Version: 5.7.2 Effective date: August 20, 2026 Market: Syria
1. Scope and roles
This Addendum applies where the Local FleetOS Entity named in the Office’s Order Form processes personal data on behalf of and on the documented instructions of that Office. It forms part of FOS-06 for that country market only. No other FleetOS market entity is a processor or subprocessor merely because it shares branding, ownership, directors, infrastructure or technology.
| Processing | Role of the Office | Role of FleetOS |
|---|---|---|
| Office's own transport operations, Driver management, fares, complaints | Controller | Processor |
| Office's own marketing to its customers | Controller | Processor |
| FleetOS account administration, platform security, fraud prevention, billing, product analytics, legal compliance | — | Controller in its own right |
| Restricted-party and sanctions screening | — | Controller in its own right (legal obligation) |
| Aggregated and de-identified analytics | — | Controller in its own right |
| Where FleetOS acts as controller in its own right, this Addendum does not apply to that processing — FOS-02 does. The distinction matters: an Office cannot instruct FleetOS to stop processing data FleetOS must process for its own legal compliance. |
|---|
FleetOS Direct data. This Addendum governs Office-controlled data only. Personal data processed by the Local FleetOS Entity for its own FleetOS Direct transportation operation is controlled under FOS-02 and is not Office-processor data under this Addendum.
2. Instructions
We process personal data only on your documented instructions, which are: this Addendum; FOS-06; the Order Form; and any further written instruction you give that is within the scope of the service.
We will tell you if we consider an instruction infringes applicable data protection law, and may suspend that processing until it is resolved. Where law requires us to process otherwise than on your instruction, we will tell you first unless the law prohibits it.
3. Confidentiality and personnel
Personnel with access to personal data are bound by written confidentiality obligations, are trained, and have access only on a least-privilege basis, reviewed at least quarterly.
4. Security
We implement the technical and organisational measures in FOS-06 Schedule 3. We may update them provided the level of protection is not materially reduced.
5. Subprocessors
5.1 General authorisation
You give general authorisation for us to engage subprocessors. The current list is in Schedule 2 and is published in the Legal Center.
5.2 Changes
We give at least 30 days' notice before adding or replacing a subprocessor. You may object on reasonable data protection grounds within 15 days, stating the grounds. We will work in good faith to resolve the objection; if we cannot, you may terminate the affected service with a pro-rata refund of prepaid unused fees.
5.3 Our responsibility
We impose obligations on each subprocessor at least as protective as this Addendum and remain contractually responsible for its processing to the extent required by applicable law and this Addendum. That responsibility is subject to FOS-06 §23, including the Data/Security Supercap in §23.3A, except to the extent applicable law prohibits limitation.
Other FleetOS market entities. A company operating FleetOS in another country may process Office Data only if it is specifically identified in Schedule 2 as a subprocessor or other lawful recipient, an appropriate written intercompany processing agreement is in force, access is least-privilege and purpose-limited, and every required international-transfer mechanism has been completed. Common branding or ownership is not authorisation to access Office Data.
6. Assistance to you
We will assist you, at your cost where the assistance is not trivial, with: responding to individual rights requests; data protection impact assessments; prior consultation with a regulator; and demonstrating compliance.
Where an individual contacts us directly about processing for which you are controller, we will not respond substantively; we will forward the request to you within 5 business days and tell the individual we have done so.
7. Personal data breach
We will notify you of a confirmed personal data breach affecting your personal data without undue delay and, as a contractual target, within 24 hours of confirmation, subject only to the investigation necessary to make the notification meaningful.
Our notification will describe, to the extent known: the nature of the breach; the categories and approximate number of individuals and records; the likely consequences; the measures taken or proposed; and a contact point. We will provide updates as the investigation develops and will assist you with your own notification obligations.
"Confirmation" means the point at which we determine a breach has occurred, not the point at which we first receive an alert. We do not delay confirmation to defer the clock.
8. Deletion and return
On termination, and at your written election made within 30 days, we will return or delete personal data processed on your behalf, except where we must retain it under applicable law, for a legal hold, or for the defence of a claim. Backups are deleted on their ordinary cycle. We will confirm deletion in writing on request.
9. Audit
We will make available the information reasonably necessary to demonstrate compliance, including our current certifications and penetration test summary under NDA.
You may audit no more than once in any 12 months, on at least 30 days' notice, during business hours, subject to confidentiality, and at your cost — unless the audit reveals material non-compliance, in which case we bear our own costs and reimburse yours. We may satisfy an audit request by providing a recent third-party audit report where it reasonably addresses your scope. Additional audits may be conducted following a personal data breach or a regulator direction.
10. International transfers
Transfers are made only on the basis recorded in Schedule 2 for the relevant country market. Market data is logically partitioned by Local FleetOS Entity. Where a transfer requires a specific mechanism — standard contractual clauses, adequacy decision, approved contractual terms, consent or another lawful basis — that mechanism is identified before the transfer occurs and is a condition of activating the recipient or market.
