1. Parties and roles
- Processor — Talos BV, Groeningenlei 74/2, 2550 Kontich, Belgium.
- Controller — the Customer that has entered into the Terms of Service with Talos.
To the extent Talos processes personal data on behalf of the Customer to provide the Talos service, Talos acts as a processor and the Customer acts as the controller.
2. Subject matter, duration, nature and purpose
| Element | Detail |
|---|---|
| Subject matter | Processing of personal data required to provide the Talos fleet intelligence service. |
| Duration | For the duration of the Terms of Service, plus a maximum 30-day export window. |
| Nature | Collection, storage, structuring, retrieval, analysis, transmission and deletion of data. |
| Purpose | Delivering the service to the Customer, providing support, and ensuring security. |
| Types of data | Contact data, account data, usage data, and fleet telemetry that may include operator or driver identifiers. |
| Categories of data subjects | Customer employees, contractors, operators and other authorised users. |
3. Processor obligations
Talos will:
- Process personal data only on documented instructions from the Customer, including as set out in the Terms of Service and the platform configuration.
- Ensure that persons authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures (see section 5).
- Assist the Customer with data subject requests, DPIAs and consultations with supervisory authorities, so far as reasonably possible.
- Notify the Customer without undue delay, and in any event within 72 hours, of any personal data breach.
- At the choice of the Customer, delete or return all personal data at the end of the service, unless retention is required by law.
- Make available all information necessary to demonstrate compliance and allow for and contribute to audits.
4. Sub-processors
The Customer authorises Talos to engage sub-processors for the service, subject to prior general written authorisation. Talos will inform the Customer of any intended additions or replacements at least 30 days in advance and give the Customer the opportunity to object on reasonable grounds.
The current list of sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Edge network, DDoS protection, CDN | EU (with global failover under SCCs) |
| Hetzner Online GmbH | Application hosting and database | Germany (EU) |
| Supabase Inc. | Managed Postgres, authentication and object storage | EU region (Frankfurt) |
| Resend, Inc. | Transactional email delivery | EU / US under SCCs |
| Stripe Payments Europe, Ltd. | Payment processing and invoicing | Ireland (EU) |
This list is representative of the sub-processors Talos may use. The definitive, up-to-date list for any specific engagement is provided in the signed DPA schedule with the Customer.
5. Security measures
Talos maintains the following technical and organisational measures (TOMs):
- Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control and mandatory multi-factor authentication for staff.
- Least-privilege access — production access limited to a named on-call rotation and logged.
- Segregated environments for development, staging and production.
- Regular vulnerability scanning and independent penetration testing at least annually.
- Encrypted, geographically redundant backups with tested restore procedures.
- Documented incident response plan with defined roles and communication paths.
- Employee security awareness training and confidentiality obligations.
6. International transfers
Personal data is primarily stored in the European Union. Where a sub-processor processes data outside the EU/EEA, the transfer is protected by the European Commission's Standard Contractual Clauses (SCCs) or an equivalent adequacy mechanism, together with any additional measures required by applicable case law (e.g. Schrems II).
7. Breach notification
Talos will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach. Notifications include, to the extent known: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address it.
8. Return and deletion of data
On termination of the Terms of Service, and at the Customer's choice, Talos will:
- Provide a data export in a structured, commonly used, machine-readable format, available for 30 days; and
- Delete all personal data from production systems within 30 days of the end of the export window, and from backups within the standard backup rotation (maximum 90 days), unless retention is required by law.
9. Audits
Talos makes available to the Customer, on written request no more than once per year, information necessary to demonstrate compliance with this DPA. This can take the form of a written questionnaire, a summary of the most recent independent audit report, or an on-site audit at the Customer's expense with reasonable prior notice.
10. Contact
Data protection matters: privacy@talos.be. Security incidents: security@talos.be.
A signed, counter-signed version of this DPA is available on request for Customers who need one for their own compliance records.