DATA PROCESSING AGREEMENT
1 Parties and Application
This Data Processing Agreement (the "DPA") applies between Delta Media AS, organisation number 916 747 330, Smalvollveien 58, 0667 Oslo, Norway, trading as Future Driver (the "Processor" or "Future Driver"), and the customer that has entered into a customer agreement, order form or accepted offer for the Future Driver services (the "Controller").
This DPA forms part of the agreement under which Future Driver provides its web platform, mobile applications, integrations and related services to the Controller.
This DPA applies automatically to every customer relationship from the time the customer relationship is established, whether through a signed agreement, an accepted offer, an order form or use of the services. A separate signature is not required.
If the parties have signed a customer-specific data processing agreement, that signed agreement applies instead of this DPA. Future Driver will enter into a customer-specific data processing agreement on request. Contact help@futuredriver.app.
If this DPA conflicts with the customer agreement regarding the processing of personal data, this DPA prevails. Terms defined in the GDPR have the same meaning in this DPA.
This DPA is published in Norwegian and English. For Controllers established in Norway, the Norwegian version prevails in the event of any discrepancy. For all other Controllers, the English version prevails.
2 Purpose
The purpose of this DPA is to regulate Future Driver's processing of personal data on behalf of the Controller and to ensure compliance with:
- Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR");
- the Norwegian Personal Data Act of 15 June 2018 No. 38; and
- other applicable data protection legislation.
Future Driver shall process personal data only to provide, operate, secure, maintain and support the services agreed with the Controller.
3 Roles and Responsibilities
The Controller determines the purposes and essential means of the processing of personal data.
Future Driver acts as a data processor and shall process personal data only on documented instructions from the Controller, unless processing is required by applicable law. Documented instructions include:
- the customer agreement;
- this DPA;
- the Controller's configuration and use of the services;
- instructions submitted by authorised customer administrators; and
- other written instructions accepted by Future Driver.
Future Driver shall notify the Controller without undue delay if Future Driver considers that an instruction infringes applicable data protection legislation.
The Controller is responsible for ensuring that:
- there is a valid legal basis for the processing;
- affected individuals receive the required privacy information;
- the use of GPS, employee monitoring and other control measures complies with applicable data protection and employment law, including the Norwegian Working Environment Act chapter 9;
- only necessary personal data is submitted to the services; and
- user access, permissions and enabled modules are appropriately configured.
4 Nature and Purpose of the Processing
Future Driver provides a fleet, equipment, service and operations management platform. Depending on the modules and integrations enabled by the Controller, processing may include:
- administration of users, organisations, roles and permissions;
- fleet and equipment management;
- operations planning, shifts, trips, jobs and assignments;
- GPS positioning, geofencing and equipment movement history;
- damage, tyre, temperature, HSE and equipment reports;
- photographs, comments, documents and signatures;
- workshop bookings, service, repairs and maintenance;
- driver qualifications, tachograph data and equipment compliance information;
- notifications and operational communications;
- integrations with telematics providers, transport management systems, public registers and customer systems;
- customer reports, dashboards and operational analysis;
- customer support, troubleshooting, monitoring and security; and
- AI-assisted functionality where enabled by the Controller.
Processing may include collection, receipt, recording, organisation, storage, updating, retrieval, consultation, display, analysis, transmission, restriction, export, backup and deletion.
The processing continues for the duration of the customer agreement and for the limited period required to return or delete personal data following termination.
5 Categories of Data Subjects
The personal data may concern:
- employees and drivers;
- temporary workers and contractors;
- subcontractor personnel;
- customer administrators and other authorised users;
- dispatchers, workshop personnel and operational managers;
- customer contacts and representatives;
- personnel of the Controller's customers, suppliers and service partners; and
- individuals who may incidentally appear in photographs, reports, messages or other submitted material.