11. Liability
Liability under this Addendum is subject to FOS-06 §23, including the Data/Security Supercap in §23.3A, except where applicable law prohibits limitation of liability for a particular data-protection obligation, in which case the limitation applies only to the maximum lawful extent.
Schedule 1 — Processing details
| Item | Detail |
|---|---|
| Subject matter | Provision of cloud dispatch, booking, fleet management and payment-support software |
| Duration | The term of FOS-06, plus retention periods in Schedule 3 |
| Nature and purpose | Hosting, storage, retrieval, transmission, display, analysis, backup, deletion |
| Categories of data subject | Passengers; Drivers; Office personnel; applicants; website visitors |
| Categories of personal data | Identity and contact; account and credentials; licence, permit and vehicle records; precise location and trip data; payment tokens and transaction records; communications; device and usage data; incident and safety records |
| Special category / sensitive data | Biometric templates and background-screening results are processed only if a lawful Syria feature is separately activated and all required notices, permissions, consents, vendor protections and retention rules are in place. No FleetOS biometric-template feature is enabled at the current launch configuration; Office screening remains the Office’s responsibility unless a lawful FleetOS Direct operation is separately activated. |
| Frequency | Continuous, for the duration of the service |
Schedule 2 — Subprocessor and data-location register
The Approved Subprocessor and Data-Location Register is the subprocessor/data section of the FleetOS compliance record for the applicable country market. The public-facing version is displayed in the FleetOS Legal Center and is incorporated into this Addendum by reference. The version displayed to the Office at acceptance is retained with the Office’s agreement evidence.
For each approved subprocessor, the register identifies at least: legal name; service; categories of data processed; principal processing location(s); applicable transfer basis or safeguard where required; and the country market(s) for which the subprocessor is approved. A FleetOS entity from another country is not an implicit subprocessor and must be specifically listed if it will process Office Data on behalf of the Local FleetOS Entity.
FleetOS will not intentionally permit a new subprocessor to process Office Data before it has completed appropriate due diligence, entered into written data-protection terms, and added that subprocessor to the approved register. Changes are subject to the notice and objection procedure in §5.2.
The register also identifies the approved primary hosting and backup regions for the applicable market and any transfer or localisation safeguard applicable to that deployment. If a processing activity requires a subprocessor, hosting location or transfer mechanism that has not been approved and published for the market, that processing activity is not enabled until the register is updated in accordance with this Addendum.
Schedule 3 — Data retention register
This Schedule is the authoritative source for retention. FOS-02 §8 summarises it; where they differ, this Schedule controls.
| Record category | Retention | Trigger | Basis |
|---|---|---|---|
| Account profile | 3 years after closure | Account closure | Dispute defence; fraud prevention |
| Authentication and security logs | 24 months | Event | Security; incident investigation |
| Ride and booking records | 7 years | Ride completion | Tax; accounting; dispute defence |
| Fare, payment and refund records | 7 years | Transaction | Tax; accounting; payment network rules |
| Chargeback and dispute records | 7 years | Resolution | Payment network rules; defence |
| Detailed precise trip location | 12 months, then aggregated or deleted; longer only for a documented open claim, investigation, legal hold, insurance matter or legal requirement | Ride completion | Safety; dispute; fraud; legal necessity |
| Aggregated / de-identified trip data | Indefinite | — | Not personal data once irreversibly de-identified |
| Driver compliance documents | Term of affiliation + 7 years | Affiliation end | Regulatory; audit; defence |
| Driver applications not accepted | No longer than necessary for the applicable claim/limitation period recorded in the FleetOS compliance record | Decision | Claim defence; applicable law |
| Biometric templates (only if separately activated) | Purpose satisfied or mandatory local deadline, whichever is earlier | Verification complete | Applicable biometric/privacy law |
| Background screening results | Applicable lawful retention period recorded in the FleetOS compliance record | Decision | Applicable employment, transport and privacy law |
| Restricted-party screening records | 7 years | Screening event | Sanctions record-keeping |
| Communications and support tickets | 3 years | Closure | Service; dispute |
| Call recordings where enabled | 90 days, unless a shorter period is required by local law or the purpose | Recording | Safety; quality; consent-dependent |
| Safety incident records | 7 years, longer where a claim is open | Incident | Defence; regulatory |
| Marketing consent and opt-out | 5 years after last communication | Communication | Proof of consent |
| Agreement acceptance evidence | Term + 7 years | Acceptance | Enforceability evidence |
| Cookie consent records | 24 months | Consent | Proof of consent |
Legal hold overrides everything in this table. Where litigation, a regulatory investigation or a preservation obligation is reasonably anticipated, deletion is suspended for the affected records until the hold is released by the person who imposed it.