Service Club ®
Academy Compliance Jobs Perks Shop
Get in touch
Academy Compliance Jobs Perks Shop
ENESDEFRITNL

Data Processing Agreement

Effective date: June 2026

This Schedule forms an integral part of the applicable Service Club Business Customer Terms of Service or Client Terms and Conditions. It applies automatically where, and to the extent that, Service Club processes personal data on behalf of the Client as processor for the purposes of Article 28 of Regulation (EU) 2016/679. It does not apply to processing carried out by Service Club as independent controller or to any processing for which the parties are independent controllers or joint controllers, unless expressly stated otherwise.

1. Status and Incorporation

  • 1.1. This Data Processing Agreement (DPA) forms part of the agreement between Service Club and the Client where, and to the extent that, Service Club processes personal data on behalf of the Client as processor within the meaning of Article 4(8) and Article 28 GDPR.
  • 1.2. This DPA applies only for processing activities where the Client determines the purposes and essential means of processing and Service Club acts on the Client's documented instructions.
  • 1.3. Where Service Club acts as independent controller, this DPA does not apply to that processing. Such controller processing shall be governed by Service Club's privacy notice and applicable data protection law. Where the parties jointly determine purposes and means, they shall agree a separate Article 26 GDPR arrangement.

2. Subject Matter, Duration, Nature and Purpose

  • 2.1. The subject matter, duration, nature and purpose of the processing are those required to provide the relevant Service Club services under the applicable Terms, Order Form and Annex A to this DPA.
  • 2.2. Processing shall continue for the duration of the relevant services and any post-termination period necessary for deletion, return, legal retention, dispute management, security, audit or compliance obligations.

2.3. Processing Description

Defined term Description
Services Perks, Jobs, Academy, Micro Academy, Marketplace, Shop and related platform services where Service Club acts as processor.
Purposes Account setup, eligibility management, access control, service delivery, training delivery, reporting, support, communications, fraud prevention, security and agreed integrations.
Data subjects Workers, candidates, trainees, logistics workers, client administrators, client personnel, trainers, support contacts.
Data categories Identification data, contact details, eligibility, role/location, account identifiers, communications, attendance, redemption data, training records, support tickets, security logs, fraud indicators.
Retention As instructed by Client and as necessary for service delivery, deletion/return, legal retention, security, fraud prevention, accounting and dispute management.

3. Categories of Data Subjects and Personal Data

  • 3.1. Data subjects may include Workers, couriers, logistics workers, warehouse workers, fulfilment workers, forklift operators, trainees, candidates, client administrators, client personnel, trainers, support contacts and other individuals whose data are processed in connection with the services.
  • 3.2. Categories of personal data may include identification data, contact details, CV/profile details, right-to-work evidence, vehicle-related information, eligibility data, role/location data, account data, training attendance, VR and telematics data, attention-related indicators, AI-supported learning analytics, redemption data, application data, document metadata, communications, support records, security logs, fraud indicators and other data agreed in Annex A.
  • 3.3. Special category data, criminal offence data, health data, union membership data, biometric data for identification, children's data or other high-risk data shall not be processed unless expressly agreed in writing, strictly necessary and supported by a lawful basis and appropriate safeguards.

4. Client Obligations

  • 4.1. The Client shall ensure that processing instructions are lawful, documented, specific and consistent with GDPR, LOPDGDD and applicable law.
  • 4.2. The Client shall be responsible for determining the lawful basis, providing required transparency information, handling its own data subject rights, defining retention periods, ensuring data minimisation, assessing high-risk processing and conducting any DPIA required by Article 35 GDPR for Client-side purposes.
  • 4.3. The Client shall not instruct Service Club to process personal data unlawfully, excessively, opaquely, discriminatorily or in a way that conflicts with applicable labour, data protection, electronic communications, AI or fundamental-rights rules.

5. Processor Obligations

  • 5.1. Service Club shall process personal data only on documented instructions from the Client, including with regard to transfers to a third country or international organisation, unless required to do so by Union or Member State law. In such case, Service Club shall inform the Client of that legal requirement before processing unless the law prohibits such information on important grounds of public interest.
  • 5.2. Service Club shall ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • 5.3. Service Club shall implement appropriate technical and organisational measures in accordance with Article 32 GDPR, taking into account the nature of the processing, the risks, state of the art, implementation costs and the categories of personal data.
  • 5.4. Service Club shall assist the Client, taking into account the nature of processing and information available to Service Club, with data subject requests, security, breach notifications, DPIAs and consultations with supervisory authorities, to the extent required by Articles 28, 32-36 GDPR.

