Legal
GDPR-compliant data processing terms for enterprise customers using the MobilitySQR platform.
Last updated: June 9, 2026
For the purposes of this Data Processing Agreement ("DPA"), the following definitions apply:
MobilitySQR processes Personal Data on behalf of the Customer solely for the purpose of providing global mobility services through the MobilitySQR platform, as described in the applicable service agreement.
This DPA applies to all Personal Data processed by MobilitySQR in connection with the Services and supplements the Terms of Service and any other agreements between the parties. In the event of a conflict between this DPA and the Terms of Service regarding data protection matters, this DPA shall prevail.
MobilitySQR may process the following categories of Personal Data on behalf of the Customer:
MobilitySQR shall process Personal Data only on documented instructions from the Customer, unless required to do so by European Union or Member State law to which MobilitySQR is subject. In such a case, MobilitySQR shall inform the Customer of that legal requirement before processing, unless prohibited by law.
The Customer's instructions for data processing are set out in the service agreement and this DPA. Any additional or modified instructions must be agreed upon in writing by both parties.
MobilitySQR shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
MobilitySQR ensures that all personnel authorized to process Personal Data have committed to confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
Access to Personal Data is restricted to those employees and contractors who require such access for the performance of the Services, and is governed by the principle of least privilege.
For full details on our security posture, please refer to our Security page.
MobilitySQR uses the following categories of sub-processors in the delivery of the Services:
MobilitySQR shall notify the Customer at least 30 days before engaging any new sub-processor, providing details of the sub-processor's identity, location, and the processing activities to be performed.
The Customer may object to the appointment of a new sub-processor by notifying MobilitySQR in writing within 14 days of receiving notice. If the objection is not resolved to the Customer's reasonable satisfaction, the Customer may terminate the affected Services without penalty.
MobilitySQR shall impose data protection obligations on each sub-processor no less protective than those set out in this DPA, and shall remain fully liable for the acts and omissions of its sub-processors.
MobilitySQR shall assist the Customer in fulfilling its obligation to respond to requests from Data Subjects exercising their rights under applicable data protection law, including:
MobilitySQR shall notify the Customer promptly if it receives a request directly from a Data Subject and shall not respond to such request without the Customer's prior written authorization, unless legally obligated to do so.
MobilitySQR shall notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Customer's data.
The notification shall include:
MobilitySQR shall cooperate fully with the Customer in investigating the breach, mitigating its effects, and meeting any reporting obligations to Supervisory Authorities or Data Subjects.
Where Personal Data is transferred outside the European Economic Area (EEA) or the United Kingdom, MobilitySQR shall ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR.
Transfers are protected by the European Commission's Standard Contractual Clauses (SCCs), as adopted under Commission Implementing Decision (EU) 2021/914, supplemented by additional technical and organizational measures where necessary.
MobilitySQR maintains a record of all international transfers of Personal Data, including the destination country, the legal basis for the transfer, and the safeguards applied. This record is available to the Customer upon request.
The Customer, or an independent third-party auditor appointed by the Customer, may audit MobilitySQR's compliance with this DPA. Audits may be conducted no more than once per year, with at least 30 days' prior written notice, and shall be conducted during normal business hours in a manner that minimizes disruption to MobilitySQR's operations.
MobilitySQR shall provide all information reasonably necessary to demonstrate compliance and shall cooperate fully with the audit process.
As an alternative to on-site audits, MobilitySQR provides its current SOC 2 Type II report and other relevant compliance certifications as evidence of its security and data protection practices. These reports are available upon request under NDA.
Upon termination or expiry of the service agreement, MobilitySQR shall, at the Customer's written election:
In either case, MobilitySQR shall complete the return or deletion within 30 days of receiving the Customer's instruction, and shall provide written certification of deletion upon request.
MobilitySQR may retain Personal Data beyond this period only where retention is required by applicable law, in which case it shall inform the Customer of the legal basis and scope of the required retention, and shall continue to protect such data in accordance with this DPA.
This DPA shall be governed by the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR, as applicable, with respect to the processing of Personal Data of EU and UK Data Subjects respectively.
This DPA supplements and forms an integral part of the Terms of Service. In the event of any conflict between this DPA and the Terms of Service regarding the processing and protection of Personal Data, the provisions of this DPA shall prevail.
Any disputes arising from this DPA shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.
Enterprise customers can request a countersigned Data Processing Agreement. Contact our legal team to get started.
Request Signed DPA