Skip to content
EVstring

Draft — to be reviewed by qualified counsel before publication. Bracketed text such as [Company legal name] marks details still to be completed.

Data processing addendum

Last updated: · Status: draft

The terms under which EVstring processes personal data for its customers, covering GDPR Article 28, the UK GDPR, India’s DPDP Act 2023, the CCPA/CPRA and China’s PIPL.

1. Scope and roles

This Data Processing Addendum (“DPA”) forms part of the agreement between [Company legal name] (“EVstring”, “Processor”) and the Customer for the EVstring service (the “Agreement”). It applies where EVstring processes personal data on the Customer’s behalf (“Customer Personal Data”).

The Customer is the controller (or, under India’s DPDP Act, the data fiduciary) and EVstring is the processor (data processor). Where the Customer is itself a processor for another controller, EVstring acts as its sub-processor and the Customer warrants that its instructions are authorised by that controller. Under the CCPA, EVstring is a service provider; under China’s PIPL, EVstring is an entrusted party.

2. Details of processing

Subject matterProvision of the EVstring digital battery passport service
DurationThe term of the Agreement plus the deletion period in section 10
Nature and purposeHosting, storage, access control, display to authorised participants, audit logging, backup and support
Data subjectsCustomer’s Authorised Users; the Customer’s business contacts; vehicle owners or keepers only to the extent a VIN or image relates to them
Personal dataNames, business contact details, roles, user IDs, authentication data, activity and audit logs, IP addresses; vehicle identification numbers (restricted tier); incidental personal data in uploaded documents or photos
Special categoriesNone intended. The Customer must not upload special categories of personal data.

3. Processing on instructions

EVstring processes Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law, in which case EVstring will inform the Customer before processing unless the law prohibits it. The Agreement, this DPA and the Customer’s configuration of the Service are the Customer’s complete instructions. EVstring will tell the Customer if, in its opinion, an instruction infringes data-protection law.

4. Ledger architecture

The parties agree the following design commitments, which support data minimisation and erasure:

  • Customer Personal Data is not written to the permissioned ledger. The ledger holds identifiers, states, organisation addresses and hashes only.
  • VINs are written to the ledger only as salted hashes; the salt is stored off-chain and its deletion renders the hash unlinkable.
  • Restricted documents are encrypted with per-document keys before storage; deletion of the key (crypto-shredding) is the agreed method of erasing encrypted content that may persist in distributed storage.

5. Confidentiality of personnel

EVstring ensures that persons authorised to process Customer Personal Data are bound by confidentiality obligations and receive appropriate data-protection training, and that access is limited to those who need it.

6. Security

EVstring implements the technical and organisational measures in Annex II, including:

  • encryption in transit (TLS) and AES-256-GCM encryption of restricted documents at rest;
  • role-based access control enforced in the API and the smart contracts, with least privilege;
  • salted password hashing, sign-in throttling and account lockout;
  • audit logging of access to restricted and regulator-tier data;
  • secrets kept out of source code and logs, with per-organisation signing keys;
  • backups, tested restoration and the ability to rebuild the database from the ledger;
  • vulnerability management, dependency scanning and secure development practices.

EVstring may update these measures provided the overall level of protection is not reduced.

7. Sub-processors

The Customer gives general authorisation for EVstring to engage the sub-processors listed in Annex III. EVstring will give at least [30] days’ notice of a new sub-processor, during which the Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected service and receive a refund of prepaid fees. EVstring imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for their performance.

8. Data subject requests and assistance

Taking into account the nature of the processing, EVstring will assist the Customer with appropriate technical and organisational measures to respond to requests from data subjects or data principals (including access, correction, erasure and portability), and with security, breach notification, data protection impact assessments and prior consultation with authorities. EVstring will forward to the Customer any request it receives directly that relates to Customer Personal Data and will not respond except on the Customer’s instructions.

9. Personal data breaches

EVstring will notify the Customer without undue delay, and in any event within [48] hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information the Customer reasonably needs to meet its own notification obligations (including under GDPR Art. 33–34 and the DPDP Rules), and will update that information as it becomes available. EVstring will take reasonable steps to contain and remedy the breach.

10. Return and deletion

On termination of the Agreement, EVstring will make Customer Personal Data available for export for [30] days and will then delete it, including by crypto-shredding encrypted documents, within [90] days, unless the law requires retention. Backups are overwritten on their normal cycle. On-chain records, which contain no personal data, are not deleted.

11. Information and audits

EVstring will make available the information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, by the Customer or an independent auditor mandated by it, on at least [30] days’ notice, no more than once a year unless required by an authority or following a breach, during business hours and subject to confidentiality. EVstring does not currently hold third-party security certifications; it will share any it obtains.

12. International transfers

Customer Personal Data is hosted in [Primary hosting region]. EVstring will not transfer it outside the region selected by the Customer except in accordance with this section.

  • EU/EEA: transfers to a country without an adequacy decision are governed by the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 (Module Two, or Module Three where the Customer is a processor), which are incorporated by reference. Clause 7 (docking) applies; option 2 of Clause 9 applies with the notice period in section 7; option 1 of Clause 11 does not apply; Clauses 17 and 18 select [Member State] law and courts.
  • UK: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses applies.
  • Switzerland: the Standard Contractual Clauses apply with the adaptations required by the Federal Act on Data Protection.
  • India: EVstring will not transfer Customer Personal Data to a country or territory restricted by notification of the Central Government under section 16 of the DPDP Act.
  • China: where PIPL applies, EVstring will support the Customer in completing a security assessment, standard contract filing or certification before any transfer out of mainland China.

EVstring will carry out and document transfer impact assessments where required.

13. India: DPDP Act 2023

EVstring processes Customer Personal Data only under this valid contract with the data fiduciary, as section 8(2) of the DPDP Act requires. It will implement reasonable security safeguards to prevent personal data breach, assist the Customer to honour data principal rights and consent withdrawals (including those received through a registered consent manager), and erase Customer Personal Data when instructed or when the Customer informs EVstring that the specified purpose is no longer served.

14. California: CCPA / CPRA

As a service provider, EVstring will not:

  • sell or share the Customer’s personal information;
  • retain, use or disclose it for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship with the Customer;
  • combine it with personal information received from others, except as the CCPA regulations permit.

EVstring will comply with the CCPA, provide the same level of privacy protection it requires, notify the Customer if it can no longer meet its obligations, and allow the Customer to take reasonable steps to stop and remediate unauthorised use. EVstring certifies that it understands and will comply with these restrictions.

15. China: PIPL entrusted processing

Where PIPL applies, EVstring will process personal information only as agreed in this DPA regarding purpose, duration, method, categories and protection measures, will not further entrust processing without the Customer’s consent, and will return or delete personal information when the entrustment ends.

16. Liability and precedence

Each party’s liability under this DPA is subject to the limitations in the Agreement, except where the law or the Standard Contractual Clauses provide otherwise. If this DPA conflicts with the Agreement, this DPA prevails for the processing of personal data; the Standard Contractual Clauses prevail over both.

17. Annexes

Annex I: Parties and description of processing

Data exporter: the Customer, [Customer name and address], contact [Customer DPO / privacy contact]. Data importer: [Company legal name], [Registered address], contact [DPO email address]. Description of processing: as set out in section 2.

Annex II: Technical and organisational measures

As described in section 6, together with [link to detailed security documentation].

Annex III: Sub-processors

Sub-processorServiceLocation
[Hosting provider]Infrastructure hosting[Region]
[Email provider]Transactional email[Region]
[Support tooling provider]Customer support[Region]

Questions about this DPA: [privacy contact email]. See also our Privacy policy and compliance mapping.