6 Categories of Personal Data
Depending on the services used, Future Driver may process:
- names, work email addresses and telephone numbers;
- employer, department, role and user identifiers;
- account status, permissions and authentication information;
- equipment and vehicle assignments;
- shifts, trips, jobs, tasks and operational activity;
- current and historical GPS positions;
- timestamps, routes, geofence events and addresses derived from coordinates;
- registration numbers, equipment identifiers and equipment status;
- driver card numbers and tachograph activity data where the tachograph module is enabled;
- damage, inspection, tyre, temperature, HSE and service reports;
- photographs, comments, signatures and related metadata;
- workshop, maintenance and compliance information;
- device identifiers, IP addresses, application versions and technical logs;
- support requests, messages and attachments;
- data received through integrations authorised by the Controller; and
- information included in prompts, context and generated output when AI-assisted functionality is enabled.
The services are not designed for the processing of special categories of personal data under Article 9 GDPR or information concerning criminal convictions and offences under Article 10 GDPR. The Controller shall not intentionally submit such information unless the parties have agreed the processing and appropriate safeguards in writing.
7 Confidentiality and Access
Future Driver shall ensure that persons authorised to process personal data:
- are subject to a binding duty of confidentiality;
- receive access only where required for their work;
- have access appropriate to their role;
- receive relevant security and privacy instructions; and
- have their access removed when it is no longer required.
The confidentiality obligation continues after a person's employment, assignment or system access has ended.
8 Information Security
Future Driver shall implement and maintain appropriate technical and organisational measures in accordance with Article 32 GDPR. These measures include, where relevant:
- role-based access controls and least-privilege access;
- protection of administrative and production access, including multi-factor authentication;
- encryption of personal data in transit;
- encryption of production databases, storage volumes and backups using cloud-provider controls;
- logical separation of customer organisations;
- logging and monitoring of relevant security and administrative events;
- controlled software development and deployment;
- risk-based vulnerability management and security testing;
- backups and recovery procedures;
- incident detection and response procedures;
- controlled data export and deletion procedures; and
- security and privacy review of relevant suppliers.
A current description of the measures is available on request. Future Driver may update these measures to reflect technical and operational developments, provided that the overall level of protection is not materially reduced.
The Controller is responsible for security within its control, including user administration, role assignments, endpoint security, safeguarding credentials and reviewing user access.
9 Data Subject Requests and Compliance Assistance
Taking into account the nature of the processing, Future Driver shall assist the Controller, through appropriate technical and organisational measures where possible, in responding to requests from data subjects concerning access, rectification, erasure, restriction, data portability, objection and rights relating to automated decision-making.
If Future Driver receives a request directly from a data subject concerning personal data processed on behalf of the Controller, Future Driver shall forward the request to the Controller without undue delay where the relevant Controller can be identified.
Future Driver shall also provide reasonable assistance with the Controller's obligations under Articles 32 to 36 GDPR, including security assessments, personal data breaches, data protection impact assessments and prior consultation with a supervisory authority.
10 Personal Data Breaches
Future Driver shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data and, where feasible, within 24 hours. To the extent that the information is available, the notification shall include:
- a description of the nature of the breach;
- the categories of data and data subjects affected;
- the approximate number of affected data subjects and records;
- the likely consequences of the breach;
- measures taken or proposed to contain and remedy the breach; and
- a contact point for further information.
Future Driver may provide information in phases as the investigation progresses. Notifications are sent to the contact person registered for the Controller. The Controller is responsible for notifying the relevant supervisory authority and affected individuals unless otherwise agreed or required by law.
11 Subprocessors
The Controller gives Future Driver general written authorisation to use subprocessors to provide and support the services. Future Driver shall:
- enter into a written data processing agreement with each subprocessor;
- impose data protection obligations that are no less protective than the relevant obligations in this DPA;
- remain responsible for the subprocessor's performance as required by Article 28 GDPR; and
- assess relevant privacy and security risks before engaging a subprocessor.
