1. Parties and status
This DPA is between the Customer identified in the Vehivyn registration record (Controller) and Intravyn Ltd trading as Intravyn, company 17252837 (Processor). It forms part of the Terms of Service. Defined data-protection terms have the meanings in the UK GDPR and Data Protection Act 2018.
If this DPA conflicts with the Terms about processing Customer Personal Data, this DPA prevails.
2. Instructions and purpose limitation
Intravyn will process Customer Personal Data only on the Customer’s documented instructions, including those in the Terms and Schedule 1, unless UK law requires otherwise. In that case Intravyn will notify the Customer before processing unless the law prohibits notice.
Intravyn will promptly inform the Customer if, in its opinion, an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve it. The Customer is responsible for lawful instructions, transparency and a valid lawful basis.
3. Confidentiality and personnel
Intravyn will ensure people authorised to process Customer Personal Data have committed to confidentiality or are under an appropriate statutory duty, receive proportionate training and access data only as necessary for their role.
4. Security
Taking account of the state of the art, implementation costs, the nature, scope, context and purposes of processing and risks to people, Intravyn will maintain appropriate technical and organisational measures under UK GDPR Article 32. Current measures are described in Schedule 2.
Security measures may evolve without materially reducing overall protection. No system can be guaranteed completely secure; this clause does not reduce Intravyn’s statutory obligations.
5. Subprocessors
The Customer gives general written authorisation for the processors listed on the Subprocessors page. Intravyn will impose materially equivalent data-protection obligations by written contract and remains responsible for each subprocessor’s performance of those obligations.
Intravyn will publish notice of an intended addition or replacement, allowing the Customer a reasonable opportunity to object on genuine data-protection grounds. The parties will work in good faith on a reasonable solution; if none is available, either party may end the affected service.
6. International transfers
Intravyn will not transfer Customer Personal Data outside the United Kingdom unless the transfer complies with UK data-protection law. Safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement or UK Addendum, with transfer-risk assessment and supplementary measures where required. The Customer authorises transfers inherent in approved subprocessor services subject to these safeguards.
7. Rights and compliance assistance
Taking account of the nature of processing, Intravyn will provide reasonable technical and organisational assistance so the Customer can respond to data-subject requests. If Intravyn receives a request relating to Customer Personal Data, it will forward it promptly and will not respond substantively except on instruction or where legally required.
Intravyn will reasonably assist with security, breach notification, data-protection impact assessments and prior consultation obligations under UK GDPR Articles 32–36, considering the information available and nature of processing.
8. Personal data breaches
Intravyn will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. As information becomes available, notice will describe the nature of the breach, affected categories and approximate numbers, likely consequences, measures taken or proposed and a contact point. Intravyn will contain, investigate and remediate the breach and preserve relevant evidence. Notice is not an admission of fault.
9. Information and audits
Intravyn will make available information reasonably necessary to demonstrate compliance with this DPA and allow audits or inspections by the Customer or an independent auditor bound by confidentiality. Unless a regulator or material incident requires otherwise, the Customer will give reasonable notice, avoid unnecessary disruption, use existing reports first and bear its audit costs. Intravyn may charge reasonable costs for duplicative or excessive requests.
10. Return and deletion
On termination or written instruction, at the Customer’s choice Intravyn will return or delete Customer Personal Data and delete copies, unless UK law requires retention. Data in protected backups will be put beyond ordinary use and deleted or overwritten through the documented backup cycle. Intravyn may retain limited evidence needed for legal obligations or claims, kept protected and isolated.
Until an automated account export/deletion workflow is available, the Customer may submit return or deletion instructions to legal@intravyn.com.
Schedule 1 — Processing details
| Subject matter | Hosting and operating the Vehivyn garage-management service and related support. |
|---|---|
| Duration | For the Customer’s use of the service, plus the limited return/deletion and lawful-retention period. |
| Nature and purposes | Collection, recording, organisation, storage, retrieval, consultation, use, transmission, backup, support, correction, export and deletion as instructed to provide and secure Vehivyn. |
| Data subjects | Customer personnel and authorised users; the garage’s customers and contacts; vehicle owners, keepers or drivers; suppliers; and people recorded in jobs, quotes, invoices, timesheets or communications. |
| Data categories | Names, contact and business details; user and role data; vehicle registration, make/model, mileage and MOT-related data; appointments, job notes and history; quotes, invoices, purchasing and payment-status information; staff timesheets; correspondence and support content; identifiers, audit and security data. |
| Special-category/criminal-offence data | Not intentionally required. The Customer must not enter it unless necessary, lawful and specifically agreed with appropriate safeguards. |
| Controller obligations | Give lawful instructions; provide notices; establish lawful bases; minimise data; manage user access; respond to people; and notify Intravyn of relevant restrictions. |
Schedule 2 — Security measures
- Role-based access and tenant-scoped application controls; least-privilege operational access.
- Authentication controls, password protection and account verification; transport encryption for production endpoints.
- Logging, monitoring and incident-response procedures proportionate to the service.
- Vulnerability, dependency and production security testing before launch and periodically thereafter.
- Managed database, file storage, snapshots and backups on Hostinger infrastructure with recovery procedures.
- Change control, code review, tested additive migrations and separation of development from production operations.
- Confidentiality commitments, access review and removal when access is no longer required.
- Data minimisation, retention review, erasure/return handling and subprocessor due diligence.
Credential rotation, connection-string logging remediation, password-hashing review and production security testing remain recorded security workstreams.
Contact us
Data Protection Lead, Intravyn Ltd, Reeth Cottage, Aysgarth, Leyburn, DL8 3AH.
Email legal@intravyn.com for legal or privacy matters, or support@intravyn.com for product support.
