Data Processing Agreement (DPA)
_Last updated: 17 August 2026 · Version 4_
This Data Processing Agreement ("DPA") forms part of the agreement between Coachcomp Limited trading as CoachComp ("Processor") and the operator using the Service ("Controller") and applies whenever CoachComp processes personal data on the Controller's behalf.
1. Processor details
- Registered company: Coachcomp Limited, registered in England and Wales, company number 17362338
- Registered address: SY11 4EE, England
- ICO registration reference: ZC223321
- Contact: info@coachcomp.co.uk
2. Definitions
Capitalised terms follow the meanings in the UK GDPR and the Data Protection Act 2018.
3. Subject matter and duration
- Subject matter: processing personal data supplied by the Controller in connection with the CoachComp compliance platform.
- Duration: for as long as the Controller holds an active CoachComp account, plus any post-termination retention required by law.
4. Nature and purpose of processing
Storage, transmission, structuring, retrieval, analysis (including AI-assisted review), and deletion of Controller data for the purpose of transport-compliance management (O-licence records, drivers, vehicles, policies, audits, cases, Q&A).
5. Categories of data subjects
- Controller's staff (operator admins and users)
- Controller's drivers and other operational personnel
- Third parties named in incident, case or audit records
6. Categories of personal data
Identity data (name, contact details), employment data (licence, CPC, medical, endorsements, training records), operational data (vehicle assignments, tacho, MOT, defects, incidents), account credentials, and any additional data the Controller chooses to upload.
7. Processor obligations (Art. 28 UK GDPR)
CoachComp shall:
1. Process personal data only on documented instructions from the Controller, including with respect to international transfers.
2. Ensure personnel authorised to process personal data are subject to confidentiality.
3. Implement appropriate technical and organisational measures, including encryption in transit and at rest, row-level access controls, server-side authentication, least-privilege database roles, logging and monitoring.
4. Not engage a subprocessor without general prior authorisation. A current list of subprocessors is set out in the Annex; CoachComp will give the Controller reasonable notice of intended changes and an opportunity to object.
5. Assist the Controller, taking into account the nature of the processing, with responding to data-subject rights requests, security, breach notification, DPIAs and prior consultations.
6. Notify the Controller without undue delay after becoming aware of a personal-data breach, and in any event within 72 hours where feasible.
7. At the Controller's choice, delete or return all personal data at the end of the provision of services, save where retention is required by law.
8. Make available all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, on reasonable notice and subject to confidentiality.
8. International transfers
Where personal data is transferred outside the UK, CoachComp relies on adequacy decisions or the UK International Data Transfer Addendum to the EU SCCs, or such other safeguard as is recognised by law.
9. Liability and precedence
To the extent of any conflict, this DPA prevails over other terms in relation to the processing of personal data. Nothing in this DPA limits either party's obligations under UK data-protection law.
10. Signatures
This DPA is entered into by acceptance of the Service terms and does not require a wet signature. On written request, CoachComp will provide a countersigned copy.
---
Annex A — Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Lovable Cloud (Supabase) | Hosting, database, authentication, storage | EU |
| Lovable AI Gateway | Model routing for AI features | EU / UK |
| Perplexity | Research citations for Q&A | US (SCCs + UK IDTA) |
| DVSA MOT History API | Vehicle MOT lookups | UK |
| Stripe | Subscription billing | EU / US (SCCs + UK IDTA) |
Annex B — Technical and organisational measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Row-Level Security on all user-data tables, scoped to authenticated user or operator
- Bearer-token authenticated server functions; service-role access limited to trusted server-only paths
- Automated retention sweeps with audit logging (`retention_events`)
- Access logging, backup encryption, and staff access on a need-to-know basis
Annex C — Controller details
To be completed by the Controller on execution or as recorded in the Controller's CoachComp account.