Legal
Data Processing Agreement
Dotra Compliance Platform
This Data Processing Agreement (this “DPA”) is entered into by and between VisionaryV LLC, a Texas limited liability company (“Processor,” “Provider,” “we,” or “us”), and the entity identified in the signature block below (“Controller,” “Customer,” or “you”), and supplements the Master Subscription Agreement between the Parties (the “MSA”). This DPA is effective as of the date last signed below (the “DPA Effective Date”).
Capitalized terms not defined in this DPA have the meanings given in the MSA. In the event of any conflict between this DPA and the MSA with respect to the processing of Personal Data, this DPA controls.
1. Definitions
“Applicable Data Protection Laws” means all U.S. federal and state laws and regulations applicable to the processing of Personal Data, including without limitation the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), the Texas Data Privacy and Security Act (“TDPSA”), and the comprehensive consumer privacy laws of Virginia, Colorado, Connecticut, Utah, and other states as they take effect, in each case as amended from time to time.
“Controller” means the entity that determines the purposes and means of the processing of Personal Data. The Parties acknowledge that, with respect to Customer Data, Customer is the Controller. Equivalent terms used in Applicable Data Protection Laws (such as “business” under CCPA) have the same meaning as Controller for purposes of this DPA.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates, including without limitation drivers, employees, contractors, and other personnel of Customer.
“Personal Data” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Data Subject, that is contained within Customer Data and processed by Processor on behalf of Controller under the MSA.
“Processing” means any operation or set of operations performed on Personal Data, including without limitation collection, recording, organization, storage, access, retrieval, use, disclosure, transmission, deletion, or destruction.
“Processor” means the entity that processes Personal Data on behalf of the Controller. The Parties acknowledge that, with respect to Customer Data, Provider is the Processor. Equivalent terms used in Applicable Data Protection Laws (such as “service provider” under CCPA) have the same meaning as Processor for purposes of this DPA.
“Security Incident” means any unauthorized access to, disclosure of, alteration of, loss of, or destruction of Personal Data that Processor processes on behalf of Controller.
“Sensitive Personal Information” means the categories of Personal Data designated as “sensitive personal information,” “sensitive personal data,” or comparable terms under Applicable Data Protection Laws, including without limitation Social Security Numbers, driver's license numbers, government identifiers, and information about a Data Subject's health.
“Subprocessor” means any third party engaged by Processor to process Personal Data on behalf of Controller.
2. Roles and Scope of Processing
2.1 Roles.
With respect to the processing of Personal Data under the MSA: (a) Customer is the Controller; and (b) Provider is the Processor acting on behalf of Customer. Each Party will comply with its respective obligations under Applicable Data Protection Laws.
2.2 Scope.
This DPA applies to all processing of Personal Data by Provider as Processor in the course of providing the Services to Customer under the MSA. The subject matter, duration, nature, purpose, and categories of Personal Data processed, and categories of Data Subjects, are described in Annex A (Description of Processing).
2.3 Compliance.
Customer is responsible for ensuring that its provision of Personal Data to Provider and Provider's processing of Personal Data as described in this DPA and the MSA complies with Applicable Data Protection Laws. Customer represents and warrants that it has provided all required notices and obtained all required consents, authorizations, or other lawful bases for Provider's processing of Personal Data as contemplated by this DPA and the MSA. Provider will comply with its obligations as a Processor under Applicable Data Protection Laws.
3. Processor Obligations
3.1 Documented Instructions.
Provider will process Personal Data only on documented instructions from Customer, including with respect to international transfers, except to the extent required by applicable law. The MSA, this DPA, and Customer's use of the Services constitute Customer's documented instructions for processing. Provider will inform Customer if, in Provider's opinion, an instruction infringes Applicable Data Protection Laws.
3.2 Restrictions on Use.
Provider will not: (a) sell or share Personal Data within the meaning of the CCPA or other Applicable Data Protection Laws; (b) retain, use, or disclose Personal Data for any purpose other than the specific business purpose of providing the Services, except as permitted by Applicable Data Protection Laws; (c) retain, use, or disclose Personal Data outside of the direct business relationship between the Parties, except as permitted by Applicable Data Protection Laws; or (d) combine Personal Data with personal information that Provider receives from or on behalf of another person or entity, or collects from its own interaction with a Data Subject, except as permitted by Applicable Data Protection Laws.
