days (France: 60 days) |
Working Times & Remaining Driving Time
Webfleet delivers accurate, up-to-date remaining driving times, helping you and your drivers to stay compliant with regulations. Precise data on how many hours your drivers have left each day also enables your dispatchers to plan more effectively and efficiently. Learn more about Remaining Driving Time here.
| Data Category | Description | Retention Period |
|---|---|---|
| Work State | The different work and break states reported by the driver collected from tachograph (driving, other work, availability and break), PRO devices, and the Work App (work and break states) | 37 months |
| Driving and Working Time Violation Event Notifications | Notifications displayed in the Webfleet Telematics Service Platform user interface flagging driver violation events based on driving time and working time calculated from work states reported by driver in the tachograph. | 90 days |
About Webfleet's Mobile Apps
The Webfleet mobile apps help fleet managers run their fleets on the go and effectively communicate with their mobile workforce. Driver-oriented apps also help streamline workflows wherever drivers are. Learn more about Webfleet's Mobile Apps here. Most data points listed below reflect the same data that is processed in the context of the WEBFLEET Service as a whole. Unless expressly stated otherwise, the retention time for such data points will follow the data lifecycle defined for the WEBFLEET Service in general, as per the tables above. Webfleet's mobile apps data processing activities are also subject to Webfleet's privacy notice.
Mobile App: Logbook App
| Data Category | Description | Retention Period |
|---|---|---|
| Driver Name | Name that the fleet manager enters in the Webfleet UI at driver creation | Undefined (data follows object lifecycle) |
| Driver Email | Email address that the fleet manager enters in the Webfleet UI at driver creation and which may be used to login | |
| Driver Phone Number | Phone number that the fleet manager enters in the Webfleet UI at driver creation and which may be used to login | |
| Driver Trip Mode (Change) in Logbook | Privacy management change events to drive in private/commute or business modes | Current calendar year + 2 full calendar years |
| Driver/Vehicle Association | The vehicle that has been assigned or selected by the driver in the Logbook App | Undefined (data follows object lifecycle) |
| Driver OptiDrive Score, Ranking and Trip Data | Driving behavior data (OptiDrive), calculated by the LINK device in the vehicle and only visualized in the Logbook App: OptiDrive Score, trips with their unique scores and ranking within the company drivers (all set up by the fleet manager in the Webfleet UI) | Current calendar year + 2 full calendar years In the app for 14 days |
| Vehicle Location | Location of the vehicle where the LINK device is installed or in case of mobile tracking unit, the location of mobile device that is associated to a vehicle in Webfleet | 90 days (France: 60 days) |
| Vehicle Tracks | Sequence of coherent positions | |
| Vehicle Trips | All trips made by a registered driver with the vehicle | Current calendar year + 2 full calendar years |
| Vehicle Name/Number | Name/number of the vehicle that has been added in the Webfleet UI by the fleet manager | Undefined (data follows object lifecycle) |
| Vehicle License Plate | The license plate entered by the fleet manager in the Webfleet UI | |
| Vehicle Specification | Vehicle data added automatically or manually by the fleet manager in the Webfleet UI | |
| Vehicle Odometer | Odometer of the assigned vehicle, either coming from the CAN or added manually by the driver | |
| Vehicle Push Notifications | Push notifications sent about vehicle assignment | Not persisted |
| Logbook Reports | PDF or Excel sheets that can be created in the Logbook App | Current calendar year + 2 full calendar years |
Mobile App: TPMS Tools App
| Data Category | Description | Retention Period |
|---|---|---|
| Tire pressure current readings | Signals from tire pressure sensors' last reading: pressure, temperature, TPMS sensor battery level (valve mounted sensor) | Undefined (data follows object lifecycle) |
| Tire pressure historical readings | Signals from tire pressure sensors' readings: pressure, temperature | 90 days |
| Tire-related configuration | Vehicle/asset chassis layout, recommended axle pressure | Undefined (data follows object lifecycle) |
Mobile App: Vehicle Check App
| Data Category | Description | Retention Period |
|---|---|---|
