Legal
On this page
This Data Processing Agreement (DPA) supplements our Terms of Service for customers established in the European Union or processing personal data of EU data subjects. It applies where the use of our API involves the processing of personal data on behalf of the customer within the meaning of Art. 28 GDPR. A countersigned copy is available on request; contact info@vehicleimagery.com.
The customer is the controller, Vehicle Imagery is the processor. The subject matter is the resolution of vehicle identifiers submitted by the customer, such as vehicle identification numbers (VINs) or licence plate numbers, into vehicle specifications and images. Licence plates, and depending on context VINs, can constitute personal data; this DPA exists for exactly those cases.
Processing on behalf of the customer is limited to receiving vehicle identifiers via API request, resolving them against vehicle data, returning the corresponding specification and image, and the technical logging necessary to operate, secure and bill the service. In addition, we process de-identified request data for our own purposes as an independent controller: improving resolution quality, closing catalogue coverage gaps and keeping error rates low. This quality dataset contains vehicle identifiers, resolution outcomes and error codes, and is permanently decoupled from IP addresses, customer identity and any end customer context. We do not use customer submitted data to build profiles of natural persons.
Processing lasts for the duration of the customer relationship. Full request logs, containing vehicle identifiers together with IP addresses and customer context, are retained for 6 months for operations, security and billing, then deleted. Before deletion, vehicle identifiers and their resolution outcomes are transferred into the de-identified quality dataset described in section 2, stripped of IP addresses and customer linkage; licence plate numbers are not carried over once resolved to a vehicle. Aggregated billing records without personal data are kept for up to ten years to meet statutory commercial and tax retention duties. On termination, personal data processed on the customer's behalf is deleted within 30 days, subject to those statutory duties. Images cached by the customer in the customer's own infrastructure are outside our control and the customer's responsibility.
The customer grants general authorisation for the sub-processors listed below. We inform customers of intended changes in advance, and the customer may object on reasonable data protection grounds.
Current sub-processors: Cloudflare, Inc. (USA), providing global hosting, content delivery and edge infrastructure for the API. Tools used only for our marketing website and content production do not process customer API data and are not sub-processors under this DPA.
Our API runs on Cloudflare's global network, which means request processing can occur outside the EEA. Transfers to Cloudflare, Inc. are safeguarded by the EU Standard Contractual Clauses incorporated in Cloudflare's data processing terms, alongside Cloudflare's participation in the EU-US Data Privacy Framework.
A summary of our technical and organisational measures is available on request: encryption in transit for all API traffic, API key based access control, separation of customer environments, access logging, and least privilege administration.
We support audits primarily through documentation and completed questionnaires. On reasonable notice, and no more than once per year absent a concrete cause, the customer may verify compliance through an independent auditor bound to confidentiality, during business hours and without access to other customers' data.
Liability follows the Terms of Service. Should individual provisions of this DPA be invalid, the remainder stays unaffected. The law governing the Terms of Service applies. Where a signed individual DPA exists between the parties, it prevails over this published version.