3.3 Confidentiality.
Provider will ensure that personnel authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to Personal Data is limited to personnel who require such access to perform their duties.
3.4 Compliance Certification.
Provider certifies that it understands the restrictions in this Section 3 and Applicable Data Protection Laws, and will comply with them.
3.5 Administrative and Support Access.
Provider's authorized personnel may access Personal Data, including Sensitive Personal Information, on a read-only basis for the purpose of providing customer support, troubleshooting, account onboarding and administration, verifying compliance-related information at Customer's request, and maintaining the security and integrity of the Services. Such access constitutes Processing under Customer's documented instructions described in Section 3.1, is restricted to personnel who require such access to perform their duties consistent with Section 3.3, and is logged as described in Annex B. Provider's personnel do not have the ability to create, edit, or delete Personal Data through such read-only administrative access, which does not include conducting, administering, or evaluating any drug or alcohol test. The random-selection tool described in Section 3.6 is separate from and additional to the administrative access described in this Section 3.5.
3.6 Random Testing Selection Tool.
Where Customer has two (2) or more CDL drivers, Provider makes available through the Services a random-selection tool that Customer uses to assist in administering Customer's own drug and alcohol testing program, as described in the MSA. Provider's role with respect to this tool is limited to: (a) generating random-selection outputs based on the driver roster Customer maintains in the Services; and (b) storing any drug and alcohol test results or related records that Customer chooses to upload. Customer, as the employer, remains solely responsible for operating its testing program, engaging all required service agents (including collection sites and Medical Review Officers), reporting violations to the FMCSA Clearinghouse, conducting required Clearinghouse queries, and ensuring its overall program satisfies applicable regulatory requirements. Provider does not act as a Consortium/Third-Party Administrator with respect to Customer's testing program, does not act on Customer's behalf in the FMCSA Clearinghouse, and does not conduct, administer, or evaluate drug or alcohol tests. This functionality is not available to customers with a single CDL driver or to owner-operators, who must enroll in an external qualified consortium to meet their applicable random testing requirements independently of the Services.
4. Security Measures
4.1 Technical and Organizational Measures.
Provider will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. Such measures are described in Annex B (Security Measures) and may be updated by Provider from time to time, provided that any updates will not materially decrease the overall level of protection.
4.2 Risk-Based Approach.
The measures described in Annex B reflect the state of the art, the costs of implementation, the nature, scope, context, and purposes of the processing, and the risk to the rights and freedoms of Data Subjects.
5. Subprocessors
5.1 General Authorization.
Customer provides general authorization for Provider to engage Subprocessors to process Personal Data in connection with the Services, subject to the requirements of this Section 5.
5.2 List of Subprocessors.
A current list of Provider's Subprocessors is provided in Annex C (Current Subprocessors), which Customer acknowledges and approves. Provider will maintain an up-to-date list of Subprocessors and will make it available to Customer upon written request.
5.3 Notice of New Subprocessors.
Provider will provide Customer with at least thirty (30) days' prior written notice (which may be by email to the Customer's designated contact) of any intended addition or replacement of a Subprocessor that processes Personal Data. Customer may object to such addition or replacement on reasonable grounds related to the Subprocessor's ability to comply with Applicable Data Protection Laws by providing written notice to Provider within fifteen (15) business days of receipt of Provider's notice. If Customer objects, the Parties will work in good faith to resolve the objection; if the Parties are unable to resolve the objection within a reasonable time, Customer may, as its sole and exclusive remedy, terminate the affected portion of the Services by providing written notice to Provider, in which case Customer will be entitled to a pro-rated refund of any prepaid fees for the unused portion of the then-current billing cycle.
5.4 Subprocessor Obligations.
Provider will enter into a written agreement with each Subprocessor that imposes data protection obligations on the Subprocessor that are substantially equivalent to those imposed on Provider under this DPA, to the extent applicable to the nature of the services provided by the Subprocessor.
