Data Processing Addendum (UK)
Edition 2 September 2026
Download PDF · 14 pages · 161 KB- Provider
- Onroute Intelligence, Inc.
- Incorporated into
- The Subscription Terms (UK), clause 5.2
- Edition
- 2 September 2026
Parties
Onroute Intelligence Inc. Data Processing Addendum (United Kingdom)
Edition: 2 September 2026.
This Data Processing Addendum (“DPA”) is entered into between Onroute Intelligence Inc., a corporation incorporated in the State of Delaware, USA, whose registered office is at 251 Little Falls Drive, Wilmington, Delaware 19808, USA (“Onroute”) and your organisation (“Customer”) (each a “Party” and together the “Parties”).
Background
During the provision of the Services (as defined in the Onroute Subscription Terms), Onroute will Process Personal Data as a Processor (each as defined below) on behalf of Customer.
Pursuant to clause 5.2 of the Onroute Subscription Terms entered into by the Parties, this DPA is incorporated into the Onroute Subscription Terms, and this DPA shall apply to all Processing of Customer Personal Data (as defined below) by Onroute on behalf of the Customer.
The Parties agree as follows:
Clause 1 Definitions and Interpretation
Expressions defined in the Onroute Subscription Terms that are not defined in this DPA shall have the same meaning in this DPA.
In the event of any conflict between any terms of the Onroute Subscription Terms and this DPA, this DPA shall take priority. In this DPA, references to “Clauses” are to clauses of this DPA.
The definitions clause of the Onroute Subscription Terms is amended to include the following definitions:
| Term | Meaning |
|---|---|
| “Applicable Data Protection Laws” | any applicable legislation in force from time to time relating to the protection of personal data of individuals including, where applicable, the UK GDPR (as defined in section 3 of the Data Protection Act 2018) and the Data Protection Act 2018; |
| “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Process” and “Processing” | shall have the respective meanings given to them (and equivalent expressions) in Applicable Data Protection Laws, and “Customer Personal Data” means the Personal Data set out in the Description of Processing where such data is Processed by Onroute as a Processor on behalf of Customer; |
| “Data Protection Clauses” | all provisions contained in Clauses 1.4 and 2 of this DPA, the Description of Processing and any International Data Transfer Agreement or standard contractual clauses entered into between the Parties pursuant to Clause 2.2.5 of this DPA (including as completed in Schedule 2); and |
| “Description of Processing” | the description of Processing in Schedule 1 to this DPA; |
| “Liability” or “Liabilities” | all direct and indirect: losses, damages, charges, expenses, reasonable legal and other professional costs awarded against, suffered, incurred or paid by Onroute; |
| “Onroute Personnel” | any employees, staff, workers, agents or consultants of any companies in Onroute’s group of companies; |
| “Related Persons” | companies in Customer’s or Onroute’s group of companies (as applicable) and their employees, officers, shareholders, Affiliates, representatives, agents, consultants, contractors, suppliers and advisers. |
In the Data Protection Clauses (unless the context requires otherwise):
an obligation of any Party to indemnify any person against a Liability is to be construed as including an obligation to indemnify and hold harmless and keep that person indemnified on demand and in full from and against each Liability incurred as a result of suffering, defending or settling a claim alleging that Liability; and
references to “writing” and “written” shall include email but not fax.
Clause 2 Data Protection
The Parties agree that Customer is a Controller and that Onroute is a Processor for the purposes of Processing the Customer Personal Data pursuant to this DPA.
