1. Parties and how this DPA applies
This Data Processing Agreement (DPA) is between Pro Mapping Software Ltd, trading as Lorry Route, a company registered in England and Wales under number 11607946, whose registered office is at 124 City Road, London EC1V 2NX (Lorry Route), and the business or organisation that subscribes to the Services (the Customer).
Background
- (A) Lorry Route provides HGV, coach, bus and van route planning, fleet management and turn-by-turn navigation software to the Customer under the Lorry Route Terms and Conditions and any order form or subscription (together, the Main Agreement).
- (B) In providing the Services, Lorry Route processes personal data on the Customer's behalf, for example the details of the Customer's drivers and fleet managers.
- (C) This DPA meets the requirements of Article 28 of the UK GDPR and forms part of the Main Agreement.
How this DPA applies
1.1 This DPA applies automatically from the date the Customer accepts the Main Agreement, creates an account or first uses the Services, whichever is earliest. No signature is needed.
1.2 If the Customer processes Customer Personal Data as a processor for another controller, the Customer confirms it is authorised to give the instructions in this DPA, and Lorry Route acts as its Sub-processor on the same terms.
2. Definitions
2.1 In this DPA, controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings given in the UK GDPR.
2.2 The following terms also apply:
Applicable Data Protection Law: The UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other UK data protection legislation in force, each as amended (including by the Data (Use and Access) Act 2025)
UK GDPR: The retained EU law version of Regulation (EU) 2016/679 as it forms part of the law of the United Kingdom
Services: The route planning, fleet management, navigation and route sharing services Lorry Route provides under the Main Agreement
Customer Personal Data: Personal data processed by Lorry Route on behalf of the Customer in providing the Services, as described in Schedule 1
Sub-processor: Any third party appointed by Lorry Route to process Customer Personal Data
Restricted Transfer: A transfer of Customer Personal Data to a country or organisation outside the UK that is subject to Chapter V of the UK GDPR
IDTA: The International Data Transfer Agreement issued by the ICO under section 119A of the Data Protection Act 2018
UK Addendum: The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the ICO
2.3 References to legislation include that legislation as amended or replaced from time to time.
3. Roles, scope and instructions
3.1 For Customer Personal Data, the Customer is the controller and Lorry Route is the processor. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Schedule 1.
3.2 Lorry Route will process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless required to do otherwise by UK law. In that case Lorry Route will tell the Customer of the legal requirement before processing, unless the law prohibits it from doing so.
3.3 The Main Agreement, this DPA, and the Customer's use and configuration of the Services are the Customer's complete documented instructions at the date of this DPA. Further instructions must be given in writing and, if they go beyond the Services, may be subject to reasonable additional charges agreed in advance.
3.4 Lorry Route will tell the Customer promptly if, in its opinion, an instruction infringes Applicable Data Protection Law. Lorry Route may suspend the relevant processing until the Customer confirms or amends the instruction.
3.5 The Customer confirms that it has a lawful basis under Article 6 of the UK GDPR for the processing it instructs, and that it has given drivers and other data subjects the transparency information required by Articles 13 and 14. The Customer is responsible for the accuracy and lawfulness of the Customer Personal Data it provides.
3.6 Lorry Route acts as an independent controller, and not under this DPA, for personal data it holds about the Customer's account holders for its own billing, account management, security and legal compliance purposes, as described in the Lorry Route Privacy Policy.
4. Processor obligations
Confidentiality
4.1 Lorry Route will ensure that everyone authorised to process Customer Personal Data is bound by a duty of confidentiality, by contract or by statute, and processes it only as needed to provide the Services.
Security
4.2 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, Lorry Route will implement appropriate technical and organisational measures to protect Customer Personal Data as required by Article 32 of the UK GDPR. As a minimum these include the measures in Schedule 2.
Sub-processors
4.3 The Customer gives Lorry Route general authorisation to use the Sub-processors listed in Schedule 3.
4.4 Lorry Route will give the Customer at least 30 days' notice, by email to the Customer's account contact or by publishing the updated Schedule 3 on its website, before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within 14 days. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees for the remaining term.
4.5 Lorry Route will enter into a written contract with each Sub-processor that imposes data protection obligations no less protective than this DPA, and remains fully liable to the Customer for each Sub-processor's performance.
Data subject requests
4.6 Taking into account the nature of the processing, Lorry Route will assist the Customer by appropriate technical and organisational measures in responding to requests from data subjects to exercise their rights under Chapter III of the UK GDPR.
4.7 If Lorry Route receives such a request directly, it will not respond except to tell the requester to contact the Customer, and will forward the request to the Customer within 5 working days.
Personal data breaches
4.8 Lorry Route will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
4.9 The notification will, as far as known, describe the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Lorry Route will provide further information as it becomes available and will help the Customer meet its obligations under Articles 33 and 34.
Assistance
4.10 Lorry Route will give the Customer reasonable assistance with its obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to Lorry Route.
Return and deletion
4.11 On termination or expiry of the Services, Lorry Route will, at the Customer's choice, return or delete Customer Personal Data. The Customer may export its data through the Services at any time before termination. If the Customer gives no instruction within 30 days after termination, Lorry Route will delete the data within a further 60 days.
4.12 Lorry Route may keep Customer Personal Data to the extent UK law requires it, and will continue to protect it under this DPA. Deletion from backups will occur in line with the normal backup cycle, not later than 90 days after deletion from live systems.