5.5 Liability for Subprocessors.
Provider remains responsible for the acts and omissions of its Subprocessors with respect to the processing of Personal Data to the same extent as if Provider were performing the services directly, subject to the limitations of liability set forth in the MSA.
6. Data Subject Rights
6.1 Assistance.
Taking into account the nature of the processing, Provider will assist Customer through appropriate technical and organizational measures, insofar as commercially reasonable, in fulfilling Customer's obligations to respond to verifiable requests by Data Subjects to exercise their rights under Applicable Data Protection Laws, including rights of access, correction, deletion, portability, and opt-out of sale or sharing.
6.2 Forwarding Requests.
If Provider receives a request from a Data Subject directly relating to Personal Data processed on behalf of Customer, Provider will: (a) not respond to the request on its own behalf except to confirm that the request relates to Customer; and (b) promptly forward the request to Customer or direct the Data Subject to contact Customer.
6.3 Customer Responsibility.
Customer is responsible for responding to Data Subject requests and for determining whether and how to do so. Provider has no obligation to assess the validity of Data Subject requests received by Customer.
7. Security Incidents
7.1 Notification.
Provider will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident. Such notification will be made to the Customer contact identified in the MSA or otherwise designated by Customer in writing.
7.2 Information Provided.
To the extent reasonably available at the time of notification, Provider's notification will include: (a) a description of the nature of the Security Incident, including the categories and approximate number of Data Subjects affected and the categories and approximate volume of Personal Data records affected; (b) the contact details of Provider's point of contact for further information; (c) a description of the likely consequences of the Security Incident; and (d) a description of the measures Provider has taken or proposes to take to address the Security Incident, including measures to mitigate adverse effects. Where it is not possible to provide all of this information at the same time, the information may be provided in phases without further undue delay.
7.3 Cooperation.
Provider will reasonably cooperate with Customer in investigating and responding to a Security Incident, including providing Customer with reasonably available information necessary for Customer to comply with its notification obligations under Applicable Data Protection Laws.
7.4 No Admission.
Provider's notification of or response to a Security Incident under this Section 7 will not be construed as an acknowledgment by Provider of any fault or liability with respect to the Security Incident.
8. Audits and Demonstrating Compliance
8.1 Annual Self-Attestation.
On an annual basis, upon Customer's written request, Provider will provide a written self-attestation confirming Provider's compliance with this DPA and the security measures described in Annex B.
8.2 Documentation.
Provider will make available to Customer, upon Customer's reasonable written request and no more than once per twelve (12) month period (except in the event of a Security Incident or as required by a supervisory authority), reasonable documentation evidencing Provider's compliance with this DPA, which may include: (a) Provider's then-current information security policies; (b) summary descriptions of Provider's technical and organizational measures; (c) responses to a standard security questionnaire (such as the SIG-Lite or CAIQ); and (d) if and when available, copies of Provider's most recent third-party audit reports (such as SOC 2).
8.3 No On-Site Audits.
Customer may not conduct on-site audits of Provider's facilities. The documentation provided pursuant to Section 8.2 constitutes Customer's exclusive means of verifying Provider's compliance with this DPA, except where on-site audit rights are mandated by Applicable Data Protection Laws and cannot be waived, in which case the Parties will negotiate in good faith reasonable scope, timing, and confidentiality terms for any such audit.
8.4 Confidentiality of Audit Materials.
Any documentation or information provided by Provider pursuant to this Section 8 is Provider's Confidential Information under the MSA and may be used by Customer solely for the purpose of verifying Provider's compliance with this DPA.
9. Return and Deletion of Personal Data
9.1 Return or Deletion.
Upon expiration or termination of the MSA, Provider will, at Customer's election made in writing within thirty (30) days of such expiration or termination, either: (a) make Customer Data available for export to Customer in a commercially reasonable format; or (b) delete Customer Data from Provider's production systems. If Customer does not make an election within such thirty (30) day period, Provider may delete Customer Data.
9.2 Backups.
Notwithstanding Section 9.1, Provider may retain backup copies of Customer Data for up to ninety (90) days following deletion from production systems, after which such backup copies will be deleted in accordance with Provider's standard data retention policies.