In respect of any Customer Personal Data Processed by Onroute, Onroute shall:
implement appropriate technical and organisational measures to protect against Personal Data Breaches affecting Customer Personal Data;
be generally authorised by Customer in writing to engage with any other Processor to Process the Customer Personal Data (“Sub-Processor”) subject to Onroute notifying the Customer of any intended changes concerning the addition or replacement of Sub-Processor(s) and permitting Customer to object to such changes in writing within ten (10) days from the date that it is notified by Onroute. If no objection is received by Onroute within such time period, Customer shall be deemed to have given its approval to use such Sub-Processor. Onroute shall use its reasonable (but commercially prudent) endeavours to ensure that any Sub-Processor agrees in writing to comply with obligations materially equivalent to those imposed on Onroute in this Clause 2. If Customer does not consent to use of such Sub-Processors, Onroute shall be entitled to terminate the Services and this DPA immediately by notice in writing. A list of Onroute’s current Sub-Processors is published as part of Onroute’s Trust and Compliance documentation at https://www.onroute.io/trustandcompliance (or a successor location notified to Customer);
only Process Customer Personal Data in accordance with Customer’s documented instructions from time to time except to the extent necessary to comply with applicable law. For the avoidance of doubt, the provisions of this DPA are not instructions for the purposes of this Clause 2.2.3;
notwithstanding Clause 2.2.3, have no obligation to comply (nor any Liability for non-compliance) with any of Customer’s instructions which will or are likely to (in Onroute’s opinion): (a) vary the provisions of this DPA; (b) be inconsistent with the Description of Processing; or (c) breach any Applicable Data Protection Laws, and shall notify Customer in writing of the same. The Customer shall seek its own independent legal advice to determine whether any instruction received by Onroute and which Onroute believes is infringing is in fact infringing or likely to be infringing;
not transfer any Customer Personal Data outside of the UK or European Economic Area (“EEA”) if such transfer would directly cause Customer to breach its obligations under Article 44 of the UK GDPR. Subject to the foregoing provisions of this Clause 2.2.5, Customer hereby consents to Onroute and its Sub-Processors transferring Customer Personal Data outside the UK or EEA. Where such a transfer is a restricted transfer for the purposes of the UK GDPR, it shall be made under the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018 and in force from 21 March 2022 (the “IDTA”), as completed in Schedule 2 to this DPA, which is incorporated into and forms part of this DPA; save that, where the recipient is certified under and the transfer is covered by the UK Extension to the EU–US Data Privacy Framework (or another adequacy regulation or adequacy decision then in force under the UK GDPR), the transfer may instead be made in reliance on that framework or adequacy for so long as it applies. For the purposes of the IDTA, Customer is the data exporter and the relevant recipient is the data importer, and Customer’s entry into the Onroute Subscription Terms and this DPA is treated as its entry into the IDTA as provided in clause 5.2 of the Onroute Subscription Terms. Customer shall promptly complete or enter into any further transfer documentation that Onroute reasonably requires in order to comply with the Data Protection Clauses and/or Applicable Data Protection Laws;
ensure that all Onroute Personnel who have access to and/or Process Customer Personal Data are committed to keeping Customer Personal Data confidential;
notify Customer without undue delay and in writing if Onroute becomes aware of a breach of security of Customer Personal Data, together with particulars of the breach to the extent available to Onroute;
provide such assistance (at Customer’s cost and to such extent permitted by Applicable Data Protection Laws) as Customer may reasonably require in responding to any request from a Data Subject and in ensuring compliance with its obligations under Applicable Data Protection Laws with respect to security, breach notifications, impact assessments, consultations with a supervisory authority, and (where applicable) automated decision-making and AI-transparency requirements. In no event shall Onroute be obliged to respond directly to any such request or correspondence unless specifically required to do so by law; and
for the sole purpose of demonstrating Onroute’s compliance with the Data Protection Clauses, provide such information as Customer reasonably requires, or, where the provision of information alone is not reasonably sufficient for that purpose, allow for and contribute to an audit of Onroute by up to two (2) of Customer’s representatives (in each case, at Customer’s cost, including any auditors’ or administrative fees). Customer shall give not less than one (1) month’s prior written notice prior to the date it wishes to conduct the audit and shall conduct any such audit no more than once per calendar year at such time and date that is convenient for Onroute (except where required otherwise by a supervisory authority with competent jurisdiction). Any non-compliance discovered by such audit will be promptly notified by Customer to Onroute in writing. Customer shall not disclose to any third party (other than, where applicable, the external auditor performing the audit) any information or reports obtained or produced in connection with any such audit and shall use such information and reports solely for the purposes of meeting its regulatory audit requirements and/or confirming Onroute’s compliance with the requirements of the Data Protection Clauses. Customer shall ensure that it takes reasonable steps and any steps requested by Onroute to minimise any interruption to the business of Onroute when exercising its rights under this Clause 2.2.9. If a third party conducts the audit, Onroute may object to the auditor if the auditor is, in Onroute’s reasonable opinion, not suitably qualified or independent, a competitor of Onroute, or otherwise manifestly unsuitable. Such objection by Onroute will require Customer to appoint another auditor or conduct the audit itself;
not use, and shall procure that its Sub-Processors do not use, any Customer Personal Data to train, fine-tune or otherwise develop any artificial-intelligence or machine-learning model in any form that identifies, or can reasonably be used to identify, any individual; except that Onroute may aggregate, anonymise or de-identify Customer Personal Data so that it no longer constitutes Personal Data (and cannot reasonably be used by any person to identify any Data Subject) and may use the resulting data solely to operate, secure, analyse, develop, train and improve its own systems, products and services (including through third-party providers of artificial-intelligence models and services engaged as Sub-Processors to host, train, fine-tune or evaluate models for Onroute), and not to make that data or any resulting model available to any third party for that third party’s own purposes, and Onroute will not authorise any third party to use Customer Personal Data that identifies any individual to train that third party’s own generally available models; and
where the Services include AI features, Process Customer Personal Data through third-party providers of artificial-intelligence models and services engaged by Onroute as Sub-Processors, solely to provide those features in accordance with Customer’s instructions and the Onroute Subscription Terms. Such engagement is subject to Clause 2.2.2 (Sub-Processors) and the transfer provisions of Clause 2.2.5, and any development, training, fine-tuning or evaluation of models is subject to Clause 2.2.10.
