1. This agreement and how it applies
This Data Processing Agreement (the “DPA”) is made between GarageFlow Systems OÜ, registry code 17601459, of Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia (“GarageFlow”, “we”, “us”) and the business that subscribes to the service (“you”). It records the terms required by Article 28(3) of Regulation (EU) 2016/679 (the “GDPR”).
The DPA is incorporated into our Terms of Service and forms part of them. It applies from the moment you accept those terms — there is no separate signature to collect and no form to request. If your own compliance process requires a countersigned copy, write to [email protected] and we will provide one.
It governs the personal data we process on your behalf: the records you enter about your own customers, their vehicles, the work you do, and your staff (“Customer Personal Data”). It does not govern the data we hold as a controller in our own right — your account, your subscription, and your billing records — which is covered by our Privacy Policy instead. Section 2 of that policy explains the split.
Terms such as “controller”, “processor”, “sub-processor”, “data subject”, “processing”, and “personal data breach” carry the meanings given to them in the GDPR.
2. Roles of the parties
You are the controller of Customer Personal Data. You decide what to collect, why, and how long to keep it. We are your processor and act only on your instructions.
If you are yourself acting as a processor for someone else — for example where you service a fleet under contract to its operator — you engage us as a sub-processor, and you confirm you have the authority from that controller to do so. This DPA then applies as though references to your obligations as controller were references to the obligations you owe that controller.
You are responsible for having a lawful basis for the data you enter, for giving the individuals concerned the information Articles 13 and 14 require, and for the accuracy and legality of your instructions to us.
3. Subject matter and scope of the processing
4. Our obligations as processor
4.1 Documented instructions
We process Customer Personal Data only on your documented instructions, including as to transfers to a third country. Your instructions consist of this DPA, the Terms of Service, your configuration and use of the product's features, and any further written instruction we agree to. We will not process the data for our own purposes, and we do not sell it or use it to train artificial-intelligence models.
We will tell you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law, and may suspend that instruction until it is withdrawn or amended. We may also process the data where EU or member-state law requires it, in which case we will inform you of that requirement first unless the law forbids it.
4.2 Confidentiality
Access to Customer Personal Data is limited to personnel who need it to deliver or support the service. Everyone with access is bound by a contractual duty of confidentiality that survives the end of their engagement, and is instructed to process the data only as this DPA allows.
4.3 Security
We implement the technical and organisational measures described in Annex II to provide a level of security appropriate to the risk, as Article 32 requires. We keep those measures under review and may change them as the service and the threat landscape evolve, provided the change does not materially reduce the protection given to Customer Personal Data.
4.4 Assistance with data subject rights
The product itself is the primary way you meet these obligations: you can search, view, correct, export, and delete customer and vehicle records directly, without asking us. Where a request cannot be met with those tools, we will assist you by appropriate technical and organisational measures, taking into account the nature of the processing. We do not charge for reasonable assistance.
If a data subject contacts us directly about data belonging to your shop, we will not respond to the substance of their request. We will tell them to contact you, and let you know it happened.
4.5 Assistance with your wider obligations
Taking into account the nature of the processing and the information available to us, we assist you in complying with Articles 32 to 36 — security of processing, notification of personal data breaches to your supervisory authority and to affected individuals, data protection impact assessments, and prior consultation.
4.6 Records
We maintain a record of the processing we carry out on your behalf, as Article 30(2) requires, and make it available to a supervisory authority on request.