| Driver Login Credentials | Driver email and password | 24 months (France: 2 months) |
| VIN (Vehicle Identification Number) | Used as vehicle identification number | |
| License Plate | Used as vehicle identification number | |
| Driver Name | User includes driver name in Driver Module & assign him/her to a vehicle and to the Vehicle Check App feature | |
| Vehicle Inspection Filled Checklist | Drivers perform vehicle inspections and marks components with defects and what type of defects they have | |
| Vehicle Defects | Vehicle damages marked by drivers while doing inspection of a vehicle | |
| Pictures of Defect | Pictures of damages reported by driver | |
| Driver Notes (related to defect) | Notes reported while performing the inspection | |
| Checklist Timestamps & Duration | Checklist performance date and time, duration |
Mobile App: Webfleet Mobile App
| Data Category | Description | Retention Period |
|---|---|---|
| Addresses | Geolocation data, shipping addresses, way points and EV charging station locations | 90 days (France: 60 days) |
| Areas | Geo-zone definitions to determine areas of wanted or unwanted vehicle position | |
| Driver Data | Driver name, address, and contact data as phone, email, identification numbers | |
| Orders and Order States | Job data for drivers, order destinations, attachments, electronic proof of delivery, and order status | |
| Text Messages | Messages exchanged between fleet manager and driver through driver terminals | |
| User-Managed Vehicle Data | Individual vehicle specifications, additional telematics data (manually) including registration, VIN or license plate, and additional data made accessible by Client | |
| Fleet Manager Notifications | Fleet managers can receive notifications of certain driving events (e.g., harsh braking, cornering, racing) and other vehicle data (e.g., on-board diagnostic data, malfunction, trouble codes, fuel level, movements with ignition off, power disconnection etc.) in the app—all manageable in the app | 90 days |
| Detailed Position Messages | Current/historical location of a vehicle with a LINK device | 90 days (France: 60 days) |
| Ignition Changes | If and when ignition is switched on and off | |
| Momentary Odometer and Fuel Level | The current odometer and fuel levels | |
| Trips and Trip Position Data including time stamp | Registration of trip start and trip end location and time only – no detailed route | Current calendar year + 2 full calendar years |
| Trip Fuel and Energy Consumption | Fuel and/or energy consumption during a trip | |
| Trip Odometer | Distance driven during a trip | |
| VIN (Vehicle Identification Number) | 17-character unique identifier for a vehicle which displays the car's unique features, specifications and manufacturer which can be used to track recalls, registrations, warranty claims, thefts and insurance coverage as well as map a vehicle to a particular owner or data subject | |
| Webfleet Video Data | All (live) data from Webfleet Video as available to fleet manager | 90 days (France: 60 days) |
| Driving KPIs and OptiDrive Scores | Aggregated driving behavior indicators (speeding, driving events, idling, fuel, constant speed, coasting, green speed, gear shift) and resulting OptiDrive scores | Current calendar year + 2 full calendar years |
| Work Time Statistics | Driver/co-driver check in/out |
Mobile App: Work App
| Data Category | Description | Retention Period |
|---|---|---|
| Driver Name | Name that the fleet manager enters in the Webfleet UI at driver creation | Undefined (data follows object lifecycle) |
| Driver Email | Email address that the fleet manager enters in the Webfleet UI at driver creation and which may be used to login | |
| Driver Phone Number | Phone number that the fleet manager enters in the Webfleet UI at driver creation and which may be used to login | |
| Working Times | Manually started/paused/ended registration of working times. Automatic working times registration when used with driver card + tachograph | Current calendar year + 2 full calendar years |
| Remaining Driving Times | For drivers with tachograph and driver card, the legally allowed remaining driving time is shown in the Work App | 37 months |
| Driver/Vehicle Association | The vehicle that has been assigned to the driver using the Work App | Undefined (data follows object lifecycle) |
| Driver License Details | Includes name, category, valid from/to — only available if feature is activated | |
