Data Processing Agreement

Last updated July 31, 2026

This Data Processing Agreement (DPA) supplements our Terms of Service for customers established in the European Union or processing personal data of EU data subjects. It applies where the use of our API involves the processing of personal data on behalf of the customer within the meaning of Art. 28 GDPR. A countersigned copy is available on request; contact info@vehicleimagery.com.

1. Roles and subject matter

The customer is the controller, Vehicle Imagery is the processor. The subject matter is the resolution of vehicle identifiers submitted by the customer, such as vehicle identification numbers (VINs) or licence plate numbers, into vehicle specifications and images. Licence plates, and depending on context VINs, can constitute personal data; this DPA exists for exactly those cases.

2. Nature and purpose of processing

Processing on behalf of the customer is limited to receiving vehicle identifiers via API request, resolving them against vehicle data, returning the corresponding specification and image, and the technical logging necessary to operate, secure and bill the service. In addition, we process de-identified request data for our own purposes as an independent controller: improving resolution quality, closing catalogue coverage gaps and keeping error rates low. This quality dataset contains vehicle identifiers, resolution outcomes and error codes, and is permanently decoupled from IP addresses, customer identity and any end customer context. We do not use customer submitted data to build profiles of natural persons.

3. Categories of data and data subjects

  • Data categories: vehicle identifiers (VIN, licence plate), technical request metadata such as IP address, timestamps and API key identity
  • Data subjects: the customer's own customers and prospects whose vehicles are being resolved, and the customer's staff using the API
  • No special categories of data under Art. 9 GDPR are required by or requested through the service

4. Duration, deletion and return

Processing lasts for the duration of the customer relationship. Full request logs, containing vehicle identifiers together with IP addresses and customer context, are retained for 6 months for operations, security and billing, then deleted. Before deletion, vehicle identifiers and their resolution outcomes are transferred into the de-identified quality dataset described in section 2, stripped of IP addresses and customer linkage; licence plate numbers are not carried over once resolved to a vehicle. Aggregated billing records without personal data are kept for up to ten years to meet statutory commercial and tax retention duties. On termination, personal data processed on the customer's behalf is deleted within 30 days, subject to those statutory duties. Images cached by the customer in the customer's own infrastructure are outside our control and the customer's responsibility.

5. Obligations of the processor

  1. Process identifiers only as instructed through the API's documented functioning and this DPA
  2. Bind all persons involved to confidentiality
  3. Implement appropriate technical and organisational measures per Art. 32 GDPR (Annex, TOMs)
  4. Support the customer with data subject requests and Art. 32 to 36 obligations to the extent the processing allows
  5. Notify the customer without undue delay of any personal data breach affecting their data
  6. Provide the information necessary to demonstrate compliance and allow audits as described below

6. Sub-processors

The customer grants general authorisation for the sub-processors listed below. We inform customers of intended changes in advance, and the customer may object on reasonable data protection grounds.

Current sub-processors: Cloudflare, Inc. (USA), providing global hosting, content delivery and edge infrastructure for the API. Tools used only for our marketing website and content production do not process customer API data and are not sub-processors under this DPA.

7. International transfers

Our API runs on Cloudflare's global network, which means request processing can occur outside the EEA. Transfers to Cloudflare, Inc. are safeguarded by the EU Standard Contractual Clauses incorporated in Cloudflare's data processing terms, alongside Cloudflare's participation in the EU-US Data Privacy Framework.

8. Technical and organisational measures

A summary of our technical and organisational measures is available on request: encryption in transit for all API traffic, API key based access control, separation of customer environments, access logging, and least privilege administration.

9. Audits

We support audits primarily through documentation and completed questionnaires. On reasonable notice, and no more than once per year absent a concrete cause, the customer may verify compliance through an independent auditor bound to confidentiality, during business hours and without access to other customers' data.

10. Liability and final provisions

Liability follows the Terms of Service. Should individual provisions of this DPA be invalid, the remainder stays unaffected. The law governing the Terms of Service applies. Where a signed individual DPA exists between the parties, it prevails over this published version.