5.5. Sub-Processors

  1. The Client authorises Service Club to appoint sub-processors for hosting, communications, analytics, payment, support, security, infrastructure, CRM, LMS, VR platforms, AI-model provision, telematics, messaging, document management and similar services required to provide the services.
  2. Service Club shall impose data protection obligations on sub-processors that are no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.
  3. Service Club shall maintain an up-to-date list of material sub-processors and make it available to the Client (e.g., through a dedicated link, platform section, or upon request). Service Club shall notify the Client of intended material changes at least fourteen (14) days before the change takes effect, giving the Client an opportunity to object on reasonable data protection grounds.

5.6. International Transfers

  1. Service Club shall not transfer personal data outside the EEA unless the transfer complies with Chapter V GDPR, including an adequacy decision, Standard Contractual Clauses, supplementary measures where required, derogations or another lawful transfer mechanism.
  2. The Client acknowledges that certain providers may provide support, communications or infrastructure services from outside the EEA. Where applicable, Service Club shall implement transfer safeguards and provide reasonable information to the Client on request.

5.7. Security Measures

  1. Service Club shall maintain measures appropriate to the risk, which may include access controls, authentication, role-based permissions, encryption in transit, backup, logging, segregation, secure development practices, vulnerability management, confidentiality commitments, incident response and secure deletion processes.
  2. The specific measures may evolve over time, provided that the level of protection is not materially reduced. Annex B describes the baseline measures.

5.8. Personal Data Breach

  1. Service Club shall notify the Client without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Client.
  2. The notification shall include, to the extent known and available, the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, measures taken or proposed and a contact point. The Client remains responsible for notifications to supervisory authorities or data subjects where the Client is controller.

5.9. Data Subject Rights

  1. Service Club shall, taking into account the nature of processing, assist the Client by appropriate technical and organisational measures, insofar as possible, for fulfilment of the Client's obligation to respond to requests for access, rectification, erasure, restriction, portability, objection and automated decision-making rights.
  2. If Service Club receives a request relating to Client-controlled processing, Service Club may redirect the data subject to the Client or inform the Client, unless legally prohibited.

5.10. AI, Automated Tools and High-Risk Processing

  1. Where Service Club uses AI-supported or automated tools as processor on behalf of the Client, the Client shall be responsible for confirming the intended purpose, lawful basis, transparency, proportionality, human oversight and any assessment required under GDPR, LOPDGDD, labour law and the AI Act.
  2. Service Club shall not be required to configure AI or automated tools for employment-related decision-making, ranking, dismissal, access to work or similar legally significant purposes unless separately agreed and lawfully assessed. Where the Client uses Service Club's AI or automated tools for such purposes, the Client remains solely responsible for compliance with Article 22 GDPR, applicable labour laws, and the AI Act.

6. Audit and Information Rights

  • 6.1. Service Club shall make available to the Client information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.
  • 6.2. Audits shall be subject to reasonable notice, confidentiality, security restrictions, business-hours limitations and avoidance of disruption. The Client may not access data of other clients, confidential platform architecture, trade secrets or information that would compromise security.

7. Deletion and Return

  • 7.1. At the Client's choice and subject to technical feasibility, legal retention and Service Club controller obligations, Service Club shall delete or return personal data processed on behalf of the Client after the end of the services.
  • 7.2. Service Club may retain copies where required by Union or Member State law, for legal claims, security logs, accounting, fraud prevention or compliance purposes, provided that such retained data remain protected and are not processed for incompatible purposes.

8. Liability and Precedence

  • 8.1. Liability under this DPA shall be governed by the liability provisions of the applicable Terms or written agreement, without prejudice to mandatory GDPR liability rules that cannot be excluded.
  • 8.2. In case of conflict between this DPA and the Terms concerning processor obligations, this DPA prevails for the relevant processing.

9. Governing Law

This DPA is governed by Spanish law and applicable EU data protection law. The courts designated in the applicable Terms shall have jurisdiction, without prejudice to mandatory supervisory authority powers and data subject rights.

Annex A - Details of Processing

This Annex forms part of the Data Processing Agreement and describes the processing of personal data carried out by Service Club on behalf of the Client.

