MIRA
Official Terms & PoliciesEffective date:

Data Processing Addendum (DPA)

DPA Legal Framework Summary

This Data Processing Addendum ("DPA") supplements the MIRA Business Dealer Partner Agreement and Terms of Service between Motorsync Ltd ("Motorsync", "Data Processor") and your business entity ("Customer", "Data Controller").

  • GDPR Article 28 Compliance: Establishes legally binding data processing terms required under UK GDPR and EU GDPR for B2B SaaS usage.
  • Clear Roles: Customer acts as Data Controller for showroom visitor/lead data stored in MIRA Business; Motorsync acts strictly as Data Processor.
  • Security Safeguards: Enforces end-to-end encryption, multi-tenant data isolation, zero-trust access, and a 72-hour maximum incident notification SLA.

By executing a MIRA Business order form or utilizing MIRA Business software services, Customer agrees to be legally bound by this DPA.

1. Definitions & Statutory Context

Terms such as "Personal Data", "Processing", "Data Subject", "Supervisory Authority", and "Technical and Organisational Measures" have the meanings set forth in the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.

Data ControllerThe dealership, credit broker, or enterprise entity that determines the purposes and means of processing Customer Personal Data within MIRA Business.
Data ProcessorMotorsync Ltd ("Motorsync", "MIRA"), which processes Customer Personal Data solely on behalf of and according to the instructions of the Data Controller.
Customer Personal DataAny personal data processed by Motorsync Ltd in the provision of MIRA Business SaaS services, including lead contact info, vehicle records, CRM logs, and finance metadata.
Security IncidentAny confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

2. Scope of Processing & Data Categories

Motorsync shall process Customer Personal Data exclusively for the purpose of delivering MIRA Business SaaS functions:

  • Categories of Data Subjects: Dealership leads, vehicle buyers, showroom check-in visitors, dealership staff users, and finance applicants.
  • Categories of Personal Data: Names, contact details (email, phone, address), driving licence verification numbers, vehicle preferences, E-Garage service history, soft credit search metadata, and in-app communications.
  • Duration of Processing: For the duration of Customer's active subscription plus post-termination data retention grace periods.

3. Data Processor Obligations

Motorsync warrants and agrees that it shall:

  • Process Customer Personal Data solely on documented written instructions from Customer, including contractually defined SaaS routing and storage operations.
  • Ensure that all personnel authorised to process Customer Personal Data are bound by strict statutory or contractual confidentiality obligations.
  • Promptly notify Customer if, in Motorsync's opinion, an instruction infringes UK GDPR or applicable privacy legislation.

4. Technical & Organizational Security Measures (TOMs)

Security Infrastructure: Motorsync maintains an ISO 27001 / SOC 2 aligned security control framework. Technical measures include TLS 1.3 encryption in transit, AES-256 encryption at rest, automated vulnerability scanning, strict tenant isolation in database architectures, and zero-trust role-based access control (RBAC).

5. Sub-Processor Authorization & Management

Customer provides general authorization for Motorsync to engage third-party infrastructure sub-processors:

  • Cloud Infrastructure & Databases: Amazon Web Services (AWS UK Region), Google Cloud Platform (GCP EU/UK), Microsoft Azure (Azure UK/EU Region).
  • Communication Services: Twilio (SMS routing), SendGrid (transactional email).
  • Sub-processor Changes: Motorsync shall provide Customer with 14 days prior notice before onboarding new sub-processors, allowing Customer to object on reasonable data protection grounds.

6. Personal Data Breach Notification

In the event of a confirmed Security Incident involving Customer Personal Data, Motorsync shall:

  • Notify Customer in writing without undue delay, and in any event within 72 hours of becoming aware of the incident.
  • Provide reasonable details regarding the nature of the breach, affected data categories, estimated number of impacted data subjects, and recommended mitigation actions.
  • Take prompt remedial measures to mitigate adverse consequences and prevent recurrence.

7. Data Subject Rights (DSAR) Assistance

Taking into account the nature of SaaS processing, Motorsync shall assist Customer by appropriate technical and organisational measures in fulfilling Customer's legal obligations to respond to Data Subject Access Requests (DSARs), erasure requests, or processing restrictions.

8. International Data Transfers & SCCs

Customer Personal Data is primarily stored and processed within the United Kingdom and European Economic Area (EEA). If cross-border transfers occur, Motorsync guarantees implementation of the UK International Data Transfer Addendum (IDTA) or Standard Contractual Clauses (SCCs).

9. Data Return, Export & Deletion

Upon subscription expiry or termination of the main commercial agreement, Motorsync shall, at Customer's choice, securely delete or export all Customer Personal Data within 30 days, except where law requires retention.

10. Audit Rights & Compliance Verification

Motorsync shall make available to Customer information necessary to demonstrate compliance with UK GDPR Article 28 obligations and allow for reasonable compliance documentation reviews or independent third-party audit reports (e.g. SOC 2 Type II audit summaries).

11. Term, Governing Law & DPO Contact

Motorsync Ltd Data Protection Officer (DPO)

Email: privacy@motorsync.co.uk

Postal Address: Data Protection Officer, Motorsync Ltd, 5 Maltby Court, Leeds, LS15 9BA, United Kingdom

Jurisdiction: Governed exclusively by the laws of England & Wales under the jurisdiction of the English courts.

Related Regulatory & Policy Documents