| Driver OptiDrive Score, Ranking and Trip Data | Driving behavior data (OptiDrive), calculated by the LINK device in the vehicle and only visualized in the Work App: OptiDrive Score, trips with their unique scores and ranking within the company drivers (all set up by the fleet manager in the Webfleet UI) | Current calendar year + 2 full calendar years In the app for 14 days |
| E-Learning Records | Title of the relevant e-learning content, assignment date, due date, start date and completion date — only available if feature is activated | Undefined (data follows object lifecycle) |
| Vehicle Location | Location of the vehicle where the LINK device is installed or in case of mobile tracking unit, the location of mobile device that is associated to a vehicle in Webfleet | 90 days (France: 60 days) |
| Vehicle Tracks | Sequence of coherent positions | |
| Vehicle Trips | All trips made by a registered driver with the vehicle | Current calendar year + 2 full calendar years |
| Vehicle Routing, Destination & ETA | Routes, destinations and estimated time of arrival (ETA) to the destination, as used for navigation | Undefined (data follows object lifecycle) |
| Vehicle Name/Number | Name/number of the vehicle that has been added in the Webfleet UI by the fleet manager | |
| Vehicle License Plate | The license plate entered by the fleet manager in the Webfleet UI | |
| Vehicle Specification | Vehicle data added automatically or manually by the fleet manager in the Webfleet UI | |
| Text Messages | Short text messages sent between the driver/vehicle and the fleet manager (within Work App and Webfleet) | 90 days (France: 60 days) |
| Orders and Order Updates | Order created by the fleet manager in Webfleet or via WF.connect API, including customer name, address, contact person info (name, phone number), any free text order text/description, signature (ePOD) of the customer, order status data, every kind of update relating to orders (order-related status messages) | |
| Order Attachments | PDF files and pictures attached by the driver in the Work App or by the fleet manager in the Webfleet UI | Undefined (data follows object lifecycle) |
| ePOD Signatures | Signature of the customer | |
| Driver Trip Mode (Change) in Logbook | Privacy management change events to drive in private/commute or business modes | Current calendar year + 2 full calendar years |
| Cold Chain Data | Temperature data, violation information – only available if feature is activated | 1 year |
| Driving Behavior Feedback (Active Driver Feedback) | Instant, in-cab, real-time feedback for drivers, shown in the Work App about driving behavior, including events of harsh breaking, cornering, and racing starts. | 90 days (France: 60 days) |
| Driver Smart Notifications | Smart rules can be set up by the fleet manager in the Webfleet UI and many vehicle notifications can be sent to the driver. Driver will see push notifications and the history of notifications in the Work App | 90 days In the app for 14 days |
| Vehicle Odometer | Odometer of the assigned vehicle, either coming from the CAN or added manually by the driver | Undefined (data follows object lifecycle) |
| Generic Push Notifications | Push notifications sent to driver about new incoming text messages, new orders, order updates, new e-learning assigned, etc. | 90 days |
Appendix 2
Sub-Processors
Webfleet Solutions has engaged the following entities to process Client Data to deliver core features of the Webfleet Telematics Service Platform and the WEBFLEET Service more broadly:
| Company | Scope of Processing | Principal Location(s) of Processing | Contact |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Secure data hosting services for all Client Data processed as part of Webfleet Solutions' offerings. Also includes data processing for inference in AI features offered by Webfleet when they are actively enabled by the Client: Webfleet Fleet Advisor, In-App Translation Service. | EEA – Luxembourg, Germany, France | aws.amazon.com/contact-us |
| Microsoft Ireland Operations Limited | EEA – North Europe | microsoft.com/en-us/privacy/privacy-support-requests | |
| TomTom International B.V. | Provision of services relating to traffic, security cameras, local search, road condition services, weather information and fuel pricing. | EEA – The Netherlands | tomtom.com |
| Webfleet Solutions Development Germany GmbH | Webfleet Solutions's technology hub which includes Information Technology and Secure Software Development. | EEA – Germany | Same as Webfleet Solutions: digitaltrust@bridgestone.com |
Product- and Service-Specific Sub-Processors
