ملحق معالجة البيانات (DPA)

Version: 1.0

Last Updated: 21 July 2026

This Data Processing Addendum ("DPA") is entered into by and between:

Aliyyu Global Private Limited, an Indian company, acting through its GarageBox business unit ("GarageBox", "Processor", "we", "us", or "our"),

and

the customer entity that has entered into the GarageBox Terms of Service, Order Form, Master Services Agreement, or other written agreement governing the use of the GarageBox Services ("Customer" or "Controller").

GarageBox is a product, brand, and service of Aliyyu Global Private Limited.

This DPA forms part of and is incorporated into the Agreement between the parties.

1. Purpose and Scope

This DPA applies when GarageBox processes Personal Data on behalf of the Customerin connection with the provision of the GarageBox cloud-based workshop and automotive service management platform, mobile applications, APIs, support services, and related services (collectively, the "Services").

This DPA sets out the parties' obligations regarding the processing of Personal Data under applicable data protection laws.

2. Definitions

For the purposes of this DPA:

"Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including, where applicable:

  • Regulation (EU) 2016/679 (GDPR);
  • the UK GDPR;
  • the UK Data Protection Act 2018;
  • the Digital Personal Data Protection Act, 2023 (India); and
  • any other applicable privacy or data protection laws.

"Personal Data" means any information relating to an identified or identifiable natural person processed by GarageBox on behalf of the Customer.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, and deletion.

"Data Subject" means the individual to whom the Personal Data relates.

"Subprocessor" means a third party engaged by GarageBox to process Personal Data on behalf of the Customer.

"Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by GarageBox on behalf of the Customer.

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

3. Roles of the Parties

The parties acknowledge that:

  • the Customer is the Controller of the Personal Data; and
  • GarageBox is the Processor of the Personal Data.

The Customer is responsible for:

  • determining the purposes and means of processing;
  • obtaining any required consents;
  • providing privacy notices to Data Subjects; and
  • ensuring that its instructions comply with Applicable Data Protection Law.

4. Processing Instructions

GarageBox shall process Personal Data only:

  • on the Customer's documented instructions;
  • as necessary to provide and support the Services;
  • to comply with applicable law; or
  • as otherwise agreed in writing by the parties.

The Agreement, this DPA, and any configuration or use of the Services by the Customer constitute the Customer's documented instructions.

If GarageBox believes that an instruction infringes Applicable Data Protection Law, GarageBox shall inform the Customer without undue delay unless prohibited by law.

5. Details of Processing

5.1 Subject Matter

Provision of the GarageBox software platform and related support, hosting, security, analytics, and maintenance services.

5.2 Duration

For the duration of the Agreement and any applicable post-termination retention period.

5.3 Nature and Purpose

Processing activities may include:

  • hosting and storage of Customer Data;
  • user authentication and account management;
  • vehicle service and repair management;
  • invoicing and payment record processing;
  • customer communication and notifications;
  • backup and disaster recovery;
  • technical support and troubleshooting; and
  • security monitoring and fraud prevention.

5.4 Categories of Data Subjects

  • Customer employees and contractors;
  • workshop technicians and service advisors;
  • vehicle owners and drivers;
  • supplier and vendor contacts; and
  • other individuals whose data is submitted by the Customer.

5.5 Categories of Personal Data

  • names and contact details;
  • company and employment information;
  • vehicle identification information (VIN, registration number, make, model);
  • service history and inspection records;
  • billing and transaction records;
  • user account credentials and authentication data; and
  • files, images, videos, and documents uploaded by the Customer.

The Customer shall not upload special categories of personal data unless expressly agreed in writing and supported by appropriate safeguards.

6. Confidentiality

GarageBox shall ensure that persons authorized to process Personal Data:

  • are bound by confidentiality obligations; and
  • receive appropriate privacy and security training.

These obligations shall survive termination of their engagement and of the Agreement.

7. Security Measures

GarageBox shall implement appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.

Such measures may include:

  • encryption of data in transit using TLS 1.2 or higher;
  • encryption at rest where supported by the underlying infrastructure;
  • role-based access controls;
  • least-privilege access management;
  • multi-factor authentication for privileged access where applicable;
  • logging and monitoring of administrative access;
  • vulnerability management and security patching;
  • secure software development practices;
  • malware protection;
  • regular backups and recovery testing; and
  • incident response and business continuity procedures.

GarageBox may update these measures from time to time, provided that the overall level of security is not materially reduced.

8. Subprocessors

8.1 General Authorization

The Customer authorizes GarageBox to engage Subprocessors to assist in providing the Services.

8.2 Subprocessor Obligations

GarageBox shall enter into a written agreement with each Subprocessor that imposes data protection obligations substantially equivalent to those set out in this DPA.

GarageBox remains responsible for the acts and omissions of its Subprocessors to the extent required by Applicable Data Protection Law.

8.3 Subprocessor List

GarageBox shall maintain a current list of Subprocessors and provide it upon request or through a designated webpage.

8.4 Changes to Subprocessors

GarageBox will provide notice of material changes to Subprocessors where reasonably practicable. The Customer may object on reasonable data protection grounds within 15 days of receiving notice. If the parties cannot resolve the objection, the Customer may terminate the affected Services without penalty.