Audits and information
4.13 Lorry Route will make available to the Customer all information necessary to show compliance with Article 28 of the UK GDPR and this DPA.
4.14 Lorry Route will allow and contribute to audits, including inspections, by the Customer or an auditor the Customer appoints, no more than once in any 12 months (unless a personal data breach or a regulator requires otherwise), on at least 30 days' written notice, during business hours, subject to reasonable confidentiality terms and without unreasonable disruption to Lorry Route's business. The Customer bears the cost of any audit. Lorry Route may satisfy an audit request in the first instance by providing recent independent audit reports or certifications, where these exist and cover the relevant controls.
5. International transfers
5.1 Lorry Route will not make a Restricted Transfer of Customer Personal Data unless one of the following applies:
- the destination is covered by UK adequacy regulations under Article 45 of the UK GDPR (including the UK Extension to the EU-US Data Privacy Framework, where the recipient is certified);
- the transfer is protected by the IDTA or the UK Addendum, which the parties agree will be entered into between Lorry Route (or its Sub-processor) and the recipient before the transfer takes place; or
- another appropriate safeguard or exception under Chapter V of the UK GDPR applies.
5.2 Lorry Route will carry out and document a transfer risk assessment where the transfer mechanism requires one, and will make it available to the Customer on request.
5.3 As at the date of this DPA, the locations of processing and any Restricted Transfers are as stated in Schedule 3.
6. Term, liability and governing law
6.1 This DPA starts on the date set out in section 1.1 (or, if earlier, when Lorry Route first processes Customer Personal Data) and continues for as long as Lorry Route processes Customer Personal Data on the Customer's behalf. Sections 4.11 and 4.12 and any other provision intended to survive will continue after termination.
6.2 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Main Agreement. Nothing in this DPA limits liability that cannot be limited by law, or a data subject's rights against either party under Article 82 of the UK GDPR.
6.3 If there is a conflict between this DPA and the Main Agreement on the processing of personal data, this DPA prevails. If there is a conflict between the body of this DPA and a Schedule, the body prevails, and if the IDTA or UK Addendum applies to a transfer, its terms prevail over this DPA for that transfer.
6.4 Lorry Route may update this DPA where needed to reflect changes in Applicable Data Protection Law, by publishing the updated version on its website and emailing the Customer at least 30 days before it takes effect. Any other change must be agreed in writing and signed by both parties.
6.5 This DPA and any non-contractual obligations arising from it are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction, subject to any different jurisdiction clause in the IDTA or UK Addendum for a Restricted Transfer.
7. Acceptance and contact
7.1 The Customer accepts this DPA in the way described in section 1.1, and the parties agree that it is legally binding without a handwritten or electronic signature.
7.2 Questions about this DPA, requests for a countersigned copy, and notices under it can be sent to Lorry Route at hello@lorryroute.com or to its registered office.
Schedule 1 – Details of processing
Subject matter: Provision of the Lorry Route route planning, fleet management, navigation and route sharing Services to the Customer
Duration: The term of the Main Agreement, plus the return and deletion period in sections 4.11 and 4.12
Nature of processing: Collection, storage, organisation, retrieval, use, transmission (including by email and SMS route sharing), backup and deletion
Purpose: To plan compliant routes for the Customer's vehicles, assign and share routes with drivers, provide turn-by-turn navigation, keep route history, and support and secure the Services
Data subjects: The Customer's fleet managers and other authorised users; the Customer's drivers; any other individuals whose details the Customer enters into the Services (for example delivery contacts in route notes)
Personal data: users and drivers: Name, work email address, work phone number, login credentials, user activity logs, IP address and device information
Personal data: routes and vehicles: Routes assigned to or shared with named drivers, route history, start, end and waypoint addresses, vehicle registration and profile linked to a driver, device location during active navigation, journey time and distance estimates
Special category data: None intended. The Customer must not enter special category or criminal offence data into the Services
Frequency: Continuous, for the duration of the Services
Retention: For the term of the Main Agreement, then returned or deleted under sections 4.11 and 4.12. Route history is kept while the account is active unless the Customer deletes it sooner
Schedule 2 – Security measures
Lorry Route will maintain at least the following measures.
Encryption: Customer Personal Data encrypted in transit (TLS 1.2 or higher)
Access control: Role-based access on a need-to-know basis; unique user IDs; multi-factor authentication for staff with access to production systems; access reviewed at least annually and removed promptly when staff leave
Customer accounts: Password rules for portal and mobile app logins
Hosting and infrastructure: Hosted with Digital Ocean in London; network segregation, firewalls and monitoring; production separated from test environments
Logging and monitoring: Security logging of access and administrative actions; alerts for unusual activity
Backups and resilience: Regular encrypted backups; documented disaster recovery and business continuity plan
Incident response: Documented incident response procedure, with roles, escalation and breach notification to the Customer in line with section 4.8
Staff: Confidentiality obligations in employment or engagement contracts
Physical security: Office access controls; no Customer Personal Data stored on removable media
Data minimisation and deletion: Only data needed for the Services is collected; deletion routines for closed accounts and expired data under sections 4.11 and 4.12
Schedule 3 – Approved sub-processors
The Customer authorises the following Sub-processors.
Digital Ocean: Hosting of the Lorry Route application, databases and backups - UK
Twilio/Sendgrid: Sending routes to drivers by SMS/Emails

