FleetCifu Data Processing Addendum
Last updated: 9 October 2026
This addendum forms part of the FleetCifu Customer Agreement between the parties (the "Agreement"). If it conflicts with the Agreement on anything about personal data, this addendum wins.
1. Definitions
- Data Protection Law means the Cayman Islands Data Protection Act (2021 Revision) and its regulations. It also includes any other data protection law that applies to the Customer's use of the Service, to the extent it applies (see clause 13).
- Personal Data, Sensitive Personal Data, data controller, data processor, data subject and processing have the meanings given in Data Protection Law.
- Customer Personal Data means Personal Data in Customer Data that we process for the Customer under the Agreement.
- Face Data means driver enrolment photos, face images captured for matching, and any face templates or measurements made from them.
- Personal Data Breach means a breach of security that leads to the accidental or unlawful loss, destruction, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- Subprocessor means a third party we engage that processes Customer Personal Data.
- Other capitalised terms have the meanings in the Agreement.
2. Roles
2.1 The Customer is the data controller of Customer Personal Data. It decides why and how its vehicles, drivers and Users are tracked and recorded. We are the Customer's data processor.
2.2 We are a data controller only for our own business information about the Customer: account administration, billing, contract records and security logs about access to our systems. That information is covered by our Privacy Policy.
2.3 Annex 1 sets out the details of the processing.
3. Customer's responsibilities
3.1 The Customer is responsible for having a lawful basis under Data Protection Law and employment law for the processing it asks us to do. In particular, it will:
(a) tell drivers, staff and, where relevant, passengers about vehicle tracking and in-cab and road-facing recording before it starts. We provide a driver notice template and an in-cab sticker;
(b) obtain each driver's informed, freely given consent before enrolling them for face matching. It will keep a record of that consent and tell us promptly, through the app, when a driver withdraws consent or leaves;
(c) set retention periods in the app that are no longer than it needs;
(d) give only authorised people access, with the right roles; and
(e) make sure its instructions to us comply with Data Protection Law.
3.2 The Customer's instructions are set out in the Agreement, this addendum, and the settings it chooses in the app. Other instructions must be in writing and agreed by us. Extra work may be charged at agreed rates.
4. Our obligations
4.1 Instructions. We process Customer Personal Data only on the Customer's documented instructions, unless the law requires otherwise. In that case we tell the Customer first, where the law allows. We tell the Customer if we believe an instruction breaks Data Protection Law.
4.2 Purpose limitation. We process Customer Personal Data only to:
(a) provide the Service to the Customer, including:
- maps, trips and playback;
- safety alerts and clips;
- coaching messages;
- reports;
- alert emails and messages;
- answers from Cifu; and
- face matching where enabled;
(b) provide support, keep the Service secure and prevent abuse; and
(c) comply with law.
We do not use it for our own marketing, profiling or any other purpose.
4.3 What we never do.
(a) We do not sell, rent or trade Customer Personal Data, driver data or Face Data.
(b) We do not share Face Data with anyone outside the Customer's authorised Users, except a Subprocessor needed to perform the match (if one is used and listed in Annex 3) or where the law requires it.
(c) We do not use Customer Personal Data or Face Data to train shared AI models that serve other customers. We switch on the no-training and minimal-retention options our AI providers offer, and we do not opt the Customer into any provider training program.
(d) We do not use the Service for continuous in-cab facial recognition.
(e) We do not combine one customer's Personal Data with another customer's, except as anonymised, aggregated statistics that cannot identify any customer, vehicle or person.
4.4 Confidentiality of staff. Only staff and contractors who need access to provide the Service can access Customer Personal Data, and they are bound to keep it confidential.
4.5 Security. We maintain the technical and organisational measures in Annex 2, appropriate to the risk. We may improve these measures but will not reduce the overall level of protection.
5. Driver face matching
5.1 Face matching is off unless the Customer turns it on and is used only once the Customer confirms driver consent under clause 3.1(b).