Webfleet Solutions has engaged the following entities to process Client Data to deliver specific features of the Webfleet Telematics Service Platform, as individually highlighted below. To the extent that Client does not use certain features listed below, the Sub-Processor involvement that apply only to those unused features will not apply to Client:
| Company | Scope of Processing/Service | Principal Location(s) of Processing | Contact |
|---|---|---|---|
| BIA Power Grid, S.L. | Provision of data and services regarding EV charging stations as part of the provision of the EV Charger Monitoring services provided by Webfleet Solutions. This enables the sending of commands to the charger to manage charge sessions and the receipt of charger and charge session data for processing in the Webfleet Telematics Service Platform. | EEA – Spain | biapower.io |
| Bridgestone Europe NV/SA | Provision of tire pressure monitoring events and related data (Tirematics) in the context of Webfleet Solutions's tire pressure monitoring service (TPMS). | EEA – Belgium, Ireland | bridgestone.com |
| DAKO Systemtechnik und Service GmbH & Co. KG | Provision of services related to the operation of the WEBFLEET Tachograph Manager. | EEA – Germany | dako.de |
| Google Ireland Limited | Provision of push notifications (Firebase Messaging) in the Webfleet mobile applications. | EEA, Google Cloud Platform Locations | cloud.google.com/contact |
| Jibe Mobility B.V. | Provision of EV charger-related data and services in the context of the EV Charger Monitoring services provided by Webfleet Solutions. This enables the receipt of charger and charge session data for processing in the Webfleet Telematics Service Platform, as well as to other charger management systems that the Client uses. | EEA – The Netherlands, Romania | jibe.company |
| LeMobi Leszek Chwalinski | Provision of e-toll collection and management services in Poland and Hungary. | EEA – Poland, Hungary | lemobi.pl |
| Lytx, Inc. | Provision of data processing services and customer support associated with the operation of CAM 50 Webfleet Video solutions. | EEA – Luxembourg United Kingdom *, Israel * | lytx.com |
| Longship IT Solutions B.V. | Provision of data and services regarding EV charging stations as part of the provision of the EV Charger Monitoring services provided by Webfleet Solutions. This enables the sending of commands to the charger to manage charge sessions and the receipt of charger and charge session data for processing in the Webfleet Telematics Service Platform. | EEA – The Netherlands | evesto.com |
| MiTAC Digital Technology Corporation | Strictly in the operation of the CAM Lite & CAM Pro Webfleet Video solutions and exclusively upon explicit request of Webfleet Solutions: providing troubleshooting and technical support services for system deployments, configurations, updates, corrections and improvements. | Taiwan ** | mitacmdt.com/en |
| Peregrine Technologies GmbH | Strictly in the operation of the Enhanced Road Safetyfeature exclusive to the CAM Pro Webfleet Video solution aimed at detecting critical situations, such as speed sign violations, red-light violations, difficult road or weather conditions, and truck size or weight restrictions. | EEA – Germany | peregrine.ai |
| Verkeersveiligheid Groep Nederland B.V. | Provision of an independent e-learning platform for driver coaching services, including audiovisual content, quizzes, course completion tracking, and quiz performance scoring. | EEA – The Netherlands | verkeersveiligheidgroep.nl |
* Data processing outside the European Economic Area carried out based on Article 45 GDPR.
** Data processing outside the European Economic Area carried out based on Article 46(2)(c) GDPR.
Appendix 3
OEM & Third-Party Integrations Data Processing Terms
1. Applicability & Precedence. This Appendix governs Client-initiated processing of Client Data in connection with third parties other than the Sub-Processors listed in Appendix 2. Third parties may include OEMs and independent providers offering integrations with the WEBFLEET Service (each a Third-Party Integration Provider
and, together with OEMs, Integration Providers
). For clarity, this Appendix 3 does not apply to Vehicles from OEM brands listed in Section 3 that have not been linked to the WEBFLEET Service via the applicable OEM Platform under the OEM Schedule. If there is a conflict between this Appendix 3 and the DPA, this Appendix 3 prevails with respect to the processing of Client Data in Client-initiated integrations to the extent of any inconsistency.
