Parties and scope
This agreement is between the organization that uses Wheelerate (the “operator”) and Wheelerate (“we”, “us”). It forms part of the terms of service and applies whenever we process personal data on the operator’s behalf in providing Wheelerate.
Terms such as personal data, processing, data controller and data processor have the meaning given to them by the Data Protection Act, 2019 of Kenya and by any other data protection law that applies (“data protection law”).
Roles and instructions
- The operator is the data controller of the personal data that it and its people keep in Wheelerate; we are its data processor.
- We process that personal data only on the operator’s documented instructions: this agreement, the terms of service, and the operator’s own use and settings of Wheelerate. If the law requires us to process it otherwise, we will tell the operator first, unless the law forbids that.
- If we believe an instruction breaks data protection law, we will tell the operator.
- The operator is responsible for having a lawful basis for the personal data it keeps in Wheelerate, and for telling the people it concerns what it does with it.
Details of the processing
- Subject matter
- Providing Wheelerate, fleet operations software, to the operator.
- Duration
- While the operator uses Wheelerate, and afterwards only as set out in End of service.
- Nature and purpose
- Storing, organizing and displaying the operator’s information, working out schedules, availability, alerts and financial summaries from it, backing it up and keeping it secure, so that the operator can run its operations.
- People concerned
- The operator’s customers and their contacts; its drivers; its staff and the other members of its organization; the people it invites.
- Personal data
- Names; email addresses; phone numbers; driver licence numbers and expiry dates; booking details, including pickup and drop-off places and itineraries; notes the operator writes; account identifiers and roles; the record of who changed what.
- Sensitive personal data
- None is needed. The operator should not enter sensitive personal data, such as health information, in Wheelerate’s free-text fields.
Confidentiality
We make sure that the people who can reach the operator’s personal data are bound by confidentiality, and reach it only as far as they need to provide, support or secure Wheelerate.
Security
We protect the operator’s personal data with these measures, among others:
- Separation of organizations in the database. Every request carries a signed statement of the organization it acts for, and the database’s row-level security refuses records of any other organization.
- Least privilege. The application’s own database account cannot alter or delete the record of changes; changes to the database’s structure need a separate account. The record changes only when the operator erases a person’s details (they are erased from it too) or deletes its organization, each through a dedicated path that is itself recorded.
- Encryption. Connections are encrypted between the browser, our network edge and the application, and between the application and the database. Backups are encrypted before they are stored and can be read only with a recovery key kept offline.
- Sign-in. People sign in through an identity provider using OpenID Connect; Wheelerate never receives or stores passwords. Sessions end after at most 12 hours, and roles limit what each person can see and do.
- Accountability. An append-only record of changes, kept for the operator.
- Logs without personal content. No names, contact details, request contents or search terms are written to our logs.
- Tested releases. Every change to Wheelerate is tested before release, including automated tests that one organization cannot read or change another’s data.
Sub-processors
The operator authorises us to use these sub-processors:
- Google Cloud
- Hosting of the application, its database, backups and logs.
- Cloudflare
- Delivering the application to browsers, encrypting connections and protecting against attacks, across its global network.
- Our sign-in provider
- Signing people in to Wheelerate.
We place data protection obligations on each sub-processor that protect personal data at least as well as this agreement, and we remain responsible for their work. Before we add or replace a sub-processor, we tell the owners of the operator’s organization, so that the operator can object; if we cannot reasonably meet an objection, the operator may stop using Wheelerate.
International transfers
The personal data is hosted on Google Cloud. If it is stored outside the country where the operator is established, we transfer it there only as data protection law allows, with the safeguards it requires.
Helping the operator
- Requests from individuals. In Wheelerate, the operator’s owners and administrators can find and correct customer and driver records, download everything held about one of them, and erase what identifies them, themselves. If someone asks us directly about personal data the operator controls, we pass the request to the operator, and do not answer it ourselves unless the operator asks us to.
- Assessments and consultations. As far as is reasonable, we help the operator with data protection impact assessments, and with consultations with the data protection authority, that concern Wheelerate.
Personal data breaches
If we become aware of a breach of security affecting the operator’s personal data, we will tell the operator without undue delay, with what we know about its nature, the people and the data affected, its likely consequences and what we are doing about it, and we will keep the operator informed. This is so that the operator can meet its own obligations to notify the data protection authority and the people affected.
End of service
The operator can download all its data at any time, in commonly used formats (JSON and CSV), and its owners can delete its organization at any time: the organization closes at once and is deleted with all its data 14 days later, unless an owner cancels first. Copies in backups are deleted when those backups expire, 14 days later. When the operator stops using Wheelerate, we will also, on its written instruction, give it a copy of its data or delete it within 30 days of the instruction, unless the law requires us to keep it.
Information and audits
We make available the information reasonably needed to show that we meet this agreement, and we answer the operator’s reasonable written questions about our security. Audits beyond that are agreed in advance, take place at a reasonable time and with reasonable notice, and are subject to confidentiality.
General
If this agreement and the terms of service conflict on the protection of personal data, this agreement prevails. It lasts for as long as we process personal data for the operator. The limits of liability in the terms of service apply to it, except where data protection law does not allow them to.
Contact us
Email hello@wheelerate.com.