5. Your obligations as controller
- Ensure you have a lawful basis for every category of personal data you enter, and that your privacy notice tells the individuals concerned that a shop management provider processes their data on your behalf
- Do not enter special categories of personal data — health, biometric, racial or ethnic origin, or criminal-offence data — into free-text fields such as notes, findings, or messages. The product is not designed to hold them and Annex II is not calibrated for them
- Where you use the marketing, service-reminder, or review-invitation features, hold a lawful basis for each recipient — consent or the soft opt-in for existing customers, as your jurisdiction requires — and honour opt-outs you receive outside the product by recording them in it. Every message we send on your behalf carries an unsubscribe link and we suppress anyone who has opted out, but the decision to send is yours
- Keep credentials confidential, grant each staff member only the access their role needs, and remove access promptly when someone leaves
- Respond to your own customers’ data subject requests, and to your own supervisory authority
- Give instructions that are lawful, and keep the data you hold accurate and up to date
6. Sub-processors
You give us a general written authorisation, under Article 28(2), to engage sub-processors. The ones engaged today are listed in Annex III. Several of them are engaged only if you choose to connect that integration; until you do, no Customer Personal Data reaches them.
Every sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA. We remain fully liable to you for their performance of those obligations.
Before we add or replace a sub-processor we will give you at least 30 days' notice, by email to your account owner and by updating Annex III on this page. You may object within that period on reasonable grounds relating to data protection. We will work with you to address the objection; if we cannot within a reasonable time, you may terminate the affected part of the service — or the subscription, if the sub-processor is not tied to an optional integration — and receive a pro-rata refund of fees prepaid for the unused remainder of your term.
7. International transfers
Our application servers, primary database, and file storage are hosted in Germany. Customer Personal Data is stored in the European Union and stays there. Transfers outside the EEA happen only through the sub-processors in Annex III, and only for the purpose stated there.
Where a transfer to a third country takes place, we rely on an adequacy decision of the European Commission where one covers that country, and otherwise on the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 — Module Two where the transfer is controller-to-processor, and Module Three where it is processor-to-sub-processor. You authorise us to conclude those clauses with our sub-processors in your name and on your behalf, and to agree the docking, governing law, and forum options in a manner consistent with this DPA.
We carry out transfer impact assessments where they are required, and will provide a copy of the safeguards in place on written request to [email protected], with commercially sensitive terms redacted. If a transfer mechanism we rely on is invalidated, we will implement an alternative without undue delay; if none is available, either party may terminate the affected processing.
8. Personal data breach
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay, by email to your account owner. The notification will describe, so far as we know it at the time:
- The nature of the breach, including the categories and approximate number of data subjects and records concerned
- The likely consequences
- The measures we have taken or propose to take to address it and to mitigate its effects
- A contact point for further information
Where we cannot provide all of that at once, we will provide it in phases as it becomes available. Notifying you under this section is not an acknowledgement of fault or liability.
Deciding whether the breach must be reported to a supervisory authority under Article 33, or communicated to affected individuals under Article 34, is yours as controller. We will not make that notification on your behalf unless you ask us to, or unless the law requires us to act directly.
9. Information and audits
On written request we will make available the information reasonably necessary to demonstrate compliance with Article 28, including our answers to a reasonable security questionnaire and any certifications or reports we hold.
Where that information is not sufficient, you or an independent auditor you appoint — who must not be a competitor of ours and must be bound by confidentiality — may audit our processing. Audits take place during business hours, on at least 30 days' written notice, no more than once in any twelve-month period, and must not unreasonably disrupt our operations. You bear your own costs and ours.
The once-a-year limit does not apply where a supervisory authority requires an audit, or following a personal data breach affecting your data. Because the service is multi-tenant, an audit cannot extend to other customers' data, and cannot extend to physical infrastructure we do not operate — for our hosting provider we will pass on the assurances and certifications they make available to us.
10. Return and deletion of data
You can export your data at any time while your subscription is active, using the export features in the product. You do not need our involvement and we do not withhold data as leverage in a billing dispute.
When the subscription ends we keep your data for 90 days so you can retrieve it, then delete it from the live service. If you ask us in writing to delete it sooner, we will.
Deleted data persists in backups until those backups age out on their rolling cycle, which completes within 30 days. Backup copies are not restored into the live service except for disaster recovery, and this DPA continues to protect them for as long as they exist. We may also retain data where EU or member-state law requires it — for example accounting records — in which case we keep it only for that purpose and only for as long as the obligation lasts.