5.2 Purpose. Face Data is used only to check which enrolled driver is driving:
- at the start of a trip; and
- if the Customer chooses, in occasional rate-limited spot checks.
Each trip is labelled as matched, not matched or unknown, for a person to review. Face-match results are aids, not final decisions. The Customer will not take disciplinary action based only on an automated match result without human review.
5.3 Sensitive data. The parties treat Face Data as sensitive personal data and apply the extra protections in this clause.
5.4 Access. Only Users the Customer gives a face-review or owner role can view Face Data. Views of enrolment photos and match images are logged.
5.5 Retention.
- Enrolment photos are kept while the driver is enrolled.
- They are deleted within 7 days after the Customer removes the driver or records a withdrawal of consent.
- Match images are kept for the period in Annex 4. Then they are deleted, leaving only the match result on the trip.
6. Subprocessors
6.1 The Customer gives general authorisation for us to use the Subprocessors listed in Annex 3.
6.2 We bind each Subprocessor by written contract to data protection terms that protect Customer Personal Data at least as well as this addendum. We remain responsible for their performance.
6.3 We will give at least 30 days' notice of a new or replacement Subprocessor, by email or in the app. The Customer may object on reasonable data protection grounds within that period. We will then discuss the objection in good faith. If we cannot resolve it, the Customer may end the affected Service without penalty and receive a refund of prepaid fees for the unused period.
7. Where data is stored and international transfers
7.1 Customer Personal Data is stored and processed by our cloud providers, which may be outside the Cayman Islands. The hosting region is stated in Annex 3.
7.2 Where Customer Personal Data is transferred outside the Cayman Islands, we make sure the transfer meets Data Protection Law. We do this through the provider's contractual commitments, and through technical safeguards such as encryption in transit and at rest.
8. Personal Data Breaches
8.1 We notify the Customer without undue delay, and in any case within 48 hours, after we become aware of a Personal Data Breach. We do this so the Customer can meet its own notice duties under Data Protection Law.
8.2 The notice describes, as far as known at the time:
- what happened;
- the categories and approximate number of people and records affected;
- likely consequences;
- what we have done or propose to do; and
- a contact for more information.
We update the Customer as we learn more.
8.3 We take reasonable steps to contain the breach and reduce harm. We support the Customer in any notice to the Ombudsman and affected people. We do not notify the Ombudsman or data subjects about Customer Personal Data on the Customer's behalf unless the Customer asks or the law requires it.
9. Helping the Customer
9.1 Requests from individuals. If a driver, staff member or other person contacts us directly about Customer Personal Data, we pass the request to the Customer. We do not respond ourselves except to redirect them, unless the Customer asks us to. We give reasonable help, mainly through the app's export and delete tools, so the Customer can respond to requests to access, correct, delete or object.
9.2 Assessments and the Ombudsman. We give reasonable information and help for the Customer's data protection impact assessments and any enquiry from the Ombudsman about the Service. Help that goes beyond providing existing documents may be charged at agreed rates.
10. Information and audits
10.1 On request, and no more than once a year unless there has been a Personal Data Breach or a regulator requires it, we will:
- answer a reasonable security and privacy questionnaire; and
- provide the current version of our security summary and Subprocessor list.
10.2 If that is not enough to show compliance, the Customer may audit our compliance with this addendum. This requires at least 30 days' notice, takes place during business hours, is at the Customer's cost, uses an auditor bound by confidentiality, and is limited to our own systems and records. It must not compromise other customers' data or our Subprocessors' security. Audits of Subprocessors rely on their own published reports and certifications.
11. Retention, return and deletion
11.1 During the Agreement, Customer Personal Data is kept for the periods the Customer sets in the app. Where no setting is chosen, the defaults in Annex 4 apply.
