Legal
Fleet data processing terms
Last updated: Draft — pending owner sign-off
These draft terms describe how AutoArchive handles data on behalf of a fleet workspace.
Company details
AUTOARCHIVE LTD · Company no. pending · Registered office: pending · Registered in England and Wales. Contact: contact@autoarchive.uk.
Publication blocker
The intended contracting company, company number and registered office are pending confirmation. These draft terms must not be treated as final until those details are supplied.
Owner decision required
A solicitor must review these fleet data processing terms before they are signed or published as final.
Roles and instructions
The fleet customer controls the personal data in its workspace. AutoArchive acts as its processor, using that data only to provide the service on the customer's documented instructions, unless the law requires otherwise. The customer is responsible for its own instructions and for deciding which people may access its workspace.
Confidentiality and security
People authorised to handle fleet data must keep it confidential. We use access controls, private file storage, short-lived file links, audit records and other appropriate technical and organisational security measures to protect the data.
Sub-processors and data sources
Lovable/Supabase provides hosting, authentication, storage and the AI gateway; an OpenAI model processes AI requests through the gateway; Stripe handles payments; Google provides optional sign-in; the Lovable-managed email delivery provider sends service messages; and Lovable error reporting handles technical errors. With user consent, a third-party AI app connected through MCP/OAuth can read the authorised vehicle history. DVSA supplies MOT history as a data source, not as our sub-processor. See the privacy policy for more information.
Breach notification and requests
We will notify the fleet customer of a personal data breach without undue delay after becoming aware of it, and provide information to help the customer respond. We will also assist the customer with requests from people to exercise their data rights, taking into account the nature of the processing and the information available to us.
At the end of the contract
At the customer's choice, we will delete or return its fleet personal data at the end of the service, unless the law requires us to retain it. The retention & deletion policy explains current deletion and backup limitations.
Audit information
On request, we will make available information reasonably needed to show compliance with these processing terms and support appropriate audits or inspections, subject to security and confidentiality requirements.