1. Subject matter and duration of the processing

  • Subject Matter: The processing of personal data is carried out to provide the Service Club Platform and related services (including Perks, Jobs, Academy, Micro Academy, Marketplace, and Shop) as agreed upon in the relevant Order Form or Terms of Service.
  • Duration: The processing shall continue for the duration of the relevant services and any post-termination period strictly necessary for deletion, return, legal retention, dispute management, security, audit, or compliance obligations.

2. Nature and purpose of the processing

The nature of the processing involves the collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, and erasure of personal data. The purposes include:

  • Account setup, access control, and eligibility management.
  • Recruitment-support, candidate matching, and onboarding support.
  • Training delivery (including classroom, virtual, VR, behind-the-wheel, and AI-supported training).
  • Platform communications, reporting, support, security, and fraud prevention.

3. Categories of data subjects

The personal data transferred concern the following categories of data subjects:

  • Workers, couriers, delivery workers, warehouse workers, fulfilment workers, and forklift operators.
  • Trainees, candidates, and logistics workers.
  • Client administrators, client personnel, trainers, and support contacts.

4. Types of personal data processed

The personal data transferred concern the following categories of data:

  • Identification and Contact Data: Name, surname, email address, telephone number, location, and account identifiers.
  • Profile and Eligibility Data: CV details, work history, availability, eligibility criteria, licences, and right-to-work evidence where requested.
  • Training and Performance Data: Enrolment records, attendance, training scores, VR and telematics data, attention-related indicators, and AI-supported learning analytics.
  • Operational Data: Redemption data for Perks, application statuses, document metadata, support tickets, communications, security logs, and fraud indicators.

5. Sensitive data / Special categories of data

  • Service Club does not process special category data, criminal offence data, biometric data for identification, or health data on behalf of the Client unless expressly agreed in writing, strictly necessary, and supported by a lawful basis and appropriate safeguards.

Annex B - Technical and Organisational Measures (TOMs)

This Annex forms part of the Data Processing Agreement and describes the technical and organisational security measures implemented by Service Club to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. These baseline measures may be supplemented by more detailed internal information security documentation, which Service Club may make available to the Client upon reasonable request, subject to confidentiality restrictions.

1. Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services

  • Access Controls: Implementation of role-based access controls (RBAC), ensuring personnel only have access to data necessary for their role.
  • Encryption: Personal data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
  • System Resilience: Infrastructure is hosted on AWS (Ireland). To ensure resilience, systems are configured to resume operations in an alternative Availability Zone in the event of an outage, in accordance with applicable SLAs.

2. Measures for the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident

  • Backups: Automated, encrypted backups of critical databases are performed daily and maintained with a 7-day retention period.

3. Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures

  • Vulnerability Management: Implementation of CI/CD pipeline security scanning; code is automatically scanned for vulnerabilities prior to production, and deployments are blocked if vulnerabilities are detected.
  • Penetration Testing: Annual third-party penetration testing of the Service Club Platform.
  • Security Logs: Active logging of system actions and security events within the core infrastructure.

4. Measures for user identification and authorisation

  • Implementation of distinct, individual user accounts and credentials for all personnel.
  • Documented IT onboarding and offboarding checklist processes to ensure system access is granted appropriately and revoked manually upon an employee's termination or role change.

5. Measures for the protection of data during transmission

  • All personal data transmitted over external networks is secured using TLS 1.3 encryption protocols.

6. Measures for ensuring physical security of locations at which personal data are processed

  • Service Club utilizes top-tier cloud and SaaS providers (AWS, Google Workspace, Holded) that maintain rigorous enterprise-grade physical security measures (e.g., biometric access, 24/7 security guards) at their respective data centers.
  • Service Club's corporate offices require keycard access to prevent unauthorized physical entry.
Service Club ®

The ultimate solution for drivers and companies that move the world. We source, train, and deliver ready-to-drive talent. Join the Club ®.

Solutions

  • Academy
  • Compliance
  • Jobs
  • Perks
  • Shop

Company

  • About
  • Careers
  • Contact
  • Blog

© 2026 Service Club ®. All rights reserved.

Privacy Cookies Cookie preferences Legal Notice Terms & Conditions DPA
  • English
  • Español
  • Deutsch
  • Français
  • Italiano
  • Nederlands