DAEDALUS

Data Processing Agreement

Effective June 15, 2026  ·  Version 1.0
This DPA is incorporated into and forms part of the Daedalus Terms of Service. It applies automatically to all accounts and does not require a separate signature.

This Data Processing Agreement ("DPA") is entered into between you, the customer ("Controller"), and Daedalus Automotive ("Daedalus," "Processor"), governing the processing of personal data by Daedalus on behalf of the Controller in connection with the Service. This DPA implements the requirements of GDPR Article 28 and equivalent provisions in applicable data-protection laws.

1. Definitions

Terms defined in the GDPR (Regulation (EU) 2016/679) have the same meaning here. "Service" means the Daedalus Shop platform and related services described in the Terms of Service. "Controller Data" means personal data that the Controller uploads, enters, or generates through the Service, including customer records, vehicle data, repair history, and communications.

2. Roles

The Controller (you) determines the purposes and means of processing Controller Data. The Processor (Daedalus) processes Controller Data solely on the Controller's instructions as set out in this DPA and the Terms of Service. Where Daedalus processes data for its own purposes (e.g., account security, service improvement using anonymized data), it acts as an independent Controller for that processing.

3. Subject Matter, Duration, Nature, and Purpose

4. Categories of Data and Data Subjects

See Schedule A below for details. Controller Data relates to the Controller's customers (vehicle owners) and employees/technicians.

5. Processor Obligations

5.1 Instructions

Daedalus will process Controller Data only on documented instructions from the Controller — meaning the Controller's use of the Service features and this DPA. If Daedalus is required by EU or member-state law to process Controller Data for another purpose, Daedalus will inform the Controller of that requirement before processing, unless prohibited by law.

5.2 Confidentiality of Personnel

Daedalus will ensure that personnel authorized to process Controller Data are bound by appropriate confidentiality obligations, whether contractual or statutory.

5.3 Security

Daedalus will implement the technical and organizational measures described in Schedule C to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32.

5.4 Sub-processors

The Controller grants Daedalus general authorization to engage sub-processors, subject to the conditions in this section. Current sub-processors are listed in Schedule B. Daedalus will:

The Controller may object to a new sub-processor within 14 days of notice. If the parties cannot resolve the objection in good faith within 30 days, the Controller may terminate the Service on 30 days' written notice.

5.5 Data Subject Rights

Daedalus will, taking into account the nature of the processing, assist the Controller in fulfilling its obligations to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). Shop users can initiate GDPR/CCPA requests from within the Service at Settings → Privacy & Data Requests.

5.6 Assistance with Controller Obligations

Daedalus will assist the Controller with:

Such assistance will be provided at reasonable cost to the Controller for activities beyond normal Service operations.

5.7 Deletion and Return of Data

On termination of the Service, or at the Controller's written request, Daedalus will (at the Controller's choice) return all Controller Data in a standard machine-readable format or securely delete it, and will certify deletion in writing. Data retained for legal obligations (tax retention) is excluded from deletion until the required retention period expires.

5.8 Audit Rights

Daedalus will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. Daedalus may satisfy audit requests through third-party certifications (SOC 2, ISO 27001, or equivalent) or by allowing the Controller to conduct audits (at the Controller's expense and on reasonable notice) no more than once per year, unless a data breach justifies more frequent review.

5.9 Notification of Infringement

Daedalus will promptly inform the Controller if, in its opinion, a Controller instruction infringes applicable data-protection law.

6. International Data Transfers

The Service is hosted on infrastructure in the United States (Fly.io). If the Controller is established in the European Economic Area or United Kingdom and transfers personal data to Daedalus, that transfer relies on the EU–US Data Privacy Framework (where applicable) or on Standard Contractual Clauses (Module 2: Controller to Processor) incorporated by reference into this DPA. Controller may request the applicable SCCs by emailing [email protected].

7. Data Breach Notification

Daedalus will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller Data, and in any event within 48 hours where feasible. The notification will include:

The Controller is responsible for notifying its own data subjects and supervisory authorities as required by applicable law within the timelines those laws specify (72 hours to supervisory authority under GDPR Article 33).

8. Liability

Each party is liable for damages caused by processing that infringes this DPA or applicable data-protection law. This DPA does not extend the liability limits set out in the Terms of Service.

9. Governing Law and Jurisdiction

This DPA is governed by the law specified in the Terms of Service, except where mandatory provisions of the applicable data-protection law of the Controller's jurisdiction require otherwise.

Schedule A — Categories of Data and Data Subjects

Category of Data Subject Categories of Personal Data
Controller's customers (vehicle owners) Name, phone, email, postal address, vehicle VIN, license plate, vehicle make/model/year, repair history, invoice records, SMS/email communication logs
Controller's employees and technicians Name, display name, email, login activity logs, labor records
Controller account holder Name, email, business address, tax ID, login security logs

Sensitive personal data: None collected by Daedalus as Processor. Payment card data is handled entirely by third-party payment processors; Daedalus does not receive or store raw card numbers.

Schedule B — Authorized Sub-processors

Sub-processor Purpose Location
Fly.io Cloud hosting, database, and network infrastructure USA (primarily); optional EU region available on request
Postmark (ActiveCampaign) Transactional email delivery USA
SMS provider (configurable) Appointment reminder SMS (when enabled by Controller) USA
PartsTech Parts pricing lookups (year/make/model only, no customer data) USA
Anthropic (optional) AI diagnostic assistant responses (when cloud LLM enabled) USA. Governed by Anthropic's usage policies. Prompts contain diagnostic context only — no customer PII is included.

Daedalus will update this list and provide 30 days' notice before adding or replacing any sub-processor. Current list: request by email.

Schedule C — Technical and Organizational Security Measures