Data Processing Agreement
1. Parties and roles
This agreement is between the business named on the licence ("you", the controller) and COC AutoDocs Ltd, company number 17449142, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ ("we", the processor). It applies to the personal data we process on your behalf in providing the CoC AutoDocs service, described in Annex A. For your account, enquiries, licence and payment records we are the controller and our privacy policy applies instead.
"UK GDPR", "Data Protection Act 2018", "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in UK data protection law.
2. Your obligations
You are responsible for the lawfulness of the personal data you put into the service and of your instructions to us. You confirm that you have a lawful basis for processing the personal data of your staff and of the signatories named on your certificates, that you have given them the information the law requires, and that your instructions will comply with data protection law.
3. Our obligations
We will:
- Act only on your documented instructions. Your instructions are this agreement, the customer agreement, and the actions you take in the service, such as making a file, inviting a colleague or pressing Send to the VCA. We will not process your data for any other purpose, and we do not use it to train models, profile people or market to anyone. If the law requires us to process it otherwise, we will tell you first unless the law forbids that. If we think an instruction breaks the law, we will tell you.
- Keep it confidential. Everyone with access to your data on our side is bound by a duty of confidentiality. Access is limited to what is needed to run and support the service, and every administrative action is logged.
- Keep it secure. We apply the measures in Annex B, which we consider appropriate to the risk under Article 32, and we review them at least yearly.
- Use sub-processors only as allowed. You authorise the sub-processors in Annex C. We will email account owners at least 14 days before a new sub-processor handles your data. If you object on reasonable grounds and we cannot resolve it, you may end the customer agreement and we refund any prepaid unused period. We impose written terms on each sub-processor no less protective than this agreement and remain responsible to you for their performance.
- Help you with people's rights. The service lets you export or delete any person's data, or the whole company, yourself without asking us. Where it cannot, we will help within five working days of your request. If a data subject contacts us directly about your data we will pass the request to you promptly and not respond except to say so.
- Help you with security, breaches and impact assessments. We will give you the information you reasonably need to meet your own obligations under Articles 32 to 36, taking into account what we know.
- Delete or return your data at the end. Within 30 days of the customer agreement ending, or earlier on your instruction, we delete your data, and it leaves our backups within a further 30 days. Before that, you can export everything as JSON and XML from the Company page. Your statutory duty as the manufacturer to keep certificates for ten years (assimilated Regulation (EU) 2018/858, Article 14(3)) is yours to meet from that export; we hold nothing for you after deletion. We keep only what the law requires us to keep, which is payment records for six years, and we do not keep personal data in them beyond the name and address on the invoice.
- Show you we comply. We will make available the information reasonably necessary to demonstrate compliance with Article 28, and answer a written security questionnaire once a year on request. You may audit us, or appoint an independent auditor bound by confidentiality to do so, on 30 days' notice, no more than once a year unless a breach or a regulator requires otherwise, during working hours and without disrupting other customers. You bear the cost of your audit unless it finds a material breach of this agreement.
4. International transfers
Your data is stored and processed in Railway's Amsterdam region, in the European Union, which is covered by the UK's adequacy regulations. Two of our suppliers are American companies, so contracting with them is a restricted transfer under UK data protection law even though the data sits in Europe: Railway, which hosts the service, and Resend, which sends our email. Both transfers are made under the International Data Transfer Addendum issued by the Information Commissioner, which forms part of each supplier's data processing agreement with us. We will not move your data outside the European Economic Area without telling you first and putting equivalent safeguards in place.
5. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting your data, by email to the account owner. The notice will say what we know at the time: the nature of the breach, the data and people likely affected, the likely consequences, what we have done and what we recommend you do. We will update you as we learn more and cooperate with your own notifications to the Information Commissioner and to affected people, which remain your responsibility as controller. We do not tell the Commissioner or data subjects on your behalf unless you ask us to.
6. Liability, term and precedence
Liability under this agreement is subject to the limits in the customer agreement. This agreement lasts for as long as we hold your data. If it conflicts with the customer agreement on a data protection matter, this agreement prevails. If the law changes so that any part of this agreement no longer meets Article 28, we will update it and email account owners.
Annex A: the processing
| Subject matter | Hosting the CoC AutoDocs service, in which your staff produce, store, sign, track and submit electronic Certificates of Conformity and related records. |
|---|---|
| Duration | The term of the customer agreement, plus the deletion periods in section 3(7). |
| Nature and purpose | Storing, organising, generating, signing on your instruction, transmitting to the VCA on your instruction, backing up and deleting the data, solely to provide the service. |
| Types of personal data | Names and job titles of signatories; names and email addresses of your staff who use the service; which staff member made or changed each file, and when; vehicle identification numbers and vehicle data as you enter them; VCA credentials you enter, held encrypted. No special category data, and no data about children. |
| Categories of data subject | Your employees and contractors who use the service; the people you name as signatories; and, only where a vehicle's data identifies one, an individual customer of yours. |
Annex B: security measures
- All connections encrypted with TLS; HTTP Strict Transport Security enforced.
- The database is hosted in an EU data centre and accepts connections only from the application.
- No passwords are held; sign-in is by a single-use link emailed to the user. Sign-in requests are rate-limited per address and per recipient.
- Signing keys and certificates are created or loaded in the customer's own browser and never sent to us.
- VCA client secrets are encrypted at rest with a key held outside the database.
- Every administrative action is recorded in an audit trail kept for 24 months.
- Access to the owner dashboard is restricted to named administrators.
- Daily encrypted backups with point-in-time restore, kept in the same EU region as the database.
- Security headers applied on every response; dependencies reviewed for known vulnerabilities before each release.
- A written breach procedure, tested by walkthrough at least yearly.
Annex C: sub-processors
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Railway Corporation (United States) | Runs the application and the database; holds backups | All service data | Amsterdam, Netherlands. SOC 2 Type II certified. Contracting entity in the United States, under the UK International Data Transfer Addendum |
| Stripe (Stripe Payments Europe Ltd / Stripe Payments UK Ltd) | Takes card payments and issues receipts | Name, email and billing address of the person paying; card data is held by Stripe alone | Ireland and United Kingdom; Stripe's own UK GDPR terms |
| Resend, Inc. | Sends sign-in links, licence keys and invitations | Recipient email address and message | United States, under the UK IDTA |
The Vehicle Certification Agency is not a sub-processor. It receives files only when you send them, under your own VCA account, and is a separate controller of what it receives.
Effective 9 September 2026. This is the published version; a signed copy is available on request for customers whose procurement process requires one.