OAS

OAS Data Processing Agreement

Version:
v0-beta
Last updated:
21 September 2026
Effective:
22 September 2026
Supplier:
Simon Perryment, sole trader trading as OAS. Legal notices: [email protected].

Contract status: this DPA is intended to be incorporated into the applicable Order Form and OAS Terms when completed and approved. It is not an ordinary user clickwrap document. Customers should obtain legal advice on controller/processor allocation for each processing activity.

1. Purpose and scope

1.1 This Data Processing Agreement (DPA) applies where the Customer makes Personal Data available to OAS for the hosted OAS services. “Customer”, “Personal Data”, “Processing”, “Controller”, “Processor” and “Subprocessor” have the meanings in UK GDPR as amended by applicable UK legislation, including the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

1.2 The Customer is Controller and OAS is Processor for the Customer Data described in Schedule 1, unless the parties expressly document a different role. The DPA does not turn OAS into a controller of the customer’s employment, driver, licensing or safety decisions.

1.3 The Terms, Order Form and this DPA form one agreement. For conflict about Personal Data, this DPA prevails; the Order Form controls service scope and commercial details.

2. Documented instructions and customer duties

2.1 OAS will process Personal Data only on documented instructions in the Terms, Order Form, configured features, customer sharing actions and written support instructions, unless UK law requires otherwise. OAS will inform the Customer of that legal requirement unless law prohibits notice.

2.2 The Customer is responsible for lawful collection, accuracy, fair notices, lawful bases, Article 9 and Article 10/DPA 2018 conditions, data minimisation, retention, responding to individuals and ensuring that every operator represented in a workspace has authorised the processing.

2.3 The Customer must not instruct OAS to use special-category or criminal-offence data for a new purpose without recording the required condition and safeguards.

3. Confidentiality and authorised persons

3.1 OAS will ensure that persons authorised to process Personal Data are bound by confidentiality and receive appropriate security instructions. The Customer must control its Authorised Users, roles and sharing links.

3.2 Each party will protect the other’s confidential information using at least reasonable care and will disclose it only to personnel, professional advisers, suppliers or authorities with a need and lawful basis.

4. Security

4.1 OAS will maintain technical and organisational measures appropriate to the risk of the Processing and will make relevant security information available to the Customer on reasonable request. Nothing in this DPA is a claim of certification or a guarantee that every risk can be eliminated.

4.2 OAS will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer Data, provide reasonably available details, and cooperate with the Customer’s risk assessment and regulatory or individual notifications.

5. Rights requests, assistance and assessments

5.1 Taking into account the nature of the Processing, OAS will provide reasonable assistance with rights requests, security obligations, breach assessments, DPIAs and prior consultation. OAS may charge reasonable costs for manifestly excessive or unusually complex assistance where law permits.

5.2 The Customer remains responsible for deciding whether a request should be granted and for communicating with the individual. OAS will not disclose another customer’s data.

5.3 On reasonable notice, OAS will make available information needed to demonstrate compliance and will support an audit or inspection limited to the Customer Data, subject to confidentiality, security and operational safeguards.

6. Subprocessors

6.1 The Customer gives general written authorisation for the Subprocessors listed in the public register and any subsequently notified Subprocessor used to provide the services. OAS will impose data-protection obligations no less protective than this DPA and remains responsible for the Subprocessor’s performance.

6.2 OAS will give advance notice of a proposed new Subprocessor. The Customer may object on reasonable data-protection grounds within the notice period. The parties will work in good faith on a solution; unresolved material objection may allow termination of the affected service.

7. International transfers

7.1 OAS will not transfer Customer Personal Data outside the UK except under a lawful transfer mechanism and appropriate supplementary measures. The current destination, mechanism and transfer-risk status must be recorded in the Subprocessor and International Transfer Registers before activation.

7.2 The parties will cooperate with required transfer assessments and updates when a legal or regulatory change affects a mechanism.

8. Return and deletion

8.1 On expiry or termination, OAS will provide read-only or support-assisted export for 30 days, unless the Order Form says otherwise. OAS will delete production Customer Data within 90 days after that period, subject to legal holds, documented backup expiry and data that must be retained by law.

8.2 The Customer must export records needed for statutory retention before access ends. OAS may retain minimal evidence needed to establish compliance, resolve disputes or meet legal obligations, with access restricted and deletion reviewed.

Schedule 1 — processing description

Subject matter: hosted transport compliance, fleet, driver, document, signature, tachograph and operator-licensing workflows.

Duration: the Order Form term plus the exit periods above, unless a documented instruction or legal hold requires longer.

Categories of people: customer contacts, transport managers, operators, fleet staff, drivers, applicants, contractors, signatories and support users.

Categories of data: identity and contact information; employment/role and access data; vehicle and licence data; maintenance, inspection, tachograph and infringement records; right-to-work and DVLA evidence; signatures, images, documents, audit and security data. Special-category and criminal-offence data may occur only where the Customer has established the required conditions.

Purposes: the customer’s compliance management, recordkeeping, safety workflow, document sharing, signatures, reporting, alerts, audit and authorised integrations.

Recipients: Customer-authorised users and operators; OAS personnel; listed subprocessors; and partners specifically activated or directed by the Customer with the required role, purpose, notice and safeguards.