TIR40
Back to home

Draft — these documents are being finalised together with the company's registration and have not yet been reviewed by a lawyer. Highlighted parts are placeholders.

Data Processing Agreement

Last updated: 24 September 2026

This Data Processing Agreement ("DPA") is between the company that uses TIR40 (the "Customer", the controller) and Company name SRL (the "Provider", the processor). It forms part of the Terms of Service and applies automatically from the moment the Customer accepts them. It is meant to satisfy Article 28 of Regulation (EU) 2016/679 (GDPR).

1. Scope and roles

The Provider processes personal data on behalf of the Customer only to provide TIR40 (the “Service”). For that data (“Customer Personal Data”) the Customer is the controller and the Provider is the processor. The subject matter, duration, nature and purpose of the processing, and the types of data and data subjects, are set out in Annex 1. The Provider is the controller of its own account and website data, which its Privacy Policy covers.

2. Instructions

The Provider processes Customer Personal Data only on the Customer's documented instructions — which are the Terms, this DPA, and the Customer's use of the Service's features and settings — unless EU or Member State law requires otherwise, in which case the Provider tells the Customer beforehand unless the law forbids it. The Provider tells the Customer if it believes an instruction infringes data-protection law.

3. Confidentiality

The Provider ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality, and that access is limited to what is needed to run and support the Service.

4. Security

The Provider applies appropriate technical and organisational measures under Article 32 GDPR, at least those in Annex 2, and may update them provided the overall level of protection is not reduced.

5. Sub-processors

  • The Customer gives general authorisation to use the sub-processors listed in Annex 3.
  • The Provider will give the Customer at least 30 days' notice (in the app or by email) before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that time; if the parties cannot resolve it, the Customer may terminate the affected Service.
  • The Provider imposes on each sub-processor data-protection obligations no less protective than this DPA and remains responsible for their performance.

6. International transfers

Customer Personal Data is stored in the European Union (Ireland). Where the Provider or a sub-processor transfers it outside the EU/EEA, this happens only under a valid transfer mechanism under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision.

7. Assistance

Taking into account the nature of the processing, the Provider helps the Customer, by appropriate measures (including the export and delete functions in the Service), to respond to requests from data subjects, and to meet its obligations on security, breach notification, data-protection impact assessments and consultation with authorities. If a data subject contacts the Provider directly about Customer Personal Data, the Provider refers them to the Customer.

8. Personal-data breaches

The Provider notifies the Customer without undue delay, and where possible within 48 hours, after becoming aware of a personal-data breach affecting Customer Personal Data, and gives the information it then has: what happened, the likely consequences, the data and people affected, and the measures taken or proposed. The Customer decides whether and how to notify the authority and the people concerned.

9. Return and deletion

While the account is active the Customer can export its data and delete records itself in the Service. When the agreement ends the Provider deletes Customer Personal Data within 30 days, unless EU or Member State law requires it to be kept. Copies in encrypted provider backups are overwritten in the normal backup cycle (up to 7 days). On request the Provider confirms the deletion in writing.

10. Information and audits

The Provider makes available the information needed to show compliance with Article 28 GDPR and allows for audits, including inspections, by the Customer or an auditor the Customer appoints. Audits are announced at least 30 days ahead, happen no more than once a year (unless a breach requires otherwise), run during business hours without disrupting operations or exposing other customers' data, and are done under confidentiality. The Provider may first satisfy the request with documentation, such as its sub-processors' audit reports and certifications.

11. The Customer's responsibilities

  • The Customer is responsible for having a lawful basis for the data it enters, and for giving the required information to data subjects — in particular to drivers, about the position captured when a driver taps “Arrived” or shares their location, and about working-time records.
  • The Customer enters only the data it needs, and does not use the Service to store special categories of data (Article 9 GDPR) or criminal-offence data.
  • The Customer controls who has access to its workspace, and with which role.