9.3 Retention as Required by Law.
Notwithstanding Sections 9.1 and 9.2, Provider may retain Personal Data to the extent and for the period required by applicable law, provided that Provider will continue to apply the protections of this DPA to any such retained Personal Data and will use such Personal Data solely for the purposes that necessitated its retention.
10. International Data Transfers
The Services are provided from, and Personal Data is processed within, the United States. Customer acknowledges that this is the agreed-upon location for the processing of Personal Data. If Provider processes Personal Data outside of the United States, Provider will do so only in compliance with Applicable Data Protection Laws and on the basis of an appropriate transfer mechanism.
11. Liability
Each Party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set forth in the MSA. Any reference in the MSA to the liability of a Party includes that Party's liability under this DPA.
12. General Provisions
12.1 Term.
This DPA is effective as of the DPA Effective Date and will continue until the later of: (a) the expiration or termination of the MSA; or (b) the date Provider ceases to process Personal Data on behalf of Customer.
12.2 Order of Precedence.
In the event of a conflict between this DPA and the MSA with respect to the processing of Personal Data, this DPA controls. With respect to all other matters, the MSA controls.
12.3 Amendments.
The Parties may amend this DPA by mutual written agreement. Provider may update this DPA from time to time as required to reflect changes in Applicable Data Protection Laws, provided that any such update will not materially diminish the protections afforded to Personal Data under this DPA.
12.4 Governing Law and Venue.
This DPA is governed by the laws of the State of Texas, and the Parties consent to the jurisdiction and venue set forth in the MSA.
12.5 Severability.
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions will remain in full force and effect, and the invalid or unenforceable provision will be modified to the minimum extent necessary to make it valid and enforceable.
12.6 Counterparts.
This DPA may be executed in counterparts and by electronic signature, each of which is deemed an original.
Signature Block
IN WITNESS WHEREOF, the Parties have caused this DPA to be executed by their duly authorized representatives as of the DPA Effective Date.
Processor
VisionaryV LLC
- By
- Name
- Title
- Date
Controller (Customer)
- Entity Name
- By
- Name
- Title
- Date
Annex A — Description of Processing
1. Subject Matter.
Provision of the Dotra compliance platform and related services to Customer as described in the MSA and applicable Order Form.
2. Duration.
The duration of the MSA and any applicable Order Form, plus any post-termination period during which Provider retains Personal Data pursuant to Section 9 of this DPA.
3. Nature and Purpose.
Hosting, storage, retrieval, organization, processing, and transmission of regulatory compliance documents and related Personal Data, for the purpose of helping Customer manage compliance with motor carrier and transportation regulations applicable to Customer's business.
4. Categories of Data Subjects.
Categories of Data Subjects whose Personal Data may be processed include:
- Drivers and prospective drivers employed by or contracting with Customer;
- Employees, officers, and contractors of Customer (other than drivers);
- Authorized Users of the Services designated by Customer; and
- Other individuals whose Personal Data is contained in Customer's regulatory compliance records.
5. Categories of Personal Data.
Categories of Personal Data that may be processed include:
- Identifiers: name, business or personal contact information, date of birth, driver's license number, USDOT or MC number references, and similar identifiers;
- Employment-related information: hire and termination dates, job title, employment status, qualifications, and training records;
- Regulatory compliance information: medical examiner's certificates and related health-related information limited to fitness for duty; drug and alcohol testing records (which may include limited Sensitive Personal Information such as Social Security Numbers where required by 49 C.F.R. Part 40); driver qualification files; hours-of-service records; vehicle inspection records; accident records; and other records required under the Federal Motor Carrier Safety Regulations and applicable state regulations;
- Operational data: assignments, routes (to the extent provided by Customer), and other operational information that Customer chooses to upload;
- Authorized User account information: account credentials and usage information of Authorized Users.
6. Sensitive Personal Information.
To the extent Customer uploads Sensitive Personal Information (including Social Security Numbers or health-related information), Provider will process such information solely for the purposes set forth in this Annex A and in accordance with the security measures set forth in Annex B. Provider's access to Sensitive Personal Information through the read-only administrative access described in Section 3.5 is limited to displaying records furnished or maintained by Customer. Where Customer has two (2) or more CDL drivers, Provider also processes driver roster information through the random-selection tool described in Section 3.6 for the purpose of generating selection outputs that Customer uses in administering its own testing program; Provider does not act as a Consortium/Third-Party Administrator with respect to any such information and does not interact with the FMCSA Clearinghouse on Customer's behalf in connection with this tool.