The following subprocessors are used as of the effective date of this DPA:
Amazon Web Services EMEA SARL
Function: Cloud hosting, databases, storage, backups and Amazon Bedrock (AI-assisted functionality)
Location: EU (AWS Region Frankfurt, eu-central-1)
Applies: Standard, all customers
OVH SAS (OVHcloud)
Function: Dedicated servers for geocoding (conversion of GPS coordinates to addresses) and self-hosted log management (Graylog)
Location: Germany (OVHcloud data centre Limburg, eu-west-lim)
Applies: Standard, all customers
FiveDotTwelve sp. z o.o.
Function: DevOps services: operation, monitoring and maintenance of Future Driver's cloud infrastructure
Location: Poland (EU)
Applies: Standard, all customers
Teltonika Telematics UAB
Function: Telematics device connectivity, firmware and device management
Location: Lithuania (EU)
Applies: Where GPS hardware is delivered by Future Driver
Gurtam (flespi)
Function: Telematics data gateway, used as fallback for Teltonika device connectivity
Location: EU (Vilnius, Lithuania)
Applies: Fallback only
Google Cloud EMEA Ltd (Google Workspace)
Function: Support mailbox and ticket handling for help@futuredriver.app
Location: Ireland (EU), with transfers governed by Google's Standard Contractual Clauses
Applies: Standard, all customers
Google Ireland Ltd (Firebase Cloud Messaging)
Function: Delivery of push notifications to the Android and iOS apps (device tokens and notification content only)
Location: EU / USA under Google's Standard Contractual Clauses
Applies: Standard, all app users
Apple Inc. (Apple Push Notification service)
Function: Delivery of push notifications to the iOS app (device tokens and notification content only)
Location: USA, EU-US Data Privacy Framework
Applies: Standard, all iOS app users
Infolab Narloch Sp. z o.o. (TACHO API)
Function: Analysis of tachograph, driver card and vehicle unit data for driving time and rest infringements
Location: Poland (EU)
Applies: Where the tachograph module is enabled
Google Ireland Ltd (Firebase Crashlytics)
Function: Crash reporting for the mobile apps (device identifiers, app version, crash traces)
Location: EU / USA under Google's Standard Contractual Clauses
Applies: Standard, all app users
Brevo (Sendinblue SAS)
Function: Transactional email and SMS notifications
Location: France (EU)
Applies: Standard, all customers
Future Driver shall give at least 30 days' written notice before a new or replacement subprocessor begins processing the Controller's personal data. Notice is given by email to the contact person registered for the Controller and by updating this list. The Controller may register an additional notification address with help@futuredriver.app.
The Controller may object during the notice period where it has reasonable grounds relating to data protection. The parties shall work in good faith to address the objection. If no reasonable solution is available, the Controller may discontinue the affected feature or terminate the affected services in accordance with the customer agreement.
12 Cloud Infrastructure and Amazon Bedrock
Future Driver uses Amazon Web Services for cloud infrastructure and related services. Production data is stored and processed in the AWS Region Frankfurt (eu-central-1), Germany. Future Driver also uses OVHcloud servers in Germany for geocoding and for self-hosted log management.
Where the Controller enables AI-assisted functionality, Future Driver may submit selected customer content and relevant context to Amazon Bedrock to generate a response or analysis on behalf of the Controller. Amazon Bedrock is used exclusively in AWS Regions located within the EEA, and cross-region inference to Regions outside the EEA is disabled.
Future Driver shall not use the Controller's personal data to train a general-purpose AI model, or permit a model provider to use it for that purpose, unless the Controller gives separate express written authorisation. Amazon Bedrock does not use customer prompts or generated output to train models.
Under Amazon Bedrock's documented service architecture, foundation model providers do not have access to AWS-controlled model deployment accounts, Amazon Bedrock logs, customer prompts or generated completions. For this reason, a foundation model provider made available through Amazon Bedrock is not separately treated as a Future Driver subprocessor where the provider cannot access the Controller's personal data. Future Driver shall reassess this position if its AWS configuration or the relevant Amazon Bedrock terms or architecture change.