11. Liability
Each party's liability under this DPA is subject to the exclusions and limits in the Terms of Service. Nothing in this DPA limits the rights of a data subject, or either party's liability to a data subject or a supervisory authority under Article 82 GDPR.
12. Term, precedence, and changes
This DPA takes effect when you accept the Terms of Service and continues for as long as we process Customer Personal Data on your behalf. Sections 7 to 11 survive its termination for as long as we hold any of that data.
If this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails. If it conflicts with Standard Contractual Clauses that apply to a transfer, those clauses prevail.
We may update this DPA to reflect changes in law, in the service, or in our sub-processors. For a change that materially affects your rights we will give at least 30 days' notice; if the change reduces the protection given to Customer Personal Data and you do not accept it, you may terminate your subscription before it takes effect and receive a pro-rata refund of prepaid fees. Changes to Annex III follow the notice and objection process in section 6.
This agreement is published in English. Translations are provided for convenience only; in the event of any discrepancy, the English text governs.
Details of the processing
A. Parties
Controller (data exporter): the subscribing business, as identified by the shop and billing details in its GarageFlow account. Processor (data importer): GarageFlow Systems OÜ, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia — [email protected].
B. Description of the processing
| Subject matter | Provision of the GarageFlow shop management service to the controller. |
| Duration | For the term of the subscription, plus the 90-day retrieval window and the backup cycle described in section 10. |
| Nature of the processing | Collection, recording, organisation, storage, retrieval, consultation, use, alteration, transmission to recipients the controller designates, backup, restriction, and erasure — all by automated means. |
| Purpose | Operating repair orders, estimates, inspections, scheduling, invoicing, payments, inventory, reporting, and communications between the shop and its customers; sending service reminders, marketing campaigns and review invitations the controller configures, and measuring their delivery and response; providing support to the controller. |
| Frequency | Continuous, for as long as the controller uses the service. |
| Categories of data subject | The controller’s customers and their authorised contacts; vehicle owners and drivers; the controller’s staff and other users of its account; the controller’s suppliers’ contacts. |
| Categories of personal data | Identity and contact details (name, company, email, phone, postal address); language and contact preferences; marketing preferences, including whether the data subject has opted out; vehicle records including VIN, registration plate, mileage history and photographs; work records including estimates, repair orders, inspection findings, parts and labour; financial records including invoices, payments, and payment terms; correspondence between the shop and its customers; marketing and review-invitation records, including which messages were sent and whether each was delivered, opened, or clicked; reviews received on the controller’s connected Google Business Profile and replies to them; electronic signatures captured on authorisation; staff clock-in and clock-out records; free-text notes entered by the controller. |
| Special categories of data | None. The service is not designed to process special-category data and the controller undertakes in section 5 not to enter it. |
| Data concerning children | None expected. The service is a business tool and is not directed at children. |
| Transfers to sub-processors | As set out in Annex III, for the purposes and with the frequency stated there, for the duration of the subscription. |
C. Competent supervisory authority
Ours, as an establishment in Estonia, is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — https://www.aki.ee/en. Yours is the authority of the member state in which you are established. Where Standard Contractual Clauses apply, the competent authority is determined under clause 13 of those clauses.
Technical and organisational measures
The measures below are those actually in place. We describe them at a level of detail that is useful without itself becoming a map of the system for an attacker.
