Data Processing Agreement
DV-DPA-001 · Version 1.0 · Effective
1. Parties and purpose
This Data Processing Agreement (DPA) forms part of the agreement between Axholme ETM Ltd trading as DV Check ("DV Check") and the customer identified in the applicable order, account or service agreement ("Customer"). It applies where DV Check processes personal data on behalf of the Customer as processor.
2. Roles
For processing governed by this DPA, the Customer acts as controller and DV Check acts as processor, except where law or a separate written agreement establishes another role. Each party remains responsible for its own independent processing.
3. Processing instructions
DV Check will process personal data only on documented Customer instructions, including the instructions inherent in providing the contracted service, unless required by law.
The Customer warrants that its instructions are lawful and that it has the necessary authority, transparency and consent/declaration where required to submit data and request checks.
DV Check will notify the Customer if, in its opinion, an instruction infringes applicable data protection law, subject to legal restrictions.
4. Confidentiality and personnel
DV Check will ensure persons authorised to process Customer personal data are subject to appropriate confidentiality obligations and receive proportionate data protection and security training.
5. Security
DV Check will implement appropriate technical and organisational measures taking account of the nature of processing and risk, including access control, MFA, encryption where appropriate, logging, patching, malware protection, backup/recovery, incident management and secure development controls as described in its security policies.
6. Sub-processors
The Customer gives general authorisation for DV Check to use sub-processors necessary to provide the service, subject to suitable written terms and due diligence. DV Check remains responsible for the performance of processor obligations delegated to its sub-processors. Material changes to sub-processors will be notified or otherwise made available in accordance with the service terms. The current sub-processors are listed in Schedule C.
7. Data subject rights
Taking account of the nature of processing, DV Check will provide reasonable assistance to enable the Customer to respond to requests to exercise data subject rights. DV Check will not independently respond on the Customer's behalf except where authorised or legally required.
8. Breach notification
DV Check will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data and will provide available information reasonably required for the Customer to meet its legal obligations. Notifications may be updated as investigation progresses.
9. DPIAs and regulators
DV Check will provide reasonable information and assistance for data protection impact assessments and prior consultation obligations relating to the contracted processing, taking into account the nature of processing and information available to DV Check.
10. Deletion and return
On termination or expiry, DV Check will delete or return Customer personal data in accordance with the service terms and retention policy, unless retention is required by law, the DVLA ADD contract or another applicable obligation. Secure backups may be deleted in accordance with normal backup cycles while remaining protected and unavailable for ordinary use.
11. Audit and information
DV Check will make available information reasonably necessary to demonstrate compliance with applicable processor obligations and will support proportionate audits subject to reasonable notice, confidentiality, security and non-disruption requirements. Existing independent reports, certifications or evidence may be used where appropriate.
Schedule A: Processing details
- Subject matter: provision of DV Check driving licence checking and compliance services.
- Duration: for the term of the service plus applicable retention periods.
- Nature: collection, storage, retrieval, transmission, display, logging, support and deletion.
- Purpose: authorised licence checking, compliance management, account administration and service support.
- Data subjects: drivers, customer users and business contacts.
- Data types: identity/contact data, driving licence identifiers and DVLA response data, consent/declaration records, account/audit data.
- Special/sensitive elements: driving record information may reveal offence/endorsement or health-related restriction information depending on source data; access must be restricted and lawful.
Schedule B: Customer acceptance
This DPA is accepted electronically. When an account is created, the person creating it confirms they agree on behalf of the Customer organisation, and DV Check records the organisation, the person, the version of this DPA and the date and time of acceptance. That record stands in place of a signature.
Schedule C: Sub-processors
- Supabase: database and authentication. Hosted in London (AWS eu-west-2).
- Vercel: application hosting. Application servers run in London.
- Resend: sending service emails, including consent requests to drivers.
- Cloudflare: DNS and bot protection on sign-in and sign-up forms.
- Stripe: card payments for credit purchases. Handles account billing details only, never driver data.
- Purelymail: our support mailbox.
See also our Privacy Policy and how driver data is protected.