13 International Transfers
Future Driver shall not transfer personal data outside the EEA, or permit access from outside the EEA, unless the transfer complies with Chapter V GDPR.
Where an adequacy decision does not apply, Future Driver shall use an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, and implement supplementary safeguards where required.
Information about processing locations and transfer safeguards shall be made available to the Controller on reasonable request.
14 Use of Anonymised Information
Future Driver shall not use personal data processed on behalf of the Controller for unrelated product development, marketing or other independent purposes.
Future Driver may use statistical, aggregated or anonymised information to improve and develop the services where the information can no longer reasonably be linked to the Controller, a vehicle, a user or another identifiable individual. Pseudonymised information remains personal data and shall continue to be protected under this DPA.
15 Documentation and Audits
Future Driver shall make available information reasonably necessary to demonstrate compliance with this DPA. This may include relevant policies and procedures, descriptions of technical and organisational measures, summaries of security assessments, relevant audit reports or certifications, and answers to reasonable security and privacy questionnaires.
If the available documentation is insufficient, the Controller may conduct an audit itself or through an independent auditor bound by confidentiality. Unless a personal data breach, supervisory authority request or credible evidence of material non-compliance requires earlier action, audits shall:
- be limited to once in any 12-month period;
- take place during normal business hours;
- be notified at least 30 days in advance;
- avoid unreasonable disruption to Future Driver's operations; and
- protect the confidentiality and security of other customers.
Each party bears its own costs of an audit. Future Driver shall cooperate with competent supervisory authorities as required by law.
16 Return and Deletion
During the customer relationship, the Controller may export personal data using available functions in the services or by making a reasonable support request. Data is retained in the services for the duration of the customer agreement unless the Controller instructs a shorter retention period.
When the services end, Future Driver shall, at the Controller's choice, return or delete personal data processed on behalf of the Controller unless applicable law requires continued storage. Return is provided in a commonly used, machine-readable format.
Deletion is performed in two steps. Data is first deactivated in the services (soft delete), so that it is no longer accessible to users, and then permanently deleted from production systems within 30 days of the Controller's instruction or the end of the services. Residual copies stored in protected backups are deleted through Future Driver's ordinary backup lifecycle, no later than 35 days after deletion from production systems. Until deletion, such copies remain protected and shall not be used for ordinary business purposes.
Future Driver may retain limited information that it processes as an independent controller, including contract, invoicing, security and legal compliance records.
17 Duration and Termination
This DPA applies for as long as Future Driver processes personal data on behalf of the Controller.
If Future Driver materially breaches this DPA, the Controller may require Future Driver to suspend the affected processing until compliance has been restored. If compliance cannot be restored within a reasonable period, the Controller may terminate the affected services in accordance with the customer agreement.
Future Driver may suspend processing that it reasonably believes would violate applicable data protection legislation or create an immediate and material security risk, and shall notify the Controller without undue delay.
18 Changes to this DPA
Future Driver may update this DPA to reflect changes in law, guidance from supervisory authorities or the services. Material changes are notified to the contact person registered for the Controller at least 30 days before they take effect. The current version and its effective date are always published on this page. Changes do not reduce the level of protection for personal data.
19 Governing Law and Venue
This DPA is governed by Norwegian law. Disputes shall first be addressed through negotiations between the parties. If the dispute cannot be resolved, Oslo District Court shall be the agreed venue, subject to mandatory rights and powers under applicable data protection legislation. This applies also after termination.
20 Contact
Questions about this DPA, subprocessors or Future Driver's processing of personal data may be sent to:
Delta Media AS, trading as Future Driver
Organisation number 916 747 330
Smalvollveien 58, 0667 Oslo, Norway
help@futuredriver.app | +47 21 05 14 05
Effective date: 01.09.2026