# DPP GRID DATA PROCESSING ADDENDUM

**Version 1.2 — 31 July 2026**

This Data Processing Addendum (**DPA**) forms part of the agreement between **Fleeta Limited trading as DPP Grid** (**DPP Grid**, **Processor**, **we**) and the customer identified in the applicable Service Terms, Order Form or Digital Product Passport Services and Registration Agency Agreement (**Customer**, **Controller**, **you**).

## 1. Scope and definitions

### 1.1 Scope

This DPA applies where DPP Grid processes Customer Personal Data on behalf of the Customer in providing the Services.

### 1.2 Definitions

**Applicable Data Protection Law** means the UK GDPR, Data Protection Act 2018, EU GDPR where applicable, PECR and other data-protection or electronic-communications law applicable to the processing.

**Customer Personal Data** means Personal Data contained in Customer Data and processed by DPP Grid solely on behalf of the Customer.

**Data Breach** means a personal data breach affecting Customer Personal Data.

**Restricted Transfer** means a transfer of Personal Data requiring an approved transfer mechanism under Applicable Data Protection Law.

**Sub-processor** means a third party appointed by DPP Grid to process Customer Personal Data on behalf of the Customer.

Terms such as **Personal Data**, **Controller**, **Processor**, **Data Subject**, **processing** and **Supervisory Authority** have the meanings given by Applicable Data Protection Law.

### 1.3 Independent-controller processing

This DPA does not govern Personal Data that DPP Grid processes as an independent Controller for account administration, billing, security, fraud prevention, contract and delegation evidence, legal compliance, service analytics or marketing. That processing is described in the DPP Grid Privacy Notice.

## 2. Processing particulars

The subject matter, duration, nature, purpose, types of Personal Data and categories of Data Subject are set out in Annex 1 and the applicable Order Form. The Customer's configuration, use of features and documented instructions provide additional detail.

## 3. Customer instructions and responsibilities

### 3.1 Instructions

DPP Grid will process Customer Personal Data only:

(a) on the Customer's documented instructions, including this DPA, the main agreement, Customer Account configuration, approved workflows, support instructions and authorised integration settings; or

(b) where required by applicable law, in which case DPP Grid will inform the Customer before processing unless the law prohibits notice.

### 3.2 Unlawful instructions

DPP Grid will inform the Customer if, in DPP Grid's reasonable opinion, an instruction infringes Applicable Data Protection Law. DPP Grid may suspend the affected processing while the Parties clarify or modify the instruction.

### 3.3 Customer responsibilities

The Customer is responsible for:

- providing lawful, fair and transparent instructions;
- having an appropriate lawful basis and notices;
- collecting only data necessary for the relevant purpose;
- responding to Data Subjects and authorities as Controller;
- deciding which Personal Data is published in a public passport;
- assessing whether special-category or high-risk data is appropriate; and
- configuring access rights and retention consistent with law.

## 4. Confidentiality and personnel

DPP Grid will ensure that people authorised to process Customer Personal Data:

- need access for their role;
- are bound by contractual or statutory confidentiality;
- receive appropriate data-protection and security guidance; and
- process the data only as permitted by this DPA.

Access will be reviewed and removed when no longer required.

## 5. Security

### 5.1 Measures

DPP Grid will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Current baseline measures are described in Annex 2.

### 5.2 Changes

DPP Grid may update security measures to reflect technology, risk and service changes, provided the overall protection is not materially reduced.

### 5.3 Customer controls

The Customer is responsible for secure account configuration, user permissions, credentials, endpoint security, connected applications, data minimisation and the accuracy of contact details used for incident notifications.

## 6. Sub-processors

### 6.1 General authorisation

The Customer gives DPP Grid general written authorisation to use the Sub-processors listed in the current DPP Grid Subprocessor and Third-Party Services Notice.

### 6.2 New or replacement Sub-processors

DPP Grid will give at least 15 days' notice before a new material Sub-processor begins processing Customer Personal Data, unless an urgent security, legal or service-continuity need makes shorter notice reasonable.

### 6.3 Objection

The Customer may object on reasonable data-protection grounds during the notice period. The Parties will work in good faith to address the objection. If no reasonable alternative is available, DPP Grid may allow the Customer to terminate the materially affected Service without penalty for the unused prepaid period.

### 6.4 Flow-down terms

DPP Grid will impose data-protection obligations on each Sub-processor that provide a substantially equivalent level of protection for the relevant processing. DPP Grid remains responsible to the Customer for the Sub-processor's performance to the extent required by law and contract.

### 6.5 Customer-connected services

A platform connected and selected directly by the Customer, such as Shopify, may be a separate Controller or a customer-appointed processor rather than DPP Grid's Sub-processor. The relevant service terms and configuration determine the role.

