BikeYa
BikeYa Legal Centre

BikeYa Data Processing Addendum

Terms for BikeYa’s processing of personal data on a rental business’s instructions.

Version
1
Effective date
29 July 2026

1. Scope, roles, and processing

This Addendum forms part of the service agreement whenever BikeYa processes personal data on behalf of the rental business. The business is the controller and BikeYa is the processor for that data; each party remains an independent controller for its own administration, security, billing, legal compliance, and claims.

Processing covers the operation of rental-management, online-shop, communication, document, reporting, and support functions for the service term plus applicable deletion, backup, and legally required retention periods.

Data subjects may include customers, prospective renters, drivers, emergency contacts, business personnel, and people named in uploaded records. Processing may include collection, recording, storage, retrieval, use, transmission to authorised users, restriction, backup, deletion, and destruction.

2. Instructions and business obligations

BikeYa processes business personal data only on documented instructions contained in the service agreement, the business’s configured use of the service, and lawful support requests.

The business is responsible for a lawful basis, transparent notices, required consents, data accuracy, minimisation, retention choices, responses to individuals, and lawful use of identity or driving documents.

3. Confidentiality and security

People authorised by BikeYa to process business personal data are bound by confidentiality. BikeYa maintains risk-appropriate access control, authentication, encryption in transit, logging, dependency management, backup, recovery, monitoring, incident response, and staff-access restrictions.

4. Subprocessors and transfers

The business gives general authorisation for BikeYa to use subprocessors necessary to provide the service. BikeYa will maintain a current list, give reasonable notice of a material new subprocessor, impose substantially equivalent data-protection duties, and remain responsible to the extent required by law.

International transfers use a mechanism permitted by applicable law, including adequate protection, binding safeguards, or valid consent where required.

5. Assistance and incidents

Taking into account the nature of processing, BikeYa will reasonably assist with individual-rights requests, security obligations, impact assessments, consultations, and legally required records.

BikeYa will notify the business without undue delay after confirming a personal-data protection failure affecting business personal data and will provide available details and reasonable assistance. The business remains responsible for controller notifications.

6. Return, deletion, and audit information

At the end of the service, BikeYa will provide reasonable export functionality where included in the plan and delete or return business personal data according to the service process, unless law requires retention. Residual backup copies remain protected and are deleted through normal cycles.

BikeYa will provide information reasonably necessary to demonstrate compliance. A proportionate audit may be requested on reasonable notice, subject to confidentiality, security, non-disruption, and reasonable cost conditions.

7. Priority

For processing of business personal data, this Addendum prevails over inconsistent service terms. All other service terms remain in effect.