7. Frequency of Processing.
Continuous, during the term of the MSA.
Annex B — Security Measures
Provider implements and maintains the following technical and organizational measures designed to protect Personal Data. Specific measures may be updated by Provider from time to time, provided that any updates will not materially decrease the overall level of protection.
- Access Controls. Role-based access controls limit access to Personal Data to authorized personnel who require access to perform their duties. Authentication mechanisms include unique user identifiers and strong password requirements. Multi-factor authentication is required for administrative access to systems that process Personal Data. Read-only administrative access by Provider personnel to Customer accounts, as described in Section 3.5, is restricted to authorized personnel and is logged in accordance with Section 6 below.
- Encryption. Personal Data is encrypted in transit using industry-standard transport-layer security protocols (such as TLS 1.2 or later). Personal Data at rest is encrypted using industry-standard encryption algorithms (such as AES-256).
- Network Security. Network-level controls include the use of firewalls, intrusion detection mechanisms, and segmentation of production and non-production environments. Production systems are hosted by reputable cloud infrastructure providers with established security certifications (such as SOC 2 or ISO 27001).
- Application Security. Provider follows secure software development practices, including code review of changes that affect security-relevant functions, dependency management, and remediation of known vulnerabilities in a timely manner based on severity.
- Personnel Security. Personnel with access to Personal Data are required to undergo background checks where permitted by applicable law and are bound by written confidentiality obligations. Personnel receive regular training on data protection and security responsibilities.
- Logging and Monitoring. Provider maintains logs of administrative and security-relevant events within its production systems and monitors such logs for anomalous activity. Logs are retained for a period consistent with operational and legal requirements.
- Vulnerability Management. Provider applies security patches and updates to systems on a risk-prioritized basis. Provider performs periodic vulnerability assessments of its systems.
- Business Continuity. Provider maintains backup and disaster recovery procedures designed to restore the availability of Personal Data and the Services within reasonable timeframes following an outage or incident.
- Incident Response. Provider maintains a documented incident response plan that defines roles, communication channels, and escalation procedures for responding to suspected Security Incidents.
- Vendor Management. Provider performs reasonable due diligence on Subprocessors prior to engagement and imposes contractual obligations on Subprocessors consistent with this DPA.
- Physical Security. Provider does not operate its own data centers. Production infrastructure is hosted by third-party cloud providers that maintain industry-standard physical security controls at their facilities, including controlled access, monitoring, and environmental safeguards.
- Data Minimization and Retention. Provider processes Personal Data only as necessary to provide the Services and applies retention practices designed to limit the retention of Personal Data beyond what is needed for the agreed processing purposes.
Annex C — Current Subprocessors
Provider currently engages the Subprocessors listed below to process Personal Data in connection with the Services. This list may be updated from time to time in accordance with Section 5 of this DPA. The most current list will be made available upon written request.
- Vercel, Inc. — Application hosting and content delivery. Location of Processing: United States.
- Supabase, Inc. — Database hosting, authentication, and file storage. Location of Processing: United States.
- Stripe, Inc. — Payment processing. Location of Processing: United States.
- Google LLC — Email, productivity, and business communications (Google Workspace); website analytics (Google Analytics); tag management and conversion tracking on the public marketing site only (Google Tag Manager, Google Ads). Location of Processing: United States.
- Meta Platforms, Inc. — Conversion tracking and advertising measurement on the public marketing site only (Meta Pixel). Location of Processing: United States.
- [Additional Subprocessors] — [To be added as engaged — e.g., document processing or AI service providers]. Location: [Location].
Note: Google Tag Manager, Google Ads conversion tracking, and the Meta Pixel are deployed on the public marketing site (dotracompliance.com) only. These tools are not active within the authenticated Dotra application where Customer Data is managed, and they do not process Customer Data as defined in this DPA. Additional Subprocessors may be added in accordance with the notice and objection procedures set forth in Section 5 of this DPA.