Data Processing Agreement
September 1, 2026
1. Parties, roles and scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between TrackSights ApS, CVR 44719037, Bredgade 45 C, 1260 København, Denmark ("TrackSights", "Processor") and the business customer ("Customer", "Controller"). It applies where TrackSights processes personal data on the Customer's behalf in providing the Service.
For personal data processed under the Service, the Customer is the controller and TrackSights is the processor. Where TrackSights determines the purposes and means of processing for its own account (for example billing, fraud prevention, securing the Service, and improving the Service using aggregated and anonymised data), it acts as an independent controller under its Privacy Policy, and this DPA does not apply to that processing.
Terms defined in the Terms of Service have the same meaning here. "GDPR" means Regulation (EU) 2016/679 and the Danish Data Protection Act (databeskyttelsesloven). "Personal data", "processing", "data subject", "controller", "processor" and "supervisory authority" have the meanings in the GDPR.
2. Processing on documented instructions
TrackSights will process personal data only on the Customer's documented instructions, including as set out in the Terms of Service, this DPA (see Annex 1) and the Customer's configuration and use of the Service, unless required to process by EU or Member State law — in which case TrackSights will inform the Customer of that requirement before processing, unless the law prohibits it on important grounds of public interest.
TrackSights will inform the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other data-protection law. TrackSights is not obliged to assess the lawfulness of the Customer's instructions generally.
3. Confidentiality
TrackSights will ensure that persons authorised to process the personal data are bound by an appropriate obligation of confidentiality (contractual or statutory) and are made aware of their data-protection responsibilities. Access is limited to personnel who need it to provide, secure or support the Service.
4. Security of processing
Taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, TrackSights will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2 (Art. 32 GDPR). TrackSights may update these measures from time to time provided the overall level of protection is not materially reduced.
5. Sub-processors
The Customer gives TrackSights general authorisation to engage sub-processors to process personal data, subject to this section. The current list of sub-processors is available on request at legal@tracksights.com, and the Customer's authorisation covers the sub-processors on that list as at the effective date of this DPA.
TrackSights will impose on each sub-processor, by written contract, data-protection obligations equivalent to those in this DPA (in particular sufficient guarantees of appropriate technical and organisational measures), and remains fully liable to the Customer for a sub-processor's performance of its obligations.
TrackSights will give the Customer at least 30 days' prior notice of any intended addition or replacement of a sub-processor, by email to the Customer's account email. The Customer may object on reasonable, documented data-protection grounds within 14 days of the notice; the parties will then discuss in good faith, and if the objection cannot be resolved the Customer may terminate the affected part of the Service with effect from the change, as its sole remedy.
6. Assistance to the Customer
Taking into account the nature of the processing and the information available to it, TrackSights will assist the Customer by appropriate technical and organisational measures, insofar as possible, with:
- responding to requests to exercise data-subject rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection);
- ensuring compliance with the security, breach-notification, data-protection-impact-assessment and prior-consultation obligations in Arts. 32–36 GDPR, taking into account the information available to TrackSights.
Where TrackSights receives a request directly from a data subject relating to the Customer's Customer Data, it will not respond directly (except to confirm the request should be directed to the Customer) and will forward the request to the Customer without undue delay. TrackSights may charge a reasonable fee for assistance that goes beyond the standard functionality of the Service.
7. Personal data breach
TrackSights will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and will provide the information reasonably available to it to help the Customer meet its own notification obligations under Arts. 33–34 GDPR, including the nature of the breach, likely consequences, and measures taken or proposed. TrackSights' notification of, or response to, a breach is not an acknowledgement of fault or liability.
8. International transfers
TrackSights will not transfer personal data to a country outside the EU/EEA without an appropriate safeguard under Chapter V GDPR — an adequacy decision (including, for certified US providers, the EU–US Data Privacy Framework) or the EU Standard Contractual Clauses, with supplementary measures where required. The transfer position for sub-processors is described in Annex 3. The Customer authorises the transfers described in Annex 3 and grants TrackSights authority to enter into transfer mechanisms with sub-processors on the Customer's behalf where required.
9. Audits
TrackSights will make available to the Customer information reasonably necessary to demonstrate compliance with Art. 28 GDPR and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates (not a competitor of TrackSights). To minimise disruption, TrackSights may satisfy audit requests by providing responses to written questions and current third-party certifications or audit reports (e.g. ISO 27001 / SOC 2) where available; on-site inspections are on at least 30 days' prior written notice, no more than once per 12 months (except following a personal data breach affecting the Customer or where required by a supervisory authority), during business hours, subject to confidentiality, without access to other customers' data, and at the Customer's cost.
10. Return and deletion
On termination of the Service, TrackSights will delete the personal data processed on the Customer's behalf, unless EU or Member State law requires storage. If the Customer instead requests, in writing within 30 days of termination, the return or export of its Customer Data, TrackSights will make it available in a commonly used format before deletion. After that 30-day period, deletion proceeds, subject to routine backup expiry cycles and any legal-retention obligation.
Aggregated and anonymised data created under §14 of the Terms of Service — which no longer identifies the Customer, any individual or any specific vehicle transaction — is not personal data processed on the Customer's behalf, is owned by TrackSights, and is not subject to this section.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. In case of conflict on personal-data matters, this DPA prevails over the rest of the Terms of Service. This DPA is governed by the law and jurisdiction stated in the Terms of Service. Nothing in this DPA limits either party's obligations to data subjects or supervisory authorities under mandatory law.
Annex 1 — Details of processing
- Subject matter: provision of the TrackSights Service (vehicle screening, valuation, VIN lookups, case archiving, market insights, monitoring and analytics).
- Duration: the term of the Customer's subscription, plus the post-termination export/deletion period in §10.
- Nature and purpose: hosting, storing, organising, retrieving, transmitting and displaying Customer Data to provide the Service and support to the Customer.
- Types of personal data: account and User details (name, business email, role); billing/contact details; and any personal data contained in Customer Data the Customer chooses to submit — for example, data relating to vehicles, owners, dealers or counterparties (which may include names, contact details, VINs and transaction details). The Customer must not submit special-category data.
- Categories of data subjects: the Customer's Users and staff; and individuals referenced in the Customer's Customer Data (e.g. vehicle owners/keepers, dealers, business counterparties).
Annex 2 — Technical and organisational security measures
TrackSights implements measures appropriate to the risk, including:
- encryption of personal data in transit (TLS) and at rest;
- access restricted to authorised personnel on a need-to-know basis, with unique credentials and multi-factor authentication for administrative access;
- network and application security controls;
- logging and monitoring of the production environment;
- regular backups;
- separation of production and non-production environments;
- secure software-development practices;
- due diligence on sub-processors;
- confidentiality obligations for all personnel and security awareness in day-to-day operations;
- an incident-response process, including post-incident review of production incidents.
TrackSights may update these measures under §4 of this DPA.
Annex 3 — Sub-processors
The current list of sub-processors, including each provider's purpose, is available on request at legal@tracksights.com. Sub-processors process personal data primarily within the EU/EEA. Where a sub-processor processes personal data outside the EU/EEA, TrackSights relies on an adequacy decision (including, for certified US providers, the EU–US Data Privacy Framework) or the EU Standard Contractual Clauses, with supplementary measures where required.