11.2 When the Agreement ends, the Customer can export its data in a machine-readable format for 30 days. We then delete or anonymise Customer Personal Data within 30 days after that export window closes, including from live systems.
11.3 Backup copies are overwritten in the normal backup cycle within 35 days. Until then they are kept secure and not used.
11.4 We may keep data only where the law requires it, and then only for that purpose and for as long as required. We confirm deletion in writing on request.
12. Liability
12.1 Each party's liability under this addendum is subject to the limits and exclusions in the Agreement, including the data protection cap in clause 13.3 of the Agreement.
13. Other laws
13.1 If the Customer tells us in writing that another data protection law applies to its Customer Personal Data, the parties will agree in good faith any extra terms that law needs. For example, this could be the UK or EU General Data Protection Regulation because the Customer operates or has drivers there. Nothing in this addendum says that we are registered with, or regulated by, any authority outside the Cayman Islands.
14. Term
14.1 This addendum lasts as long as we process Customer Personal Data under the Agreement, and continues after the Agreement ends until deletion is complete.
Signed for IC 360 Ltd
Name: ____________________ Title: ____________________ Date: __________
Signed for the Customer
Name: ____________________ Title: ____________________ Date: __________
Annex 1: Details of processing
| Subject matter | Providing the FleetCifu platform and CIFU AI Dashcam package to the Customer |
| Duration | The term of the Agreement plus the export and deletion period in clause 11 |
| Nature of processing | Collection from vehicles and Users; storage; display; analysis (alerts, scoring, summaries); transmission of alerts and messages; face matching where enabled; export; deletion |
| Purpose | As in clause 4.2 only |
| Data subjects | The Customer's drivers, other staff and Users; passengers and people outside the vehicle who are captured incidentally in video or audio; recipients of alerts |
| Categories of Personal Data | Account: names, work email addresses, roles and sign-in records of Users. Vehicle and trip: GPS location, speed, heading, ignition, trips, stops, geofence visits and vehicle diagnostics, linked to vehicle and driver. Camera: video, still images and in-cab audio from road-facing, cabin and rear cameras, plus safety alerts (for example forward-collision, lane-departure, distraction, phone use, fatigue). Driver: names, contact details for alerts and coaching, and driving scores. Assistant: questions to Cifu and answers, and transcripts of spoken questions where voice is enabled. Technical: device identifiers, connection, security and audit logs |
| Sensitive Personal Data | Face Data, only where face matching is enabled (clause 5). Video or audio may incidentally reveal sensitive information; it is not processed to extract it |
| Frequency | Continuous while vehicles are running and the Service is active |
Annex 2: Security measures (summary)
- Encryption: data is encrypted in transit (HTTPS/TLS) between the app, our servers and providers, and at rest at the hosting storage layer. Selected driver contact details are encrypted at the application layer.
- Access control: role-based access in the app (owner, manager, viewer and face-review roles). Each customer's data is kept separate by account. Staff access to production systems is limited to named people who need it and requires strong authentication.
- Logging: sensitive actions are logged, including assistant-confirmed actions, settings changes and access to Face Data.
- Data-use controls: live video switches off automatically after a short time, video uses a lower-data stream by default, and per-vehicle data budgets apply.
- AI providers: prompts are built from the Customer's own fleet facts. Provider no-training and minimal-retention settings are used where offered.
- Resilience: database backups and a tested restore process.
- Vulnerability management: dependency updates and security fixes applied promptly. Secrets are kept out of source code.
- Incident response: a documented incident and breach process (OP-07, in progress), with notice under clause 8.
- Devices: cameras connect only to our platform. Lost or removed devices can be disabled from the Service.
Annex 3: Subprocessors
| Subprocessor | Purpose | Data involved | Location / region |
|---|---|---|---|
| Railway | Application, database and camera-connection hosting | Fleet and account data stored in the Service | Confirm hosting region |
| Resend | Alert and notification emails | Recipient emails, alert content | United States |