The Customer shall:
ensure that the Description of Processing at all times accurately reflects Onroute’s Processing of Customer Personal Data as a Processor for Customer in relation to the Services. Where Customer requires changes to the Description of Processing it shall provide an amended version (a “Revised Description”) to Onroute. Such Revised Description shall be deemed to have replaced the Description of Processing within five (5) days of Onroute’s written confirmation and this DPA shall be deemed amended accordingly on that date. If the nature of the Processing under this DPA changes in such a way as to change the scope of the Services, Onroute shall be entitled to amend the charges for the Services accordingly;
ensure that all instructions it issues to Onroute comply with Applicable Data Protection Laws;
be and remain solely responsible for determining the legal basis and conditions for the Processing of all Customer Personal Data under this DPA;
indemnify Onroute against all Liabilities arising out of or in connection with any breach by Customer of any of the terms of this Clause 2.3, including all amounts paid or payable by Onroute or any of its Related Persons to a third party which would not have been paid or payable if Customer’s breach of this Clause 2.3 had not occurred; and
where Customer uses any AI feature or agent to communicate with, or to make or support decisions affecting, individuals, be solely responsible as Controller for compliance with Applicable Data Protection Laws in respect of that use, including any transparency and automated-decision-making requirements, and for making any disclosure required by law that an individual is interacting with, or receiving content generated by, artificial intelligence.
To the extent permitted by law, Onroute accepts no liability for any: (i) inaccurate data (including Personal Data) provided to Customer as part of the Services to the extent that such inaccuracy arises from incorrect data provided by Customer, any Data Subjects or any of Onroute’s sources that are not Sub-Processors; or (ii) representations, guarantees or conditions that the Services and/or the Personal Data are fit for a particular purpose or will meet Customer’s requirements.
Each Party’s liability arising out of or in connection with this DPA, whether in contract, tort or otherwise, is subject to the ‘Limitation of Liability’ section of the Onroute Subscription Terms, and any reference in such section to the liability of a Party means the aggregate liability of that Party under the Onroute Subscription Terms and this DPA.
Onroute shall not be liable for any Liabilities in connection with this DPA or the Services to the extent that Onroute is not in any way responsible for the event giving rise to the Liabilities and/or Customer or its Related Persons are responsible for the Liabilities, in each case, in accordance with Article 82 of the UK GDPR.
This DPA shall terminate upon the expiry or termination of the Onroute Subscription Terms or, if earlier, Onroute ceasing to Process Customer Personal Data. On the expiry or termination of this DPA (at Customer’s option and cost) Onroute shall either return to Customer all Customer Personal Data or securely dispose of it, except where it is required to store it pursuant to applicable law. Notwithstanding this, where Onroute acts as a Processor on behalf of another Controller and the same Customer Personal Data Processed under this DPA is also Processed on behalf of that other Controller, Onroute is legally required to retain such Customer Personal Data and shall continue to Process the Customer Personal Data for that other Controller.
Job sharing. Where Customer uses the Services to share a job containing Personal Data with another organisation, Customer and that receiving organisation each act as independent Controllers of that Personal Data, and each is responsible for its own compliance with Applicable Data Protection Laws in respect of it. Onroute Processes such shared Personal Data as Customer’s Processor solely as necessary to transmit it between the organisations through the Services. Onroute is not a Controller of that Personal Data, is not a party to the arrangement between the organisations, and is not responsible for the receiving organisation’s Processing of it. The receiving organisation Processes the shared Personal Data under its own agreement with Onroute (including its own data processing addendum) and not under this DPA.
Clause 3 General
Except as set out in this DPA, the Onroute Subscription Terms shall continue in full force and effect.
This DPA shall be governed by the laws of England and any dispute or claim arising out of or in connection with it (including in relation to its formation) shall be subject to the exclusive jurisdiction of the English courts.
