Data Processing Agreement
Last updated July 6, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the Carrier (“Customer”, the controller) and [Company Legal Name](“Provider”, the processor) for use of eWall TMS(the “Service”). It applies to the extent Provider processes Personal Data on Customer’s behalf and Data Protection Laws (such as the GDPR or comparable laws) apply.
1. Definitions
“Personal Data”, “processing”, “controller”, “processor”, and “data subject” have the meanings given in applicable Data Protection Laws. “Customer Personal Data” means Personal Data that Provider processes on Customer’s behalf under the agreement.
2. Roles and scope
Customer is the controller and Provider is the processor of Customer Personal Data. Provider will process Customer Personal Data only on Customer’s documented instructions, including as set out in the agreement and this DPA, unless required by law (in which case Provider will inform Customer unless legally prohibited).
3. Details of processing
- Subject matter and duration: processing for the term of the agreement plus any wind-down period.
- Nature and purpose:hosting and operating a transportation management platform on Customer’s behalf — storing, organizing, and making available the data Customer submits.
- Categories of data subjects:Customer’s drivers; Customer’s staff and users; and contacts at Customer’s customers, shippers, receivers, and brokers.
- Categories of Personal Data: identification and contact details; driver qualification and compliance data (CDL, medical card, MVR, drug-test and Clearinghouse dates, date of birth); operational records (loads, stops/addresses, equipment, invoices, settlements); uploaded compliance documents; and, where enabled, vehicle location and telematics data.
4. Provider obligations
- process Customer Personal Data only on Customer’s documented instructions;
- ensure persons authorized to process the data are bound by confidentiality;
- implement appropriate technical and organizational security measures (Section 8);
- assist Customer, taking into account the nature of processing, in responding to data subject requests and in meeting its security, breach-notification, and impact-assessment obligations; and
- at Customer’s choice, delete or return Customer Personal Data at the end of the services, except where retention is required by law (Section 10).
5. Sub-processors
Customer authorizes Provider to engage the sub-processors listed below to process Customer Personal Data. Provider imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains responsible for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Motive (Keep Truckin, Inc.) | ELD / GPS vehicle location & driver data import for live tracking | United States |
| FMCSA QCMobile — U.S. Department of Transportation | Carrier lookup by USDOT/MC number | United States |
| Google Maps Platform (Google LLC) | Address autocomplete and mapping | United States |
| Microsoft Azure Communication Services | Transactional email delivery (invitations, password resets, notifications) | United States / European Union |
| Microsoft Azure Blob Storage | Storage of uploaded compliance documents | United States / European Union |
| Stripe, Inc. | Online invoice payment processing (card data handled entirely by Stripe) | United States |
Provider will give Customer notice of any intended addition or replacement of a sub-processor, giving Customer the opportunity to object on reasonable data-protection grounds.
6. International transfers
Where Provider transfers Customer Personal Data across borders in a way that requires a transfer mechanism under Data Protection Laws, Provider will implement an appropriate mechanism, such as the Standard Contractual Clauses.
7. Data subject requests
Taking into account the nature of the processing, Provider will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights. If Provider receives such a request directly, it will refer the data subject to Customer.
8. Security measures
Provider maintains measures appropriate to the risk, including: encryption of data in transit and of sensitive secrets at rest; password hashing and tokenization of session and credential-recovery tokens; role-based access control scoped to each Customer’s tenant; audit logging of significant actions; access controls and least-privilege administration; and regular review of these measures.
9. Personal data breach
Provider will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations.
10. Deletion and return
On termination or expiry of the services, and at Customer’s election, Provider will delete or return Customer Personal Data within a reasonable period, except where retention is required by applicable law. Customer may export its data before deletion.
11. Audits
Provider will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, subject to reasonable confidentiality, scheduling, and security requirements.
12. Liability and precedence
This DPA is subject to the limitations of liability in the agreement. If there is a conflict between this DPA and the agreement regarding the processing of Customer Personal Data, this DPA controls.
13. Contact
Data-protection contact: privacy@example.com.