Legal
Data Processing Agreement
1. Parties, scope and instructions
1.1. This DPA forms part of the Terms between the Customer and Edge technologies MB, company code 308133888, registered address Savanorių pr. 243-73, Kauno m., Lietuva ("Processor"). It governs personal data processed on the Customer's behalf, not the Provider's separate controller activities described in the Privacy Policy.
1.2. The Customer acts as controller, or as a processor authorized by its controller to appoint Hawler as a subprocessor. References to the Customer's instructions include the relevant controller instructions it is authorized to pass on.
1.3. Processing comprises receiving, storing, organizing, validating addresses, calculating routes, generating assignments/results, retrieving, exporting and deleting operational data to provide Hawler. It continues during the agreement, including an active Starter account, and for the limited return/deletion period afterward.
1.4. Data subjects may include Customer personnel, drivers, delivery recipients, contacts and other people identified in submitted operational data. Data may include names/contact details where supplied, addresses, coordinates, vehicle identifiers and related jobs, schedules and route results. Special-category data and criminal-conviction data are not needed for ordinary routing and must not be submitted unless expressly agreed with appropriate safeguards.
1.5. The Terms, this DPA and Customer actions through supported features constitute documented instructions. Additional lawful instructions may be provided in writing. The Processor will process only on those instructions, including for international transfers, unless EU or Member State law requires otherwise; it will inform the Customer of such a requirement unless prohibited by law. It will promptly flag an instruction it considers contrary to applicable data-protection law.
2. Processor obligations
2.1. The Processor will ensure authorized personnel are subject to confidentiality obligations and restrict access to what is necessary.
2.2. It will maintain appropriate technical and organizational measures under GDPR Article 32, documented in Annex B, and will not materially reduce the agreed level of protection during the processing.
2.3. Taking account of the processing and information available, it will assist the Customer with data-subject requests, security, breach notification, data-protection impact assessments and prior consultation under GDPR Articles 32–36. It will promptly forward requests relating to Customer-controlled data and will not independently answer on the Customer's behalf unless authorized or legally required.
2.4. It will make information reasonably necessary to demonstrate compliance available and allow and contribute to audits, including inspections, by the Customer or its mandated independent auditor. Reasonable notice, confidentiality and safeguards for other customers may be agreed, but must not prevent effective verification or urgent/regulatory audits.
3. Subprocessors and transfers
3.1. The Customer grants general written authorization to engage subprocessors subject to this section. The current processing arrangements are described in Annex A. Before appointing a new subprocessor for Customer operational personal data, the Processor will provide its identity, functions, locations and relevant safeguards at least 14 calendar days before processing begins, allowing an objection on reasonable data-protection grounds. The same notice applies to a replacement.
3.2. If the Customer objects within that notice period, the parties will seek a reasonable solution before the proposed provider processes the affected data. If none is available, the Customer may terminate the affected Service before that processing begins and receive a proportionate refund of unused prepaid base fees.
3.3. The Processor will impose equivalent relevant data-protection obligations on subprocessors and remains responsible to the Customer for their performance of those obligations.
3.4. International transfers must comply with GDPR Chapter V and the documented instructions. Annex A identifies locations, including remote access, and the applicable transfer mechanism. Any required standard contractual clauses take precedence over conflicting provisions.
4. Personal data breaches
4.1. The Processor will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting data processed on the Customer's behalf. It will not wait for a complete investigation before giving the initial notification.
4.2. Available information will include the nature of the breach, affected data and data-subject categories and approximate numbers where known, likely consequences, measures taken or proposed, and a contact for follow-up. Missing information may be provided in stages without undue further delay. The Processor will assist the Customer's response and keep relevant records.
5. Return and deletion
5.1. Cancellation of paid renewal while the Customer retains a Starter account does not end all processing. On actual termination of the relevant processing, the Processor will, at the Customer's choice, return or delete the personal data and delete existing copies unless EU or Member State law requires retention.
5.2. Return, retrieval and deletion follow Terms section 9. Data is retained only for the agreed transition and retrieval period and then deleted from active systems. A verified instruction for earlier deletion is completed within 30 calendar days, subject to mandatory retention. Residual backups are removed within 30 calendar days after active-system deletion, remain protected and unavailable for ordinary use, and any necessary restoration will reapply the deletion instruction. Statutory switching and retrieval periods take precedence over a shorter contractual period.
5.3. Legally retained data remains protected and is processed only for the applicable legal purpose. The Processor will confirm completion of the agreed deletion process on request.
6. General provisions
6.1. Lithuanian law governs this DPA, subject to mandatory data-protection law and any applicable transfer clauses. The Terms' liability provisions apply only insofar as permitted by law; they do not restrict data-subject rights or supervisory powers. This DPA prevails over conflicting Terms on Customer personal-data processing.
Annex A — Processing arrangements and separate service providers
Customer operational personal data is processed by Edge technologies MB in its EU-based systems. No external address-processing or AI provider is authorized to receive that data under this DPA. Appointment of any operational-data subprocessor requires the notice and safeguards in section 3.
The following services concern billing or technical website/map use. Their inclusion does not authorize sending uploaded Customer operational records to them:
| Provider | Information and purpose | Role and locations |
|---|---|---|
| Stripe, including Stripe Payments Europe, Limited and relevant Stripe affiliates | Billing contacts/details, subscription information, payment/invoice records and usage quantities; payment processing, invoicing, tax and fraud prevention | Processor for relevant billing services and independent controller for its own purposes; international processing including the EU and US under Stripe's privacy and transfer terms |
| Google Analytics, provided through Google Ireland Limited and relevant Google affiliates | Marketing-site events and technical measurement information; understanding website use | Provider for Hawler's own website measurement, rather than a subprocessor for uploaded operational data; international processing including the EU and US under Google's applicable terms and safeguards |
| OpenStreetMap Foundation and its tile-delivery infrastructure | Browser/network requests and requested map area; delivery of background map images | Separate map-service processing under the Foundation's privacy policy; global tile-delivery network |
Provider privacy and transfer links appear in the Privacy and Cookie Policies. Contact info@hawler.eu for current information or relevant safeguards. Any change that introduces processing of Customer operational personal data remains subject to this DPA, irrespective of the provider's existing role for other purposes.
Annex B — Agreed security and deletion measures
The Processor shall maintain the following measures for Customer personal data:
- Encrypted public network connections and protection of stored personal data and backups through encryption and controlled access, with access to encryption keys restricted to authorized personnel.
- Authenticated access, organization-level authorization and separation of customer workspaces. Privileged access is limited to personnel who need it and removed when no longer required.
- Confidentiality obligations, secure handling procedures and access reviews for personnel with access to Customer personal data.
- Backups, a documented restoration procedure and periodic recovery tests; copies containing deleted data expire within the 30-day backup-deletion period.
- Timely security updates and risk-based vulnerability remediation, security logging with the retention limits in the Privacy Policy, and a process for investigating incidents and issuing the notifications in this DPA.
- Verified export/deletion requests, protected delivery of returned data and deletion from active systems and backups under Terms section 9. Restoring a backup must not permanently restore data already subject to deletion.
- Periodic review and testing of the effectiveness of these measures, and additional review after material changes or significant incidents. Compliance information is available through the audit arrangements in section 2.4.