Effective June 15, 2026 · Version 1.0
This DPA is incorporated into and forms part of the
Daedalus Terms of Service.
It applies automatically to all accounts and does not require a separate signature.
This Data Processing Agreement ("DPA") is entered into between you, the customer ("Controller"), and Daedalus Automotive ("Daedalus," "Processor"), governing the processing of personal data by Daedalus on behalf of the Controller in connection with the Service. This DPA implements the requirements of GDPR Article 28 and equivalent provisions in applicable data-protection laws.
Terms defined in the GDPR (Regulation (EU) 2016/679) have the same meaning here. "Service" means the Daedalus Shop platform and related services described in the Terms of Service. "Controller Data" means personal data that the Controller uploads, enters, or generates through the Service, including customer records, vehicle data, repair history, and communications.
The Controller (you) determines the purposes and means of processing Controller Data. The Processor (Daedalus) processes Controller Data solely on the Controller's instructions as set out in this DPA and the Terms of Service. Where Daedalus processes data for its own purposes (e.g., account security, service improvement using anonymized data), it acts as an independent Controller for that processing.
See Schedule A below for details. Controller Data relates to the Controller's customers (vehicle owners) and employees/technicians.
Daedalus will process Controller Data only on documented instructions from the Controller — meaning the Controller's use of the Service features and this DPA. If Daedalus is required by EU or member-state law to process Controller Data for another purpose, Daedalus will inform the Controller of that requirement before processing, unless prohibited by law.
Daedalus will ensure that personnel authorized to process Controller Data are bound by appropriate confidentiality obligations, whether contractual or statutory.
Daedalus will implement the technical and organizational measures described in Schedule C to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32.
The Controller grants Daedalus general authorization to engage sub-processors, subject to the conditions in this section. Current sub-processors are listed in Schedule B. Daedalus will:
The Controller may object to a new sub-processor within 14 days of notice. If the parties cannot resolve the objection in good faith within 30 days, the Controller may terminate the Service on 30 days' written notice.
Daedalus will, taking into account the nature of the processing, assist the Controller in fulfilling its obligations to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). Shop users can initiate GDPR/CCPA requests from within the Service at Settings → Privacy & Data Requests.
Daedalus will assist the Controller with:
Such assistance will be provided at reasonable cost to the Controller for activities beyond normal Service operations.
On termination of the Service, or at the Controller's written request, Daedalus will (at the Controller's choice) return all Controller Data in a standard machine-readable format or securely delete it, and will certify deletion in writing. Data retained for legal obligations (tax retention) is excluded from deletion until the required retention period expires.
Daedalus will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. Daedalus may satisfy audit requests through third-party certifications (SOC 2, ISO 27001, or equivalent) or by allowing the Controller to conduct audits (at the Controller's expense and on reasonable notice) no more than once per year, unless a data breach justifies more frequent review.
Daedalus will promptly inform the Controller if, in its opinion, a Controller instruction infringes applicable data-protection law.
The Service is hosted on infrastructure in the United States (Fly.io). If the Controller is established in the European Economic Area or United Kingdom and transfers personal data to Daedalus, that transfer relies on the EU–US Data Privacy Framework (where applicable) or on Standard Contractual Clauses (Module 2: Controller to Processor) incorporated by reference into this DPA. Controller may request the applicable SCCs by emailing [email protected].
Daedalus will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller Data, and in any event within 48 hours where feasible. The notification will include:
The Controller is responsible for notifying its own data subjects and supervisory authorities as required by applicable law within the timelines those laws specify (72 hours to supervisory authority under GDPR Article 33).
Each party is liable for damages caused by processing that infringes this DPA or applicable data-protection law. This DPA does not extend the liability limits set out in the Terms of Service.
This DPA is governed by the law specified in the Terms of Service, except where mandatory provisions of the applicable data-protection law of the Controller's jurisdiction require otherwise.
| Category of Data Subject | Categories of Personal Data |
|---|---|
| Controller's customers (vehicle owners) | Name, phone, email, postal address, vehicle VIN, license plate, vehicle make/model/year, repair history, invoice records, SMS/email communication logs |
| Controller's employees and technicians | Name, display name, email, login activity logs, labor records |
| Controller account holder | Name, email, business address, tax ID, login security logs |
Sensitive personal data: None collected by Daedalus as Processor. Payment card data is handled entirely by third-party payment processors; Daedalus does not receive or store raw card numbers.
| Sub-processor | Purpose | Location |
|---|---|---|
| Fly.io | Cloud hosting, database, and network infrastructure | USA (primarily); optional EU region available on request |
| Postmark (ActiveCampaign) | Transactional email delivery | USA |
| SMS provider (configurable) | Appointment reminder SMS (when enabled by Controller) | USA |
| PartsTech | Parts pricing lookups (year/make/model only, no customer data) | USA |
| Anthropic (optional) | AI diagnostic assistant responses (when cloud LLM enabled) | USA. Governed by Anthropic's usage policies. Prompts contain diagnostic context only — no customer PII is included. |
Daedalus will update this list and provide 30 days' notice before adding or replacing any sub-processor. Current list: request by email.