This Data Processing Agreement ("DPA") forms part of the Platform Terms between White Stripe Innovations Private Limited ("Processor", "we") and the Operator ("Controller", "you"). It applies whenever we process personal data on your behalf through the zevOS Service. It is written to satisfy the Digital Personal Data Protection Act, 2023 (India) and is structured so that a GDPR Article 28 addendum can be attached for Operators serving the EEA or UK.
1. Roles
- You are the controller (data fiduciary) for personal data of your drivers, partners, staff and site contacts that you collect or that the Service collects for you.
- We are the processor for that data and act only on your documented instructions, which are: to provide the Service as described in the Platform Terms and its documentation, and as you configure it in the dashboard.
- We are an independent controller for the limited data we process for our own purposes: your account and billing records, security logs, and the platform privacy notice describes these.
2. What we process
- Data subjects: drivers, your staff, your partners and their staff, site contacts.
- Categories: identity and contact data (name, phone, email), vehicle details drivers add, RFID identifiers, charging session data (charger, location, time, energy, tariff, amount), payment references (never full card data), device and technical data, support correspondence.
- Duration: for the life of your account plus the retention periods in Section 8.
3. Our obligations
- Process personal data only on your instructions; tell you if an instruction would in our view breach applicable law.
- Ensure staff with access are bound by confidentiality and trained.
- Apply the security measures in Section 6.
- Assist you, at your reasonable request, with data-subject rights, breach notifications and impact assessments.
- Delete or return personal data at the end of the Service as set out in Section 8.
- Make available the information reasonably necessary to demonstrate compliance and allow audits by you or an auditor you mandate, on 30 days' notice, no more than once a year unless a breach or regulator requires otherwise.
4. Your obligations
- Have a lawful basis for the data you collect through the Service and present drivers with a privacy notice before they pay.
- Give instructions that comply with applicable law.
- Respond to data-subject requests from your drivers, partners and staff; the Service provides self-service tools for the common ones.
5. Sub-processors
- You authorise us to use the sub-processors listed on the Sub-processors page. We will notify Operators of additions by email at least 14 days in advance; you may object on reasonable data-protection grounds within that period, in which case we will work with you on a solution or you may terminate the affected part of the Service.
- We impose data-protection obligations on each sub-processor that are no less protective than this DPA and remain responsible for their performance.
6. Security
- Encryption in transit (TLS) and at rest; payment-gateway credentials stored encrypted.
- Tenant isolation: every record carries your tenant identifier and access is filtered by it at the data layer.
- Role-based access with an audit log of administrative actions.
- Backups with point-in-time recovery; disaster-recovery procedures tested periodically.
- Vulnerability management and monitoring.
7. Personal-data breach
We will notify you without undue delay, and in any event within 48 hours of confirming a personal-data breach affecting your data, with the information we have at that time and updates as the investigation proceeds. You are responsible for notifications to regulators and data subjects as the controller; we will assist.
8. Retention, return and deletion
- Session and money records: eight years, to meet tax and financial record-keeping requirements.
- Account and profile data: for the life of the account. Automatic closure of unused driver accounts is off unless you switch it on in Settings → Legal (one year minimum); when on, the driver is warned 30 days ahead, activity cancels it, accounts holding money are never closed, and every closure is written to your audit log. Contact details on session and money records are removed once their eight-year period ends.
- OCPP message logs: 90 days. Telemetry: 13 months. Support correspondence: three years.
- Records of legal acceptances: retained indefinitely as evidence of the contract.
- On termination you may export your data for 30 days, after which personal data is deleted or anonymised except where retention is required by law.
9. International transfers
Production data is stored on cloud infrastructure in India (Microsoft Azure, Central India). We will give notice before moving the primary storage region. Operators serving the EEA or UK who require data residency or standard contractual clauses should contact us before onboarding drivers from those regions.
10. Liability
Liability under this DPA is subject to the limitations in the Platform Terms, except that nothing limits liability that cannot be limited under applicable data-protection law.
11. Contact
Data-protection contact: support@zevos.ai