| Measure | What we do |
|---|---|
| Encryption in transit | All traffic between browsers, our servers, and our sub-processors runs over TLS. The service is not reachable over unencrypted HTTP. |
| Credential storage | Passwords are stored only as salted hashes and are never recoverable. Single-use sign-in-link tokens are stored hashed. Access tokens for connected accounting and payment providers are encrypted at rest. |
| Tenant isolation | Every record is bound to a shop, and a query scope applied at the data layer restricts each request to the shop of the authenticated user. One shop cannot reach another’s records. |
| Access control | Access within a shop is role-based — owners, managers, and technicians see different data and hold different rights. Access to production systems is limited to personnel who need it for operation and support. |
| Authentication protections | Sign-in, sign-up, password-reset, and sign-in-link endpoints are rate-limited to resist credential stuffing and enumeration. Sessions and API tokens are revocable and expire. |
| Logging and accountability | Administrative actions taken on the platform are recorded in an append-only audit log with the actor, the action, and the time. Application errors are captured for diagnosis and retained for 30 days. |
| Data location | Application servers, the primary database, and uploaded files are hosted in an EU data centre in Nuremberg, Germany, in facilities certified by the hosting provider to ISO/IEC 27001. |
| Backup and recovery | The database is backed up on a regular schedule. Backups age out on a rolling cycle completing within 30 days, and are restored only for disaster recovery. |
| Segregation of environments | Development and test environments are separate from production and are not populated with live customer data. |
| Change management | Changes are version-controlled and covered by an automated test suite that is run before release. |
| Deletion | Records deleted in the product are removed from the live service; the retention and backup rules in section 10 govern what happens after that. |
| Personnel | Everyone with access to personal data is bound by confidentiality obligations that survive the end of their engagement. |
| Sub-processor assurance | Sub-processors are selected on their security posture and engaged under data processing terms no less protective than these. |
Two things we deliberately do not claim: we do not currently offer multi-factor authentication for staff accounts, and we do not hold an ISO 27001 or SOC 2 certification of our own. Where a certification is referenced above it is our hosting provider's, covering their facilities rather than our application. We will update this annex as that changes.
Authorised sub-processors
This is the list of sub-processors authorised under section 6, current as of 16 September 2026. Entries marked optional are engaged only if you connect that integration.
- Purpose
- Application hosting, primary database, and file storage
- Personal data
- All customer personal data stored in the service
- Location
- Germany (EU)
- Transfer safeguard
- None required — processing stays in the EEA
- Purpose
- Subscription billing and card payments
- Personal data
- Shop billing contact and payment identifiers; where a shop takes payment through the product, the payer’s name, email, and payment details
- Location
- EU / United States
- Transfer safeguard
- Standard Contractual Clauses
- Purpose
- Sending and receiving email
- Personal data
- Recipient name and email address, and the content of the message sent
- Location
- United States
- Transfer safeguard
- Standard Contractual Clauses
- Purpose
- Real-time updates in the app
- Personal data
- Record identifiers and notification content delivered to signed-in staff
- Location
- EU / United States
- Transfer safeguard
- Standard Contractual Clauses
- Purpose
- AI suggested replies to customer messages and to reviews
- Personal data
- The recent messages in the conversation being answered, with the customer name and vehicle; or the review being replied to — reviewer display name, rating, and text
- Location
- United States
- Transfer safeguard
- Standard Contractual Clauses
- Purpose
- Customer sign-in to the portal, and Business Profile reviews
- Personal data
- Name and email address of the person signing in; where a shop connects its Business Profile, the reviews it has received — reviewer display name, rating, and review text — and any reply the shop publishes
- Location
- United States
- Transfer safeguard
- Standard Contractual Clauses
- Purpose
- WhatsApp messaging
- Personal data
- Recipient phone number and message content
- Location
- EU / United States
- Transfer safeguard
- Standard Contractual Clauses
- Purpose
- Accounting sync
- Personal data
- Customer name, contact details, and invoice data synced to the shop’s ledger
- Location
- United States
- Transfer safeguard
- Standard Contractual Clauses
- Purpose
- Accounting sync
- Personal data
- Customer name, contact details, and invoice data synced to the shop’s ledger
- Location
- New Zealand
- Transfer safeguard
- Adequacy decision (New Zealand)
- Purpose
- Card payment processing
- Personal data
- Payer name and payment details for payments taken through the product
- Location
- Iceland (EEA)
- Transfer safeguard
- None required — processing stays in the EEA
We also use a third-party vehicle catalogue to populate makes, models, and trim levels. It receives no personal data — we download a reference list of vehicle specifications and store it on our own servers — so it is not a sub-processor and is not listed here.
To be notified of changes to this list, write to [email protected]. Account owners are notified by email automatically.