## 7. International transfers

### 7.1 Safeguards

DPP Grid will not make a Restricted Transfer of Customer Personal Data unless an approved safeguard or exception applies. Depending on the transfer, this may include:

- a UK or EU adequacy decision;
- EU Standard Contractual Clauses;
- the UK Addendum to the EU Standard Contractual Clauses;
- the UK International Data Transfer Agreement; or
- another mechanism recognised under Applicable Data Protection Law.

### 7.2 Incorporation

Where required, the applicable standard clauses are incorporated into this DPA by reference and completed using the information in the main agreement, Annex 1, Annex 2 and the Subprocessor Notice. If further signature or tables are legally required, the Parties will complete them promptly.

### 7.3 Assessments and supplementary measures

DPP Grid will conduct or support required transfer assessments and apply reasonable supplementary technical, contractual or organisational measures based on the risk.

## 8. Data Subject requests

### 8.1 Notice

If DPP Grid receives a request from a Data Subject relating to Customer Personal Data, DPP Grid will, where legally permitted, promptly notify the Customer and not respond substantively except on the Customer's instruction or where law requires.

### 8.2 Assistance

Taking into account the nature of processing, DPP Grid will provide reasonable technical and organisational assistance to help the Customer respond to rights requests, including access, correction, erasure, restriction, objection and portability.

### 8.3 Costs

Routine in-product tools are included in the Services. DPP Grid may charge reasonable Fees for substantial, unusual or repetitive assistance not caused by DPP Grid's breach, after informing the Customer.

## 9. Security incidents and Data Breaches

### 9.1 Notification

DPP Grid will notify the Customer without undue delay after becoming aware of a Data Breach and, where reasonably practicable, provide an initial notice within 48 hours.

### 9.2 Information

As information becomes available, DPP Grid will provide:

- the nature of the Data Breach;
- categories and approximate numbers of affected Data Subjects and records, where known;
- likely consequences;
- measures taken or proposed; and
- a contact for follow-up.

Information may be provided in phases. A notification is not an admission of fault or liability.

### 9.3 Cooperation

DPP Grid will reasonably assist the Customer with investigation, containment, remediation, regulatory notification and Data Subject communication, taking account of the nature of processing and information available.

### 9.4 Records

DPP Grid will document Data Breaches as required by law.

## 10. Assistance with compliance

Taking into account the nature of processing and information available, DPP Grid will reasonably assist the Customer with:

- security obligations;
- Data Breach assessment and notifications;
- data-protection impact assessments;
- prior consultation with a Supervisory Authority; and
- records and information reasonably needed to demonstrate the Customer's compliance relating to the Services.

DPP Grid may charge for substantial assistance not included in the plan and not caused by DPP Grid's breach.

## 11. Government and authority requests

Unless legally prohibited, DPP Grid will notify the Customer of a legally binding request for Customer Personal Data. DPP Grid will review the request, disclose only what it reasonably believes is legally required, and challenge an unlawful or disproportionate request where reasonable in the circumstances.

This clause does not prevent a Registry submission or authority disclosure expressly instructed or required as part of the Services.

## 12. Audits and information rights

### 12.1 Compliance information

DPP Grid will make available information reasonably necessary to demonstrate compliance with this DPA, which may include policies, summaries, questionnaires, independent reports or certifications where available.

### 12.2 Customer audit

If that information is insufficient, the Customer may conduct an audit or appoint an independent auditor, subject to:

- at least 30 days' written notice unless a Data Breach or authority requires shorter notice;
- no more than one routine audit in a 12-month period;
- normal business hours and minimal disruption;
- appropriate confidentiality and security restrictions;
- no access to another customer's data, privileged information or system vulnerabilities; and
- the Customer paying reasonable costs unless the audit identifies a material breach by DPP Grid.

### 12.3 Regulatory audit

The limits above do not prevent a competent Supervisory Authority from exercising its lawful powers.

## 13. Return and deletion

### 13.1 Customer choice

At the end of the Services, DPP Grid will, at the Customer's choice and subject to the main agreement, return or delete Customer Personal Data unless law requires retention.

### 13.2 Export period

The Customer should use available export tools before termination. Unless an Order Form states otherwise, DPP Grid will keep an available export accessible for at least 30 days after termination.

### 13.3 Backup rotation

Data may remain in protected backups until normal rotation, ordinarily no longer than 90 days after active deletion, unless a longer period is documented for resilience or legal reasons. During that period it will be beyond ordinary use and restored only for disaster recovery, after which deletion instructions will be reapplied.

### 13.4 Required continuity

Where a Digital Product Passport must remain accessible for a product-lifecycle or statutory period, the Parties must arrange continued hosting, transfer or backup before termination. Such continued availability is a service obligation under the main agreement, not a reason to retain unrelated Personal Data indefinitely.

## 14. Records and compliance

DPP Grid will maintain records of processing required of a Processor and cooperate with a competent Supervisory Authority as required by law.

