Fleet Log← Back to site

Data processing agreement

The processor terms under which App-Artery handles a workshop's records.

VersionKE-2026-08-29In effect29 August 2026Applies toKenya
RegionUnited KingdomKenya

Contents

  1. Roles
  2. Subject matter and duration
  3. Sub-processors
  4. Processing outside Kenya
  5. Security measures
  6. Confidentiality
  7. Assisting the controller
  8. Deletion and return
  9. Audit

Roles

This agreement applies where App-Artery processes personal data on a workshop's behalf, and is made under the Data Protection Act 2019. It forms part of our terms of service.

The workshop is the data controller. App-Artery is the data processor. The workshop decides what personal data is recorded and why; we process it only on the workshop's documented instructions, which include the instructions given by using the features of the service.

We will tell the workshop if we believe an instruction breaches the Act.

Subject matter and duration

Subject matter: providing workshop management software.

Duration: for as long as the workshop holds an account, and for any period afterwards during which we are required to retain records.

Nature and purpose: storing, organising and displaying records of customers, vehicles and work carried out on them, and sending emails the service generates.

Categories of data subject: the workshop's customers, and the workshop's own staff who hold accounts.

Categories of personal data: names, telephone numbers, email addresses, postal addresses, vehicle registrations and vehicle details, service and repair history, and prices charged. No sensitive personal data as defined by the Act is required by the service, and it should not be entered into it.

Sub-processors

The workshop authorises the following sub-processors:

  • Amazon Web Services (AWS): hosting, database and storage, in the London region, eu-west-2.
  • Amazon Simple Email Service (AWS SES): transactional email, being invitations and password resets.

We will give notice before adding or replacing a sub-processor, and the workshop may object on reasonable data protection grounds.

Processing outside Kenya

The workshop's personal data is processed in the United Kingdom, in the AWS London region. This is a transfer of personal data outside Kenya and the workshop should be aware of it before entering customer records.

The transfer is necessary for the performance of our contract with the workshop, and the United Kingdom affords a standard of data protection comparable to that required by the Act. The data concerned is ordinary commercial record-keeping for vehicle servicing, and is not within the categories for which the Act requires processing through a server situated in Kenya.

If we intend to process the data anywhere else, we will give notice first and put an appropriate safeguard in place before any transfer.

Security measures

The measures below are the ones actually in place. We have deliberately not listed anything we do not do.

  • Data encrypted at rest, and in transit over TLS.
  • The database is not reachable from the internet; it sits in private subnets and accepts connections only from the application.
  • Role-based access control within the application, with four roles, so that staff see only what their role allows. A workshop's records are separated from every other workshop's at the point of every query.
  • Passwords stored using a one-way hash, never in a recoverable form.
  • Access to production systems restricted to App-Artery personnel who need it.
  • Daily backups, retained for seven days.

We do not currently hold ISO 27001, SOC 2 or an equivalent certification, we do not carry out formal penetration testing, and we do not operate 24-hour monitoring. We would rather say so than imply otherwise.

Confidentiality

Anyone we authorise to process the workshop's personal data is bound by a duty of confidence.

Assisting the controller

We will help the workshop respond to requests from data subjects, and to meet its obligations on security, breach notification and data protection impact assessments, taking into account what we know and what the service can do.

If we become aware of a personal data breach affecting the workshop's data, we will tell the workshop without undue delay and give them what we know, so that they can notify the Office of the Data Protection Commissioner within the period the Act allows.

Deletion and return

On request, and at the end of the agreement, we will delete or return the workshop's personal data. Deleting a customer in the application removes their record and everything attached to it immediately.

We keep only what law requires us to keep, and for no longer than it requires.

Audit

We will make available the information reasonably needed to show that we are meeting this agreement, and will contribute to an audit conducted by the workshop or an auditor it appoints, on reasonable notice and no more than once a year unless a breach or the Data Commissioner requires otherwise.

© 2026 App-Artery · Fleet LogCambridge, UK · Nairobi, KE