1. Who is responsible for what
These terms explain how personal data is handled when a mobile tyre fitter (the "Customer") uses TyreStack, a service provided by Mediant Partners Ltd, company number SC889184, registered in Scotland ("we", the "Supplier").
| Data | Controller | Our role |
|---|---|---|
| The Customer's own customers: names, addresses, phone numbers, vehicle registrations and details, WhatsApp and other messages, quotes, jobs, schedules, payment status, notes. | The Customer | Processor. We act only on the Customer's documented instructions, as set out below. |
| Customer account, user, billing and support data; service security and usage records. | Mediant Partners Ltd | Controller. See our privacy notice. |
The Customer is responsible for having a lawful basis and giving its own customers the required privacy information, including that it uses TyreStack. We are responsible for processing that data only as set out here and for protecting it.
2. Data processing terms
This section is the data processing agreement required by Article 28 of the UK GDPR. It forms part of, and is incorporated into, the Customer terms of service and applies from the day the Customer starts using the service. If there is a conflict between this section and any other term about personal data, this section prevails.
2.1 Subject matter, duration and purpose
We process the Customer's customer data to provide the TyreStack service described in the order form and Customer terms: receiving and organising enquiries into jobs, preparing and sending quotes, scheduling, showing job locations, supporting fitters in the field, tracking stock and payment status, and related support. Processing lasts for the term of the agreement and until return or deletion under section 2.10.
2.2 Nature of the data and people affected
- Types of personal data: name, postal address, phone number, email address, vehicle registration and vehicle details, message content, appointment and job details, quote and invoice details, and payment status. We do not ask for or intend the service to hold special category data or criminal-offence data, and the Customer must not put it there deliberately.
- People: the Customer's customers and enquirers, and their staff and contractors who use the service.
2.3 Instructions
We process personal data only on the Customer's documented instructions, which are these terms, the order form and the Customer's use and configuration of the service, unless the law requires otherwise. In that case we will tell the Customer before processing, unless the law forbids us. We will tell the Customer if we believe an instruction breaches data protection law.
2.4 Confidentiality
Everyone we authorise to process the data is bound by a duty of confidentiality and has access only where needed to provide the service.
2.5 Security
We implement appropriate technical and organisational measures under Article 32, including:
- encryption in transit (TLS) and at rest;
- logical separation of each Customer's data from every other customer's, enforced in the database itself and not only in the application;
- role-based access, strong authentication for staff, and least-privilege access to production systems;
- credentials and API keys held in managed secret stores, never in source code;
- logging and alerting for unusual access and errors;
- regular backups, and tested deployment and recovery procedures; and
- change control and automated testing before changes reach production.
2.6 Customer-connected services
The Customer may connect services it holds its own account with, such as WhatsApp Business (Meta), accounting software, read-only bank data, Google Business Profile and Google Ads, and its tyre supplier. Those services are provided to the Customer under the Customer's own terms with those providers. We connect to them using the permissions the Customer grants, and we are not responsible for how those providers handle data on their own systems. They are not our sub-processors.
2.7 Sub-processors
The Customer gives general authorisation for the sub-processors below. Each is bound by a written contract with data protection terms no less protective than these, and we remain responsible for them.
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Google Cloud EMEA Ltd (Google Cloud Platform) | Hosting the application, database, storage and scheduled jobs. | London, United Kingdom (europe-west2). |
| Cloudflare, Inc. (and group companies) | DNS, content delivery and security in front of the service. | Global edge network; only transient request data passes through. UK transfer safeguards apply. |
| Google Workspace (Google Ireland Ltd) | Our email and support correspondence. | UK / European Economic Area, with UK transfer safeguards. |
We will give at least 30 days' notice (by email to the Customer's account contact) before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; if we cannot reasonably accommodate the objection, the Customer may terminate the affected service without penalty and receive a pro-rata refund of fees paid in advance.
2.8 International transfers
We store the Customer's customer data in the United Kingdom. If we or a sub-processor transfer personal data outside the UK, we will do so only with a lawful mechanism in place: a UK adequacy regulation, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, plus any transfer risk assessment required.
2.9 Helping the Customer meet its obligations
- People's rights. We will give the Customer the tools and, where needed, reasonable help to respond to requests to access, correct, erase, restrict, port or object to the processing of personal data. If someone contacts us directly about data we hold for a Customer, we will pass the request to the Customer without undue delay and will not respond ourselves except to say we have done so.
- Personal data breaches. We will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting its data, with the information we have to help the Customer decide whether to report it to the Information Commissioner's Office (which must be within 72 hours of the Customer becoming aware) and to affected people.
- Assessments and consultation. We will give reasonable help with data protection impact assessments and prior consultation with the regulator, taking into account the nature of processing and the information we hold.
2.10 Return and deletion
When the agreement ends, or earlier on written request, the Customer may export its data in a standard machine-readable format. We will then delete the Customer's customer data from live systems within 90 days, and from backups on their normal rolling expiry (no later than a further 90 days), unless the law requires us to keep it, in which case we will keep it confidential and process it only for that purpose.
2.11 Audits and information
We will make available the information needed to show compliance with Article 28 and allow for and contribute to audits, including inspections, by the Customer or an auditor it appoints, on reasonable notice (at least 30 days), no more than once a year unless a regulator requires otherwise or following a breach, during business hours, subject to confidentiality and without unreasonable disruption. We may satisfy an audit request first by providing up-to-date documentation or independent reports. Each party bears its own costs unless the audit reveals a material breach by us.
2.12 Records
We keep records of processing carried out for the Customer as Article 30(2) requires.
3. Contact
For data protection questions, to exercise a right, or to give a notice under these terms: privacy@tyrestack.com, or Mediant Partners Ltd, 5 South Charlotte Street, Edinburgh, EH2 4AN, Scotland.
If you are one of a fitter's customers and want to see, correct or delete your data, please contact the fitter you dealt with: they decide what happens to it. If you cannot identify them, or they do not respond, contact us and we will help you reach them. You can complain to the Information Commissioner's Office at ico.org.uk.
4. Governing law
These data processing terms are governed by the law of Scotland and the Scottish courts have exclusive jurisdiction, as set out in the Customer terms.