Vasthaul
Draft for review by counsel — not yet in force
Back to the site
Policies

Data Processing Addendum

For a carrier that needs one. It sets out, clause by clause, how Vasthaul processes personal information on the carrier’s behalf. It is part of the terms of service.

Last updated
2 September 2026

1. Roles

The carrier is the organization in control of the personal information in its account — the controller, in the words of most privacy laws, and the business under California’s. [legal entity] is its service provider, or processor. The individuals are the carrier’s office users and drivers, and the customer and broker contacts whose details appear on the carrier’s paperwork.

2. Instructions

We process personal information only to provide the service described in the terms, only as the carrier instructs through the product and in writing, and never for a purpose of our own. If an instruction would break the law, we say so instead of following it.

The categories of information, the purposes and the retention periods are the ones set out in the privacy policy, which is incorporated here.

3. Confidentiality

Everyone who works for us and can reach a carrier’s data is bound to keep it confidential, and reaches it only to support that carrier, only when asked.

4. Sub-processors

The carrier authorizes the providers on the sub-processor page, each engaged under a written agreement that binds it to protections no weaker than these. We give thirty days’ notice before adding one; a carrier that objects on reasonable grounds, and cannot be accommodated, may end the agreement without penalty. We remain responsible for what a sub-processor does with the carrier’s data. Sub-processors.

5. Transfers outside Canada

The database is in Canada. Document reading, email, hosting, billing and text messaging are done by providers in the United States. For a carrier with people in Quebec, we keep a privacy impact assessment of those transfers on file, provide it on request, and this addendum is the written agreement Law 25 requires. For a carrier with people in Alberta, we provide the wording and the contact the carrier needs to give its notice under the Personal Information Protection Act.

6. Security

  • Tenant isolation enforced by row-level security in the database, on every table, with no exception.
  • Encryption in transit and at rest.
  • Role-based access; a driver’s account cannot reach load revenue by any path.
  • An append-only record of every change, with who made it and when.
  • One-time-code sign-in; no stored passwords.
  • Compliance documents readable only by the carrier’s office.

7. Breach notice

We notify the carrier within seventy-two hours of learning of a breach of security involving its personal information, with what happened, the categories and people affected, the likely consequences and what we are doing, and we update it as we learn more. We help the carrier meet its own obligations to notify individuals and the commissioner. We keep an incident register for at least five years.

8. Requests from individuals

A request from a driver or a contact to see, correct or delete their information goes to the carrier, and we help the carrier answer it within the law’s time limit. If one reaches us directly we pass it to the carrier within five business days and, if the carrier asks, answer it on the carrier’s behalf.

9. Return and deletion

When the agreement ends the carrier has thirty days of read-only access to take a complete export. After that we keep the records for the retention period the law requires of the carrier, or delete them sooner on the carrier’s written instruction, except for any record we are ourselves required to keep, and we confirm the deletion in writing.

10. Audit

Once a year on request, and after any breach, we give the carrier the information it reasonably needs to satisfy itself that this addendum is being kept — our security description, our sub-processor agreements in summary, and any third-party attestation we hold. Where that is not enough, the carrier or an auditor it appoints may audit us, on thirty days’ notice, at the carrier’s cost, without disrupting other carriers.

11. California carriers

Where the California Consumer Privacy Act applies to the carrier, we are its service provider, and we certify that we understand and will comply with the following: we do not sell or share the personal information; we do not retain, use or disclose it for any purpose other than the business purpose in the terms, or outside the direct business relationship with the carrier; we do not combine it with personal information from any other source except as the Act’s regulations permit; we notify the carrier if we can no longer meet these obligations; and the carrier may take reasonable steps to stop and remedy any unauthorized use.

12. Term

This addendum lasts as long as we hold the carrier’s personal information, and the obligations on breach, confidentiality and deletion survive the end of the terms.