Skip to main content

Last updated: 28 July 2026

Data Processing Agreement

Data-processing terms for customer-controlled personal data handled through the early-access Drivefino service.

Early-access notice. Drivefino is currently in an early-access validation stage. Product features and these terms may develop as the service is tested and improved.

About this agreement

Version: Early access 1.0. Effective date: 28 July 2026.

This DPA is intended for early-access customers using Drivefino to process instructor-controlled personal data. It should be read with the Terms, Privacy Policy and Security page.

1. Parties, scope and precedence

This early-access DPA describes Drivefino’s processor obligations to a customer that controls Customer Personal Data. It applies when a customer accepts it as part of using the service. If it conflicts with the Terms on protection of Customer Personal Data, this DPA takes precedence for that subject.

2. Subject matter and duration

Processing of customer-controlled student, related-person, lesson, note and document data to provide Drivefino for the subscription term and the approved return/deletion period.

3. Nature and purpose

Hosting, organising, retrieving, displaying, transmitting, backing up, securing, supporting and deleting Customer Personal Data on documented customer instructions.

4. Data subjects and data categories

Students (including minors), parents/guardians, emergency contacts, instructors and document recipients; identity/contact, licence, booking/location, progress/lesson notes, price/payment status, communications, documents, sharing and technical/audit data. Special-category data is not required and should not be entered unless lawfully necessary.

5. Documented instructions and legal conflicts

Process only on the Terms, this DPA and lawful customer instructions. A final DPA must define how Processor handles unlawful instructions and legally compelled processing.

6. Confidentiality

Authorised personnel must be bound by appropriate confidentiality obligations and receive access only where needed to operate, support or secure the service.

7. Security measures

Use the measures in Annex 2 and notify the Controller before materially reducing them. No measure guarantees absolute security.

8. Service providers

Drivefino may use subprocessors under written data-protection terms and remains responsible as required by applicable data-protection law. Drivefino will provide notice of relevant changes where required by the customer agreement or applicable law.

9. Rights assistance

Taking account of the processing, Drivefino will reasonably assist the customer with verified access, correction, deletion, restriction, objection and portability requests. Students normally submit requests about instructor-managed records to their instructor.

10. Security incidents and breaches

Drivefino will notify the affected customer without undue delay after becoming aware of a breach of Customer Personal Data and provide information reasonably available to support the customer’s obligations. Not every security incident is a reportable personal-data breach.

11. DPIA and regulator assistance

Taking account of the processing and available information, Drivefino will provide reasonable assistance for risk assessments, DPIAs, prior consultations and regulator enquiries.

12. Deletion or return

After the service ends, Drivefino will handle verified return or deletion requests subject to the current export capabilities, applicable law and legitimate retention needs. Data removed from active systems may remain in protected backups until those copies expire through the normal backup cycle.

13. Audits and compliance information

Drivefino will make information reasonably necessary to demonstrate these processor obligations available. Any audit must protect other customers, security and confidential information and be proportionate in timing, scope and frequency.

14. International transfers

Drivefino will not make a transfer restricted by applicable data-protection law without an available legal transfer mechanism and appropriate safeguards.

15. Liability and conflict

The liability provisions in the Terms apply to this DPA, subject to any liability that applicable law does not permit the parties to exclude or limit.

Annex 1 — processing details

Processing occurs as needed throughout the customer’s use of Drivefino. The customer controls the purposes and content of student records; Drivefino hosts and processes them to provide the service. DPA enquiries can be sent to support@drivefino.com.

Annex 2 — technical and organisational measures

Measures include tenant-scoped repositories, Argon2 password hashes, rotating hashed refresh tokens, private object storage, expiring signed file links, TLS termination, signature-verified Stripe webhooks and selected audit events. Drivefino reviews these measures as the early-access service develops.

Annex 3 — service providers and transfers

Drivefino uses external services where needed for document storage, transactional email, subscription billing and consent-based website analytics. International transfers are handled as described above and in the Privacy Policy.