Data Processing Agreement (DPA)
This DPA forms part of the Agreement based on the LiteTMS.eu Terms of Service between the Customer (the Controller) and CodeJungle Sp. z o.o., Kawki 51, 42-140 Panki, Poland, KRS: 0000722231, NIP: 5742064222, REGON: 369658794 (the Processor). Acceptance of the Terms also concludes this DPA in electronic form. It applies where CodeJungle processes personal data on the Customer's behalf.
§1. Scope, purpose, operations, and duration
- The subject matter is the processing needed to provide and secure the Customer's LiteTMS workspace, including hosting, storage, organisation, retrieval, display, transmission at the Customer's request, support, backup, deletion, and operation of activated integrations.
- The purpose is to provide the SaaS transport-management functions selected by the Customer. The nature of processing is automated and, where authorised support requires it, limited manual access.
- This DPA lasts for as long as the Processor holds Customer Personal Data. Termination, transition, return, retrieval, and deletion are governed by §7 and the Terms.
- For account administration, billing, fraud prevention, security records, and compliance duties where CodeJungle determines the purpose and means, CodeJungle acts as an independent controller under the Privacy Policy; those activities are outside this DPA.
§2. People and data covered
- Data subjects may include the Customer's authorised users, employees, drivers, candidates, representatives, contractors, carriers, suppliers, customers, recipients, senders, contacts, and other people identified in Customer Content.
- Data may include names and identifiers; contact, account, authentication, professional and employment data; signatures; communications; order, route, vehicle-linked and location data; financial and settlement data; documents, images, audio and attachments; device, usage, and audit data; and other data the Customer chooses to enter.
- The service is not intended for routine processing of special-category data or criminal-conviction data. The Customer must not enter it unless this is necessary and lawful, the Customer has assessed the risk and applicable Art. 9 or 10 GDPR condition, and the parties have agreed any additional safeguards reasonably required.
§3. Documented instructions
- The Processor acts only on the Customer's documented instructions, including for international transfers, unless EU or Member State law requires otherwise. In that case it will inform the Customer before processing unless the law prohibits notice on important public-interest grounds.
- The Terms, this DPA, the Customer's settings and use of System functions, support requests, and written directions accepted by the Processor are documented instructions. An instruction outside the agreed service may require a separate scope and fee.
- The Processor will promptly tell the Customer if, in its opinion, an instruction infringes data-protection law. It may suspend only the affected processing until the instruction is changed, confirmed lawful, or withdrawn.
- The Customer remains responsible for the lawfulness, fairness, accuracy, transparency, and minimisation of Customer Personal Data, for notices and data-subject requests, and for the instructions it gives. The Customer must configure permissions and retention appropriately and must not instruct unlawful processing.
§4. Processor duties and assistance
- The Processor ensures that people authorised to process Customer Personal Data are bound by confidentiality and receive access only as needed.
- Taking account of the state of the art, implementation costs, and the nature, scope, context, purposes, and risk, the Processor maintains measures appropriate under Art. 32 GDPR. The current core measures are listed in Annex 1.
- Taking account of the nature of processing and information available to it, the Processor reasonably assists the Customer with data-subject requests and compliance with Arts. 32–36 GDPR, including security, breach notification, impact assessments, and prior consultation.
- The Processor will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and, where feasible, aims to give initial notice within 48 hours. It will provide the information available about the nature and likely consequences, affected data and people, measures taken or proposed, and a contact point. Information may be supplied in phases. Notification is not an admission of fault.
- The Processor will make available information reasonably necessary to demonstrate compliance with Art. 28 GDPR and this DPA.
§5. Sub-processors and international transfers
- The Customer gives general written authorisation to use sub-processors needed for the service. Depending on activated features, the current categories and provider brands include: OVHcloud (hosting); Cloudflare (network security, Turnstile, and R2 storage of files and backups); Amazon Web Services (alternative or additional storage of files and backups, §5.9); EmailLabs (e-mail); SMSAPI.pl (SMS); Google Firebase Cloud Messaging (push); the configured Umami host (service analytics); HERE, Google Maps Platform, Mapbox, and the configured Protomaps source (maps/routing); Fakturownia.pl (invoicing); OpenRouter (routing of AI requests) and the AI model providers described in §5.7 (AI features); and ElevenLabs (speech-to-text voice transcription and text-to-speech voice playback of translated messages, covering voice recordings and the message text sent for synthesis). Stripe generally acts as an independent controller for regulated payment processing rather than as a sub-processor under this DPA.
- The Processor will provide, before an applicable provider first processes Customer Personal Data, the provider's full legal identity, business address, contact point, function, processing location, and applicable transfer safeguard. It will keep that information current and make a copy available to the Customer at any time at contact@litetms.eu. A brand above may be supplied by a different group entity depending on the Customer's deployment and the provider account.
- The Processor will give at least 14 days' advance notice by e-mail or a durable System message before a new sub-processor starts processing Customer Personal Data, including its identity, function, and processing location. An urgent replacement may take effect sooner only where delay would create a material security or service-continuity risk; notice will follow without undue delay and the Customer retains the objection rights below.
- The Customer may object during the notice period, or without undue delay after an urgent notice, on reasonable, documented data-protection grounds. The parties will try in good faith to use a reasonable alternative. If none is available, either party may discontinue the affected feature; the Customer may terminate the affected service without penalty. Unless the urgent-replacement rule above applies, the new sub-processor will not begin processing before the objection period ends.