Schedule 1 Description of Processing
Processing of Personal Data
| Subject matter: | The Processing of Customer Personal Data by Onroute to perform the Services and its obligations under the Onroute Subscription Terms. |
|---|---|
| Nature: | collection, recording, organisation, storage, adaptation, retrieval, disclosure, restriction, erasure and destruction of Customer Personal Data, and all other Processing operations required to perform the Services. |
| Duration: | Until termination of the Onroute Subscription Terms, or this DPA (whichever is earlier). |
| Data Subjects: | The Personal Data concern the following categories of Data Subjects:
|
| Purposes of the Processing: | The Processing is necessary for the following purposes:
|
| Categories of Personal Data: | The Personal Data Processed fall within the following categories:
|
| Special categories of Personal Data: | The categories of Personal Data are determined and controlled by Customer in its sole discretion and may include special categories of Personal Data (as defined in Article 9 of the UK GDPR) to the extent Customer chooses to submit it. Onroute Processes Customer Personal Data only on Customer’s instructions in providing the Services. Customer remains solely responsible under Clause 2.3.3 for the legal basis and any condition required under Article 9 of the UK GDPR for such Processing. Customer should not submit special categories of Personal Data except to the extent necessary for its use of the Services. |
Schedule 2 International Data Transfer Agreement (IDTA)
This Schedule completes the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018 and in force from 21 March 2022 (the “IDTA”). The Mandatory Clauses of the IDTA, as revised under the ICO’s review process from time to time, are incorporated into and form part of this DPA, and the Tables below (together with the Description of Processing in Schedule 1) complete them. This Schedule applies only where, and to the extent that, a transfer of Customer Personal Data is a restricted transfer under the UK GDPR that is not covered by an adequacy regulation or adequacy decision then in force (including the UK Extension to the EU–US Data Privacy Framework). In the event of any conflict between the Mandatory Clauses of the IDTA and any other provision of this DPA or the Onroute Subscription Terms, the Mandatory Clauses prevail to the extent necessary to resolve the conflict.
Table 1: Parties and signatures
| Data Exporter | Data Importer | |
|---|---|---|
| Party | The Customer. | Onroute Intelligence Inc. |
| Full legal name | As set out in the Order or the account registration details provided by Customer. | Onroute Intelligence Inc. |
| Main address | As set out in the Order or the account registration details provided by Customer. | 251 Little Falls Drive, Wilmington, Delaware 19808, USA. |
| Key contact | The Customer’s administrator, or the contact set out in the Order or provided at sign-up. | Data protection contact, support@onroute.io. |
| Signature | By entering into the Onroute Subscription Terms and this DPA, the Data Exporter is treated as having signed and entered into this IDTA on the Effective Date (see clause 5.2 of the Onroute Subscription Terms). | By entering into the Onroute Subscription Terms and this DPA, the Data Importer is treated as having signed and entered into this IDTA on the Effective Date. |
Table 2: Transfer details
| UK country’s law that governs the IDTA | England and Wales. |
|---|---|
| Primary place for legal claims | The courts of England and Wales. |
| Status of the Data Exporter | Controller (as set out in Clause 2.1 of this DPA). |
| Status of the Data Importer | Processor acting on behalf of the Data Exporter (as set out in Clause 2.1 of this DPA). |
| Linked agreement | The Onroute Subscription Terms and this DPA (including Schedule 1), and each applicable Order. |
| Term | This IDTA takes effect on the Effective Date and continues for so long as Onroute Processes Customer Personal Data under this DPA. It ends in accordance with Clause 2.7 of this DPA and the Mandatory Clauses. |
| Ending the IDTA before the end of the term | The Parties may end this IDTA as provided in the Mandatory Clauses, including where the other Party is in breach, and the Data Exporter may end it where the ICO issues a revised Approved IDTA under section 119A(1) of the Data Protection Act 2018 with which the Data Importer cannot comply. |
| Can the Importer make further transfers (onward transfers)? | Yes, to Sub-Processors in accordance with Clause 2.2.2 of this DPA (including third-party providers of artificial-intelligence models and services engaged to provide the AI features). A list of current Sub-Processors is published as part of Onroute’s Trust and Compliance documentation at https://www.onroute.io/trustandcompliance. Each Sub-Processor is bound by obligations materially equivalent to those in this DPA and, where it is outside the UK or EEA and not covered by an adequacy regulation, by an appropriate transfer mechanism. |
| Frequency of the transfer | Continuous, for the duration of the Services. |
Table 3: Transferred data
The categories of Data Subjects, the categories of Personal Data, the special categories of Personal Data, and the nature, purposes and duration of the Processing are as set out in the Description of Processing in Schedule 1 to this DPA, which is incorporated into and completes this Table 3. The transfer is on a continuous basis for the duration of the Services.
Table 4: Security requirements
The Data Importer implements and maintains the technical and organisational measures required by Clause 2.2.1 of this DPA and described in the security information published within Onroute’s Trust and Compliance Documentation (referred to in clause 5.1 of the Onroute Subscription Terms), as updated by Onroute from time to time provided that the overall level of security is not materially reduced during the term.
Extra Protection Clauses and Commercial Clauses
The additional safeguards and commercial provisions applicable to the transfer are as set out in this DPA and the Onroute Subscription Terms, including the confidentiality, security, sub-processor, audit, personal-data-breach-notification and liability provisions. No further Extra Protection Clauses or Commercial Clauses are specified.