12. Liability, precedence and term

Each party's liability under this DPA is subject to the limits in the Terms of Service, without affecting data subjects' rights or any liability that cannot be limited by law. If this DPA and the Terms conflict on data protection, this DPA prevails. It lasts as long as the Provider processes Customer Personal Data, and is governed by the law that governs the Terms.

Annex 1 — Details of the processing

ItemDescription
Subject matterProviding the TIR40 haulage-planning service to the Customer.
DurationFor as long as the Customer has an account, plus the deletion period in section 9.
Nature and purposeHosting, storing, displaying, organising and transmitting the Customer's data so it can plan and dispatch loads, manage its fleet, keep documents, issue invoices and produce reports; reading uploaded order documents and drafting text with AI features when the Customer's users choose to use them.
Data subjectsThe Customer's users and employees (dispatchers, managers, administrators); its drivers; contact persons at the Customer's own customers, consignors and consignees.
Types of personal dataNames, email addresses, phone numbers and roles; drivers' names, phone numbers, licence and document expiry dates, working-time and rest records, per-diem records; positions (latitude/longitude) captured when a driver taps “Arrived” or shares their location — not continuous tracking; vehicle registration plates; the last six digits of fuel cards; and whatever appears in documents the Customer uploads (for example names and signatures on CMR notes and transport orders).
Special categoriesNone intended. The Customer must not enter them (section 11).

Annex 2 — Security measures

  • Separation of tenants: every company's data is isolated from other companies' data by row-level security in the database, and server actions re-check the user's company and role.
  • Access control: sign-in with individual accounts, roles (administrator, manager, dispatcher), and a closed sign-up requiring an access code; passwords are stored only as hashes by the sign-in provider.
  • Driver links: no login, but each link contains a long random code, is limited to one job, and only shows what that job needs.
  • Encryption: connections to the Service and between the Service and its providers are encrypted in transit; the database and file storage are encrypted at rest by the hosting provider.
  • Files: uploaded documents sit in private storage, organised per company, readable only through the signed-in application.
  • Audit trail: changes to loads and other key records are logged with user and time.
  • Availability: provider-managed database backups; EU-region hosting.
  • Personnel and vendors: access limited to what is necessary; sub-processors bound by data-processing agreements.
  • Data minimisation: no analytics or advertising trackers; AI features only receive what a user sends or uploads to them (for example an order document, pasted email text, a CMR photo, or the notes of a load that a driver opens on their link).

Annex 3 — Sub-processors

ProviderWhat it does for TIR40WhereData involved
Supabase (Supabase, Inc.)Database, sign-in (authentication) and file storage — where all TIR40 data lives.EU — Ireland (AWS eu-west-1)All data in the workspace: accounts, fleet, loads, customers, documents and photos.
Vercel (Vercel Inc.)Hosting of the application and its network edge.Application runs in Dublin, Ireland; requests pass through Vercel's edge networkRequests and responses while the app is used, short-lived technical logs (e.g. IP address).
Anthropic (Anthropic PBC)AI features: reading an uploaded transport-order PDF or a pasted order email into a load, reading a photographed signed CMR (is it signed, are there remarks), translating the dispatcher's notes into the driver's language on the driver link, and drafting delay and demurrage emails from the note you type.United StatesOnly what you send to an AI feature: the uploaded document, pasted email text or CMR photo, the dispatcher's notes for a load (to translate them for the driver), or the load details and note for a draft. Anthropic's commercial terms state that data sent through its API is not used to train its models.
Resend (Resend, Inc.)Sending sign-up confirmation and password-reset emails, and error alerts to the operator.United States / EU sending regionsThe recipient's email address and the content of that email.
Google (Google Ireland Ltd / Google LLC)Places search for nearby repair shops and truck parking; Google Fonts for the typefaces on our pages.EU / United StatesFor Places: the search text and a map position (a truck's last position or the map centre) — no name or account. For Fonts: your browser's IP address when a page loads.