2. On-Demand Third-Party Data Processing Enablement. By enabling a connection between the WEBFLEET Service and an Integration Provider, Client issues documented instructions to Webfleet Solutions to send, receive, and otherwise process Client Data to/from that Integration Provider as needed for interoperability with the WEBFLEET Service:
- OEM Onboard Units. If Client uses OEM Onboard Unit interfaces, Webfleet Solutions' enablement thereof in the WEBFLEET Service is (1) subject to the OEM Schedule and (2) contingent on per-Vehicle authentication and consent via Webfleet Solutions' secure methods and/or the OEM Platform following each OEM's requirements.
- Third-Party Integration Providers. If Client links services from Third-Party Integration Providers to the WEBFLEET Service, Webfleet Solutions' enablement thereof occurs upon (1) Client's request (via the WEBFLEET Service user interface or Webfleet Solutions' support channels) and (2) the ensuing linkage of Client's WEBFLEET Service environment to the provider using credentials securely managed by Webfleet Solutions.
3. OEM Integrations. Depending on the OEM integration(s) selected by Client, Client acknowledges and agrees that Client Data will be further processed by the following OEMs, as the case may be:
| Legal Entity | Relevant Vehicle Brand Group | Principal Location of Processing | OEM Specifications & Contact |
|---|---|---|---|
| Bayerische Motoren Werke AG | BMW Group | Germany | bmw.com |
| Ford Smart Mobility U.K. Limited | Ford Group | England * | ford.com |
| Mercedes-Benz Connectivity Services GmbH | Mercedes-Benz Group | Germany | mercedes-benz.com |
| Mobilisights S.p.A. | Stellantis Group | Italy | mobilisights.com |
| Renault S.A.S. | Renault Group | France | renaultgroup.com |
| TB Digital Services GmbH | Traton Group | Germany | company.rio.cloud |
| Volkswagen Group Info Services AG | Volkswagen Group | Germany | drivesomethinggreater.com |
* Data processing outside the European Economic Area carried out based on Article 45 GDPR.
4. Processing of Client Data by Integration Providers. Webfleet Solutions does not control and is not responsible for Integration Providers' services, including their security, availability, or compliance. Furthermore, given the limited scope of Client Data processed per selected integration, Client acknowledges and agrees that each Integration Provider will independently:
- Technical Specifications. Define, maintain, and update the technical methods/specifications for data made available to Webfleet Solutions for further processing within the WEBFLEET Service. All such data is provided
as is
/as available
without any representation or warranty by Webfleet Solutions to Client regarding accuracy or quality; - Purposes and Means. Determine the purposes and means of processing for data generated, collected, or otherwise processed under the services each Integration Provider provides to Client, including any further (sub-)processing on its behalf;
- Security. Implement and maintain its own technical and organizational measures to protect Client Data, ensure lawful processing, and conduct its own security audits/assessments of data processing environments;
- Security Incidents. Receive notifications from Webfleet Solutions of (suspected) personal data breaches, including and related follow-up communications aimed at protecting Client Data and complying with applicable law;
- External Access Requests. Receive notifications from Webfleet Solutions of binding requests for access to Client Data by governmental (law-enforcement) authorities or comparable requests, to the extent permitted by law;
- Cooperation. Remain responsible for cooperation requested by Client relating to security of processing, access to data, data subject requests, DPIAs, audits, breaches, and prior consultation with Supervisory Authorities insofar as those requests concern processing by the Integration Provider. Requests for audits or assessments of an Integration Provider's environment must be pursued by Client under Client's agreement with that Integration Provider; Webfleet Solutions will reasonably coordinate to the extent such requests involve the WEBFLEET Service, in line with the provisions of the DPA;
- Service Changes and Availability. Subject to the terms of the agreements referred to in Items 5 and 6 below, suspend, terminate, or change their services. Disruptions in an Integration Provider's services may result in irretrievable loss of Client Data expected from that provider, without liability of Webfleet Solutions. Webfleet Solutions' service levels, availability, support, and data-freshness commitments under the Agreement exclude data feeds, functionality, latency, or outages attributable to Integration Providers outside of Webfleet Solutions' control.