- The Processor imposes substantially the same data-protection obligations on each sub-processor by contract and remains liable to the Customer for the sub-processor's performance as required by Art. 28(4) GDPR.
- Core hosting and storage are in the EU. For a restricted transfer, the Processor uses a lawful GDPR Chapter V mechanism, such as an adequacy decision (including the EU-US Data Privacy Framework for a participating recipient) or the European Commission's Standard Contractual Clauses with supplementary measures where appropriate. On request, it will provide relevant safeguard information or a copy, subject to necessary redactions.
- AI model providers. OpenRouter passes each AI request to the provider of the selected AI model or to a provider operating an endpoint for that model (an "AI model provider"). The Processor may select, replace, or combine AI models without a new notice under §5.3 if: (a) the AI model provider is included in the sub-processor information provided under §5.2; (b) text requests go only to endpoints that OpenRouter identifies as not storing request content beyond processing the request (zero data retention) and not using it for training, and a request is not processed if no such endpoint is available; and (c) any transfer outside the EEA is covered under §5.6. Using an AI model provider that is not yet included in that information is the engagement of a new sub-processor under §5.3. Condition (b) does not cover voice recordings sent through OpenRouter for transcription; the retention terms of the provider serving them apply.
- Services the Customer chooses. A service that the Customer or its users connect to the System under their own account or authorisation with its provider, such as an AI app connected through the LiteTMS MCP server or a telematics account configured by the Customer (a “Customer-selected service”), is not a sub-processor: the Processor does not engage its provider, so §5.1 to §5.5 and §5.7 do not apply to it. A connection made by the Customer, or by a user while the Customer allows such connections in the System, is the Customer's documented instruction under §3 to transmit to that service, and to receive from it, the Customer Personal Data that the connection and the user's permissions cover. Where that transmission is a transfer outside the EEA, the Customer instructs the Processor to rely on the transfer basis available for that provider, such as an adequacy decision covering it (including the EU-US Data Privacy Framework where the provider participates) or the safeguards in the Customer's agreement with the provider, and the Customer is responsible for ensuring that such a basis exists before it allows the connection. As between the parties, the Customer is also responsible for choosing the service, for its agreement with the provider, for the lawfulness of the transmission, and for the provider's processing. The Processor remains responsible for the security and correct operation of the connection within its control, transmits only what the connection covers, and lets the Customer end a connection in the System. A provider named in §5.1 remains a sub-processor for the processing described there. This paragraph does not affect a data subject's rights under Art. 82 GDPR or the Processor's liability for its own breach.
- Storage of files and backups. Stored files and encrypted backups are kept in Cloudflare R2. The Processor may also keep them, or copies of them, with Amazon Web Services, or move them between these two providers, without a new notice under §5.3 if: (a) the data stays in the EU; and (b) backups are encrypted before they leave the Processor's systems. Storing them with any other provider is the engagement of a new sub-processor under §5.3. Whichever provider holds them, backups are kept and deleted as §7.3 provides.
§6. Reviews and audits
- The Processor will first provide available security and compliance information, questionnaires, or independent reports where these reasonably meet the Customer's need.
- If further verification is reasonably necessary, the Customer or an independent auditor bound by confidentiality may conduct an audit. Unless a breach, regulator, or urgent risk justifies shorter notice, the Customer gives at least 14 days' notice. Audits occur during normal business hours, no more than once per year, and must avoid access to other customers' data, security compromise, or unreasonable disruption.
- The Processor bears its ordinary cost of demonstrating compliance. The Customer bears its auditor's costs and the Processor's reasonable, pre-agreed cost of exceptional, customer-specific work, unless the audit identifies a material Processor breach. Nothing in this paragraph restricts a competent authority or makes mandatory cooperation conditional on payment.
- The Customer will promptly provide the Processor with the audit findings. Each party protects the other's confidential and security-sensitive information.
§7. Return, transition, and deletion
- During the contract, the Customer may use available export functions. On termination it may choose return or deletion, subject to the transition and retrieval rights in §15 of the Terms. If it does not make a different lawful choice, the Processor keeps data available through the applicable retrieval period and then deletes it from active systems.
- The Processor deletes or returns Customer Personal Data and deletes existing copies after the agreed retrieval period, unless EU or Member State law requires retention. It will confirm completion on request.
- Data in disaster-recovery backups is put beyond ordinary use and access, is not restored except for disaster recovery, and expires under the documented rotation cycle, which may take up to 12 months. If a backup is restored, applicable deletions are reapplied.
§8. Liability and order of documents
- The liability rules in §16 of the Terms apply to this DPA. No limitation restricts a data subject's rights under Art. 82 GDPR, a regulator's powers, or liability that mandatory law does not allow the parties to limit. Administrative fines remain payable by the person on whom they are imposed.
- If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA prevails. An individually signed data-processing agreement prevails over this online DPA for its subject matter.
- Polish law governs, without prejudice to the GDPR or other mandatory law. The jurisdiction provision in the Terms applies.
Annex 1. Core technical and organisational measures
- TLS encryption for data in transit;
- logical tenant separation and access controls;
- individual authentication, role-based permissions, and two-factor authentication functionality;
- host-only, HttpOnly authentication cookies and controlled session lifetimes;
- audit and security logging;
- automated backups, restricted ordinary access, and a defined rotation cycle;
- limited staff access based on role and need;
- security-event and personal-data-breach handling;
- sub-processor review and contractual data-protection obligations;
- controlled deletion from active systems and isolation of backup copies until expiry.
Measures may evolve with risk and technology, provided the overall level of protection is not materially reduced during the contract.