9. International Data Transfers

GarageBox serves customers globally, and Personal Data may be processed in countries other than the country of origin.

Where Applicable Data Protection Law restricts international transfers, GarageBox shall implement appropriate safeguards, including:

  • the European Commission Standard Contractual Clauses (SCCs), where applicable;
  • the UK International Data Transfer Addendum, where applicable;
  • transfers to jurisdictions recognized as providing an adequate level of protection; or
  • other lawful transfer mechanisms.

The SCCs are incorporated by reference where required for restricted transfers.

10. Assistance to the Customer

Taking into account the nature of the processing, GarageBox shall provide reasonable assistance to the Customer in fulfilling its obligations relating to:

  • Data Subject rights requests;
  • security of processing;
  • personal data breach notifications;
  • data protection impact assessments (DPIAs); and
  • consultations with supervisory authorities.

GarageBox may charge reasonable fees for assistance requiring substantial additional effort beyond standard support services.

11. Data Subject Requests

If GarageBox receives a request directly from a Data Subject regarding Personal Data processed on behalf of the Customer, GarageBox shall:

  • promptly notify the Customer;
  • not respond to the request except on the Customer's documented instructions or as required by law; and
  • provide reasonable assistance to enable the Customer to respond.

The Customer is responsible for responding to Data Subject requests.

12. Security Incident Notification

GarageBox shall notify the Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data.

The notification shall include, where available:

  • the nature of the incident;
  • the categories of affected Personal Data;
  • the likely consequences;
  • the measures taken or proposed to address the incident; and
  • contact information for follow-up.

Notification of a Security Incident does not constitute an admission of fault or liability.

13. Audit and Compliance

13.1 Compliance Information

GarageBox shall make available information reasonably necessary to demonstrate compliance with this DPA.

13.2 Customer Audit Rights

If the information provided is insufficient, the Customer may request an audit no more than once every 12 months, subject to:

  • 30 days' prior written notice;
  • confidentiality obligations;
  • audits being conducted during normal business hours;
  • no unreasonable disruption to GarageBox operations; and
  • the Customer bearing its own costs and reimbursing GarageBox for reasonable audit-related expenses.

GarageBox may satisfy audit obligations by providing independent audit reports or certifications, such as ISO 27001 or SOC 2 reports, when available.

14. Return and Deletion of Data

Upon termination or expiration of the Services, GarageBox shall:

  • provide the Customer with a reasonable opportunity to export Customer Data; and
  • delete or return Personal Data after the applicable retention period unless retention is required by law.

Backup copies may be retained for a limited period in accordance with GarageBox's backup and disaster recovery procedures, after which they will be securely deleted or overwritten.

15. Liability

The liability of each party arising under this DPA shall be subject to the limitations of liability set out in the Agreement.

Nothing in this DPA limits liability that cannot be limited under Applicable Data Protection Law.

16. Governing Law

This DPA shall be governed by the governing law specified in the Agreement, except to the extent that the incorporated Standard Contractual Clauses require otherwise.

17. Order of Precedence

In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.

If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses shall prevail to the extent of the conflict.

18. Contact Information

Privacy Team

Aliyyu Global Private Limited

GarageBox (Product / Brand / Service)

Email: [email protected]

Legal Team

Email: [email protected]

Security Team

Email: [email protected]

Website: https://www.garagebox.io

Annex 1 – Technical and Organizational Measures (TOMs)

GarageBox maintains measures that may include:

  • encryption in transit (TLS 1.2+);
  • encryption at rest where supported;
  • role-based access controls;
  • least-privilege administration;
  • administrative access logging and monitoring;
  • multi-factor authentication for privileged accounts;
  • secure configuration management;
  • regular security patching;
  • endpoint and malware protection;
  • backup and recovery procedures;
  • disaster recovery planning;
  • security awareness training; and
  • documented incident response procedures.

GarageBox may update these measures periodically, provided that the overall security posture is not materially reduced.

Annex 2 – International Transfer Mechanism

Where Personal Data originating from the European Economic Area, Switzerland, or the United Kingdom is transferred to a country that is not recognized as providing an adequate level of protection, the parties agree that:

  • the European Commission Standard Contractual Clauses (Module Two: Controller to Processor) are incorporated by reference; and
  • for UK transfers, the UK International Data Transfer Addendum applies to the SCCs.

For the purposes of the SCCs:

  • the Customer is the Data Exporter; and
  • GarageBox is the Data Importer.

The SCCs shall be deemed completed with the information contained in this DPA and the Agreement.

Annex 3 – Subprocessor Categories

GarageBox may engage Subprocessors in the following categories:

  • cloud infrastructure providers;
  • content delivery and network security providers;
  • database and backup providers;
  • email and notification providers;
  • analytics and monitoring providers;
  • customer support and ticketing providers;
  • payment processing providers; and
  • security and fraud prevention providers.

A current list of Subprocessors, including processing locations, will be made available upon request or through a designated webpage.

Execution

This DPA is deemed accepted and incorporated into the Agreement upon the earlier of:

  • the Customer's acceptance of the Agreement;
  • execution of an Order Form referencing this DPA; or
  • the Customer's use of the Services after this DPA is made available.

Where a signed version is required, the parties may execute this DPA electronically, and electronic signatures shall have the same legal effect as handwritten signatures.