Legal
Data processing agreement
How we process the personal data you keep in Odobase on your behalf.
Last updated
1. Parties and scope
This Data Processing Agreement (“DPA”) is between the company that holds an Odobase account (“you”, the controller) and EqualPixels, F-16 Ali View Garden, Phase 3, Lahore Cantt, Lahore 58200, Pakistan (“we”, the processor). It applies whenever we process personal data on your behalf in providing the Odobase service, and is intended to meet Article 28 of the EU General Data Protection Regulation (“GDPR”) and equivalent laws.
Where this DPA and the Terms of Service disagree about personal data, this DPA prevails.
2. Details of the processing
2.1 Subject matter and duration
Providing the Odobase fleet and booking service to you, for as long as your account is open and for the deletion period in section 9 afterwards.
2.2 Nature and purpose
Storing, organising, displaying, transmitting and deleting records so that you can take bookings, dispatch trips, track vehicles, message customers, issue invoices and run reports.
2.3 Categories of data subjects
- Your customers, their contacts and their passengers
- Your drivers
- Your staff and other users of your account
- People who submit your booking forms
2.4 Types of personal data
- Names, phone numbers, email addresses and postal or billing addresses
- Pickup and drop-off addresses, flight numbers and trip history
- Vehicle location during trips, recorded from the driver app
- Driver identity and licence numbers, where you record them
- Messages sent to your customers and their replies
- Consent records, and IP addresses and browser details captured with them
The service is not designed for special categories of personal data, and you agree not to store them in it.
3. Our obligations
- We process personal data only on your documented instructions — this DPA, the Terms, and what you do in the service — unless the law requires otherwise, in which case we will tell you first where we lawfully can.
- We tell you if we believe an instruction breaks data protection law.
- Everyone at EqualPixels who can reach your data is bound by confidentiality.
- We do not sell your data, use it for advertising, or combine it with other customers’ data.
4. Security
We keep technical and organisational measures appropriate to the risk, including:
- Encryption of traffic in transit, and encryption of secrets and access tokens at rest
- Separation of every company’s records from every other company’s, enforced in the application
- Two-factor authentication for our staff, and available to every user of your account
- A log of sign-ins and an audit log of sensitive actions
- Restricted, individual access to production systems, and regular backups
5. Sub-processors
You authorise us to use the sub-processors listed on our sub-processor list. We bind each one to data protection terms no less protective than this DPA, and we remain responsible for them.
We will update the list at least 30 days before a new sub-processor starts processing your data. If you object on reasonable data protection grounds, tell us within that period; if we cannot address the objection, you may end the affected service and receive a refund of prepaid fees for the unused period.
6. International transfers
Our servers are hosted in the European Union. Some sub-processors, and our own support staff, process data outside the European Economic Area. Where they do, the transfer is covered by an adequacy decision or by the European Commission’s Standard Contractual Clauses (module two, controller to processor, or module three, processor to processor), which are incorporated into this DPA by reference.
7. Helping you meet your obligations
The service gives you tools to answer your data subjects directly: exporting everything held about a customer, erasing a customer while keeping the invoices the law requires you to retain, recording consent, and setting how long GPS points, unconverted enquiries and message logs are kept. Where those are not enough, we will help you respond to requests from data subjects and regulators, and with data protection impact assessments, taking into account the nature of the processing.
8. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data. The notice will describe what happened, the data and people affected as far as we know them, the likely consequences, and what we are doing about it, and we will update it as we learn more.
9. Return and deletion
You can export your records at any time while your account is open. When it closes, we delete or anonymise your personal data within 90 days, except where the law requires us to keep it; backups age out on their normal cycle.
10. Information and audits
We will make available the information reasonably necessary to show that we meet this DPA, and allow audits by you or an auditor you appoint, on reasonable notice, at most once a year unless a regulator requires more or a breach has occurred, and subject to confidentiality.
11. Acceptance and changes
A company administrator accepts this DPA in Settings → Privacy & security. We record who accepted it, when, and which version. If we change it, we publish the new version here with a new date and ask for it to be accepted again.
Questions about this DPA: info@odobase.com.
This document is published in English. If it is made available in another language, the English version governs.