1.Parties and scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service or of any written agreement between Outturn (the "Processor") and the Customer (the "Controller"). It applies whenever the Processor processes personal data contained in Customer Data on the Controller's behalf.
Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given in Regulation (EU) 2016/679 ("GDPR").
2.Details of the processing
| Item | Description |
|---|---|
| Subject matter and duration | Provision of the Outturn Service for the term of the Customer's Subscription or agreement, and until deletion under section "Return and deletion" |
| Nature and purpose | Hosting, storage, import, matching, deterministic checking, display, export and deletion of Customer Data to provide the Service |
| Data subjects | The Controller's Authorised Users; employees and contact persons of the Controller's counterparties (carriers, forwarders, agents, cargo owners); drivers |
| Categories of personal data | Names, work contact details, roles; vehicle registration numbers and driver identifiers in transport records; names and signatures appearing in operational documents; content of e-mails in connected department mailboxes; activity and audit records |
| Special categories | Not intended. The Controller must not upload special categories of data or data on criminal convictions |
3.Processing on documented instructions
The Processor processes personal data only on the Controller's documented instructions, which are given by the Terms, this DPA and the Controller's configuration and use of the Service, unless Union or Member State law requires otherwise; in that case the Processor informs the Controller before processing unless the law prohibits it.
The Processor immediately informs the Controller if, in its opinion, an instruction infringes data protection law.
4.Confidentiality
The Processor ensures that persons authorised to process the personal data are bound by confidentiality. Access by Outturn staff to a Workspace for support requires a time-limited access grant and is recorded in a log visible to the Controller.
5.Security of processing
The Processor implements the technical and organisational measures required by Article 32 GDPR, including:
- EU hosting with Hetzner Online GmbH in Nuremberg, Germany; the server is reachable only through an encrypted Cloudflare tunnel, with HTTPS to the user's browser;
- logical separation of each Workspace, enforced on every request, and role-based access control within a Workspace;
- passwords stored as Argon2id hashes; two-factor authentication available to every user and required for sensitive actions; two-factor secrets stored encrypted;
- session limits (12 hours absolute, 30 minutes idle), protection against cross-site request forgery, sign-in rate limits and account lockout, security headers;
- append-only audit log of significant actions, and approval by a second person for sensitive actions;
- continuous backups encrypted on the client side, with restore tests;
- health monitoring and incident handling, with a public status page.
6.Sub-processors
The Controller gives general authorisation for the Processor to engage the sub-processors listed on the Sub-processors page. The Processor informs the Controller of any intended addition or replacement at least 30 days in advance by e-mail to the Workspace administrator and on that page. The Controller may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the affected Service without penalty.
The Processor imposes on each sub-processor data protection obligations equivalent to those in this DPA and remains responsible to the Controller for their performance (GDPR Art. 28(2) and 28(4)).
7.International transfers
Customer Data is stored in the European Union. Any transfer of personal data to a third country by the Processor or a sub-processor takes place only in compliance with Chapter V GDPR, on the basis of an adequacy decision (including the EU-US Data Privacy Framework for certified recipients) or the European Commission's Standard Contractual Clauses.
8.Assistance to the Controller
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures in responding to data subject requests (GDPR Art. 15–22), including through the Service's export and deletion functions, and forwards to the Controller without undue delay any request it receives directly.
The Processor assists the Controller in ensuring compliance with Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation, by providing the information available to it.
9.Personal data breaches
The Processor notifies the Controller without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notification describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences and the measures taken or proposed. Information may be provided in phases.
10.Return and deletion
The Controller can export all Workspace data at any time as a ZIP archive with a manifest and SHA-256 checksums; the download link is valid for 72 hours.
At the end of the Service, or on the Controller's confirmed deletion request after a 7-day cooling-off period, the Processor deletes Customer Data from the live systems, unless Union or Member State law requires storage. A record that the deletion took place is kept as evidence.
Copies in encrypted backups are deleted when the backup copies expire: daily copies after 30 days and monthly copies after 12 months; yearly copies of stored source files are kept for up to 10 years. Pilot environments use a 30-day backup cycle. Data in backups is not used for any purpose other than restoration.
11.Information and audits
The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, by the Controller or an auditor it mandates. Audits take place on at least 30 days' notice, during business hours, no more than once a year unless a personal data breach or a supervisory authority requires otherwise, and at the Controller's cost.
12.Liability and precedence
The limitation of liability in the Terms or the written agreement applies to this DPA, except where the GDPR provides otherwise. In case of conflict between this DPA and other terms on the protection of personal data, this DPA prevails. This DPA is governed by the laws of Ireland.