5. Client's Independent Agreements. Client's use of Integration Providers with the WEBFLEET Service depends on Client's lawful use of the relevant Vehicles, Onboard Units, and services those providers supply to Client. Client's separate agreements with each Integration Provider (including the OEM Platform terms) solely govern that relationship. Client is exclusively responsible for complying with those terms, including in its use of the WEBFLEET Service. Client may consult (1) its own contracts and the websites listed in Item 3 (for OEMs) and (2) its contracts and websites of each Third-Party Integration Provider to understand features, behavior, settings, specifications, requirements, and limitations applicable to the offerings of each Integration Provider.
6. Webfleet Solutions' Independent Agreements. Webfleet Solutions maintains OEM Agreements with the OEMs listed in Item 3 and separate agreements with Third-Party Integration Providers. Shared processing of Client Data between Webfleet Solutions and any Integration Provider at Client's direction is subject to the continued effectiveness of these agreements. If any such agreement terminates, affected WEBFLEET Service features or data-processing capabilities will be adjusted accordingly. Where an OEM Agreement involves an OEM processing personal data in Client Data in the capacity of a Sub-Processor, then Section 3 of the DPA applies to Webfleet Solutions' engagement of that OEM.
Appendix 4
Technical & Organizational Measures
Webfleet Solutions maintains an ISO/IEC 27001 certification (available on request) which covers Webfleet Solutions' scope of processing of Client Data detailed in the DPA and includes the below technical and organizational measures to ensure the security of Client Data:
Technical & Organizational Measures | Confidentiality of Client Data
| Domain | Description of Measures and their Purposes |
|---|---|
| Access Control Buildings, Offices, Data Centers |
Purpose: Prevent unauthorized access to data processing systems where Client Data is processed. |
| Access Control Systems |
Purpose: Prevent unauthorized use of systems where Client Data is processed. |
| Access Control Client Data |
Purposes:(1) Ensure that authorized users of a system where Client Data is processed may only access the Client Data for which they are authorized, and (2) prevent Client Data from being read while the data is in use, in motion, or at rest without authorization. |
| Segregated Processing |
Purpose: Ensure that Client Data collected for different purposes can be processed separately. |
Technical & Organizational Measures | Integrity of Client Data
| Domain | Description of Measures and their Purposes |
|---|---|
| Transfer Control |
Purpose: Ensure that Client Data cannot be read, copied, or modified during electronic transmission or during transportation or storage to disk. Additionally, to control and determine to which bodies the transfer of Client Data provided by data communication equipment is allowed. |
| Input Control |
Purpose: Control and monitor if and by whom Client Data has been entered, changed, or removed on data processing systems. |
Technical & Organizational Measures | Availability of Client Data & Resilience
| Domain | Description of Measures and their Purposes |
|---|---|
| Availability Control |
Purpose: Ensure that Client Data is protected against accidental destruction or loss. |
Technical & Organizational Measures | Organizational Management
| Domain | Description of Measures and their Purposes |
|---|---|
| Organizational Efforts ISMS & DPMS |
Purpose: Ensure that the Webfleet Solutions' workforce is sufficiently informed, educated and engaged on information security, privacy and data protection topics in a way that matches the roles and specific exposure to Client Data of each teammate. |
| Third Party Management Sub-Processors |
Purpose: Ensure that Client Data processed by a Sub-Processor is only processed as instructed by the Client. |
Data Access Specification Sheet
Under development
This Data Access Specification Sheet is currently under development.
The most up-to-date version, once available, can be consulted at webfleet.com/dpa.