## 15. Liability and priority

The liability provisions of the main agreement apply to this DPA. Nothing in this DPA limits liability that cannot lawfully be limited.

If this DPA conflicts with the main agreement on Processor obligations, this DPA prevails. Standard transfer clauses prevail to the extent required by their mandatory terms.

## 16. Term and termination

This DPA begins when DPP Grid first processes Customer Personal Data and continues until that processing ends and the data has been returned or deleted in accordance with clause 13.

## 17. Governing law

Unless mandatory data-protection or transfer terms require otherwise, this DPA is governed by the laws of England and Wales and the courts of England and Wales have exclusive jurisdiction.

---

# Annex 1 — Processing details

## Subject matter

Provision of the DPP Grid platform and selected services, including product-data import, supplier and evidence workflows, DPP creation, hosting, publication, lifecycle management, integrations, support, exports and, where activated, Registry preparation and submission.

## Duration

For the term of the Services and the deletion or return period described in this DPA, plus any separately agreed continuity period.

## Nature and purpose

Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, transmission, publication where instructed, restriction, backup, export, deletion and related technical processing necessary to provide the Services.

## Categories of Data Subject

Depending on Customer use:

- Customer employees, contractors and Authorised Users;
- supplier, manufacturer, importer, distributor and other value-chain contacts;
- sole traders and named compliance or safety contacts;
- signatories and authorised representatives;
- repairers, refurbishers, recyclers and professional service contacts;
- product owners or consumers where the Customer chooses to record lifecycle or ownership information; and
- individuals contacting support through the Customer.

## Types of Personal Data

Depending on Customer use:

- name, business contact details, title and organisation;
- account and permission data;
- identifiers and authority records;
- IP address, device and usage logs;
- signatures, acceptance records and audit trails;
- supplier, compliance, safety and evidence contacts;
- product ownership, repair or lifecycle records;
- free-text, files, images and documents uploaded by the Customer; and
- other Personal Data the Customer elects to process through supported fields.

## Special-category and criminal-offence data

Not intended or authorised by default. Any such processing requires a specific written agreement, documented lawful basis, necessity assessment and appropriate safeguards.

## Frequency

Continuous or as initiated by Customer users, connected systems, scheduled imports, public scans, support activity and approved workflows.

## Customer rights and obligations

As set out in the main agreement, this DPA, the Customer Account settings and Applicable Data Protection Law.

# Annex 2 — Baseline technical and organisational measures

The following measures describe the controls maintained by the current DPP Grid release. Their scope remains subject to the selected service, workspace entitlements and the signed agreement; no control is promised beyond what is enabled and evidenced for the customer.

## Governance and confidentiality

- documented access, security and incident responsibilities;
- confidentiality obligations for authorised personnel;
- security and privacy awareness appropriate to role;
- controlled onboarding and offboarding; and
- supplier due diligence for material Sub-processors.

## Identity and access management

- tenant-scoped server-side authorisation;
- role-based access for workspace users;
- strong password policy;
- multi-factor authentication for privileged access where available;
- session expiry and revocation controls;
- least-privilege administrative access; and
- periodic access review.

## Data protection and encryption

- TLS for data in transit;
- encryption of sensitive secrets and selected Personal Data at rest;
- private-by-default evidence storage;
- separation of public and restricted fields;
- secure key and secret management; and
- prohibition on customer secrets in source control.

## Application and infrastructure security

- CSRF protection, input validation and rate limiting;
- restricted file upload handling and malware or file-type controls appropriate to risk;
- security headers and content-security policy where applicable;
- dependency and vulnerability management;
- environment separation and controlled deployment;
- logging of privileged and material actions; and
- tested backup and rollback procedures.

## Availability and recovery

- scheduled backups appropriate to service tier;
- restoration tests or documented recovery checks;
- incident response and escalation process;
- monitoring of availability and material errors; and
- business continuity proportional to the Services.

## Tenant separation and auditability

- customer-scoped queries and object access;
- prevention of mixed-customer Registry batches unless expressly supported;
- immutable or append-only evidence for key approvals and submissions where appropriate;
- correlation identifiers for external operations; and
- retention and deletion jobs with auditable outcomes.

## Integration security

- OAuth or delegated access rather than password collection where supported;
- encrypted integration tokens;
- minimal scopes;
- webhook signature verification, idempotency and replay controls;
- credential-health and revocation handling; and
- no secret values in ordinary logs.

# Annex 3 — Sub-processors

The current list is maintained at the proposed route `/subprocessors` and forms part of this DPA. It must identify, for each material Sub-processor:

- legal name;
- service and processing purpose;
- relevant categories of Personal Data;
- processing location;
- transfer mechanism where relevant; and
- notice date for additions or replacements.

# Annex 4 — Contact points

DPP Grid privacy and security contact: **support@dppgrid.com**  
Customer privacy contact: the privacy contact recorded in the applicable Order Form or Customer Account.
